CISA-KR 문제 196
The auditor should be most concerned about the security policy documents being available on a public domain website. This is because this exposes the organization's security posture and strategy to potential attackers, who can exploit the information to launch targeted attacks or bypass the security controls. The security policy documents should be classified as confidential and protected from unauthorized access or disclosure. The other options are less severe than exposing the security policy documents to the public, although they may also indicate some gaps or weaknesses in the security policy development, implementation, or maintenance process. References:
CISA Review Manual (Digital Version), Chapter 5, Section 5.31
CISA Online Review Course, Domain 3, Module 1, Lesson 12
CISA-KR 문제 197
A recovery point objective (RPO) is the maximum acceptable amount of data loss after an unplanned data-loss incident, expressed as an amount of time. This is generally thought of as the point in time before the event at which data can be successfully recovered - that is, the time elapsed since the most recent reliable backup1.
RPOs are important to consider when reviewing an organization's defined data backup and restoration procedures, because they determine how frequently the organization needs to perform backups, and how much data it can afford to lose in case of a disaster. RPOs are usually defined based on the business impact and criticality of the data, as well as the compliance and regulatory requirements. For example, a financial institution may have a very low RPO (such as a few minutes or seconds) for its transactional data, while a research institute may have a higher RPO (such as a few hours or days) for its experimental data.
The other possible options are:
A: Business continuity plan (BCP): A BCP is a document that outlines how an organization will continue to operate or resume its critical functions and processes in the event of a disruption or disaster.
A BCP includes various elements, such as risk assessment, business impact analysis, recovery strategies, roles and responsibilities, communication plan, and testing and maintenance. A BCP is related to an organization's defined data backup and restoration procedures, but it is not the most important factor to consider when reviewing them. A BCP defines the recovery objectives and strategies for the entire organization, while the data backup and restoration procedures are more specific and technical in nature.
C: Mean time to restore (MTTR): MTTR is a metric that measures the average time it takes to restore a system or service after a failure or outage. MTTR is an indicator of the efficiency and effectiveness of an organization's recovery process, as well as the availability and reliability of its systems or services.
MTTR is related to an organization's defined data backup and restoration procedures, but it is not the most important factor to consider when reviewing them. MTTR reflects the actual performance of the recovery process, while the data backup and restoration procedures define the expected steps and actions for the recovery process.
D: Mean time between failures (MTBF): MTBF is a metric that measures the average time between failures or outages of a system or service. MTBF is an indicator of the quality and durability of an organization's systems or services, as well as their susceptibility to failures or outages. MTBF is related to an organization's defined data backup and restoration procedures, but it is not the most important factor to consider when reviewing them. MTBF reflects the potential frequency of failures or outages, while the data backup and restoration procedures define the contingency plans for failures or outages.
CISA-KR 문제 198
The main purpose of an information security management system (ISMS) is to reduce the frequency and impact of information security incidents. An ISMS is a systematic approach to managing information security risks, policies, procedures, and controls within an organization. An ISMS aims to ensure the confidentiality, integrity, and availability of information assets, as well as to comply with relevant laws and regulations. The other options are not the main purpose of an ISMS, but rather some of its possible benefits or components.
References:
CISA Review Manual (Digital Version), Chapter 7, Section 7.11
CISA Review Questions, Answers & Explanations Database, Question ID 205
CISA-KR 문제 199
Reconciliation of total amounts by project is the best control to ensure that data is accurately entered into the job-costing system from spreadsheets. Reconciliation is a process of comparing two sets of data to identify any differences or discrepancies between them. By reconciling the total amounts by project from spreadsheets with those from the job-costing system, any errors or omissions in data entry can be detected and corrected.
Validity checks are controls that verify that data conforms to predefined formats or ranges. They can prevent entry of character data into numeric fields, but they cannot ensure that the numeric data is correct or complete.
