CISA-KR 문제 216
ISACA CISA Reference:Digital forensics best practices emphasize write-blocking devices to prevent contamination of evidence.
Risk Implication:Without a write blocker, evidence may be tampered with, compromising its admissibility in court.
CISA-KR 문제 217
Option B is not correct because identifying approved data workflows across the enterprise is a subsequent step after conducting data inventory and classification. Data workflows are the processes and channels through which data are created, stored, accessed, shared, or transmitted within or outside the organization4. Identifying approved data workflows helps to define the normal and legitimate use of data, as well as to detect and prevent unauthorized or anomalous data activities5. However, before identifying approved data workflows, the organization needs to know what data it has and how it should be classified.
Option C is not correct because conducting a threat analysis against sensitive data usage is another subsequent step after conducting data inventory and classification. Threat analysis is the process of identifying and assessing the potential sources, methods, and impacts of data loss or leakage incidents. Threat analysis helps to design and implement effective DLP controls and countermeasures based on the risk profile of each data category. However, before conducting threat analysis, the organization needs to know what data it has and how it should be classified.
Option D is not correct because creating the DLP policies and templates is the final step after conducting data inventory and classification, identifying approved data workflows, and conducting threat analysis. DLP policies and templates are the rules and configurations that specify how the DLP solution should monitor, detect, report, and respond to data loss or leakage events. DLP policies and templates should be aligned with the organization's business needs, regulatory obligations, and risk appetite. However, before creating the DLP policies and templates, the organization needs to know what data it has, how it should be classified, how it should be used, and what threats it faces.
References:
Data Inventory & Classification: The First Step in Data Protection1
Data Classification: What It Is And Why You Need It2
How to Prioritize Your Data Loss Prevention Strategy in 20203
What Is Data Workflow? Definition & Examples4
How to Identify Data Workflows for Your Business5
Threat Analysis: A Comprehensive Guide for Beginners
How to Conduct a Threat Assessment for Your Business
What Is Data Loss Prevention (DLP)? Definition & Examples
How to Create Effective Data Loss Prevention Policies
CISA-KR 문제 218
The application design phase is when the software requirements are translated into a logical and physical design that specifies how the application will look and work. This phase is the best time to discuss application controls because it allows the developers to incorporate them into the design specifications and ensure that they are aligned with the business objectives and user needs. By discussing application controls early in the design phase, the developers can also avoid costly rework or changes later in the development process.
The other phases are not as optimal as the application design phase to initiate the discussion of application controls. A. Business case development phase when stakeholders are identified. The business case development phase is when the feasibility, scope, objectives, benefits, risks, and costs of a software project are defined and evaluated. This phase is important for obtaining stakeholder approval and support for the project, but it is too early to discuss application controls in detail because the software requirements and functionalities are not yet clear or finalized. B. User acceptance testing (UAT) phase when test scenarios are designed. The user acceptance testing phase is when the software is tested by the end-users or stakeholders to verify that it meets their expectations and requirements. This phase is too late to discuss application controls because it is near the end of the development process and any changes or additions to the application controls would require retesting and revalidation of the software. C. Application coding phase when algorithms are developed to solve business problems. The application coding phase is when the software design is translated into executable code using programming languages and tools. This phase is not ideal to discuss application controls because it is after the design phase and any changes or additions to the application controls would require redesigning and recoding of the software.
References:
* ISACA, CISA Review Manual, 27th Edition, 2019, p. 2471
* ISACA, CISA Review Questions, Answers & Explanations Database - 12 Month Subscription2
* What Is Application Control? | McAfee3
* What Is Application Lifecycle Management? | Red Hat4
CISA-KR 문제 219
CISA-KR 문제 220
Verifying duplicate calculations in data processing is a detective control, as it helps to identify errors or anomalies in data processing. Reviewing user access rights for segregation is also a detective control, as it helps to detect any violations of segregation of duties principles. References: ISACA, CISA Review Manual,
27th Edition, 2018, page 64
- 다른 버전
- 263ISACA.CISA-KR.v2026-08-15.q712
- 4291ISACA.CISA-KR.v2026-05-16.q709
- 1847ISACA.CISA-KR.v2026-05-06.q261
- 3251ISACA.CISA-KR.v2026-03-16.q665
- 4718ISACA.CISA-KR.v2026-03-07.q651
- 9428ISACA.CISA-KR.v2025-04-07.q633
- 3801ISACA.CISA-KR.v2025-04-02.q544
- 4306ISACA.CISA-KR.v2025-03-31.q534
- 5498ISACA.CISA-KR.v2025-03-28.q617
- 3301ISACA.CISA-KR.v2025-03-19.q581
- 4180ISACA.CISA-KR.v2025-03-03.q807
- 5241ISACA.CISA-KR.v2024-02-07.q421
- 2917ISACA.CISA-KR.v2024-01-31.q392
- 5425ISACA.CISA-KR.v2023-10-24.q329
- 5252ISACA.CISA-KR.v2023-07-31.q266
- 3248ISACA.CISA-KR.v2023-06-23.q324
- 최근 업로드
- 263ISACA.CISA-KR.v2026-08-15.q712
- 226Microsoft.MS-700-KR.v2026-08-15.q203
- 154Microsoft.AZ-305-KR.v2026-08-14.q177
- 225Microsoft.DP-900-KR.v2026-08-13.q130
- 293Microsoft.PL-600.v2026-08-11.q206
- 233Microsoft.DP-100.v2026-08-11.q160
- 196Oracle.1Z0-1048-25.v2026-08-11.q68
- 162ISQI.CTAL-TAE.v2026-08-11.q37
- 204ServiceNow.CIS-HR.v2026-08-11.q84
- 283Salesforce.Plat-Arch-201.v2026-08-10.q101
PDF 파일 다운로드
메일 주소를 입력하시고 다운로드 하세요. ISACA.CISA-KR.v2025-04-03.q628 모의시험 시험자료를 다운 받으세요.
