Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISACA logo

Certified in the Governance of Enterprise IT

Domain 4Objective 1

Risk Frameworks and Standards CGEIT Practice Questions (Page 1)

Part of the Risk Optimization domain, which accounts for 19% of the CGEIT exam.

23questions here
5free pages
5concepts
19%of the exam

Questions 1–5

  1. 1foundation · easy

    An organization using NIST RMF has categorized its information system and selected the appropriate security controls. What is the next step in the RMF process?

    Select an answer first
  2. 2foundation · easy

    When selecting a risk framework, which factor is most important to consider to ensure the framework aligns with the organization's objectives?

    Select an answer first
  3. 3application · medium

    A company is required by its industry regulator to implement a risk management framework that includes internal control over financial reporting. The company also wants to improve its IT governance. Which combination of frameworks should the company adopt?

    Select an answer first
  4. 4expert · hard

    A large manufacturing company has separate risk functions: the enterprise risk team uses COSO ERM for strategic risks, and the IT security team uses NIST RMF for system-level security. The board is concerned about duplication of effort and inconsistent risk reporting. What is the most effective integration approach?

    Select an answer first
  5. 5foundation · easy

    Which risk management framework is known for its principles-based approach and provides generic guidelines that can be applied to any type of organization, regardless of size or sector?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CGEIT” is a trademark of its owner, used for identification only.