Which of the following should be done FIRST when preparing to migrate patient records to a cloud service provider?
Which of the following should be the MOST essential consideration when outsourcing IT services?
Which of the following is the PRIMARY objective of a data protection impact assessment?
Which of the following presents the GREATEST challenge for a large-scale enterprise when procuring Infrastructure as a Service (IaaS)?
A CIO has been asked to modify an organization's IT performance measurement system to reflect recent changes in technology, including the movement of some data processing to a cloud solution. Which of the following is the PRIMARY consideration when designing such a measurement system?
To benefit from economies of scale, a CIO is deciding whether to outsource some IT services. Which of the following would be the MOST important consideration during the decision-making process?
Which of the following is MOST important to ensure that IT project selections meet the enterprise’s business requirements?
An enterprise has an overarching enterprise architecture (EA) document. The CIO is concerned that EA is not leveraged in recent IT-enabled investments. Which of the following would BEST help to address these concerns and enforce the leveraging of EA?
Which of the following BEST enables an enterprise to achieve the benefits of implementing new Internet of Things (loT) technology?
The board of an organization has been informed of possible cyberthreats. Which of the following should be the board’s NEXT course of action?
A newly established IT steering committee is concerned whether a system is meeting availability objectives. Which of the following will provide the BEST information to make an assessment?
A high-tech enterprise is concerned that leading competitors have been successfully recruiting top talent from the enterprise's research and development business unit.
What should the leadership team mandate FIRST?
Which of the following is MOST important to have in place to ensure a business continuity plan (BCP) can be executed?
An enterprise recently experienced a major breach that was escalated effectively. However, the recovery took far longer than expected, resulting in significant financial loss. Which of the following is MOST likely the root cause of this scenario?
Which of the following should be the FIRST step to ensure IT resources have the appropriate skills and experience level to support enterprise objectives?
New legislation requires an enterprise to report cybersecurity incidents to a government agency within a defined timeline. Which of the following should be the FIRST course of action?
Which of the following is the BEST way for a CIO to provide progress updates on a newly implemented IT strategic plan to the board of directors?
Present an IT summary dashboard.
Present IT critical success factors (CSFs).
Report results Of key risk indicators (KRIs).
Which of the following should be the PRIMARY consideration when implementing IT governance in a small, newly established organization?
Which of the following should be the PRIMARY consideration when implementing an emerging technology with unclear regulatory and compliance requirements?
An organization has decided to integrate IT risk with the enterprise risk management (ERM) framework. The FIRST step to enable this integration is to establish:
An enterprise has decided to invest in Internet of Things (IoT) technology as part of its strategic plan. Which of the following presents the GREATEST risk to consider as part of the technical risk management process?
A series of cyber events impacting internet-facing business services has been successfully contained. To minimize future business risk exposure, which of the following should the board require of the IT team?
Despite an adequate training budget, IT staff are not keeping skills current with emerging technologies critical to the business. Which of the following is the BEST way for the enterprise to address this situation?
An enterprise’s IT director is concerned that the chair of the IT steering committee is stealing confidential company information. Which of the following is the IT director’s BEST course of action?
Which of the following BEST helps to ensure that IT policies are
aligned with organizational strategies?
Which of the following is the MOST effective approach to ensure senior management sponsorship of IT risk management?
When an enterprise outsources to a third-party data center, who is accountable for the governance of data retention controls for the data that has been transferred?
An enterprise is concerned that ongoing maintenance costs are not being considered when prioritizing IT-enabled business investments. Which of the following should be the enterprise's FIRST course of action?
An enterprise wants to establish key risk indicators (KRIs) in an effort to better manage IT risk. Which of the following should be identified FIRST?
What is the BEST way for a board of directors to improve its ability to identify material changes to the enterprise IT risk profile?
Which of the following is the BEST way to express the value of financial investments in cybersecurity?
Which of the following provides an enterprise with the BEST understanding of the value proposition for employing a new cloud service?
Which of the following roles is accountable for the confidentiality, integrity, and availability of information within an enterprise?
Which of the following would BEST help to prevent an IT system from becoming obsolete before its planned return on investment (ROI)?
