• Wrong document? Swap it for free
  • Written by students who passed
  • Immediately available after payment
  • Read online or as PDF
Sell
Where do you study
Your language
Document preview thumbnail
Preview 4 out of 38 pages
Exam (elaborations)

WGU E091 Task 1 CIO Leadership Strategy Report | Building a Successful IT Organization | Fully Completed 2026.

Document preview thumbnail
Preview 4 out of 38 pages

WGU E091 Task 1 CIO Leadership Strategy Report | Building a Successful IT Organization | Fully Completed 2026.

Content preview

WGU E091 Task 1 CIO Leadership Strategy Report |
Building a Successful IT Organization | Fully
Completed 2026.
1. A CIO is evaluating the potential impact of a ransomware attack. Which risk
management process is being performed?
• A. Risk mitigation
• B. Risk identification
• C. Risk transference
• D. Risk analysis
Answer: D. Risk analysis
Rationale: Risk analysis involves evaluating the likelihood and impact of
identified risks. Assessing a ransomware attack's potential damage falls
under this category. Risk identification is the first step of finding risks, while
mitigation involves reducing them.


2. Which strategy best describes transferring IT risk to a third party?
• A. Cyber insurance policy
• B. Implementing a firewall
• C. Employee security training
• D. Data encryption
Answer: A. Cyber insurance policy
Rationale: Risk transference shifts financial consequence to an insurer.
Implementing a firewall and training employees are examples of risk
mitigation (reducing the likelihood). Encryption reduces impact.

,3. What should a Business Continuity Plan (BCP) include for IT infrastructure?
• A. Recovery Time Objective (RTO) and Recovery Point Objective (RPO)
• B. Only a list of hardware vendors
• C. Employee vacation schedules
• D. Marketing strategy documents
Answer: A. Recovery Time Objective (RTO) and Recovery Point
Objective (RPO)
Rationale: RTO and RPO are fundamental metrics for a BCP. They define
acceptable downtime and data loss. The other options are irrelevant to
continuity planning.


4. Which international standard is most relevant for IT risk management?
• A. ISO 31000
• B. ISO 9001
• C. ISO 14001
• D. ISO 27018
Answer: A. ISO 31000
Rationale: ISO 31000 provides principles and guidelines for enterprise
risk management. ISO 9001 is quality management, and ISO 14001 is
environmental management.


5. A CIO uses "decision analysis tools" to choose between projects. This is an
example of:
• A. Risk avoidance
• B. Risk acceptance
• C. Risk evaluation

, • D. Risk ignorance
Answer: C. Risk evaluation
Rationale: Decision analysis tools help evaluate alternatives and their
associated risks, supporting informed decisions. Risk avoidance means not
engaging in the activity.


6. What is the primary goal of a risk mitigation strategy?
• A. Eliminate all risks
• B. Transfer risk to customers
• C. Reduce the likelihood or impact of a risk
• D. Ignore low-level risks
Answer: C. Reduce the likelihood or impact of a risk
Rationale: Mitigation aims to minimize risk. It is impossible to eliminate
all risks, and ignoring them is not a formal strategy.


7. An organization’s contingency plan for sudden environmental changes should
primarily focus on:
• A. Maintaining current stock prices
• B. Rapidly adapting IT operations to new conditions
• C. Reducing employee headcount
• D. Increasing marketing spend
Answer: B. Rapidly adapting IT operations to new conditions
Rationale: Contingency plans ensure operational stability during rapid
changes. IT operations must be flexible to support business continuity
under new conditions.

, 8. In enterprise risk management, "risk appetite" refers to:
• A. The cost of risk management
• B. The number of risks identified
• C. The amount of risk an organization is willing to accept
• D. The process of eliminating risk
Answer: C. The amount of risk an organization is willing to accept
Rationale: Risk appetite is a key concept in ERM; it guides how much
risk the organization will tolerate in pursuit of objectives.


9. Which tool categorizes IT projects by strategic importance and risk?
• A. McFarlan’s Strategic Grid
• B. Balanced Scorecard
• C. Porter’s Value Chain
• D. Gartner Hype Cycle
Answer: A. McFarlan’s Strategic Grid
Rationale: The Strategic Grid classifies projects (Strategic, Support, High
Potential, Factory) to evaluate their risk and strategic value. The Balanced
Scorecard focuses on performance metrics.


10. Risk optimization strategies aim to:
• A. Maximize returns relative to risk
• B. Minimize all returns
• C. Maximize risk at all costs
• D. Focus only on compliance
Answer: A. Maximize returns relative to risk

Document information

Uploaded on
August 10, 2026
Number of pages
38
Written in
2026/2027
Type
Exam (elaborations)
Contains
Questions & answers
$27.49

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Sold
1
Followers
0
Items
482
Last sold
3 weeks ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions