
Certified in the Governance of Enterprise IT
Domain 1Objective 3
Compliance, Ethics, and Culture CGEIT Practice Questions (Page 7)
Part of the Governance of Enterprise IT domain, which accounts for 40% of the CGEIT exam.
37questions here
8free pages
9concepts
40%of the exam
Questions 31–35
- 31
A healthcare organization's IT governance committee is evaluating a proposal to use de-identified patient data for a research project that could improve treatment outcomes. The data is technically de-identified under HIPAA, but the committee is concerned about the ethical implications of using data without explicit patient consent. Which decision-making approach best balances ethical and compliance considerations?
Select an answer first - 32
What is the purpose of using an ethical decision-making framework in IT governance?
Select an answer first - 33
What is the primary purpose of a compliance risk assessment in IT governance?
Select an answer first - 34
A technology company has a culture that rewards rapid feature delivery, often at the expense of documentation and security reviews. The IT governance team wants to improve compliance with internal security standards. Which approach is most likely to be effective?
Select an answer first - 35
A cloud service provider (CSP) offers infrastructure-as-a-service to healthcare clients. The CSP is not a covered entity under HIPAA, but its clients are. The CSP wants to support its clients' compliance. Which responsibility is most appropriate for the CSP to assume?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CGEIT” is a trademark of its owner, used for identification only.