CISA-KR 문제 206
CISA-KR 문제 207
The application should meet the organization's requirements (A) is not the best answer, because it is a general and obvious criterion that applies to any application system acquisition, not a specific and important recommendation for a financial application system. The organization's requirementsshould be clearly defined and documented in the RFP, but they may not necessarily include audit trails as a design feature.
Potential suppliers should have experience in the relevant area is not the best answer, because it is a factor that affects the selection of the supplier, not the design of the financial application system. The experience and reputation of potential suppliers should be evaluated and verified during the RFP process, but they may not guarantee that the supplier will include audit trails in the design.
Vendor employee background checks should be conducted regularly (D) is not the best answer, because it is a measure that affects the security and trustworthiness of the vendor, not the design of the financial application system. Vendor employee background checks should be performed as part of the vendor management and due diligence process, but they may not ensure that the vendor will include audit trails in the design.
CISA-KR 문제 208
데이터에 대한 책임은 누구에게 있나요?
이 프로젝트의 분류는 무엇입니까?
The information owner is the person or entity that has the authority and responsibility for the business processes and functions that collect, use, store, and dispose of data1.
The information owner is accountable for ensuring that the data is handled in compliance with the applicable laws, regulations, policies, and standards, such as the GDPR and the PIPEDA1234.
The information owner is in the best position to determine the purpose and necessity of collecting and retaining data, as well as the risks and benefits associated with it1.
The information owner should consult with other stakeholders, such as the risk manager, the database administrator (DBA), and the privacy manager, to establish and implement appropriate data classification policies and procedures2.
Data classification is the process of organizing data in groups based on their attributes and characteristics, and then assigning class labels that describe a set of attributes that hold true for the corresponding data sets345.
Data classification helps organizations to identify, manage, protect, and understand their data, as well as to comply with modern data privacy regulations345.
Data classification also helps to determine appropriate user access levels, which means defining who can access, modify, share, or delete data based on their roles, responsibilities, and needs345.
Therefore, the information owner should be responsible for the data classification in an ERP migration project from local systems to the cloud (option C), as they have the authority and accountability for the data and its protection.
The other options are not correct because:
The information security officer (option A) is responsible for overseeing and coordinating the security policies and practices of the organization that involve data6. The information security officer should advise and assist the information owner on the best practices and standards for data security, but not determine the data classification.
The database administrator (DBA) (option B) is responsible for installing, configuring, monitoring, maintaining, and improving the performance of databases and data stores that contain data5. The DBA should support the information owner in implementing and enforcing the data classification policies and procedures, but not determine them.
The data architect (option D) is responsible for designing, modeling, and documenting the logical and physical structures of databases and data stores that contain data7. The data architect should collaborate with the information owner in creating and maintaining the data classification schema and metadata, but not determine them.
CISA-KR 문제 209
다음 중 어떤 것을 다음에 해야 할까요?
Software errors, bugs, or vulnerabilities that can affect the functionality, reliability, or security of the applications3 Software failures, delays, or overruns that can affect the delivery, performance, or customer satisfaction of the applications3 Software non-compliance that can result in legal, regulatory, or contractual violations or penalties3 The next step that the IS auditor should do after identifying deficiencies in SDLC policies is to communicate the observation to the auditee. The auditee is the person or entity that is subject to the audit and is responsible for the area being audited4. In this case, the auditee could be the software development manager, the project manager, or the senior management of the organization. Communicating the observation to the auditee is important for several reasons:
It allows the IS auditor to verify the accuracy and validity of the observation and gather additional evidence or information from the auditee4 It gives the auditee an opportunity to respond to the observation and provide their perspective, explanation, or justification for the deficiencies4 It enables the IS auditor to discuss with the auditee the potential impact, root cause, and remediation plan for the deficiencies4 It fosters a collaborative and constructive relationship between the IS auditor and the auditee and promotes transparency and accountability in the audit process4 The other options are not as appropriate as communicating the observation to the auditee. Documenting the findings in the audit report is a later stepthat should be done after communicating with the auditee and finalizing the observation. Identifying who approved the policies is not relevant for addressing the deficiencies and may imply blame or fault on a specific person or group. Escalating the situation to the lead auditor is not necessary unless there is a serious disagreement or conflict with the auditee that cannot be resolved by normal communication. Therefore, option D is the correct answer.
References:
What Is The Software Development Life Cycle? | PagerDuty
Software Development Life Cycle (SDLC) Policy | StrongDM
What Is SDLC? Best Phases, Methodologies, and Benefits Revealed - Kellton Communicating Audit Findings
CISA-KR 문제 210
- 다른 버전
- 250ISACA.CISA-KR.v2026-08-15.q712
- 4287ISACA.CISA-KR.v2026-05-16.q709
- 1844ISACA.CISA-KR.v2026-05-06.q261
- 3239ISACA.CISA-KR.v2026-03-16.q665
- 4712ISACA.CISA-KR.v2026-03-07.q651
- 9421ISACA.CISA-KR.v2025-04-07.q633
- 3795ISACA.CISA-KR.v2025-04-02.q544
- 4300ISACA.CISA-KR.v2025-03-31.q534
- 5482ISACA.CISA-KR.v2025-03-28.q617
- 3295ISACA.CISA-KR.v2025-03-19.q581
- 4170ISACA.CISA-KR.v2025-03-03.q807
- 5235ISACA.CISA-KR.v2024-02-07.q421
- 2917ISACA.CISA-KR.v2024-01-31.q392
- 5425ISACA.CISA-KR.v2023-10-24.q329
- 5247ISACA.CISA-KR.v2023-07-31.q266
- 3246ISACA.CISA-KR.v2023-06-23.q324
- 최근 업로드
- 250ISACA.CISA-KR.v2026-08-15.q712
- 214Microsoft.MS-700-KR.v2026-08-15.q203
- 152Microsoft.AZ-305-KR.v2026-08-14.q177
- 225Microsoft.DP-900-KR.v2026-08-13.q130
- 292Microsoft.PL-600.v2026-08-11.q206
- 233Microsoft.DP-100.v2026-08-11.q160
- 196Oracle.1Z0-1048-25.v2026-08-11.q68
- 162ISQI.CTAL-TAE.v2026-08-11.q37
- 204ServiceNow.CIS-HR.v2026-08-11.q84
- 283Salesforce.Plat-Arch-201.v2026-08-10.q101
PDF 파일 다운로드
메일 주소를 입력하시고 다운로드 하세요. ISACA.CISA-KR.v2025-04-03.q628 모의시험 시험자료를 다운 받으세요.
