CISA-KR 문제 121
One of the aspects that an IS auditor should review when evaluating information systems governance for a large organization is the approval processes for new system implementations. This is because new system implementations are significant IT investments that require careful planning, analysis, design, development, testing, deployment, and evaluation to ensure that they meet the business requirements, deliver the expected benefits, comply with the relevant standards and regulations, and minimize the potential risks2. The approval processes for new system implementations should involve the appropriate stakeholders, such as senior management, business owners, IT managers, project managers, users, and auditors, who have the authority and responsibility to approve or reject the proposed system implementations based on predefined criteria and metrics3. The approval processes for new system implementations should also be documented, transparent, consistent, and timely to ensure accountability and traceability4. Therefore, an IS auditor should review the approval processes for new system implementations to assess whether they are aligned with the information systems governance framework and objectives.
The other possible options are:
* Procedures for adding a new user to the invoice processing system: This is an operational task that involves granting access rights and permissions to a specific user for a specific system based on the principle of least privilege. This is not a strategic or high-level function that falls under information systems governance. Therefore, an IS auditor should not review this aspect when evaluating information systems governance for a large organization.
* Approval processes for updating the corporate website: This is a tactical task that involves making changes or enhancements to the content or design of the corporate website based on the business needs and feedback. This is not a strategic or high-level function that falls under information systems governance. Therefore, an IS auditor should not review this aspect when evaluating information systems governance for a large organization.
* Procedures for regression testing system changes: This is a technical task that involves verifying that existing system functionalities are not adversely affected by new system changes or updates. This is not a strategic or high-level function that falls under information systems governance. Therefore, an IS auditor should not review this aspect when evaluating information systems governance for a large organization. References: 1: What is IT Governance? - Definition from Techopedia 2: System Implementation - an overview | ScienceDirect Topics 3: Project Approval Process - Project Management Knowledge 4: 5 Best Practices For A Successful Project Approval Process | Kissflow Project : Principle of Least Privilege (POLP) | Imperva : How to Update Your Website Content - 7 Step Guide | HostGator Blog : What Is Regression Testing? Definition & Best Practices | BrowserStack
CISA-KR 문제 122
CISA-KR 문제 123
The public key can be shared with anyone, while the private key must be kept secret by the owner. To create a digital signature, the sender first applies a hash function to the plaintext message to generate a digest. Then, the sender encrypts the digest with their private key to produce the digital signature. To verify the digital signature, the receiver decrypts the digital signature with the sender's public key to obtain the digest. Then, the receiver applies the same hash function to the plaintext message to generate another digest. If the two digests match, it means that the message has not been altered and that it came from the sender. The security of a digital signature depends on the secrecy of the sender's private key. If an attacker obtains the sender's private key, they can create fake digital signatures for any message they want, thus compromising the control provided by the digital signature. Reversing the hash function using the digest is not possible, as hash functions are designed to be one-way functions that cannot be inverted. Altering the plaintext message will result in a different digest after applying the hash function, which will not match with the decrypted digest from the digital signature, thus invalidating the digital signature. Deciphering the receiver's public key is not relevant, as public keys are meant to be publicly available and do not affect the security of digital signatures.
CISA-KR 문제 124
References:
How Accurate are today's Fingerprint Scanners? - Bayometric
25 Advantages and Disadvantages of Iris Recognition - Biometric Today
Iris Recognition Technology (or, Musings While Going through Airport ...
The Critics Were Wrong: NIST Data Shows the Best Facial Recognition Algorithms Are Neither Racist Nor Sexist | ITIF NIST Launches Studies into Masks' Effect on Face Recognition Software Retinal scan - Wikipedia How accurate are retinal security scans - Smart Eye Technology
CISA-KR 문제 125
The other options are not as helpful as post-implementation review for measuring benefits realization for a new system:
* Function point analysis. This is a technique that measures the size and complexity of a software system based on the number and types of functions it provides. Function point analysis can help estimate the cost, effort, and time required to develop, maintain, or enhance a software system, but it does not measure the actual benefits or value that the system delivers to the organization or its users.
* Balanced scorecard review. This is a strategic management tool that measures the performance of an organization or a business unit based on four perspectives: financial, customer, internal process, and learning and growth. A balanced scorecard review can help align the organization's vision, mission, and goals with its activities and outcomes, but it does not measure the specific benefits or impacts of a new system.
* Business impact analysis (BIA). This is a process that identifies and evaluates the potential effects of a disruption or disaster on the organization's critical business functions and processes. A BIA can help determine the recovery priorities, objectives, and strategies for the organization in case of an emergency, but it does not measure the benefits or value of a new system.
- 다른 버전
- 227ISACA.CISA-KR.v2026-08-15.q712
- 4246ISACA.CISA-KR.v2026-05-16.q709
- 1829ISACA.CISA-KR.v2026-05-06.q261
- 3199ISACA.CISA-KR.v2026-03-16.q665
- 4685ISACA.CISA-KR.v2026-03-07.q651
- 9355ISACA.CISA-KR.v2025-04-07.q633
- 4499ISACA.CISA-KR.v2025-04-03.q628
- 4293ISACA.CISA-KR.v2025-03-31.q534
- 5443ISACA.CISA-KR.v2025-03-28.q617
- 3272ISACA.CISA-KR.v2025-03-19.q581
- 4080ISACA.CISA-KR.v2025-03-03.q807
- 5232ISACA.CISA-KR.v2024-02-07.q421
- 2897ISACA.CISA-KR.v2024-01-31.q392
- 5408ISACA.CISA-KR.v2023-10-24.q329
- 5244ISACA.CISA-KR.v2023-07-31.q266
- 3244ISACA.CISA-KR.v2023-06-23.q324
- 최근 업로드
- 227ISACA.CISA-KR.v2026-08-15.q712
- 170Microsoft.MS-700-KR.v2026-08-15.q203
- 133Microsoft.AZ-305-KR.v2026-08-14.q177
- 203Microsoft.DP-900-KR.v2026-08-13.q130
- 290Microsoft.PL-600.v2026-08-11.q206
- 223Microsoft.DP-100.v2026-08-11.q160
- 189Oracle.1Z0-1048-25.v2026-08-11.q68
- 160ISQI.CTAL-TAE.v2026-08-11.q37
- 202ServiceNow.CIS-HR.v2026-08-11.q84
- 282Salesforce.Plat-Arch-201.v2026-08-10.q101
PDF 파일 다운로드
메일 주소를 입력하시고 다운로드 하세요. ISACA.CISA-KR.v2025-04-02.q544 모의시험 시험자료를 다운 받으세요.
