A new chief information officer (CIO) of an enterprise recommends implementing portfolio management after realizing there is no process in place for evaluating investments prior to selection. What should be the PRIMARY strategic goal driving this decision?
A CIO is planning to implement an enterprise resource planning (ERP) system at the request of the business. Of the following, who is accountable for providing sponsorship for the IT-enabled change across the enterprise?
The accountability for a business continuity program for business-critical systems is BEST assigned to the:
An IT governance committee realizes there are antiquated technologies in use throughout the enterprise. Which of the following is the BEST group to evaluate the recommendations to address these shortcomings?
A strategic IT-enabled investment is failing due to unforeseen technology problems. What should be the board of directors' FIRST course of action?
A CIO of an enterprise is concerned that IT and the business have different priorities. Which of the following would BEST demonstrate the current state of strategic alignment?
Which of the following will BEST enable an IT steering committee to monitor the achievement of overall IT objectives on a continuous basis?
An independent consultant has been hired to conduct an ad hoc audit of an enterprise’s information security office with results reported to the IT governance committee and the board Which of the following is MOST important to provide to the consultant before the audit begins?
The PRIMARY benefit of integrating IT resource planning into enterprise strategic planning is that it enables the enterprise to:
A large enterprise that is diversifying its business will be transitioning to a new software platform, which is expected to cause data changes. Which of the following should be done FIRST when developing the related metadata management process?
A strategic systems project was implemented several months ago. Which of the following is the BEST reference for the IT steering committee as they evaluate its level of success?
The CIO in a large enterprise is seeking assurance that significant IT risk is being proactively monitored and does not exceed agreed risk tolerance levels. The BEST way to provide this ongoing assurance is to require the development of:
An IT investment review board wants to ensure that IT will be able to support business initiatives. Each initiative is comprised of several interrelated IT projects. Which of the following would help ensure that the initiatives meet their goals?
The board of directors has mandated the use of geolocation software to track mobile assets assigned to employees who travel outside of their home country. To comply with this mandate, the IT steering committee should FIRST request
An enterprise experiencing issues with data protection and least privilege is implementing enterprise-wide data encryption in response. Which of the following is the BEST approach to ensure all business units work toward remediating these issues?
An enterprise has had the same IT governance framework in place for several years. Currently, large and small capital projects go through the same architectural governance reviews. Despite repeated requests to streamline the review process for small capital projects, business units have received no response from IT. The business units have recently escalated this issue to the newly appointed GO. Which of the following should be done FIRST to begin addressing business needs?
An enterprise embarked on an aggressive strategy requiring the implementation of several large IT projects impacting multiple business processes across all departments. Initially employees were supportive of the strategy, but there is growing fatigue and frustration with the ongoing new capabilities which must be learned. Which of the following would be the BEST action performed by senior management?
When developing effective metrics for the measurement of solution delivery, it is MOST important to:
What is the PRIMARY objective for performing an IT due diligence review prior to the acquisition of a competitor?
Who is PRIMARILY accountable for delivering the benefits of an IT-enabled investment program to the enterprise?
A multinational enterprise recently purchased a large company located in a different country. When introducing the concept of governance to the new acquisition, it is MOST important that executive management recognize:
Senior management wants to promote investment in IT, but is uncertain that associated risks are being properly identified. The BEST way to address this concern is to:
Which of the following MOST effectively prevents an IT system from becoming technologically obsolete before its planned return on investment (ROi)?
Which of the following is the BEST method for making a strategic decision to invest in cloud services?
Before an IT strategy committee can approve an IT risk assessment framework, which of the following is MOST important to have established?
An enterprise made a significant change to its business operating model that resulted in a new strategic direction. Which of the following should be reviewed FIRST to ensure IT congruence with the new business strategy?
An enterprise has established a new department to oversee the life cycle of activities that support data management objectives. Which of the following should be done NEXT?
A board of directors wants to ensure the enterprise is responsive to changes in its environment that would directly impact critical business processes. Which of the following will BEST facilitate meeting this objective?
