ISACA · CGEIT
Validates expertise in governance of enterprise IT across four domains: organizational structure and IT frameworks, resource allocation, benefits realization, and risk optimization.
Practice Questions
598
≈ 3 practice exams
Duration
240 minutes
Passing Score
450/800
Difficulty
ProfessionalLast Updated
Jan 2026
Use this CGEIT practice exam to prepare for Certified in the Governance of Enterprise IT (CGEIT) with realistic questions, detailed explanations, and focused study modes. The practice bank includes 598 questions for ISACA CGEIT, so you can review the exam steadily instead of relying on one long cram session.
As you practice, pay extra attention to recurring topics such as Governance of Enterprise IT (40%), IT Resources (15%), Benefits Realization (26%), and Risk Optimization (19%). Start with short sessions to identify weak areas, then move into timed quizzes once your accuracy is consistent.
The explanations are especially useful when you want to connect exam wording to the responsibilities and scenarios described in the official certification guidance. Use the free preview first, then unlock the full question bank when you are ready to build a complete study routine.
The Certified in the Governance of Enterprise IT (CGEIT) is a professional-level credential offered by ISACA that validates deep expertise in enterprise IT governance frameworks and practices. It is widely regarded as the premier—and only—framework-agnostic IT governance certification for individuals, designed to demonstrate mastery across four critical domains: Governance of Enterprise IT, IT Resources, Benefits Realization, and Risk Optimization. Since its introduction in 2007, more than 8,000 professionals worldwide have earned the CGEIT, signaling their ability to align IT strategy with organizational objectives and maximize the value of IT investments.
The certification covers a broad spectrum of governance competencies, including the design and oversight of governance frameworks, enterprise and information architecture, IT resource planning and lifecycle management, IT-enabled investment analysis, business case development, and enterprise risk management. Holders are recognized for their ability to bridge technology and business strategy—ensuring that IT functions deliver measurable business value while maintaining compliance and minimizing risk. The CGEIT is periodically updated through validation studies with global subject matter experts, and its current four-domain structure reflects the consolidation of prior content into a more streamlined, practice-relevant outline.
CGEIT is intended for seasoned IT and business professionals who operate in governance, oversight, or advisory capacities—typically those with at least five years of relevant experience. Ideal candidates include Chief Information Officers (CIOs), Chief Information Security Officers (CISOs), Chief Technology Officers (CTOs), IT Directors, Audit Directors, IT Governance Managers, Risk and Compliance Managers, and Senior IT Managers who are responsible for shaping or executing enterprise IT governance strategies.
The certification is also well-suited for IT consultants, information security specialists, IT assurance professionals, and organizational strategic managers who advise boards or executive leadership on governance matters. It is most valuable for professionals seeking to move into or formalize their standing in C-suite and senior leadership roles where alignment of IT with business goals is a primary responsibility.
ISACA does not require any formal prerequisites to register for and sit the CGEIT exam. However, to apply for and receive the CGEIT certification after passing the exam, candidates must demonstrate a minimum of five years of work experience in managing, advising, or providing oversight in support of enterprise IT governance. This experience must span at least three of the four CGEIT domains, and a mandatory minimum of one year must be directly related to Domain 1: Governance of Enterprise IT. All qualifying work experience must fall within the ten years preceding the application date.
While no specific prior certifications are required, ISACA recommends that candidates have a solid foundation in IT strategy, risk management, and organizational governance before attempting the exam. Familiarity with established frameworks such as COBIT, ITIL, ISO/IEC 38500, or similar enterprise governance frameworks will provide important context for the exam content. Candidates have five years from their exam pass date to submit their experience application.
The CGEIT exam consists of 150 multiple-choice questions, all of which are scored, covering practical knowledge across the four job practice domains. The exam is delivered as a computer-based test and may be taken either at an authorized PSI testing center worldwide or via a remotely proctored online session, offering flexibility for candidates globally. The total exam duration is 240 minutes (four hours).
Scoring uses a scaled score system with a maximum of 800 points. The passing score is 450 out of 800. Exam registration is continuous—candidates can register at any time and schedule a testing appointment as early as 48 hours after payment. Exam fees are US$575 for ISACA members and US$760 for non-members, with a one-time US$50 application processing fee due upon certification application.
CGEIT holders consistently earn among the highest salaries in the IT profession. ISACA reports an average annual salary of US$141,000 for CGEIT-certified professionals, with 70% reporting on-the-job improvements and 22% receiving a pay increase after earning the credential. Specific roles command notable compensation: CIOs average around US$161,000, IT Directors approximately US$120,000, and CISOs around US$122,500. Certified professionals typically earn 25% more than their non-certified peers in comparable roles.
