CISA-KR 문제 216
다음 중 가장 큰 우려 사항은 무엇일까요?
Audit logging can help monitor and verify the compliance and effectiveness of the access controls, as well as detect and investigate any unauthorized or suspicious access or actions. Audit logging can also provide evidence and accountability for the security and integrity of the system and the data.
Without audit logging, the IS auditor would not be able to audit the access controls for the shared CRM system, as there would be no reliable or traceable records of the access history or patterns. Without audit logging, the organization would also not be able to identify or respond to any potential breaches or incidents that may compromise the confidentiality, availability, or accuracy of the CRM data. Without audit logging, the organization would also not be able to demonstrate or prove itscompliance with any applicable policies, regulations, or standards that may require audit logging for CRM systems.
Single sign-on is not enabled is not a great concern for an IS auditor evaluating the access controls for a shared CRM system, but rather a potential improvement or enhancement. Single sign-on is a process that allows users to access multiple systems or applications with one set of credentials, such as a username and password. Single sign-on can help simplify and streamline the user experience, as well as reduce the risk of password fatigue or compromise. However, single sign-on is not a mandatory or essential requirement for access controls, and it may also introduce some challenges or risks, such as dependency on a single point of failure or vulnerability.
Security baseline is not consistently applied is not a great concern for an IS auditor evaluating the access controls for a shared CRM system, but rather a minor issue or gap. Security baseline is a set of minimum security standards or requirements that apply to a system or application, such as password policies, encryption protocols, or firewall rules. Security baseline can help ensure that the system or application meets a certain level of security and compliance. However, security baseline is not a sufficient or comprehensive measure for access controls, and it may also need to be customized or adjusted according to the specific needs and risks of each system or application.
Complex passwords are not required is not a great concern for an IS auditor evaluating the access controls for a shared CRM system, but rather a common practice or recommendation. Complex passwords are passwords that are composed of a combination of different types of characters, such as letters, numbers, symbols, and cases. Complex passwords can help prevent or deter brute-force attacks or guessing attempts by making the passwords harder to crack or predict. However, complex passwords are not a guarantee or guarantee of security, and they may also have some drawbacks or limitations, such as user inconvenience, memorability issues, or reuse across multiple systems or applications.
References:
* Customer Relationship Management Risks and Controls - CRM Simplified 1
* Customer relationship management: A guide - Zendesk 2
* How to Protect Your Customer Relationship Management (CRM) Data from Hackers 3
* What is CRM? | A Definition by Salesforce 4
CISA-KR 문제 217
* Using a Cloud-Based Order Management Tool Without Approval (Option A)is a clear example of shadow IT because the employee is circumventing established IT policies to implement a solution independently.
* Accessing Personal Banking Information on a Company-Provided Laptop (Option B)is a potential misuse of resources but does not qualify as shadow IT since it does not involve unauthorized technology.
* Using Personal Email for Client Communication (Option C)may violate communication policies but is not related to the adoption of unapproved IT systems.
* Accessing Social Media on a Company-Provided Tablet (Option D)is improper use of a company asset but does not involve unauthorized IT tools.
Shadow IT introduces risks such as data breaches, lack of compliance, and inefficiencies due to lack of integration with official systems. Organizations should have clear policies and monitoring mechanisms to address such risks.
Reference:ISACA CISA Review Manual, Job Practice Area 1: Governance and Management of IT.
CISA-KR 문제 218
According to the ISACA Code of Professional Ethics, IS auditors should maintain objectivity and independence in their professional judgment and avoid any situations that may impair or be presumed to impair their objectivity or independence1. Objectivity is the mental attitude of an IS auditor that allows them to perform their work honestly, impartially, and with integrity, while independence is the freedom from conditions that threaten the ability of an IS auditor to carry out their work in an unbiased manner2.
The IS audit manager who was involved in supervising the payroll application upgrade project may have a self-review threat, which is the risk that an IS auditor will not appropriately evaluate the results of a previous judgment made or service performed by them or their subordinates3. The IS audit manager may also have a familiarity threat, which is the risk that an IS auditor will be influenced by a close relationship with someone involved in the project or by their own personal interests4. These threats may compromise the IS audit manager's objectivity and independence and affect the quality and credibility of the audit.
Therefore, the IS audit manager should disclose their involvement in the project to their senior management and the audit committee and decline to perform or manage the audit. The IS audit manager should also recommend outsourcing the audit to independent and qualified resources who have no connection or interest in the project and who have the necessary skills and experience to conduct a reliable and effective audit.
