CISA-KR 문제 246
The primary reason an IS auditor would recommend replacing universal PIN codes with an RFID access card system at a data center is to improve traceability (A). Traceability is the ability to track and monitor the activities and movements of individuals or objects within a system or environment. Traceability is important for ensuring security, accountability, and compliance in a data center, where sensitive and critical data are stored and processed.
An RFID access card system can improve traceability by using RFID technology to verify and record the identity and access of each user who enters or exits the data center. RFID stands for Radio Frequency Identification, and it enables wireless communication between a reader and an RFID tag. An RFID tag is installed in a door key card or fob, which users use to gain access to the data center. An RFID reader is installed near the door, and it contains an antenna that receives data transmitted by the RFID tag. A control panel is a computer server that reads and interprets the data passed along by the RFID reader. A database is a storage system that stores the data collected by the control panel1.
An RFID access card system can provide several benefits for traceability, such as123:
It can uniquely identify each user and their access level, and prevent unauthorized access or impersonation.
It can record the date, time, and duration of each user's access, and generate logs and reports for auditing purposes.
It can monitor the location and status of each user within the data center, and alert security personnel in case of any anomalies or emergencies.
It can integrate with other security systems, such as cameras, alarms, or biometrics, to enhance verification and protection.
A universal PIN code system, on the other hand, can compromise traceability by using a single or shared personal identification number (PIN) to grant access to multiple users. A universal PIN code system can pose several risks for traceability, such as4:
It can be easily guessed, stolen, shared, or compromised by malicious actors or insiders.
It can not distinguish between different users or their access levels, and allow unauthorized or excessive access.
It can not record or track the activities or movements of each user within the data center, and create gaps or errors in the audit trail.
It can not integrate with other security systems, and provide limited verification and protection.
Therefore, an IS auditor would recommend replacing universal PIN codes with an RFID access card system at a data center to improve traceability.
References:
RFID Access Control Guide: 4 Best RFID Access Control Systems - ButterflyMX Choosing Card Technology in 2023 | ICT RFID Vs Magnetic Key Cards: What's The Difference? - Go Safer Security RFID vs Barcode - Advantages, Disadvantages & Differences
CISA-KR 문제 247
Unauthorized changes can be moved into production is the best concern that is addressed by securing production source libraries. Production source libraries contain the source code of programs that are used in the production environment. Securing production source libraries means implementing access controls, change management procedures, and audit trails to prevent unauthorized or improper changes to the source code that could affect the functionality, performance, or security of the production programs. The other options are less relevant concerns that may not be directly addressed by securing production source libraries, but rather by other controls such as program approval, version control, or change testing. References:
CISA Review Manual (Digital Version), Chapter 4, Section 4.2.3.21
CISA Review Questions, Answers & Explanations Database, Question ID 213
CISA-KR 문제 248
An audit report of the controls by the service provider's external auditor provides the best evidence that a third-party service provider's information security controls are effective. An external auditor is an independent and objective party that can assess the design and operating effectiveness of the service provider's information security controls based on established standards and criteria. An external auditor can also provide an opinion on the adequacy and compliance of the service provider's information security controls, as well as recommendations for improvement.
Documentation of the service provider's security configuration controls is a source of evidence that a third-party service provider's information security controls are effective, but it is not the best evidence.
Documentation of the security configuration controls can show the settings and parameters of the service provider's information systems and networks, but it may not reflect the actual implementation and operation of the controls. Documentation of the security configuration controls may also be outdated, incomplete, or inaccurate.
An interview with the service provider's information security officer is a source of evidence that a third-party service provider's information security controls are effective, but it is not the best evidence. An interview with the information security officer can provide insights into the service provider's information security strategy, policies, and procedures, but it may not verify the actual performance and compliance of the information security controls. An interview with the information security officer may also be biased, subjective, or misleading.
A review of the service provider's policies and procedures is a source of evidence that a third-party service provider's information security controls are effective, but it is not the best evidence. A review of the policies and procedures can show the service provider's information security objectives, requirements, and guidelines, but it may not demonstrate the actual execution and enforcement of the information security controls. A review of the policies and procedures may also be insufficient, inconsistent, or outdated.
