IIA-CIA-Part3-KR 문제 81
Access control methods are classified into three main authentication factors:
Something You Know - Passwords, PINs, security questions.
Something You Have - Physical devices like keycards, smart cards, or security tokens.
Something You Are - Biometrics such as fingerprints, retina scans, or voice recognition.
Why a Card-Key Scanner is the Correct Answer:
A card-key scanner verifies access using a physical card, which aligns with the " something you have " authentication factor.
Users must possess the key card to gain entry, making it a classic example of physical token-based security.
Why Other Options Are Incorrect:
A). A retina characteristics reader - Incorrect, as retina scans fall under " something you are " (biometrics), not
" something you have " .
B). A PIN code reader - Incorrect, as PIN codes are " something you know " , not a physical possession.
D). A fingerprint scanner - Incorrect, as fingerprints are biometric ( " something you are " ), not a physical object.
IIA's Perspective on Physical Security Controls:
IIA Standard 2110 - Governance emphasizes the importance of using multi-factor authentication to enhance security.
IIA GTAG (Global Technology Audit Guide) on Access Control recommends the use of physical security devices like card-key scanners to prevent unauthorized access.
ISO 27001 Information Security Standard identifies " something you have " authentication methods as critical components of access control.
IIA References:
IIA Standard 2110 - Governance & IT Security
IIA GTAG - Physical Security & Access Controls
ISO 27001 Information Security Standard - Multi-Factor Authentication
Thus, the correct and verified answer is C. A card-key scanner.
IIA-CIA-Part3-KR 문제 82
MBO is a performance management approach where employees and managers set specific, measurable goals together.
The main purpose of MBO is to align individual objectives with organizational goals, enhancing motivation and engagement.
Why Option C (Helps Keep Employees Motivated) Is Correct?
Employee motivation improves when individuals understand how their efforts contribute to the organization's success.
Setting clear objectives and allowing employees to participate in goal-setting increases job satisfaction and engagement.
IIA Standard 2120 - Risk Management supports frameworks like MBO that contribute to organizational performance and employee effectiveness.
Why Other Options Are Incorrect?
Option A (Most helpful in organizations with rapid changes):
MBO is less effective in rapidly changing environments because it relies on long-term goal setting.
Option B (Best in mechanistic organizations with rigid tasks):
MBO works better in adaptive, flexible organizations, not those with rigid structures.
Option D (Distinguishes strategic from operational goals):
MBO focuses on individual and team goals, not distinguishing strategic vs. operational goals.
MBO enhances employee motivation by involving them in goal-setting and performance tracking.
IIA Standard 2120 supports employee engagement strategies for better performance management.
Final Justification:IIA References:
IPPF Standard 2120 - Risk Management (Employee Engagement & Performance Management) COSO ERM - Performance Measurement & Goal Alignment
IIA-CIA-Part3-KR 문제 83
Why Option B (Monitoring for vulnerabilities based on industry intelligence) is Correct:
Continuous monitoring for vulnerabilities helps detect emerging threats, security breaches, and weaknesses in IT systems.
Uses threat intelligence feeds, security information and event management (SIEM) systems, and intrusion detection systems (IDS).
Helps organizations respond quickly to cyberattacks by identifying patterns, suspicious activity, or known vulnerabilities.
Why Other Options Are Incorrect:
Option A (A list of trustworthy, good traffic and a list of unauthorized, blocked traffic):
Incorrect because this describes a whitelisting/blacklisting technique, which is a preventive control, not a detective control.
Option C (Comprehensive service level agreements with vendors):
Incorrect because service level agreements (SLAs) ensure contractual obligations, but do not detect security threats.
Option D (Firewall and other network perimeter protection tools):
Incorrect because firewalls are preventive controls, designed to block unauthorized access, not detect threats after they occur.
IIA GTAG - "Auditing Cybersecurity Risks": Discusses detective controls such as vulnerability monitoring and threat intelligence.
COBIT 2019 - DSS05 (Manage Security Services): Recommends continuous monitoring for cyber threats as a detective control.
NIST Cybersecurity Framework - Detect Function: Highlights vulnerability management and threat monitoring as key detective measures.
IIA References:Thus, the correct answer is B. Monitoring for vulnerabilities based on industry intelligence.
IIA-CIA-Part3-KR 문제 84
(A) Estimate time required to complete the whole project.
Incorrect: Time estimation comes after breaking the project into smaller tasks.
(B) Determine the responses to expected project risks.
Incorrect: Risk management is important but is planned after defining project tasks and scope.
(C) Break the project into manageable components. (Correct Answer)
Dividing the project into smaller tasks (WBS) helps in resource allocation, scheduling, and risk assessment.
IIA GTAG 12 - Project Risk Management suggests using WBS to define tasks clearly.
(D) Identify resources needed to complete the project.
Incorrect: Resources can only be allocated effectively after defining project components.
IIA GTAG 12 - Project Risk Management: Recommends Work Breakdown Structure (WBS) as the first step in project planning.
PMBOK (Project Management Body of Knowledge): Defines WBS as the foundation of project planning.
Analysis of Each Option:IIA References Supporting the Answer:Thus, the correct answer is (C) Break the project into manageable components, as this is the first step in structuring and planning a successful project.
IIA-CIA-Part3-KR 문제 85
Treating receivers with respect supports professional communication and reduces resistance. Matching presentation and delivery helps ensure the message is received correctly. Developing ideas without overstatement supports accuracy, objectivity, and credibility. These principles are especially important in internal audit communications, where clarity and neutrality affect management acceptance and governance decisions. Therefore, Option A is the exception and the correct answer.
- 다른 버전
- 1868IIA.IIA-CIA-Part3-KR.v2026-05-02.q255
- 1627IIA.IIA-CIA-Part3-KR.v2026-02-16.q207
- 2547IIA.IIA-CIA-Part3-KR.v2025-04-09.q203
- 최근 업로드
- 149Microsoft.DP-700-KR.v2026-08-20.q47
- 306ISC.CISSP-KR.v2026-08-20.q862
- 198Microsoft.SC-100-KR.v2026-08-20.q141
- 238Microsoft.AZ-305-KR.v2026-08-20.q223
- 856IIA.IIA-CIA-Part1-KR.v2026-08-19.q374
- 1355IIA.IIA-CIA-Part3-KR.v2026-08-19.q374
- 183Microsoft.DP-700-KR.v2026-08-19.q59
- 236AMP.CRL.v2026-08-18.q46
- 894Microsoft.AZ-305-KR.v2026-08-17.q162
- 237IIA.IAA-IAP-KR.v2026-08-17.q41
PDF 파일 다운로드
메일 주소를 입력하시고 다운로드 하세요. IIA.IIA-CIA-Part3-KR.v2026-08-19.q374 모의시험 시험자료를 다운 받으세요.
