CISA-KR 문제 201
The other options are not as effective as including the requirement in the incident management response plan:
* Establishing key performance indicators (KPIs) for timely identification of security incidents is a good practice, but it does not guarantee compliance with the regulation. KPIs are metrics that measure the performance of a process or activity, but they do not specify how to perform it. The IS auditor should also provide guidance on how to identify and report security incidents within 24 hours.
* Engaging an external security incident response expert for incident handling is a possible option, but it may not be feasible or cost-effective. The organization may not have the budget or time to hire an external expert, or may prefer to handle the incidents internally. The IS auditor should also evaluate the qualifications and trustworthiness of the external expert, and ensure that they comply with the regulation and other contractual or legal obligations.
* Enhancing the alert functionality of the intrusion detection system (IDS) is a useful measure, but it is not sufficient to comply with the regulation. An IDS is a tool that monitors network traffic for malicious activity and alerts the network administrator or takes preventive action. However, an IDS may not detect all types of security incidents, or may generate false positives or negatives. The IS auditor should also consider other sources of incident detection, such as logs, reports, audits, or user feedback.
CISA-KR 문제 202
Anonymizing internal IP addresses is important for online security, as it helps protect the organization from several threats. If an attacker controls a server that employees connect to, the outgoing IP address of the organization's router is logged on the server. This IP address can be used by the attacker to launch a denial-of- service (DoS) attack or to create more targeted attacks such as phishing2. With a web proxy server, the IP shown in web logs is the web proxy's, which means an attacker would not have access to theorganization's router outgoing IP address2.
Anonymizing outgoing IP addresses is also important when carrying out sensitive actions online, such as law enforcement investigations or competitive intelligence. A web proxy server can help users avoid exposing their internal IP address that leads back to their organization, and instead use a third-party web proxy that provides more anonymity2.
The other options are not directly related to reducing organizational risk by using a web proxy server. Providing multi-factor authentication for additional security (option B) is a benefit of some web proxy servers, but it is not the main purpose of using a web proxy server3. Providing faster response than direct access(option C) is a benefit of some web proxy servers that cache content forbetter data transfer speeds and less bandwidth usage, but it is not directly related to reducing organizational risk1. Load balancing traffic to optimize data pathways (option D) is a benefit of some web proxy servers that distribute traffic across multiple servers, but it is not directly related to reducing organizational risk4.
References: 1: Proxy servers and tunneling 2: Multi-factor authentication: How to enable 2FA and boost your security 3: What Is Multi-factor Authentication (MFA) Security? 4: How it works: Microsoft Entra multifactor authentication
CISA-KR 문제 203
A rollback strategy, test cases, and post-implementation review objectives are not the most important considerations for a go-live decision when implementing an upgraded ERP system. These are important elements of project planning, execution, and evaluation, but they are not sufficient to determine whether the project is worth pursuing or delivering. These elements should be aligned with and derived from the business case.
CISA-KR 문제 204
Technical specifications are not documented is a possible concern for an IS auditor when reviewing an ICS that uses older unsupported technology in the scope of an upcoming audit, but it is not the most significant one. Technical specifications are documents that describe the technical characteristics or requirements of a system or component, such as functionality, performance, design, etc. Technical specifications are not documented, as they may affect the understanding, maintenance, and improvement of the ICS and its components. However, this concern may not beassociated with older unsupported technology, as it may affect any ICS regardless of its technology level.
CISA-KR 문제 205
White box testingis the most effective foridentifying hidden errorsand optimizingsource code quality.
* Option A (Incorrect):UAT focuses on functionalityfrom anend-user perspective, not source code errors.
* Option B (Incorrect):Black box testingexamines software behaviorwithout reviewing code, making it less effective for code-level optimization.
* Option C (Correct):White box testing(also known asclear box or structural testing)analyzes source codefor vulnerabilities, logic errors, and optimization opportunities.
* Option D (Incorrect):Penetration testingidentifiessecurity weaknesses, but it does notfocus on code efficiency.
Reference:ISACA CISA Review Manual -Domain 3: Information Systems Acquisition, Development, and Implementation- Coverssoftware testing methodologies and secure coding practices.
- 다른 버전
- 323ISACA.CISA-KR.v2026-08-15.q712
- 4321ISACA.CISA-KR.v2026-05-16.q709
- 1869ISACA.CISA-KR.v2026-05-06.q261
- 3335ISACA.CISA-KR.v2026-03-16.q665
- 4743ISACA.CISA-KR.v2026-03-07.q651
- 9445ISACA.CISA-KR.v2025-04-07.q633
- 3810ISACA.CISA-KR.v2025-04-02.q544
- 4317ISACA.CISA-KR.v2025-03-31.q534
- 5527ISACA.CISA-KR.v2025-03-28.q617
- 3313ISACA.CISA-KR.v2025-03-19.q581
- 4198ISACA.CISA-KR.v2025-03-03.q807
- 5245ISACA.CISA-KR.v2024-02-07.q421
- 2939ISACA.CISA-KR.v2024-01-31.q392
- 5434ISACA.CISA-KR.v2023-10-24.q329
- 5260ISACA.CISA-KR.v2023-07-31.q266
- 3260ISACA.CISA-KR.v2023-06-23.q324
- 최근 업로드
- 127Microsoft.AZ-305-KR.v2026-08-17.q162
- 143IIA.IAA-IAP-KR.v2026-08-17.q41
- 323ISACA.CISA-KR.v2026-08-15.q712
- 259Microsoft.MS-700-KR.v2026-08-15.q203
- 181Microsoft.AZ-305-KR.v2026-08-14.q177
- 239Microsoft.DP-900-KR.v2026-08-13.q130
- 317Microsoft.PL-600.v2026-08-11.q206
- 270Microsoft.DP-100.v2026-08-11.q160
- 209Oracle.1Z0-1048-25.v2026-08-11.q68
- 177ISQI.CTAL-TAE.v2026-08-11.q37
PDF 파일 다운로드
메일 주소를 입력하시고 다운로드 하세요. ISACA.CISA-KR.v2025-04-03.q628 모의시험 시험자료를 다운 받으세요.