References:
ISACA, CISA Review Manual, 27th Edition, 2019, p. 284
ISACA, CISA Review Questions, Answers & Explanations Database - 12 Month Subscription
CISA-KR 문제 249
The best evidence to determine whether transactions have been executed by authorized employees is audit trails. Audit trails are secure records that catalog events or procedures to provide support documentation. They are used to authenticate security and operational actions, mitigate challenges, or provide proof of compliance and operational integrity2. Audit trails can track and trace the following information related to transactions:
Who initiated, approved, modified, or deleted a transaction
When a transaction occurred (date and time)
Where a transaction took place (location or device)
What type of transaction was performed (action or operation)
Why a transaction was executed (purpose or reason)
By analyzing audit trails, an IS auditor can verify whether transactions have been executed by authorized employees or not. Audit trails can also identify any unauthorized, fraudulent, or erroneous transactions that may have occurred. Audit trails can also help to resolve any disputes or discrepancies that may arise from transactions.
References:
What Is an Audit Trail? Everything You Need to Know
CISA-KR 문제 250
The greatest concern to an IS auditor who is assessing an organization's configuration and release management process is that changes and change approvals are not documented. This is because documentation is essential for ensuring the traceability, accountability, and quality of the changes made to the configuration items (CIs) and the releases deployed to the production environment. Without documentation, it would be difficult to verify the authenticity, validity, and authorization of the changes, as well as to identify and resolve any issues or incidents that may arise from the changes. Documentation also helps to maintain compliance with internal and external standards and regulations, as well as to facilitate audits and reviews.
The other options are not as concerning as option B, although they may also indicate some weaknesses in the configuration and release management process. The organization does not use an industry-recognized methodology, but this does not necessarily mean that their process is ineffective or inefficient. The organization may have developed their own methodology that suits their specific needs and context. However, using an industry-recognized methodology could help them adopt best practices and improve their process maturity. All changes require middle and senior management approval, but this may not be a problem if the organization has a clear and streamlined approval process that does not cause delays or bottlenecks in the change implementation. However, requiring too many approvals could also introduce unnecessary complexity and bureaucracy in the process. There is no centralized configuration management database (CMDB), but this does not mean that the organization does not have a way of managing their CIs and their relationships. The organization may use other tools or methods to store and access their configuration data, such as spreadsheets, documents, or repositories. However, having a centralized CMDB could help them improve their visibility, accuracy, and consistency of their configuration data.
References:
1: The Essential Guide to Release Management | Smartsheet
2: 5 steps to a successful release management process - Lucidchart
3: Configuration Management process overview - Micro Focus
4: Release and Deployment Management process overview - Micro Focus
- 다른 버전
- 3874ISACA.CISA-KR.v2026-05-16.q709
- 1778ISACA.CISA-KR.v2026-05-06.q261
- 3095ISACA.CISA-KR.v2026-03-16.q665
- 4447ISACA.CISA-KR.v2026-03-07.q651
- 9186ISACA.CISA-KR.v2025-04-07.q633
- 4439ISACA.CISA-KR.v2025-04-03.q628
- 3639ISACA.CISA-KR.v2025-04-02.q544
- 4200ISACA.CISA-KR.v2025-03-31.q534
- 5303ISACA.CISA-KR.v2025-03-28.q617
- 3099ISACA.CISA-KR.v2025-03-19.q581
- 3962ISACA.CISA-KR.v2025-03-03.q807
- 2793ISACA.CISA-KR.v2024-01-31.q392
- 5260ISACA.CISA-KR.v2023-10-24.q329
- 5188ISACA.CISA-KR.v2023-07-31.q266
- 3098ISACA.CISA-KR.v2023-06-23.q324
- 최근 업로드
- 120Microsoft.DP-900-KR.v2026-08-13.q130
- 227Microsoft.PL-600.v2026-08-11.q206
- 168Microsoft.DP-100.v2026-08-11.q160
- 167Oracle.1Z0-1048-25.v2026-08-11.q68
- 140ISQI.CTAL-TAE.v2026-08-11.q37
- 184ServiceNow.CIS-HR.v2026-08-11.q84
- 255Salesforce.Plat-Arch-201.v2026-08-10.q101
- 240Databricks.Databricks-Machine-Learning-Professional.v2026-08-10.q76
- 189F5.F5CAB2.v2026-08-10.q41
- 296APA.CPP-Remote.v2026-08-08.q109
PDF 파일 다운로드
메일 주소를 입력하시고 다운로드 하세요. ISACA.CISA-KR.v2024-02-07.q421 모의시험 시험자료를 다운 받으세요.
