CISA-KR 문제 266
References
1: IT Governance and the Balanced Scorecard - ISACA Journal
2: IT Steering Committee Best Practices: A Recipe for Success
3: What is IT Governance? - Definition from Techopedia
4: CISA Cybersecurity Strategic Plan | CISA
CISA-KR 문제 267
One of the key aspects of change management is measuring its effectiveness, which means assessing whether the changes have achieved the desired outcomes and met the expectations of the stakeholders. There are various indicators that can be used to measure change management effectiveness, such as time, cost, quality, scope, satisfaction, and performance.
Among the four options given, the most appropriate indicator of change management effectiveness is the number of incidents resulting from changes. An incident is an unplanned event or interruption that affects the normal operation or service delivery of an information system. Incidents can be caused by various factors, such as errors, defects, failures, malfunctions, or malicious attacks. Incidents can have negative impacts on the organization, such as loss of data, productivity, reputation, or revenue.
The number of incidents resulting from changes is a direct measure of how well the changes have been planned, implemented, monitored, and evaluated. A high number of incidents indicates that the changes have not been properly tested, verified, communicated, or controlled. A low number of incidents indicates that the changes have been executed smoothly and successfully. Therefore, the number of incidents resulting from changes reflects the quality and effectiveness of the change management process.
The other three options are not as appropriate indicators of change management effectiveness as the number of incidents resulting from changes. The time lag between changes to the configuration and the update of records is a measure of how timely and accurate the configuration management process is. Configuration management is a subset of change management that focuses on identifying, documenting, and controlling the configuration items (CIs) that make up an information system. The time lag between changes and updates of documentation materials is a measure of how well the documentation process is aligned with the change management process. Documentation is an important aspect of change management that provides information and guidance to the stakeholders involved in or affected by the changes. The number of system software changes is a measure of how frequently and extensively the system software is modified or updated. System software changes are a type of change that affects the operating system, middleware, or utilities that support an information system.
While these three indicators are relevant and useful for measuring certain aspects of change management, they do not directly measure the outcomes or impacts of the changes on the organization. They are more related to the inputs or activities of change management than to its outputs or results. Therefore, they are not as appropriate indicators of change management effectiveness as the number of incidents resulting from changes.
References:
* Metrics for Measuring Change Management - Prosci
* How to Measure Change Management Effectiveness: Metrics, Tools & Processes
* Metrics for Measuring Change Management 2023 - Zendesk
CISA-KR 문제 268
Verifying user management approval of modifications is a method of verifying that the changes to production programs were authorized and documented, but it does not ensure that the changes were implemented correctly or accurately. References: CISA Review Manual (Digital Version) , Chapter 4: Information Systems Operations and Business Resilience, Section 4.3: Change Management Practices.
CISA-KR 문제 269
CISA-KR 문제 270
An insider attack poses the greatest risk to an organization's most sensitive data because:
An insider has a high level of trust and privilege within the organization, which allows them to bypass security controls and access confidential or restricted data without raising suspicion or detection.
An insider has a deep knowledge of the organization's operations, processes, policies, and vulnerabilities, which enables them to exploit them effectively and cause maximum damage or disruption.
An insider can use various techniques and tools to conceal their identity and actions, such as encryption, steganography, deletion, or alteration of logs or evidence.
An insider can cause significant harm or loss to the organization in terms of data integrity, availability, confidentiality, reputation, compliance, and profitability.
According to the 2023 Cost of Insider Threats Global Report by Ponemon Institute and ObserveIT 1, the average annual cost of insider threats for organizations worldwide was $11.45 million in 2022, a 31% increase from 2018. The report also found that the average number of incidents per organization was 77 in 2022, a
47% increase from 2018. The report classified insider threats into three categories: careless or negligent employees or contractors, criminal or malicious insiders, and credential thieves. The report revealed that careless or negligent insiders were the most common and costly type of insider threat, accounting for 62% of all incidents and $4.58 million in costs.
The other options are not the greatest risk to an organization's most sensitive data, although they can still pose significant threats.
A password attack is a type of cyberattack that attempts to guess or crack a user's password to gain unauthorized access to their account or system. A password attack can use various methods, such as brute force, dictionary, rainbow table, phishing, keylogging, or social engineering. A password attack can compromise the security and privacy of the user's data and information. However, a password attack can be prevented or mitigated by using strong and unique passwords, changing passwords frequently, enabling multi- factor authentication (MFA), and avoiding clicking on suspicious links or attachments.
An eavesdropping attack is a type of cyberattack that intercepts or monitors the communication between two parties without their knowledge or consent. An eavesdropping attack can use various techniques, such as wiretapping, packet sniffing, man-in-the-middle (MITM), or side-channel. An eavesdropping attack can expose the content and metadata of the communication, such as messages, files, voice calls, emails, etc.
However, an eavesdropping attack can be prevented or mitigated by using encryption, authentication, digital signatures, VPNs (virtual private networks), or secure protocols.
A spear phishing attack is a type of phishing attack that targets a specific individual or group with personalized and convincing emails that appear to come from a trusted source. A spear phishing attack aims to trick the recipient into clicking on a malicious link or attachment that can infect their device with malware or steal their credentials or data. A spear phishing attack can compromise the security and privacy of the recipient's data and information. However, a spear phishing attack can be prevented or mitigated by verifying the sender's identity and email address, checking the email content for spelling and grammar errors, hovering over links before clicking on them (or not clicking at all), scanning attachments for viruses before opening them (or not opening at all), and reporting suspicious emails to IT security staff.
- 다른 버전
- 3880ISACA.CISA-KR.v2026-05-16.q709
- 1779ISACA.CISA-KR.v2026-05-06.q261
- 3100ISACA.CISA-KR.v2026-03-16.q665
- 4456ISACA.CISA-KR.v2026-03-07.q651
- 9189ISACA.CISA-KR.v2025-04-07.q633
- 4442ISACA.CISA-KR.v2025-04-03.q628
- 3643ISACA.CISA-KR.v2025-04-02.q544
- 4202ISACA.CISA-KR.v2025-03-31.q534
- 5306ISACA.CISA-KR.v2025-03-28.q617
- 3966ISACA.CISA-KR.v2025-03-03.q807
- 5124ISACA.CISA-KR.v2024-02-07.q421
- 2793ISACA.CISA-KR.v2024-01-31.q392
- 5260ISACA.CISA-KR.v2023-10-24.q329
- 5207ISACA.CISA-KR.v2023-07-31.q266
- 3098ISACA.CISA-KR.v2023-06-23.q324
- 최근 업로드
- 136Microsoft.DP-900-KR.v2026-08-13.q130
- 228Microsoft.PL-600.v2026-08-11.q206
- 168Microsoft.DP-100.v2026-08-11.q160
- 168Oracle.1Z0-1048-25.v2026-08-11.q68
- 143ISQI.CTAL-TAE.v2026-08-11.q37
- 186ServiceNow.CIS-HR.v2026-08-11.q84
- 255Salesforce.Plat-Arch-201.v2026-08-10.q101
- 243Databricks.Databricks-Machine-Learning-Professional.v2026-08-10.q76
- 190F5.F5CAB2.v2026-08-10.q41
- 297APA.CPP-Remote.v2026-08-08.q109
PDF 파일 다운로드
메일 주소를 입력하시고 다운로드 하세요. ISACA.CISA-KR.v2025-03-19.q581 모의시험 시험자료를 다운 받으세요.
