dc dotCreds
ISACA CGEIT Practice Test

ISACA CGEIT Practice Test

Start today’s free 10-question ISACA CGEIT set with source-backed explanations, local progress, and a fresh rotation every morning.

10 Free Daily Questions Source-backed Explanations 200 Verified Questions

Questions updated at Aug 23, 2026, 8:12 PM CDT

Go Pro - One Time Unlock

Unlock the full CGEIT bank

200 verified questions Exam Mode Practice Mode Detailed explanations Weak-area review No subscription - one-time unlock

Get the complete source-backed bank with Interview Questions, the full Study Guide, full Course Notes, detailed explanations, weak-area review, and exam-style practice.

Interview Questions Full Study Guide Full Course Notes Exam Mode Practice Mode Guided Course Detailed explanations Weak-area review No subscription
$4.99 One-time payment
See bundle and PDF options

We will confirm your site email in one quick checkout step.

Why DotCreds?

Practice with explanations that teach.

Source links for every answer Every wrong answer explained Guided Course included Practice and Exam Mode Weak-area tracking Same verified bank across web practice

What you get with free practice

10 Free Questions Daily Fresh set every day from the live bank
Detailed Explanations Learn with clear source-backed answers
Track Your Progress Daily history and performance insights
Upgrade Anytime Unlock the full bank when you are ready
Today's 10 ISACA CGEIT questions

Use this ISACA CGEIT practice test to review ISACA Certified in the Governance of Enterprise IT. Questions rotate daily and each answer links back to the source used to write it.

Today’s Set
10 questions
Rotates at 10:00 AM local time
Progress
0/10
Answered on this page
Accuracy
0%
Loading countdown…

200 verified questions are in the live bank. Free daily questions are selected from a rotating sample set. Unlock Pro to access the full question bank.

Preparing today’s free questions... Ordering the final locked-bank set before showing the practice cards.
Question 1 of 10
Objective Establish risk governance Risk Optimization (19%)

A payment processor has a risk committee for a fraud and transaction-monitoring platform upgrade, but the committee receives hundreds of technical vulnerabilities without aggregation by business service, objective or risk owner. Given security controls cannot materially increase transaction latency, what governance improvement is MOST important?

Concept tested:
Question 2 of 10
Objective Define value measures Benefits Realization (26%)

A high-growth software company reports ROI for the integration of a recently acquired SaaS business using benefits forecast at approval but actual costs through today. Benefit assumptions have since changed materially and the acquired unit moves faster but has less mature governance and risk practices. Which correction produces the MOST decision-useful value measure?

Concept tested:
Question 3 of 10
Objective Align IT with enterprise strategy Governance of Enterprise IT (40%)

A manufacturer is consolidating analytics across finance, supply chain and service operations. Each function uses the term 'customer' differently, and the selected data-platform vendor proposes adopting its own canonical model to accelerate implementation. Executives want the platform decision completed before the next planning cycle. What should governance require FIRST?

Concept tested:
Question 4 of 10
Objective Integrate security and resilience Risk Optimization (19%)

A digital media company completed a tabletop exercise for a streaming-platform modernization. The plan was followed exactly, but communications with a critical supplier failed and executives received conflicting status reports, while rapid growth has created unpredictable cloud cost and capacity pressure. What should happen NEXT?

Concept tested:
Question 5 of 10
Objective Manage sourcing and people IT Resources (15%)

A large insurer is preparing for an AI-enabled underwriting program. A competency assessment shows that current staff can operate the existing environment but cannot govern or support the target architecture, and the board wants growth without exceeding a moderate risk appetite or emerging regulatory obligations. Which action BEST aligns resource development with business needs?

Concept tested:
Question 6 of 10
Objective Monitor benefits delivery Benefits Realization (26%)

An energy trading company is controlling a cross-border ERP and analytics program. One promised benefit depends on a regulatory approval that is now delayed, while other benefits are ahead of plan and market volatility and jurisdiction-specific rules frequently change business priorities. What should governance do?

Concept tested:
Question 7 of 10
Objective Establish governance frameworks Governance of Enterprise IT (40%)

A high-growth software company adopted a governance framework two years ago. During the integration of a recently acquired SaaS business, repeated workarounds show that staff view governance as an IT compliance exercise rather than a business decision system. Given the acquired unit moves faster but has less mature governance and risk practices, what is the MOST appropriate governance response?

