Try 12 original Certified in the Governance of Enterprise IT (CGEIT) sample questions on governance frameworks, value delivery, resource optimization, risk oversight, performance, and accountability, then use the Notify me form for IT Mastery practice updates.
Certified in the Governance of Enterprise IT (CGEIT) is an ISACA governance route for candidates who work with enterprise IT value delivery, risk oversight, resource optimization, and performance measurement.
Use these 12 original sample questions for initial self-assessment. The full IT Mastery route for CGEIT is not available yet; try the preview and use the Notify me form if this is your target route.
CGEIT is about governance, not day-to-day administration. The best answer often clarifies accountability, oversight, value, risk, resources, and performance rather than solving the operational problem directly.
These questions are original IT Mastery preview items for enterprise IT governance judgment. They are not official ISACA exam questions.
Topic: governance versus management
A major IT program is late and over budget. What is the governance body’s best role?
Best answer: B
Explanation: Governance provides oversight and accountability. Management handles day-to-day execution, while governance evaluates performance, risk, value, and corrective direction.
Topic: value delivery
An IT investment delivered on time but did not produce the expected business benefit. What should governance focus on?
Best answer: D
Explanation: Value delivery is not only technical completion. Governance should track whether intended benefits were defined, owned, measured, and realized.
Topic: resource optimization
Several strategic initiatives depend on the same scarce cybersecurity architects. What should governance require?
Best answer: A
Explanation: Resource optimization requires prioritization. Governance should align scarce resources to strategy, risk, and value rather than overcommitting capacity.
Topic: performance measurement
The board receives IT reports full of server uptime metrics but no business-value indicators. What is the main weakness?
Best answer: C
Explanation: Governance metrics should support oversight. Technical measures may be useful, but they should connect to business outcomes, risk, value, and accountability.
Topic: risk oversight
A cloud migration creates new third-party concentration risk. What should governance ensure?
Best answer: D
Explanation: Governance does not eliminate risk by approving a strategy. It ensures risks are understood, owned, monitored, and considered against appetite.
Topic: accountability
A digital transformation program has no single owner for benefit realization. What should be corrected?
Best answer: B
Explanation: Governance depends on accountability. Without an owner for outcomes and metrics, benefit realization becomes weak.
Topic: governance framework
An organization adopts an IT governance framework but treats it as a checklist with no decision rights. What is missing?
Best answer: A
Explanation: Framework adoption should clarify how governance works. Decision rights, roles, accountability, and monitoring matter more than checklist adoption.
Topic: strategic alignment
IT proposes a platform investment with unclear connection to enterprise strategy. What should governance ask first?
Best answer: C
Explanation: Strategic alignment connects IT investment to enterprise goals. Governance should require a clear business rationale and value measure.
Topic: portfolio oversight
A portfolio contains many small projects that individually look useful but collectively exceed budget and capacity. What is the governance issue?
Best answer: A
Explanation: Portfolio governance considers the whole set of investments. Capacity, dependencies, budget, risk, and value must be managed across the portfolio.
Topic: stakeholder reporting
Executive reports show green status even though business users report poor adoption. What should governance challenge?
Best answer: B
Explanation: Governance reporting should reflect reality. Adoption and stakeholder outcomes are important value indicators, not noise.
Topic: policy oversight
An IT policy exists but exceptions are approved informally and never reviewed. What should governance require?
Best answer: D
Explanation: Governance should ensure exceptions are controlled and transparent. Unreviewed exceptions can undermine policy and risk appetite.
Topic: continuous improvement
A governance committee receives repeated audit findings about weak project benefit tracking. What is the best governance response?
Best answer: C
Explanation: Governance should act on repeated findings by requiring accountable remediation and follow-up, not by ignoring assurance feedback.
| Area | What to check |
|---|---|
| Accountability | Identify who owns decisions, outcomes, risks, resources, and benefits. |
| Value | Connect IT investments to measurable business outcomes. |
| Oversight | Use metrics that show risk, performance, adoption, and benefit realization. |
| Scope | Choose governance action, not operational task execution. |