CISA-KR 문제 276
The greatest risk associated with the situation of business units purchasing cloud-based applications without IT support is that the applications may not reasonably protect data. Cloud-based applications are software applications that run on the internet, rather than on a local device or network. Cloud-based applications offer many benefits, such as scalability, accessibility, and cost-effectiveness, but they also pose many challenges and risks, especially for data security1.
Data security is the process of protecting data from unauthorized access, use, modification, disclosure, or destruction. Data security is essential for ensuring the confidentiality, integrity, and availability of data, as well as complying with legal and regulatory requirements. Data security is especially important for cloud-based applications, as data are stored and processed on remote servers that are owned and managed by third-party cloud service providers (CSPs)2.
When business units purchase cloud-based applications without IT support, they may not be aware of or follow the best practices and standards for data security in the cloud. They may not perform adequate risk assessments, vendor evaluations, contract reviews, or audits to ensure that the CSPs and the applications meet the organization's data security policies and expectations. They may not implement appropriate data encryption, backup, recovery, or disposal methods to protect the data in transit and at rest. They may not monitor or control the access and usage of the data by internal or external users. They may not report or respond to any data breaches or incidents that may occur3.
These actions or inactions may expose the organization's data to various threats and vulnerabilities in the cloud, such as cyberattacks, human errors, malicious insiders, misconfigurations, or legal disputes. These threats and vulnerabilities may result in data loss, leakage, corruption, or compromise, which may have serious consequences for the organization's reputation, operations, performance, compliance, and liability4.
Therefore, it is essential that business units consult and collaborate with IT support before purchasing any cloud-based applications, and follow the organization's guidelines and procedures for cloud security. IT support can help business units to select and use cloud-based applications that are suitable and secure for their needs and objectives.
References:
Top 5 Risks With Cloud Software and How to Mitigate Them4
Mitigate risks and secure your cloud-native applications3
12 Risks, Threats & Vulnerabilities in Moving to the Cloud2
Best Practices to Manage Risks in the Cloud1
CISA-KR 문제 277
The greatest concern for an IS auditor when an international organization intends to roll out a global data privacy policy is that local regulations may contradict the policy. Data privacy regulations vary across different countries and regions, and they may impose different or conflicting requirements on how personal data can be collected, processed, stored, transferred, and disclosed. The organization should ensure that its global data privacy policy complies with the applicable local regulations in each jurisdiction where it operates, or risk facing legal sanctions or reputational damage. Requirements may become unreasonable, but this is not a major concern for an IS auditor, as it is a business decision that should be based on a cost-benefit analysis.
The policy may conflict with existing application requirements, but this is not a serious concern for an IS auditor, as it can be resolved by modifying or updating the applications to align with the policy. Local management may not accept the policy, but this is not a critical concern for an IS auditor, as it can be mitigated by providing adequate training and awareness on the policy and its benefits. References:
CISA Review Manual, 27th Edition, pages 406-4071
CISA Review Questions, Answers & Explanations Database, Question ID: 2592
CISA-KR 문제 278
The answer B is correct because a system-generated list of staff and their project assignments, roles, and responsibilities is the most useful to an IS auditor performing a review of access controls for a document management system. A document management system is a software that helps organizations store, manage, and share documents electronically. Access controls are the mechanisms that restrict or allow access to the documents based on predefined criteria, such as user identity, role, or project. An IS auditor needs to verify that the access controls are properly configured and implemented to ensure the security, confidentiality, and integrity of the documents.
A system-generated list of staff and their project assignments, roles, and responsibilities can help the IS auditor to perform the following tasks:
Identify the users who have access to the document management system and their level of access (e.g., read-only, edit, delete, etc.).
Compare the actual access rights of the users with their expected or authorized access rights based on their roles and responsibilities.
Detect any anomalies, discrepancies, or violations in the access rights of the users, such as excessive or unauthorized access, segregation of duties conflicts, or dormant or inactive accounts.
