CISA-KR 문제 211
CISA-KR 문제 212
Senior management's request, prior year's audit findings, and previous audit coverage and scope are also possible bases for selecting which IS audits to perform in the coming year, but not as primary as the organizational risk assessment. These factors are more secondary or supplementary sources of information that can help IS auditors refine or adjust their audit plan based on specific needs or issues identified by management or previous audits. However, thesefactors may not reflect the current or emerging risks that may affect the organization's operations or performance. References: ISACA CISA Review Manual 27th Edition, page 295
CISA-KR 문제 213
The other options are not as concerning as option C for an IS auditor reviewing the threat assessment for a data center. Option A, some of the identified threats are unlikely to occur, is not a problem as long as the likelihood and impact of each threat are properly estimated and prioritized. A threat assessment should consider all possible scenarios, even if they have a low probability of occurrence, to ensure that the data center is prepared for any eventuality2. Option B, all identified threats relate to external entities, is not a flaw as long as the assessment also considers internal threats, such as human errors, malicious insiders, or equipment failures. External threats are often more visible and severe than internal threats, but they are not the only source of risk for a data center3. Option D, neighboring organizations' operations have been included, is not a mistake as long as the assessment also focuses on the data center's own operations. Neighboring organizations' operations may have an impact on the data center's security and availability, especially if they share physical or network infrastructure or resources. A threat assessment should take into account the interdependencies and interactions between the data center and its external environment4.
References:
* ISACA, CISA Review Manual, 27th Edition, 2019
* ISACA, CISA Review Questions, Answers & Explanations Database - 12 Month Subscription
* Data Center Threats and Vulnerabilities1
* Datacenter threat, vulnerability, and risk assessment2
* Data Centre Risk Assessment3
CISA-KR 문제 214
CISA-KR 문제 215
Data classification typically involves assigning labels or tags to data assets, such as public, internal, confidential, or restricted. These labels indicate the level of protection and handling required for the data.
Based on the data classification, organizations can implement appropriate controls to safeguard the data, such as encryption, access control lists, audit logs, backup policies, etc. These controls help to prevent unauthorized access, disclosure, modification, or loss of data, and to ensure compliance with relevant laws and regulations.
If a data owner assigns an incorrect classification level to data, it can result in either underprotection or overprotection of the data. Underprotection means that the data is classified at a lower level than it should be, which exposes it to higher risks of compromise or breach. For example, if a data owner classifies personal health information (PHI) as public instead of confidential, it may allow anyone to access or share the data without proper authorization or consent. This can violate the privacy rights of the data subjects and the compliance requirements of regulations such as HIPAA (Health Insurance Portability and Accountability Act). Overprotection means that the data is classified at a higher level than it should be, which limits its availability or usability. For example, if a data owner classifies marketing materials as restricted instead of public, it may prevent potential customers or partners from accessing or viewing the data. This can reduce the business value and opportunities of the data.
Therefore, an IS auditor should be concerned about the accuracy and consistency of data classification by data owners, as it affects the security and efficiency of data management. An IS auditor should review the policies and procedures for data classification, verify that the data owners have adequate knowledge and skills to classify their data, and test that the data classification labels match with the actual sensitivity and impact of the data.
References:
* Data Classification: What It Is and How to Implement It
* What Is Data Classification? - Definition, Levels & Examples ...
* Data Classification: A Guide for Data Security Leaders
- 다른 버전
- 225ISACA.CISA-KR.v2026-08-15.q712
- 4220ISACA.CISA-KR.v2026-05-16.q709
- 1827ISACA.CISA-KR.v2026-05-06.q261
- 3194ISACA.CISA-KR.v2026-03-16.q665
- 4664ISACA.CISA-KR.v2026-03-07.q651
- 9347ISACA.CISA-KR.v2025-04-07.q633
- 4494ISACA.CISA-KR.v2025-04-03.q628
- 4286ISACA.CISA-KR.v2025-03-31.q534
- 5432ISACA.CISA-KR.v2025-03-28.q617
- 3257ISACA.CISA-KR.v2025-03-19.q581
- 4061ISACA.CISA-KR.v2025-03-03.q807
- 5218ISACA.CISA-KR.v2024-02-07.q421
- 2872ISACA.CISA-KR.v2024-01-31.q392
- 5391ISACA.CISA-KR.v2023-10-24.q329
- 5231ISACA.CISA-KR.v2023-07-31.q266
- 3231ISACA.CISA-KR.v2023-06-23.q324
- 최근 업로드
- 225ISACA.CISA-KR.v2026-08-15.q712
- 168Microsoft.MS-700-KR.v2026-08-15.q203
- 132Microsoft.AZ-305-KR.v2026-08-14.q177
- 192Microsoft.DP-900-KR.v2026-08-13.q130
- 290Microsoft.PL-600.v2026-08-11.q206
- 221Microsoft.DP-100.v2026-08-11.q160
- 188Oracle.1Z0-1048-25.v2026-08-11.q68
- 160ISQI.CTAL-TAE.v2026-08-11.q37
- 202ServiceNow.CIS-HR.v2026-08-11.q84
- 281Salesforce.Plat-Arch-201.v2026-08-10.q101
PDF 파일 다운로드
메일 주소를 입력하시고 다운로드 하세요. ISACA.CISA-KR.v2025-04-02.q544 모의시험 시험자료를 다운 받으세요.
