Which of the following is the BEST way for a CIO to provide progress updates on a newly implemented IT strategic plan to the board of directors?
The accountability for a business continuity program for business-critical systems is BEST assigned to the:
An enterprise considers implementing a system that uses a technology that is not in line with its IT strategy. The business case indicates significant benefit to the enterprise. Which of the following is the BEST way to manage this situation within an IT governance framework?
A review of the effectiveness of IT governance within an enterprise has revealed that several innovation improvement initiatives are failing. An analysis shows a lack of stakeholder buy-in to the improvements. Implementing which of the following would have prevented this problem?
When developing a business case for an enterprise resource planning (ERP) implementation, which of the following, if overlooked, causes the GREATEST impact to the enterprise?
A root-cause analysis indicates a major service disruption due to a lack of competency of newly hired IT system administrators. Who should be accountable for resolving the situation?
A newly hired IT director of a large international enterprise has been asked to provide periodic updates regarding IT risk to the board. Which of the following is the MOST effective way to initially address this request?
A newly appointed CIO has issued a new IT strategic plan. Which of the following is the MOST effective way for the CIO to ensure the IT management team is held accountable for the delivery of the plan?
Which of the following is the BEST approach to assist an enterprise in planning for iT-enabled investments?
To ensure IT risk is managed in a consistent manner, it is MOST important for IT governance to establish a:
Which of the following is the GREATEST benefit of using a quantitative risk assessment method?
Which of the following should be done FIRST when designing an IT balanced scorecard?
Which of the following is the MOST important benefit of effective IT governance reporting?
Which of the following should be the MOST important consideration for a hospital planning to use cloud services and mobile applications?
An enterprise is trying to increase the maturity of its IT process from being ad hoc to being repeatable. Which of the following is the PRIMARY benefit of this change?
To meet the growing demands of a newly established business unit, IT senior management has been tasked with changing the current IT organization model to
service-oriented. With significant growth expected of the IT organization, which of the following is the MOST important consideration when planning for long-term IT
service delivery?
A business has outsourced IT operations to several third-party providers, but service level agreements (SLAs) are not clearly defined in all cases. Which of the following is the GREATEST risk to the business?
Which of the following is MOST important to include in IT governance reporting to the board of directors?
Which of the following should be the PRIMARY basis for establishing categories within an information classification scheme?
Which of the following IT governance actions would be the BEST way to minimize the likelihood of IT failures jeopardizing the corporate value of an IT-dependent organization?
Which aspect of information governance BEST enables an enterprise to avoid duplication of records and promote consistency of data?
A large enterprise has decided to use an emerging technology that needs to be integrated with the current IT infrastructure. Which of the following is the BEST way to prevent adverse effects to the enterprise resulting from the new technology?
Following a re-prioritization of business objectives by management, which of the following should be performed FIRST to allocate resources to IT processes?
An internal audit revealed a widespread perception that the enterprise's IT governance reporting lacks transparency Which of the following should the CIO do FIRST?
Which of the following is the BEST way to implement effective IT risk management?
Which of the following should be the ClO's GREATEST consideration when making changes to the IT strategy'?
Which of the following should be the FIRST action taken by a newly formed IT governance committee to ensure reports are compliant with regulations and identify key IT risks?
An enterprise incurred penalties for noncompliance with privacy regulations. Which of the following is MOST important to ensure appropriate ownership of access controls to address this deficiency?
An IT strategy committee wants to evaluate how well the IT department supports the business strategy. Which of the following is the BEST method for making this determination?
The BEST way to decide how to prioritize issues identified in an IT risk and control self-assessment (CSA) is to understand the risk and:
Which of the following roles should approve major IT purchases to help prevent conflicts of interest?
A business unit is planning to replace an existing IT legacy solution with a hosted Software as a Service (SaaS) solution. However, business management is concerned that stored data will be at risk. Which of the following is the MOST effective way to reduce the risk associated with the SaaS solution?
Which of the following would provide the MOST useful information to measure the alignment of IT with the enterprise?
