CISA-KR 문제 306
An IT balanced scorecard (BSC) is a performance metric that is used to identify, improve, and control the various functions and outcomes of an IT department or organization. An IT BSC is based on the concept of the balanced scorecard, which was introduced by Robert Kaplan and David Norton in 1992 as a strategic management system that translates the vision and strategy of an organization into measurable objectives and actions. An IT BSC adapts the balanced scorecard framework to the specific needs and goals of the IT function, aligning it with the business strategy and value proposition.
An IT BSC typically consists of four perspectives that help managers plan, implement, and evaluate the IT performance: customer, internal process, learning and growth, and financial. Each perspective defines a set of objectives, measures, targets, and initiatives that reflect the IT contribution to the organization's success. For example, the customer perspective may measure the satisfaction and retention of internal and external customers who use IT services or products; the internal process perspective may measure the efficiency and effectiveness of IT processes such as development, delivery, support, or security; the learning and growth perspective may measure the skills, knowledge, innovation, and culture of the IT staff; and the financial perspective may measure the costs, benefits, and return on investment of IT projects or assets.
An IT BSC provides a new IS auditor with the most useful information to evaluate overall IT performance because it:
Provides a comprehensive and balanced view of the IT function from multiple angles and stakeholders Links the IT objectives and activities to the business strategy and value creation Enables a clear communication and alignment of expectations and priorities among IT managers, staff, customers, and other stakeholders Facilitates a continuous monitoring and improvement of IT performance based on data-driven feedback and analysis Supports a holistic and integrated approach to IT governance, risk management, and compliance Therefore, an IT BSC is a valuable tool for a new IS auditor to assess how well the IT function is fulfilling its mission and delivering value to the organization.
References:
The IT Balanced Scorecard (BSC) Explained - BMC Software
What Is a Balanced Scorecard (BSC), How Is it Used in Business?
Lost in the Woods: COBIT 2019 and the IT Balanced Scorecard - ISACA
CISA-KR 문제 307
An organization outsourced its IS functions. To meet its responsibility for disaster recovery, the organization should coordinate disaster recovery administration with the outsourcing vendor. This is because the organization remains accountable for ensuring the continuity and availability of its IS functions, even if they are outsourced to a third party. The organization should establish clear roles and responsibilities, communication channels, testing procedures, and escalation processes with the outsourcing vendor for disaster recovery purposes. The organization should not discontinue maintenance of the disaster recovery plan (DRP), as it still needs to have a documented and updated plan for restoring its IS functions in case of a disaster. The organization should not delegate evaluation of disaster recovery to a third party or internal audit, as it still needs to monitor and review the performance and compliance of the outsourcing vendor with respect to disaster recovery objectives and standards. References: CISA Review Manual (Digital Version), [ISACA Auditing Standards]
CISA-KR 문제 308
A heuristic intrusion detection system (IDS) provides the most protection against emerging threats, as it uses behavioral analysis and anomaly detection to identify unknown or zero-day attacks. A heuristic IDS can adapt to changing patterns and learn from previous incidents, making it more effective than a signature-based IDS, which relies on predefined rules and signatures to detect known attacks. A demilitarized zone (DMZ) is a network segment that separates the internal network from the external network, and it can provide some protection against external threats, but not against internal or emerging threats. Real-time updating of antivirus software is important to protect against malware, but it may not be sufficient to prevent new or sophisticated attacks that exploit unknown vulnerabilities. References: CISA Review Manual (Digital Version) 1, page
452-453.
CISA-KR 문제 309
Full disk encryption (FDE) is a means of protecting information by encrypting all of the data on a disk, including temporary files, programs, and system files1. FDE is best suited for addressing the risk scenario of physical theft of media on which information is stored, as it prevents unauthorized access to the data even if the device is lost or stolen2. FDE does not prevent data leakage as a result of employees leaving to work for competitors, as they may still have access to the data while using the device or copy the data to another device before leaving. FDE does not prevent noncompliance fines related to storage of regulated information, as it does not ensure that the data is stored in accordance with the applicable laws and regulations. FDE does not prevent unauthorized logical access to information through an application interface, as it does not control the access rights and permissions of users and applications. *References: According to the ISACA IT Audit and Assurance Standards, Guidelines and Tools and Techniques for IS Audit and Assurance Professionals, section
2402 Planning, "The IS audit and assurance professional should identify and assess risk relevant to the area under review." 3 One of the risk factors to consider is "the sensitivity of information processed, stored or transmitted by the system" 3. FDE is one of the possible controls to mitigate the risk of unauthorized disclosure of sensitive information due to physical theft of media.
CISA-KR 문제 310
Social engineering is the manipulation of people to perform actions or divulge confidential information. It is a common technique used by attackers to gain unauthorized access to systems or data. Employees who use public social networking sites may be vulnerable to social engineering attacks, such as phishing, baiting, or pretexting, which pose the greatest risk to the organization's security. The other options are not as serious as social engineering, as they relate to web application vulnerabilities, intellectual property rights, and reputation management, which are less likely to compromise the organization's assets or operations. References: CISA Review Manual (Digital Version), Domain 5: Protection of Information Assets, Section 5.3 Security Awareness Training1
- 다른 버전
- 3859ISACA.CISA-KR.v2026-05-16.q709
- 1766ISACA.CISA-KR.v2026-05-06.q261
- 3093ISACA.CISA-KR.v2026-03-16.q665
- 4444ISACA.CISA-KR.v2026-03-07.q651
- 9181ISACA.CISA-KR.v2025-04-07.q633
- 4438ISACA.CISA-KR.v2025-04-03.q628
- 3635ISACA.CISA-KR.v2025-04-02.q544
- 4196ISACA.CISA-KR.v2025-03-31.q534
- 5300ISACA.CISA-KR.v2025-03-28.q617
- 3083ISACA.CISA-KR.v2025-03-19.q581
- 3959ISACA.CISA-KR.v2025-03-03.q807
- 2792ISACA.CISA-KR.v2024-01-31.q392
- 5260ISACA.CISA-KR.v2023-10-24.q329
- 5172ISACA.CISA-KR.v2023-07-31.q266
- 3098ISACA.CISA-KR.v2023-06-23.q324
- 최근 업로드
- 102Microsoft.DP-900-KR.v2026-08-13.q130
- 227Microsoft.PL-600.v2026-08-11.q206
- 164Microsoft.DP-100.v2026-08-11.q160
- 166Oracle.1Z0-1048-25.v2026-08-11.q68
- 139ISQI.CTAL-TAE.v2026-08-11.q37
- 183ServiceNow.CIS-HR.v2026-08-11.q84
- 254Salesforce.Plat-Arch-201.v2026-08-10.q101
- 240Databricks.Databricks-Machine-Learning-Professional.v2026-08-10.q76
- 189F5.F5CAB2.v2026-08-10.q41
- 292APA.CPP-Remote.v2026-08-08.q109
PDF 파일 다운로드
메일 주소를 입력하시고 다운로드 하세요. ISACA.CISA-KR.v2024-02-07.q421 모의시험 시험자료를 다운 받으세요.