Evaluate the effectiveness and efficiency of the access control policies and procedures, such as user provisioning, deprovisioning, authentication, authorization, auditing, etc.
The other options are not as useful as option B. Policies and procedures for managing documents provided by department heads (option A) are not reliable sources of information for an IS auditor because they may not reflect the actual practices or compliance status of the document management system. Previous audit reports related to other departments' use of the same system (option C) are not relevant for an IS auditor because they may not address the specific issues or risks associated with the current department's use of the document management system. Information provided by the audit team lead on the authentication systems used by the department (option D) is not sufficient for an IS auditor because authentication is only one aspect of access control and it does not provide information on the authorization or auditing of the document access.
References:
Overview of document management in SharePoint
Setting Up a Document Control System: 6 Basic Steps
Access Control Management: Purpose, Types, Tools, & Benefits
9 Best Document Management Systems of 2023
CISA-KR 문제 279
A router is a type of device that sits on the perimeter of a corporate or home network, where it obtains a public IP address and then generates private IP addresses internally. A router connects two or more networks and forwards packets between them based on routing rules. A router can also provide network address translation (NAT) functionality, which allows multiple devices to share a single public IP address and access the internet.
A switch is a type of device that connects multiple devices within a network and forwards packets based on MAC addresses. An intrusion prevention system (IPS) is a type of device that monitors network traffic and blocks or modifies malicious packets based on predefined rules. A gateway is a type of device that acts as an interface between different networks or protocols, such as a modem or a firewall. References: CISA Review Manual (Digital Version), [ISACA Glossary of Terms]
CISA-KR 문제 280
The best approach for management in developing a test plan is to use processing parameters that are simulated by production entities and customers. This is because using realistic data and scenarios can help to evaluate the functionality, performance, reliability, and security of the new system under actual operating conditions and expectations. Using processing parameters that are randomly selected by a test generator, provided by the vendor of the application, or randomly selected by the user may not be sufficient or representative of the production environment and may not reveal all the potential issues or defects of the new system. References: [ISACA CISA Review Manual 27th Edition], page 266.
- 다른 버전
- 3860ISACA.CISA-KR.v2026-05-16.q709
- 1773ISACA.CISA-KR.v2026-05-06.q261
- 3095ISACA.CISA-KR.v2026-03-16.q665
- 4445ISACA.CISA-KR.v2026-03-07.q651
- 9182ISACA.CISA-KR.v2025-04-07.q633
- 4438ISACA.CISA-KR.v2025-04-03.q628
- 3635ISACA.CISA-KR.v2025-04-02.q544
- 4196ISACA.CISA-KR.v2025-03-31.q534
- 5300ISACA.CISA-KR.v2025-03-28.q617
- 3089ISACA.CISA-KR.v2025-03-19.q581
- 3960ISACA.CISA-KR.v2025-03-03.q807
- 2793ISACA.CISA-KR.v2024-01-31.q392
- 5260ISACA.CISA-KR.v2023-10-24.q329
- 5180ISACA.CISA-KR.v2023-07-31.q266
- 3098ISACA.CISA-KR.v2023-06-23.q324
- 최근 업로드
- 107Microsoft.DP-900-KR.v2026-08-13.q130
- 227Microsoft.PL-600.v2026-08-11.q206
- 165Microsoft.DP-100.v2026-08-11.q160
- 166Oracle.1Z0-1048-25.v2026-08-11.q68
- 140ISQI.CTAL-TAE.v2026-08-11.q37
- 183ServiceNow.CIS-HR.v2026-08-11.q84
- 255Salesforce.Plat-Arch-201.v2026-08-10.q101
- 240Databricks.Databricks-Machine-Learning-Professional.v2026-08-10.q76
- 189F5.F5CAB2.v2026-08-10.q41
- 292APA.CPP-Remote.v2026-08-08.q109
PDF 파일 다운로드
메일 주소를 입력하시고 다운로드 하세요. ISACA.CISA-KR.v2024-02-07.q421 모의시험 시험자료를 다운 받으세요.
