Skip to content

CITM-001 Certified Information Technology Manager Practice Questions

Prepare for CITM-001 with more than an answer.

266 questions in the full set20 sample questionsUpdated Aug 11, 2025
Exam fee
$190 USD
Level
Professional
Valid for
Lifetime
Domains covered on the exam 9
  1. IT Workplace Foundations12%
  2. Information Interpretation and Management10%
  3. Business IT Frameworks15%
  4. Corporate IT Strategy13%
  5. Management Control12%
  6. IT and Globalization8%
  7. Software and Database Technologies10%
  8. Database Management10%
  9. Information Systems Design10%
  1. 1

    A university is implementing a new campus-wide Wi-Fi network. The IT manager's primary security concern is preventing unauthorized devices from connecting. Which security mechanism provides the MOST effective method for authenticating devices to the network?

    Show answer details

    Correct answer: D

    WPA2-Enterprise with 802.1X is the gold standard for enterprise network authentication. Unlike a shared password (PSK), it requires each user or device to have unique credentials, which are authenticated against a central directory (like Active Directory) via a RADIUS server. This allows for granular control, individual access revocation, and robust security against unauthorized access. MAC filtering and hiding the SSID are easily circumvented and are not considered strong security measures.

  2. 2

    True or False: According to ITIL 4, a 'change' is defined as the addition, modification, or removal of anything that could have a direct or indirect effect on services, while an 'incident' is an unplanned interruption to a service or reduction in the quality of a service.

    Show answer details

    Correct answer: A

    This statement accurately reflects the official ITIL 4 definitions. A 'change' is a planned activity to alter a service or component, managed through Change Enablement/Control. An 'incident' is an unplanned event that disrupts service and must be resolved as quickly as possible through Incident Management. Understanding this fundamental distinction is critical for effective IT Service Management.

  3. 3

    Case Study:

    A regional bank, 'SecureTrust Bank', is facing increasing pressure from regulators to improve its cybersecurity posture and disaster recovery capabilities. An internal audit revealed several critical vulnerabilities: inconsistent server patching, no centralized logging system, and a disaster recovery plan that has not been tested in over two years. The bank's core banking system runs on a mix of physical and virtualized servers in a single on-premises data center.

    The CIO has tasked the IT Manager with developing a comprehensive plan to address these issues within a 12-month timeframe. The budget is constrained, so solutions must be cost-effective. The primary objectives are to improve the bank's Recovery Time Objective (RTO) to under 4 hours, achieve a Recovery Point Objective (RPO) of 1 hour, and implement continuous security monitoring.

    Given the constraints and objectives, which of the following plans represents the MOST effective and pragmatic approach?

    Show answer details

    Correct answer: C

    This plan is the most effective and pragmatic. DRaaS is a cost-effective way to achieve aggressive RTO/RPO targets without the massive capital expenditure of building a secondary data center. Cloud-native SIEM solutions are typically faster to deploy and more scalable than on-premises alternatives, addressing the logging requirement efficiently. This frees up budget to tackle the critical patching issue with an automated tool. This approach addresses all key objectives within a reasonable budget and timeframe by leveraging cloud services.

  4. 4

    Which of the following describes the relationship between data, information, and knowledge in a business context?

    Show answer details

    Correct answer: C

    This option correctly describes the hierarchical relationship often depicted in the DIKW (Data, Information, Knowledge, Wisdom) pyramid. Data consists of raw facts (e.g., sales figures). When this data is processed and put into context (e.g., sales figures by region and quarter), it becomes information. When this information is understood, synthesized with experience, and used for decision-making (e.g., identifying a sales trend and launching a targeted marketing campaign), it becomes knowledge.

  5. 5

    An e-commerce company needs to protect sensitive customer data, such as credit card numbers, stored in its database. The company must comply with PCI DSS, which requires that stored cardholder data be unreadable. The data is frequently used by a payment processing application but should not be viewable by database administrators. Which data protection technique is most appropriate?

    graph TD subgraph DataProtection A[Application] --> B{Data Access} B -->|Write| C[Database] B -->|Read| C D[DB Administrator] -.-x|Direct Access Blocked| C end

    Show answer details

    Correct answer: B

    Application-level encryption is the most appropriate solution. The application encrypts the data before writing it to the database and decrypts it after reading. This means the data at rest in the database is always encrypted and unreadable, even to a database administrator with full privileges. The encryption keys are managed by the application, not the database, providing a strong separation of duties. This meets the PCI DSS requirement to render data unreadable and protects it from privileged database users.

  6. 6

    An IT Manager at a global logistics company is tasked with implementing a unified communication platform for teams spread across North America, Europe, and Asia. The primary challenge is ensuring regulatory compliance with data sovereignty laws like GDPR in Europe. Which strategy best addresses this challenge while maintaining a seamless user experience?

    Show answer details

    Correct answer: C

    This is the optimal solution. A platform with federated architecture and geo-fencing capabilities directly addresses data sovereignty requirements like GDPR by ensuring data is stored within a specific geographic region (the EU). This meets compliance mandates without fragmenting the user experience, as federation allows different regional instances to communicate securely. A centralized US deployment would violate GDPR. End-to-end encryption protects data in transit but does not address data residency requirements. Deploying separate, isolated platforms would create a fragmented user experience and hinder cross-regional collaboration.

  7. 7

    A financial services firm is evaluating a Business Process Outsourcing (BPO) partner for its customer support operations. As the IT Manager, you are responsible for the technical due diligence. Which of the following are the MOST critical security certifications to verify in the potential partner to ensure protection of sensitive customer financial data? (Select TWO)

    Show answer details

    Correct answer: B, C

    A SOC 2 Type II report is crucial as it audits the operational effectiveness of a service organization's security, availability, processing integrity, confidentiality, and privacy controls over a period of time. This provides assurance that the vendor's security practices are not just designed well, but are also functioning effectively.

    The Payment Card Industry Data Security Standard (PCI DSS) is mandatory for any organization that stores, processes, or transmits cardholder data. Since the firm is in financial services, ensuring the BPO partner is PCI DSS compliant is non-negotiable for protecting payment information.

  8. 8

    An IT Manager is designing a new data center network to support a high-performance computing (HPC) cluster and standard enterprise applications. The key requirements are extremely low latency for the HPC traffic and logical segmentation from the enterprise traffic. Which network topology should be implemented?

    Show answer details

    Correct answer: B

    A spine-and-leaf architecture is the industry standard for modern data centers, especially those requiring low latency and high east-west traffic bandwidth, which is characteristic of HPC clusters. Every leaf switch is connected to every spine switch, ensuring that traffic is always only two hops away from its destination. This design provides predictable low latency and high throughput, making it ideal for the HPC requirement. Logical segmentation can then be achieved using technologies like VLANs or VXLANs.

    graph TD subgraph Spine Layer S1[Spine 1] S2[Spine 2] end subgraph Leaf Layer L1[Leaf 1] L2[Leaf 2] L3[Leaf 3] end L1 -- all links -- S1 L1 -- all links -- S2 L2 -- all links -- S1 L2 -- all links -- S2 L3 -- all links -- S1 L3 -- all links -- S2 subgraph Servers HPC1 & HPC2 --> L1 APP1 & APP2 --> L2 DB1 & DB2 --> L3 end
  9. 9

    A company is developing its corporate IT strategy. The executive board has prioritized 'improving customer experience' as the number one business goal for the next two years. As the IT Manager, which of the following IT initiatives provides the MOST direct strategic alignment with this goal?

    Show answer details

    Correct answer: C

    A CRM platform is specifically designed to manage and analyze customer interactions and data throughout the customer lifecycle. Implementing a new, integrated CRM directly supports the goal of improving customer experience by providing a 360-degree view of the customer, enabling personalized service, and streamlining communication across sales, marketing, and support teams. The other options are valuable IT initiatives but are less directly aligned with the specific business goal of enhancing customer experience.

  10. 10

    True or False: In the context of enterprise architecture, the Zachman Framework is primarily a prescriptive methodology that dictates the specific steps for creating an architecture.

    Show answer details

    Correct answer: B

    The statement is false. The Zachman Framework is an ontology or a taxonomy, not a prescriptive methodology. It provides a structured way of viewing and defining an enterprise from different perspectives (e.g., Planner, Owner, Designer) and across different interrogatives (What, How, Where, Who, When, Why). It describes the artifacts to create but doesn't prescribe the process for creating them. Frameworks like TOGAF are process-oriented and prescriptive.

Create an account to continue.