
お手軽CGEIT問題集PDFのベスト問題集を使おう!高得点目指すならここ
Isaca Certificaton CGEIT試験と認定テストエンジン
CGEIT認定試験の資格を得るには、候補者は、試験でカバーされている5つのドメインのうち少なくとも2つの経験を含め、ITガバナンスの分野で少なくとも5年の経験が必要です。さらに、候補者はISACA専門倫理コードを遵守し、CGEIT試験に成功裏に合格する必要があります。全体として、CGEIT認定は、ITガバナンスの専門知識を実証し、分野でのキャリアを促進しようとしているITの専門家にとって貴重な資格です。
質問 # 266
During the implementation phase of a central ERP system, a project manager identifies a significant lack of human capabilities to support the system. The issue is reported to the project sponsor, and the sponsor sends a request for an increase in the budget to the IT steering committee. What should be the IT steering committee's FIRST action?
- A. Provide appropriate training.
- B. Refer back to the project sponsor for resolution.
- C. Approve the budget request.
- D. Require a revised business case.
正解:C
質問 # 267
A newly appointed CIO has issued a new IT strategic plan. Which of the following is the MOST effective way for the CIO to ensure the IT management team is held accountable for the delivery of the plan?
- A. Enforce disciplinary action for managers if the plan is not delivered.
- B. Revise the managers' performance goals to include key objectives.
- C. Update the IT balanced scorecard with key objectives.
正解:C
質問 # 268
Which of the following should be the MAIN governance focus when implementing a newly approved bring your own device (BYOD) policy?
- A. Educating employees on the increased IT security risk to the enterprise
- B. Recommending mobile applications that will increase business productivity
- C. Understanding knowledge gaps of IT employees to support different mobile platforms
- D. Training employees on the enterprise's chosen mobile device management system
正解:A
解説:
The main governance focus when implementing a newly approved BYOD policy is to educate employees on the increased IT security risk to the enterprise. BYOD introduces various challenges and threats to the enterprise's data and network security, such as device loss or theft, unauthorized access, malware infection, data leakage, and compliance violations. Therefore, it is essential to raise the awareness and understanding of employees on the potential risks and their responsibilities in protecting the enterprise's assets and information. Educating employees on the IT security risk can also help to foster a culture of security and compliance, and to promote best practices for BYOD usage, such as following the acceptable use policy, installing security software, and reporting incidents. Reference:= The Ultimate Guide to BYOD Security: Definition & More - Digital Guardian; Enterprise mobility and security: How to build a BYOD policy; Bring Your Own Device for Executives | Cyber.gov.au
質問 # 269
Which of the following is a way of delivering value to customers by facilitating outcome that customers wish to get without the control of specific costs and risks?
- A. Processes
- B. Service Desk
- C. Service
- D. Functions
正解:C
解説:
Section: Volume B
質問 # 270
Which of the following components of a policy BEST enables the governance of enterprise IT?
- A. Disciplinary actions
- B. Regulatory requirements
- C. Terms and definitions
- D. Roles and responsibilities
正解:D
解説:
A policy is a document that defines the rules and guidelines for how an organization conducts its activities and operations. A policy can help to ensure the compliance, consistency, and quality of the organization's performance and outcomes1. A policy typically consists of several components, such as purpose, scope, terms and definitions, roles and responsibilities, procedures, compliance, and review2.
From a governance perspective, one of the most important components of a policy is roles and responsibilities, because it clarifies who is accountable and responsible for implementing, enforcing, monitoring, and improving the policy. Roles and responsibilities can help to establish the authority, accountability, and communication among different stakeholders involved in the policy, such as the board of directors, senior management, business units, IT staff, customers, regulators, etc. Roles and responsibilities can also help to avoid confusion, duplication, or conflict of work among the stakeholders3 .
The governance of enterprise IT (GEIT) is the system by which the current and future use of IT is directed and controlled by an organization. GEIT aims to ensure that IT supports the organization's strategy and objectives, delivers value and benefits, manages risks and resources, and measures performance and outcomes. GEIT requires a clear definition of roles and responsibilities for the IT governance policies, processes, structures, and relationships. Some of the common roles and responsibilities involved in GEIT are:
The board of directors: provides strategic direction, oversight, and approval for IT governance The senior management: provides leadership, support, and guidance for IT governance The business units: provide input, feedback, and collaboration for IT governance The IT function: provides execution, delivery, and improvement for IT governance The audit function: provides assurance, evaluation, and recommendation for IT governance The external stakeholders: provide requirements, expectations, and compliance for IT governance References: What is a Policy? Definition & Examples. Policy Components: Definition & Examples. Roles & Responsibilities in Policy Development. [Policy Development: Roles & Responsibilities]. [What is IT Governance? Definition & Frameworks]. [IT Governance Roles & Responsibilities]. [Roles & Responsibilities in IT Governance].
