CISA-KR 문제 281
Executing nondisclosure agreements (NDAs), determining reporting requirements for vulnerabilities, and defining the testing scope are important steps when planning a penetration test, but they are not the first step.
These steps should be done after obtaining management consent for the testing, as they depend on the approval and involvement of management and other parties.
CISA-KR 문제 282
MDM can help protect corporate applications on employee-owned devices by:
Enforcing security policies and settings, such as encryption, password, firewall, antivirus, and VPN.
Controlling the installation, update, and removal of corporate applications and data.
Separating corporate and personal data and applications on the device using containers or profiles.
Monitoring and auditing the device's compliance status, activity, and location.
Performing remote actions, such as lock, wipe, backup, or restore, in case of loss, theft, or compromise.
MDM can provide a comprehensive and centralized approach to maintain the security of corporate applications on employee-owned devices, regardless of the device type, platform, or ownership. MDM can also help the organization comply with regulatory and industry standards for data protection and privacy.
Enabling remote data destruction capabilities is a useful feature for maintaining the security of corporate applications on employee-owned devices, but it is not the best method by itself. Remote data destruction allows the organization to erase the corporate data and applications from the device in case of loss, theft, or compromise. However, this feature does not prevent unauthorized access or misuse of the corporate data and applications before they are destroyed. Remote data destruction is usually part of an MDM solution.
Disabling unnecessary network connectivity options is a good practice for maintaining the security of corporate applications on employee-owned devices, but it is not the best method by itself. Network connectivity options, such as Wi-Fi, Bluetooth, NFC, or USB, can expose the device to potential attacks or data leakage. Disabling these options when they are not needed can reduce the attack surface and improve battery life. However, this practice does not address other security risks or requirements for the corporate applications on the device. Disabling network connectivity options can also be part of an MDM solution.
Requiring security awareness training for mobile users is an important measure for maintaining the security of corporate applications on employee-owned devices, but it is not the best method by itself. Security awareness training can educate the users about the potential threats and best practices for using their devices securely. It can also help foster a culture of security and responsibility among the users. However, security awareness training cannot guarantee that the users will follow the security policies and guidelines consistently and correctly. Security awareness training should be complemented by technical controls, such as MDM.
References:
Protecting Corporate Data on Mobile Devices for All Companies1
Mobile Device Security: Corporate-Owned Personally-Enabled (COPE)23
CISA-KR 문제 283
Documentation of the service provider's security configuration controls is a source of evidence that a third- party service provider's information security controls are effective, but it is not the best evidence.
Documentation of the security configuration controls can show the settings and parameters of the service provider's information systems and networks, but it may not reflect the actual implementation and operation of the controls. Documentation of the security configuration controls may also be outdated, incomplete, or inaccurate.
An interview with the service provider's information security officer is a source of evidence that a third-party service provider's information security controls are effective, but it is not the best evidence. An interview with the information security officer can provide insights into the service provider's information security strategy, policies, and procedures, but it may not verify the actual performance and compliance of the information security controls. An interview with the information security officer may also be biased, subjective, or misleading.
A review of the service provider's policies and procedures is a source of evidence that a third-party service provider's information security controls are effective, but it is not the best evidence. A review of the policies and procedures can show the service provider's information security objectives, requirements, and guidelines, but it may not demonstrate the actual execution and enforcement of the information security controls. A review of the policies and procedures may also be insufficient, inconsistent, or outdated.
References:
* ISACA, CISA Review Manual, 27th Edition, 2019, p. 284
* ISACA, CISA Review Questions, Answers & Explanations Database - 12 Month Subscription
CISA-KR 문제 284
Reference: CISA Vulnerability Scanning, Description.
CISA-KR 문제 285
* CISA Review Manual (Digital Version), Chapter 1, Section 1.3.21
* CISA Online Review Course, Domain 5, Module 2, Lesson 22
- 다른 버전
- 3882ISACA.CISA-KR.v2026-05-16.q709
- 1779ISACA.CISA-KR.v2026-05-06.q261
- 3102ISACA.CISA-KR.v2026-03-16.q665
- 4456ISACA.CISA-KR.v2026-03-07.q651
- 9190ISACA.CISA-KR.v2025-04-07.q633
- 4442ISACA.CISA-KR.v2025-04-03.q628
- 3643ISACA.CISA-KR.v2025-04-02.q544
- 4202ISACA.CISA-KR.v2025-03-31.q534
- 5306ISACA.CISA-KR.v2025-03-28.q617
- 3966ISACA.CISA-KR.v2025-03-03.q807
- 5124ISACA.CISA-KR.v2024-02-07.q421
- 2793ISACA.CISA-KR.v2024-01-31.q392
- 5260ISACA.CISA-KR.v2023-10-24.q329
- 5207ISACA.CISA-KR.v2023-07-31.q266
- 3098ISACA.CISA-KR.v2023-06-23.q324
- 최근 업로드
- 136Microsoft.DP-900-KR.v2026-08-13.q130
- 228Microsoft.PL-600.v2026-08-11.q206
- 168Microsoft.DP-100.v2026-08-11.q160
- 168Oracle.1Z0-1048-25.v2026-08-11.q68
- 143ISQI.CTAL-TAE.v2026-08-11.q37
- 186ServiceNow.CIS-HR.v2026-08-11.q84
- 255Salesforce.Plat-Arch-201.v2026-08-10.q101
- 243Databricks.Databricks-Machine-Learning-Professional.v2026-08-10.q76
- 190F5.F5CAB2.v2026-08-10.q41
- 297APA.CPP-Remote.v2026-08-08.q109
PDF 파일 다운로드
메일 주소를 입력하시고 다운로드 하세요. ISACA.CISA-KR.v2025-03-19.q581 모의시험 시험자료를 다운 받으세요.
