CISA-KR 문제 361
Quality control reviews are the best way to demonstrate to senior management and the board that an audit function is compliant with standards and the code of ethics. These reviews assess the efficiency and effectiveness of the audit function, ensure compliance with audit standards and ethics, and identify areas for improvement12. While audit staff interviews, control self-assessments (CSAs), and corrective action plans can provide valuable insights, they do not offer the same level of assurance as a comprehensive quality control review12.
References: The Institute of Internal Auditors1, AuditBoard2
CISA-KR 문제 362
The best recommendation for an organization that does not have a process to identify and correct records that do not get transferred to the receiving system is to implement software to perform automatic reconciliations of data between systems. This will ensure that the data integrity and completeness are maintained and that any errors or discrepancies are detected and resolved in a timely manner. Enabling encryption, decryption, and electronic signing of data files may enhance the data security and authenticity, but not the data accuracy or consistency. Having coders perform manual reconciliation of data between systems may be prone to human errors and inefficiencies. Automating the transfer of data between systems as much as feasible may reduce the chances of data loss or corruption, but not eliminate them completely. References: IS Audit and Assurance Standards, section "Standard 1202: Risk Assessment in Planning"
CISA-KR 문제 363
The greatest challenge to the alignment of business and IT is the lack of chief information officer (CIO) involvement in board meetings. The CIO is the senior executive responsible for overseeing the IT strategy, governance, and operations of the organization, and ensuring that they support the business objectives and needs. The CIO should be involved in board meetings to communicate the value and contribution of IT to the organization, to align the IT vision and direction with the business strategy and priorities, and to advocate for the IT resources and investments required to achieve the desired outcomes. The lack of CIO involvement in board meetings can result in a disconnect between business and IT, a loss of trust and confidence in IT, and missed opportunities for innovation and value creation. The other options are not as challenging as the lack of CIO involvement in board meetings, because they either do not affect the strategic alignment of business and IT, or they can be addressed by other means such as collaboration, negotiation, or escalation. References:
CISA Review Manual (Digital Version)1, Chapter 1, Section 1.2.1
CISA-KR 문제 364
A disaster recovery plan (DRP) is a set of procedures and resources that enable an organization to restore its critical operations, data, and applications in the event of a disaster1. A DRP should be aligned with the organization's business continuity plan (BCP), which defines the strategies and objectives for maintaining business functions during and after a disaster1.
To ensure that a DRP is effective, it should be tested regularly and thoroughly to identify and resolve any issues or gaps that might hinder its execution2345. Testing a DRP can help evaluate its feasibility, validity, reliability, and compatibility with the organization's environment and needs4. Testing can also help prepare the staff, stakeholders, and vendors involved in the DRP for their roles and responsibilities during a disaster3.
There are different methods and levels of testing a DRP, depending on the scope, complexity, and objectives of the test4. Some of the common testing methods are:
Walkthrough testing: This is a step-by-step review of the DRP by the disaster recovery team and relevant stakeholders. It aims to verify the completeness and accuracy of the plan, as well as to clarify any doubts or questions among the participants45.
Simulation testing: This is a mock exercise of the DRP in a simulated disaster scenario. It aims to assess the readiness and effectiveness of the plan, as well as to identify any challenges or weaknesses that might arise during a real disaster45.
Checklist testing: This is a verification of the availability and functionality of the resources and equipment required for the DRP. It aims to ensure that the backup systems, data, and documentation are accessible and up-to-date45.
Full interruption testing: This is the most realistic and rigorous method of testing a DRP. It involves shutting down the primary site and activating the backup site for a certain period of time. It aims to measure the actual impact and performance of the DRP under real conditions45.
Parallel testing: This is a less disruptive method of testing a DRP. It involves running the backup site in parallel with the primary site without affecting the normal operations. It aims to compare and validate the results and outputs of both sites45.
Among these methods, full interruption testing would best demonstrate that an effective DRP is in place, as it provides the most accurate and comprehensive evaluation of the plan's capabilities and limitations4. Full interruption testing can reveal any hidden or unforeseen issues or risks that might affect the recovery process, such as data loss, system failure, compatibility problems, or human errors4. Full interruption testing can also verify that the backup site can support the critical operations and services of the organization without compromising its quality or security4.
However, full interruption testing also has some drawbacks, such as being costly, time-consuming, risky, and disruptive to the normal operations4. Therefore, it should be planned carefully and conducted periodically with proper coordination and communication among all parties involved4.
The other options are not as effective as full interruption testing in demonstrating that an effective DRP is in place. Frequent testing of backups is only one aspect of checklist testing, which does not cover other components or scenarios of the DRP4. Annual walk-through testing is only a theoretical review of the DRP, which does not test its practical implementation or outcomes4. Periodic risk assessment is only a preparatory step for developing or updating the DRP, which does not test its functionality or performance4.
References: 2: Best Practices For Disaster Recovery Testing | Snyk 3: Disaster Recovery Plan (DR) Testing - Methods and Must-haves - US Signal 4: Disaster Recovery Testing: What You Need to Know - Enterprise Storage Forum 5: Disaster Recovery Testing Best Practices - MSP360 1: How to Test a Disaster Recovery Plan - Abacus
CISA-KR 문제 365
Periodically reviewing log files is the most effective way to detect intrusion attempts from outside the organization, as they can provide evidence of unauthorized access attempts, source IP addresses, timestamps and other relevant information. Using smart cards with one-time passwords or installing biometrics-based authentication can prevent unauthorized access, but not detect it. Configuring the router as a firewall can block unwanted traffic, but not log it. References: ISACA, CISA Review Manual, 27th Edition, 2018, page 361
- 다른 버전
- 3980ISACA.CISA-KR.v2026-05-16.q709
- 1797ISACA.CISA-KR.v2026-05-06.q261
- 3118ISACA.CISA-KR.v2026-03-16.q665
- 4484ISACA.CISA-KR.v2026-03-07.q651
- 9211ISACA.CISA-KR.v2025-04-07.q633
- 4451ISACA.CISA-KR.v2025-04-03.q628
- 3672ISACA.CISA-KR.v2025-04-02.q544
- 4221ISACA.CISA-KR.v2025-03-31.q534
- 5320ISACA.CISA-KR.v2025-03-28.q617
- 3151ISACA.CISA-KR.v2025-03-19.q581
- 3976ISACA.CISA-KR.v2025-03-03.q807
- 5133ISACA.CISA-KR.v2024-02-07.q421
- 5268ISACA.CISA-KR.v2023-10-24.q329
- 5215ISACA.CISA-KR.v2023-07-31.q266
- 3112ISACA.CISA-KR.v2023-06-23.q324
- 최근 업로드
- 115Microsoft.AZ-305-KR.v2026-08-14.q177
- 154Microsoft.DP-900-KR.v2026-08-13.q130
- 244Microsoft.PL-600.v2026-08-11.q206
- 183Microsoft.DP-100.v2026-08-11.q160
- 177Oracle.1Z0-1048-25.v2026-08-11.q68
- 145ISQI.CTAL-TAE.v2026-08-11.q37
- 195ServiceNow.CIS-HR.v2026-08-11.q84
- 259Salesforce.Plat-Arch-201.v2026-08-10.q101
- 245Databricks.Databricks-Machine-Learning-Professional.v2026-08-10.q76
- 192F5.F5CAB2.v2026-08-10.q41
PDF 파일 다운로드
메일 주소를 입력하시고 다운로드 하세요. ISACA.CISA-KR.v2024-01-31.q392 모의시험 시험자료를 다운 받으세요.
