CISA-KR 문제 336
CISA-KR 문제 337
The greatest risk when relying on reports generated by EUC is that the data may be inaccurate. Data accuracy refers to the extent to which the data in the reports reflect the true values of the underlying information4.
Inaccurate data can lead to erroneous decisions, misleading analysis, unreliable reporting, and compliance violations. Some of the factors that can cause data inaccuracy in EUC reports are:
Lack of rigorous testing: EUC tools may not undergo the same level of testing and validation as IT-developed applications, which can result in errors, bugs, or inconsistencies in the data processing and output3.
Lack of version and change control: EUC tools may not have a clear record of the changes made to them over time, which can create confusion, duplication, or loss of data. Users may also modify or overwrite the data without proper authorization or documentation3.
Lack of documentation and reliance on end-user who developed it: EUC tools may not have sufficient documentation to explain their purpose, functionality, assumptions, limitations, and dependencies. Users may also rely on the knowledge and expertise of the original developer, who may not be available or may not have followed best practices3.
Lack of maintenance processes: EUC tools may not have regular updates, backups, or reviews to ensure their functionality and security. Users may also neglect to delete or archive obsolete or redundant data3.
Lack of security: EUC tools may not have adequate access controls, encryption, or authentication mechanisms to protect the data from unauthorized access, modification, or disclosure. Users may also store or share the data in insecure locations or devices3.
Lack of audit trail: EUC tools may not have a traceable history of the data sources, inputs, outputs, calculations, and transformations. Users may also manipulate or falsify the data without detection or accountability3.
Overreliance on manual controls: EUC tools may depend on human intervention to input, verify, or correct the data, which can introduce errors, delays, or biases. Users may also lack the skills or training to use the EUC tools effectively and efficiently3.
The other options are not as great as data inaccuracy when relying on EUC reports. Reports may not work efficiently, reports may not be timely, and historical data may not be available are all potential risks associated with EUC tools, but they are less severe and less frequent than data inaccuracy. Moreover, these risks can be mitigated by improving the performance, scheduling, and storage of the EUC tools. However, data inaccuracy can have a pervasive and lasting impact on the quality and credibility of the reports and the decisions based on them. Therefore, option A is the correct answer.
References:
What is Data Accuracy?
What Is End User Computing (EUC) Risk?
End-user computing
End-User Computing (EUC) Risks: A Comprehensive Guide
CISA-KR 문제 338
CISA-KR 문제 339
The other options are not the best evidence of continuous compliance with the anti-malware policy. Penetration testing results are reports that show the vulnerabilities and risks of the workstations and network from an external or internal attacker's perspective4. While penetration testing can help to assess the security posture and resilience of the organization, it does not provide information on the daily anti-malware scans or their outcomes. Management attestation is a statement or declaration from the management that they have complied with the anti-malware policy5. While management attestation can demonstrate commitment and accountability, it does not provide objective or verifiable evidence of compliance. Recent malware scan reports are documents that show the summary or details of the latest anti-malware scans performed on the workstations. While recent malware scan reports can indicate the current status and performance of the anti- malware software, they do not provide historical or comprehensive evidence of compliance.
References:
Malwarebytes Anti-Malware (MBAM) log collection and threat reports ...
Malicious Behavior Detection using Windows Audit Logs
PCI Requirement 5.2 - Ensure all Anti-Virus Mechanisms are Current ...
Management Attestation - an overview | ScienceDirect Topics
How to Read a Malware Scan Report | Techwalla
CISA-KR 문제 340
It provides an opportunity to identify and correct any issues or conflicts that may have arisen during the development and implementation process. While other options like adding developers to the change approval board, limiting code deployment access to a small number of people, and creating staging environments can also serve as compensating controls, a post-implementation change review provides a more comprehensive and effective control mechanism21.
References:
Review and Close Change process ST 2 5 - Micro Focus
Change Management for SOC: Risks, Controls, Audits, Guidance
- 다른 버전
- 4087ISACA.CISA-KR.v2026-05-16.q709
- 1818ISACA.CISA-KR.v2026-05-06.q261
- 3147ISACA.CISA-KR.v2026-03-16.q665
- 4525ISACA.CISA-KR.v2026-03-07.q651
- 9314ISACA.CISA-KR.v2025-04-07.q633
- 4465ISACA.CISA-KR.v2025-04-03.q628
- 3713ISACA.CISA-KR.v2025-04-02.q544
- 4243ISACA.CISA-KR.v2025-03-31.q534
- 5346ISACA.CISA-KR.v2025-03-28.q617
- 4043ISACA.CISA-KR.v2025-03-03.q807
- 5213ISACA.CISA-KR.v2024-02-07.q421
- 2869ISACA.CISA-KR.v2024-01-31.q392
- 5385ISACA.CISA-KR.v2023-10-24.q329
- 5219ISACA.CISA-KR.v2023-07-31.q266
- 3212ISACA.CISA-KR.v2023-06-23.q324
- 최근 업로드
- 121Microsoft.AZ-305-KR.v2026-08-14.q177
- 163Microsoft.DP-900-KR.v2026-08-13.q130
- 270Microsoft.PL-600.v2026-08-11.q206
- 203Microsoft.DP-100.v2026-08-11.q160
- 180Oracle.1Z0-1048-25.v2026-08-11.q68
- 153ISQI.CTAL-TAE.v2026-08-11.q37
- 197ServiceNow.CIS-HR.v2026-08-11.q84
- 259Salesforce.Plat-Arch-201.v2026-08-10.q101
- 247Databricks.Databricks-Machine-Learning-Professional.v2026-08-10.q76
- 193F5.F5CAB2.v2026-08-10.q41
PDF 파일 다운로드
메일 주소를 입력하시고 다운로드 하세요. ISACA.CISA-KR.v2025-03-19.q581 모의시험 시험자료를 다운 받으세요.
