CISA-KR 문제 116
Lack of alignment and integration between technology and business strategies, leading to suboptimal outcomes and missed opportunities.
Lack of clarity and consistency in technology risk identification, assessment, mitigation, and reporting, leading to gaps and overlaps in risk coverage and exposure.
Lack of communication and collaboration among different stakeholders involved in technology risk management, leading to conflicts and inefficiencies.
Lack of oversight and accountability for technology risk management activities and results, leading to poor quality and reliability.
CISA-KR 문제 117
Therefore, it is essential that logs are stored in a separate host that is isolated and secured from the network and the firewall itself, to prevent unauthorized access or modification of the logs. Automated alerts are being sent when a risk is detected is a good practice for enhancing the security and efficiency of a firewall, but it is not the most important thing for an IS auditor to verify, as alerts may not always be accurate, timely, or actionable. Insider attacks are being controlled is a desirable outcome for a firewall, but it is not the most important thing for an IS auditor to verify, as insider attacks may involve other factors or methods that bypass or compromise the firewall, such as social engineering, credential theft, or physical access. Access to configuration files is restricted is a critical control for ensuring the security and integrity of a firewall, but it is not the most important thing for an IS auditor to verify, as configuration files may not reflect the actual state or performance of the firewall.
CISA-KR 문제 118
CISA-KR 문제 119
While evaluating the data classification process of an organization, an IS auditor's primary focus should be on whether data is correctly classified. This means that the data is assigned to the appropriate classification level based on its sensitivity, importance, integrity, availability, compliance requirements, and business value. Correct data classification ensures that the data is protected according to its risk level, and that the organization can comply with relevant laws and regulations that apply to different types of data3.
The other three options are not the primary focus of an IS auditor while evaluating the data classification process, although they may be relevant or useful for certain aspects of data management. Data classifications are automated means that the organization uses software tools or algorithms to analyze and label data based on predefined rules or criteria. This can improve the efficiency and consistency of data classification, but it does not guarantee that the data is correctly classified. The IS auditor still needs to verify the accuracy and validity of the automated classifications, and check for any errors or anomalies.
A data dictionary is maintained means that the organization keeps a record of the definitions, formats, sources, and relationships of the data elements in its systems or databases. This can enhance the understanding and usability of the data, but it does not ensure that the data is correctly classified. The IS auditor still needs to examine the content and context of the data, and compare it with the classification criteria and policies.
Data retention requirements are clearly defined means that the organization specifies how long it will keep different types of data, and when it will delete or archive them. This can help reduce storage costs, improve performance, and comply with legal obligations, but it does not ensure that the data is correctly classified. The IS auditor still needs to assess whether the data is stored and protected according to its classification level, and whether the retention periods are appropriate for each type of data.
Therefore, data is correctly classified is the best answer.
References:
* Data Classification: The Basics and a 6-Step Checklist - NetApp
* What is Data Classification? Guidelines and Process -Varonis
* Data Classification and Handling Procedures Guide
CISA-KR 문제 120
Re-partitioning is not a way to sanitize a hard disk for reuse, but rather a way to organize the hard disk into different logical sections or volumes. Re-partitioning does not erase the data on the hard disk, but only changes the structure and allocation of the disk space. Re-partitioning may make the data inaccessible to the operating system, but not to other tools or methods that can scan or recover the data from the disk sectors.
Degaussing is a way to sanitize a hard disk for reuse, but only for magnetic hard disks, not solid state drives (SSDs). Degaussing is a process that exposes the hard disk to a strong magnetic field, which disrupts and destroys the magnetic alignment of the data on the disk platters. Degaussing can effectively erase the data on magnetic hard disks, but it can also damage or render unusable the electronic components of the hard disk, such as the read/write heads or circuit boards. Degaussing also does not work on SSDs, which store data using flash memory cells, not magnetic media.
Formatting is not a way to sanitize a hard disk for reuse, but rather a way to prepare the hard disk for use by an operating system. Formatting is a process that creates a file system on the hard disk, which defines how the data is stored and accessed on the disk. Formatting does not erase the data on the hard disk, but only deletes the file system metadata and marks the disk space as available for new data. Formatting may make the data invisible to the operating system, but not to other tools or methods that can restore or recover the data from the disk sectors.
References:
* How to Wipe A Hard Drive for Reuse? Check the Quickest Way to Wipe A Hard Drive - EaseUS 1
* HP PCs - Using Secure Erase or HP Disk Sanitizer 2
* HOW to QUICKLY and PERMANENTLY SANITIZE ANY DRIVE (SSD, USB thumb drive ...)
- 다른 버전
- 228ISACA.CISA-KR.v2026-08-15.q712
- 4247ISACA.CISA-KR.v2026-05-16.q709
- 1829ISACA.CISA-KR.v2026-05-06.q261
- 3199ISACA.CISA-KR.v2026-03-16.q665
- 4686ISACA.CISA-KR.v2026-03-07.q651
- 9358ISACA.CISA-KR.v2025-04-07.q633
- 4499ISACA.CISA-KR.v2025-04-03.q628
- 4293ISACA.CISA-KR.v2025-03-31.q534
- 5443ISACA.CISA-KR.v2025-03-28.q617
- 3272ISACA.CISA-KR.v2025-03-19.q581
- 4084ISACA.CISA-KR.v2025-03-03.q807
- 5232ISACA.CISA-KR.v2024-02-07.q421
- 2903ISACA.CISA-KR.v2024-01-31.q392
- 5411ISACA.CISA-KR.v2023-10-24.q329
- 5244ISACA.CISA-KR.v2023-07-31.q266
- 3244ISACA.CISA-KR.v2023-06-23.q324
- 최근 업로드
- 228ISACA.CISA-KR.v2026-08-15.q712
- 171Microsoft.MS-700-KR.v2026-08-15.q203
- 133Microsoft.AZ-305-KR.v2026-08-14.q177
- 203Microsoft.DP-900-KR.v2026-08-13.q130
- 290Microsoft.PL-600.v2026-08-11.q206
- 224Microsoft.DP-100.v2026-08-11.q160
- 189Oracle.1Z0-1048-25.v2026-08-11.q68
- 160ISQI.CTAL-TAE.v2026-08-11.q37
- 202ServiceNow.CIS-HR.v2026-08-11.q84
- 282Salesforce.Plat-Arch-201.v2026-08-10.q101
PDF 파일 다운로드
메일 주소를 입력하시고 다운로드 하세요. ISACA.CISA-KR.v2025-04-02.q544 모의시험 시험자료를 다운 받으세요.