Which of the following is the BEST indication of effective IT-business strategic alignment?
Which of the following provides the BEST evidence of effective IT governance?
To measure the value of IT-enabled investments, an enterprise needs to identify its drivers as defined by its:
Which of the following should a CIO review to obtain a holistic view of IT performance when identifying potential gaps in service delivery?
An enterprise is implementing its first mobile sales channel. Final approval for accepting the associated IT risk should be obtained from which of the following?
An enterprise is assessing whether to utilize wearable technology. The enterprise has no prior experience with this technology and has asked the chief technology officer (CTO) to assess the impact to the enterprise. The CTO should FIRST:
An IT steering committee is concerned about staff saving data files containing sensitive corporate information on publicly available cloud file storage applications. Which of the following should be done FIRST to address this concern?
Which of the following is the GREATEST expected strategic organizational benefit from the standardization of technical platforms?
An enterprise has a centralized IT function but also allows business units to have their own technology operations, resulting in duplicate technologies and conflicting priorities. Which of the following should be done FIRST to reduce the complexity of the IT landscape?
Within a governance structure for risk management, which of the following activities should be performed by the second line of defense?
Which of the following BEST helps to ensure that IT policies are
aligned with organizational strategies?
Which of the following would BEST help assess the effectiveness of a newly established IT governance framework?
Which of the following is the MOST efficient approach for using risk scenarios to evaluate a new business opportunity?
Which of the following should a new CIO do FIRST to set the strategic direction for IT?
Despite an adequate training budget. IT staff are not keeping skills current with emerging technologies critical to the business. Which of the following is the BEST way for the enterprise to address this situation?
Which of the following BEST facilitates the standardization of IT vendor selection?
IT senior management has just received a survey report indicating that more than one third of the organization's key IT staff plan to retire within the next 12 months. Which of the following is the MOST important governance action to prepare for this possibility?
A CIO just received a final audit report that indicates there is inconsistent enforcement of the enterprise's mobile device acceptable use policy throughout all business units. Which of the following should be the FIRST step to address this issue?
Individual business units within an enterprise have been designing their own IT solutions without consulting the IT department. From a governance perspective, what is the GREATEST issue associated with this situation?
A CEO wants to establish a governance framework to facilitate the alignment of IT and business strategies. Which of the following should be a KEY requirement of this framework?
Which of the following is MOST important to document for a business ethics program?
Before establishing IT key nsk indicators (KRls) which of the following should be defined FIRST?
Which of the following decisions would be made by the IT strategy committee?
Which of the following is the GREATEST impact to an enterprise that has ineffective information architecture?
From a governance perspective, the PRIMARY goal of an IT risk optimization process should be to ensure:
What is the BEST criterion for prioritizing IT risk remediation when resource requirements are equal?
Which of the following is the BEST approach to assist an enterprise in planning for iT-enabled investments?
Which of the following is the BEST approach when reviewing The security status of a new business acquisition?
Of the following, who should approve the criteria for information quality within an enterprise?
The BEST way to manage continuous improvement of governance-related processes is to:
An enterprise is evaluating a Software as a Service (SaaS) solution to support a core business process. There is no outsourcing governance or vendor management in place. What should be the CEO's FIRST course of action?
A review of the effectiveness of IT governance within an enterprise has revealed that several innovation improvement initiatives are failing. An analysis shows a lack of stakeholder buy-in to the improvements. Implementing which of the following would have prevented this problem?
While assessing the feasibility of introducing new IT practices and standards into the IT governance framework, it is CRITICAL to understand an organization's:
A rail transport company has the worst on-time arrival record in the industry due to an antiquated IT system that controls scheduling. Despite employee resistance, an initiative lo upgrade the technology and related processes has been approved. To maximize employee engagement throughout the project, which of the following should be in place prior to the start of the initiative?
Which of the following is the BEST way to demonstrate that IT strategy supports a new enterprise strategy?
