โ† All CMA Flashcard Decks

IT Environment and Governance Flashcards

7 cards from real CMA practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 IT Environment and Governance flashcards as text
  1. What is the primary purpose of a Configuration Management Database (CMDB) in IT governance?

    Answer: Tracking IT assets and their relationships to support change and incident management

    A CMDB maintains records of IT configuration items (CIs) and their interdependencies, enabling informed change management, impact analysis, and incident resolution.

  2. An enterprise has multiple disparate legacy systems. Which architectural approach best supports IT governance by providing a unified integration layer?

    Answer: Enterprise Service Bus (ESB) or API management platform

    An ESB or API management platform centralizes integration, enabling governance of data flows, versioning, and access control across heterogeneous systems.

  3. Under SOX (Sarbanes-Oxley) compliance, what must a master architect ensure regarding financial IT systems?

    Answer: Adequate internal controls over financial reporting processes are designed and documented

    SOX Section 404 requires organizations to document and test internal controls over financial reporting, which includes the IT systems that process financial data.

  4. Which IT governance practice directly reduces the risk of a single point of failure in critical enterprise systems?

    Answer: Implementing high-availability and redundancy architectures

    High-availability designs with redundancy (clustering, failover, load balancing) eliminate single points of failure and improve system resilience.

  5. A master architect is asked to define IT risk appetite for the organization. What does 'risk appetite' mean in this context?

    Answer: The level of risk the organization is willing to accept in pursuit of its objectives

    Risk appetite defines how much risk an organization is willing to accept before taking action, guiding investment in controls and risk treatment decisions.

  6. What is the difference between IT risk management and IT risk governance?

    Answer: Risk management is operational execution; risk governance sets policies, oversight, and accountability structures

    IT risk governance establishes the policies, roles, and oversight structures, while IT risk management involves the day-to-day identification, assessment, and treatment of risks.

  7. Which of the following is a best practice for managing technical debt within an IT governance framework?

    Answer: Tracking, prioritizing, and scheduling remediation of technical debt as part of the architecture roadmap

    Effective governance treats technical debt as a managed liability, tracked in the architecture backlog and addressed through scheduled remediation efforts.