View All CGEIT Actual Exam Questions Answers and Explanations for Free Sep-2025 [Q153-Q176]

Share

View All CGEIT Actual Exam Questions Answers and Explanations for Free Sep-2025

The Most In-Demand ISACA CGEIT Pass Guaranteed Quiz 


ISACA CGEIT certification provides numerous benefits to individuals and organizations. For individuals, the certification can help them enhance their career prospects and increase their earning potential. For organizations, the certification can help them ensure that their IT governance is aligned with their business objectives and that their IT systems are secure and effective.


ISACA CGEIT certification is a valuable certification for professionals who work in the field of IT governance. It provides the skills and knowledge required to effectively manage the governance of enterprise IT, and it is recognized globally as one of the most prestigious certifications in the IT industry. Certified in the Governance of Enterprise IT Exam certification provides numerous benefits to individuals and organizations, and it is a worthwhile investment for anyone looking to enhance their career in the field of IT governance.

 

NEW QUESTION # 153
The BEST way for a CIO to manage the organizational impact of deploying a new enterprise-wide tool is to implement:

  • A. resource management.
  • B. risk management.
  • C. change management.
  • D. project management.

Answer: B


NEW QUESTION # 154
An enterprise is about to complete a major acquisition, and a decision has been made that both companies will be using the parent company's IT infrastructure. Which of the following should be done NEXT?

  • A. Update the enterprise architecture (EA).
  • B. Conduct a gap analysis.
  • C. Develop a communication plan to support the merger.
  • D. Perform a business impact analysis (BIA.

Answer: B

Explanation:
A gap analysis is the process of comparing the current state and the desired state of an organization or a system, and identifying the gaps or differences between them1. A gap analysis can help to determine the actions and resources needed to bridge the gaps and achieve the desired outcomes2. In the context of an IT infrastructure integration after a major acquisition, a gap analysis can help to:
Assess the compatibility and interoperability of the IT systems, applications, data, and processes of both companies3 Identify the gaps, risks, issues, and opportunities related to the IT infrastructure integration4 Prioritize and plan the IT infrastructure integration activities and projects5 Align the IT infrastructure integration with the business goals and objectives of the acquisition Therefore, conducting a gap analysis should be done NEXT after deciding that both companies will be using the parent company's IT infrastructure.
The other options are not as important as option C. While it is important to update the enterprise architecture (EA), perform a business impact analysis (BIA), and develop a communication plan to support the merger, these are subsequent steps that can be done after conducting a gap analysis. A gap analysis can provide valuable inputs and insights for these steps, such as the current and target EA, the potential impacts of the IT infrastructure integration on the business operations and stakeholders, and the communication needs and channels for the IT infrastructure integration. Reference:= What is Gap Analysis? Definition, Methodology & Examples | ASQ1 Gap Analysis: How to Bridge the Gap Between Performance and ...2 How to Make a Successful IT Integration Strategy for Mergers and ...4 M&A: The Six Phases of IT Integration - Interlink Cloud Blog3 Post-Merger Integration: M&A Integration Process Guide - DealRoom5 Success Factors for Integrating IT Systems After a Merger | CIO


NEW QUESTION # 155
A business has outsourced IT operations to several third-party providers, but service level agreements (SLAs) are not clearly defined in all cases. Which of the following is the GREATEST risk to the business?

  • A. Costs are not measurable.
  • B. Third parties could provide overlapping services.
  • C. Quality of services is not enforceable.
  • D. The scope of work is not clearly defined.

Answer: C


NEW QUESTION # 156
Fill in the blank with an appropriate word.
________is also referred to as corporate governance, and covers issues such as board structures, roles and executive remuneration.

Answer:

Explanation:
Conformance


NEW QUESTION # 157
Which of the following ISO standards defines the corporate governance of IT?

  • A. ISO 9000
  • B. ISO 20000
  • C. ISO 27001
  • D. ISO 38500

Answer: D


NEW QUESTION # 158
Which of the following is the BEST justification for a procurement manager to agree to purchase IT equipment from a specific vendor during a sales promotion?

  • A. The product is offered at the lowest price.
  • B. The equipment adds value to the enterprise.
  • C. The business profit surpasses the IT cost for the equipment.
  • D. The IT benefit surpasses the business benefit from the purchase.

Answer: C


NEW QUESTION # 159
Which of the following is MOST important to review during IT strategy development?

