CISA-KR 문제 261
The execution phase is the stage of the internal audit process where the audit team performs the audit procedures according to the audit plan. The execution phase involves testing the design and operating effectiveness of the controls, collecting and analyzing evidence, documenting the audit work and results, and identifying any issues or findings. The execution phase aims to provide sufficient and appropriate evidence to support the audit conclusions and recommendations.
The follow-up phase is the stage of the internal audit process where the audit team monitors and verifies the implementation of the corrective actions agreed upon by the auditee in response to the audit findings. The follow-up phase involves reviewing the evidence provided by the auditee, conducting additional tests or interviews if necessary, and evaluating whether the corrective actions have adequately addressed the root causes of the findings. The follow-up phase aims to ensure that the auditee has taken timely and effective actions to improve its processes and controls.
The selection phase is not a standard stage of the internal audit process, but it may refer to the process of selecting which areas or functions to audit based on a risk assessment or an annual audit plan. The selection phase involves evaluating the inherent and residual risks of each potential auditable area, considering the impact, likelihood, and frequency of those risks, as well as other factors such as regulatory requirements, stakeholder expectations, previous audit results, and available resources. The selection phase aims to prioritize and allocate the audit resources to those areas that present the highest risks or opportunities for improvement.
Therefore, option A is the correct answer.
References:
* Stages and phases of internal audit - piranirisk.com
* Step-by-Step Internal Audit Checklist | AuditBoard
* Audit Process | The Office of Internal Audit - University of Oregon
CISA-KR 문제 262
CISA-KR 문제 263
* A. Security parameters should not be set in accordance with the manufacturer's standards alone, as they may not reflect the organization's specific security needs and environment. The manufacturer's standards are general recommendations or best practices for configuring the server's security parameters based on common scenarios and threats. An IS auditor should compare the manufacturer's standards with the organization's policies and identify any gaps or conflicts that need to be resolved.
* B. A detailed business case should have been formally approved prior to the purchase of a new server rather than during its installation. A business case is a document that justifies the need for a new server based on its expected benefits, costs, risks, and alternatives. A business case should be approved by senior management before initiating a project to acquire a new server.
* D. The procurement project should have invited tenders from at least three different suppliers before purchasing a new server rather than during its installation. A tender is a formal offer or proposal to provide a product or service at a specified price and quality. Inviting tenders from multiple suppliers helps to ensure a fair and competitive procurement process that can result in the best value for money and quality for the organization. References: Server Security - ISACA, [Information Security Policy - ISACA], [Server Hardening - ISACA], [Business Case - ISACA], [Tender - ISACA], [Procurement Management - ISACA]
CISA-KR 문제 264
Management's commitment to information security also demonstrates leadership, sets the tone and culture, and establishes the strategic direction and objectives for information security. User accountability for information security, alignment of information security with IT objectives, and integration of business and information security are also important factors for the success of an information security program, but they are not as critical as management'scommitment to information security, as they depend on or derive from it. References: Info Technology & Systems Resources | COBIT, Risk, Governance ... - ISACA, IT Governance and Process Maturity
CISA-KR 문제 265
- 다른 버전
- 323ISACA.CISA-KR.v2026-08-15.q712
- 4322ISACA.CISA-KR.v2026-05-16.q709
- 1869ISACA.CISA-KR.v2026-05-06.q261
- 3340ISACA.CISA-KR.v2026-03-16.q665
- 4744ISACA.CISA-KR.v2026-03-07.q651
- 9446ISACA.CISA-KR.v2025-04-07.q633
- 3811ISACA.CISA-KR.v2025-04-02.q544
- 4317ISACA.CISA-KR.v2025-03-31.q534
- 5529ISACA.CISA-KR.v2025-03-28.q617
- 3314ISACA.CISA-KR.v2025-03-19.q581
- 4198ISACA.CISA-KR.v2025-03-03.q807
- 5246ISACA.CISA-KR.v2024-02-07.q421
- 2939ISACA.CISA-KR.v2024-01-31.q392
- 5437ISACA.CISA-KR.v2023-10-24.q329
- 5261ISACA.CISA-KR.v2023-07-31.q266
- 3260ISACA.CISA-KR.v2023-06-23.q324
- 최근 업로드
- 133Microsoft.AZ-305-KR.v2026-08-17.q162
- 143IIA.IAA-IAP-KR.v2026-08-17.q41
- 323ISACA.CISA-KR.v2026-08-15.q712
- 259Microsoft.MS-700-KR.v2026-08-15.q203
- 181Microsoft.AZ-305-KR.v2026-08-14.q177
- 252Microsoft.DP-900-KR.v2026-08-13.q130
- 319Microsoft.PL-600.v2026-08-11.q206
- 272Microsoft.DP-100.v2026-08-11.q160
- 210Oracle.1Z0-1048-25.v2026-08-11.q68
- 178ISQI.CTAL-TAE.v2026-08-11.q37
PDF 파일 다운로드
메일 주소를 입력하시고 다운로드 하세요. ISACA.CISA-KR.v2025-04-03.q628 모의시험 시험자료를 다운 받으세요.