The other options are not the best course of action for the IS audit manager.
Transferring the assignment to a different audit manager despite lack of IT project management experience is not the best course of action because it may result in a low-quality audit that does not meet the expectations and standards of the stakeholders. IT project management experience is essential for auditing an IT project, as it requires knowledge of project management methodologies, tools, techniques, risks, and best practices. An audit manager who lacks IT project management experience may not be able to plan, execute, report, and follow up on the audit effectively and efficiently.
Managing the audit since there is no one else with the appropriate experience is not the best course of action because it violates the ethical principles and standards of objectivity and independence for IS auditors.
Managing the audit would create a conflict of interest and a threat to objectivity and independence for the IS audit manager, as they would be reviewing their own work or that of their subordinate. Managing the audit would also undermine the credibility and reliability of the audit results and recommendations, as they may be biased or influenced by personal or professional relationships or interests.
Having a senior IS auditor manage the project with the IS audit manager performing final review is not the best course of action because it still involves the IS audit manager in the audit process, which poses a conflict of interest and a threat to objectivity and independence. Performing final review would require the IS audit manager to evaluate and approve the work done by the senior IS auditor, which may be affected by their previous involvement in or knowledge of the project. Performing final review would also expose theIS audit manager to undue pressure or influence from management or other stakeholders who may have expectations or preferences regarding the audit outcome.
CISA-KR 문제 219
27th Edition, page 385
CISA-KR 문제 220
Performing a review of privileged roles and responsibilities is also a good practice, but it may not address the specific risk of data leakage by the vendor with privileged access. Requiring the vendor to implement job rotation for privileged roles may reduce the risk of collusion or fraud, but it may not prevent or detect data leakage by any individual with privileged access. References: CISA Review Manual (Digital Version),
[ISACA Privacy Principles and Program Management Guide]
프리미엄 번들
DumpTop 에서 공유하는 최신 CISA-KR 시험 덤프는 CISA-KR 시험패스를 도와드릴수 있습니다! DumpTop 은 최근 업데이트된 CISA-KR 시험자료를 제공해드립니다. DumpTop CISA-KR 덤프도 시험문제 변경에 따라 업데이트되었으며 오답도 수정되었습니다. DumpTop CISA-KR 덤프 최신버전을 공유받아보세요.
(1562 Q&As 덤프, 30%OFF할인코드: KrDump)
- 다른 버전
- 249ISACA.CISA-KR.v2026-08-15.q712
- 4281ISACA.CISA-KR.v2026-05-16.q709
- 1842ISACA.CISA-KR.v2026-05-06.q261
- 3228ISACA.CISA-KR.v2026-03-16.q665
- 4711ISACA.CISA-KR.v2026-03-07.q651
- 9420ISACA.CISA-KR.v2025-04-07.q633
- 4511ISACA.CISA-KR.v2025-04-03.q628
- 3795ISACA.CISA-KR.v2025-04-02.q544
- 4300ISACA.CISA-KR.v2025-03-31.q534
- 3295ISACA.CISA-KR.v2025-03-19.q581
- 4157ISACA.CISA-KR.v2025-03-03.q807
- 5235ISACA.CISA-KR.v2024-02-07.q421
- 2904ISACA.CISA-KR.v2024-01-31.q392
- 5412ISACA.CISA-KR.v2023-10-24.q329
- 5247ISACA.CISA-KR.v2023-07-31.q266
- 3245ISACA.CISA-KR.v2023-06-23.q324
- 최근 업로드
- 249ISACA.CISA-KR.v2026-08-15.q712
- 212Microsoft.MS-700-KR.v2026-08-15.q203
- 148Microsoft.AZ-305-KR.v2026-08-14.q177
- 219Microsoft.DP-900-KR.v2026-08-13.q130
- 291Microsoft.PL-600.v2026-08-11.q206
- 232Microsoft.DP-100.v2026-08-11.q160
- 194Oracle.1Z0-1048-25.v2026-08-11.q68
- 161ISQI.CTAL-TAE.v2026-08-11.q37
- 204ServiceNow.CIS-HR.v2026-08-11.q84
- 283Salesforce.Plat-Arch-201.v2026-08-10.q101
PDF 파일 다운로드
메일 주소를 입력하시고 다운로드 하세요. ISACA.CISA-KR.v2025-03-28.q617 모의시험 시험자료를 다운 받으세요.