An enterprise plans to expand into new markets in countries lacking data privacy regulations, increasing risk exposure. Which of the following is the BEST course of action for the CIO?
It has been discovered that multiple business units across an enterprise are using duplicate IT applications and services to fulfill their individual needs. Which of the following would be MOST helpful to address this concern?
Which of the following would provide the BEST input for prioritizing strategic IT improvement initiatives?
An enterprise considering implementing IT governance should FIRST develop the scope of the IT governance program and:
Enterprise IT has overseen the implementation of an array of data services with overlapping functionality leading to business inefficiencies. Which of the following is the MOST likely cause of this situation?
Which of the following is the BEST way to ensure the continued usefulness of IT governance reports for stakeholders?
Which of the following BEST reflects mature risk management in an enterprise?
Acceptance of an enterprise's newly implemented IT governance initiatives has been resisted by a functional group requesting more autonomy over technology choices. Which of the following is MOST important to accommodate this need for autonomy?
An executive sponsor of a partially completed IT project has learned that the financial assumptions supporting the project have changed. Which of the following governance actions should be taken FIRST?
Which of the following is the PRIMARY element in sustaining an effective governance framework?
An enterprise has made the strategic decision to reduce operating costs for the next year and is taking advantage of cost reductions offered by an external cloud service provider. Which of the following should be the IT steering committee's PRIMARY concern?
Which of the following is the MOST effective way for a CIO to govern business unit deployment of shadow IT applications in a cloud environment?
An enterprise considers implementing a system that uses a technology that is not in line with its IT strategy. The business case indicates significant benefit to the enterprise. Which of the following is the BEST way to manage this situation within an IT governance framework?
Which of the following MOST effectively demonstrates operational readiness to address information security risk issues?
Due to continually missed service level agreements (SLAs), an enterprise plans to terminate its contract with a vendor providing IT help desk services. The enterprise s IT department will assume the help desk-related responsibilities. Which of the following would BEST facilitate this transition?
A company is considering selling products online, and the CIO has been asked to advise the board of directors of potential problems with this strategy. Which of the following is the ClO's BEST course of action?
An enterprise can BEST assess the benefits of a new IT project through its life cycle by:
Establishing a uniform definition for likelihood and impact through risk management standards PRIMARILY addresses which of the following concerns?
Which of the following is MOST critical for the successful implementation of an IT process?
An enterprise has a zero-tolerance policy regarding security. This policy is causing a large number of email attachments to be blocked and is a disruption to enterprise. Which of the following should be the FIRST governance step to address this email issue?
Which of the following would be of MOST concern regarding the effectiveness of risk management processes?
Which of the following would provide the MOST useful information to measure the alignment of IT with the enterprise?
IT governance within an enterprise is attempting to drive a cultural shift to enhance compliance with IT security policies. The BEST way to support this objective is to ensure that enterprise IT policies are:
When identifying improvements focused on the information asset life cycle, which of the following is CRITICAL for enabling data interoperability?
What should be an IT steering committee's FIRST course of action when an enterprise is considering establishing a virtual reality store to sell its products?
Which of the following is the MOST efficient way for an IT transformation project manager to communicate the project progress with stakeholders?
Which of the following is the PRIMARY consideration for an enterprise when deciding whether to adopt a qualitative risk assessment method?
An internal auditor conducts an assessment of a two-year-old IT risk management program. Which of the following findings should be of MOST concern to the CIO?
Which of the following is MOST important for a CIO to ensure before signing a contract for a new cloud-based customer relationship management (CRM) system?
Which of the following BEST facilitates the adoption of an IT governance program in an enterprise?
In a large enterprise, which of the following is the BEST approach to enable effective communication to senior management regarding the project status for a strategic enterprise resource management system implementation?
Which of the following should be considered FIRST when assessing the implications of new external regulations on IT compliance?
Which of the following is MOST likely to have a negative impact on
accountability for information risk ownership?
