CISA-KR 문제 566
The other options are not as important as verifying that access privileges have been reviewed:
* Investigating access rights for expiration dates is a useful task, but it is not the most important one.
Expiration dates are the dates when access rights are automatically revoked or suspended after a certain period of time or after a specific event. The IS auditor should check that the expiration dates are set appropriately and enforced consistently, but this is not as critical as reviewing the access privileges themselves.
* Updating the continuity plan for critical resources is a necessary task, but it is not the most urgent one.
A continuity plan is a document that outlines the procedures and actions to be taken in the event of a disruption or disaster that affects the availability of IT resources. The IS auditor should update the continuity plan to reflect the changes and dependencies introduced by the merger, but this can be done after verifying that the access privileges are secure and compliant.
* Updating the security policy is an essential task, but it is not the most immediate one. A security policy is a document that defines the rules and guidelines for securing IT resources and protecting information assets. The IS auditor should update the security policy to incorporate the best practices and standards of both organizations, and to address any new risks or threats posed by the merger, but this can be done after verifying that the access privileges are aligned with the policy.
CISA-KR 문제 567
References
1: Understanding Digital Signatures | CISA
2: Signature Verification | CISA
3: SECFND: Digital Signatures from Skillsoft | NICCS
CISA-KR 문제 568
Minimizing business downtime is critical when implementing a new system that supports an essential process like month-end closing.
* Option A (Incorrect):Thebig bang approachinvolves replacing the old system with the new system all at once. This method carries ahigh riskbecause if issues arise, they may causesignificant downtime and disruption.
* Option B (Correct):Aphased approachgradually implements the system in stages, allowing users to adaptand minimizing the risk of complete failure. This strategy is ideal for critical systems that cannot afford extended downtime.
* Option C (Incorrect):Thecutover approachis a variation of big bang, where the old system is shut down, and the new system is activated. This method isriskyfor month-end processes because errors can causebusiness delays.
* Option D (Incorrect):Theparallel approachruns both old and new systems simultaneously to verify accuracy, but it isresource-intensiveand may not be practical for a high-volume month-end process.
Reference:ISACA CISA Review Manual -Domain 3: Information Systems Acquisition, Development, and Implementation- Covers system implementation strategies, risk management, and best practices.
CISA-KR 문제 569
CISA-KR 문제 570
One of the key aspects of change management is measuring its effectiveness, which means assessing whether the changes have achieved the desired outcomes and met the expectations of the stakeholders. There are various indicators that can be used to measure change management effectiveness, such as time, cost, quality, scope, satisfaction, and performance.
Among the four options given, the most appropriate indicator of change management effectiveness is the number of incidents resulting from changes. An incident is an unplanned event or interruption that affects the normal operation or service delivery of an information system. Incidents can be caused by various factors, such as errors, defects, failures, malfunctions, or malicious attacks. Incidents can have negative impacts on the organization, such as loss of data, productivity, reputation, or revenue.
The number of incidents resulting from changes is a direct measure of how well the changes have been planned, implemented, monitored, and evaluated. A high number of incidents indicates that the changes have not been properly tested, verified, communicated, or controlled. A low number of incidents indicates that the changes have been executed smoothly and successfully. Therefore, the number of incidents resulting from changes reflects the quality and effectiveness of the change management process.
The other three options are not as appropriate indicators of change management effectiveness as the number of incidents resulting from changes. The time lag between changes to the configuration and the update of records is a measure of how timely and accurate the configuration management process is. Configuration management is a subset of change management that focuses on identifying, documenting, and controlling the configuration items (CIs) that make up an information system. The time lag between changes and updates of documentation materials is a measure of how well the documentation process is aligned with the change management process. Documentation is an important aspect of change management that provides information and guidance to the stakeholders involved in or affected by the changes. The number of system software changes is a measure of how frequently and extensively the system software is modified or updated. System software changes are a type of change that affects the operating system, middleware, or utilities that support an information system.
While these three indicators are relevant and useful for measuring certain aspects of change management, they do not directly measure the outcomes or impacts of the changes on the organization. They are more related to the inputs or activities of change management than to its outputs or results. Therefore, they are not as appropriate indicators of change management effectiveness as the number of incidents resulting from changes.
References:
* Metrics for Measuring Change Management - Prosci
* How to Measure Change Management Effectiveness: Metrics, Tools & Processes
* Metrics for Measuring Change Management 2023 - Zendesk
- 다른 버전
- 196ISACA.CISA-KR.v2026-08-15.q712
- 4135ISACA.CISA-KR.v2026-05-16.q709
- 1823ISACA.CISA-KR.v2026-05-06.q261
- 3156ISACA.CISA-KR.v2026-03-16.q665
- 4542ISACA.CISA-KR.v2026-03-07.q651
- 9321ISACA.CISA-KR.v2025-04-07.q633
- 4474ISACA.CISA-KR.v2025-04-03.q628
- 3719ISACA.CISA-KR.v2025-04-02.q544
- 4249ISACA.CISA-KR.v2025-03-31.q534
- 3247ISACA.CISA-KR.v2025-03-19.q581
- 4051ISACA.CISA-KR.v2025-03-03.q807
- 5215ISACA.CISA-KR.v2024-02-07.q421
- 2871ISACA.CISA-KR.v2024-01-31.q392
- 5386ISACA.CISA-KR.v2023-10-24.q329
- 5229ISACA.CISA-KR.v2023-07-31.q266
- 3228ISACA.CISA-KR.v2023-06-23.q324
- 최근 업로드
- 196ISACA.CISA-KR.v2026-08-15.q712
- 150Microsoft.MS-700-KR.v2026-08-15.q203
- 125Microsoft.AZ-305-KR.v2026-08-14.q177
- 180Microsoft.DP-900-KR.v2026-08-13.q130
- 278Microsoft.PL-600.v2026-08-11.q206
- 217Microsoft.DP-100.v2026-08-11.q160
- 186Oracle.1Z0-1048-25.v2026-08-11.q68
- 159ISQI.CTAL-TAE.v2026-08-11.q37
- 200ServiceNow.CIS-HR.v2026-08-11.q84
- 263Salesforce.Plat-Arch-201.v2026-08-10.q101
PDF 파일 다운로드
메일 주소를 입력하시고 다운로드 하세요. ISACA.CISA-KR.v2025-03-28.q617 모의시험 시험자료를 다운 받으세요.
