CISA-KR 문제 426
CISA-KR 문제 427
Data backup and retrieval are essential processes for ensuring the availability, integrity, and security of data in case of loss, corruption, or damage2. Data backup is the process of creating and storing copies of data in a separate location from the original data2. Data retrieval is the process of accessing and restoring the backed- up data when needed2. Critical data are data that are vital for the operation, continuity, and recovery of the organization3.
If the vendor is unable to restore critical data, the organization may face severe consequences, such as:
Business disruption: The organization may not be able to perform its core functions, deliver its products or services, or meet its customer or stakeholder expectations3.
Revenue loss: The organization may lose income, market share, or competitive advantage due to reduced sales, customer dissatisfaction, or reputation damage3.
Legal liability: The organization may face lawsuits, fines, or penalties for breaching contractual, regulatory, or statutory obligations related to data protection, privacy, or security3.
Recovery cost: The organization may incur additional expenses for repairing or replacing the lost or corrupted data, restoring the system functionality, or compensating the affected parties3.
The other options are not as great as the vendor's inability to restore critical data. The organization may be locked into an unfavorable contract with the vendor, which may limit its flexibility, control, or choice over the service quality, cost, or duration4. However, this risk can be mitigated by negotiating better terms and conditions, reviewing the contract periodically, or switching to another vendor if possible4. The vendor may be unable to restore data by recovery time objective (RTO) requirements, which are the maximum acceptable time frames for restoring data after a disruption5. However, this risk can be reduced by setting realistic and achievable RTOs, monitoring the vendor's performance, or implementing alternative recovery strategies if needed5. The organization may not be allowed to inspect the vendor's data center, which may limit its visibility, transparency, or assurance over the service provider's infrastructure, security, or compliance.
However, this risk can be overcome by requesting third-party audits, certifications, or reports from the vendor that demonstrate their adherence to industry standards and best practices. Therefore, option B is the correct answer.
References:
What is SaaS? Software as a Service | Microsoft Azure
What is Data Backup? - Definition from Techopedia
Critical Data Definition
The Risks of Cloud Computing | Cloud Academy
Recovery Time Objective (RTO) Definition
[Cloud Computing Security Risks: What You Need To Know | CloudHealth by VMware]
CISA-KR 문제 428
CISA-KR 문제 429
Demonstrated support from which of the following roles in an organization has the most influence over information security governance? The answer is C, the board of directors. The board of directors is the highest governing body of an organization, responsible for overseeing its strategic direction, performance, and accountability. The board of directors sets the tone at the top for information security governance by:
* Establishing a clear vision, mission, and values for information security
* Approving and reviewing information security policies and standards
* Allocating sufficient resources and budget for information security
* Appointing and empowering a chief information security officer (CISO) or equivalent role
* Holding management accountable for information security performance and compliance
* Communicating and promoting information security awareness and culture The board of directors has the most influence over information security governance because it has the ultimate authority and responsibility for ensuring that information security is aligned with the organization's business objectives, risks, and stakeholder expectations.
References:
* 10: What is Information Security Governance? - RiskOptics - Reciprocity
* 11: Information Security Governance and Risk Management | Moss Adams
* 12: ISO/IEC 27014:2020 - Information security, cybersecurity and privacy ...
CISA-KR 문제 430
* ISACA, CISA Review Manual, 27th Edition, chapter 4, section 4.41
* ISACA, COBIT 2019 Framework: Introduction and Methodology, section 3.2
- 다른 버전
- 4088ISACA.CISA-KR.v2026-05-16.q709
- 1819ISACA.CISA-KR.v2026-05-06.q261
- 3148ISACA.CISA-KR.v2026-03-16.q665
- 4530ISACA.CISA-KR.v2026-03-07.q651
- 9316ISACA.CISA-KR.v2025-04-07.q633
- 4465ISACA.CISA-KR.v2025-04-03.q628
- 3713ISACA.CISA-KR.v2025-04-02.q544
- 4244ISACA.CISA-KR.v2025-03-31.q534
- 5347ISACA.CISA-KR.v2025-03-28.q617
- 4045ISACA.CISA-KR.v2025-03-03.q807
- 5214ISACA.CISA-KR.v2024-02-07.q421
- 2870ISACA.CISA-KR.v2024-01-31.q392
- 5385ISACA.CISA-KR.v2023-10-24.q329
- 5219ISACA.CISA-KR.v2023-07-31.q266
- 3212ISACA.CISA-KR.v2023-06-23.q324
- 최근 업로드
- 125Microsoft.AZ-305-KR.v2026-08-14.q177
- 164Microsoft.DP-900-KR.v2026-08-13.q130
- 270Microsoft.PL-600.v2026-08-11.q206
- 204Microsoft.DP-100.v2026-08-11.q160
- 185Oracle.1Z0-1048-25.v2026-08-11.q68
- 154ISQI.CTAL-TAE.v2026-08-11.q37
- 199ServiceNow.CIS-HR.v2026-08-11.q84
- 259Salesforce.Plat-Arch-201.v2026-08-10.q101
- 248Databricks.Databricks-Machine-Learning-Professional.v2026-08-10.q76
- 194F5.F5CAB2.v2026-08-10.q41
PDF 파일 다운로드
메일 주소를 입력하시고 다운로드 하세요. ISACA.CISA-KR.v2025-03-19.q581 모의시험 시험자료를 다운 받으세요.
