CISA-KR 문제 216
References:
* 2: How Do I Secure my Data in a Multi-Tenant Cloud Environment? | Thales
* 3: Protecting Sensitive Customer Data in a Cloud-Based Multi-Tenant Environment | Saturn Cloud
* 4: Microsoft 365 isolation controls - Microsoft Service Assurance
CISA-KR 문제 217
A thin client architecture can enhance the security of desktop PCs by reducing the exposure or vulnerability of data and applications on individual devices, and centralizing the security management and control on the server. However, this advantage may depend on other factors such as network security, server security, user authentication, etc. Administrative security can be provided for the client is a possible advantage of moving from many desktop PCs to a thin client architecture, but it is not the major one. A thin client architecture can provide administrative security for clients by allowing administrators to configure and manage client devices remotely from the server, and enforce policies and restrictions on client access or usage. However, this advantage may depend on other factors such as network reliability, server availability, user compliance, etc.
System administration can be better managed is a possible advantage of moving from many desktop PCs to a thin client architecture, but it is not the major one. A thin client architecture can improve system administration by simplifying and streamlining the tasks and activities involved in maintaining and supporting client devices, such as backup, recovery, troubleshooting, etc., and consolidating them on the server.
However, this advantage may depend on other factors such as network bandwidth, server capacity, user satisfaction
CISA-KR 문제 218
Remote access servers, Secure Sockets Layers (SSLs), and failover services are not directly related to firewall protection, but rather to other aspects of network security, such as authentication, encryption, and availability. References: CISA Review Manual (Digital Version), Chapter 5: Protection of Information Assets, Section 5.2: Network Security Devices and Technologies
CISA-KR 문제 219
Data classification typically involves assigning labels or tags to data assets, such as public, internal, confidential, or restricted. These labels indicate the level of protection and handling required for the data.
Based on the data classification, organizations can implement appropriate controls to safeguard the data, such as encryption, access control lists, audit logs, backup policies, etc. These controls help to prevent unauthorized access, disclosure, modification, or loss of data, and to ensure compliance with relevant laws and regulations.
If a data owner assigns an incorrect classification level to data, it can result in either underprotection or overprotection of the data. Underprotection means that the data is classified at a lower level than it should be, which exposes it to higher risks of compromise or breach. For example, if a data owner classifies personal health information (PHI) as public instead of confidential, it may allow anyone to access or share the data without proper authorization or consent. This can violate the privacy rights of the data subjects and the compliance requirements of regulations such as HIPAA (Health Insurance Portability and Accountability Act). Overprotection means that the data is classified at a higher level than it should be, which limits its availability or usability. For example, if a data owner classifies marketing materials as restricted instead of public, it may prevent potential customers or partners from accessing or viewing the data. This can reduce the business value and opportunities of the data.
Therefore, an IS auditor should be concerned about the accuracy and consistency of data classification by data owners, as it affects the security and efficiency of data management. An IS auditor should review the policies and procedures for data classification, verify that the data owners have adequate knowledge and skills to classify their data, and test that the data classification labels match with the actual sensitivity and impact of the data.
References:
* Data Classification: What It Is and How to Implement It
* What Is Data Classification? - Definition, Levels & Examples ...
* Data Classification: A Guide for Data Security Leaders
CISA-KR 문제 220
- 다른 버전
- 3877ISACA.CISA-KR.v2026-05-16.q709
- 1779ISACA.CISA-KR.v2026-05-06.q261
- 3099ISACA.CISA-KR.v2026-03-16.q665
- 4452ISACA.CISA-KR.v2026-03-07.q651
- 9189ISACA.CISA-KR.v2025-04-07.q633
- 4440ISACA.CISA-KR.v2025-04-03.q628
- 3641ISACA.CISA-KR.v2025-04-02.q544
- 4200ISACA.CISA-KR.v2025-03-31.q534
- 5304ISACA.CISA-KR.v2025-03-28.q617
- 3965ISACA.CISA-KR.v2025-03-03.q807
- 5124ISACA.CISA-KR.v2024-02-07.q421
- 2793ISACA.CISA-KR.v2024-01-31.q392
- 5260ISACA.CISA-KR.v2023-10-24.q329
- 5200ISACA.CISA-KR.v2023-07-31.q266
- 3098ISACA.CISA-KR.v2023-06-23.q324
- 최근 업로드
- 136Microsoft.DP-900-KR.v2026-08-13.q130
- 228Microsoft.PL-600.v2026-08-11.q206
- 168Microsoft.DP-100.v2026-08-11.q160
- 168Oracle.1Z0-1048-25.v2026-08-11.q68
- 143ISQI.CTAL-TAE.v2026-08-11.q37
- 185ServiceNow.CIS-HR.v2026-08-11.q84
- 255Salesforce.Plat-Arch-201.v2026-08-10.q101
- 241Databricks.Databricks-Machine-Learning-Professional.v2026-08-10.q76
- 190F5.F5CAB2.v2026-08-10.q41
- 297APA.CPP-Remote.v2026-08-08.q109
PDF 파일 다운로드
메일 주소를 입력하시고 다운로드 하세요. ISACA.CISA-KR.v2025-03-19.q581 모의시험 시험자료를 다운 받으세요.
