CISA-KR 문제 186
A project change management process is a set of procedures that defines how changes to the project scope, schedule, budget, quality, or resources are requested, evaluated, approved, implemented, and controlled12.
A project change management process helps to ensure that the changes are aligned with the project objectives, stakeholders' expectations, and business needs12.
Adding a new system functionality during the development phase without following a project change management process can introduce risks such as:
The added functionality has not been documented (option A), which can lead to confusion, inconsistency, errors, and rework3.
The project may fail to meet the established deadline (option C), which can result in delays, penalties, and customer dissatisfaction3.
The project may go over budget (option D), which can cause cost overruns, financial losses, and reduced profitability3.
However, the main risk is that the new functionality may not meet requirements (option B), which can have serious consequences such as:
The new functionality may not be compatible with the existing system or other components3.
The new functionality may not be tested or verified for quality, performance, security, or usability3.
The new functionality may not deliver the expected value or benefits to the users or customers3.
The new functionality may not comply with the regulatory or contractual obligations3.
The new functionality may cause dissatisfaction, complaints, or litigation from the stakeholders3.
Therefore, the main risk associated with adding a new system functionality during the development phase without following a project change management process is that the new functionality may not meet requirements (option B), as this can jeopardize the success and acceptance of the project.
References: 1: How to Make a Change Management Plan (Templates Included) - ProjectManager 2: What Is Change Management? Process & Models Explained - ProjectManager 3: 8 Steps for an Effective Change Management Process - Smartsheet
CISA-KR 문제 187
This way, the organization can ensure that they have a complete and accurate copy of the source code that reflects their current needs and requirements.
Bringing the escrow version up to date can help the organization to avoid or reduce the risks and costs associated with using an outdated or incompatible version of the source code. For example, an older version of the source code may have bugs, errors, or vulnerabilities that could affect the functionality, security, or performance of the application. An older version of the source code may also lack some features, enhancements, or integrations that could improve the usability, efficiency, or value of the application. An older version of the source code may also not comply with some standards, regulations, or contracts that could affect the quality, reliability, or legality of the application1.
The other options are not as good as bringing the escrow version up to date for the organization. Option A, analyzing a new application that meets the current requirements, is a possible option but it may be more time- consuming, expensive, and risky than updating the existing application. The organization may have to go through a complex and lengthy process of selecting, acquiring, implementing, testing, and migrating to a new application, which could disrupt their operations and performance. The organization may also have to deal with compatibility, interoperability, or data quality issues when switching to a new application2. Option B, performing an analysis to determine the business risk, is a necessary step but not a recommendation for the organization. The organization should already be aware of the business risk of using an application whose vendor has gone out of business and whose escrow has an older version of the source code. The organization should focus on finding and implementing a solution to mitigate or eliminate this risk3. Option D, developing a maintenance plan to support the application using the existing code, is not a feasible option because it assumes that the organization has access to the existing code. However, this is not the case because the vendor has gone out of business and the escrow has an older version of the source code. The organization cannot support or maintain an application without having a complete and accurate copy of its source code.
References:
* How Important Is Source Code Escrow - ISACA1
* The What and Why of Source Code Escrow2
* Unlocking Source Code In Escrow 2023: A Guide To Secure Software3
CISA-KR 문제 188
The other options are not as advantageous as option D, as they may not reflect the true benefits or limitations of vulnerability scanning compared to penetration testing. The testing produces a lower number of false positive results, but this is not necessarily true, as vulnerability scanning may report vulnerabilities that are not exploitable or relevant in the context of the organization. Network bandwidth is utilized more efficiently, but this may not be a significant advantage, as vulnerability scanning may still consume considerable network resources depending on the scope and frequency of the scans. Custom-developed applications can be tested more accurately, but this is also not true, as vulnerability scanning may not be able to detect complex or unknown vulnerabilities that require manual analysis or exploitation.
References:
* 1: Vulnerability scanning vs penetration testing: What's the difference? | TechRepublic
* 2: Vulnerability Scanning vs. Penetration Testing - Fortinet
* 3: Penetration Test Vs Vulnerability Scan | Digital Defense
* 4: Penetration Testing vs. Vulnerability Scanning: What's the difference?
* 5: Penetration Testing vs. Vulnerability Scanning | Secureworks
* 6: PCI DSS Quick Reference Guide - PCI Security Standards Council
CISA-KR 문제 189
CISA-KR 문제 190
& Systems Resources | COBIT, Risk, Governance ... - ISACA, CISA Certification | Certified Information Systems Auditor | ISACA
- 다른 버전
- 303ISACA.CISA-KR.v2026-08-15.q712
- 4320ISACA.CISA-KR.v2026-05-16.q709
- 1866ISACA.CISA-KR.v2026-05-06.q261
- 3333ISACA.CISA-KR.v2026-03-16.q665
- 4742ISACA.CISA-KR.v2026-03-07.q651
- 9445ISACA.CISA-KR.v2025-04-07.q633
- 4554ISACA.CISA-KR.v2025-04-03.q628
- 3810ISACA.CISA-KR.v2025-04-02.q544
- 5525ISACA.CISA-KR.v2025-03-28.q617
- 3313ISACA.CISA-KR.v2025-03-19.q581
- 4197ISACA.CISA-KR.v2025-03-03.q807
- 5245ISACA.CISA-KR.v2024-02-07.q421
- 2921ISACA.CISA-KR.v2024-01-31.q392
- 5430ISACA.CISA-KR.v2023-10-24.q329
- 5260ISACA.CISA-KR.v2023-07-31.q266
- 3259ISACA.CISA-KR.v2023-06-23.q324
- 최근 업로드
- 126Microsoft.AZ-305-KR.v2026-08-17.q162
- 140IIA.IAA-IAP-KR.v2026-08-17.q41
- 303ISACA.CISA-KR.v2026-08-15.q712
- 238Microsoft.MS-700-KR.v2026-08-15.q203
- 173Microsoft.AZ-305-KR.v2026-08-14.q177
- 238Microsoft.DP-900-KR.v2026-08-13.q130
- 315Microsoft.PL-600.v2026-08-11.q206
- 267Microsoft.DP-100.v2026-08-11.q160
- 209Oracle.1Z0-1048-25.v2026-08-11.q68
- 177ISQI.CTAL-TAE.v2026-08-11.q37
PDF 파일 다운로드
메일 주소를 입력하시고 다운로드 하세요. ISACA.CISA-KR.v2025-03-31.q534 모의시험 시험자료를 다운 받으세요.