An enterprise's board of directors is developing a strategy change. Although the strategy is not finalized, the board recognizes the need for IT to be responsive. Which of the following is the FIRST step to prepare for this change?
Which of the following would be MOST helpful to review when determining how to allocate IT resources during a resource shortage?
When an enterprise is evaluating potential IT service vendors, which of the following BEST enables a clear understanding of the vendor's capabilities that will be critical to the enterprise's strategy?
An enterprise's IT department has been operating independently without regard to business concerns, leading to misalignment between business and IT. The BEST way to establish alignment would be to require:
When selecting a cloud provider, which of the following provides the MOST comprehensive information regarding the current status and effectiveness of the provider's controls?
Which of the following BEST enables an enterprise to achieve the benefits of implementing new Internet of Things (loT) technology?
Which of the following is the BEST critical success factor (CSF) to use when changing an IT value management program in an enterprise?
A high-tech enterprise is concerned that leading competitors have been successfully recruiting top talent from the enterprise's research and development business unit.
What should the leadership team mandate FIRST?
Which of the following characteristics would BEST indicate that an IT process is a good candidate for outsourcing?
Which of the following would BEST help to ensure the appropriate allocation of IT resources to support an enterprise's mission?
When a shortfall of IT resources is identified, the FIRST course of action is to;
An enterprise has made the strategic decision to begin a global expansion program which will require opening sales offices in countries across the world. Which of the following should be the FIRST consideration with regard to the IT service desk which will remain centralized?
Which of the following is MOST important for a data steward to verify when a system's data is edited by an automated tool to fix an incident?
Which of the following is the BEST way to encourage employees to raise ethics concerns in full confidence?
A CIO has recently been made aware of a new regulatory requirement that may affect IT-enabled business activities. Which of the following should be the CIO s FIRST step in deciding the appropriate response to the new requirement?
An enterprise is concerned that ongoing maintenance costs are not being considered when prioritizing IT-enabled business investments. Which of the following should be the enterprise's FIRST course of action?
Which of the following would be an IT steering committee's BEST course of action upon learning business units have been independently procuring cloud services?
When establishing a methodology for business cases, it would be MOST beneficial for an enterprise to include procedures for:
A CEO realizes the need to implement IT governance to support the strategic alignment of business and IT goals. Which of the following would BEST enable this initiative?
An enterprise has decided to use third-party software for a business process which is hosted and supported by the same third party. The BEST way to provide quality of service oversight would be to establish a process:
A CIO was notified that a new employee was observed wearing a headset with an optical lens at the organization's data center. The individual was entering voice commands into the device. When approached, the employee explained the device is a new personal technology serving as a hands-free version of a smart phone. The CIO is concerned with potential security vulnerabilities of allowing such devices, and whether they should be banned from the facility. What should be the NEXT course of action in response to the ClO's concern?
Which of the following is the BEST way to address the risk associated with new IT investments?
Which strategic planning approach would be MOST appropriate for a large enterprise to follow when revamping its IT services?
When conducting a risk assessment in support of a new regulatory
requirement, the IT risk committee should FIRST consider the:
An enterprise recently implemented a significant change in its business strategy by moving to a technologically advanced product with considerable impact on the business. What should be the FINAL step in completing the changes to IT processes?
Which of the following BEST supports an IT strategy committee’s objective to align employee competencies with planned initiatives?
Which of the following is the BEST way for a CIO to assess the consistency of IT processes against industry benchmarks to determine where to focus improvement initiatives?
Of the following, who is responsible for the achievement of IT strategic objectives?
Which of the following should be the FIRST action taken by a newly formed IT governance committee to ensure reports are compliant with regulations and identify key IT risks?
Which of the following roles should be responsible for data normalization when it is found that a new system includes duplicates of data items?
Which of the following is the BEST method to confirm whether a pilot project was successful?
