CISA-KR 문제 346
The information security manager is not the most important stakeholder because their role is mainly focused on ensuring the confidentiality, integrity, and availability of the information systems and data that support the expense claim process. The information security manager can help the IS auditor with assessing the technical aspects of the system, such as access controls, encryption, logging, and backup, but they may not have sufficient knowledge or authority over the business rules and policies that prevent fraud1.
The quality assurance (QA) manager is not the most important stakeholder because their role is mainly focused on ensuring the quality and reliability of the software applications and systems that support the expense claim process. The QA manager can help the IS auditor with testing and verifying the functionality and performanceof the system, but they may not have sufficient knowledge or authority over the business rules and policies that prevent fraud1.
The business department executive is not the most important stakeholder because their role is mainly focused on overseeing the strategic objectives and financial performance of the business department that uses the expense claim system. The business department executive can help the IS auditor with understanding the business context and needs of the expense claim process, but they may not have sufficient knowledge or authority over the operational details and controls that prevent fraud
CISA-KR 문제 347
Therefore, option B is the correct answer.
Option A is not correct because end user testing is not eliminated by acquiring a software package. Even though the software package may have been tested by the vendor or supplier, it may still have bugs, compatibility issues, or configuration problems that need to be fixed before deployment4. Option C is not correct because end user testing is not increased by acquiring a software package. The scope and extent of end user testing depend on various factors, such as the complexity, criticality, and customization of the system, and not on whether it is developed in-house or acquired. Option D is not correct because end user testing is not reduced by acquiring a software package. The software package may still require modifications or integrations to suit the specific needs and environment of the organization, and these changes need to be tested by the end users.
References:
Chapter 4 Methods of Software Acquisition5
What is User Acceptance Testing (UAT): A Complete Guide1
What Is End-to-End Testing? (With How-To and Example)3
How to Evaluate New Software in 5 Steps4
User Acceptance Testing (UAT) in ERP Projects
User Acceptance Testing for Packaged Software
CISA-KR 문제 348
A threat assessment should not exclude any potential threats based on subjective judgments or assumptions, as they may still have a high impact if they materialize.
The exercise was completed by local management is not a cause for concern, as it shows that the threat assessment is conducted by the people who are most familiar with the data center's operations, environment, and risks. Local management may have more relevant and accurate information and insights than external parties, and may be more invested in the outcome of the threat assessment.
Neighboring organizations' operations have been included is not a cause for concern, as it shows that the threat assessment is holistic and contextual, and considers the interdependencies and influences of external factors on the data center's security. Neighboring organizations' operations may pose direct or indirect threats to the data center, such as physical damage, network interference, or shared vulnerabilities.
References:
* IBM Security Services 2016 Cyber Security Intelligence Index 1
CISA-KR 문제 349
CISA-KR 문제 350
4, Section 4.2.21
- 다른 버전
- 326ISACA.CISA-KR.v2026-08-15.q712
- 4327ISACA.CISA-KR.v2026-05-16.q709
- 1871ISACA.CISA-KR.v2026-05-06.q261
- 3347ISACA.CISA-KR.v2026-03-16.q665
- 4744ISACA.CISA-KR.v2026-03-07.q651
- 9446ISACA.CISA-KR.v2025-04-07.q633
- 3811ISACA.CISA-KR.v2025-04-02.q544
- 4317ISACA.CISA-KR.v2025-03-31.q534
- 5529ISACA.CISA-KR.v2025-03-28.q617
- 3314ISACA.CISA-KR.v2025-03-19.q581
- 4198ISACA.CISA-KR.v2025-03-03.q807
- 5246ISACA.CISA-KR.v2024-02-07.q421
- 2939ISACA.CISA-KR.v2024-01-31.q392
- 5441ISACA.CISA-KR.v2023-10-24.q329
- 5262ISACA.CISA-KR.v2023-07-31.q266
- 3260ISACA.CISA-KR.v2023-06-23.q324
- 최근 업로드
- 137Microsoft.AZ-305-KR.v2026-08-17.q162
- 152IIA.IAA-IAP-KR.v2026-08-17.q41
- 326ISACA.CISA-KR.v2026-08-15.q712
- 259Microsoft.MS-700-KR.v2026-08-15.q203
- 181Microsoft.AZ-305-KR.v2026-08-14.q177
- 255Microsoft.DP-900-KR.v2026-08-13.q130
- 322Microsoft.PL-600.v2026-08-11.q206
- 279Microsoft.DP-100.v2026-08-11.q160
- 211Oracle.1Z0-1048-25.v2026-08-11.q68
- 180ISQI.CTAL-TAE.v2026-08-11.q37
PDF 파일 다운로드
메일 주소를 입력하시고 다운로드 하세요. ISACA.CISA-KR.v2025-04-03.q628 모의시험 시험자료를 다운 받으세요.