  • A. Industry best practices
  • B. Data flows that indicate areas requiring IT support
  • C. IT balanced scorecard
  • D. Current business environment

Answer: D


NEW QUESTION # 160
Which of the following is the BEST indicator for measuring performance when implementing DevSecOps in an enterprise?

  • A. Deployments per day
  • B. Number of defects released per day
  • C. Mean time to repair
  • D. Percentage of automated tests

Answer: D

Explanation:
Percentage of automated testsis a key indicator in DevSecOps because it reflects the integration of security and quality into the development lifecycle. Automation is a cornerstone of DevSecOps, enabling continuous integration and deployment with embedded testing and security validation.
While mean time to repair and deployment frequency are valuable,automation directly supports the goals of security, speed, and reliability in DevSecOps.
Reference:
CGEIT Review Manual: Domain 3 - Benefits Realization
COBIT 2019: BAI03 (Manage Solutions Identification and Build), DSS05 (Manage Security Services).


NEW QUESTION # 161
In a large enterprise, which of the following is the BEST approach to enable effective communication to senior management regarding the project status for a strategic enterprise resource management system implementation?

  • A. Weekly project reports reviewed by business and IT management
  • B. Project management office with business and IT representatives
  • C. Project status updates on the intranet
  • D. A steering committee involving business and IT

Answer: D

Explanation:
A steering committee involving business and IT is the best approach to enable effective communication to senior management regarding the project status for a strategic enterprise resource management system implementation. This is because a steering committee is a group of senior executives, stakeholders, and experts who provide strategic direction, guidance, and oversight for the project1. A steering committee can help to:
* Communicate the project vision, goals, benefits, and risks to senior management and other stakeholders1
* Monitor and review the project progress, performance, quality, and deliverables1
* Resolve any issues, conflicts, or changes that may arise during the project1
* Ensure the alignment of the project with the business strategy, objectives, and priorities1
* Provide support, resources, and sponsorship for the project1
A steering committee involving business and IT can ensure that both the functional and technical aspects of the project are well represented and communicated to senior management. This can help to avoid any misunderstandings, gaps, or misalignments between the business and IT perspectives. A steering committee can also facilitate effective communication among senior management, project team, and other stakeholders, and foster a collaborative and supportive environment for the project success2.
The other options, project management office with business and IT representatives, weekly project reports reviewed by business and IT management, and project status updates on the intranet are not as effective as a steering committee for enabling communication to senior management regarding the project status. A project management office is a centralized unit that provides standards, methodologies, tools, and support for project management3. A project management office can help to improve the efficiency and consistency of project delivery, but it does not have the authority or responsibility to communicate directly with senior management or influence their decisions3. Weekly project reports are documents that summarize the progress, performance, issues, and risks of a project in a given period4. Weekly project reports can help to keep senior management informed of the project status, but they may not be sufficient to address their concerns or expectations. Weekly project reports may also be too frequent or detailed for senior management who may prefer a higher-level or less frequent view of the project4. Project status updates on the intranet are web-based messages that provide information about the current state of a project5. Project status updates on the intranet can help to increase the visibility and transparency of the project status to senior management and other stakeholders, but they may not be effective in engaging them or soliciting their feedback. Project status updates on the intranet may also be overlooked or ignored by senior management who may have limited time or access to the intranet5. References
:= What is a Project Steering Committee? | Clarizen, How To Run An Effective Steering Committee Meeting
- BrightWork, What Is a Project Management Office (PMO)? | Smartsheet, How To Write A Project Status Report: The Ultimate Guide, Project Status Update Email Sample : Templates and Examples


NEW QUESTION # 162
The PRIMARY benefit of using an IT service catalog as part of the IT governance program is that it.

  • A. improves the ability to allocate IT resources
  • B. establishes enterprise performance metrics per service
  • C. provides a foundation for measuring IT performance,
  • D. ensures IT effectively meets future business needs,

