
Certified in the Governance of Enterprise IT
Domain 4Objective 1
Risk Frameworks and Standards CGEIT Practice Questions (Page 2)
Part of the Risk Optimization domain, which accounts for 19% of the CGEIT exam.
23questions here
5free pages
5concepts
19%of the exam
Questions 6–10
- 6
A financial services firm is required by its national regulator to implement a risk management framework that aligns with the Basel Committee's operational risk principles. The firm also wants to certify its information security management system to ISO/IEC 27001. Which approach best satisfies both requirements?
Select an answer first - 7
A company's IT risk team uses ISO/IEC 27005 for risk assessments, while the enterprise risk team uses COSO ERM. The board wants to see IT risks in the context of enterprise risks. What is the most effective way to achieve this?
Select an answer first - 8
How does an enterprise risk management framework, such as COSO ERM, typically integrate with IT governance?
Select an answer first - 9
Which standard provides guidelines for information security risk management and is closely aligned with the ISO/IEC 27000 family of standards?
Select an answer first - 10
Which risk management framework is specifically designed for federal agencies in the United States and emphasizes a structured, six-step process for integrating security and privacy risk management into the system development lifecycle?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CGEIT” is a trademark of its owner, used for identification only.