ISACA · CGEIT
Validates expertise in governance of enterprise IT across four domains: organizational structure and IT frameworks, resource allocation, benefits realization, and risk optimization.
Practice Questions
598
≈ 3 practice exams
Duration
240 minutes
Passing Score
450/800
Difficulty
ProfessionalLast Updated
Jan 2026
Use this CGEIT practice exam to prepare for Certified in the Governance of Enterprise IT (CGEIT) with realistic questions, detailed explanations, and focused study modes. The practice bank includes 598 questions for ISACA CGEIT, so you can review the exam steadily instead of relying on one long cram session.
As you practice, pay extra attention to recurring topics such as Governance of Enterprise IT (40%), IT Resources (15%), Benefits Realization (26%), and Risk Optimization (19%). Start with short sessions to identify weak areas, then move into timed quizzes once your accuracy is consistent.
The explanations are especially useful when you want to connect exam wording to the responsibilities and scenarios described in the official certification guidance. Use the free preview first, then unlock the full question bank when you are ready to build a complete study routine.
The Certified in the Governance of Enterprise IT (CGEIT) is a professional-level credential offered by ISACA that validates deep expertise in enterprise IT governance frameworks and practices. It is widely regarded as the premier—and only—framework-agnostic IT governance certification for individuals, designed to demonstrate mastery across four critical domains: Governance of Enterprise IT, IT Resources, Benefits Realization, and Risk Optimization. Since its introduction in 2007, more than 8,000 professionals worldwide have earned the CGEIT, signaling their ability to align IT strategy with organizational objectives and maximize the value of IT investments.
The certification covers a broad spectrum of governance competencies, including the design and oversight of governance frameworks, enterprise and information architecture, IT resource planning and lifecycle management, IT-enabled investment analysis, business case development, and enterprise risk management. Holders are recognized for their ability to bridge technology and business strategy—ensuring that IT functions deliver measurable business value while maintaining compliance and minimizing risk. The CGEIT is periodically updated through validation studies with global subject matter experts, and its current four-domain structure reflects the consolidation of prior content into a more streamlined, practice-relevant outline.
CGEIT is intended for seasoned IT and business professionals who operate in governance, oversight, or advisory capacities—typically those with at least five years of relevant experience. Ideal candidates include Chief Information Officers (CIOs), Chief Information Security Officers (CISOs), Chief Technology Officers (CTOs), IT Directors, Audit Directors, IT Governance Managers, Risk and Compliance Managers, and Senior IT Managers who are responsible for shaping or executing enterprise IT governance strategies.
The certification is also well-suited for IT consultants, information security specialists, IT assurance professionals, and organizational strategic managers who advise boards or executive leadership on governance matters. It is most valuable for professionals seeking to move into or formalize their standing in C-suite and senior leadership roles where alignment of IT with business goals is a primary responsibility.
ISACA does not require any formal prerequisites to register for and sit the CGEIT exam. However, to apply for and receive the CGEIT certification after passing the exam, candidates must demonstrate a minimum of five years of work experience in managing, advising, or providing oversight in support of enterprise IT governance. This experience must span at least three of the four CGEIT domains, and a mandatory minimum of one year must be directly related to Domain 1: Governance of Enterprise IT. All qualifying work experience must fall within the ten years preceding the application date.
While no specific prior certifications are required, ISACA recommends that candidates have a solid foundation in IT strategy, risk management, and organizational governance before attempting the exam. Familiarity with established frameworks such as COBIT, ITIL, ISO/IEC 38500, or similar enterprise governance frameworks will provide important context for the exam content. Candidates have five years from their exam pass date to submit their experience application.
The CGEIT exam consists of 150 multiple-choice questions, all of which are scored, covering practical knowledge across the four job practice domains. The exam is delivered as a computer-based test and may be taken either at an authorized PSI testing center worldwide or via a remotely proctored online session, offering flexibility for candidates globally. The total exam duration is 240 minutes (four hours).
Scoring uses a scaled score system with a maximum of 800 points. The passing score is 450 out of 800. Exam registration is continuous—candidates can register at any time and schedule a testing appointment as early as 48 hours after payment. Exam fees are US$575 for ISACA members and US$760 for non-members, with a one-time US$50 application processing fee due upon certification application.
CGEIT holders consistently earn among the highest salaries in the IT profession. ISACA reports an average annual salary of US$141,000 for CGEIT-certified professionals, with 70% reporting on-the-job improvements and 22% receiving a pay increase after earning the credential. Specific roles command notable compensation: CIOs average around US$161,000, IT Directors approximately US$120,000, and CISOs around US$122,500. Certified professionals typically earn 25% more than their non-certified peers in comparable roles.
The CGEIT is widely considered a capstone credential in the IT governance space—one that unlocks access to executive, advisory, and board-level roles that require demonstrated governance expertise. It is recognized globally, with strong demand in the United States, Singapore, and other major technology markets. Unlike many technical certifications, CGEIT signals strategic leadership capability, making it a differentiator for professionals competing for CIO, CTO, IT Director, and governance consulting positions. There is no comparable framework-agnostic IT governance certification at this level, positioning CGEIT as the definitive credential for professionals whose primary responsibility is aligning enterprise IT with organizational strategy.
5 sample questions with answers and explanations. The full bank has 598 questions, enough for 3 full-length practice exams.
