Certified in the Governance of Enterprise IT Practice Exam — CGEIT:Certified in the Governance of Enterprise IT

1. The question bank is cloud‑connected and updates automatically; no manual re‑acquisition is required.

2. Start practicing right after activating the question bank. It supports simultaneous use on websites and mini‑programs, with one‑click bilingual switching for each question.

3. Functions include online practice, mock tests, note‑taking, wrong‑question recording, etc., valid for one year.

4. Recommended practice order: Turn on review mode to browse questions → Complete sequential practice → Take mock exams for pre‑test self‑assessment.

5. Activation codes can be purchased by clicking Buy Now on the right or via our official Tmall flagship store.

6. For inquiries, contact customer service through mini‑program, WeChat, WhatsApp or LINE.

Exam information

I. Basic Exam Information

- Exam Name: ISACA Certified in the Governance of Enterprise IT® (CGEIT®)

- Exam Languages: Two language versions are available globally, including Simplified Chinese and English, with unified language options worldwide.

- Registration Eligibility: There are no restrictions for exam registration, and all individuals may sign up for the exam. A formal CGEIT credential application is required upon passing the exam. Credential prerequisites:

 • Possess a minimum of 5 years of work experience related to enterprise IT governance, with practical experience in at least two of the four CGEIT practice domains

 • Work experience shall be in advisory or managerial roles with active involvement in organizational IT governance

 • Agree to and abide by the ISACA Code of Professional Ethics

 • Note: No experience exemptions are allowed for CGEIT; the full 5-year work experience requirement must be fulfilled

- Exam Fees: USD 575 for ISACA members; USD 760 for non-members. A USD 50 credential application fee is required after passing the exam.

- Exam Duration: 4 hours (240 minutes), covering all 150 exam questions.

- Exam Format: ISACA offers two standard exam modes worldwide: remote-proctored online exam (video proctoring via PSI) and in-person computer-based testing (CBT).

 Available exam modes by region:

 • Hong Kong: In-person CBT only

 • Taiwan: In-person CBT and online exam

 • Macau: In-person CBT only

 • Mainland China: In-person CBT arranged by ISACA-authorized partners

 • Overseas regions: Free to choose between remote proctoring and in-person CBT

- Exam Questions: 150 multiple-choice questions. All questions are scored with no unscored pre-test items.

- Scoring Details:

 • A preliminary pass/fail result is provided immediately after the exam.

 • Official exam results will be sent via email within 10 working days.

 • Passing score: 450 points (total score: 800 points; scaled scoring range: 200 – 800).

- Exam Eligibility Validity: After successful registration, candidates must schedule and complete the exam within 6 months. Eligibility will expire if overdue, and re-registration and payment will be required.


II. Detailed Exam Content (Latest Exam Outline)

The CGEIT exam consists of four core practice domains with a total weight of 100%. It assesses the professional competencies and practical capabilities of enterprise IT governance practitioners.


1. Enterprise IT Governance (40%): Governance frameworks (COBIT, ITIL, ISO and others), governance structure and responsibilities, alignment between IT strategy and business objectives, policy and standard formulation, regulatory compliance, and performance evaluation of IT governance.

2. IT Resources (15%): IT human resource management, IT asset management, IT infrastructure management, data governance and administration, application system management, vendor and outsourcing management.

3. Benefits Realization (26%): IT portfolio management, program and project management, IT value measurement and reporting, business case development, IT-business collaboration, and innovation management.

4. Risk Optimization (19%): IT risk management frameworks, risk identification and assessment, risk response strategies, IT internal control management, business continuity and disaster recovery, and information security governance.


Core Assessment Focus

Capabilities in designing and implementing enterprise IT governance frameworks, optimal allocation of IT resources, delivery of IT investment benefits, comprehensive IT risk management, cross-departmental collaboration and stakeholder management.


