CISA-KR 문제 546
CISA-KR 문제 547
Periodic review of access profiles by management: This is a type of logical access control that involves verifying that the access rights assigned to each cardholder are appropriate, necessary, and consistent with the organization's policies and procedures. Periodic review of access profiles can help to detect and correct any errors, inconsistencies, or violations in the access control system, such as outdated, excessive, or redundant access rights, segregation of duties conflicts, or unauthorized changes. Periodic review of access profiles can also help to ensure compliance with internal and external audit requirements and regulations.
Implementation of additional PIN pads: This is a type of multi-factor authentication (MFA) that requires the cardholder to enter a personal identification number (PIN) in addition to swiping their card. MFA can enhance the security of the access control system by adding another layer of verification and reducing the risk of lost, stolen, or cloned cards being used by unauthorized persons.
Installation of closed-circuit television (CCTV): This is a type of surveillance system that uses cameras and monitors to record and display the images of the people and activities in the restricted areas. CCTV can deter potential intruders, provide evidence of any security incidents or breaches, and enable real-time monitoring and response by security personnel.
The other options are not as effective or relevant as periodic review of access profiles by management for an additional control when using swipe cards. Physical sign-in of all employees for access to restricted areas is a redundant and inefficient control that can be easily bypassed or manipulated. It also does not provide any assurance or verification of the identity or access rights of the cardholders. Audit hooks are software routines embedded in an application that can trigger an alert or a report when certain conditions are met. Audit hooks can help to detect anomalies or exceptions in access control lists, but they do not provide a comprehensive or integrated view of them.
References:
ISACA, CISA Review Manual, 27th Edition, 2019, p. 236
ISACA, ITAF: A Professional Practices Framework for IS Audit/Assurance, 3rd Edition, 2014, p. 88 Data Analytics for Auditing Access Control
CISA-KR 문제 548
Compliance testing, on the other hand, is more focused on assessing the adequacy and effectiveness of internal controls over software licensing, such as policies, procedures,and monitoring mechanisms.
Compliance testing alone cannot provide sufficient assurance that the software license audit objectives are met, as itdoes notverify the actual software usage and compliance status. Judgmental sampling and stop-or- go sampling are methods of selecting samples for testing, not types of testing themselves. *References:
According to the ISACA IT Audit and Assurance Standards, Guidelines and Tools and Techniques for IS Audit and Assurance Professionals, section 1206 Testing, "The IS audit and assurance professional should perform sufficient testing to obtain sufficient appropriate evidence to support conclusions reached." 1 The section also defines substantive testing as "testing performed to obtain audit evidence to detect material misstatements in transactions orbalances" and compliance testing as "testing performed to obtain audit evidence on theoperating effectiveness of controls." 1 According to the ISACA IT Audit and Assurance Guideline G15 Software License Management, "The objective of a software license auditis to provide management with an independent assessment relating to compliance with software license agreements." 2 The guideline also states that "substantive tests should be performed on a sample basis to verify that all software installed on devices within scope has been appropriately licensed." 2
CISA-KR 문제 549
References:
* Service Level Agreement (SLA)Examples and Template
* What is an SLA? Best practices for service-level agreements
CISA-KR 문제 550
- 다른 버전
- 196ISACA.CISA-KR.v2026-08-15.q712
- 4135ISACA.CISA-KR.v2026-05-16.q709
- 1823ISACA.CISA-KR.v2026-05-06.q261
- 3156ISACA.CISA-KR.v2026-03-16.q665
- 4542ISACA.CISA-KR.v2026-03-07.q651
- 9321ISACA.CISA-KR.v2025-04-07.q633
- 4474ISACA.CISA-KR.v2025-04-03.q628
- 3719ISACA.CISA-KR.v2025-04-02.q544
- 4249ISACA.CISA-KR.v2025-03-31.q534
- 3247ISACA.CISA-KR.v2025-03-19.q581
- 4051ISACA.CISA-KR.v2025-03-03.q807
- 5215ISACA.CISA-KR.v2024-02-07.q421
- 2871ISACA.CISA-KR.v2024-01-31.q392
- 5386ISACA.CISA-KR.v2023-10-24.q329
- 5229ISACA.CISA-KR.v2023-07-31.q266
- 3228ISACA.CISA-KR.v2023-06-23.q324
- 최근 업로드
- 196ISACA.CISA-KR.v2026-08-15.q712
- 151Microsoft.MS-700-KR.v2026-08-15.q203
- 125Microsoft.AZ-305-KR.v2026-08-14.q177
- 180Microsoft.DP-900-KR.v2026-08-13.q130
- 278Microsoft.PL-600.v2026-08-11.q206
- 217Microsoft.DP-100.v2026-08-11.q160
- 186Oracle.1Z0-1048-25.v2026-08-11.q68
- 159ISQI.CTAL-TAE.v2026-08-11.q37
- 200ServiceNow.CIS-HR.v2026-08-11.q84
- 263Salesforce.Plat-Arch-201.v2026-08-10.q101
PDF 파일 다운로드
메일 주소를 입력하시고 다운로드 하세요. ISACA.CISA-KR.v2025-03-28.q617 모의시험 시험자료를 다운 받으세요.
