CISA-KR 문제 531
The SLA has not been reviewed in more than a year is not the greatest concern, although it is a good practice to review and update the SLA periodically to ensure that it reflects the current business needs and expectations, as well as any changes in the service provider's capabilities or performance. However, a lack of review does not necessarily imply a lack of compliance or quality of service, as long as the SLA is still valid and enforceable34.
Backup data is hosted online only is not the greatest concern, although it may pose some security risks if the backup data is not encrypted or protected by adequate access controls. Online backup data means that the backup data is stored on a remote server that can be accessed via the Internet, which may offer some advantages such as faster recovery, lower cost, and higher availability than offline backup data that is stored on physical media such as tapes or disks. However, online backup data also requires reliable network connectivity and bandwidth, as well as proper security measures to prevent unauthorized access or tampering56.
The recovery point objective (RPO) has a shorter duration than documented in the DRP is not the greatest concern, although it may indicate some inconsistency or misalignment between the SLA and the DRP. The RPO is the maximum acceptable amount of data loss measured in time from a disaster or a disruption. A shorter RPO than the DRP means that the bank may lose less data than expected, which may be beneficial for its business continuity and recovery. However, a shorter RPO may also imply more frequent backups, which may increase the cost and complexity of the backup process
CISA-KR 문제 532
An incident response plan aims to:
Detect and identify the incident as soon as possible.
Contain and isolate the incident to prevent further damage or spread.
Analyze and investigate the incident to determine its cause, scope, and impact.
Eradicate and eliminate the incident and its root causes from the affected systems and data.
Recover and restore the normal operations and functionality of the systems and data.
Learn and improve from the incident by documenting the lessons learned, best practices, and recommendations for future prevention and mitigation.
By following an incident response plan, the organization can minimize the negative consequences of an adverse event on its information assets, such as:
Loss or corruption of data or information.
Disclosure or theft of confidential or sensitive data or information.
Interruption or degradation of system or service availability or performance.
Legal or regulatory noncompliance or liability.
Financial or reputational loss or damage.
An incident response plan also helps the organization to demonstrate its due diligence and accountability in protecting its information assets and complying with its legal and contractual obligations.
The other options are not the primary purpose of an incident response plan, although they may be secondary benefits or outcomes of having one.
Increasing the effectiveness of preventive controls is not the primary purpose of an incident response plan.
Preventive controls are controls that aim to prevent or deter incidents from occurring in the first place, such as firewalls, antivirus software, encryption, authentication, etc. An incident response plan is a reactive control that deals with incidents after they have occurred. However, an incident response plan may help to improve the effectiveness of preventive controls by identifying and addressing their weaknesses or gaps.
Reducing the maximum tolerable downtime (MTD) of impacted systems is not the primary purpose of an incident response plan. MTD is a measure of how long an organization can tolerate a system or service outage before it causes unacceptable harm or loss to its business operations or objectives. An incident response plan may help to reduce the MTD of impacted systems by facilitating a faster and smoother recovery process.
However, reducing the MTD is not the main goal of an incident response plan, but rather a desired outcome.
Increasing awareness of impacts from adverse events to IT systems is not the primary purpose of an incident response plan. Awareness is a state of being informed or conscious of something. An incident response plan may help to increase awareness of impacts from adverse events to IT systems by providing information and communication channels for stakeholders, such as management, employees, customers, regulators, etc.
However, increasing awareness is not the main objective of an incident response plan, but rather a means to achieve other objectives, such as reducing impact, ensuring compliance, or maintaining trust.
CISA-KR 문제 533
CISA-KR 문제 534
A roles and responsibility matrix can help avoid confusion, duplication, or omission of work, as well as ensure accountability and communication among the IT function and its customers, partners, and suppliers.
Therefore, an IS auditor should focus on reviewing the roles and responsibility matrix when evaluating the maturity model for a technology organization.
