CISA-KR 문제 51
The best approach for determining the overall IT risk appetite of an organization when business units use different methods for managing IT risks is to prioritize the organization's IT risk scenarios. IT risk appetite is the amount and type of IT risk that an organization is willing to accept in pursuit of its objectives. IT risk scenarios are hypothetical situations that describe the potential impact of IT risk events on the organization's objectives, processes, and resources. By prioritizing the organization's IT risk scenarios, the IS auditor can identify the most significant IT risks that affect the organization as a whole, and align them with the organization's strategic goals, values, and culture. Prioritizing the organization's IT risk scenarios can also help to communicate and monitor the IT risk appetite across the organization, and facilitate consistent and informed decision making. The other approaches (A, B and D) are not effective for determining the overall IT risk appetite of an organization, as they do not consider the impact and likelihood of IT risks on the organization's objectives, nor do they account for the diversity and complexity of IT risks across different business units. References: CISA Review Manual (Digital Version), Chapter 2: Governance and Management of Information Technology, Section 2.3: Information Technology Risk Management
CISA-KR 문제 52
The best way to ensure that business continuity plans (BCPs) will work effectively in the event of a major disaster is to involve staff at all levels in periodic paper walk-through exercises. This means that the BCPs are tested and validated by the people who will execute them in a real situation, and any gaps, errors, or inconsistencies can be identified and corrected. Paper walk-through exercises are also a good way to raise awareness and train staff on their roles and responsibilities in a BCP scenario, as well as to evaluate the feasibility and effectiveness of the recovery strategies1.
The other options are not the best ways to ensure that BCPs will work effectively, because they do not involve testing or validating the plans. Preparing detailed plans for each business function is important, but it does not guarantee that the plans are realistic, practical, or aligned with the overall business objectives and priorities2. Regularly updating business impact assessments is also essential, but it does not ensure that the BCPs are aligned with the current business environment and risks2. Making senior managers responsible for their plan sections is a good way to assign accountability and authority, but it does not ensure that the plan sections are coordinated and integrated with each other2. References:
Best Practice Guide: Business Continuity Planning (BCP)3
Best Practices for Creating a Business Continuity Plan1
Business Continuity Plan Best Practices
CISA-KR 문제 53
An organization considering the outsourcing of a business application should first conduct a cost-benefit analysis to evaluate the feasibility, viability and desirability of the outsourcing decision. A cost-benefit analysis should compare the costs and benefits of outsourcing versus keeping the application in-house, taking into account factors such as financial, operational, strategic, legal, regulatory, security and quality aspects. A cost-benefit analysis should also identify the risks and opportunities associated with outsourcing, and provide a basis for defining the service level requirements, performing a vulnerability assessment, and issuing a request for proposal (RFP) in the subsequent stages of the outsourcing process. References: Info Technology & Systems Resources | COBIT, Risk, Governance ... - ISACA, CISA Certification | Certified Information Systems Auditor | ISACA
CISA-KR 문제 54
The most effective control for protecting the confidentiality and integrity of data stored unencrypted on virtual machines is to monitor access to stored images and snapshots of virtual machines. Images and snapshots are copies of virtual machines that can be used for backup, restoration, or cloning purposes. If data stored on virtual machines are unencrypted, they may be exposed or compromised if unauthorized or malicious users access or copy the images or snapshots. Therefore, monitoring access to stored images and snapshots can help detect and prevent any unauthorized or suspicious activities, and provide audit trails for accountability and investigation.
Restricting access to images and snapshots of virtual machines, limiting creation of virtual machine images and snapshots, and reviewing logical access controls on virtual machines regularly are not the most effective controls for protecting the confidentiality and integrity of data stored unencrypted on virtual machines. These controls may help reduce the risk or impact of data exposure or compromise, but they do not provide sufficient visibility or assurance of data protection. Restricting access to images and snapshots may not prevent authorized users from abusing their privileges or credentials. Limiting creation of virtual machine images and snapshots may not address the existing copies that may contain sensitive data. Reviewing logical access controls on virtual machines regularly may not reflect the actual access activities on images and snapshots.
CISA-KR 문제 55
Reviewing the last compile date of production programs is the most efficient way to detect unauthorized changes to production programs, as it can quickly identify any discrepancies between the expected and actual dates of program modification. The last compile date is a timestamp that indicates when a program was last compiled or translated from source code to executable code. Any changes to the source code would require a recompilation, which would update the last compile date. The IS auditor can compare the last compile date of production programs with the authorized change requests and reports to verify that only approved changes were implemented. The other options are not as efficient as option A, as they are more time-consuming, labor-intensive or error-prone. Manually comparing code in production programs to controlled copies is a method of verifying that the code in production matches the code in a secure repository or library, but it requires access to both versions of code and a tool or technique to compare them line by line. Periodically running and reviewing test data against production programs is a method of verifying that the programs produce the expected outputs and results, but it requires designing, executing and evaluating test cases for each program. Verifying user management approval of modifications is a method of verifying that the changes to production programs were authorized and documented, but it does not ensure that the changes were implemented correctly or accurately. References: CISA Review Manual (Digital Version) , Chapter 4:
Information Systems Operations and Business Resilience, Section 4.3: Change Management Practices.
- 다른 버전
- 3963ISACA.CISA-KR.v2026-05-16.q709
- 1796ISACA.CISA-KR.v2026-05-06.q261
- 3118ISACA.CISA-KR.v2026-03-16.q665
- 4484ISACA.CISA-KR.v2026-03-07.q651
- 9206ISACA.CISA-KR.v2025-04-07.q633
- 4451ISACA.CISA-KR.v2025-04-03.q628
- 3659ISACA.CISA-KR.v2025-04-02.q544
- 4220ISACA.CISA-KR.v2025-03-31.q534
- 5320ISACA.CISA-KR.v2025-03-28.q617
- 3151ISACA.CISA-KR.v2025-03-19.q581
- 3973ISACA.CISA-KR.v2025-03-03.q807
- 5133ISACA.CISA-KR.v2024-02-07.q421
- 5267ISACA.CISA-KR.v2023-10-24.q329
- 5215ISACA.CISA-KR.v2023-07-31.q266
- 3105ISACA.CISA-KR.v2023-06-23.q324
- 최근 업로드
- 112Microsoft.AZ-305-KR.v2026-08-14.q177
- 154Microsoft.DP-900-KR.v2026-08-13.q130
- 244Microsoft.PL-600.v2026-08-11.q206
- 183Microsoft.DP-100.v2026-08-11.q160
- 177Oracle.1Z0-1048-25.v2026-08-11.q68
- 145ISQI.CTAL-TAE.v2026-08-11.q37
- 195ServiceNow.CIS-HR.v2026-08-11.q84
- 258Salesforce.Plat-Arch-201.v2026-08-10.q101
- 245Databricks.Databricks-Machine-Learning-Professional.v2026-08-10.q76
- 192F5.F5CAB2.v2026-08-10.q41
PDF 파일 다운로드
메일 주소를 입력하시고 다운로드 하세요. ISACA.CISA-KR.v2024-01-31.q392 모의시험 시험자료를 다운 받으세요.
