CISA-KR 문제 131
A project steering committee is an advisory group that consists of senior stakeholders and experts who offer guidance and support to a project manager and their team. The steering committee is mainly concerned with the direction, scope, budget, timeline, and methods used to realize a given project1.
One of the key roles of a steering committee is to monitor the progress and performance of the project and ensure that it aligns with the business objectives and stakeholder expectations. The steering committee also provides feedback, advice, and recommendations to the project manager and helps them resolve any issues or challenges that may arise during the project lifecycle. The steering committee communicates regularly with the project manager and other stakeholders through meetings, reports, and presentations23.
Therefore, providing regular project updates and oversight is the primary responsibility of a project steering committee.
References:
Steering Committee: Definition, Roles & Meeting Tips - ProjectManager
Project Steering Committee: Roles, Best Practices, Challenges - ProjectPractical Steering Committee: Complete Guide with Examples & Templates - Status.net
CISA-KR 문제 132
References
ISACA CISA Review Manual (Current Edition) - Chapter on End-User Computing (EUC) risks Industry Research on Spreadsheet Errors: Multiple studies highlight the prevalence of errors in spreadsheets, especially those used for financial purposes.
CISA-KR 문제 133
Data security is the process of protecting data from unauthorized access, use, modification, disclosure, or destruction. Data security is essential for ensuring the confidentiality, integrity, and availability of data, as well as complying with legal and regulatory requirements. Data security is especially important for cloud- based applications, as data are stored and processed on remote servers that are owned and managed by third- party cloud service providers (CSPs)2.
When business units purchase cloud-based applications without IT support, they may not be aware of or follow the best practices and standards for data security in the cloud. They may not perform adequate risk assessments, vendor evaluations, contract reviews, or audits to ensure that the CSPs and the applications meet the organization's data security policies and expectations. They may not implement appropriate data encryption, backup, recovery, or disposal methods to protect the data in transit and at rest. They may not monitor or control the access and usage of the data by internal or external users. They may not report or respond to any data breaches or incidents that may occur3.
These actions or inactions may expose the organization's data to various threats and vulnerabilities in the cloud, such as cyberattacks, human errors, malicious insiders, misconfigurations, or legal disputes. These threats and vulnerabilities may result in data loss, leakage, corruption, or compromise, which may have serious consequences for the organization's reputation, operations, performance, compliance, and liability4.
Therefore, it is essential that business units consult and collaborate with IT support before purchasing any cloud-based applications, and follow the organization's guidelines and procedures for cloud security. IT support can help business units to select and use cloud-based applications that are suitable and secure for their needs and objectives.
References:
* Top 5 Risks With Cloud Software and How to Mitigate Them4
* Mitigate risks and secure your cloud-native applications3
* 12 Risks, Threats & Vulnerabilities in Moving to the Cloud2
* Best Practices to Manage Risks in the Cloud1
CISA-KR 문제 134
CISA-KR 문제 135
One of the best ways to mitigate the impact of ransomware attacks is to back up data frequently12345. Data backups are copies of the organization's data that are stored in a separate location or medium, such as an external hard drive, cloud storage, or tape2. Data backups can help the organization restore its data in case of a ransomware attack, without paying the ransom or losing valuable information2. Data backups should be performed regularly, preferably daily or weekly, depending on the criticality and volume of the data2. Data backups should also be tested periodically to ensure their integrity and usability2.
The other options are not as effective as backing up data frequently in mitigating the impact of ransomware attacks. Invoking the disaster recovery plan (DRP) is a reactive measure that can help the organization resume its operations after a ransomware attack, but it does not prevent or reduce the damage caused by the attack3.
Paying the ransom is not a recommended option, as it does not guarantee the decryption of the data or the deletion of the stolen data by the attackers. Paying the ransom also encourages further attacks and funds criminal activities14. Requiring password changes for administrative accounts is a good security practice, but it is not sufficient to prevent or recover from ransomware attacks. Ransomware attacks can exploit other vulnerabilities, such as phishing emails, outdated software, or weak network security15.
References: 1: How to Mitigate the Risk of Ransomware Attacks: The Definitive Guide 2: Mitigating malware and ransomware attacks - The National Cyber Security Centre 3: 3 steps to prevent and recover from ransomware 4: Ransomware Epidemic: Use these 8 Strategies to Mitigate Risk 5: Practical Steps to Mitigate Ransomware Attacks - ITSecurityWire
- 다른 버전
- 227ISACA.CISA-KR.v2026-08-15.q712
- 4246ISACA.CISA-KR.v2026-05-16.q709
- 1829ISACA.CISA-KR.v2026-05-06.q261
- 3199ISACA.CISA-KR.v2026-03-16.q665
- 4685ISACA.CISA-KR.v2026-03-07.q651
- 9355ISACA.CISA-KR.v2025-04-07.q633
- 4499ISACA.CISA-KR.v2025-04-03.q628
- 4293ISACA.CISA-KR.v2025-03-31.q534
- 5443ISACA.CISA-KR.v2025-03-28.q617
- 3272ISACA.CISA-KR.v2025-03-19.q581
- 4080ISACA.CISA-KR.v2025-03-03.q807
- 5232ISACA.CISA-KR.v2024-02-07.q421
- 2897ISACA.CISA-KR.v2024-01-31.q392
- 5408ISACA.CISA-KR.v2023-10-24.q329
- 5244ISACA.CISA-KR.v2023-07-31.q266
- 3244ISACA.CISA-KR.v2023-06-23.q324
- 최근 업로드
- 227ISACA.CISA-KR.v2026-08-15.q712
- 170Microsoft.MS-700-KR.v2026-08-15.q203
- 133Microsoft.AZ-305-KR.v2026-08-14.q177
- 202Microsoft.DP-900-KR.v2026-08-13.q130
- 290Microsoft.PL-600.v2026-08-11.q206
- 223Microsoft.DP-100.v2026-08-11.q160
- 189Oracle.1Z0-1048-25.v2026-08-11.q68
- 160ISQI.CTAL-TAE.v2026-08-11.q37
- 202ServiceNow.CIS-HR.v2026-08-11.q84
- 282Salesforce.Plat-Arch-201.v2026-08-10.q101
PDF 파일 다운로드
메일 주소를 입력하시고 다운로드 하세요. ISACA.CISA-KR.v2025-04-02.q544 모의시험 시험자료를 다운 받으세요.