質問 # 271
John is the project manager of the NHQ Project for his company. His project has 75 stakeholders, some of which are external to the organization. John needs to make certain that he communicates about risk in the most appropriate method for the external stakeholders. Which project management plan will be the best guide for John to communicate to the external stakeholders?
- A. Risk Management Plan
- B. Communications Management Plan
- C. Project Management Plan
- D. Risk Response Plan
正解:B
質問 # 272
The CIO of a financial and insurance company is considering the projects and portfolio for the coming year Which of the following projects is a non-discretionary project?
- A. Data center relocation
- B. Compliance with statutory regulations
正解:B
解説:
C. Actuarial application system analysis and design
D. Core banking applications scalability assessment
Explanation:
According to the web search results, projects where management has a choice in implementing them are called discretionary projects. Projects where no choice exists are called nondiscretionary projects1. Compliance with statutory regulations is a nondiscretionary project, as it is required by law and cannot be avoided or postponed. The other options are discretionary projects, as they are based on the management's decision and preference, and can be prioritized or delayed according to the business needs and goals. Reference: CGEIT Certification, CIO Dashboard, Answers
質問 # 273
The board of directors of a major retail chain wants to know what capabilities are in place to prevent customer credit card data from being hacked. Which of the following should be established to provide useful information about a potential future event?
- A. Risk tolerance
- B. Lead indicators
- C. Performance indicators
- D. Lag indicators
正解:B
質問 # 274
Communicating which of the following to staff BEST demonstrates senior management's commitment to IT governance?
- A. Objectives and responsibilities
- B. Approved IT investment opportunities
- C. Need for enterprise architecture (EA)
- D. Legal and regulatory requirements
正解:A
解説:
Communicating the objectives and responsibilities to staff is the BEST way to demonstrate senior management's commitment to IT governance. IT governance is the process of ensuring that IT supports the achievement of the organization's goals and objectives, and delivers value to its stakeholders1. IT governance involves aligning the IT strategy, policies, processes, and resources with the business strategy, needs, and expectations2. However, implementing and sustaining IT governance requires a significant amount of change in the organization, such as introducing new technologies, standards, roles, and responsibilities3. Therefore, communicating the objectives and responsibilities to staff is essential for demonstrating senior management's commitment to IT governance, as it can:
* Provide the direction and mandate for the IT governance initiative on an ongoing basis
* Communicate the vision, mission, goals, and objectives of the IT function to all stakeholders
* Allocate the necessary resources and capabilities to enable the IT governance processes and activities
* Monitor and evaluate the performance and outcomes of the IT function and provide feedback and recognition
* Foster a positive and collaborative culture that values IT as a strategic partner and enabler of the business The other options are not as good as option C. While it is important to communicate the legal and regulatory requirements, the approved IT investment opportunities, and the need for enterprise architecture (EA), these are not sufficient to demonstrate senior management's commitment to IT governance. They are rather means to achieve the end goal of implementing and sustaining IT governance. They do not necessarily reflect the level of commitment, involvement, and support from the management toward IT governance. References :=
* What is IT Governance? Definition & Examples | ASQ2
* What is IT governance? A formal way to align IT & business strategy1
* How to Involve Senior Management in the Information Security Governance ...3
質問 # 275
Which of the following processes contained in the Portfolio Management domain of Val
IT creates an overall portfolio view?
- A. PM8
- B. PM10
- C. PM7
- D. PM9
正解:D
質問 # 276
Which of the following is the BEST way for a CIO to provide senior business management with increased visibility to the overall performance of the IT operation?
- A. Provide service level agreement (SLA) performance statistics.
- B. Develop key risk indicators (KRIs).
- C. Provide return on investment (ROI) reports.
- D. Develop key performance indicators (KPIs).
正解:D
解説:
Comprehensive and Detailed Explanation:
The CGEIT Review Manual 8th Edition, in its Governance of Enterprise IT domain, highlights the need for IT performance reporting to ensure transparency with senior management. Key performance indicators (KPIs) provide a comprehensive view of IT operations, covering metrics like system availability, project delivery, and cost efficiency. KPIs align IT performance with business objectives, offering a holistic perspective. The manual likely references COBIT 2019's MEA01-Monitor, Evaluate, and Assess Performance, which emphasizes KPIs for performance visibility.
