CISA-KR 문제 446
Mapping IT processes to roles can help to identify such dependencies and assess their impact on the continuity and security of IT operations. The other activities do not provide as much insight into single person dependencies, as they do not show the relationship between IT processes and roles. References: CISA Review Manual, 27th Edition, page 94
CISA-KR 문제 447
According to the ISACA Code of Professional Ethics, IS auditors should maintain objectivity and independence in their professional judgment and avoid any situations that may impair or be presumed to impair their objectivity or independence1. Objectivity is the mental attitude of an IS auditor that allows them to perform their work honestly, impartially, and with integrity, while independence is the freedom from conditions that threaten the ability of an IS auditor to carry out their work in an unbiased manner2.
The IS audit manager who was involved in supervising the payroll application upgrade project may have a self-review threat, which is the risk that an IS auditor will not appropriately evaluate the results of a previous judgment made or service performed by them or their subordinates3. The IS audit manager may also have a familiarity threat, which is the risk that an IS auditor will be influenced by a close relationship with someone involved in the project or by their own personal interests4. These threats may compromise the IS audit manager's objectivity and independence and affect the quality and credibility of the audit.
Therefore, the IS audit manager should disclose their involvement in the project to their senior management and the audit committee and decline to perform or manage the audit. The IS audit manager should also recommend outsourcing the audit to independent and qualified resources who have no connection or interest in the project and who have the necessary skills and experience to conduct a reliable and effective audit.
The other options are not the best course of action for the IS audit manager.
Transferring the assignment to a different audit manager despite lack of IT project management experience is not the best course of action because it may result in a low-quality audit that does not meet the expectations and standards of the stakeholders. IT project management experience is essential for auditing an IT project, as it requires knowledge of project management methodologies, tools, techniques, risks, and best practices. An audit manager who lacks IT project management experience may not be able to plan, execute, report, and follow up on the audit effectively and efficiently.
Managing the audit since there is no one else with the appropriate experience is not the best course of action because it violates the ethical principles and standards of objectivity and independence for IS auditors.
Managing the audit would create a conflict of interest and a threat to objectivity and independence for the IS audit manager, as they would be reviewing their own work or that of their subordinate. Managing the audit would also undermine the credibility and reliability of the audit results and recommendations, as they may be biased or influenced by personal or professional relationships or interests.
Having a senior IS auditor manage the project with the IS audit manager performing final review is not the best course of action because it still involves the IS audit manager in the audit process, which poses a conflict of interest and a threat to objectivity and independence. Performing final review would require the IS audit manager to evaluate and approve the work done by the senior IS auditor, which may be affected by their previous involvement in or knowledge of the project. Performing final review would also expose theIS audit manager to undue pressure or influence from management or other stakeholders who may have expectations or preferences regarding the audit outcome.
CISA-KR 문제 448
Continuous auditing of access controls can help detect and prevent unauthorized access, data leakage, data manipulation, or data loss that could compromise the security, reliability, or compliance of the real-time data systems.
Testing encryption standards on the disaster recovery system is not the best process for continuous auditing for a large financial institution. Encryption standards are important for protecting the data stored or transmitted by the disaster recovery system, which is a system that provides backup and recovery capabilities in case of a disruption or disaster. However, testing encryption standards is not a continuous process, but rather a periodic or event-driven process that can be performed as part of the disaster recovery plan testing or validation.
Performing parallel testing between systems is not the best process for continuous auditing for a large financial institution. Parallel testing is a process of comparing the results of two or more systems that perform the same function or task, such as a new system and an old system, or a primary system and a backup system.
Parallel testing can help verify the accuracy, consistency, and compatibility of the systems. However, parallel testing is not a continuous process, but rather a temporary or transitional process that can be performed as part of the system implementation or migration.
Validating performance of help desk metrics is not the best process for continuous auditing for a large financial institution. Help desk metrics are indicators that measure the efficiency, effectiveness, and quality of the help desk service, which is a service that provides technical support and assistance to the users of information systems and technology. Help desk metrics can include metrics such as response time, resolution time, customer satisfaction, and service level agreement (SLA) compliance. Validating performance of help desk metrics can help evaluate and improve the help desk service. However, validating performance of help desk metrics is not a continuous auditing process, but rather a continuous monitoring process that can be performed by the help desk management or quality assurance team.
References:
* All eyes on: Continuous auditing - KPMG Global 1
* Internal audit's role at financial institutions: PwC 2
* The Fed - Supervisory Policy and Guidance Topics - Large Banking ... 3
* Continuous Audit: Definition, Steps, Advantages and Disadvantages 4
CISA-KR 문제 449
* CISA Review Manual (Digital Version)
* CISA Questions, Answers & Explanations Database
CISA-KR 문제 450
A rollback strategy, test cases, and post-implementation review objectives are not the most important considerations for a go-live decision when implementing an upgraded ERP system. These are important elements of project planning, execution, and evaluation, but they are not sufficient to determine whether the project is worth pursuing or delivering. These elements should be aligned with and derived from the business case.
- 다른 버전
- 4089ISACA.CISA-KR.v2026-05-16.q709
- 1820ISACA.CISA-KR.v2026-05-06.q261
- 3150ISACA.CISA-KR.v2026-03-16.q665
- 4532ISACA.CISA-KR.v2026-03-07.q651
- 9316ISACA.CISA-KR.v2025-04-07.q633
- 4465ISACA.CISA-KR.v2025-04-03.q628
- 3713ISACA.CISA-KR.v2025-04-02.q544
- 4244ISACA.CISA-KR.v2025-03-31.q534
- 5347ISACA.CISA-KR.v2025-03-28.q617
- 4048ISACA.CISA-KR.v2025-03-03.q807
- 5215ISACA.CISA-KR.v2024-02-07.q421
- 2870ISACA.CISA-KR.v2024-01-31.q392
- 5385ISACA.CISA-KR.v2023-10-24.q329
- 5219ISACA.CISA-KR.v2023-07-31.q266
- 3212ISACA.CISA-KR.v2023-06-23.q324
- 최근 업로드
- 125Microsoft.AZ-305-KR.v2026-08-14.q177
- 164Microsoft.DP-900-KR.v2026-08-13.q130
- 272Microsoft.PL-600.v2026-08-11.q206
- 215Microsoft.DP-100.v2026-08-11.q160
- 186Oracle.1Z0-1048-25.v2026-08-11.q68
- 156ISQI.CTAL-TAE.v2026-08-11.q37
- 200ServiceNow.CIS-HR.v2026-08-11.q84
- 260Salesforce.Plat-Arch-201.v2026-08-10.q101
- 248Databricks.Databricks-Machine-Learning-Professional.v2026-08-10.q76
- 195F5.F5CAB2.v2026-08-10.q41
PDF 파일 다운로드
메일 주소를 입력하시고 다운로드 하세요. ISACA.CISA-KR.v2025-03-19.q581 모의시험 시험자료를 다운 받으세요.