The GREATEST benefit associated with a decision to implement performance metrics for key IT assets is the ability to:
A large enterprise is implementing an information security policy exception process. The BEST way to ensure that security risk is properly addressed is to:
Which of the following would be the BEST way for an enterprise to address new legal and regulatory requirements applicable to IT?
Which of the following is the BEST way for a CIO to assess the consistency of IT processes against industry benchmarks to determine where to focus improvement initiatives?
An enterprise's board of directors is developing a strategy change. Although the strategy is not finalized, the board recognizes the need for IT to be responsive. Which of the following is the FIRST step to prepare for this change?
An internal auditor conducts an assessment of a two-year-old IT risk management program. Which of the following findings should be of MOST concern to the CIO?
An interna! health organization has been notified that a data breach has resulted in patient records being published online. Which of the
following is MOST important consideration when determining the process for meeting the organization's legal and regulatory obligations?
Which of the following is the BEST way to address the risk associated with new IT investments?
A CIO is planning to implement an enterprise resource planning (ERP) system at the request of the business. Of the following, who is accountable for providing sponsorship for the IT-enabled change across the enterprise?
An enterprise learns that some of its business divisions have been approaching technology vendors for cloud services, resulting in duplicate support contracts and underutilization of IT services. Which of the following should be done FIRST to address this issue?
The MOST appropriate method for evaluating the capability of IT governance is through the use of:
What is the PRIMARY benefit of aligning information architecture with enterprise architecture (EA)?
An IT governance committee is reviewing its current risk management policy in light of increased usage of social media within an enterprise. The FIRST task for the governance committee is to:
An enterprise is assessing whether to utilize wearable technology. The enterprise has no prior experience with this technology and has asked the chief technology officer (CTO) to assess the impact to the enterprise. The CTO should FIRST:
Which of the following metrics is MOST useful to ensure IT services meet business requirements?
Which of the following is the BEST indicator of the effectiveness of IT governance in an enterprise?
An IT governance committee realizes there are antiquated technologies in use throughout the enterprise. Which of the following is the BEST group to evaluate the recommendations to address these shortcomings?
Which of the following is MOST important to include in the customer dimension of an IT balanced scorecard?
An enterprise is concerned that ongoing maintenance costs are not being considered when prioritizing IT-enabled business investments. Which of the following should be the enterprise's FIRST course of action?
When selecting a cloud provider, which of the following provides the MOST comprehensive information regarding the current status and effectiveness of the provider's controls?
Which of the following is MOST important for a CIO to ensure before signing a contract for a new cloud-based customer relationship management (CRM) system?
What should be an IT steering committee's FIRST course of action when an enterprise is considering establishing a virtual reality store to sell its products?
Which of the following would be an IT steering committee's BEST course of action upon learning business units have been independently procuring cloud services?
Which of the following should a new CIO do FIRST to set the strategic direction for IT?
From an IT governance perspective, which of the following would be the MOST significant impact of moving all IT applications to an external Software as a Service (SaaS) cloud provider?
An enterprise has decided to use third-party software for a business process which is hosted and supported by the same third party. The BEST way to provide quality of service oversight would be to establish a process:
Which of the following is the PRIMARY reason to monitor data classification efforts?
The BEST way for a CIO to justify maintaining and supporting social media platforms is by demonstrating:
Which of the following should be the PRIMARY consideration when implementing an emerging technology with unclear regulatory and compliance requirements?
An enterprise has made the strategic decision to begin a global expansion program which will require opening sales offices in countries across the world. Which of the following should be the FIRST consideration with regard to the IT service desk which will remain centralized?
Which of the following is the PRIMARY benefit to an enterprise when risk management is practiced effectively throughout the organization?
Which of the following would BEST help assess the effectiveness of a newly established IT governance framework?
A small enterprise has just hired its first CIO, who has been tasked with making the IT department more efficient. What should be the CIO's NEXT step after identifying several new improvement initiatives?
