
Certified in the Governance of Enterprise IT
Domain 4Objective 1
Risk Frameworks and Standards CGEIT Practice Questions (Page 4)
Part of the Risk Optimization domain, which accounts for 19% of the CGEIT exam.
23questions here
5free pages
5concepts
19%of the exam
Questions 16–20
- 16
An organization that must comply with U.S. federal cybersecurity requirements is selecting a risk framework. Which framework would be most appropriate for this regulatory context?
Select an answer first - 17
A company is using ISO/IEC 27005 to manage risks to its customer database. After identifying a risk of unauthorized access, what is the next step in the risk management process?
Select an answer first - 18
What is the primary role of ISO/IEC 27005 in an organization's IT risk management process?
Select an answer first - 19
A large enterprise has a mature IT governance structure based on COBIT and wants to integrate risk management more formally. The board wants to ensure that IT risks are considered in strategic decision-making. Which approach best integrates risk management with IT governance?
Select an answer first - 20
A non-profit organization wants to implement a risk management framework that is simple, cost-effective, and focuses on mission-critical risks. The organization does not have a dedicated IT risk team. Which framework is most appropriate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CGEIT” is a trademark of its owner, used for identification only.