Set 4 Parts 1-3 Questions & Answers Verified Actual Exam
2026/2027 – Complete Exam-Style Q&As | 100% Certified
Verified – Pass Guaranteed – A+ Graded
PART 1: IT STRATEGY & GOVERNANCE (Questions 1–25)
Q1: A mid-sized healthcare organization is reviewing its IT strategic plan for the next three years. The
CIO wants to ensure that IT investments directly support the organization's mission to improve patient
outcomes while controlling costs. Which strategic planning tool would BEST help align IT initiatives with
these dual business objectives?
A. A purely technical roadmap focused only on infrastructure upgrades and hardware refresh cycles
B. The Balanced Scorecard, which links IT performance to financial, customer, internal process, and
learning/growth perspectives [CORRECT]
C. A detailed project Gantt chart showing timelines for all planned software implementations
D. A vendor comparison matrix evaluating only the top three cloud service providers by market share
Correct Answer: B
Rationale: The best answer is B. The Balanced Scorecard is designed specifically to connect strategic
objectives across multiple dimensions—financial health, customer satisfaction, internal processes, and
organizational learning—making it ideal for aligning IT with both patient outcome goals and cost control.
This framework forces leadership to think beyond just the technology itself and consider how IT creates
value across the entire organization. The other options either focus too narrowly on technical details or
miss the strategic alignment piece entirely.
Q2: During a strategic planning session, the CFO argues that IT should be treated as a cost center to be
minimized, while the CIO believes IT is a strategic enabler. Which of the following arguments BEST
supports the CIO's position?
A. IT spending should always be capped at 3% of total revenue regardless of industry benchmarks
B. Technology investments that improve operational efficiency and enable new revenue streams
demonstrate IT's role as a value creator, not just an expense [CORRECT]
,C. The IT department should be allowed to purchase any technology it wants without budget constraints
D. Outsourcing all IT functions to the lowest-cost provider is the only way to prove strategic value
Correct Answer: B
Rationale: The best answer is B. This choice captures the essence of IT as a strategic enabler by pointing
to concrete outcomes—efficiency gains and new revenue opportunities—that demonstrate return on
investment beyond simple cost reduction. A well-run IT function doesn't just spend money; it generates
measurable business value. The other options either represent the cost-center mentality (A, D) or an
unrealistic lack of fiscal responsibility (C).
Q3: A retail company is analyzing its competitive position in the e-commerce market. The strategy team
wants to understand the forces that determine the intensity of competition and profitability in their
industry. Which framework should they apply?
A. The Deming Cycle (Plan-Do-Check-Act) for continuous quality improvement
B. Porter's Five Forces, which examines competitive rivalry, supplier power, buyer power, threat of
substitution, and threat of new entry [CORRECT]
C. The OSI model for understanding network protocol layers
D. A simple SWOT analysis listing only the company's internal strengths and weaknesses
Correct Answer: B
Rationale: The best answer is B. Porter's Five Forces is the classic framework for analyzing industry
structure and competitive dynamics—it looks at the external environment to explain why some
industries are more profitable than others. For a retail company trying to understand e-commerce
competition, this model reveals where pressure points exist and where strategic IT investments might
create competitive advantage. SWOT is useful too, but it doesn't specifically analyze industry-wide
competitive forces the way Porter's model does.
Q4: A manufacturing firm is conducting a SWOT analysis as part of its IT strategic planning process. The
team identifies that the company has a highly skilled IT workforce but notes that its legacy ERP system is
outdated and difficult to integrate with modern cloud applications. How should these findings be
classified?
A. Both are internal factors; the skilled workforce is a Strength, and the legacy ERP is a Weakness
[CORRECT]
B. The skilled workforce is an Opportunity, and the legacy ERP is a Threat
C. The skilled workforce is a Strength, and the legacy ERP is an external Threat
D. Both are external factors; the workforce reflects market conditions, and the ERP gap reflects
competitive pressure
,Correct Answer: A
Rationale: The best answer is A. In SWOT analysis, strengths and weaknesses are internal to the
organization—things the company controls or possesses—while opportunities and threats are external
environmental factors. A skilled workforce is clearly an internal asset (strength), and an outdated ERP
system is an internal limitation (weakness) that the company can address through strategic IT planning.