Which of the following BEST supports an IT staff restructure as part of an annual IT strategy review with senior management?
Which of the following would be MOST helpful to review when determining how to allocate IT resources during a resource shortage?
A CIO is planning to interview enterprise stakeholders to assess whether the IT strategic plan is continuing to support enterprise business objectives. The CIO would be MOST effective by starting the interview process with:
IT governance within an enterprise is attempting to drive a cultural shift to enhance compliance with IT security policies. The BEST way to support this objective is to ensure that enterprise IT policies are:
An organization has decided to integrate IT risk with the enterprise risk management (ERM) framework. The FIRST step to enable this integration is to establish:
When identifying improvements focused on the information asset life cycle, which of the following is CRITICAL for enabling data interoperability?
A CIO was notified that a new employee was observed wearing a headset with an optical lens at the organization's data center. The individual was entering voice commands into the device. When approached, the employee explained the device is a new personal technology serving as a hands-free version of a smart phone. The CIO is concerned with potential security vulnerabilities of allowing such devices, and whether they should be banned from the facility. What should be the NEXT course of action in response to the ClO's concern?
Which of the following has the GREATEST impact on the design of an IT governance framework?
Which of the following is the GREATEST consideration when evaluating whether to comply with the new carbon footprint regulations impacted by blockchain technology?
Which of the following is the BEST critical success factor (CSF) to use when changing an IT value management program in an enterprise?
Which of the following is the BEST way for a CIO to ensure that IT-related training is taken seriously by the IT management team and direct employees?
Which of the following is the BEST way to encourage employees to raise ethics concerns in full confidence?
An enterprise has a centralized IT function but also allows business units to have their own technology operations, resulting in duplicate technologies and conflicting priorities. Which of the following should be done FIRST to reduce the complexity of the IT landscape?
Which of the following BEST facilitates the adoption of an IT governance program in an enterprise?
Which of the following is the BEST approach to ensure global regulatory compliance when implementing a new business process?
Which of the following is the PRIMARY purpose of an effective set of key risk indicators (KRIs)?
The PRIMARY reason for implementing an IT governance program in an enterprise is to
When developing an IT strategic plan that supports an enterprise's business goals which of the following should be done FIRST?
Establishing a uniform definition for likelihood and impact BEST enables an enterprise to:
An enterprise is concerned with the potential for data leakage as a result of increased use of social media in the workplace, and wishes to establish a social media strategy. Which of the following should be the MOST important consideration in developing this strategy?
Enterprise leadership is concerned with the potential for discrimination against certain demographic groups resulting from the use of machine learning models What should be done FIRST to address this concern?
The CEO of an organization is concerned that there are inconsistencies in the way information assets are classified across the enterprise. Which of the following is be the BEST way for the CIO to address these concerns?
As part of the implementation of IT governance, the board of an enterprise should establish an IT strategy committee to:
The risk committee is overwhelmed by the number of false positives included in risk reports. What action would BEST address this situation?
Which of the following should be the PRIMARY governance objective for selecting key risk indicators (KRIs) related to legal and regulatory compliance?
Which of the following is the BEST outcome measure to determine the effectiveness of IT nsk management processes?
Which of the following is the BEST way to address an IT audit finding that many enterprise application updates lack appropriate documentation?
Which of the following is the MOST appropriate mechanism for measuring overall IT organizational performance?
Which of the following BEST facilitates governance oversight of data protection measures?
Which of the following should be established FIRST so that data owners can consistently assess the level of data protection needed across the enterprise?
When establishing a risk management process which of the following should be the FIRST step?
An organization is evaluating vendors to provide mobile device management (MDM) services. Which of the following is a KEY governance consideration for the IT steering committee?
A CIO just received a final audit report that indicates there is inconsistent enforcement of the enterprise's mobile device acceptable use policy throughout all business units. Which of the following should be the FIRST step to address this issue?
Which of the following provides the BEST information to assess the effective alignment of IT investments?