Preview — answers shown1. A global retail organization is implementing COBIT 2019 and must select appropriate values for the 11 design factors to tailor its governance system. The company operates in highly regulated markets across multiple jurisdictions with significant GDPR, PCI-DSS, and SOX compliance requirements. Which value should the organization assign to Design Factor 6 - Compliance Requirements? (Select one!)
Explanation
High compliance requirements is correct because the organization faces multiple significant regulatory frameworks including GDPR for data protection, PCI-DSS for payment card security, and SOX for financial controls across multiple jurisdictions. Low would apply to industries with minimal regulation. Normal would apply to standard single-jurisdiction requirements. Variable is not a valid COBIT 2019 design factor value, as each factor requires a specific assignment to properly calibrate governance priorities.
2. A global enterprise implements COBIT EDM01 (Ensured Governance Framework Setting and Maintenance) to establish IT governance. The board must understand which components comprise a governance system according to COBIT 2019. Which components must be considered when implementing the governance framework? (Select three!)
Multiple correct answersExplanation
COBIT 2019 defines governance systems using seven components that must work together holistically: Processes (organized practices achieving objectives), Organizational Structures (decision-making entities and reporting relationships), Principles, Policies, and Frameworks (governance direction translated to practical guidance), Information (data produced and used), Culture, Ethics, and Behavior (individual and organizational conduct factors), People, Skills, and Competencies (human resource capabilities), and Services, Infrastructure, and Applications (technology enabling governance). When implementing EDM01 to establish governance frameworks, organizations must consider all seven components comprehensively, not just processes or structures alone. While Culture, Ethics, and Behavior is a valid component establishing tone at the top, the question asks for three components and the first three listed represent fundamental governance elements. Marketing strategies and physical security controls are management activities or technical controls, not governance system components. Understanding these seven components is essential for COBIT implementation and avoiding incomplete governance system designs that focus only on processes while neglecting structures, policies, culture, or other critical elements.
3. An enterprise implements COBIT BAI09 Managed Assets to improve IT asset lifecycle management. During asset retirement, the process identifies 200 servers containing sensitive customer data that must be decommissioned. Which activities should be prioritized during the disposal stage to meet governance requirements? (Select two!)
Multiple correct answersExplanation
Secure data sanitization following approved standards and ensuring compliance with environmental disposal regulations are the priority governance activities during asset disposal. Data sanitization protects sensitive information from unauthorized disclosure and meets regulatory requirements for data protection. Environmental compliance ensures proper disposal following regulations for electronic waste. Updating the configuration management database is important for asset tracking but secondary to security and compliance during disposal. Vendor contract negotiation is a procurement activity, not a disposal governance priority. Calculating residual value is a financial consideration that doesn't address the governance risks of improper disposal.
4. A healthcare provider implements COBIT DSS04 Managed Continuity with Recovery Time Objectives ranging from 4 hours for critical patient systems to 48 hours for administrative systems. Annual business impact analysis reveals that the maximum tolerable period of disruption for the electronic health record system is 2 hours. The current RTO is 6 hours. What should the IT continuity manager do FIRST? (Select one!)
Explanation
Escalating to executive management is correct because there is a critical gap where the current RTO of 6 hours exceeds the MTPD of 2 hours, meaning the organization faces risk of irreparable business damage during system outages. This requires executive-level decision-making about risk acceptance versus investment in improved recovery capabilities. MTPD sets the absolute boundary that RTO must not exceed. Simply updating documentation does not address the underlying capability gap. Implementing additional redundancy may be the eventual solution but requires executive approval for the likely significant investment. While risk assessment is valuable, the immediate priority is escalating the known gap to decision-makers who can authorize resources to close it.
5. An enterprise has implemented COBIT Design Factor 7 (Role of IT) assessment to inform governance priorities. Analysis places the organization in the Strategic quadrant of the Strategic Impact Grid where current operations are highly dependent on IT and future strategic success depends on IT innovation. The CIO proposes governance changes based on this assessment. Which governance approach would be MOST appropriate for an organization in the Strategic quadrant? (Select one!)
Explanation
Organizations in the Strategic quadrant face the governance challenge of maintaining highly reliable operations that current business depends on while simultaneously enabling IT innovation critical to future strategic success. This requires balanced governance that does not sacrifice current operational excellence for innovation or vice versa. The governance system must address both run-the-business stability and change-the-business transformation imperatives. This is the most challenging governance position requiring sophisticated balance. Cost reduction focus is appropriate for the Support quadrant where IT has low strategic impact and limited operational criticality. Strategic quadrant organizations depend on IT for competitive advantage and cannot govern primarily through cost minimization. Strong centralized controls emphasize stability appropriate for the Factory quadrant where current operations are critical but future strategic impact is low. Strategic quadrant requires both stability and innovation agility, not just control. Prioritizing innovation over operational stability is appropriate for the Turnaround quadrant where current IT is not meeting needs but future strategy depends on IT improvement. Strategic quadrant organizations cannot sacrifice current operational excellence that business depends on, making pure innovation focus inappropriate.
Certified Cybersecurity Operations Analyst (CCOA)
CCOA · 593 questions
Certified Data Privacy Solutions Engineer (CDPSE)
CDPSE · 749 questions
Certified in Risk and Information Systems Control (CRISC)
CRISC · 761 questions
Certified Information Security Manager (CISM)
CISM · 1196 questions
Certified Information Systems Auditor (CISA)
CISA · 895 questions
Cloud Fundamentals Certificate
Cloud-Fund · 600 questions
$17.99
One-time access to this exam