CISA-KR 문제 471
Ensuring the open issues are retained in the audit results is a course of action for an IS auditor when an auditee is unable to close all audit recommendations by the time of the follow-up audit, but it is not the best one. Ensuring the open issues are retained in the audit results can help the IS auditor document and report the status and progress of the audit recommendations, as well as provide a basis for future follow-up audits.
However, ensuring the open issues are retained in the audit results does not provide an analysis or evaluation of the residual risk due to open issues, which is more important for informing decision-making and action- taking.
Terminating the follow-up because open issues are not resolved is not a course of action for an IS auditor when an auditee is unable to close all audit recommendations by the time of the follow-up audit, but rather a consequence or outcome of it. Terminating the follow-up because open issues are not resolved may indicate that the auditee has failed to comply with the agreed-upon actions or deadlines, or that the IS auditor has encountered significant obstacles or resistance from the auditee. Terminating the follow-up because open issues are not resolved may also trigger further actions or sanctions from the IS auditor or other authorities, such as issuing a qualified or adverse opinion, withholding certification, or imposing penalties.
Recommending compensating controls for open issues is not a course of action for an IS auditor when an auditee is unable to close all audit recommendations by the time of the follow-up audit, but rather a possible outcome or result of it. Compensating controls are alternative or additional controls that are implemented to reduce or eliminate the risk associated with a weakness or deficiency in another control. Recommending compensating controls for open issues may be appropriate when the auditee is unable to implement the original audit recommendations due to technical, operational, financial, or other constraints, and when the compensating controls can provide a similar or equivalent level of assurance. However, recommending compensating controls for open issues requires a prior evaluation of the residual risk due to open issues, which is more important for determining whether compensating controls are necessary and feasible.
References:
* Follow-up Audits - Canadian Audit and Accountability Foundation 1
* Conducting The Audit Follow-Up: When To Verify - The Auditor 2
* Internal Audit Follow Ups: Are They Really Worth The Effort
CISA-KR 문제 472
CISA-KR 문제 473
A circuit gateway is a type of firewall that operates at the transport layer of the network model (layer 4), which is where data are transferred between end points over the network. A circuit gateway provides a moderate degree of control against hacker intrusion by establishing a secure connection between two end points (such as client and server) and relaying network packets between them without inspecting or analyzing their content. A circuit gateway can also perform functions such as encryption, authentication, or address translation to improve the security and privacy of network traffic. A packet filtering router is a type of firewall that operates at the network layer of the network model (layer 3), which is where data are routed between different networks or subnets. A packet filtering router provides a low degree of control against hacker intrusion by examining the header of each network packet and allowing or denying access based on basic criteria such as source address, destination address, port number, protocol, etc. A packet filtering router can also perform functions such as routing, forwarding, or address translation to optimize the delivery and efficiency of network traffic. A screening router is a type of firewall that operates at the network layer of the network model (layer 3), which is where data are routed between different networks or subnets. A screening router provides a low degree of control against hacker intrusion by examining the header of each network packet and allowing or denying access based on basic criteria such as source address, destination address, port number, protocol, etc. A screening router can also perform functions such as routing, forwarding, or address translation to optimize the delivery and efficiency of network traffic.
CISA-KR 문제 474
CISA-KR 문제 475
Nodes are devices or systems that are connected to the network and can communicate with each other. Nodes can include servers, workstations, routers, switches, firewalls, printers, scanners, cameras, etc. Identifying the existing nodes on the network will help the auditor to determine the scope, objectives, and methodology of the audit. It will also help the auditor to assess the network topology, architecture, performance, security, and compliance. References:
* CISA Review Manual (Digital Version)
* CISA Questions, Answers & Explanations Database
- 다른 버전
- 328ISACA.CISA-KR.v2026-08-15.q712
- 4351ISACA.CISA-KR.v2026-05-16.q709
- 1874ISACA.CISA-KR.v2026-05-06.q261
- 3349ISACA.CISA-KR.v2026-03-16.q665
- 4747ISACA.CISA-KR.v2026-03-07.q651
- 9450ISACA.CISA-KR.v2025-04-07.q633
- 3811ISACA.CISA-KR.v2025-04-02.q544
- 4318ISACA.CISA-KR.v2025-03-31.q534
- 5531ISACA.CISA-KR.v2025-03-28.q617
- 3316ISACA.CISA-KR.v2025-03-19.q581
- 4200ISACA.CISA-KR.v2025-03-03.q807
- 5247ISACA.CISA-KR.v2024-02-07.q421
- 2941ISACA.CISA-KR.v2024-01-31.q392
- 5443ISACA.CISA-KR.v2023-10-24.q329
- 5263ISACA.CISA-KR.v2023-07-31.q266
- 3262ISACA.CISA-KR.v2023-06-23.q324
- 최근 업로드
- 166Microsoft.AZ-305-KR.v2026-08-17.q162
- 154IIA.IAA-IAP-KR.v2026-08-17.q41
- 328ISACA.CISA-KR.v2026-08-15.q712
- 261Microsoft.MS-700-KR.v2026-08-15.q203
- 192Microsoft.AZ-305-KR.v2026-08-14.q177
- 261Microsoft.DP-900-KR.v2026-08-13.q130
- 322Microsoft.PL-600.v2026-08-11.q206
- 288Microsoft.DP-100.v2026-08-11.q160
- 213Oracle.1Z0-1048-25.v2026-08-11.q68
- 182ISQI.CTAL-TAE.v2026-08-11.q37
PDF 파일 다운로드
메일 주소를 입력하시고 다운로드 하세요. ISACA.CISA-KR.v2025-04-03.q628 모의시험 시험자료를 다운 받으세요.
