IIA-CIA-Part3-KR 문제 226
(A) Incorrect - Assigning new roles and responsibilities for senior IT management.
While defining roles is important, it is a management function rather than a direct cybersecurity policy update.
Cybersecurity policies focus on risks like data protection, access controls, and device security rather than IT management roles.
(B) Correct - Growing use of bring your own devices for organizational matters.
BYOD introduces security risks such as unauthorized access, weak endpoint security, and data loss.
Cybersecurity policies must address encryption, remote access controls, and mobile device management (MDM) solutions.
(C) Incorrect - Expansion of operations into new markets with limited IT access.
While IT expansion poses challenges, cybersecurity policies focus more on data security, threat management, and risk mitigation rather than market access issues.
(D) Incorrect - Hiring new personnel within the IT department for security purposes.
Hiring staff improves security operations but is a resource management decision, not a direct cybersecurity policy concern.
Cybersecurity policies focus on access controls, risk assessments, and compliance requirements.
IIA's GTAG (Global Technology Audit Guide) - Cybersecurity and Risk Management Highlights BYOD as a key cybersecurity risk requiring clear policies and controls.
NIST Cybersecurity Framework - Mobile Device Security
Recommends specific policies for managing BYOD risks.
Analysis of Answer Choices:IIA References and Internal Auditing Standards:
IIA-CIA-Part3-KR 문제 227
Why Option A (Key performance indicators) is Correct:
KPIs (Key Performance Indicators) measure the effectiveness and success of big data systems.
KPIs help track system efficiency, data processing speed, accuracy, and resource utilization during production.
Examples of KPIs in big data systems include data ingestion rate, processing time, query performance, system uptime, and error rates.
Why Other Options Are Incorrect:
Option B (Reports of software customization):
Incorrect because software customization reports document system modifications but do not monitor system performance.
Option C (Change and patch management):
Incorrect because change and patch management deals with software updates and security fixes, not ongoing performance monitoring.
Option D (Master data management):
Incorrect because master data management focuses on data governance and consistency, not real-time system performance.
IIA GTAG - "Auditing Big Data Systems": Recommends using KPIs to measure the effectiveness of big data implementation.
COBIT 2019 - APO08 (Manage Performance and Capacity): Emphasizes KPI tracking for IT and data system performance.
NIST Big Data Framework: Highlights the importance of KPIs for monitoring big data system performance.
IIA References:
IIA-CIA-Part3-KR 문제 228
* Outsourcing refers to contracting business processes, functions, or expertise to an external service provider.
* Companies use outsourcing to reduce costs, access specialized skills, and improve efficiency.
* Why Option B (Contracting Functions or Knowledge-Related Work with an External Provider) Is Correct?
* Outsourcing involves delegating specific business functions (e.g., IT support, payroll, customer service) to external specialists.
* IIA Standard 2110 - Governance supports evaluating outsourcing risks and effectiveness.
* ISO 37500 - Outsourcing Management Framework emphasizes knowledge-based work outsourcing for expertise gains.
* Why Other Options Are Incorrect?
* Option A (Foreign service providers for cost savings):
* While some outsourcing involves foreign providers, outsourcing is not limited to offshoring.
* Option C (Internal service provider):
* Internal service providers do not involve outsourcing, as the work remains within the company.
* Option D (External + internal provider collaboration):
* This describes co-sourcing, not pure outsourcing.
* Outsourcing involves contracting business functions to an external provider, making option B correct.
* IIA Standard 2110 supports governance over outsourcing decisions and risk management.
Final Justification:IIA References:
* IPPF Standard 2110 - Governance (Outsourcing & Vendor Risk Management)
* ISO 37500 - Outsourcing Management Framework
* COSO ERM - Third-Party Risk Management in Outsourcing
IIA-CIA-Part3-KR 문제 229
IIA-CIA-Part3-KR 문제 230
A). Wide Area Network (WAN) (Correct Answer)
WANs cover extensive geographical areas, such as multiple cities, countries, or even continents.
They use various communication technologies, including leased lines, satellite connections, VPNs, and MPLS.
WANs enable organizations with distributed operations to centralize data management and enhance business continuity.
Example: An international corporation like a multinational bank or a global retail chain relies on a WAN to link its offices worldwide.
B). Local Area Network (LAN) (Incorrect Answer)
LANs are confined to a small area, such as an office building, factory, or campus.
They provide high-speed connectivity but are not designed for geographically dispersed locations.
Example: A single office using Ethernet and Wi-Fi to connect employees' devices.
C). Metropolitan Area Network (MAN) (Incorrect Answer)
MANs span a city or a large campus but do not extend to multiple countries.
Example: A city's government agencies using a fiber-optic MAN for interdepartmental communication.
D). Storage Area Network (SAN) (Incorrect Answer)
SANs are dedicated high-speed networks designed for large-scale data storage and retrieval.
They are not meant for interconnecting geographically dispersed locations.
Example: A financial institution using a SAN for high-speed access to critical databases.
The IIA's Global Technology Audit Guide (GTAG) - IT Risks and Controls emphasizes the importance of network infrastructure in securing and managing organizational data across multiple locations.
IIA Standard 2110 - Governance requires internal auditors to evaluate whether the organization's IT strategy (including WAN infrastructure) supports business objectives and risk management.
IIA GTAG 17 - Auditing Network Security highlights the importance of WAN security, VPNs, and encryption when managing international operations.
Explanation of Answer Choices:IIA References:Thus, the correct answer is A. Wide Area Network (WAN).
- 다른 버전
- 1866IIA.IIA-CIA-Part3-KR.v2026-05-02.q255
- 1626IIA.IIA-CIA-Part3-KR.v2026-02-16.q207
- 2546IIA.IIA-CIA-Part3-KR.v2025-04-09.q203
- 최근 업로드
- 148Microsoft.DP-700-KR.v2026-08-20.q47
- 249ISC.CISSP-KR.v2026-08-20.q862
- 195Microsoft.SC-100-KR.v2026-08-20.q141
- 233Microsoft.AZ-305-KR.v2026-08-20.q223
- 831IIA.IIA-CIA-Part1-KR.v2026-08-19.q374
- 1323IIA.IIA-CIA-Part3-KR.v2026-08-19.q374
- 180Microsoft.DP-700-KR.v2026-08-19.q59
- 234AMP.CRL.v2026-08-18.q46
- 893Microsoft.AZ-305-KR.v2026-08-17.q162
- 235IIA.IAA-IAP-KR.v2026-08-17.q41
PDF 파일 다운로드
메일 주소를 입력하시고 다운로드 하세요. IIA.IIA-CIA-Part3-KR.v2026-08-19.q374 모의시험 시험자료를 다운 받으세요.
