
Certified in the Governance of Enterprise IT
Domain 4Objective 1
Risk Frameworks and Standards CGEIT Practice Questions (Page 3)
Part of the Risk Optimization domain, which accounts for 19% of the CGEIT exam.
23questions here
5free pages
5concepts
19%of the exam
Questions 11–15
- 11
What is a key benefit of integrating a risk framework with the overall enterprise governance structure?
Select an answer first - 12
A multinational bank must comply with the EU General Data Protection Regulation (GDPR) and the Basel Committee's operational risk capital requirements. The board wants a single enterprise-wide risk language that also satisfies external auditors' expectations for a control-based framework. Which framework combination should the CGEIT advise the bank to adopt?
Select an answer first - 13
A healthcare provider is implementing a risk management program and must comply with HIPAA security rules. The CISO wants a framework that provides a structured, step-by-step process for categorizing systems, selecting controls, and authorizing systems to operate. Which framework should the CISO select?
Select an answer first - 14
A publicly traded company must comply with the Sarbanes-Oxley Act (SOX) for financial reporting controls and also wants to improve its IT risk management. The CFO prefers a framework that integrates internal control over financial reporting with IT risk. Which framework should the company adopt?
Select an answer first - 15
A company's IT department uses NIST RMF for system security, but the enterprise risk team uses COSO ERM. The CEO wants a single risk appetite statement that applies to both IT and enterprise risks. What is the best way to achieve this?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CGEIT” is a trademark of its owner, used for identification only.