Which of the following will BEST enable an IT steering committee to monitor the achievement of overall IT objectives on a continuous basis?
An IT steering committee is preparing to review proposals for projects that implement emerging technologies. In anticipation of the review, the committee should FIRST:
An assessment reveals that enterprise risk management (ERM) practices are being applied inconsistently by IT staff. Which of the following would be the MOST effective corrective action?
An enterprise wants to address the human factors of social engineering risk within the organization. From a governance perspective, which of the following is the BEST way to mitigate this risk?
An IT governance committee is defining a risk management policy for a portfolio of IT-enabled investments Which of the following should be the PRIMARY consideration when developing the policy?
Which of the following is (he GREATEST benefit of using the life cycle approach to govern information assets?
Which of the following should be the PRIMARY goal of implementing service level agreements (SLAs) with an outsourcing vendor?
An enterprise has learned of a new regulation that may impact delivery of one of its core technology services Which of the following should the done FIRST?
The CIO of an international enterprise is considering the use of an offshore cloud service provider to store customer data. Which of the following should be the MOST important consideration when making this decision?
A manufacturing company has recently decided to outsource portions of its IT operations. Which of the following would BEST justify this decision?
Which of the following should be the MOST important consideration when defining an information architecture?
Which of the following is the GREATEST impact to an enterprise that has ineffective information architecture?
An enterprise's internal audit group has scheduled a control review of a payroll system project but has been told to wait until the system is implemented. Which of the following is the GREATEST risk associated with the delay?
An enterprise's CIO requires all IT processes within the enterprise to be clearly defined. Which of the following would be the MOST immediate outcome?
An IT strategy committee wants to ensure that a risk program is successfully implemented throughout the enterprise. Which of the following would BEST support this goal?
An enterprise has a large backlog of IT projects. The current strategy is to execute projects as they are submitted, but executive management does not believe this method is optimal. Which of the following is the MOST important action to address this concern?
An enterprise considering implementing IT governance should FIRST develop the scope of the IT governance program and:
A CIO must determine if IT staff have adequate skills to deliver on key strategic objectives. Which of the following will provide the MOST useful information?
A board of directors wants to ensure the enterprise is responsive to changes in its environment that would directly impact critical business processes. Which of the following will BEST facilitate meeting this objective?
A company is considering selling products online, and the CIO has been asked to advise the board of directors of potential problems with this strategy. Which of the following is the ClO's BEST course of action?
Which of the following is MOST important when an IT-enabled business initiative involves multiple business functions?
An enterprise incurred penalties for noncompliance with privacy regulations. Which of the following is MOST important to ensure appropriate ownership of access controls to address this deficiency?
Which of the following is the PRIMARY ongoing responsibility of the IT governance function related to risk?
Which of the following would be MOST important to update if a decision is made to ban end user-owned devices in the workplace?
Which of the following responsibilities should be retained within an enterprise when outsourcing a project management office (PMO) function?
A newly established IT steering committee is concerned about whether a system is meeting availability objectives. Which of the following will provide the BEST information to make an assessment?
The board of directors has mandated the use of geolocation software to track mobile assets assigned to employees who travel outside of their home country. To comply with this mandate, the IT steering committee should FIRST request
A new and expanding enterprise has recently received a report indicating 90% of its data has been collected in just the last six months, triggering data breach and privacy concerns. What should be the IT steering committee's FIRST course of action to ensure new data is managed effectively?
Which of the following provides the BEST assurance on the effectiveness of IT service management processes?
The CEO of a large enterprise has announced me commencement of a major business expansion that will double the size of the organization. IT will need to support the expected demand expansion. What should the CIO do FIRST?
The use of an IT balanced scorecard enables the realization of business value of IT through:
A large financial institution is considering outsourcing customer call center operations which will allow the chosen vendor to access systems from offshore locations. Which of the following represents the GREATEST risk?
The board of directors of an enterprise has approved a three-year IT strategic program to centralize the core business processes of its global entities into one core system. Which of the following should be the ClO's NEXT step?
