CISA-KR 문제 231
CISA-KR 문제 232
* Inaccurate or unreliable data and results from EUC applications that are not validated, verified, or tested
* Unauthorized or inappropriate access or use of EUC applications that are not secured, controlled, or monitored
* Inconsistent or incompatible data and results from EUC applications that are not integrated, documented, or updated
* Loss or corruption of data and results from EUC applications that are not backed up, recovered, or archived Therefore, the IS auditor should be most concerned about the lack of defined criteria for EUC applications, as it can affect the quality, integrity, and availability of the EUC applications and the data they produce.
Insufficient processes to track ownership of each EUC application is a finding that should be of concern to an IS auditor assessing the risk associated with EUC in an organization, but it is not the greatest concern. The ownership of an EUC application refers to the person or group who is responsible for creating, maintaining, and using the EUC application. Insufficient processes to track ownership of each EUC application means that the organization does not have adequate mechanisms or records to identify and communicate who owns each EUC application. This can lead to risks, such as:
* Lack of accountability or ownership for the quality and accuracy of the EUC application and its data
* Lack of support or maintenance for the EUC application when the owner leaves or changes roles
* Lack of awareness or training for the users of the EUC application on its purpose and functionality However, these risks are less severe than those caused by the lack of defined criteria for EUC applications.
Insufficient processes to test for version control is a finding that should be of concern to an IS auditor assessing the risk associated with EUC in an organization, but it is not the greatest concern. Version control is a process that tracks and manages the changes made to an EUC application over time. Insufficient processes to test for version control means that the organization does not have adequate procedures or tools to ensure that the changes made to an EUC application are authorized, documented, and tested. This can lead to risks, such as:
* Errors or inconsistencies in the data and results from different versions of the EUC application
* Conflicts or confusion among the users of the EUC application on which version is current or correct
* Loss or overwrite of data and results from previous versions of the EUC application However, these risks are less severe than those caused by the lack of defined criteria for EUC applications.
Lack of awareness training for EUC users is a finding that should be of concern to an IS auditor assessing the risk associated with EUC in an organization, but it is not the greatest concern. Awareness training for EUC users is a process that educates and informs the users of the EUC applications on their roles, responsibilities, and risks. Lack of awareness training for EUC users means that the organization does not have adequate programs or materials to raise the knowledge and skills of the users on how to use and manage the EUC applications effectively and securely. This can lead to risks, such as:
* Misuse or abuse of the EUC applications by users who are not aware of their impact or implications
* Non-compliance or violation of policies or regulations by users who are not aware of their requirements or expectations
* Dissatisfaction or frustration among users who are not aware of their benefits or limitations However, these risks are less severe than those caused by the lack of defined criteria for EUC applications.
References:
* End-user computing - Wikipedia 1
* How to Manage the Risks Associated with End User Computing 2
* Managing end user computing risks - KPMG UK 3
CISA-KR 문제 233
Performing a review of privileged roles and responsibilities is also a good practice, but it may not address the specific risk of data leakage by the vendor with privileged access. Requiring the vendor to implement job rotation for privileged roles may reduce the risk of collusion or fraud, but it may not prevent or detect data leakage by any individual with privileged access. References: CISA Review Manual (Digital Version),
[ISACA Privacy Principles and Program Management Guide]
CISA-KR 문제 234
* CISA Review Manual (Digital Version), Chapter 1, Section 1.41
* CISA Online Review Course, Domain 5, Module 1, Lesson 22
CISA-KR 문제 235
* Inconsistency and conflict among different security policies and standards
* Lack of coordination and communication among different administrators
* Difficulty in monitoring and auditing the overall security status and performance
* Increased complexity and cost of security management and maintenance
Therefore, the greatest potential concern for implementing a distributed security administration system is that the security procedures may be inadequate to support the change. Security procedures are the rules and guidelines that define how security is implemented and enforced in an organization. They include policies, standards, processes, roles, responsibilities, controls, and metrics. Security procedures should be aligned with the business objectives, risks, and requirements of the organization, as well as the best practices and regulations in the industry. Security procedures should also be reviewed and updated regularly to reflect the changes in the environment, technology, and threats.
If the security procedures are not adequate to support the change from a centralized to a distributed security administration system, the organization may face increased security risks, such as unauthorized access, data breaches, compliance violations, reputation damage, and financial losses. Therefore, it is essential to ensure that the security procedures are revised and adapted to suit the new system, and that they are communicated and enforced effectively across the organization.
References:
* 1: Security in Distributed System - GeeksforGeeks
* 2: Distributed System Security Architecture - Wikipedia
* 3: Distributed Systems Security: Issues, Processes and Solutions
- 다른 버전
- 225ISACA.CISA-KR.v2026-08-15.q712
- 4217ISACA.CISA-KR.v2026-05-16.q709
- 1827ISACA.CISA-KR.v2026-05-06.q261
- 3194ISACA.CISA-KR.v2026-03-16.q665
- 4657ISACA.CISA-KR.v2026-03-07.q651
- 9347ISACA.CISA-KR.v2025-04-07.q633
- 4493ISACA.CISA-KR.v2025-04-03.q628
- 4285ISACA.CISA-KR.v2025-03-31.q534
- 5432ISACA.CISA-KR.v2025-03-28.q617
- 3257ISACA.CISA-KR.v2025-03-19.q581
- 4061ISACA.CISA-KR.v2025-03-03.q807
- 5218ISACA.CISA-KR.v2024-02-07.q421
- 2872ISACA.CISA-KR.v2024-01-31.q392
- 5391ISACA.CISA-KR.v2023-10-24.q329
- 5231ISACA.CISA-KR.v2023-07-31.q266
- 3231ISACA.CISA-KR.v2023-06-23.q324
- 최근 업로드
- 225ISACA.CISA-KR.v2026-08-15.q712
- 167Microsoft.MS-700-KR.v2026-08-15.q203
- 132Microsoft.AZ-305-KR.v2026-08-14.q177
- 191Microsoft.DP-900-KR.v2026-08-13.q130
- 290Microsoft.PL-600.v2026-08-11.q206
- 221Microsoft.DP-100.v2026-08-11.q160
- 188Oracle.1Z0-1048-25.v2026-08-11.q68
- 160ISQI.CTAL-TAE.v2026-08-11.q37
- 202ServiceNow.CIS-HR.v2026-08-11.q84
- 281Salesforce.Plat-Arch-201.v2026-08-10.q101
PDF 파일 다운로드
메일 주소를 입력하시고 다운로드 하세요. ISACA.CISA-KR.v2025-04-02.q544 모의시험 시험자료를 다운 받으세요.
