
Certified in the Governance of Enterprise IT
Domain 1Objective 3
Compliance, Ethics, and Culture CGEIT Practice Questions (Page 5)
Part of the Governance of Enterprise IT domain, which accounts for 40% of the CGEIT exam.
37questions here
8free pages
9concepts
40%of the exam
Questions 21–25
- 21
A financial services firm has a culture where employees often bypass IT security controls to meet sales targets. The board has asked the IT governance team to foster a culture that supports compliance. Which strategy is most effective for cultural change?
Select an answer first - 22
A global e-commerce company stores customer data in multiple regions. The company is subject to GDPR and must ensure that personal data of EU residents is protected. Which action is a direct obligation under GDPR?
Select an answer first - 23
A multinational retail company processes customer payment data and must comply with PCI DSS. The IT governance team is designing a compliance risk assessment. Which action best aligns with PCI DSS requirements?
Select an answer first - 24
A nonprofit organization relies on donations and has a small IT budget. The IT director discovers that a donor's personal data was accidentally exposed in a data breach. The organization is not legally required to notify the donor, but the director believes it is the ethical thing to do. However, the board is concerned about reputational damage and legal liability. Which action best balances ethics and governance?
Select an answer first - 25
Which of the following best illustrates the integration of ethics into compliance and governance processes?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CGEIT” is a trademark of its owner, used for identification only.