WGU D486 DFN1 TASK 1:
GOVERNANCE, RISK, AND
COMPLIANCE | UPDATE |
WITH COMPLETE
SOLUTIONS.
1. What is the primary purpose of IT governance?
Answer:
To ensure that IT investments and activities align with organizational goals, deliver
business value, manage risks, and comply with legal and regulatory requirements.
2. Which framework is primarily used for IT governance?
A. ISO 9001
B. COBIT
C. Scrum
D. Six Sigma
Answer:
B. COBIT
Explanation: COBIT provides comprehensive guidance for governing and managing
enterprise IT.
,3. What is risk management?
Answer:
Risk management is the continuous process of identifying, assessing, prioritizing,
treating, monitoring, and communicating risks that may impact organizational
objectives.
4. Which risk treatment option involves eliminating the activity causing the risk?
A. Accept
B. Avoid
C. Transfer
D. Mitigate
Answer:
B. Avoid
5. Which framework focuses on information security management systems (ISMS)?
A. COBIT
B. ISO/IEC 27001
C. ITIL
D. PMBOK
Answer:
B. ISO/IEC 27001
6. What is compliance?
Answer:
Compliance is adhering to applicable laws, regulations, standards, contractual
obligations, and organizational policies.
,7. Which regulation protects personal health information in the United States?
A. PCI DSS
B. GDPR
C. HIPAA
D. SOX
Answer:
C. HIPAA
8. What is the principle of least privilege?
Answer:
Users should receive only the minimum permissions necessary to perform their
assigned job responsibilities.
9. What is the difference between a threat and a vulnerability?
Answer:
Threat: Something capable of causing harm.
Vulnerability: A weakness that can be exploited by a threat.
10. Which document defines acceptable employee use of company technology
resources?
A. Incident Response Plan
B. Acceptable Use Policy
C. Disaster Recovery Plan
D. Business Impact Analysis
Answer:
, B. Acceptable Use Policy
11. What does the acronym CIA stand for in cybersecurity?
Answer:
Confidentiality
Integrity
Availability
12. Which role is ultimately responsible for corporate governance?
A. Network Administrator
B. Help Desk Manager
C. Board of Directors
D. Database Administrator
Answer:
C. Board of Directors
13. Which risk response transfers financial responsibility to another organization?
A. Avoid
B. Accept
C. Transfer
D. Reduce
Answer:
C. Transfer
Example: Purchasing cyber insurance.
14. What is a Business Impact Analysis (BIA)?
GOVERNANCE, RISK, AND
COMPLIANCE | UPDATE |
WITH COMPLETE
SOLUTIONS.
1. What is the primary purpose of IT governance?
Answer:
To ensure that IT investments and activities align with organizational goals, deliver
business value, manage risks, and comply with legal and regulatory requirements.
2. Which framework is primarily used for IT governance?
A. ISO 9001
B. COBIT
C. Scrum
D. Six Sigma
Answer:
B. COBIT
Explanation: COBIT provides comprehensive guidance for governing and managing
enterprise IT.
,3. What is risk management?
Answer:
Risk management is the continuous process of identifying, assessing, prioritizing,
treating, monitoring, and communicating risks that may impact organizational
objectives.
4. Which risk treatment option involves eliminating the activity causing the risk?
A. Accept
B. Avoid
C. Transfer
D. Mitigate
Answer:
B. Avoid
5. Which framework focuses on information security management systems (ISMS)?
A. COBIT
B. ISO/IEC 27001
C. ITIL
D. PMBOK
Answer:
B. ISO/IEC 27001
6. What is compliance?
Answer:
Compliance is adhering to applicable laws, regulations, standards, contractual
obligations, and organizational policies.
,7. Which regulation protects personal health information in the United States?
A. PCI DSS
B. GDPR
C. HIPAA
D. SOX
Answer:
C. HIPAA
8. What is the principle of least privilege?
Answer:
Users should receive only the minimum permissions necessary to perform their
assigned job responsibilities.
9. What is the difference between a threat and a vulnerability?
Answer:
Threat: Something capable of causing harm.
Vulnerability: A weakness that can be exploited by a threat.
10. Which document defines acceptable employee use of company technology
resources?
A. Incident Response Plan
B. Acceptable Use Policy
C. Disaster Recovery Plan
D. Business Impact Analysis
Answer:
, B. Acceptable Use Policy
11. What does the acronym CIA stand for in cybersecurity?
Answer:
Confidentiality
Integrity
Availability
12. Which role is ultimately responsible for corporate governance?
A. Network Administrator
B. Help Desk Manager
C. Board of Directors
D. Database Administrator
Answer:
C. Board of Directors
13. Which risk response transfers financial responsibility to another organization?
A. Avoid
B. Accept
C. Transfer
D. Reduce
Answer:
C. Transfer
Example: Purchasing cyber insurance.
14. What is a Business Impact Analysis (BIA)?