An enterprise has committed to the implementation of a new IT governance model. The BEST way to begin this implementation is to:
A business unit is planning to replace an existing IT legacy solution with a hosted Software as a Service (SaaS) solution. However, business management is concerned that stored data will be at risk. Which of the following is the MOST effective way to reduce the risk associated with the SaaS solution?
The use of an enterprise architecture (EA) framework BEST supports IT governance by providing:
Which of the following should a new CIO do FIRST to ensure information assets are effectively governed?
Which of the following BEST supports enterprise decision making for IT resource allocation?
When considering an IT change that would enable a potential new line of business, the FIRST strategic step for IT governance would be to ensure agreement among the stakeholders regarding:
Following the rollout of an enterprise IT software solution that hosts sensitive data it was discovered that the application's role-based access control was not functioning as specified Which of the following is the BEST way to prevent reoccurrence in the future?
The PRIMARY objective of promoting business ethics within the IT enterprise should be to ensure:
Which of the following should be the PRIMARY goal of implementing service level agreements (SLAs) with an outsourcing vendor?
Which of the following would provide the MOST useful information to understand the associated risks when implementing a new digital transformation strategy?
A financial services company has implemented the use of a cloud-based centralized customer relationship management (CRM) system. The company has decided to go multi-national. Which of the following should be the enterprise risk management (ERM) committee's PRIMARY consideration?
An IT steering committee is preparing to review proposals for projects that implement emerging technologies. In anticipation of the review, the committee should FIRST:
The BEST way to decide how to prioritize issues identified in an IT risk and control self-assessment (CSA) is to understand the risk and:
An enterprise is concerned with the potential for data leakage as a result of increased use of social media in the workplace, and wishes to establish a social media strategy. Which of the following should be the MOST important consideration in developing this strategy?
Which of the following should be the FIRST step in updating an IT strategic plan?
An enterprise has launched a series of critical new IT initiatives that are expected to produce substantial value Which of the following would BEST provide the board with an indication of progress of the IT initiatives?
The IT department has determined that problems with a business report are due to quality issues within a set of data to whom should IT refer the matter for resolution?
Which of the following would BEST help a CIO enhance the competencies of an IT business analytics team?
The PRIMARY reason a CIO and IT senior management should stay aware of the business environment is to:
An enterprise has decided to implement an IT risk management program After establishing stakeholder desired outcomes, the MAIN goal of the IT strategy committee should be to:
Which of the following is the BEST outcome measure to determine the effectiveness of IT nsk management processes?
A large enterprise has decided to use an emerging technology that needs to be integrated with the current IT infrastructure. Which of the following is the BEST way to prevent adverse effects to the enterprise resulting from the new technology?
After shifting from lease to purchase of IT infrastructure and software licenses, an enterprise has to pay for unexpected lease extensions causing significant cost overruns. The BEST direction for the IT steering committee would be to establish;
An IT steering committee has received a report that supports the economic and service benefits of moving infrastructure hosting to an external cloud provider. Business leadership is very concerned about the security risk and potential loss of customer data. What is the BEST way for the committee to address these concerns?
Which of the following should senior management do FIRST when developing and managing digital applications for a new enterprise?
Which of the following is MOST important for an enterprise to review when classifying information assets?
Which of the following BEST enables an enterprise to determine how business expectations should be addressed in a governance program?
Which of the following should IT governance mandate before any transition of data from a legacy system to a new technology platform?
An enterprise has performed a business impact analysis (BIA) considering a number of risk scenarios Which of the following should the enterprise do NEXT?
Which of the following IT governance practices would BEST support IT and enterprise strategic alignment?
In a large enterprise, which of the following should be responsible for the implementation of an IT balanced scorecard?
In a successful enterprise that is profitable in its marketplace and consistently growing in size, the non-IT workforce has grown by 50% in the last two years. The demand for IT staff in the marketplace is more than the supply, and the enterprise is losing staff to rival organizations. Due to the rapid growth. IT has struggled to keep up with the enterprise, and IT procedures and associated job roles are not well-defined. The MOST critical activity for reducing the impact caused by IT staff turnover is to: