IIA-CIA-Part3-KR 문제 126
Encryption & Secure Communication: VPNs use strong encryption protocols (e.g., AES-256) to protect data from unauthorized access.
Restricted Access Control: Users must authenticate through a secure VPN gateway, reducing the risk of unauthorized access.
Compliance with IT Security Standards: VPNs are recommended by security frameworks such as NIST 800-
53, ISO 27001, and CIS Critical Security Controls.
Option B (Logging devices that access the network, including date, time, and user identity): Logging is important for monitoring but does not prevent unauthorized access-it only records it after the fact.
Option C (Tracking all mobile device physical locations and banning access from non-designated areas):
Geofencing can help restrict access but is not as secure as a VPN, and attackers could spoof locations.
Option D (Permitting only authorized IT personnel to have administrative control of mobile devices): While restricting administrative control is good practice, it does not prevent unauthorized users from connecting to the network.
IIA's GTAG on IT Security & Cybersecurity Risks highlights VPNs as a critical security measure to prevent unauthorized access.
ISO 27001 (Annex A.13) - Network Security Management recommends encrypting data transmissions to secure wireless network access.
NIST 800-53 (SC-12, SC-13, SC-28) emphasizes using VPNs for secure remote and wireless network access.
Why Option A is Correct (VPN):Why Other Options Are Incorrect:IIA References:Thus, the most appropriate answer is A. Allowing access to the organization's network only through a virtual private network (VPN).
IIA-CIA-Part3-KR 문제 127
Understanding Decentralized Organizational Structures
A decentralized organization distributes decision-making authority to lower levels of management and employees rather than concentrating power at the top.
This structure requires a strong organizational culture to ensure alignment with company goals since direct oversight is reduced.
Why Option A is Correct?
Higher reliance on organizational culture is necessary in decentralized organizations because:
Employees must make independent decisions that align with company values and objectives.
Leaders trust teams to operate autonomously, which requires a shared sense of mission and ethics.
IIA Standard 2110 - Governance emphasizes the importance of corporate culture in managing risks within decentralized structures.
Decentralization requires informal controls like culture, rather than rigid policies and electronic monitoring.
Why Other Options Are Incorrect?
Option B (Clear expectations set for employees):
While clear expectations are important, they are common in both centralized and decentralized structures and do not distinguish decentralization.
Option C (Electronic monitoring techniques employed):
Centralized organizations are more likely to use electronic monitoring for control. Decentralized structures rely more on trust and culture.
Option D (Defined code for employee behavior):
Both centralized and decentralized organizations have codes of conduct, but culture plays a stronger role in decentralized settings.
Decentralized organizations rely on strong corporate culture to ensure employees make decisions aligned with organizational goals.
IIA Standard 2110 supports corporate culture as a key element in governance and risk management.
Final Justification:IIA References:
IPPF Standard 2110 - Governance (Corporate Culture & Risk Management)
COSO ERM Framework - Culture & Decision-Making in Decentralized Structures
IIA-CIA-Part3-KR 문제 128
A). Firewall (Correct Answer) - Firewalls prevent unauthorized access by filtering traffic, blocking malicious connections, and securing the network perimeter.
B). Encryption - While encryption protects data confidentiality, it does not actively prevent unauthorized access to a network.
C). Antivirus - Antivirus software protects against malware and viruses but does not prevent unauthorized network access.
D). Biometrics - Biometrics controls physical or logical access (e.g., fingerprint authentication) but does not secure a network from external threats.
IIA GTAG 15 - Information Security Governance highlights firewalls as a critical security control for network protection.
IIA IPPF Standard 2110 - Governance emphasizes the need for network security policies that include firewalls.
NIST SP 800-41 Rev. 1 - Guidelines on Firewalls and Firewall Policy states that firewalls are the first line of defense in securing organizational networks.
Explanation of Each Option:IIA References:
IIA-CIA-Part3-KR 문제 129
* Why Option B (Overhead costs, direct labor, direct materials) is Correct:
* Direct materials: Raw materials used directly in production (e.g., wood for furniture).
* Direct labor: Labor costs directly tied to production (e.g., factory workers assembling a product).
* Manufacturing overhead: Indirect costs related to production (e.g., depreciation, factory utilities, maintenance).
* These categories align with GAAP, IFRS, and cost accounting standards.
* Why Other Options Are Incorrect:
* Option A (Direct materials, indirect materials, raw materials):
* "Indirect materials" and "raw materials" are part of manufacturing overhead and direct materials, respectively, but do not form a primary cost classification.
* Option C (Direct materials, direct labor, depreciation on factory buildings):
* Depreciation on factory buildings is an overhead cost, not a separate category.
* Option D (Raw materials, factory employees' wages, production selling expenses):
* Selling expenses are not part of manufacturing costs; they are part of operating expenses.
* IIA Practice Guide - Auditing Cost Management: Defines manufacturing cost classifications.
* IFRS & GAAP Cost Accounting Standards: Outline manufacturing cost components.
* COSO Framework - Cost Control Guidelines: Emphasizes accurate cost allocation in financial reporting.
IIA References:
IIA-CIA-Part3-KR 문제 130
- 최근 업로드
- 108TheBerylInstitute.CPXP.v2026-06-06.q56
- 129ACAMS.CAMS7-KR.v2026-06-05.q213
- 151PaloAltoNetworks.XSIAM-Analyst.v2026-06-04.q72
- 127NLN.NEX.v2026-06-04.q54
- 176Microsoft.AZ-500-KR.v2026-06-04.q213
- 157Microsoft.DP-600-KR.v2026-06-04.q98
- 181Microsoft.AZ-204-KR.v2026-06-04.q237
- 158Microsoft.PL-600-KR.v2026-06-04.q112
- 220Microsoft.SC-300-KR.v2026-06-03.q151
- 182Microsoft.DP-600-KR.v2026-06-03.q70
PDF 파일 다운로드
메일 주소를 입력하시고 다운로드 하세요. IIA.IIA-CIA-Part3-KR.v2026-05-02.q255 모의시험 시험자료를 다운 받으세요.