Answer: C

Explanation:
An IT service catalog is a comprehensive list of all of the services an IT organization offers, such as IT support, IT operations, or IT projects. It usually includes a description of the service, its features, costs, and response and delivery times, as well as a method for requesting the service12. An IT service catalog is part of the IT governance program, which is a framework that provides a formal structure for aligning IT investments and activities with business objectives and ensuring IT effectiveness and efficiency34. The primary benefit of using an IT service catalog as part of the IT governance program is that it provides a foundation for measuring IT performance. By defining and documenting the IT services and their expected outcomes, an IT service catalog enables the IT organization to establish and monitor key performance indicators (KPIs) and service level agreements (SLAs) for each service. These metrics can help evaluate how well the IT services meet the customer needs and expectations, as well as the business goals and priorities. They can also help identify and address any gaps or issues in the IT service delivery and quality, and support continuous improvement and optimization125.
The other options are not the primary benefit of using an IT service catalog as part of the IT governance program, although they may be related or secondary benefits. Ensuring IT effectively meets future business needs, improving the ability to allocate IT resources, and establishing enterprise performance metrics per service are all desirable outcomes of using an IT service catalog, but they are not the main purpose or benefit.
They are dependent or derived from the primary benefit of providing a foundation for measuring IT performance. By measuring IT performance, the IT organization can better understand the current and future business needs, allocate IT resources more efficiently and effectively, and align enterprise performance metrics with IT service outcomes125. References:
* 4: https://www.cio.com/article/272051/governanceit-governance-definition-and-solutions.html
* 2: https://www.atlassian.com/itsm/service-request-management/service-catalog
* 5: https://www.connectwise.com/blog/managed-services/it-service-catalog
* 1: https://www.servicenow.com/products/itsm/what-is-it-service-catalog.html
* 3: https://www.gartner.com/en/information-technology/glossary/it-governance


NEW QUESTION # 163
The IT department has determined that problems with a business report are due to quality issues within a set of data To whom should IT refer the matter for resolution?

  • A. Internal audit
  • B. Data steward
  • C. Data architect
  • D. Business analyst

Answer: B


NEW QUESTION # 164
When a shortfall of IT resources is identified, the FIRST course of action is to;

  • A. reallocate the budget to close the gap in resources.
  • B. negotiate best pricing for contracted resources.
  • C. reduce business requirements.
  • D. perform a business impact analysis (BIA).

Answer: D

Explanation:
Performing a business impact analysis (BIA) is the first course of action when a shortfall of IT resources is identified because it helps to assess the potential impact of the resource gap on the business processes, objectives, and goals. A BIA can also help to prioritize the criticality of the IT resources, identify the minimum acceptable levels of service, and determine the recovery strategies and resource requirements. A BIA can provide a basis for making informed decisions on how to allocate the available IT resources or acquire additional resources to close the gap.
Reference:
According to ISACA's CGEIT Review Manual 2021, one of the key activities for ensuring effective IT resource management is to "perform a business impact analysis (BIA) to identify and prioritize critical IT resources."1 According to ISACA's COBIT 2019 Framework, one of the governance objectives for managing IT resources is to "ensure that a BIA is performed to determine the required level of availability, continuity and security of IT services and data."2 According to ISACA's Business Continuity Management guide, one of the steps for developing a business continuity plan is to "conduct a BIA to identify the critical business processes and IT resources that support them."3


NEW QUESTION # 165
The PRIMARY reason a CIO and IT senior management should stay aware of the business environment is to:

  • A. measure efficiency of IT resources.
  • B. adjust IT strategy as needed.
  • C. revisit prioritization of IT projects.
  • D. re-assess the IT investment portfolio.

Answer: B

Explanation:
According to the CGEIT exam guide, the primary reason a CIO and IT senior management should stay aware of the business environment is to adjust IT strategy as needed. IT strategy is the plan that defines how IT will support and enable the business strategy and objectives of the enterprise. The business environment is the external and internal factors that affect the enterprise's performance and success, such as market trends, customer demands, competitor actions, regulatory changes, technological innovations, etc. The CIO and IT senior management should stay aware of the business environment to identify and anticipate the opportunities and threats that may arise, and to align and adapt the IT strategy accordingly. This will help to ensure that IT delivers value, benefits and competitive advantage to the enterprise, and that IT risks are managed and mitigated effectively. References: CGEIT Exam Candidate Guide, page 13. CGEIT Certification, What is IT Strategy?, What is Business Environment?


NEW QUESTION # 166
Best practice states that IT governance MUST:

  • A. be a component of enterprise governance.
  • B. enforce consistent policy across the enterprise.
  • C. be applied in the same manner throughout the enterprise.
  • D. apply consistent target levels of maturity to processes.

