
Certified in the Governance of Enterprise IT
Domain 4Objective 7
Risk Assessment Methods CGEIT Practice Questions (Page 6)
Part of the Risk Optimization domain, which accounts for 19% of the CGEIT exam.
30questions here
6free pages
8concepts
19%of the exam
Questions 26–30
- 26
A manufacturing company is assessing risks in its supply chain. They have detailed data on supplier performance and delivery times, but they also need to consider the reputational impact of a supply chain disruption. The risk team wants to produce a risk register that includes both financial and non-financial impacts. Which approach is most effective?
Select an answer first - 27
In the context of enterprise IT governance, what is the primary purpose of a risk assessment method within the broader risk optimization process?
Select an answer first - 28
An enterprise has detailed historical data on system failures and financial impacts, and decision-makers require a cost-benefit analysis of potential risk mitigation controls. Which risk assessment method is most appropriate?
Select an answer first - 29
After completing a quantitative risk assessment, the risk team has produced detailed ALE calculations for various IT assets. The board members are not familiar with ALE and prefer a clear, concise summary that supports decision-making. What is the most effective way to communicate the results?
Select an answer first - 30
In a hybrid risk assessment, which scenario best illustrates the combined use of qualitative and quantitative methods?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CGEIT
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CGEIT” is a trademark of its owner, used for identification only.