CISA-KR 문제 41
CISA-KR 문제 42
Disposing backup media prematurely may result in data loss, unavailability, or corruption, which may have severe consequences for the bank's reputation, operations, and security. Backup media not being reviewed before disposal, degaussing being used instead of physical shredding, and hardware not being destroyed by a certified vendor are also findings that may pose some risks to the bank's disposal process, but they are not as critical as backup media being disposed before the end of the retention period. References: ISACA CISA Review Manual 27th Edition, page 302.
CISA-KR 문제 43
The other options are less effective physical controls for data center access. The data center is patrolled by a security guard is a deterrent measure, but it does not prevent unauthorized access by itself. A security guard may not be able to monitor all entry points, or may be distracted, bribed, or overpowered by intruders. Access to the data center is monitored by video cameras is a detective measure, but it does not prevent unauthorized access either. Video cameras can record the activities of intruders, but they cannot stop them from entering or alert the security personnel in real time. ID badges must be displayed before access is granted is a preventive measure, but it relies on human verification, which can be prone to errors or manipulation. ID badges can also be lost, stolen, or forged by intruders.
References:
Mantrap (access control) - Wikipedia1
Tailgating (security) - Wikipedia2
CISA-KR 문제 44
Recommending the application be patched to meet requirements is not the best way for the auditor to address this issue. Patching the application may not be feasible, cost-effective, or timely, given that the application will be decommissioned in three months. Patching the application may also introduce new risks or errors that could affect the functionality or performance of the application.
Informing the IT director of the policy noncompliance is not the best way for the auditor to address this issue.
Informing the IT director of the policy noncompliance may not resolve the issue or mitigate the risk, especially if the IT director is already aware of the situation and has decided to accept it. Informing the IT director of the policy noncompliance may also create unnecessary conflict or tension between the auditor and the auditee.
Taking no action since the application will be decommissioned in three months is not the best way for the auditor to address this issue. Taking no action may expose the organization to significant risks or consequences, such as data breaches, regulatory fines, or reputational damage, if the application is compromised or exploited by malicious actors. Taking no action may also violate the auditor's professional standards and responsibilities, such as due care, objectivity, and reporting.
References:
* ISACA, CISA Review Manual, 27th Edition, 2019, p. 289
* ISACA, CISA Review Questions, Answers & Explanations Database - 12 Month Subscription
* Cybersecurity Engineering for Legacy Systems: 6 Recommendations - SEI Blog
* How to Secure Your Company's Legacy Applications - iCorps
CISA-KR 문제 45
A change control log is a record of all changes made to the system, including the date, time, description, reason, authorization, and impact of each change3. A change control log can help the IS auditor to verify whether modifications to the operating system parameters were authorized by comparing the log entries with the actual system settings and the change approval documents4.
- 다른 버전
- 193ISACA.CISA-KR.v2026-08-15.q712
- 4124ISACA.CISA-KR.v2026-05-16.q709
- 1821ISACA.CISA-KR.v2026-05-06.q261
- 3156ISACA.CISA-KR.v2026-03-16.q665
- 4539ISACA.CISA-KR.v2026-03-07.q651
- 9321ISACA.CISA-KR.v2025-04-07.q633
- 4472ISACA.CISA-KR.v2025-04-03.q628
- 3719ISACA.CISA-KR.v2025-04-02.q544
- 4247ISACA.CISA-KR.v2025-03-31.q534
- 3245ISACA.CISA-KR.v2025-03-19.q581
- 4051ISACA.CISA-KR.v2025-03-03.q807
- 5215ISACA.CISA-KR.v2024-02-07.q421
- 2871ISACA.CISA-KR.v2024-01-31.q392
- 5386ISACA.CISA-KR.v2023-10-24.q329
- 5229ISACA.CISA-KR.v2023-07-31.q266
- 3222ISACA.CISA-KR.v2023-06-23.q324
- 최근 업로드
- 193ISACA.CISA-KR.v2026-08-15.q712
- 147Microsoft.MS-700-KR.v2026-08-15.q203
- 125Microsoft.AZ-305-KR.v2026-08-14.q177
- 180Microsoft.DP-900-KR.v2026-08-13.q130
- 278Microsoft.PL-600.v2026-08-11.q206
- 217Microsoft.DP-100.v2026-08-11.q160
- 186Oracle.1Z0-1048-25.v2026-08-11.q68
- 158ISQI.CTAL-TAE.v2026-08-11.q37
- 200ServiceNow.CIS-HR.v2026-08-11.q84
- 262Salesforce.Plat-Arch-201.v2026-08-10.q101
PDF 파일 다운로드
메일 주소를 입력하시고 다운로드 하세요. ISACA.CISA-KR.v2025-03-28.q617 모의시험 시험자료를 다운 받으세요.