When developing IT risk management policies and standards, it is MOST important to align them with:
When developing IT risk management policies and standards, it is MOST important to align them with:
A regulatory audit of an IT department has identified discrepancies between processes described in the procedures and what is actually done by system administrators.
The discrepancies were caused by recent IT application changes. Which of the following would be the BEST way to prevent the recurrence of similar findings in the future?
An enterprise has established a new department to oversee the life cycle of activities that support data management objectives. Which of the following should be done NEXT?
What is the PRIMARY benefit of aligning information architecture with enterprise architecture (EA)?
Which of the following MOST effectively prevents an IT system from becoming technologically obsolete before its planned return on investment (ROi)?
A CIO was notified that a new employee was observed wearing a headset with an optical lens at the organization's data center. The individual was entering voice commands into the device. When approached, the employee explained the device is a new personal technology serving as a hands-free version of a smart phone. The CIO is concerned with potential security vulnerabilities of allowing such devices, and whether they should be banned from the facility. What should be the NEXT course of action in response to the ClO's concern?
An enterprise is planning to upgrade its current enterprise resource planning (ERP) system to remain competitive within the industry. Which of the following would be MOST helpful to facilitate a successful implementation?
An enterprise's current business continuity plan (BCP) fails to consider many common crisis events. What would be MOST helpful to address this situation?
Which of the following is the BEST indication that an implementation plan for a new governance initiative will be successful?
A chief technology officer (CTO) wants to ensure IT governance practices adequately address risk management specific to mobile applications. To create the appropriate risk policies for IT, it is MOST important for the CTO to:
A CIO must determine if IT staff have adequate skills to deliver on key strategic objectives. Which of the following will provide the MOST useful information?
A newly appointed CIO is concerned that IT is too reactive and wants to ensure IT adds value to the enterprise by proactively anticipating business needs. Which of the following will BEST contribute to meeting this objective?
An internal auditor conducts an assessment of a two-year-old IT risk management program. Which of the following findings should be of MOST concern to the CIO?
Forensic analysis revealed an attempted breach of a personnel database containing sensitive data. A subsequent investigation found that no one within the enterprise was aware of the breach attempt, even though logs recorded the unauthorized access actions. To prevent a similar situation in the future, what is MOST important for IT governance to require?
Which of the following is the FIRST step when developing an IT risk management framework?
A new regulation requires enterprises to disclose when significant cyber incidents occur. Which of the following is MOST important for the enterprise to determine?
Which of the following is the BEST critical success factor (CSF) to use when changing an IT value management program in an enterprise?
Which of the following aspects of the transition from X-rays to digital images would be BEST addressed by implementing information security policy and procedures?
An enterprise is developing several consumer-based services using emerging technologies involving sensitive personal data. The CIO is under pressure to ensure the enterprise is first to market, but security scan results have not been adequately addressed. Reviewing which of the following will enable the CIO to make the BEST decision for the customers?
Which of the following is MOST important to have in place to ensure a business continuity plan (BCP) can be executed?
Which of the following roles has PRIMARY accountability for the security related to data assets?
An ongoing project is on track according to project plan. However, a recent regulation change will have a major impact to the project. The project sponsor's NEXT step should be to:
Which of the following is MOST likely to have a negative impact on
accountability for information risk ownership?
When a shortfall of IT resources is identified, the FIRST course of action is to;
Of the following, who is responsible for the achievement of IT strategic objectives?
When reporting key risk indicators (KRIs) to the board, what information BEST enables risk-based decision-making?
An enterprise has an ongoing issue of corporate applications not delivering the expected benefits due to missing key functionality. As a result, many groups are using spreadsheets and databases instead of approved enterprise applications to store and manipulate information. Which of the following will BEST improve the success rate of future IT initiatives?
An enterprise’s IT department has been operating independently without regard to business concerns, leading to misalignment between business and IT. The BEST way to establish alignment would be to require:
Which of the following provides the STRONGEST indication that IT governance is well established within an organizational culture?