III. Registration Process

1. Registration Process for Non-Mainland China Candidates

1. Visit the official ISACA website: https://www.isaca.org, create and log in to your MyISACA account.

2. Select the CGEIT exam for registration, and fill in personal information and work experience details.

3. Complete exam fee payment (USD 575 for members / USD 760 for non-members).

4. Upon successful payment, your 6-month exam eligibility period will take effect.

5. Schedule your exam time and location via PSI (remote proctoring or in-person CBT is optional).

6. Prepare valid identification documents and attend the exam at the scheduled time.


2. Registration Process for Mainland China Candidates

1. Register via the official ISACA China website: https://www.isaca.org.cn or ISACA-authorized partners such as ZhongShen Audit Online and Saihu Academy.

2. Submit personal information and work experience verification documents, and complete registration with assistance from authorized institutions.

3. Pay the exam fee (USD 575 for members / USD 760 for non-members). All registration formalities will be handled uniformly by the institution.

4. Upon successful registration, your 6-month exam eligibility period will take effect.

5. Follow the links or guidelines provided by the institution to schedule your exam time and test center on the PSI platform. In-person CBT is the primary option in Mainland China.

6. Present valid identification documents (ID card or passport) on exam day.


IV. Supplementary Notes

1. Credential Validity: The CGEIT credential is valid for 3 years. To maintain active status, holders must earn 120 Continuing Professional Education (CPE) credits within the validity period and pay annual maintenance fees (USD 45 for members / USD 85 for non-members).

2. Retake Policy: Candidates who fail the exam must wait 30 days before retaking it. A 90-day waiting period is required after two consecutive failures. Retake fees are identical to the initial exam fees.

3. Exam Updates: The exam outline revised in July 2020 places greater emphasis on emerging technology governance, digital transformation governance and business value delivery, which aligns with the core demands of modern enterprise IT governance.

4. Differences from Other ISACA Credentials: CGEIT focuses on enterprise IT governance and is suitable for IT governance leaders and CIOs. CISA specializes in information systems audit for IT audit professionals. CISM centers on information security management for cybersecurity managers. CRISC concentrates on IT risk and information systems control for IT risk practitioners.


Wish all candidates every success in the exam!

Sample questions

Certified in the Governance of Enterprise IT · Q1
Question #:1 - A large organization with branches across many countries is in the midst of an enterprise resource planning (ERP) transformation. The IT organization receives news that the branches in a country where the impact to the enterprise is to be greatest are being sold. What should be the NEXT step?
  • A.
    Update the ERP business case and re-evaluate the ROI.
  • B.
    Cancel the ERP transformation and re-allocate project funds.
  • C.
    Adjust the ERP implementation plan and budget.
  • D.
    Continue with the ERP migration according to plan.

Answer: C

The next step for the IT organization when they receive news that the branches in a country where the impact to the enterprise is to be greatest are being sold is to adjust the ERP implementation plan and budget. This means that the IT organization should assess the implications of the sale on the ERP transformation objectives, scope, timeline, resources, costs, and risks. The IT organization should also communicate with the relevant stakeholders, such as the business units, the vendors, and the buyers, to coordinate and align the ERP activities with the sale process. The IT organization should then revise the ERP implementation plan and budget to reflect the changes and ensure that the ERP transformation delivers value to the remaining enterprise
Certified in the Governance of Enterprise IT · Q2
Question #:2 - An enterprise is developing several consumer-based services using emerging technologies involving sensitive personal data. The CIO is under pressure to ensure the enterprise is first to market, but security scan results have not been adequately addressed. Reviewing which of the following will enable the CIO to make the BEST decision for the customers?
  • A.
    Acceptable use policy
  • B.
    Risk register
  • C.
    Ethics standards
  • D.
    Change management policy