A standard operating procedure (SOP) is a document that describes the steps and instructions for performing a routine or repetitive task or process. SOPs are important for ensuring consistency, quality, and compliance in the IT function, but they are not directly related to the maturity model. A service level agreement (SLA) is a contract that defines the expectations and obligations between an IT service provider and its customers. SLAs are important for ensuring customer satisfaction, performance measurement, and dispute resolution in the IT function, but they are not directly related to the maturity model. A business resiliency plan is a document that outlines how an IT function will continue to operate or recover from a disruption or disaster. Business resiliency is important for ensuring availability, reliability, and security in the IT function, but it is not directly related to the maturity model. References: 1: Maturity Models for IT & Technology | Splunk 2: Responsibility assignment matrix - Wikipedia 3: Roles and Responsibilities Matrix - SDLCforms
CISA-KR 문제 535
Categorizing and prioritizing data (A) is not the first step when creating a data classification program, but the third step. Categorizing and prioritizing data involves defining and applying the criteria and labels for classifying data based on its sensitivity, value, and risk. For example, data can be categorized into public, internal, confidential, or restricted levels. Categorizing and prioritizing data helps to identify and protect the most critical and sensitive data assets of the organization12.
Developing data process maps (B) is not the first step when creating a data classification program, but the fourth step. Developing data process maps involves documenting and analyzing the flow and lifecycle of data within the organization. Data process maps show how data is created, collected, stored, processed, transmitted, used, shared, archived, and disposed of. Developing data process maps helps to understand the context and dependencies of data, as well as to identify and mitigate any potential risks or issues related to data quality, security, or compliance12.
Categorizing information by owner is not the first step when creating a data classification program, but the second step. Categorizing information by owner involves assigning roles and responsibilities for each type of data based on its ownership and stewardship. Data owners are the individuals or entities that have the authority and accountability for the data. Data stewards are the individuals or entities that have the operational responsibility for managing and maintaining the data. Data custodians are the individuals or entities that have the technical responsibility for implementing and enforcing the security and access controls for the data12.
References:
7 Steps to Effective Data Classification | CDW
Data Classification: The Basics and a 6-Step Checklist - NetApp
- 다른 버전
- 207ISACA.CISA-KR.v2026-08-15.q712
- 4149ISACA.CISA-KR.v2026-05-16.q709
- 1823ISACA.CISA-KR.v2026-05-06.q261
- 3164ISACA.CISA-KR.v2026-03-16.q665
- 4555ISACA.CISA-KR.v2026-03-07.q651
- 9324ISACA.CISA-KR.v2025-04-07.q633
- 4478ISACA.CISA-KR.v2025-04-03.q628
- 3720ISACA.CISA-KR.v2025-04-02.q544
- 4251ISACA.CISA-KR.v2025-03-31.q534
- 3250ISACA.CISA-KR.v2025-03-19.q581
- 4053ISACA.CISA-KR.v2025-03-03.q807
- 5218ISACA.CISA-KR.v2024-02-07.q421
- 2871ISACA.CISA-KR.v2024-01-31.q392
- 5388ISACA.CISA-KR.v2023-10-24.q329
- 5229ISACA.CISA-KR.v2023-07-31.q266
- 3228ISACA.CISA-KR.v2023-06-23.q324
- 최근 업로드
- 207ISACA.CISA-KR.v2026-08-15.q712
- 152Microsoft.MS-700-KR.v2026-08-15.q203
- 126Microsoft.AZ-305-KR.v2026-08-14.q177
- 185Microsoft.DP-900-KR.v2026-08-13.q130
- 279Microsoft.PL-600.v2026-08-11.q206
- 218Microsoft.DP-100.v2026-08-11.q160
- 187Oracle.1Z0-1048-25.v2026-08-11.q68
- 159ISQI.CTAL-TAE.v2026-08-11.q37
- 200ServiceNow.CIS-HR.v2026-08-11.q84
- 274Salesforce.Plat-Arch-201.v2026-08-10.q101
PDF 파일 다운로드
메일 주소를 입력하시고 다운로드 하세요. ISACA.CISA-KR.v2025-03-28.q617 모의시험 시험자료를 다운 받으세요.