An enterprise is required to implement several regulatory requirements. Which of the following functions is BEST suited to determine compliance priorities?
An enterprise is assessing whether to utilize wearable technology. The enterprise has no prior experience with this technology and has asked the chief technology officer (CTO) to assess the impact to the enterprise. The CTO should FIRST:
An enterprise has made the strategic decision to begin a global expansion program which will require opening sales offices in countries across the world. Which of the following should be the FIRST consideration with regard to the IT service desk which will remain centralized?
The effect of regional differences On service delivery
Identification of IT service desk functions that can be outsourced
Which of the following is the BEST way to address the risk associated with new IT investments?
An enterprise is concerned about the community impact of its data center noise levels. Which of the following is the enterprise’s BEST course of action?
Which of the following is the MOST important reason that IT strategic planning processes need to be adequately documented and communicated?
When identifying improvements focused on the information asset life cycle, which of the following is CRITICAL for enabling data interoperability?
A small enterprise has just hired its first CIO, who has been tasked with making the IT department more efficient. What should be the CIO's NEXT step after identifying several new improvement initiatives?
An enterprise's service center is experiencing long delays in fulfilling! T service requests and very low customer satisfaction. The BEST way to determine if staff competency is the root cause of these performance problems is to compare required staff competencies with:
Which of the following is the GREATEST impact to an enterprise that has ineffective information architecture?
A large organization with branches across many countries is in the midst of an enterprise resource planning (ERP) transformation. The IT organization receives news that the branches in a country where the impact to the enterprise is to be greatest are being sold. What should be the NEXT step?
Which of the following is the BEST way to ensure new systems can be adequately supported once in production?
An enterprise plans to expand into new markets in countries lacking data privacy regulations, increasing risk exposure. Which of the following is the BEST course of action for the CIO?
Senior management wants to expand offshoring to include IT services as other types of business offshoring have already resulted in significant financial benefits for the enterprise. The CIO is currently midway through a successful five-year strategy that relies heavily on internal IT resources. What should the CIO do NEXT?
Which of the following would BEST help to improve an enterprise's ability to manage large IT investment projects?
Which of the following should be the MAIN reason for an enterprise to implement an IT risk management framework?
Which of the following is the MOST comprehensive method to report on overall IT performance to the board of directors?
An enterprise plans to implement a business intelligence (Bl) tool with data sources from various enterprise applications. Which of the following is the GREATEST challenge to implementation?
IT has launched new portfolio management policies and processes to improve the alignment of IT projects with enterprise goals. The latest audit report indicates that no improvement has been made due to confusion in the decision-making process. Which of the following is the BEST course of action for the CIO?
A board of directors is concerned that a major IT implementation has the potential to significantly disrupt enterprise operations. Which of the following would be MOST helpful in identifying the extent of the potential impact of the disruption?
An enterprise experiencing issues with data protection and least privilege is implementing enterprise-wide data encryption in response. Which of the following is the BEST approach to ensure all business units work toward remediating these issues?
Senior management is reviewing the results of a recent security incident with significant business impact. Which of the following findings should be of GREATEST concern?
A rail transport company has the worst on-time arrival record in the industry due to an antiquated IT system that controls scheduling. Despite employee resistance, an initiative lo upgrade the technology and related processes has been approved. To maximize employee engagement throughout the project, which of the following should be in place prior to the start of the initiative?
An IT audit report indicates that a lack of IT employee risk awareness is creating serious security issues in application design and configuration. Which of the following would be the BEST key risk indicator (KRI) to show progress in IT employee behavior?
Which of the following is MOST important for an IT strategy committee to ensure before initiating the development of an IT strategic plan?
Which of the following should be done FIRST when designing an IT balanced scorecard?
What should be an IT steering committee's FIRST course of action when an enterprise is considering establishing a virtual reality store to sell its products?
When establishing a risk management process which of the following should be the FIRST step?
Of the following, who should be responsible for ensuring the regular review of quality management performance against defined quality metrics?
An enterprise has decided to implement an enterprise resource planning (ERP) system to achieve operating and cost efficiencies through global IT standardization. The business units are resistant because they are used to operating autonomously. The CEO has instructed the CIO to move quickly with the implementation to force acceptance with business unit leaders. Which of the following should be the ClO's FIRST step?