Answer: A

Explanation:
IT governance must be a component of enterprise governance, as it ensures that IT supports and enables the achievement of the enterprise goals and objectives. IT governance is the responsibility of the board of directors and executive management, and it is an integral part of enterprise governance123. IT governance also aligns IT with the enterprise strategy, delivers value from IT investments, manages IT risks and resources, and measures IT performance3. References := CGEIT Exam Content Outline, Domain 1, Subtopic A: Governance Framework, Task 1: Ensure the definition, establishment, and management of a framework for the governance of enterprise IT in alignment with the mission, vision and values of the enterprise.


NEW QUESTION # 167
Which of the following would BEST help to ensure the appropriate allocation of IT resources to support an enterprise's mission?

  • A. Manage resources as part of the portfolio strategy.
  • B. Implement resource planning for each IT project.
  • C. Prioritize program requirements based on existing resources.
  • D. Develop a resource strategy as part of program management.

Answer: A

Explanation:
Managing resources as part of the portfolio strategy would best help to ensure the appropriate allocation of IT resources to support an enterprise's mission. This is because the portfolio strategy aligns the IT investments with the business goals and priorities, and ensures that the IT resources are allocated to the most valuable and strategic initiatives. By managing resources at the portfolio level, the enterprise can optimize the use of its IT resources across multiple programs and projects, and avoid resource conflicts, shortages, or wastages. A resource strategy as part of program management, prioritizing program requirements based on existing resources, and resource planning for each IT project are all useful practices, but they are not sufficient to ensure the appropriate allocation of IT resources at the enterprise level. They may only focus on the resource needs and constraints of specific programs or projects, and may not consider the overall alignment and optimization of IT resources with the enterprise's mission. Reference:= IT Portfolio Management: A Practitioner's Guide - ISACA, Resource Allocation Done Right: Best Practices for 2022 & Beyond, A Complete Guide to Resource Allocation in Projects - Float


NEW QUESTION # 168
An enterprise's chief information officer (CIO) has been receiving complaints from business executives regarding the amount their units are being charged for IT services. To maintain a good relationship with business peers, the CIO wants to be responsive to these complaints. To address this issue, the FIRST step should be to:

  • A. agree to reduce charge rates and improve relationship management with the business.
  • B. look into outsourcing of support functions to drive down the cost structure.
  • C. ask the chief financial officer (CFO) about budget revisions for the business units' IT expenditures.
  • D. quantify consumption and service level agreement (SLA) achievements per business unit.

Answer: D

Explanation:
The first step to address the issue of complaints from business executives regarding the amount their units are being charged for IT services should be to quantify consumption and service level agreement (SLA) achievements per business unit. This will help the CIO to understand the actual usage and performance of IT services by each business unit, as well as to justify and communicate the chargeback rates based on the value and quality of IT services delivered. Quantifying consumption and SLA achievements can also help identify and address any inefficiencies, discrepancies, or gaps in IT service delivery or chargeback methods.
Agreeing to reduce charge rates and improve relationship management with the business, looking into outsourcing of support functions to drive down the cost structure, and asking the CFO about budget revisions for the business units' IT expenditures are possible steps to take after quantifying consumption and SLA achievements, but they are not the first step. Agreeing to reduce charge rates without understanding the underlying causes of the complaints may result in underfunding or underpricing of IT services, which may affect their quality and sustainability. Improving relationship management with the business is important, but it should be based on transparent and accurate information about IT service consumption and chargeback. Looking into outsourcing of support functions may reduce the cost structure, but it may also introduce new risks and challenges for IT governance and management. Asking the CFO about budget revisions may help align IT expenditures with business priorities, but it may not address the root causes of the dissatisfaction with IT chargeback.


NEW QUESTION # 169
Which of the following is the BEST way to express the value of financial investments in cybersecurity?

  • A. Payback period
  • B. Net present value (NPV)
  • C. Cost-benefit analysis
  • D. Internal rate of return (IRR)

Answer: C

Explanation:
Cost-benefit analysisis the most effective and practical approach for evaluating the value of cybersecurity investments. It allows comparison of expected benefits (risk reduction, incident cost avoidance, compliance) against the costs (investment, operations).
While NPV and IRR are solid financial tools, they are better suited to revenue-generating projects.
Cybersecurity's value is often intangible or indirect, making a straightforwardcost-benefit frameworkmore suitable.
Reference:
CGEIT Review Manual: Domain 4 - Risk Optimization and Business Case Justification COBIT 2019: EDM02 (Ensure Benefits Delivery).


