IIA-CIA-Part3-KR 문제 186
An intranet is a private network used by an organization for internal communication and information sharing among employees. It is accessible only to authorized personnel within the company.
Option A (Extranet) - Allows external parties (e.g., suppliers, partners) to access limited information.
Option B (LAN) - Refers to a network infrastructure rather than controlled access.
Option D (Internet) - Is public and not restricted to internal personnel.
Thus, Option C (Intranet) is the correct answer as it ensures access only to organizational personnel.
Reference: IIA IT Security - Network Access Controls
IIA-CIA-Part3-KR 문제 187
Data Processing in Accordance with Consent (Correct Choice: B)
IIA Standard 2110 - Governance requires internal auditors to assess whether the organization has effective processes for ensuring compliance with laws and regulations, including data privacy obligations.
GDPR Article 5(1)(b) (Purpose Limitation Principle) mandates that personal data must be collected for specified, explicit, and legitimate purposes and must not be further processed in a manner incompatible with those purposes.
Internal auditors should verify that the organization adheres to this principle by ensuring that data is only used for the purpose for which consent was granted.
Why the Other Options Are Incorrect:
Option A: "Whether customers are asked to renew their consent for their data processing at least quarterly." (Incorrect) GDPR does not mandate a quarterly renewal of consent. Instead, it requires that consent be freely given, specific, informed, and unambiguous. Periodic renewal may be advisable in some cases, but it is not a strict regulatory requirement.
IIA Standard 2120 - Risk Management requires auditors to evaluate compliance risk exposure, but excessive consent renewals could lead to inefficiencies without adding value.
Option C: "Whether the organization has established explicit and entitywide policies on data transfer to third parties." (Incorrect) While data transfer policies are critical (as required under GDPR Articles 44-50 on international data transfers), they do not directly relate to the opt-in/opt-out process or consent management.
IIA Standard 2201 - Engagement Planning encourages reviewing policies, but the key focus should be on processing data according to the purpose of consent.
Option D: "Whether customers have an opportunity to opt-out the right to be forgotten from organizational records and systems." (Incorrect) The right to be forgotten (GDPR Article 17) allows individuals to request data deletion, but it is not an opt-out feature in the traditional sense. Organizations must evaluate each request based on legal grounds before erasing data.
IIA Standard 2130 - Compliance requires verifying whether the organization ensures compliance with data privacy rights, but an opt-out for the right to be forgotten is not a primary audit focus.
IIA Standard 2110 - Governance (Ensuring regulatory compliance)
IIA Standard 2120 - Risk Management (Managing data privacy risks)
IIA Standard 2130 - Compliance (Reviewing legal obligations on personal data) IIA Standard 2201 - Engagement Planning (Evaluating policies and controls) GDPR Article 5(1)(b) - Purpose Limitation Principle (Processing data as per consent) GDPR Articles 17, 44-50 (Data protection and right to be forgotten considerations) Step-by-Step Justification for the Answer:IIA References for This Answer:Thus, Option B is the correct choice as it aligns with the purpose limitation principle and internal audit's role in assessing compliance with data protection laws.
IIA-CIA-Part3-KR 문제 188
Option A exaggerates benefits of a flat structure. Option B is incorrect because hierarchical structures require more-not less-supervision. Option C is misleading because flat structures typically limit growth opportunities due to fewer layers of promotion.
Reference:
IIA Practice Guide - Organizational Governance in Internal Audit.
IIA-CIA-Part3-KR 문제 189
A router is responsible for connecting multiple networks together and directing data packets between them. It determines the best path for data to travel using IP addresses.
A switch, on the other hand, operates within a single network and connects devices like computers, printers, and servers. It uses MAC addresses to forward data within the local network (LAN).
A). A router operates at layer two, while a switch operates at layer three of the OSI model - Incorrect. A switch operates at Layer 2 (Data Link Layer), while a router operates at Layer 3 (Network Layer).
B). A router transmits data through frames, while a switch sends data through packets - Incorrect. Switches use frames at Layer 2, while routers use packets at Layer 3.
C). A router connects networks, while a switch connects devices within a network (Correct Answer) - This correctly differentiates their functions.
D). A router uses a media access control (MAC) address during the transmission of data, while a switch uses an internet protocol (IP) address - Incorrect. A switch uses MAC addresses, and a router uses IP addresses.
IIA GTAG 17 - Auditing IT Governance discusses network security and the role of routers and switches.
COBIT 2019 - DSS01 (Managed Operations) emphasizes secure and efficient network management.
NIST SP 800-53 - Security Controls for IT Systems includes guidelines on network architecture and device functionality.
Explanation of Each Option:IIA References:
IIA-CIA-Part3-KR 문제 190
Understanding the Concern:
Internal auditors must assess risks when using free software for data analysis, particularly regarding data security, confidentiality, and integrity.
When analyzing third-party vendor data, the primary risk is data compromise, unauthorized access, or data loss due to inadequate security controls in free software.
Why Data Security is the Biggest Concern:
Free software often lacks robust security measures, making sensitive vendor data susceptible to breaches, cyberattacks, or loss.
Ensuring compliance with data protection regulations (e.g., GDPR, CCPA) and contractual obligations with third-party vendors is critical.
Why Other Options Are Incorrect:
A). The ability to use the software with ease # While usability is important, security risks outweigh ease of use in an internal audit context.
B). The ability to purchase upgraded features # Upgrades may improve analysis capabilities but do not address security concerns.
D). The ability to download the software # Installing software is a technical issue, not a major audit concern compared to security.
IIA Standards and References:
IIA Standard 2110 - Governance: Internal auditors should ensure data security risks are addressed in technology use.
IIA Standard 2120 - Risk Management: Auditors must evaluate the organization's ability to safeguard data.
IIA GTAG (Global Technology Audit Guide) on Data Analytics (2017): Recommends ensuring security of third-party data when using analytical tools.
Thus, the correct answer is C: The ability to ensure that big data entered into the software is secure from potential compromises or loss.
- 다른 버전
- 1817IIA.IIA-CIA-Part3-KR.v2026-08-19.q374
- 1780IIA.IIA-CIA-Part3-KR.v2026-02-16.q207
- 2750IIA.IIA-CIA-Part3-KR.v2025-04-09.q203
- 최근 업로드
- 174Oracle.1Z1-171.v2026-09-06.q38
- 179SAP.C_S4TM.v2026-09-06.q71
- 177Oracle.1Z0-1054-26.v2026-09-06.q65
- 219Huawei.H12-831_V1.0.v2026-09-06.q231
- 150Salesforce.Plat-Arch-205.v2026-09-06.q28
- 177Salesforce.Plat-Arch-203.v2026-09-06.q90
- 144Oracle.1Z0-1050-26.v2026-09-05.q19
- 230Salesforce.Manufacturing-Cloud-Professional.v2026-09-05.q111
- 250EXIN.ITILFND_V4.v2026-09-05.q129
- 264Citrix.1Y0-312.v2026-09-05.q182
PDF 파일 다운로드
메일 주소를 입력하시고 다운로드 하세요. IIA.IIA-CIA-Part3-KR.v2026-05-02.q255 모의시험 시험자료를 다운 받으세요.
