CISA-KR 문제 161
When auditing the closing stages of a system development project, the most important consideration should be the user acceptance test (UAT) results. The UAT is a critical phase of the system development life cycle (SDLC) that ensures that the system meets the functional requirements and expectations of the end users. The UAT results provide evidence of the system's quality, performance, usability, and reliability. Control requirements, rollback procedures, and functional requirements documentation are also important considerations, but they are not as crucial as the UAT results in determining if the system is ready for deployment. References: CISA Review Manual (Digital Version)1, page 325.
CISA-KR 문제 162
The most important responsibility of user departments associated with program changes is approving changes before implementation. This is because user departments are the primary stakeholders and beneficiaries of the program changes, and they need to ensure that the changes meet their requirements, expectations, and objectives. User departments also need to approve the changes before implementation to avoid unauthorized, unnecessary, or erroneous changes that could affect the functionality, performance, or security of the program.
Providing unit test data is a responsibility of user departments associated with program changes, but it is not the most important one. Unit test data is used to verify that the individual components of the program work as expected after the changes. However, unit test data alone cannot guarantee that the program as a whole works correctly, or that the changes are aligned with the user departments' needs.
Analyzing change requests is a responsibility of user departments associated with program changes, but it is not the most important one. Analyzing change requests is the process of evaluating the feasibility, necessity, and impact of the proposed changes. However, analyzing change requests does not ensure that the changes are implemented correctly, or that they are acceptable to the user departments.
Updating documentation to reflect latest changes is a responsibility of user departments associated with program changes, but it is not the most important one. Updating documentation is the process of maintaining accurate and complete records of the program's specifications, features, and functions after the changes.
However, updating documentation does not ensure that the changes are effective, or that they are approved by the user departments.
References:
ISACA, CISA Review Manual, 27th Edition, 2019, p. 281
ISACA, CISA Review Questions, Answers & Explanations Database - 12 Month Subscription
CISA-KR 문제 163
Scope creep is the uncontrolled expansion of a project's scope, which can result in delays, cost overruns, and quality issues. To mitigate the risk of scope creep, an IS auditor should look for project change management controls, which are processes and procedures for managing changes to the project's scope, schedule, budget, and quality. Project change management controls ensure that changes are properly requested, approved, documented, communicated, and implemented. Source code version control, existence of an architecture review board, and configuration management are also important for software development, but they do not directly address the risk of scope creep. References: ISACA Frameworks: Blueprints for Success, Project Management Institute: A Guide to the Project Management Body of Knowledge
CISA-KR 문제 164
Evidence collection is the process of identifying, acquiring, preserving, and documenting digital evidence from various sources, such as computers, networks, mobile devices, or cloud services, that can be used to support the investigation and prosecution of cybercrimes. Evidence collection is an IS auditor's primary focus when evaluating the response process for cybercrimes, because it determines the quality and validity of the evidence that can be used to prove or disprove the facts of the case, identify the perpetrators, and recover the losses. Evidence collection should follow the standards and best practices for digital forensics, such as ISO/IEC 270371, which provide guidelines for ensuring the integrity, authenticity, reliability, and admissibility of the evidence2.
The other possible options are:
A: Communication with law enforcement: This is the process of reporting, cooperating, and coordinating with law enforcement agencies that have the jurisdiction and authority to investigate and prosecute cybercrimes. Communication with law enforcement is an important aspect of the response process for cybercrimes, but it is not an IS auditor's primary focus when evaluating it. Communication with law enforcement depends on the legal and regulatory requirements, the nature and severity of the incident, and the organizational policies and procedures. Communication with law enforcement should be done after evidence collection, to avoid compromising or contaminating the evidence3.
B: Notification to regulators: This is the process of informing and updating the relevant regulatory bodies or authorities that oversee or supervise the organization's activities or industry sector about the cybercrime incident. Notification to regulators is an important aspect of the response process for cybercrimes, but it is not an IS auditor's primary focus when evaluating it. Notification to regulators depends on the legal and regulatory requirements, the nature and impact of the incident, and the organizational policies and procedures. Notification to regulators should be done after evidence collection, to avoid disclosing sensitive or confidential information4.
C: Root cause analysis: This is the process of identifying and analyzing the underlying factors or causes that led to or contributed to the cybercrime incident. Root cause analysis is an important aspect of the response process for cybercrimes, but it is not an IS auditor's primary focus when evaluating it. Root cause analysis helps to prevent or mitigate future incidents, improve security controls and processes, and learn from mistakes. Root cause analysis should be done after evidence collection, to avoid interfering with or affecting the investigation5.
CISA-KR 문제 165
The IS auditor's best course of action when preparing the final report is to include the position supported by senior management in the final engagement report. The IS auditor should communicate the audit findings and recommendations to senior management and obtain their feedback and approval before issuing the final report.
If there is a disagreement between the auditee and the IS auditor regarding a recommendation for corrective action, the IS auditor should present both sides of the argument and the supporting evidence, and seek senior management's opinion and decision. The IS auditor should respect and follow senior management's position, and include it in the final engagement report, along with the auditee's comments if applicable. The other options are not the best course of action, because they either do not resolve the disagreement, do not reflect senior management's authority, or do not report the audit results accurately and completely. References: CISA Review Manual (Digital Version)1, Chapter 2, Section 2.2.5
- 다른 버전
- 4018ISACA.CISA-KR.v2026-05-16.q709
- 1804ISACA.CISA-KR.v2026-05-06.q261
- 3124ISACA.CISA-KR.v2026-03-16.q665
- 4489ISACA.CISA-KR.v2026-03-07.q651
- 9231ISACA.CISA-KR.v2025-04-07.q633
- 4453ISACA.CISA-KR.v2025-04-03.q628
- 3696ISACA.CISA-KR.v2025-04-02.q544
- 4223ISACA.CISA-KR.v2025-03-31.q534
- 5321ISACA.CISA-KR.v2025-03-28.q617
- 3152ISACA.CISA-KR.v2025-03-19.q581
- 3997ISACA.CISA-KR.v2025-03-03.q807
- 5135ISACA.CISA-KR.v2024-02-07.q421
- 5286ISACA.CISA-KR.v2023-10-24.q329
- 5215ISACA.CISA-KR.v2023-07-31.q266
- 3139ISACA.CISA-KR.v2023-06-23.q324
- 최근 업로드
- 118Microsoft.AZ-305-KR.v2026-08-14.q177
- 159Microsoft.DP-900-KR.v2026-08-13.q130
- 244Microsoft.PL-600.v2026-08-11.q206
- 183Microsoft.DP-100.v2026-08-11.q160
- 177Oracle.1Z0-1048-25.v2026-08-11.q68
- 145ISQI.CTAL-TAE.v2026-08-11.q37
- 195ServiceNow.CIS-HR.v2026-08-11.q84
- 259Salesforce.Plat-Arch-201.v2026-08-10.q101
- 245Databricks.Databricks-Machine-Learning-Professional.v2026-08-10.q76
- 192F5.F5CAB2.v2026-08-10.q41
PDF 파일 다운로드
메일 주소를 입력하시고 다운로드 하세요. ISACA.CISA-KR.v2024-01-31.q392 모의시험 시험자료를 다운 받으세요.