Mixing these up is a common error that leads to flawed strategy.
Q5: A financial services firm must comply with strict data protection regulations while also pursuing
digital transformation. The board asks the CIO to recommend a governance framework that provides
comprehensive guidance on managing IT to deliver business value while managing risk and ensuring
compliance. Which framework BEST fits this need?
A. ISO 9001, which focuses exclusively on quality management systems in manufacturing
B. COBIT, which provides a holistic framework for IT governance, risk management, and value delivery
aligned with business goals [CORRECT]
C. Six Sigma, which is primarily a statistical process improvement methodology
D. The Agile Manifesto, which guides software development team interactions but does not address
governance
Correct Answer: B
Rationale: The best answer is B. COBIT (Control Objectives for Information and Related Technologies)
was built specifically for IT governance—it bridges the gap between business requirements and IT
operations by providing principles, practices, and models for enterprise IT management. For a financial
services firm juggling compliance and transformation, COBIT offers the structured approach to risk
management and value delivery that the board is looking for. The other frameworks serve different
purposes and don't provide the comprehensive governance coverage needed here.
Q6: A hospital's IT department is implementing new patient data management systems. They need a
governance framework that emphasizes service lifecycle management, from strategy and design
through transition and operation, with a strong focus on continuous improvement. Which framework
should they adopt?
A. COBIT, which focuses on control objectives and audit compliance
B. ITIL, which provides best practices for IT service management across the entire service lifecycle
[CORRECT]
C. ISO 27001, which is specifically about information security management systems
D. The Capability Maturity Model Integration (CMMI), which assesses process maturity levels
Correct Answer: B
, Rationale: The best answer is B. ITIL (Information Technology Infrastructure Library) is the go-to
framework for IT service management, and its lifecycle approach—strategy, design, transition,
operation, and continual improvement—matches exactly what this hospital needs for managing patient
data systems over time. While COBIT and ISO 27001 are valuable, they don't provide the same depth of
operational guidance for day-to-day service delivery and improvement.
Q7: An international e-commerce company processes personal data from customers in the European
Union, the United States, and several Asian markets. Which regulation imposes the strictest
requirements on how this company must handle, store, and protect EU citizens' personal data?
A. The Health Insurance Portability and Accountability Act (HIPAA), which applies only to US healthcare
entities
B. The General Data Protection Regulation (GDPR), which mandates strict data protection standards for
EU residents' personal data regardless of where the company is located [CORRECT]
C. The Sarbanes-Oxley Act (SOX), which governs financial reporting accuracy for publicly traded
companies
D. The Children's Online Privacy Protection Act (COPPA), which only applies to data collection from
children under 13 in the US
Correct Answer: B
Rationale: The best answer is B. GDPR has extraterritorial reach—meaning it applies to any organization
worldwide that processes the personal data of EU residents, regardless of where that organization is
headquartered. The requirements around consent, data portability, breach notification, and the right to
be forgotten are among the strictest globally. For an international e-commerce company, GDPR
compliance isn't optional; it's a legal obligation that carries significant penalties for non-compliance.
Q8: A US-based health insurance company is upgrading its claims processing system. The project team
must ensure that the new system protects the privacy and security of patient health information. Which
regulation establishes the national standards for this protection?
A. The General Data Protection Regulation (GDPR), which governs EU data protection
B. The Health Insurance Portability and Accountability Act (HIPAA), which sets national standards for
protecting sensitive patient health information [CORRECT]
C. The Federal Information Security Management Act (FISMA), which applies to federal government
agencies
D. The Payment Card Industry Data Security Standard (PCI DSS), which governs credit card transaction
security
Correct Answer: B