ISACA · CGEIT
Executive-level enterprise IT governance practice across governance, resources, benefits realization, and risk optimization.
Practice Questions
598
≈ 3 practice exams
Duration
240 minutes
Passing Score
450/800
Difficulty
ProfessionalLast Updated
Oct 2026
CGEIT tests governance decisions at enterprise level, not day-to-day technology administration. The current outline weights Governance of Enterprise IT at 40%, IT Resources at 15%, Benefits Realization at 26%, and Risk Optimization at 19%, with scenarios framed around value, accountability, alignment, investment, and risk.
The exam contains 150 multiple-choice questions in four hours. ISACA reports results on a 200-800 scale and requires 450 to pass. Registration is continuous through PSI, remotely or at a test center, and costs $575 for members or $760 for nonmembers; eligibility lasts six months after registration.
Anyone may take the exam, but passing it is only the first certification step. To apply for CGEIT, you need five years of qualifying governance experience across at least three domains, including at least one year in Domain 1, then a $50 application. Use these 598 questions to practise choosing the governance action that best serves enterprise objectives rather than the most technical answer.
CGEIT is ISACA's framework-agnostic certification for governance of enterprise IT. It validates the ability to establish and maintain governance, align technology with enterprise direction, manage resources and investments, realise benefits, and optimise IT-related risk at an executive and board-facing level.
The credential is intended for experienced governance leaders, executives, directors, enterprise architects, advisers, consultants, and oversight professionals who help boards and senior management direct, evaluate, and monitor the contribution of technology to enterprise objectives.
Anyone may take the exam. Certification requires at least five years of qualifying governance work across three or more CGEIT domains, including at least one year related to Domain 1, within the 10 years before application. Candidates have five years after passing to apply.
CGEIT has 150 multiple-choice questions in four hours and uses a 200-800 scaled score with 450 required to pass. ISACA delivers it continuously through PSI at test centers or by remote proctoring. The exam costs $575 for members or $760 for nonmembers; the later certification application costs $50.
CGEIT validates senior governance capability for roles that advise boards and executives on technology value, resources, performance, and risk. Maintaining the designation requires at least 20 CPE hours annually, 120 over three years, annual fees, and compliance with ISACA policies.
5 sample questions with answers and explanations. The full bank has 598 questions, enough for 3 full-length practice exams.
Preview — answers shown1. A board of directors implements ISO/IEC 38500 for IT governance. The board evaluates an emerging AI strategy, directs management to implement cloud-first architecture, and monitors quarterly IT investment performance. Which ISO/IEC 38500 principle is MOST directly addressed by monitoring the reliability and efficiency of cloud services? (Select one!)
Explanation
Performance principle focuses on ensuring IT systems perform reliably, efficiently, and are fit for purpose. Monitoring cloud service reliability and efficiency directly evaluates whether IT systems meet performance expectations. Responsibility addresses understanding and accepting IT-related responsibilities. Strategy focuses on business alignment of IT strategies. Conformance addresses compliance with laws and regulations rather than operational performance metrics.
2. A telecommunications company develops an IT Balanced Scorecard to measure governance effectiveness. Which metrics correctly align with the Corporate Contribution perspective? (Select two!)
Multiple correct answersExplanation
The Corporate Contribution perspective focuses on IT's financial value and strategic contribution to the enterprise. IT operating costs as percentage of revenue measures cost efficiency and resource optimization at the enterprise level. Return on IT investments directly measures financial value creation across business units. Mean time to resolve incidents belongs to the Operational Excellence perspective measuring process efficiency. User satisfaction scores align with the Customer Orientation perspective measuring stakeholder satisfaction. Staff training metrics belong to the Future Orientation perspective measuring learning and innovation capability.
3. A technology company implements COBIT maturity assessment for EDM processes. The assessment reveals: EDM01 at Level 3 (Defined), EDM02 at Level 1 (Initial), EDM03 at Level 2 (Managed), EDM04 at Level 2 (Managed), and EDM05 at Level 3 (Defined). Which governance area requires the MOST urgent improvement? (Select one!)
Explanation
EDM02 Ensured Benefits Delivery at Level 1 (Initial/Ad Hoc) represents the lowest maturity level, indicating benefits realization processes are incomplete and intuitive without systematic approaches. This creates the highest governance risk as IT investments may fail to deliver expected business value. EDM01 and EDM05 at Level 3 indicate established processes. EDM03 and EDM04 at Level 2 show managed processes with basic planning and monitoring, which are less critical than the incomplete benefits delivery capability.
4. A manufacturing company implements cloud service governance. The organization deploys ERP as SaaS, development platforms as PaaS, and backup storage as IaaS. For which service model does the organization retain the MOST governance responsibility for security controls? (Select one!)
Explanation
IaaS provides the most control and therefore the most governance responsibility because the organization manages operating systems, applications, data, and security configurations on top of the infrastructure. With IaaS backup storage, the organization is responsible for access controls, encryption, data classification, and security configurations. PaaS reduces control as the provider manages the underlying platform and some security controls. SaaS provides the least control with the vendor managing applications, platforms, and most security controls, limiting organizational governance to user access and data protection policies.
5. An IT Steering Committee evaluates three proposals: implementing DevOps practices, upgrading ERP systems, and piloting blockchain for supply chain. The CIO requests approval for an exception to use a non-standard database technology for the blockchain pilot. Who should approve this architecture exception? (Select one!)
Explanation
IT Architecture Review Board is specifically responsible for enforcing architecture compliance and evaluating exception or dispensation requests against established technology standards. This body has the technical expertise and mandate to assess whether deviations from standards are justified. IT Steering Committee handles operational priorities and project approvals, not technical architecture exceptions. IT Strategy Committee operates at board level for strategic direction. While CTO may participate in architecture decisions, the formal governance structure assigns exception approval to the Architecture Review Board.
The CGEIT exam has 150 multiple-choice questions and allows four hours.
ISACA reports a scaled score from 200 to 800 and requires 450 to pass.
Governance of Enterprise IT is 40%, IT Resources 15%, Benefits Realization 26%, and Risk Optimization 19%.
ISACA lists $575 for members and $760 for nonmembers. The certification application after passing costs another $50.
Yes, but certification requires five years of qualifying governance experience across at least three domains, including one year in Domain 1.
Holders must report at least 20 CPE hours annually and 120 over three years, pay annual maintenance fees, and follow ISACA policies.
Certified Cybersecurity Operations Analyst (CCOA)
CCOA · 593 questions
Certified Data Privacy Solutions Engineer (CDPSE)
CDPSE · 749 questions
Certified in Risk and Information Systems Control (CRISC)
CRISC · 761 questions
Certified Information Security Manager (CISM)
CISM · 1196 questions
Certified Information Systems Auditor (CISA)
CISA · 895 questions
Cloud Fundamentals Certificate
Cloud-Fund · 600 questions
$17.99
One-time access to this exam