CISA-KR 문제 266
The other options are not as good as option B, as they may not capture the full scope or benefits of using an IT governance framework. Frameworks enable IT benchmarks against competitors, but this is not the main purpose or advantage of using an IT governance framework. Frameworks help facilitate control self- assessments (CSAs), but this is only one aspect or tool of an IT governance framework. Frameworks help organizations understand and manage IT risk, but this is also only one outcome or objective of an IT governance framework.
References:
* 1: What is ITIL? Your guide to the IT Infrastructure Library | CIO
* 2: IT Governance Framework | Components | Framework | Terminology - EDUCBA
* 3: IT Governance: Definitions, Frameworks and Planning - ProjectManager
* 4: What Is IT Governance? - Definition from Techopedia
* 5: What is IT Governance? A formal way to align IT & business strategy | CIO
* 6: What Is IT Governance? - Definition from WhatIs.com
* 7: ISO/IEC 20000 Information Technology Service Management Systems Standard - ISO/IEC 20000 Portal
* 8: COBIT | Control Objectives for Information Technologies | ISACA
CISA-KR 문제 267
CISA-KR 문제 268
The other options are not as advantageous as option D, as they may not reflect the true benefits or limitations of vulnerability scanning compared to penetration testing. The testing produces a lower number of false positive results, but this is not necessarily true, as vulnerability scanning may report vulnerabilities that are not exploitable or relevant in the context of the organization. Network bandwidth is utilized more efficiently, but this may not be a significant advantage, as vulnerability scanning may still consume considerable network resources depending on the scope and frequency of the scans. Custom-developed applications can be tested more accurately, but this is also not true, as vulnerability scanning may not be able to detect complex or unknown vulnerabilities that require manual analysis or exploitation.
References:
* 1: Vulnerability scanning vs penetration testing: What's the difference? | TechRepublic
* 2: Vulnerability Scanning vs. Penetration Testing - Fortinet
* 3: Penetration Test Vs Vulnerability Scan | Digital Defense
* 4: Penetration Testing vs. Vulnerability Scanning: What's the difference?
* 5: Penetration Testing vs. Vulnerability Scanning | Secureworks
* 6: PCI DSS Quick Reference Guide - PCI Security Standards Council
CISA-KR 문제 269
IS 감사원의 다음 조치는 다음 중 무엇이어야 할까요?
Option A is incorrect because reviewing the list of end users and evaluating for authorization is not the IS auditor's responsibility, but rather the system owner's or administrator's. The IS auditor should only verify that such reviews are performed and documented by the responsible parties.
Option C is incorrect because verifying management's approval for this exemption is not sufficient to address the control process weakness. Even if there is a valid reason for not performing periodic reviews of read-only users, the IS auditor should still report this as a potential risk and recommend mitigating controls.
Option D is incorrect because obtaining a verbal confirmation from IT for this exemption is not adequate evidence or documentation. The IS auditor should obtain written approval from management and verify that it is aligned with the organization's policies and standards.
References:
CISA Review Manual (Digital Version)1, Chapter 1: The Process of Auditing Information Systems, Section
1.4: Audit Evidence, p. 31-32.
CISA Review Manual (Print Version), Chapter 1: The Process of Auditing Information Systems, Section 1.4:
Audit Evidence, p. 31-32.
CISA Online Review Course2, Module 1: The Process of Auditing Information Systems, Lesson 4: Audit Evidence, slide 9-10.
CISA Questions, Answers & Explanations Database3, Question ID: QAE_CISA_710.
CISA-KR 문제 270
References
1: Change Management - CISA
2: What is Change Management? - Definition from Techopedia
3: How to Audit Change Management - ISACA Journal
The Business Case for Security | CISA
- 다른 버전
- 250ISACA.CISA-KR.v2026-08-15.q712
- 4287ISACA.CISA-KR.v2026-05-16.q709
- 1844ISACA.CISA-KR.v2026-05-06.q261
- 3239ISACA.CISA-KR.v2026-03-16.q665
- 4712ISACA.CISA-KR.v2026-03-07.q651
- 9421ISACA.CISA-KR.v2025-04-07.q633
- 4522ISACA.CISA-KR.v2025-04-03.q628
- 3795ISACA.CISA-KR.v2025-04-02.q544
- 4300ISACA.CISA-KR.v2025-03-31.q534
- 3295ISACA.CISA-KR.v2025-03-19.q581
- 4170ISACA.CISA-KR.v2025-03-03.q807
- 5235ISACA.CISA-KR.v2024-02-07.q421
- 2917ISACA.CISA-KR.v2024-01-31.q392
- 5425ISACA.CISA-KR.v2023-10-24.q329
- 5247ISACA.CISA-KR.v2023-07-31.q266
- 3246ISACA.CISA-KR.v2023-06-23.q324
- 최근 업로드
- 250ISACA.CISA-KR.v2026-08-15.q712
- 214Microsoft.MS-700-KR.v2026-08-15.q203
- 152Microsoft.AZ-305-KR.v2026-08-14.q177
- 224Microsoft.DP-900-KR.v2026-08-13.q130
- 292Microsoft.PL-600.v2026-08-11.q206
- 233Microsoft.DP-100.v2026-08-11.q160
- 195Oracle.1Z0-1048-25.v2026-08-11.q68
- 162ISQI.CTAL-TAE.v2026-08-11.q37
- 204ServiceNow.CIS-HR.v2026-08-11.q84
- 283Salesforce.Plat-Arch-201.v2026-08-10.q101
PDF 파일 다운로드
메일 주소를 입력하시고 다운로드 하세요. ISACA.CISA-KR.v2025-03-28.q617 모의시험 시험자료를 다운 받으세요.
