CISA-KR 문제 601
The other options are not as good as option D. Percentage of problems raised from incidents (option A) is a metric that shows how many incidents are escalated to problems, which are more complex and require root cause analysis and long-term solutions. This metric reflects the complexity and severity of the issues faced by the customers, but it does not directly measure the performance of the help desk function. Mean time to categorize tickets (option B) is a metric that shows how long it takes for the help desk agents to assign a category to each ticket, such as technical, billing, or feedback. This metric reflects the efficiency and accuracy of the help desk agents, but it does not measure the quality or effectiveness of the resolution. Number of incidents reported (option C) is a metric that shows how many issues are reported by the customers to the help desk function. This metric reflects the demand and workload of the help desk function, but it does not measure how well the issues are resolved or how satisfied the customers are.
References:
* Key Metrics to Measure Help Desk Performance
* 8 service desk KPIs and performance metrics for IT support
* 13 Most Important Help Desk KPIs to Track and Measure Help Desk Performance
CISA-KR 문제 602
* CISA Review Manual (Digital Version), page 325
* CISA Questions, Answers & Explanations Database, question ID 3335
CISA-KR 문제 603
CISA-KR 문제 604
CISA-KR 문제 605
The other options are not as concerning as option C for an IS auditor reviewing the threat assessment for a data center. Option A, some of the identified threats are unlikely to occur, is not a problem as long as the likelihood and impact of each threat are properly estimated and prioritized. A threat assessment should consider all possible scenarios, even if they have a low probability of occurrence, to ensure that the data center is prepared for any eventuality2. Option B, all identified threats relate to external entities, is not a flaw as long as the assessment also considers internal threats, such as human errors, malicious insiders, or equipment failures. External threats are often more visible and severe than internal threats, but they are not the only source of risk for a data center3. Option D, neighboring organizations' operations have been included, is not a mistake as long as the assessment also focuses on the data center's own operations. Neighboring organizations' operations may have an impact on the data center's security and availability, especially if they share physical or network infrastructure or resources. A threat assessment should take into account the interdependencies and interactions between the data center and its external environment4.
References:
* ISACA, CISA Review Manual, 27th Edition, 2019
* ISACA, CISA Review Questions, Answers & Explanations Database - 12 Month Subscription
* Data Center Threats and Vulnerabilities1
* Datacenter threat, vulnerability, and risk assessment2
* Data Centre Risk Assessment3
- 다른 버전
- 356ISACA.CISA-KR.v2026-08-15.q712
- 4380ISACA.CISA-KR.v2026-05-16.q709
- 1876ISACA.CISA-KR.v2026-05-06.q261
- 3350ISACA.CISA-KR.v2026-03-16.q665
- 4751ISACA.CISA-KR.v2026-03-07.q651
- 9455ISACA.CISA-KR.v2025-04-07.q633
- 3814ISACA.CISA-KR.v2025-04-02.q544
- 4321ISACA.CISA-KR.v2025-03-31.q534
- 5533ISACA.CISA-KR.v2025-03-28.q617
- 3316ISACA.CISA-KR.v2025-03-19.q581
- 4202ISACA.CISA-KR.v2025-03-03.q807
- 5250ISACA.CISA-KR.v2024-02-07.q421
- 2943ISACA.CISA-KR.v2024-01-31.q392
- 5447ISACA.CISA-KR.v2023-10-24.q329
- 5268ISACA.CISA-KR.v2023-07-31.q266
- 3265ISACA.CISA-KR.v2023-06-23.q324
- 최근 업로드
- 221Microsoft.AZ-305-KR.v2026-08-17.q162
- 167IIA.IAA-IAP-KR.v2026-08-17.q41
- 356ISACA.CISA-KR.v2026-08-15.q712
- 285Microsoft.MS-700-KR.v2026-08-15.q203
- 212Microsoft.AZ-305-KR.v2026-08-14.q177
- 275Microsoft.DP-900-KR.v2026-08-13.q130
- 323Microsoft.PL-600.v2026-08-11.q206
- 293Microsoft.DP-100.v2026-08-11.q160
- 215Oracle.1Z0-1048-25.v2026-08-11.q68
- 185ISQI.CTAL-TAE.v2026-08-11.q37
PDF 파일 다운로드
메일 주소를 입력하시고 다운로드 하세요. ISACA.CISA-KR.v2025-04-03.q628 모의시험 시험자료를 다운 받으세요.