Reasonableness checks are controls that verify that data is within expected or acceptable limits. They can detect outliers or anomalies in data, but they cannot ensure that the data matches the source. Display back of project detail after entry is a control that allows the user to review and confirm the data entered into the system. It can help reduce human errors, but it cannot guarantee that the data is accurate or consistent with the source. References: Information Systems Operations and Business Resilience, CISA Review Manual (Digital Version)
CISA-KR 문제 200
Substantive testing provides the best evidence of the validity and integrity of logs in an organization's security information and event management (SIEM) system, because it is a type of audit testing that directly examines the accuracy, completeness, and reliability of the data and transactions recorded in the logs. Substantive testing can involve various methods, such as re-performance, inspection, observation, inquiry, or computer-assisted audit techniques (CAATs), to verify the existence, occurrence, valuation, ownership, presentation, and disclosure of the log data1. Substantive testing can also detect any errors, omissions, alterations, or manipulations of the log data that may indicate fraud or misstatement2.
Compliance testing (A) is not the best evidence of the validity and integrity of logs in an organization's SIEM system, because it is a type of audit testing that evaluates the design and effectiveness of the internal controls that are implemented to ensure compliance with laws, regulations, policies, and procedures. Compliance testing can involve various methods, such as walkthroughs, questionnaires, checklists, or flowcharts, to assess the adequacy, consistency, and operation of the internal controls1. Compliance testing can provide assurance that the log data are generated and processed in accordance with the established rules and standards, but it does not directly verify the accuracy and reliability of the log data itself2.
Stop-or-go sampling (B) is not a type of audit testing, but a type of sampling technique that auditors use to select a sample from a population for testing. Stop-or-go sampling is a sequential sampling technique that allows auditors to stop testing before reaching the predetermined sample size if the results are satisfactory or conclusive. Stop-or-go sampling can reduce the audit cost and time by avoiding unnecessary testing, but it can also increase the sampling risk and uncertainty by relying on a smaller sample3. Stop-or-go sampling does not provide any evidence of the validity and integrity of logs in an organization's SIEM system by itself; it depends on the type and quality of the audit tests performed on the selected sample.
Variable sampling (D) is not a type of audit testing, but a type of sampling technique that auditors use to estimate a numerical characteristic of a population for testing. Variable sampling is a statistical sampling technique that allows auditors to measure the amount or rate of error or deviation in a population by using quantitative methods. Variable sampling can provide precise and objective results by using mathematical formulas and confidence intervals4. Variable sampling does not provide any evidence of the validity and integrity of logs in an organization's SIEM system by itself; it depends on the type and quality of the audit tests performed on the selected sample.
References:
Audit Testing Procedures - 5 Types and Their Use Cases
5 Types of Testing Methods Used During Audit Procedures | I.S. Partners Stop-or-Go Sampling Definition Variable Sampling Definition
- 다른 버전
- 4019ISACA.CISA-KR.v2026-05-16.q709
- 1808ISACA.CISA-KR.v2026-05-06.q261
- 3124ISACA.CISA-KR.v2026-03-16.q665
- 4489ISACA.CISA-KR.v2026-03-07.q651
- 9234ISACA.CISA-KR.v2025-04-07.q633
- 4453ISACA.CISA-KR.v2025-04-03.q628
- 3700ISACA.CISA-KR.v2025-04-02.q544
- 4223ISACA.CISA-KR.v2025-03-31.q534
- 5321ISACA.CISA-KR.v2025-03-28.q617
- 3152ISACA.CISA-KR.v2025-03-19.q581
- 4000ISACA.CISA-KR.v2025-03-03.q807
- 5135ISACA.CISA-KR.v2024-02-07.q421
- 5290ISACA.CISA-KR.v2023-10-24.q329
- 5215ISACA.CISA-KR.v2023-07-31.q266
- 3142ISACA.CISA-KR.v2023-06-23.q324
- 최근 업로드
- 118Microsoft.AZ-305-KR.v2026-08-14.q177
- 159Microsoft.DP-900-KR.v2026-08-13.q130
- 244Microsoft.PL-600.v2026-08-11.q206
- 184Microsoft.DP-100.v2026-08-11.q160
- 177Oracle.1Z0-1048-25.v2026-08-11.q68
- 145ISQI.CTAL-TAE.v2026-08-11.q37
- 195ServiceNow.CIS-HR.v2026-08-11.q84
- 259Salesforce.Plat-Arch-201.v2026-08-10.q101
- 245Databricks.Databricks-Machine-Learning-Professional.v2026-08-10.q76
- 192F5.F5CAB2.v2026-08-10.q41
PDF 파일 다운로드
메일 주소를 입력하시고 다운로드 하세요. ISACA.CISA-KR.v2024-01-31.q392 모의시험 시험자료를 다운 받으세요.