Concept tested:
Question 8 of 10
Objective Plan enterprise architecture IT Resources (15%)

A pharmaceutical company wants to measure whether architecture management is improving a research-data and clinical-operations transformation. The architecture team proposes counting diagrams and standards published, while regulatory evidence, intellectual property and time-to-market are all board-level concerns. Which measure is MOST meaningful to governance?

Concept tested:
Question 9 of 10
Objective Govern investments and portfolios Benefits Realization (26%)

A logistics enterprise is evaluating a shared global data and routing platform. The sponsor’s business case shows strong benefits, but those benefits depend on two unfunded data and process changes owned by other executives, and business units are decentralized and rely on different local suppliers. What should the investment committee do BEFORE approving the initiative?

Concept tested:
Question 10 of 10
Objective Monitor governance performance Governance of Enterprise IT (40%)

An electric utility reports that an OT and grid-management modernization is 'green' because projects meet schedule and budget targets. However, business outcomes are deteriorating and critical-service resilience takes precedence over short-term cost savings. Which governance monitoring change is MOST important?

Concept tested:
Locked preview

You are viewing today’s free 10. Unlock 190 more questions.

Unlock full bank
Daily sample Rotating practice Free daily questions are selected from a rotating sample set.
Pro bank Full access Unlock Pro to access the full question bank, Exam Mode, Practice Mode, and random tests.
CGEIT Pro $4.99 one-time

50 Exam Practice Test $1.99 one-time

A 50-question CGEIT PDF for short review sessions. Questions come first, then the answer review and explanations later in the file.

ISACA Bundle $9.99 one-time

Unlock all 5 active ISACA Bundle practice banks in one permanent purchase.

What’s includedCISA, CISM, CRISC, CGEIT, CDPSE
All Access $6.99/month

Unlock every active practice exam, bundle and path experience, Pro course and study content, and included downloads.

What’s includedEvery current and future active practice exam, All active bundle and career-path practice content, Pro course lessons, study content, and supported paid downloads

Choose an unlock option to continue. We will confirm your site email in one quick checkout step.

Secure checkout powered by Stripe. Source-backed questions. Not brain dumps. Checkout stays on this page and unlocks the same Pro builder on this practice page.

Purchase options

Unlock the full CGEIT bank.

Get the full bank, Exam Mode, Practice Mode, question sets, random tests, readiness tracking, saved box scores, and review tools for this exam.

The PDF versions keep questions first and move the answer review, explanations, and distractor notes to the back of the file.

200 verified exam-style questions Every choice explained Exam Mode and Practice Mode Question sets and random tests Readiness score and trends Previous test box scores

You've answered 0/10 questions in today's set.

Locked: 190 more questions in the full bank.

Locked: exam simulation mode, practice mode, readiness tracking, and saved review history.

Checkout stays on this page, so you can keep practicing, unlock the full bank, and start Exam Mode or Practice Mode when you are ready.

Cheat Sheets

7-day score keeper

Answer questions today and this will become a rolling 7-day scorecard.

Local history
Optional progress sync

Keep today’s practice moving

Guest progress saves automatically on this device. Add an email later when you want a magic link that keeps your daily CGEIT practice in sync across browsers.

Guest progress saves on this device automatically

Guest progress is available without an account.

Source-backed answer review

The free daily ISACA CGEIT set includes crawlable question text, answer choices, correct answer labels, objective mapping, and source links. Only the first SEO card includes answer explanations and any extra learning features. Pro-only bank questions stay locked; this section mirrors only the 10 free daily questions already shown on this page.

Question 1 A payment processor has a risk committee for a fraud and transaction-monitoring platform upgrade, but the committee receives hundreds of technical vulnerabilities without aggregation by business service, objective or risk owner. Given security controls cannot materially increase transaction latency, what governance improvement is MOST important?

Answer choices

  1. A. Delegate all vulnerability prioritization to security operations and report only the number of overdue patches to governance, as the primary implementation for the described business requirement.
  2. B. Translate and aggregate technology findings into business-relevant risk scenarios with accountable owners, impact, appetite/tolerance status and decision needs, within the documented operational, security, ownership, and validation requirements.
  3. C. Increase committee meeting frequency so members have more time to review the vulnerability list, subject to the existing exception and escalation process, for evaluation.
  4. D. Set a universal severity threshold and require management to remediate every vulnerability above it, with results reported against the current governance baseline, for this task.

