CISA-KR 문제 496
다음 중 가장 중요하다고 여겨지는 결과는 무엇입니까?
The other findings are not as critical as the failure to identify the security weakness, but they are still important issues that should be addressed by the organization. The attack was not automatically blocked by the intrusion detection system (IDS) is a finding that suggests that the IDS was not configured properly, or that it did not have the latest signatures or rules to detect and prevent the attack. The attack could not be traced back to the originating person is a finding that implies that the organization did not have sufficient logging, monitoring, or forensic capabilities to identify and attribute the attacker. Appropriate response documentation was not maintained is a finding that indicates that the organization did not follow a consistent and formal incident response procedure, or that it did not document its actions, decisions, and lessons learned from the incident.
References:
* ISACA CISA Review Manual 27th Edition (2019), page 254
* Incident Response Process - ISACA1
* Incident Response: How to Identify and Fix Security Weaknesses
CISA-KR 문제 497
CISA-KR 문제 498
Continuous auditing of access controls can help detect and prevent unauthorized access, data leakage, data manipulation, or data loss that could compromise the security, reliability, or compliance of the real-time data systems.
Testing encryption standards on the disaster recovery system is not the best process for continuous auditing for a large financial institution. Encryption standards are important for protecting the data stored or transmitted by the disaster recovery system, which is a system that provides backup and recovery capabilities in case of a disruption or disaster. However, testing encryption standards is not a continuous process, but rather a periodic or event-driven process that can be performed as part of the disaster recovery plan testing or validation.
Performing parallel testing between systems is not the best process for continuous auditing for a large financial institution. Parallel testing is a process of comparing the results of two or more systems that perform the same function or task, such as a new system and an old system, or a primary system and a backup system.
Parallel testing can help verify the accuracy, consistency, and compatibility of the systems. However, parallel testing is not a continuous process, but rather a temporary or transitional process that can be performed as part of the system implementation or migration.
Validating performance of help desk metrics is not the best process for continuous auditing for a large financial institution. Help desk metrics are indicators that measure the efficiency, effectiveness, and quality of the help desk service, which is a service that provides technical support and assistance to the users of information systems and technology. Help desk metrics can include metrics such as response time, resolution time, customer satisfaction, and service level agreement (SLA) compliance. Validating performance of help desk metrics can help evaluate and improve the help desk service. However, validating performance of help desk metrics is not a continuous auditing process, but rather a continuous monitoring process that can be performed by the help desk management or quality assurance team.
References:
* All eyes on: Continuous auditing - KPMG Global 1
* Internal audit's role at financial institutions: PwC 2
* The Fed - Supervisory Policy and Guidance Topics - Large Banking ... 3
* Continuous Audit: Definition, Steps, Advantages and Disadvantages 4
CISA-KR 문제 499
The other options are not required to be in place before an IS auditor initiates audit follow-up activities:
* Available resources for the activities included in the action plan. This is a factor that may affect the feasibility and success of the action plan, but it is not a prerequisite for the audit follow-up activities.
The IS auditor should assess the availability and adequacy of the resources for the action plan during the audit planning and execution phases, and provide recommendations accordingly. However, the IS auditor does not need to wait for the resources to be available before initiating the audit follow-up activities.
* A heat map with the gaps and recommendations displayed in terms of risk. This is a tool that may help the IS auditor prioritize and communicate the gaps and recommendations, but it is not a requirement for the audit follow-up activities. A heat map is a graphical representation of data that uses colors to indicate the level of risk or impact of each gap or recommendation. The IS auditor may use a heat map to support the audit report or presentation, but it does not replace the need for a management response with a committed implementation date.
* Supporting evidence for the gaps and recommendations mentioned in the audit report. This is a component that should be included in the audit report, but it is not a condition for the audit follow-up activities. Supporting evidence is the information or data that supports or substantiates the audit findings and recommendations. The IS auditor should collect and document sufficient, reliable, relevant, and useful evidence during the audit execution phase, and present it in the audit report.
However, the IS auditor does not need to have supporting evidence in place before initiating the audit follow-up activities.
CISA-KR 문제 500
* Stakeholder Communications (Option B):This is typically managed internally by the organization to ensure alignment with its crisis management plan.
* Validation of Recovered Data (Option C):The organization must verify data integrity to meet business requirements.
* Maintaining Currency of Data (Option D):While DRaaS may handle data backups, the organization retains responsibility for ensuring the relevance of the data being backed up.
Reference:ISACA CISA Review Manual, Job Practice Area 4: Protection of Information Assets.
- 다른 버전
- 243ISACA.CISA-KR.v2026-08-15.q712
- 4255ISACA.CISA-KR.v2026-05-16.q709
- 1833ISACA.CISA-KR.v2026-05-06.q261
- 3203ISACA.CISA-KR.v2026-03-16.q665
- 4695ISACA.CISA-KR.v2026-03-07.q651
- 4499ISACA.CISA-KR.v2025-04-03.q628
- 3792ISACA.CISA-KR.v2025-04-02.q544
- 4295ISACA.CISA-KR.v2025-03-31.q534
- 5446ISACA.CISA-KR.v2025-03-28.q617
- 3279ISACA.CISA-KR.v2025-03-19.q581
- 4119ISACA.CISA-KR.v2025-03-03.q807
- 5235ISACA.CISA-KR.v2024-02-07.q421
- 2904ISACA.CISA-KR.v2024-01-31.q392
- 5412ISACA.CISA-KR.v2023-10-24.q329
- 5244ISACA.CISA-KR.v2023-07-31.q266
- 3244ISACA.CISA-KR.v2023-06-23.q324
- 최근 업로드
- 243ISACA.CISA-KR.v2026-08-15.q712
- 181Microsoft.MS-700-KR.v2026-08-15.q203
- 134Microsoft.AZ-305-KR.v2026-08-14.q177
- 205Microsoft.DP-900-KR.v2026-08-13.q130
- 290Microsoft.PL-600.v2026-08-11.q206
- 227Microsoft.DP-100.v2026-08-11.q160
- 190Oracle.1Z0-1048-25.v2026-08-11.q68
- 160ISQI.CTAL-TAE.v2026-08-11.q37
- 202ServiceNow.CIS-HR.v2026-08-11.q84
- 283Salesforce.Plat-Arch-201.v2026-08-10.q101
PDF 파일 다운로드
메일 주소를 입력하시고 다운로드 하세요. ISACA.CISA-KR.v2025-04-07.q633 모의시험 시험자료를 다운 받으세요.