* Option A: KRIs focus on risks, not overall performance.
* Option B: ROI reports are financial and project-specific, not comprehensive.
* Option D: SLA performance statistics are narrow, focusing only on service delivery.
Double Verification: The answer aligns with COBIT's MEA01 and the CGEIT domain's focus on performance reporting. KPIs are the standard ISACA tool for IT performance visibility.
ISACA CGEIT Review Manual 8th Edition, Domain 1: Governance of Enterprise IT (focus on performance reporting).
COBIT 2019, MEA01-Monitor, Evaluate, and Assess Performance.
ISACA Glossary (for definitions of KPIs), available at https://www.isaca.org/resources/glossary.
質問 # 277
Which of the following frameworks describes a standard for processes within business information management at the strategy, management and operations level?
- A. BISL
- B. Val IT
- C. TOGAF
- D. COBIT
正解:A
解説:
Section: Volume A
Explanation/Reference:
質問 # 278
Which of the following aspects of IT governance BEST addresses the potential intellectual property implications of a cloud service provider having a database in another country?
- A. Contract management
- B. Data management
- C. Continuity planning
- D. Security architecture
正解:B
解説:
Data management is the aspect of IT governance that BEST addresses the potential intellectual property implications of a cloud service provider having a database in another country. Data management involves defining and implementing policies and processes for the effective and efficient acquisition, storage, distribution, usage, and disposal of data in alignment with business objectives and regulatory requirements1. Data management also includes ensuring the protection of data quality, integrity, availability, confidentiality, and ownership1. Therefore, data management can help mitigate the risks of intellectual property infringement, theft, or misuse that may arise from storing data in a foreign jurisdiction with different legal and regulatory frameworks23. References := CGEIT Review Manual (Digital Version), Chapter 4: Value Optimization, Section 4.2: IT Value Delivery, Subsection 4.2.3: IT Resource Management, Page 123 CGEIT Review Manual (Print Version), Chapter 4: Value Optimization, Section 4.2: IT Value Delivery, Subsection 4.2.3: IT Resource Management, Page 123 Cloud computing: A brief overview of intellectual property issues "in the cloud" - Lexology2 Protecting Intellectual Property in the Cloud - WIPO
質問 # 279
Which of the following components of the COSO ERM identifies the required information, captures it, and communicates it in a form and time frame that enable people to carry out their responsibilities?
- A. Objectives setting
- B. Internal environment
- C. Monitoring
- D. Information and communication
正解:D
質問 # 280
Which of the following is the BEST way to ensure new systems can be adequately supported once in production?
- A. Require operational management be identified in the business case.
- B. Establish a resource management framework.
- C. Identify key performance indicators (KPIs).
- D. Evaluate the operational requirements of the business stakeholders.
正解:A
解説:
The best way to ensure new systems can be adequately supported once in production is to require operational management be identified in the business case. This means that the business case should include the costs, benefits, risks and resources associated with the operation and maintenance of the new system, as well as the roles and responsibilities of the operational staff. By doing so, the business case can ensure that the new system is aligned with the business objectives and can deliver value to the stakeholders. Additionally, the business case can help to secure the commitment and support of the operational management for the new system. References := CGEIT Exam Content Outline, Domain 3: Benefits Realization1; COBIT 5: Enabling Processes, chapter 4, section 4.2.22; Building A Governance System: A Review of Information Flow and Items Component
質問 # 281
......
CGEIT試験を受験するためには、少なくとも1年間のITガバナンスフレームワークまたは標準の開発または実装を含む、ITガバナンスまたは管理の分野での5年間の経験が必要です。
Enterprise IT(CGEIT)認定試験の認定は、エンタープライズITのガバナンスと管理を担当するIT専門家向けに設計されています。この試験は、ITガバナンス、セキュリティ、および監査の専門家に、役割で成功するために必要な知識、スキル、ツールを提供するグローバルな組織であるISACA(情報システム監査および制御協会)によって開発および管理されています。 CGEIT認定は、ITガバナンス、リスク管理、コンプライアンスに関する候補者の専門知識を示しており、世界中の雇用主によって高く評価されています。
無料提供中のCGEIT試験問題集で(2025年最新のPDF問題集)信頼度の高いCGEITテストエンジン:https://jp.fast2test.com/CGEIT-premium-file.html
CGEITのPDFで最近更新された問題です集試験点数を伸ばそう:https://drive.google.com/open?id=1Szh7t8Lw-NH6huF_kraBtxj07v22aR5l