Correct answer

Translate and aggregate technology findings into business-relevant risk scenarios with accountable owners, impact, appetite/tolerance status and decision needs, within the documented operational, security, ownership, and validation requirements.

Risk governance needs decision-ready information about enterprise exposure, not an uncontextualized inventory of technical findings.

Wrong-answer review

  • A. Delegate all vulnerability prioritization to security operations and report only the number of overdue patches to governance, as the primary implementation for the described business requirement.: Incorrect. Operational delegation is appropriate for routine treatment, but governance still needs visibility into material aggregate risk and exceptions.
  • C. Increase committee meeting frequency so members have more time to review the vulnerability list, subject to the existing exception and escalation process, for evaluation.: Incorrect. More meeting time does not transform raw findings into business risk information.
  • D. Set a universal severity threshold and require management to remediate every vulnerability above it, with results reported against the current governance baseline, for this task.: Incorrect. Technical severity alone may not reflect business impact, exploitability, compensating controls or appetite.

Extra learning features

Why candidates miss this

The distractors, ‘Delegate all vulnerability prioritization to security operations and report only the number of overdue patches to governance’ and ‘Increase committee meeting frequency so members have more time to review the vulnerability list, subject to the existing exception and escalation process,’ are tempting because they represent simplistic solutions. However, they fail to address the core issue of translating technical findings into business risk. The decisive clue is the emphasis on actionable information and decision-making. Likely wrong answer: Delegate all vulnerability prioritization to security operations and report only the number of overdue patches to governance. Review focus: NIST SP 800-39: Managing Information Security Risk

Interview question

Q: Translate and aggregate technology findings into business-relevant risk scenarios with accountable owners, impact, appetite/tolerance status and decision needs. Strong answer: This approach ensures that risk assessments are actionable and directly inform decision-making, aligning IT investments with business priorities and risk tolerance.

  • risk scenarios
  • accountable owners
  • impact
  • appetite/tolerance
  • decision needs

Caution: Ensure the response focuses on the translation of technical findings into business-relevant risk information, not simply listing vulnerabilities.

Objective/domain: Risk Optimization (19%)

Source: NIST SP 800-39: Managing Information Security Risk

Question 2 A high-growth software company reports ROI for the integration of a recently acquired SaaS business using benefits forecast at approval but actual costs through today. Benefit assumptions have since changed materially and the acquired unit moves faster but has less mature governance and risk practices. Which correction produces the MOST decision-useful value measure?

Answer choices

  1. A. Continue using the original benefit forecast so management remains accountable to the approved business case, with the accountable owner reporting any material variance, for the affected environment.
  2. B. Use only actual realized benefits and ignore remaining expected benefits until the investment is fully implemented, while retaining the current monitoring and reporting cadence, when applied.
  3. C. Use consistently updated expected or realized benefits and costs, clearly distinguish forecast from actual, and preserve the original baseline for variance and accountability analysis, for the required outcome.
  4. D. Reset both costs and benefits to a new baseline and stop reporting variance from the original business case, for the described technical objective and its associated operational control requirements, as configured.

Correct answer

Use consistently updated expected or realized benefits and costs, clearly distinguish forecast from actual, and preserve the original baseline for variance and accountability analysis, for the required outcome.

Question 3 A manufacturer is consolidating analytics across finance, supply chain and service operations. Each function uses the term 'customer' differently, and the selected data-platform vendor proposes adopting its own canonical model to accelerate implementation. Executives want the platform decision completed before the next planning cycle. What should governance require FIRST?

Answer choices

  1. A. Select the platform with the broadest integration features and resolve semantic differences through transformation rules, for the described technical objective and its associated operational control requirements, in context.
  2. B. Create separate analytical domains for each function so each team can preserve its existing definition of customer, under the stated technical, operational, and governance constraints.
  3. C. Let the vendor’s model become the enterprise standard, then allow business units to document exceptions after implementation, for the described technical objective and its associated operational control requirements, for evaluation.
  4. D. Establish enterprise information definitions, ownership and stewardship for the shared concepts, then use those decisions to guide information architecture and platform design, in the described situation.

Correct answer

Establish enterprise information definitions, ownership and stewardship for the shared concepts, then use those decisions to guide information architecture and platform design, in the described situation.

