CISA-KR 문제 576
References:
* ISACA, CISA Review Manual, 27th Edition, 2020, p. 2381
* ISACA, CISA Review Questions, Answers & Explanations Database - 12 Month Subscription
CISA-KR 문제 577
CISA-KR 문제 578
Information Systems Operations and Business Resilience, Section 4.2: IT Service Delivery and Support
CISA-KR 문제 579
The other options are not the primary purpose of performing a parallel run of a new system. A. To train the end users and supporting staff on the new system. Training is an important part of system implementation, but it is not the main reason for doing a parallel run. Training can be done before, during, or after the parallel run, depending on the needs and preferences of the organization. B. To verify the new system provides required business functionality. Verifying the business functionality of the new system is part of user acceptance testing (UAT), which is a formal and structured process of testing whether the new system meets the specifications and expectations of the users and stakeholders. UAT is usually done before the parallel run, as a prerequisite for system changeover. C. To reduce the need for additional testing. Reducing the need for additional testing is not the primary purpose of performing a parallel run, but rather a possible benefit or outcome of doing so. A parallel run can help ensure that the new system is thoroughly tested and validated in a real-worldenvironment, which may reduce the likelihood of encountering major issues or defects later on.
However, additional testing may still be needed after the parallel run, depending on the feedback and evaluation of the users and stakeholders.
References:
* ISACA, CISA Review Manual, 27th Edition, 2019, p. 2471
* IS
CISA-KR 문제 580
A privacy program should comply with the applicable laws and regulations that govern the privacy rights and obligations of individuals and organizations, such as the General Data Protection Regulation (GDPR) or the California Consumer Privacy Act (CCPA). New regulations may introduce new requirements or changes that affect the organization's privacy program and expose it to potential compliance risks or penalties. Therefore, internal audit can help to establish an organization's privacy program by analyzing the risks posed by new regulations and providing assurance, advice, or recommendations on how to address them1. The other options are less appropriate or incorrect because:
* B. Developing procedures to monitor the use of personal data is not an appropriate role of internal audit in helping to establish an organization's privacy program, as it is more of a management or operational role. Internal audit should not be involved in designing or implementing the organization's privacy program, as it would compromise its independence and objectivity. Internal audit should provide assurance on the effectiveness and efficiency of the organization's privacy program, but not create or execute it2.
* C. Defining roles within the organization related to privacy is not an appropriate role of internal audit in helping to establish an organization's privacy program, as it is more of a governance or strategic role.
Internal audit should not be involved in setting or approving the organization's privacy strategy, objectives, or policies, as it would compromise its independence and objectivity. Internal audit should provide assurance on the alignment and compliance of the organization's privacy program with its strategy, objectives, and policies, but not define or approve them2.
* D. Designing controls to protect personal data is not an appropriate role of internal audit in helping to establish an organization's privacy program, as it is more of a management or operational role. Internal audit should not be involved in designing or implementing the organization's privacy program, as it would compromise its independence and objectivity. Internal audit should provide assurance on the adequacy and effectiveness of the organization's privacy program, but not design or implement it2.
References: ISACA Introduces New Audit Programs for Business Continuity/Disaster ..., Best Practices for Privacy Audits - ISACA, ISACA Produces New Audit and Assurance Programs for Data Privacy and ...
- 다른 버전
- 194ISACA.CISA-KR.v2026-08-15.q712
- 4126ISACA.CISA-KR.v2026-05-16.q709
- 1822ISACA.CISA-KR.v2026-05-06.q261
- 3156ISACA.CISA-KR.v2026-03-16.q665
- 4539ISACA.CISA-KR.v2026-03-07.q651
- 9321ISACA.CISA-KR.v2025-04-07.q633
- 4474ISACA.CISA-KR.v2025-04-03.q628
- 3719ISACA.CISA-KR.v2025-04-02.q544
- 4248ISACA.CISA-KR.v2025-03-31.q534
- 3246ISACA.CISA-KR.v2025-03-19.q581
- 4051ISACA.CISA-KR.v2025-03-03.q807
- 5215ISACA.CISA-KR.v2024-02-07.q421
- 2871ISACA.CISA-KR.v2024-01-31.q392
- 5386ISACA.CISA-KR.v2023-10-24.q329
- 5229ISACA.CISA-KR.v2023-07-31.q266
- 3222ISACA.CISA-KR.v2023-06-23.q324
- 최근 업로드
- 194ISACA.CISA-KR.v2026-08-15.q712
- 148Microsoft.MS-700-KR.v2026-08-15.q203
- 125Microsoft.AZ-305-KR.v2026-08-14.q177
- 180Microsoft.DP-900-KR.v2026-08-13.q130
- 278Microsoft.PL-600.v2026-08-11.q206
- 217Microsoft.DP-100.v2026-08-11.q160
- 186Oracle.1Z0-1048-25.v2026-08-11.q68
- 159ISQI.CTAL-TAE.v2026-08-11.q37
- 200ServiceNow.CIS-HR.v2026-08-11.q84
- 263Salesforce.Plat-Arch-201.v2026-08-10.q101
PDF 파일 다운로드
메일 주소를 입력하시고 다운로드 하세요. ISACA.CISA-KR.v2025-03-28.q617 모의시험 시험자료를 다운 받으세요.
