CISA-KR 문제 146
One of the challenges is to ensure that the organization's data classification policies are preserved during the process of data transformation. This means that the data should retain its original classification level and labels after it is transformed, and that the appropriate controls and protections are applied to the transformed data.
The best way to ensure this is to implement classification labels in metadata during data creation (D).
Metadata is data that describes other data, such as its source, format, content, and context. By adding classification labels to metadata, the data can be easily identified and tracked throughout its lifecycle, including during data transformation. The labels can also help enforce the proper access rights and encryption standards for the data, regardless of its state or location.
CISA-KR 문제 147
RFID has many benefits for different applications, such as inventory management, supply chain optimization, asset tracking, and access control. However, RFID also poses some challenges and risks for information security and privacy. Some of these risks are:
Privacy: RFID tags can be read by unauthorized or malicious parties, who can collect personal or sensitive data without the knowledge or consent of the tag owners. This can lead to identity theft, profiling, tracking, or surveillance2. For example, a hacker could scan an RFID-tagged passport or credit card and steal the personal information or financial details of the owner3.
Communication attacks: RFID systems are vulnerable to various types of attacks that target the wireless communication between the tags and the readers. These include eavesdropping, jamming, spoofing, replaying, cloning, or modifying the data transmitted by the tags or the readers4. For example, an attacker could intercept the data from an RFID tag and alter it before sending it to the reader, causing false or misleading information to be recorded.
Mafia fraud: This is a type of attack where an adversary acts as a man-in-the-middle and relays the information between two legitimate parties. This can allow the adversary to bypass authentication or authorization mechanisms and gain access to restricted areas or resources. For example, an attacker could use a device to relay the signal from an RFID-tagged car key to the car's ignition system and start the car without having the physical key.
CISA-KR 문제 148
A system-generated list of staff and their project assignments, roles, and responsibilities can help the IS auditor to perform the following tasks:
* Identify the users who have access to the document management system and their level of access (e.g., read-only, edit, delete, etc.).
* Compare the actual access rights of the users with their expected or authorized access rights based on their roles and responsibilities.
* Detect any anomalies, discrepancies, or violations in the access rights of the users, such as excessive or unauthorized access, segregation of duties conflicts, or dormant or inactive accounts.
* Evaluate the effectiveness and efficiency of the access control policies and procedures, such as user provisioning, deprovisioning, authentication, authorization, auditing, etc.
The other options are not as useful as option B. Policies and procedures for managing documents provided by department heads (option A) are not reliable sources of information for an IS auditor because they may not reflect the actual practices or compliance status of the document management system. Previous audit reports related to other departments' use of the same system (option C) are not relevant for an IS auditor because they may not address the specific issues or risks associatedwith the current department's use of the document management system. Information provided by the audit team lead on the authentication systems used by the department (option D) is not sufficient for an IS auditor because authentication is only one aspect of access control and it does not provide information on the authorization or auditing of the document access.
References:
* Overview of document management in SharePoint
* Setting Up a Document Control System: 6 Basic Steps
* Access Control Management: Purpose, Types,Tools, & Benefits
* 9 Best Document Management Systems of 2023
CISA-KR 문제 149
The first activity that the IS auditor should perform when preparing a plan for audits to be carried out over a specified period is to determine the audit universe. This involves defining the criteria and methods for identifying and categorizing the auditable units, such as by business function, process, system, location, or risk level. The IS auditor should also consult with the management and other stakeholders to obtain their input and expectations for the audit plan. The IS auditor should then document and validate the audit universe, and update it regularly to reflect any changes in the organization's structure, operations, or environment.
The other three activities are also important for preparing an audit plan, but they should be performed after determining the audit universe. Allocating audit resources involves assigning staff, time, budget, and tools to each audit based on their complexity, priority, and availability. Prioritizing risks involves assessing the likelihood and impact of each risk associated with each auditable unit, and ranking them according to their significance and urgency. Reviewing prior audit reports involves analyzing the findings, recommendations, and actions from previous audits related to each auditable unit, and evaluating their current status and relevance.
Therefore, determining the audit universe is the best answer.
References:
* Audit Universe - UPDATED 2022 - Examples, Templates & More!
* 01 February 2023 Audit universe - IIA
CISA-KR 문제 150
The policy includes a strong risk-based approach, the retention period allows for review during the year-end audit, and the total transaction amount has no impact on financial reporting are not the most important things for the organization to ensure when reducing the actual retention period for media containing completed low- value transactions. These are possible factors or benefits that may influence or justify the decision, but they do not override or replace the data owner responsibilities.
- 다른 버전
- 249ISACA.CISA-KR.v2026-08-15.q712
- 4281ISACA.CISA-KR.v2026-05-16.q709
- 1842ISACA.CISA-KR.v2026-05-06.q261
- 3232ISACA.CISA-KR.v2026-03-16.q665
- 4711ISACA.CISA-KR.v2026-03-07.q651
- 9420ISACA.CISA-KR.v2025-04-07.q633
- 3795ISACA.CISA-KR.v2025-04-02.q544
- 4300ISACA.CISA-KR.v2025-03-31.q534
- 5460ISACA.CISA-KR.v2025-03-28.q617
- 3295ISACA.CISA-KR.v2025-03-19.q581
- 4157ISACA.CISA-KR.v2025-03-03.q807
- 5235ISACA.CISA-KR.v2024-02-07.q421
- 2904ISACA.CISA-KR.v2024-01-31.q392
- 5412ISACA.CISA-KR.v2023-10-24.q329
- 5247ISACA.CISA-KR.v2023-07-31.q266
- 3245ISACA.CISA-KR.v2023-06-23.q324
- 최근 업로드
- 249ISACA.CISA-KR.v2026-08-15.q712
- 212Microsoft.MS-700-KR.v2026-08-15.q203
- 149Microsoft.AZ-305-KR.v2026-08-14.q177
- 219Microsoft.DP-900-KR.v2026-08-13.q130
- 291Microsoft.PL-600.v2026-08-11.q206
- 232Microsoft.DP-100.v2026-08-11.q160
- 194Oracle.1Z0-1048-25.v2026-08-11.q68
- 161ISQI.CTAL-TAE.v2026-08-11.q37
- 204ServiceNow.CIS-HR.v2026-08-11.q84
- 283Salesforce.Plat-Arch-201.v2026-08-10.q101
PDF 파일 다운로드
메일 주소를 입력하시고 다운로드 하세요. ISACA.CISA-KR.v2025-04-03.q628 모의시험 시험자료를 다운 받으세요.