Answer: B

A risk register is a tool that records and tracks the risks associated with a project or an activity, such as developing consumer-based services using emerging technologies involving sensitive personal data. A risk register typically includes information such as the risk description, category, impact, probability, status, response strategy, and owner. Reviewing the risk register will enable the CIO to make the best decision for the customers, as it will help them to identify, assess, and prioritize the risks that may affect the security, privacy, and quality of the services, and to determine the appropriate actions to mitigate or avoid them. The other options are not as relevant, as they do not provide specific information about the risks involved in the project or activity. : : CGEIT Review Manual (Digital Version), Chapter 4: Risk Optimization, Section 4.3: References IT Risk Management, Subsection 4.3.2: IT Risk Management Process, Page 156 : CGEIT Review Manual (Digital Version), Chapter 4: Risk Optimization, Section 4.3: IT Risk Management, Subsection 4.3.3: IT Risk Management Techniques and Tools, Page 158 : Capability Maturity Model and Risk Register Integration1
Certified in the Governance of Enterprise IT · Q3
Question #:3 - An analysis of an organization s security breach is complete. The results indicate that the quality of the code used for updates to its primary customer-facing software has been declining and security flaws were introduced. The FIRST IT governance action to correct this problem should be to review:
  • A.
    compliance with the user testing process.
  • B.
    the change management control framework.
  • C.
    the qualifications of developers to write secure code.
  • D.
    the incident response plan.

Answer: B

The change management control framework is the first IT governance action to correct the problem of declining code quality and security flaws, as it defines and implements the policies, procedures, and standards for managing changes to the IT systems and software. The change management control framework also ensures that changes are authorized, tested, documented, and deployed in a consistent and secure manner12. A review of the change management control framework can help to identify and address the root causes of the security breach, and to prevent or mitigate similar incidents in the future. := CGEIT Exam Content References Outline, Domain 1, Subtopic C: Technology Governance, Task 3: Ensure that IT processes are compliant with relevant laws, regulations and contractual requirements.
Certified in the Governance of Enterprise IT · Q4
Question #:4 - The PRIMARY reason for an enterprise to adopt an IT governance framework is to:
  • A.
    assure IT sustains and extends the enterprise strategies and objectives.
  • B.
    expedite IT investments among other competing business investments.
  • C.
    establish IT initiatives focused on the business strategy.
  • D.
    allow IT to optimize confidentiality, integrity, and availability of information assets.

Answer: A

IT governance is a framework that provides a formal structure for organizations to ensure that IT investments support business objectives. The primary reason for an enterprise to adopt an IT governance framework is to assure that IT sustains and extends the enterprise strategies and objectives, by aligning IT with business needs, optimizing IT performance and value, managing IT risks and resources, and measuring IT outcomes and benefits12. : ISACA, CGEIT Review Manual, 7th Edition, 2019, page 15. What Is IT Governance? References Definition, Practices and Frameworks. IT Governance: Definition, Frameworks, and Best Practices.
Certified in the Governance of Enterprise IT · Q5
Question #:5 - Which of the following has the GREATEST influence on data quality assurance?
  • A.
    Data classification
  • B.
    Data encryption
  • C.
    Data modeling
  • D.
    Data stewardship

Answer: D

Data stewardship has the greatest influence on data quality assurance. Data stewardship is the process of defining, implementing, and enforcing policies and standards for data quality, security, privacy, and usage1. Data stewards are the individuals or groups who are responsible for ensuring that the data is accurate, consistent, complete, timely, and compliant with the business rules and regulations2. Data stewardship involves activities such as data profiling, data cleansing, data validation, data monitoring, and data reporting3. Data stewardship helps to improve the trustworthiness and usability of the data for analysis and decision making. : Data Quality Assurance: Importance & Best Practices in 2023 - AIMultiple1, References Data Owners vs. Data Stewards vs. Data Custodians - CPO Magazine2, What is Data Stewardship? - Talend3

FAQ

How many practice questions are available for Certified in the Governance of Enterprise IT ?

This question bank includes 573 Certified in the Governance of Enterprise IT practice questions covering single and multiple choice, each with answers and explanations.

Are Certified in the Governance of Enterprise IT practice questions available in Chinese and English?

Certified in the Governance of Enterprise IT practice questions are currently available in English.

Can I try Certified in the Governance of Enterprise IT practice questions for free?

Yes. Free sample questions are available on this page, and the full question bank is available after signing up on Zhangxuetu.