CISA-KR 문제 181
One of the best indications that there are potential problems within an organization's IT service desk function is an excessive backlog of user requests. A backlog is a list of user requests that have not been resolved or completed by the IT service desk within a specified time frame. An excessive backlog means that the IT service desk is unable to meet the demand or expectations of the users, and that the users are experiencing delays, dissatisfaction, or frustration with the IT service desk.
An excessive backlog of user requests can indicate various problems within the IT service desk function, such as:
* Insufficient staff, resources, or capacity to handle the volume or complexity of user requests
* Ineffective processes, procedures, or tools for managing, prioritizing, or resolving user requests
* Lack of skills, knowledge, or training among the IT service desk staff to deal with different types of user requests
* Poor communication, collaboration, or coordination among the IT service desk staff or with other IT functions or stakeholders
* Low quality, performance, or security of the IT systems or services that cause frequent or recurring user issues Therefore, an excessive backlog of user requests is the best indication that there are potential problems within an organization's IT service desk function.
References:
* What is an IT Service Desk? Definition and Functions - Indeed
* The Most Common IT Help Desk Issues - SherpaDesk
* 18 Common IT Help Desk Problems and Solutions - E-Pulse Blog
CISA-KR 문제 182
This finding also suggests that there is no clear accountability or authority for information security governance at a higher level, such as senior management or board of directors. The other findings are not as concerning as this one, although they may indicate some areas for improvement or monitoring. References:
* ISACA, CISA Review Manual, 27th Edition, chapter 5, section 5.11
* ISACA, IT Governance Using COBIT and Val IT: Student Booklet - 2nd Edition4
CISA-KR 문제 183
The application implementation documents are the documents that describe the design specifications, logic, and functionality of the application and its controls. The application implementation documents may include:
Business requirements document - a document that defines the business objectives, needs, and expectations of the application.
Functional specifications document - a document that describes the features, functions, and interfaces of the application and its controls.
Technical specifications document - a document that details the technical architecture, design, and configuration of the application and its controls.
Test plan and test cases - a document that outlines the testing strategy, methodology, and scenarios for verifying the functionality and performance of the application and its controls.
User manual and training material - a document that provides instructions and guidance on how to use the application and its controls.
By reviewing the application implementation documents, an IS auditor can:
Gain an understanding of the purpose, scope, and nature of the application and its controls.
Evaluate whether the application and its controls are designed to meet the business requirements and objectives.
Identify any gaps, inconsistencies, or errors in the design of the application and its controls.
Compare the design of the application and its controls with the best practices and standards in the industry.
Determine whether the application and its controls are adequately tested and documented.
Interviewing the application developer is not the best way for an IS auditor to assess the design of an automated application control. An interview is a verbal communication technique that involves asking questions and listening to responses. An interview can be useful for obtaining general information or clarifying specific issues related to the application and its controls. However, an interview alone cannot provide sufficient evidence or documentation to support the auditor's assessment of the design of an automated application control. An interview may also be subject to bias, misunderstanding, or misinterpretation by either party.
Obtaining management attestation and sign-off is not the best way for an IS auditor to assess the design of an automated application control. Management attestation and sign-off is a formal process that involves obtaining written confirmation from management that they have reviewed and approved the design of the application and its controls. Management attestation and sign-off can indicate management's commitment and accountability for the quality and effectiveness of the application and its controls. However, management attestation and sign-off cannot substitute for an independent and objective evaluation by an IS auditor.
Management attestation and sign-off may also be influenced by pressure, conflict of interest, or fraud.
Reviewing system configuration parameters and output is not the best way for an IS auditor to assess the design of an automated application control. System configuration parameters are settings that define how the system operates or interacts with other components. System output is data or information that is produced by the system as a result of processing transactions or performing functions. Reviewing system configuration parameters and output can help an IS auditor to verify whether the system is configured correctly and whether it produces accurate and reliable output. However, reviewing system configuration parameters and output cannot provide a comprehensive view of how the application and its controls are designed to achieve their objectives. Reviewing system configuration parameters and output may also require technical expertise or access rights that may not be available to an IS auditor.
CISA-KR 문제 184
Thedata owneris the individual or entity responsible for classifying, protecting, and defining access permissions to data. They ensure that only authorized personnel can access, modify, or distribute data based on business needs and regulatory requirements.
* Data Owner (Correct Answer - B)
* The data owner is responsible forsetting user permissionsbased on job roles and business requirements.
* According toISACA's CISA Review Manual and COBIT 2019, the data owner determines access levels while IT personnel enforce them.
* Example:A finance department head (data owner) determines that only certain accountants should access sensitive payroll data.
* IT Operations Manager (Incorrect - A)
* Oversees IT infrastructure but does not define data access controls.
* Database Administrator (DBA) (Incorrect - C)
* Implements and enforces security settings but follows rules set by the data owner.
* Information Security Manager (Incorrect - D)
* Provides security guidance but does not decide specific access permissions.
References:
* ISACA CISA Review Manual
* COBIT 2019 Framework
* NIST 800-53 (Security and Privacy Controls for Federal Information Systems)
CISA-KR 문제 185
* CISA Review Manual (Digital Version), Chapter 5, Section 5.31
* CISA Review Questions, Answers & Explanations Database, Question ID 212
- 다른 버전
- 248ISACA.CISA-KR.v2026-08-15.q712
- 4268ISACA.CISA-KR.v2026-05-16.q709
- 1842ISACA.CISA-KR.v2026-05-06.q261
- 3223ISACA.CISA-KR.v2026-03-16.q665
- 4704ISACA.CISA-KR.v2026-03-07.q651
- 9420ISACA.CISA-KR.v2025-04-07.q633
- 4507ISACA.CISA-KR.v2025-04-03.q628
- 3795ISACA.CISA-KR.v2025-04-02.q544
- 4297ISACA.CISA-KR.v2025-03-31.q534
- 3295ISACA.CISA-KR.v2025-03-19.q581
- 4152ISACA.CISA-KR.v2025-03-03.q807
- 5235ISACA.CISA-KR.v2024-02-07.q421
- 2904ISACA.CISA-KR.v2024-01-31.q392
- 5412ISACA.CISA-KR.v2023-10-24.q329
- 5247ISACA.CISA-KR.v2023-07-31.q266
- 3245ISACA.CISA-KR.v2023-06-23.q324
- 최근 업로드
- 248ISACA.CISA-KR.v2026-08-15.q712
- 209Microsoft.MS-700-KR.v2026-08-15.q203
- 145Microsoft.AZ-305-KR.v2026-08-14.q177
- 212Microsoft.DP-900-KR.v2026-08-13.q130
- 291Microsoft.PL-600.v2026-08-11.q206
- 232Microsoft.DP-100.v2026-08-11.q160
- 194Oracle.1Z0-1048-25.v2026-08-11.q68
- 161ISQI.CTAL-TAE.v2026-08-11.q37
- 204ServiceNow.CIS-HR.v2026-08-11.q84
- 283Salesforce.Plat-Arch-201.v2026-08-10.q101
PDF 파일 다운로드
메일 주소를 입력하시고 다운로드 하세요. ISACA.CISA-KR.v2025-03-28.q617 모의시험 시험자료를 다운 받으세요.