NEW QUESTION # 170
Which of the following is the PRIMARY consideration for an enterprise when deciding whether to adopt a qualitative risk assessment method?

  • A. The method provides specific objective measurements of exposure.
  • B. The method provides a platform for all departments to contribute to the risk assessment.
  • C. The method enables an analysis Of recommended controls.
  • D. The method identifies areas to immediately address vulnerabilities.

Answer: B

Explanation:
The primary consideration for an enterprise when deciding whether to adopt a qualitative risk assessment method is:
The level of detail and accuracy required for the risk assessment. Qualitative risk assessment is a method that uses scenarios, subjectivity, and knowledge to evaluate risks. It does not provide specific objective measurements of exposure, but rather a relative ranking or rating of risks based on their likelihood and impact1. Qualitative risk assessment is suitable for situations where the data is scarce, uncertain, or incomplete, or where the risk assessment needs to be done quickly and easily1. However, qualitative risk assessment may also be biased, inconsistent, or inaccurate, as it depends on the judgment and experience of the risk assessors1. Therefore, an enterprise should consider the level of detail and accuracy required for the risk assessment before choosing a qualitative method. If the enterprise needs more precise and reliable estimates of risk exposure, it may opt for a quantitative method instead1.
The other options are not the primary consideration for an enterprise when deciding whether to adopt a qualitative risk assessment method. The method identifies areas to immediately address vulnerabilities, enables an analysis of recommended controls, and provides a platform for all departments to contribute to the risk assessment are all possible benefits or outcomes of using a qualitative risk assessment method, but they are not the main factor that influences the decision to use it. They may also apply to other methods of risk assessment, such as quantitative or hybrid methods2.


NEW QUESTION # 171
An enterprise has launched a series of critical new IT initiatives that are expected to produce substantial value Which of the following would BEST provide the board with an indication of progress of the IT initiatives?

  • A. Demonstration of prototype and user testing
  • B. Critical risk and issue walk-through
  • C. Portfolio management review
  • D. Full life cycle cost-benefit analysis

Answer: C

Explanation:
The best way to provide the board with an indication of progress of the IT initiatives is to conduct a portfolio management review. A portfolio management review is a process that involves evaluating and reporting on the performance, status, and outcomes of the IT projects, programs, and services that are part of the IT portfolio.
The IT portfolio is a collection of IT investments that are aligned with the enterprise's strategic objectives and expected to produce substantial value. A portfolio management review can help the board to assess and communicate the progress of the IT initiatives, as well as to identify and address any issues or risks that may affect their success. A portfolio management review can also help the board to ensure that the IT portfolio is balanced, optimized, and aligned with the business needs and priorities. IT Portfolio Management: A Comprehensive Guide | Smartsheet provides an overview of IT portfolio management and its benefits.


NEW QUESTION # 172
The BEST way for a CIO to monitor the alignment between the business and IT strategy is to regularly review

  • A. key risk indicators (KRIs)
  • B. the balanced scorecard
  • C. the risk register
  • D. IT services supporting business processes

Answer: B

Explanation:
The best way for a CIO to monitor the alignment between the business and IT strategy is to regularly review the balanced scorecard. The balanced scorecard is a strategic management tool that helps to measure and communicate the performance of an organization in relation to its vision, mission, goals, and objectives. The balanced scorecard uses four perspectives: financial, customer, internal process, and learning and growth, to evaluate how well the organization is achieving its desired outcomes and creating value for its stakeholders1. The balanced scorecard can also help to align the IT strategy with the business strategy by linking the IT objectives, initiatives, and measures with the business objectives, initiatives, and measures across the four perspectives2. By reviewing the balanced scorecard regularly, the CIO can monitor the progress and results of the IT strategy, identify the gaps and issues that need to be addressed, and ensure that the IT strategy is supporting and enabling the business strategy. According to COBIT 5, one of the seven enablers of IT governance is performance management, which includes using the balanced scorecard to align IT-related goals and metrics with enterprise goals and metrics3. The balanced scorecard is also part of the IT governance domain 5: Performance Measurement4.
The other options are not the best ways for a CIO to monitor the alignment between the business and IT strategy. Key risk indicators (KRIs) are metrics that indicate the level of risk exposure or potential impact of a risk event on an organization. KRIs can help to monitor and manage IT risks, but they do not necessarily reflect the alignment of IT strategy with business strategy. IT services supporting business processes are the activities and functions that IT provides to enable and facilitate the execution of business processes.
Reviewing IT services can help to evaluate the quality and efficiency of IT delivery, but they do not capture the strategic alignment of IT with business. The risk register is a document that records and tracks the identified risks, their causes, impacts, probabilities, responses, owners, and statuses. The risk register can help to document and communicate IT risks, but it does not measure or report the alignment of IT strategy with business strategy. References := 1: Balanced Scorecard Basics - Balanced Scorecard Institute12: Aligning Business Strategy with Information Technology Strategy - ISACA23: COBIT 5: A Business Framework for the Governance and Management of Enterprise IT, ISACA, page 314: CGEIT Review Manual 2023, ISACA, page 197. : Key Risk Indicators - ISACA3 : What are IT Services? Definition & Examples - BMC Software4 :
Risk Register - ISACA