Objective/domain: Governance of Enterprise IT (40%)

Source: ISACA CGEIT Exam Content Outline

Question 4 A digital media company completed a tabletop exercise for a streaming-platform modernization. The plan was followed exactly, but communications with a critical supplier failed and executives received conflicting status reports, while rapid growth has created unpredictable cloud cost and capacity pressure. What should happen NEXT?

Answer choices

  1. A. Replace the supplier because any communication failure during a resilience exercise proves unacceptable third-party risk, with the accountable owner reporting any material variance, for the stated requirement.
  2. B. Repeat the same exercise until participants can execute the existing plan without errors, while retaining the current monitoring and reporting cadence, within the documented operational, security, ownership, and validation requirements.
  3. C. Update response/recovery plans, roles, communication paths and supplier dependencies from the exercise findings, assign corrective owners and retest the changed elements, as the selected response to the described condition.
  4. D. Treat the exercise as successful because the plan steps were followed and focus remediation only on participant training, under the stated technical, operational, and governance constraints.

Correct answer

Update response/recovery plans, roles, communication paths and supplier dependencies from the exercise findings, assign corrective owners and retest the changed elements, as the selected response to the described condition.

Objective/domain: Risk Optimization (19%)

Source: The NIST Cybersecurity Framework (CSF) 2.0

Question 5 A large insurer is preparing for an AI-enabled underwriting program. A competency assessment shows that current staff can operate the existing environment but cannot govern or support the target architecture, and the board wants growth without exceeding a moderate risk appetite or emerging regulatory obligations. Which action BEST aligns resource development with business needs?

Answer choices

  1. A. Hire specialists for all new competencies and retain current staff only for legacy operations until retirement, while retaining the current monitoring and reporting cadence, within the documented scope, ownership, and validation boundaries.
  2. B. Send all IT staff to the same broad certification program so capability development is consistent across the organization, as the recommended implementation across the complete governed service lifecycle.
  3. C. Delay the initiative until existing employees have developed every skill required for the target state, subject to the existing exception and escalation process, for the required outcome.
  4. D. Define the future-state competencies and capacity required by the strategy, assess gaps by role, and use targeted development, hiring or sourcing plans tied to the transition timeline, within the described context.

Correct answer

Define the future-state competencies and capacity required by the strategy, assess gaps by role, and use targeted development, hiring or sourcing plans tied to the transition timeline, within the described context.

Objective/domain: IT Resources (15%)

Source: ISACA CGEIT Exam Content Outline

Question 6 An energy trading company is controlling a cross-border ERP and analytics program. One promised benefit depends on a regulatory approval that is now delayed, while other benefits are ahead of plan and market volatility and jurisdiction-specific rules frequently change business priorities. What should governance do?

Answer choices

  1. A. Remove the delayed benefit from the business case because management cannot control regulatory approval, subject to the existing exception and escalation process, as the selected approach for the stated technical and business outcome.
  2. B. Stop the entire investment because a material assumption in the original business case is no longer valid, for the described technical objective and its associated operational control requirements, in the described situation.
  3. C. Leave the business case unchanged because external delays should not alter management accountability, and review the outcome at the next approved decision gate, for the described technical objective.
  4. D. Reforecast the affected benefit and timing, assess the investment’s current overall value and risk, and decide whether scope, funding or targets should change while preserving the original baseline, as proposed.

Correct answer

Reforecast the affected benefit and timing, assess the investment’s current overall value and risk, and decide whether scope, funding or targets should change while preserving the original baseline, as proposed.

Question 7 A high-growth software company adopted a governance framework two years ago. During the integration of a recently acquired SaaS business, repeated workarounds show that staff view governance as an IT compliance exercise rather than a business decision system. Given the acquired unit moves faster but has less mature governance and risk practices, what is the MOST appropriate governance response?

Answer choices

  1. A. Increase the number of mandatory controls and require quarterly attestations from all technology staff, while retaining the current monitoring and reporting cadence, for evaluation.
  2. B. Reframe governance communications around stakeholder value, decision rights and business outcomes, and make accountable leaders visibly reinforce those expectations, under the described governance of enterprise it (40%) criteria.
  3. C. Transfer governance communications to internal audit so messages are perceived as independent of IT management, subject to the existing exception and escalation process, within this context.
  4. D. Publish more detailed procedures for every governance process and require staff to acknowledge them annually, with results reported against the current governance baseline, in the described situation.