Which of the following should be the PRIMARY goal of implementing an IT strategic planning process?
Which of the following should be the PRIMARY basis for establishing categories within an information classification scheme?
An enterprise has lost an unencrypted backup tape of archived customer data. A data breach report is not mandatory in the relevant jurisdiction. From an ethical standpoint, what should the enterprise do NEXT?
Which of the following should be the MOST important consideration for a hospital planning to use cloud services and mobile applications?
An IT steering committee has received a report that supports the economic and service benefits of moving infrastructure hosting to an external cloud provider. Business leadership is very concerned about the security risk and potential loss of customer data. What is the BEST way for the committee to address these concerns?
Following a re-prioritization of business objectives by management, which of the following should be performed FIRST to allocate resources to IT processes?
Which of the following roles should be responsible for data normalization when it is found that a new system includes duplicates of data items?
An enterprise is trying to increase the maturity of its IT process from being ad hoc to being repeatable. Which of the following is the PRIMARY benefit of this change?
During an IT strategy review, a new CIO determined that numerous important internal processes have not been updated for several years and should be reexamined. Which of the following would be the BEST approach to address this concern?
An IT steering committee is presented with an audit finding that new software applications are delivered on time but consistently have unacceptable levels of defects. Which of the following would be the BEST direction from the committee?
Which of the following would be the BEST way to facilitate the adoption of strong IT governance practices throughout a multi-divisional enterprise?
An IT steering committee wants the enterprise's mobile workforce to use cloud-based file storage to save non-sensitive corporate data, removing the need for remote access to that information. Before this change is implemented, what should be included in the data management policy?
Which of the following is the MOST important benefit of developing an information architecture model consistent with enterprise strategy?
A recent benchmarking analysis has indicated an IT organization is retaining more data and spending significantly more on data retention than its competitors. Which of the following would BEST ensure the optimization of retention costs?
An enterprise has identified potential environmental disasters that could occur in the area where its data center is located. Which of the following should be done NEXT?
Which of the following is MOST important when an IT-enabled business initiative involves multiple business functions?
A healthcare enterprise that is subject to strict compliance requirements has decided to outsource several key IT services to third-party providers. Which of the following would be the BEST way to assess compliance and avoid reputational damage?
The CEO of a large enterprise has announced me commencement of a major business expansion that will double the size of the organization. IT will need to support the expected demand expansion. What should the CIO do FIRST?
The MOST important aspect of an IT governance framework to ensure that IT supports repeatable business processes is:
In a large enterprise, which of the following is the MOST effective way to understand the business activities associated with the enterprise's information architecture?
Which of the following would be the BEST way to facilitate the successful adoption of a new technology across the enterprise?
What is the BEST criterion for prioritizing IT risk remediation when resource requirements are equal?
Which of the following would be MOST helpful to an enterprise that wants to standardize how sensitive corporate data is handled?
An enterprise is determining the objectives for an IT training improvement initiative from a governance prosected. it would be MOST important to ensure that:
The MOST effective way to ensure that IT supports the agile needs of an enterprise is to:
Which of the following IT governance actions would be the BEST way to minimize the likelihood of IT failures jeopardizing the corporate value of an IT-dependent organization?
Which of the following is the BEST way to maximize the value of an enterprise’s information asset base?
Following a strategic planning session, new IT objectives were announced. Which of the following is the MOST effective way for the CIO to ensure these objectives are cascaded to IT personnel?
Reviewing which of the following should be the FIRST step when evaluating the possibility of outsourcing an IT system?
The PRIMARY objective of promoting business ethics within the IT enterprise should be to ensure:
An IT steering committee is evaluating whether a third-party supplier is delivering the correct level of service Reviewing which of the following will provide the BEST information to the committee?
An enterprise has decided to execute a risk self-assessment to identify improvement opportunities for current IT services. Which of the following is MOST important to address in the assessment?
