IT Environment and Governance Flashcards
7 cards from real CMA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 IT Environment and Governance flashcards as text
Which IT environment model uses a shared pool of configurable computing resources accessible over a network on demand?
Answer: Cloud computing
Cloud computing is defined by NIST as on-demand network access to a shared pool of configurable resources including servers, storage, and applications.
A master architect must choose between a public, private, and hybrid cloud. For a financial institution requiring strict data sovereignty, which model is most appropriate?
Answer: Private cloud or hybrid cloud with on-premises control
A private or hybrid cloud model gives financial institutions direct control over data residency, meeting regulatory data sovereignty requirements.
In an IaaS (Infrastructure as a Service) model, which layer remains the customer's responsibility?
Answer: Operating system, middleware, and application stack
In IaaS, the provider manages physical hardware and virtualization; the customer is responsible for OS, middleware, runtime, and applications.
What is 'shadow IT' and why is it a governance concern?
Answer: Technology deployed by business units without IT department approval or knowledge
Shadow IT refers to systems deployed outside of IT governance, creating security, compliance, and integration risks unknown to the enterprise.
Which metric best measures the effectiveness of an IT governance framework?
Answer: Degree to which IT goals are aligned and measured against business outcomes
Effective IT governance is measured by how well IT outcomes align with and contribute to business objectives, not just operational efficiency.
A master architect is evaluating a DevSecOps implementation. Which governance principle does this practice best embody?
Answer: Integrating security controls into the development lifecycle from the start
DevSecOps embeds security governance directly into CI/CD pipelines, making security a continuous, integrated activity rather than a post-development gate.
Which of the following best describes the concept of 'zero trust' in IT environment governance?
Answer: Never trusting any user or device by default, requiring continuous verification
Zero trust architecture assumes no implicit trust based on network location and requires continuous verification of every user, device, and connection.