Try 12 free ISACA CGEIT practice questions
Real exam-style questions taken word for word from the ISACA CGEIT study guide. Three are below, with the full answer explanation. Enter your email and the full 12-question PDF is yours.
Unlock the full sampler
Three questions to try right now
Work each one before you open the answer. These are the same style and depth as the Certified in the Governance of Enterprise IT (CGEIT) exam expects.
Question 1. A board of directors is concerned that a major IT implementation has the potential to significantly disrupt enterprise operations. Which of the following would be MOST helpful in identifying the extent of the potential impact of the disruption?
- A. An analysis of the current enterprise risk appetite
- B. An earned value analysis (EVA) of the implementation
- C. A risk assessment of the implementation
- D. A review of lessons learned from previous implementations
Show the answer
Answer: C. A risk assessment directly evaluates the likelihood and magnitude of disruption from the specific implementation, providing the board with actionable data on potential impacts to operations, data, and stakeholders. The risk appetite statement tells the board what level of risk is acceptable but does not quantify the actual risk present. EVA measures project cost and schedule performance, not operational disruption. Lessons learned are useful inputs to planning but do not assess the specific impact of the current project.
- A: Risk appetite defines tolerance thresholds; it does not identify or measure the extent of potential impact.
- B: EVA tracks budget and schedule variance, not operational disruption risk.
- D: Historical lessons are a reference point, not an assessment of the current implementation's exposure.
Question 2. A large retail chain realizes that while there has not been any loss of data, IT security has not been a priority and should become a key goal for the enterprise. What should be the FIRST high-level initiative for a newly created IT strategy committee in order to support this business goal?
- A. Identifying gaps in information asset protection
- B. Defining data archiving and retrieval policies
- C. Recruiting and training qualified IT security staff
- D. Modernizing internal IT security practices
Show the answer
Answer: A. Before investing in people, processes, or technology, the committee must understand where current protections fall short relative to what the business requires. A gap analysis establishes the baseline and prioritizes where effort is needed most. Recruiting, training, and modernizing are all remediation actions that are premature without knowing the gaps they are intended to close. Archiving and retrieval policies address a narrow operational function, not the broad security posture.
- B: Archiving policy is a specific operational control, not a high-level strategic initiative to anchor a new security program.
- C: Staffing decisions should follow from understanding capability gaps, not precede them.
- D: Modernization is a solution category; without a gap analysis, the enterprise cannot determine which modernization steps are necessary.
Question 3. An IT director is negotiating a contract with a vendor for application management services. Other departments have raised concerns that the outsourced services may not be delivered successfully. Which of the following is the BEST way for the IT director to address this concern?
- A. Implement a communication management plan.
- B. Develop a comprehensive vendor management plan.
- C. Review the IT service risk management plan.
- D. Establish a policy on operational level agreements with vendors.
Show the answer
Answer: B. A vendor management plan is the governance artifact that defines how vendor performance will be monitored, how escalations will be handled, and how contractual obligations will be enforced throughout the engagement. It directly addresses the concern that services may not be delivered successfully by establishing the oversight structure before problems occur. A communication plan (A) supports the relationship but does not govern service delivery. Reviewing an existing risk plan (C) is reactive and does not establish new controls. Operational level agreements (D) are an output of a broader vendor management plan, not a substitute for one. ---
Unlock the full 12-question sampler
All 12 come with the same written explanations the book uses, covering why the right answer is right. We email you the PDF, nothing else.
What you get
The sampler is free. Here is exactly what lands in your inbox.
Print it or work it on screen, then score yourself against the answer key.
Nothing is written for marketing. Every question is lifted from the study guide itself.
A few days later we send one email with a code for the full study guide. That is the entire sequence.
The full ISACA CGEIT study guide
The complete guide covers the Certified in the Governance of Enterprise IT (CGEIT) exam objective by objective in plain English, with the full practice question bank behind these samples.
From $20.99
Simply Certified is an independent publisher. CGEIT is a trademark of ISACA, which does not sponsor or endorse this product. This page and the sampler are independent study material and are not affiliated with, endorsed by, or sponsored by ISACA.