Which of the following is the MOST effective way of assessing enterprise risk?
A CIO believes that a recent mission-critical IT decision by the board of directors is not in the best financial interest of all stakeholders. Which of the following is the MOST ethical course of action?
Which of the following is the MOST important benefit of developing an information architecture model consistent with enterprise strategy?
An enterprise is evaluating a Software as a Service (SaaS) solution to support a core business process. There is no outsourcing governance or vendor management in place. What should be the CEO's FIRST course of action?
An enterprise has made the strategic decision to reduce operating costs for the next year and is taking advantage of cost reductions offered by an external cloud service provider. Which of the following should be the IT steering committee's PRIMARY concern?
An IT audit report indicates that a lack of IT employee risk awareness is creating serious security issues in application design and configuration. Which of the following would be the BEST key risk indicator (KRI) to show progress in IT employee behavior?
Which of the following is the BEST way to demonstrate that IT strategy supports a new enterprise strategy?
An enterprise has decided to create its first mobile application. The IT director is concerned about the potential impact of this initiative. Which of the following is the MOST important input for managing the risk associated with this initiative?
An audit report has revealed that data scientists are analyzing sensitive "big data" files using an offsite cloud because corporate servers do not have the necessary processing capabilities. A review of policies indicates this practice is not prohibited. Which of the following should be the FIRST strategic action to address the report?
Which of the following groups should approve the implementation of new technology?
An IT steering committee is presented with an audit finding that new software applications are delivered on time but consistently have unacceptable levels of defects. Which of the following would be the BEST direction from the committee?
Senior management is reviewing the results of a recent security incident with significant business impact. Which of the following findings should be of GREATEST concern?
An IT investment review board wants to ensure that IT will be able to support business initiatives. Each initiative is comprised of several interrelated IT projects. Which of the following would help ensure that the initiatives meet their goals?
A global financial enterprise has been experiencing a substantial number of information security incidents that have directly affected its business reputation. Which of the following should be the IT governance board's FIRST course of action?
An enterprise has established a new department to oversee the life cycle of activities that support data management objectives. Which of the following should be done NEXT?
Senior management wants to expand offshoring to include IT services as other types of business offshoring have already resulted in significant financial benefits for the enterprise. The CIO is currently midway through a successful five-year strategy that relies heavily on internal IT resources. What should the CIO do NEXT?
The board and senior management of a new enterprise recently met to formalize an IT governance framework. The board of directors' FIRST step in implementing IT governance is to ensure that:
An enterprise plans to implement a business intelligence (Bl) tool with data sources from various enterprise applications. Which of the following is the GREATEST challenge to implementation?
The CIO of an enterprise learns the payroll server of a competitor has been the victim of ransomware. To help plan for the possibility of ransomed corporate data, what should be the ClO's FIRST course of action?
The PRIMARY reason for an enterprise to adopt an IT governance framework is to:
Which of the following would provide the BEST input for prioritizing strategic IT improvement initiatives?
Which of the following is the MOST effective approach to ensure senior management sponsorship of IT risk management?
An enterprise embarked on an aggressive strategy requiring the implementation of several large IT projects impacting multiple business processes across all departments. Initially employees were supportive of the strategy, but there is growing fatigue and frustration with the ongoing new capabilities which must be learned. Which of the following would be the BEST action performed by senior management?
The MOST important aspect of an IT governance framework to ensure that IT supports repeatable business processes is:
Which of the following is the MOST effective means for IT management to report to executive management regarding the value of IT?
An enterprise is initiating efforts to improve system availability to mitigate IT risk to the business. Which of the following results would be MOST important to report to the CIO to measure progress?
Which of the following represents the GREATEST challenge to implementing IT governance?
A global enterprise is experiencing an economic downturn and is rapidly losing market share. IT senior management is reassessing the core activities of the business, including IT, and the associated resource implications. Management has decided to focus on its local market and to close international operations. A critical issue from a resource management perspective is to retain the most capable staff. This is BEST achieved by: