nerdexam
Isaca

CGEIT · Question #66

From a governance perspective, the PRIMARY goal of an IT risk optimization process should be to ensure:

The correct answer is D. the impact of IT risk to the enterprise is managed.. The primary goal of an IT risk optimization process, from a governance perspective, is to ensure the overall impact of IT risk to the enterprise is effectively managed.

Submitted by viktor_hu· Apr 18, 2026Risk Optimization

Question

From a governance perspective, the PRIMARY goal of an IT risk optimization process should be to ensure:

Options

  • AIT risk thresholds are defined in the enterprise architecture (EA).
  • Bthe IT risk mitigation strategy is approved by management.
  • CIT risk is mapped to the balanced scorecard.
  • Dthe impact of IT risk to the enterprise is managed.

How the community answered

(51 responses)
  • A
    4% (2)
  • B
    8% (4)
  • C
    2% (1)
  • D
    86% (44)

Why each option

The primary goal of an IT risk optimization process, from a governance perspective, is to ensure the overall impact of IT risk to the enterprise is effectively managed.

AIT risk thresholds are defined in the enterprise architecture (EA).

Defining risk thresholds in the EA is a specific implementation detail of risk management, not the overarching primary goal of risk optimization itself.

Bthe IT risk mitigation strategy is approved by management.

Approving the IT risk mitigation strategy by management is a necessary step in the risk management process, but the ultimate goal is broader: managing the impact of those risks.

CIT risk is mapped to the balanced scorecard.

Mapping IT risk to the balanced scorecard is a reporting and measurement mechanism, not the primary goal of the risk optimization process itself, which focuses on control and impact.

Dthe impact of IT risk to the enterprise is managed.Correct

Risk optimization aims to balance the costs and benefits of risk responses, ensuring that the enterprise accepts an appropriate level of risk and that its adverse impacts are controlled and within defined tolerance levels, aligning with business objectives.

Concept tested: IT Risk Management and Governance Objectives

Source: https://www.isaca.org/resources/cobit/cobit-2019-framework-governance-and-management-objectives

Topics

#IT risk optimization#Risk management objective#Enterprise impact#IT governance perspective

Community Discussion

No community discussion yet for this question.

Full CGEIT Practice