Summer Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: exc65

An enterprise wishes to establish key risk indicators (KRIs) in an effort to better manage IT risk. Which of the following should be identified FIRST?

A.

Risk mitigation strategies

B.

Enterprise architecture (EA) components

C.

The enterprise risk appetite

D.

Key performance metrics

Which of the following metrics would provide senior management with the BEST indication of the success of IT investments?

A.

Number of IT investments tracked in the balanced scorecard

B.

Percentage of IT investments recorded in the enterprise architecture (EA)

C.

Number of IT investments impacted by business-related incidents

D.

Percentage of IT investments that meet expected benefits

An enterprise has made the strategic decision to reduce operating costs for the next year and is taking advantage of cost reductions offered by an external cloud service provider. Which of the following should be the IT steering committee's PRIMARY concern?

A.

Calculating the cost of the current solution

B.

Updating the business risk profile

C.

Changing the IT steering committee charter

D.

Revising the business's balanced scorecard

During an IT strategy review, a new CIO determined that numerous important internal processes have not been updated for several years and should be reexamined. Which of the following would be the BEST approach to address this concern?

A.

Implement a process review policy.

B.

Assemble a project review team

C.

Verify that the processes are still needed

D.

Map the processes to a capability maturity model.

Which of the following should be the MOST important consideration for a hospital planning to use cloud services and mobile applications?

A.

Privacy requirements

B.

Data classification

C.

Acceptable use policy

D.

Internet connectivity

Which of the following is the BEST way to implement effective IT risk management?

A.

Align with business risk management processes.

B.

Establish a risk management function.

C.

Minimize the number of IT risk management decision points.

D.

Adopt risk management processes.

An organization is evaluating vendors to provide mobile device management (MDM) services. Which of the following is a KEY governance consideration for the IT steering committee?

A.

Service level targets align with business requirements.

B.

Employee-owned devices will be covered by the service.

C.

The MDM services are delivered via a cloud.

D.

Technology-owned devices will be covered by the service

What is the BEST criterion for prioritizing IT risk remediation when resource requirements are equal?

A.

Deviation from IT standards

B.

IT strategy alignment

C.

IT audit recommendations

D.

Impact on business

An enterprise has identified a number of plausible risk scenarios that could result in economic loss associated with major IT investments. Which of the following is the BEST method to assess the risk?

A.

Cost-benefit analysis

B.

Qualitative analysis

C.

Business impact analysis (BIA)

D.

Quantitative analysis

Which of the following IT governance actions would be the BEST way to minimize the likelihood of IT failures jeopardizing the corporate value of an IT-dependent organization?

A.

Implement an IT risk management framework.

B.

Install an IT continuous monitoring solution.

C.

Define IT performance management measures.

D.

Benchmark IT strategy against industry peers.

IT senior management is concerned that IT service levels consistently fall below those outlined in the service level agreement (SLA). Which of the following would BEST enable the CIO to build a corrective action plan?

A.

Assessing the impact of the SLA failure

B.

Conducting an IT performance evaluation

C.

Reviewing the IT staff training plan

D.

Performing a root cause analysis

Which of the following is the BEST way to ensure all enterprise employees understand the corporate code of business conduct?

A.

Conduct scheduled and random compliance audits.

B.

Mandate annual ethics training that includes an exam.

C.

Require external business activities be documented and reported.

D.

Distribute a copy of the code and require a signature.

An enterprise's chief information officer (CIO) has been receiving complaints from business executives regarding the amount their units are being charged for IT services. To maintain a good relationship with business peers, the CIO wants to be responsive to these complaints. To address this issue, the FIRST step should be to:

A.

agree to reduce charge rates and improve relationship management with the business.

B.

look into outsourcing of support functions to drive down the cost structure.

C.

ask the chief financial officer (CFO) about budget revisions for the business units' IT expenditures.

D.

quantify consumption and service level agreement (SLA) achievements per business unit.

To evaluate IT resource management, it is MOST important to define:

A.

responsibilities for executing resource management.

B.

applicable key goals.

C.

principles for the IT strategy.

D.

IT resource utilization reporting procedures.

When developing an IT governance framework, it is MOST important for an enterprise to consider:

A.

information technology risk.

B.

framework development cost.

C.

information technology strategy.

D.

stakeholders' support.