Correct answer

Reframe governance communications around stakeholder value, decision rights and business outcomes, and make accountable leaders visibly reinforce those expectations, under the described governance of enterprise it (40%) criteria.

Objective/domain: Governance of Enterprise IT (40%)

Source: ISACA CGEIT Exam Content Outline

Question 8 A pharmaceutical company wants to measure whether architecture management is improving a research-data and clinical-operations transformation. The architecture team proposes counting diagrams and standards published, while regulatory evidence, intellectual property and time-to-market are all board-level concerns. Which measure is MOST meaningful to governance?

Answer choices

  1. A. The percentage of solution architects who complete the enterprise architecture training curriculum, and review the outcome at the next approved decision gate, as proposed.
  2. B. The extent to which approved investments conform to or intentionally update the target architecture and sequencing plan while delivering required enterprise capabilities, for the specified implementation requirement.
  3. C. The average time required for the architecture review board to approve a project design, while retaining the current monitoring and reporting cadence, for the required outcome.
  4. D. The number of architecture documents updated each quarter relative to the previous year, with the rationale documented for governance review, within the documented operational, security, ownership, and validation requirements.

Correct answer

The extent to which approved investments conform to or intentionally update the target architecture and sequencing plan while delivering required enterprise capabilities, for the specified implementation requirement.

Question 9 A logistics enterprise is evaluating a shared global data and routing platform. The sponsor’s business case shows strong benefits, but those benefits depend on two unfunded data and process changes owned by other executives, and business units are decentralized and rely on different local suppliers. What should the investment committee do BEFORE approving the initiative?

Answer choices

  1. A. Reduce the benefit forecast by a conservative percentage and approve the initiative if the adjusted return remains positive, within the documented scope, ownership, and validation boundaries.
  2. B. Evaluate the full business case dependencies, ownership, risk and funding requirements at portfolio level and approve only if the enabling changes are credibly committed, as the recommended response to this scenario.
  3. C. Approve a pilot so technical feasibility can be demonstrated before the dependent business changes are funded, and review the outcome at the next approved decision gate, for the affected environment.
  4. D. Approve the initiative because its standalone business case is positive and track the enabling work as separate projects, for the described technical objective and its associated operational control requirements, in this situation.

Correct answer

Evaluate the full business case dependencies, ownership, risk and funding requirements at portfolio level and approve only if the enabling changes are credibly committed, as the recommended response to this scenario.

Question 10 An electric utility reports that an OT and grid-management modernization is 'green' because projects meet schedule and budget targets. However, business outcomes are deteriorating and critical-service resilience takes precedence over short-term cost savings. Which governance monitoring change is MOST important?

Answer choices

  1. A. Expand the governance scorecard with resilience, business-outcome and risk measures tied to enterprise objectives, using cost and schedule only as supporting delivery evidence, for the described technical objective.
  2. B. Harmonize project-status definitions across the utility before adding new governance measures, while keeping the existing reporting model, for the described technical objective and its associated operational control requirements, within the stated policy framework.
  3. C. Have internal audit verify the reliability of project cost and schedule data before those figures are included in the board pack, for the described technical objective and its associated operational control requirements.
  4. D. Increase the cadence of cost and schedule reporting so the board sees delivery variance sooner under the existing exception and escalation rules, under organization-wide implementation-governance requirements.

Correct answer

Expand the governance scorecard with resilience, business-outcome and risk measures tied to enterprise objectives, using cost and schedule only as supporting delivery evidence, for the described technical objective.

Objective/domain: Governance of Enterprise IT (40%)

Source: ISACA CGEIT Exam Content Outline

Where to go after the daily web set

How are ISACA CGEIT questions generated?

dotCreds builds ISACA CGEIT practice questions from public exam objectives and ISACA exam and documentation references. The questions are written for realistic study practice, not copied from exam dumps.

How are explanations sourced?

Each question includes an explanation and, when available, a source link back to the provider documentation or reference used to validate the answer. That keeps the practice tied to study material you can actually review.

What score do I get?

The page tracks today's answered count and accuracy for the 10-question daily set, then saves a 7-day score history on this device so you can see your recent practice trend.

Why use this site?

The site is the fastest way to start ISACA CGEIT practice without installing anything. It is built for daily recall, quick weak-topic discovery, and source-backed explanations you can review immediately.