Q: 11
Which of the following BEST helps to ensure that IT standards will be consistently applied across the
enterprise?
Options
Discussion
Its B, not A. Board should care about risk alignment too, seems like a common trap.
A for sure, pretty standard from the official guide and past practice questions.
Be respectful. No spam.
Q: 12
Which of the following should be the FIRST step to ensure IT resources have the appropriate skills
and experience level to support enterprise objectives?
Options
Discussion
B tbh, once threats are identified you need to figure out how likely they are and what kind of damage they could cause. That's the basis of risk assessment before you jump to controls or relocation. Pretty standard process. If someone thinks differently, let me know.
Be respectful. No spam.
Q: 13
The BEST way for a CIO to manage the organizational impact of deploying a new enterprise-wide tool
is to implement:
Options
Discussion
A
Be respectful. No spam.
Q: 14
The GREATEST benefit associated with a decision to implement performance metrics for key IT assets
is the ability to:
Options
Discussion
Probably C for this one. Balanced scorecard measures IT performance against business strategy and goals, so it directly shows alignment (or lack of it). Option A is more about IT process maturity and D just covers spending, which can be a trap. Not 100% sure but I think BSC fits what the CIO needs to see. Disagree?
Not B, C. Seen similar in the official guide and the balanced scorecard is always highlighted for linking IT and business strategy.
Be respectful. No spam.
Q: 15
Which of the following should be the PRIMARY consideration when implementing IT governance in a
small, newly established organization?
Options
Discussion
Wouldn't KPIs (D) be enough for the board? Balanced scorecard always feels too broad for just IT performance.
Always with these buzzword questions... Probably A since the balanced scorecard is what execs like for high-level IT performance.
Be respectful. No spam.
Q: 16
Which of the following would be MOST helpful to an enterprise that wants to standardize how
sensitive corporate data is handled?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 17
Within a governance structure for risk management, which of the following activities should be
performed by the second line of defense?
Options
Discussion
Pretty sure it's D. Contract monitoring means you’re actually checking if suppliers are meeting the agreed SLAs, which targets the downtime issue. Still not 100% sure, anyone else ran into similar questions?
Be respectful. No spam.
Q: 18
The board of an organization has been informed of possible cyberthreats. Which of the following
should be the board’s NEXT course of action?
Options
Discussion
D . The board shouldn't jump right into evaluating controls or reassessing risk tolerance without first having a proper assessment of the actual risk at hand. It's not their job to do the analysis themselves, but to delegate that to the CIO or equivalent so they get an informed picture before making any policy or appetite decisions. If there was already a confirmed incident, A might be closer, but here it's just potential threats. Anyone disagree?
Man, ISACA loves the vision statement questions. A imo, always pops up in these practice sets.
Be respectful. No spam.
Q: 19
Which of the following provides the BEST evidence of effective IT governance?
Options
Discussion
Not A, B. Info retention policies are what actually set the rules for how long data can stay in production, especially with new privacy laws.
Be respectful. No spam.
Q: 20
An analysis of an organization s security breach is complete. The results indicate that the quality of
the code used for updates to its primary customer-facing software has been declining and security
flaws were introduced. The FIRST IT governance action to correct this problem should be to review:
Options
Discussion
Its D. Not totally sure but policy comes before training or budgets right?
Be respectful. No spam.
Question 11 of 20 · Page 2 / 2