An enterprise is about to complete a major acquisition, and a decision has been made that both companies will be using the parent company's IT infrastructure. Which of the following should be done NEXT?
Which of the following would BEST help a CIO enhance the competencies of an IT business analytics team?
The BEST way to decide how to prioritize issues identified in an IT risk and control self-assessment (CSA) is to understand the risk and:
Which of the following is a PRIMARY responsibility of the CIO when an enterprise plans to replace its enterprise resource applications?
Which of the following is the BEST indication that information security requirements are taken into consideration when developing IT processes?
Which of the following BEST supports an enterprise's ability to comply with privacy laws and regulations?
Which of the following should be the PRIMARY governance objective for selecting key risk indicators (KRIs) related to legal and regulatory compliance?
Which of the following is the MOST important consideration when developing a new IT service'?
Which of the following is MOST important to consider when planning to implement a cloud-based application for sharing documents with internal and external parties?
An IT strategy committee has reviewed an audit report indicating sales employees are using personal smartphones to conduct corporate business. Although the committee appreciates the business benefits, it is also concerned with the security risk. To deliver the business benefit, what should be the committee's FIRST recommendation?
When developing an IT training plan, which of the following is the BEST way to ensure that resource skills requirements are identified?
Which of the following is MOST important for IT governance to have in place to ensure the enterprise can maintain operations during extensive system downtime?
The MAIN responsibility of the board of directors regarding the management of enterprise risk is to:
Facing financial struggles, a CEO mandated severe budget cuts. A decision was also made to immediately change the enterprise strategic focus to put more reliance on mobile, cloud, and wireless services in an effort to boost revenue. The IT steering committee has asked the CIO tosuggest adjustments to the current IT project portfolio to allow support for the new direction despite fewer funds. What should the CIO advise the committee to do FIRST?
An enterprise's global IT program management office (PMO) has recently discovered that several IT projects are being run within a specific region without knowledge of the PMO. The projects are on time, on budget, and will deliver the proposed benefits to the specific region. Which of the following should be the PRIMARY concern of the PMO?
A data governance strategy has been defined by the IT strategy committee which includes privacy objectives related to access controls, authorized use. and data collection. Which of the following should the committee do NEXT?
What is the BEST way for an IT governance board to establish standards of behavior for the adoption of artificial intelligence (Al)?
Which of the following would a CIO use to present the overall view of IT performance to the board of directors?
After shifting from lease to purchase of IT infrastructure and software licenses, an enterprise has to pay for unexpected lease extensions causing significant cost overruns. The BEST direction for the IT steering committee would be to establish;
A project sponsor has circumvented the request for proposal (RFP) selection process. Which of the following is the MOST likely reason for this control gap?
When evaluating the process for acquiring third-party IT resources, management identified several suppliers with repeated downtime issues impacting the enterprise. Which of the following is the BEST approach to help ensure future service delivery in accordance with business objectives?
Which of the following should senior management do FIRST when developing and managing digital applications for a new enterprise?
Which of the following would be MOST useful for prioritizing IT improvement initiatives to achieve desired business outcomes?
Which of the following is the BEST indication that enterprise value is being derived from IT?
Which of the following is the BEST way to implement effective IT risk management?
A root-cause analysis indicates a major service disruption due to a lack of competency of newly hired IT system administrators. Who should be accountable for resolving the situation?
Which of the following is the GREATEST benefit of using a quantitative risk assessment method?
Which of the following IT governance practices would BEST support IT and enterprise strategic alignment?
An enterprise's decision to move to a virtualized architecture will have the GREATEST impact on:
The CIO of a large enterprise has taken the necessary steps to align IT objectives with business objectives. What is the BEST way for the CIO to ensure these objectives are delivered effectively by IT staff?
Which of the following would be the BEST way for an IT steering committee to monitor the adoption of a new enterprise IT strategy?
Which of the following is MOST important for an enterprise to review when classifying information assets?
An internal audit revealed a widespread perception that the enterprise's IT governance reporting lacks transparency Which of the following should the CIO do FIRST?
Which of the following is MOST important to document for a business ethics program?
Which of the following should a new CIO do FIRST to ensure information assets are effectively governed?
