D486 ITCL 5225
Governance, Risk, & Compliance
Final Assessment (Qns & Ans)
2025
General Instructions
1. Read All Questions Carefully: Make sure you understand each question.
2. Time Management: You have a specific amount of time to complete the exam.
Keep an eye on the clock and pace yourself.
3. Allowed Materials: Only use materials that are explicitly allowed. Unauthorized
materials can lead to disqualification.
4. ANS Format: Follow the required format for your ANS. For example, multiple-
choice questions might need you to select the best ANS, while essay questions
require detailed responses.
5. Academic Integrity: Adhere to the university's honor code. Any form of cheating or
plagiarism is strictly prohibited.
6. Technical Requirements: Ensure your computer and internet connection are
stable. For online exams, you might need a webcam and microphone for proctoring
purposes.
7. Submission: Submit your ANS before the time expires. Late submissions might
not be accepted.
©2024/2025
,1. Which of the following frameworks is most commonly
associated with establishing a structured approach to risk
management?
- a) COBIT
- b) NIST Cybersecurity Framework
- c) ISO 31000
- d) PCI-DSS
ANS: c) ISO 31000
Rationale: ISO 31000 provides guidelines on risk
management principles and frameworks that are widely
recognized and implemented across various industries.
2. In the context of information governance, which term refers to
the policies and procedures that ensure the proper handling of
sensitive data?
- a) Risk Management
- b) Data Protection
- c) Compliance
- d) Data Governance
ANS: d) Data Governance
©2024/2025
, Rationale: Data governance encompasses the management
framework for data handling, including policies and procedures to
ensure data integrity and compliance.
3. Which of the following practices is NOT part of effective risk
management?
- a) Identifying risks
- b) Ignoring minor risks
- c) Analyzing risk impact
- d) Mitigating risks
ANS: b) Ignoring minor risks
Rationale: Effective risk management requires attention to all
risks, regardless of perceived severity, to prevent potential issues.
4. The primary goal of the Sarbanes-Oxley Act (SOX) is to:
- a) Protect consumer data
- b) Enhance accuracy in corporate disclosures
- c) Regulate financial services
- d) Establish cybersecurity frameworks
ANS: b) Enhance accuracy in corporate disclosures
Rationale: SOX was enacted to protect shareholders by
improving the accuracy and reliability of corporate disclosures.
©2024/2025
, 5. Which of the following is a key performance indicator (KPI)
for assessing the effectiveness of compliance programs?
- a) Number of audits performed
- b) Employee training hours
- c) Rate of compliance violations
- d) All of the above
ANS: d) All of the above
Rationale: All options provide relevant insights into
compliance program effectiveness, encompassing audit
responsiveness, training impact, and violation rates.
Fill-in-the-Blank Questions
6. The _______ is a critical governance framework that aligns IT
and business objectives while managing risk and resource
utilization.
ANS: COBIT
Rationale: COBIT provides a comprehensive framework for
managing and governing enterprise IT.
©2024/2025
Governance, Risk, & Compliance
Final Assessment (Qns & Ans)
2025
General Instructions
1. Read All Questions Carefully: Make sure you understand each question.
2. Time Management: You have a specific amount of time to complete the exam.
Keep an eye on the clock and pace yourself.
3. Allowed Materials: Only use materials that are explicitly allowed. Unauthorized
materials can lead to disqualification.
4. ANS Format: Follow the required format for your ANS. For example, multiple-
choice questions might need you to select the best ANS, while essay questions
require detailed responses.
5. Academic Integrity: Adhere to the university's honor code. Any form of cheating or
plagiarism is strictly prohibited.
6. Technical Requirements: Ensure your computer and internet connection are
stable. For online exams, you might need a webcam and microphone for proctoring
purposes.
7. Submission: Submit your ANS before the time expires. Late submissions might
not be accepted.
©2024/2025
,1. Which of the following frameworks is most commonly
associated with establishing a structured approach to risk
management?
- a) COBIT
- b) NIST Cybersecurity Framework
- c) ISO 31000
- d) PCI-DSS
ANS: c) ISO 31000
Rationale: ISO 31000 provides guidelines on risk
management principles and frameworks that are widely
recognized and implemented across various industries.
2. In the context of information governance, which term refers to
the policies and procedures that ensure the proper handling of
sensitive data?
- a) Risk Management
- b) Data Protection
- c) Compliance
- d) Data Governance
ANS: d) Data Governance
©2024/2025
, Rationale: Data governance encompasses the management
framework for data handling, including policies and procedures to
ensure data integrity and compliance.
3. Which of the following practices is NOT part of effective risk
management?
- a) Identifying risks
- b) Ignoring minor risks
- c) Analyzing risk impact
- d) Mitigating risks
ANS: b) Ignoring minor risks
Rationale: Effective risk management requires attention to all
risks, regardless of perceived severity, to prevent potential issues.
4. The primary goal of the Sarbanes-Oxley Act (SOX) is to:
- a) Protect consumer data
- b) Enhance accuracy in corporate disclosures
- c) Regulate financial services
- d) Establish cybersecurity frameworks
ANS: b) Enhance accuracy in corporate disclosures
Rationale: SOX was enacted to protect shareholders by
improving the accuracy and reliability of corporate disclosures.
©2024/2025
, 5. Which of the following is a key performance indicator (KPI)
for assessing the effectiveness of compliance programs?
- a) Number of audits performed
- b) Employee training hours
- c) Rate of compliance violations
- d) All of the above
ANS: d) All of the above
Rationale: All options provide relevant insights into
compliance program effectiveness, encompassing audit
responsiveness, training impact, and violation rates.
Fill-in-the-Blank Questions
6. The _______ is a critical governance framework that aligns IT
and business objectives while managing risk and resource
utilization.
ANS: COBIT
Rationale: COBIT provides a comprehensive framework for
managing and governing enterprise IT.
©2024/2025