IIA-CIA-Part3-KR 문제 226
(A) Providing fire detection and suppression equipment. #
Correct. This is a direct physical security control that helps mitigate fire risks by detecting and suppressing fires.
IIA GTAG "Physical Security and IT Asset Protection" identifies fire detection as an essential physical security measure.
(B) Establishing a physical security policy and promoting it throughout the organization. # Incorrect. A policy is an administrative control, not a physical control. While important, it does not provide direct physical protection.
(C) Performing business continuity and disaster recovery planning. #
Incorrect. This is a procedural control, not a physical one. Planning for disasters does not physically secure assets but instead prepares an organization for recovery.
(D) Keeping an offsite backup of the organization's critical data. #
Incorrect. This is an IT security control, ensuring data availability rather than physically protecting assets.
IIA GTAG - "Physical Security and IT Asset Protection"
IIA Standard 2110 - Governance (Risk Management Controls)
COBIT Framework - Physical and Environmental Security Controls
Analysis of Answer Choices:IIA References:Thus, the correct answer is A, as fire detection and suppression equipment provides direct physical protection against fire-related risks.
IIA-CIA-Part3-KR 문제 227
Understanding Default Password Security Risks:
Default passwords, especially predictable ones (e.g., "123456"), pose a security threat because they are easy to guess.
If an unauthorized user gains access before the legitimate user changes the password, data confidentiality and integrity may be compromised (IIA GTAG - Global Technology Audit Guide).
Evaluating the Window of Exposure:
The primary concern is the time between account creation and password reset.
During this time, an attacker could exploit the default password to gain unauthorized access to sensitive systems.
Why Other Options Are Less Relevant:
Option A (Replacing numbers with characters) - While this improves security, it does not directly address the risk of an attacker exploiting the default password before the user resets it.
Option B (Users continuing to use the initial password) - This is a security issue, but it is mitigated by requiring a password reset upon first login. The primary concern is the time before the reset happens.
Option D (User training on password management) - While training is crucial for long-term security, it does not directly address the immediate vulnerability of default passwords before they are changed.
IIA Global Technology Audit Guide (GTAG) 16: Data Management and Security IIA Standard 2110 - Governance: Recommends addressing IT security risks, including credential management.
IIA Practice Advisory 2130.A1-1: Internal auditors should assess whether management has identified, assessed, and mitigated IT security risks, such as weak authentication practices.
Step-by-Step Analysis:Relevant IIA References:
IIA-CIA-Part3-KR 문제 228
Highly centralized decision-making
Strict hierarchy and formalized job roles
Low flexibility and innovation
Heavy reliance on formal policies, procedures, and direct supervision
(A) Primary direction of communication tends to be lateral.
Incorrect: Mechanistic structures favor vertical communication (top-down or bottom-up), not lateral (horizontal) communication.
IIA Standard 2110 - Governance emphasizes clear roles and responsibilities, which are strictly followed in mechanistic structures.
(B) Definition of assigned tasks tends to be broad and general.
Incorrect: In a mechanistic structure, tasks are specific, well-defined, and specialized, unlike in an organic structure where roles are more flexible.
COSO ERM - Control Environment highlights well-defined roles in structured environments.
(C) Type of knowledge required tends to be broad and professional.
Incorrect: Mechanistic structures rely on specialized and technical knowledge, not broad, generalized knowledge.
(D) Reliance on self-control tends to be low. (Correct Answer)
Mechanistic structures depend on external control mechanisms like supervision, rules, and formal procedures.
Employees have little autonomy, and self-control is not a primary governance mechanism.
IIA Standard 2200 - Engagement Planning stresses the importance of structure in ensuring compliance, aligning with mechanistic principles.
IIA Standard 2110 - Governance: Defines structured governance mechanisms in hierarchical organizations.
COSO ERM - Control Environment: Emphasizes reliance on formal controls in rigid structures.
GTAG 1 - Information Technology Risks and Controls: Highlights the need for structured controls in mechanistic environments.
Characteristics of a Mechanistic Structure:Analysis of Each Option:IIA References Supporting the Answer:
Thus, the correct answer is (D) because mechanistic organizations rely heavily on external controls rather than self-regulation.
IIA-CIA-Part3-KR 문제 229
Let's analyze each option:
Option A: Communication conflicts.
Incorrect.
Centralized structures generally have clear lines of authority and communication, reducing conflicts.
Communication conflicts are more common in decentralized structures where multiple decision-makers exist.
Option B: Slower decision making.
Correct.
Since all decisions must pass through top management, it delays responses to market changes and reduces flexibility.
Lower-level employees have less authority to make operational decisions, leading to bottlenecks.
IIA Reference: Internal auditors assess organizational governance, including decision-making efficiency in centralized vs. decentralized structures. (IIA Practice Guide: Organizational Governance) Option C: Loss of economies of scale.
Incorrect.
Centralization improves economies of scale by standardizing processes and consolidating resources.
Decentralization (not centralization) is more likely to lead to duplication of efforts and a loss of economies of scale.
Option D: Vulnerabilities in sharing knowledge.
Incorrect.
Centralized organizations tend to have structured knowledge-sharing frameworks, such as standardized policies and corporate training programs.
IIA-CIA-Part3-KR 문제 230
- 다른 버전
- 1772IIA.IIA-CIA-Part3-KR.v2026-08-19.q374
- 1755IIA.IIA-CIA-Part3-KR.v2026-02-16.q207
- 2720IIA.IIA-CIA-Part3-KR.v2025-04-09.q203
- 최근 업로드
- 146Huawei.H12-351_V1.0.v2026-09-04.q76
- 776Cisco.300-435.v2026-09-03.q259
- 379Oracle.1Z0-1045-26.v2026-09-03.q17
- 675IIA.IIA-CIA-Part1.v2026-09-03.q627
- 535Fortinet.NSE6_OTS_AR-7.6.v2026-09-03.q95
- 514Snowflake.DAA-C01.v2026-09-03.q67
- 3517Salesforce.AP-223.v2026-09-01.q94
- 2627Splunk.SPLK-5001.v2026-09-01.q60
- 3954Cisco.300-540.v2026-09-01.q62
- 5198Microsoft.MS-102-KR.v2026-09-01.q239
PDF 파일 다운로드
메일 주소를 입력하시고 다운로드 하세요. IIA.IIA-CIA-Part3-KR.v2026-05-02.q255 모의시험 시험자료를 다운 받으세요.