An enterprise has developed a new digital strategy to improve fraud detection. Which of the following is MOST important to consider when updating the information architecture?
To enable IT to deliver adequate services and maintain availability of a web-facing infrastructure, an IT governance committee should FIRST establish:
An enterprise-wide strategic plan has been approved by the board of directors. Which of the following would BEST support the planning of IT investments required for the enterprise?
A large enterprise has been experiencing high turnover of skilled IT personnel, resulting in a significant loss of knowledge within the IT department. Which of the following is the BEST governance action to address this concern?
Which of the following is MOST important to review during IT strategy development?
Which of the following is the BEST way to ensure the continued usefulness of IT governance reports for stakeholders?
The BEST way to manage continuous improvement of governance-related processes is to:
Which of the following are PRIMARY factors in ensuring the success of an enterprise quality assurance program?
Before an IT strategy committee can approve an IT risk assessment framework, which of the following is MOST important to have established?
What is the PRIMARY objective for performing an IT due diligence review prior to the acquisition of a competitor?
As the required core competencies of the IT workforce are anticipated and identified, what is the NEXT step in strengthening the department's human resource assets?
To reduce the risk of reputational damage through inappropriate use of social media by employees outside of the workplace, the enterprise approach regarding social media should PRIMARILY focus on;
A strategic systems project was implemented several months ago. Which of the following is the BEST reference for the IT steering committee as they evaluate its level of success?
Which of the following BEST reflects mature risk management in an enterprise?
Which of the following responsibilities should be retained within an enterprise when outsourcing a project management office (PMO) function?
Which of the following is the PRIMARY benefit of communicating the IT strategy across the enterprise?
An enterprise has a zero-tolerance policy regarding security. This policy is causing a large number of email attachments to be blocked and is a disruption to enterprise. Which of the following should be the FIRST governance step to address this email issue?
An enterprise's information security function is making changes to its data retention and backup policies. Which of the following presents the GREATEST risk?
Which of the following is the PRIMARY benefit to an enterprise when risk management is practiced effectively throughout the organization?
Which of the following is the BEST method for making a strategic decision to invest in cloud services?
An enterprise is initiating efforts to improve system availability to mitigate IT risk to the business. Which of the following results would be MOST important to report to the CIO to measure progress?
Which of the following is the BEST method to monitor IT governance effectiveness?
A large financial institution is considering outsourcing customer call center operations which will allow the chosen vendor to access systems from offshore locations. Which of the following represents the GREATEST risk?
An enterprise has had the same IT governance framework in place for several years. Currently, large and small capital projects go through the same architectural governance reviews. Despite repeated requests to streamline the review process for small capital projects, business units have received no response from IT. The business units have recently escalated this issue to the newly appointed GO. Which of the following should be done FIRST to begin addressing business needs?
When determining the optimal IT service levels to support business, which of the following is MOST important?
When developing effective metrics for the measurement of solution delivery, it is MOST important to:
A strategic IT-enabled investment is failing due to unforeseen technology problems. What should be the board of directors' FIRST course of action?
An IT strategy committee wants to ensure that a risk program is successfully implemented throughout the enterprise. Which of the following would BEST support this goal?
A board of directors wants to ensure the enterprise is responsive to changes in its environment that would directly impact critical business processes. Which of the following will BEST facilitate meeting this objective?
Which of the following is the PRIMARY ongoing responsibility of the IT governance function related to risk?
A retail enterprise has cost reduction as its top priority. From a governance perspective, which of the following should be the MOST important consideration when evaluating different IT investment options?
An enterprise has decided to use third-party software for a business process which is hosted and supported by the same third party. The BEST way to provide quality of service oversight would be to establish a process:
A newly established IT steering committee is concerned about whether a system is meeting availability objectives. Which of the following will provide the BEST information to make an assessment?
The CIO of an enterprise learns the payroll server of a competitor has been the victim of ransomware. To help plan for the possibility of ransomed corporate data, what should be the ClO's FIRST course of action?
Which of the following MUST be established before implementing an information architecture that restricts access to data based on sensitivity?