NEW QUESTION # 173
An IT strategy committee wants to evaluate how well the IT department supports the business strategy. Which of the following is the BEST method for making this determination?

  • A. Customer survey analysis
  • B. IT balanced scorecard reporting
  • C. IT controls assurance program
  • D. Capability maturity assessment

Answer: B

Explanation:
The BEST method for the IT strategy committee to evaluate how well the IT department supports the business strategy is to use IT balanced scorecard reporting. An IT balanced scorecard (BSC) is a strategic management tool that translates the IT vision and mission into measurable objectives, indicators, targets, and initiatives across four perspectives: financial, customer, internal process, and learning and growth1. An IT balanced scorecard reporting is a process of collecting, analyzing, and communicating the performance data and results of the IT department based on the IT BSC framework2. An IT balanced scorecard reporting can help to:
Align the IT objectives and activities with the business strategy and expectations3 Monitor and evaluate the efficiency, effectiveness, and value of the IT department Identify the strengths, weaknesses, opportunities, and threats of the IT department Communicate and demonstrate the contribution and impact of the IT department to the business outcomes Therefore, an IT balanced scorecard reporting is the most suitable method for the IT strategy committee to assess how well the IT department supports the business strategy.
The other options are not as good as option C. While it is useful to conduct a capability maturity assessment, a customer survey analysis, or an IT controls assurance program, these are not comprehensive enough to evaluate how well the IT department supports the business strategy. They are rather focused on specific aspects of the IT department, such as its processes, services, or controls. They do not necessarily cover all four perspectives of the IT BSC framework, which provide a holistic view of the IT performance and alignment with the business strategy. Reference:= The IT Balanced Scorecard (BSC) Explained - BMC Software1 What Is a Balanced Scorecard (BSC), How Is it Used in Business?2 How to Align Your Business Strategy with Your Technology Strategy ...3 How to Measure Your Strategic Plan's Success - dummies SWOT Analysis: What It Is and When to Use It - Business News Daily How to Communicate Strategy Effectively - ClearPoint Strategy


NEW QUESTION # 174
A financial institution with a highly regarded reputation for protecting customer interests has recently deployed a mobile payments program. Which of the following key risk indicators (KRIs) would be of MOST interest to the CIO?

  • A. Percentage of incomplete transactions
  • B. Failure rate of point-of-sale systems
  • C. Number of failed software updates on mobile devices
  • D. Total volume of suspicious transactions

Answer: D

Explanation:
The key risk indicator (KRI) that would be of most interest to the CIO of a financial institution with a highly regarded reputation for protecting customer interests that has recently deployed a mobile payments program is the total volume of suspicious transactions. This KRI measures the number and value of transactions that are flagged as potentially fraudulent, malicious, or erroneous by the mobile payments system or by the customers. This KRI reflects the level of security and reliability of the mobile payments program, as well as the customer trust and satisfaction. A high volume of suspicious transactions indicates a high risk of financial losses, reputational damage, regulatory penalties, and customer attrition for the financial institution. Therefore, the CIO should monitor this KRI closely and take appropriate actions to prevent or mitigate any incidents that may compromise the mobile payments program


NEW QUESTION # 175
Which of the following risks refers to the risk associated with an event in the absence of specific controls?

  • A. Financial reporting risk
  • B. Inherent risk
  • C. Compliance risk
  • D. Operational risk

Answer: B


NEW QUESTION # 176
......

CGEIT Free Certification Exam Material with 680 Q&As : https://pass4sure.trainingquiz.com/CGEIT-training-materials.html