CISA-KR 문제 421
* CISA Review Manual (Digital Version), Chapter 5, Section 5.2.11
* CISA Review Questions, Answers & Explanations Database, Question ID 203
CISA-KR 문제 422
The exercise was completed by local management is not a cause for concern, as it shows that the threat assessment is conducted by the people who are most familiar with the data center's operations, environment, and risks. Local management may have more relevant and accurate information and insights than external parties, and may be more invested in the outcome of the threat assessment.
Neighboring organizations' operations have been included is not a cause for concern, as it shows that the threat assessment is holistic and contextual, and considers the interdependencies and influences of external factors on the data center's security. Neighboring organizations' operations may pose direct or indirect threats to the data center, such as physical damage, network interference, or shared vulnerabilities.
References:
* IBM Security Services 2016 Cyber Security Intelligence Index 1
CISA-KR 문제 423
The other options are not as effective as automated monitoring of logs for detecting DDoS attacks. Customer service complaints are an indirect and delayed indicator of a DDoS attack, as they rely on users reporting problems with accessing a website or service. Customer service complaints may also be caused by other factors unrelated to DDoS attacks, such as server errors or network issues. Server crashes are an extreme and undesirable indicator of a DDoS attack, as they indicate that the server has already been overwhelmed by the attack and has stopped functioning. Server crashes may also result in data loss or corruption, service disruption, or reputational damage. Penetration testing is a proactive and preventive measure for assessing the security posture of a system or network, but it does not detect ongoing DDoS attacks. Penetration testing may involve simulating DDoS attacks to test the resilience or vulnerability of a system or network, but it does not monitor real-time traffic or identify actual attackers.
References:
* ISACA CISA Review Manual 27th Edition (2019), page 254
* How to prevent DDoS attacks | Methods and tools | Cloudflare2
* Understanding Denial-of-Service Attacks | CISA3
CISA-KR 문제 424
Data owners are the persons or entities that have the authority and responsibility for the business processes and functions that collect, use, store, and dispose of data1.
Data owners are accountable for ensuring that the data is handled in compliance with the applicable laws, regulations, policies, and standards, such as the GDPR and the PIPEDA1234.
Data owners are in the best position to determine the purpose and necessity of collecting and retaining data, as well as the risks and benefits associated with it1.
Data owners should consult with other stakeholders, such as the risk manager, the database administrator (DBA), and the privacy manager, to establish and implement appropriate data classification policies and procedures2.
Data classification is the process of organizing data in groups based on their attributes and characteristics, and then assigning class labels that describe a set of attributes that hold true for the corresponding data sets345.
Data classification helps organizations to identify, manage, protect, and understand their data, as well as to comply with modern data privacy regulations345.
Data classification also helps to determine appropriate user access levels, which means defining who can access, modify, share, or delete data based on their roles, responsibilities, and needs345.
Determining appropriate user access levels is the most important responsibility of data owners when implementing a data classification process, as it ensures that only authorized and legitimate users can access sensitive or important data. This provides confidentiality, integrity, availability, and accountability of data345.
Reviewing emergency changes to data (option A), authorizing application code changes (option B), and implementing access rules over database tables (option D) are not the most important responsibilities of data owners when implementing a data classification process. These are more related to the operational aspects of data management, which are usually delegated to other roles, such as the DBA or the IT staff. The data owner should oversee and approve these activities, but not perform them directly1.
CISA-KR 문제 425
Therefore, this should be the auditor's greatest concern among the given options. References:
* ISACA, IT Control Objectives for Sarbanes-Oxley, 4th Edition, section 5.3.21
* ISACA, CISA Review Manual, 27th Edition, chapter 5, section 5.42
- 다른 버전
- 4088ISACA.CISA-KR.v2026-05-16.q709
- 1819ISACA.CISA-KR.v2026-05-06.q261
- 3148ISACA.CISA-KR.v2026-03-16.q665
- 4530ISACA.CISA-KR.v2026-03-07.q651
- 9316ISACA.CISA-KR.v2025-04-07.q633
- 4465ISACA.CISA-KR.v2025-04-03.q628
- 3713ISACA.CISA-KR.v2025-04-02.q544
- 4244ISACA.CISA-KR.v2025-03-31.q534
- 5347ISACA.CISA-KR.v2025-03-28.q617
- 4045ISACA.CISA-KR.v2025-03-03.q807
- 5214ISACA.CISA-KR.v2024-02-07.q421
- 2870ISACA.CISA-KR.v2024-01-31.q392
- 5385ISACA.CISA-KR.v2023-10-24.q329
- 5219ISACA.CISA-KR.v2023-07-31.q266
- 3212ISACA.CISA-KR.v2023-06-23.q324
- 최근 업로드
- 125Microsoft.AZ-305-KR.v2026-08-14.q177
- 164Microsoft.DP-900-KR.v2026-08-13.q130
- 270Microsoft.PL-600.v2026-08-11.q206
- 204Microsoft.DP-100.v2026-08-11.q160
- 185Oracle.1Z0-1048-25.v2026-08-11.q68
- 154ISQI.CTAL-TAE.v2026-08-11.q37
- 199ServiceNow.CIS-HR.v2026-08-11.q84
- 259Salesforce.Plat-Arch-201.v2026-08-10.q101
- 248Databricks.Databricks-Machine-Learning-Professional.v2026-08-10.q76
- 194F5.F5CAB2.v2026-08-10.q41
PDF 파일 다운로드
메일 주소를 입력하시고 다운로드 하세요. ISACA.CISA-KR.v2025-03-19.q581 모의시험 시험자료를 다운 받으세요.