The CGEIT is widely considered a capstone credential in the IT governance space—one that unlocks access to executive, advisory, and board-level roles that require demonstrated governance expertise. It is recognized globally, with strong demand in the United States, Singapore, and other major technology markets. Unlike many technical certifications, CGEIT signals strategic leadership capability, making it a differentiator for professionals competing for CIO, CTO, IT Director, and governance consulting positions. There is no comparable framework-agnostic IT governance certification at this level, positioning CGEIT as the definitive credential for professionals whose primary responsibility is aligning enterprise IT with organizational strategy.
5 sample questions with answers and explanations. The full bank has 598 questions, enough for 3 full-length practice exams.
Preview — answers shown1. A financial institution implements COBIT capability assessment using the capability levels framework. The IT change management process achieves its purpose through documented procedures, but implementation varies significantly between teams, process performance is not measured, and no quantitative objectives exist. At which capability level is the change management process operating? (Select one!)
Explanation
Level 2 Managed is correct because the process achieves its purpose with documented procedures and work products, but lacks the consistent deployment across teams required for Level 3. The process is planned and has established documentation, exceeding Level 1. However, significant variation between teams and absence of quantitative objectives indicates it has not reached Level 3 Defined or Level 4 Predictable. Level 2 represents managed execution with documented procedures but inconsistent deployment.
2. An aerospace manufacturer implements COBIT APO03 Managed Enterprise Architecture integrating with TOGAF ADM. The enterprise architect proposes a cloud-native microservices architecture that deviates from the approved service-oriented architecture standard. Which governance body should review and decide on this architecture exception request? (Select one!)
Explanation
The IT Architecture Review Board is specifically responsible for enforcing architecture compliance and evaluating exception or dispensation requests when proposed solutions deviate from established architecture standards. IT Steering Committee focuses on operational project prioritization and resource allocation, not architecture governance. Board IT Strategy Committee operates at strategic governance level, too high for tactical architecture decisions. CIO has executive authority but delegates architecture exception reviews to the Architecture Review Board for structured evaluation against architecture principles and standards.
3. A manufacturing company implements the Benefits Dependency Network framework for an enterprise resource planning system investment. The investment objectives include 20% reduction in inventory costs and 15% improvement in order fulfillment cycle time. Which element should be identified FIRST in the BDN development process? (Select one!)
Explanation
Investment objectives should be identified first because the BDN framework explicitly works from left to right conceptually, starting with strategic outcomes, but is validated from right to left by tracing dependencies. The process begins by clearly defining what the organization aims to achieve, then works backward to identify required benefits, business changes, enabling changes, and IT enablers. Starting with investment objectives ensures that all downstream elements directly support strategic goals. Beginning with IT enablers represents a technology-driven rather than outcome-driven approach. Starting with business changes or enabling changes puts tactics before strategy and risks implementing changes not clearly linked to objectives.
4. A multinational corporation evaluates its IT investment portfolio and discovers the following distribution: 72% allocated to Run activities, 18% to Grow activities, and 10% to Transform activities. The CIO reviews this against Gartner recommendations for achieving competitive advantage. Which action should the CIO recommend FIRST? (Select one!)
Explanation
Gartner recommends an optimal Run-Grow-Transform mix of 50:25:25 to balance operational stability with innovation and growth. The current distribution of 72:18:10 is heavily weighted toward Run activities, limiting strategic value creation. The CIO should reduce Run spending through efficiency improvements and reallocate funds to Transform investments, which drive innovation and competitive advantage. While operational stability is important, the current 72% allocation exceeds necessary levels. Simply increasing Grow while maintaining other levels does not address the fundamental imbalance. Eliminating Transform investments would prevent innovation and competitive positioning, making it the worst option for long-term enterprise success.
5. A financial institution is implementing BAI09 Managed Assets to track IT asset lifecycle. During asset retirement, decommissioned servers containing customer financial data are disposed without data sanitization verification. Which lifecycle stage requires strengthened governance controls? (Select one!)
Explanation
Retirement and Disposal stage is correct because the specific control failure occurred during decommissioning when data sanitization was not verified before disposal. This stage requires formal processes for data destruction, environmental disposal compliance, and disposal verification documentation. Planning and Acquisition set requirements but do not address the disposal failure. Deployment encryption protects data during use but not at disposal. Operation and Maintenance monitor active assets, not retired equipment. The governance gap exists specifically in retirement procedures that failed to verify sanitization before physical disposal.
Certified Cybersecurity Operations Analyst (CCOA)
CCOA · 593 questions
Certified Data Privacy Solutions Engineer (CDPSE)
CDPSE · 749 questions
Certified in Risk and Information Systems Control (CRISC)
CRISC · 761 questions
Certified Information Security Manager (CISM)
CISM · 1196 questions
Certified Information Systems Auditor (CISA)
CISA · 895 questions
Cloud Fundamentals Certificate
Cloud-Fund · 600 questions
$17.99
One-time access to this exam