CISA-KR 문제 341
프로젝트 타당성 조사에 있어서?
CISA-KR 문제 342
A roles and responsibility matrix can help avoid confusion, duplication, or omission of work, as well as ensure accountability and communication among the IT function and its customers, partners, and suppliers.
Therefore, an IS auditor should focus on reviewing the roles and responsibility matrix when evaluating the maturity model for a technology organization.
A standard operating procedure (SOP) is a document that describes the steps and instructions for performing a routine or repetitive task or process. SOPs are important for ensuring consistency, quality, and compliance in the IT function, but they are not directly related to the maturity model. A service level agreement (SLA) is a contract that defines the expectations and obligations between an IT service provider and its customers. SLAs are important for ensuring customer satisfaction, performance measurement, and dispute resolution in the IT function, but they are not directly related to the maturity model. A business resiliency plan is a document that outlines how an IT function will continue to operate or recover from a disruption or disaster. Business resiliency is important for ensuring availability, reliability, and security in the IT function, but it is not directly related to the maturity model. References: 1: Maturity Models for IT & Technology | Splunk 2: Responsibility assignment matrix - Wikipedia 3: Roles and Responsibilities Matrix - SDLCforms
CISA-KR 문제 343
CISA-KR 문제 344
A disaster recovery plan is not a static document that can be created once and forgotten. It is a dynamic and evolving process that requires regular review and update to ensure that it remains relevant, accurate, and effective. A disaster recovery plan should be reviewed and updated at least annually, or whenever there are significant changes in the organization's structure, operations, environment, or regulations. These changes could affect the business impact analysis, risk assessment, recovery objectives, recovery strategies, roles and responsibilities, or resources of the disaster recovery plan. If the plan is not updated to reflect these changes, it could become obsolete, incomplete, or inconsistent, and fail to meet the organization's recovery needs or expectations.
The other three options are not as important as reviewing and updating the plan, although they may also contribute to the effectiveness of the disaster recovery planning process. Contracting with a third party for warm site services is a possible recovery strategy that involves using a partially equipped facility that can be quickly activated in case of a disaster. However, this strategy may not be suitable or sufficient for every organization or scenario, and it does not guarantee the success of the disaster recovery plan. Scheduling an annual tabletop exercise is a good practice that involves simulating a disaster scenario and testing the plan in a hypothetical setting. However, this exercise may not be enough to evaluate the feasibility or readiness of the plan, and it should be complemented by other types of tests, such as walkthroughs, drills, or full-scale exercises. Documenting and distributing a copy of the plan to all personnel is an essential step that ensures that everyone involved in or affected by the plan is aware of their roles and responsibilities, and has access to the relevant information and instructions. However, this step alone does not ensure that the plan is understood or followed by all personnel, and it should be accompanied by proper training, education, and awareness programs.
Therefore, reviewing and updating the plan annually or as changes occur is the best answer.
CISA-KR 문제 345
- 다른 버전
- 326ISACA.CISA-KR.v2026-08-15.q712
- 4327ISACA.CISA-KR.v2026-05-16.q709
- 1871ISACA.CISA-KR.v2026-05-06.q261
- 3347ISACA.CISA-KR.v2026-03-16.q665
- 4744ISACA.CISA-KR.v2026-03-07.q651
- 9446ISACA.CISA-KR.v2025-04-07.q633
- 3811ISACA.CISA-KR.v2025-04-02.q544
- 4317ISACA.CISA-KR.v2025-03-31.q534
- 5529ISACA.CISA-KR.v2025-03-28.q617
- 3314ISACA.CISA-KR.v2025-03-19.q581
- 4198ISACA.CISA-KR.v2025-03-03.q807
- 5246ISACA.CISA-KR.v2024-02-07.q421
- 2939ISACA.CISA-KR.v2024-01-31.q392
- 5441ISACA.CISA-KR.v2023-10-24.q329
- 5262ISACA.CISA-KR.v2023-07-31.q266
- 3260ISACA.CISA-KR.v2023-06-23.q324
- 최근 업로드
- 137Microsoft.AZ-305-KR.v2026-08-17.q162
- 152IIA.IAA-IAP-KR.v2026-08-17.q41
- 326ISACA.CISA-KR.v2026-08-15.q712
- 259Microsoft.MS-700-KR.v2026-08-15.q203
- 181Microsoft.AZ-305-KR.v2026-08-14.q177
- 255Microsoft.DP-900-KR.v2026-08-13.q130
- 322Microsoft.PL-600.v2026-08-11.q206
- 279Microsoft.DP-100.v2026-08-11.q160
- 211Oracle.1Z0-1048-25.v2026-08-11.q68
- 180ISQI.CTAL-TAE.v2026-08-11.q37
PDF 파일 다운로드
메일 주소를 입력하시고 다운로드 하세요. ISACA.CISA-KR.v2025-04-03.q628 모의시험 시험자료를 다운 받으세요.
