CISA-KR 문제 196
For online payment security, bothconfidentiality(protection of data) andnonrepudiation(ensuring the sender cannot deny a transaction) are essential.
* Option A (Incorrect):DES is outdatedandinsecurefor modern encryption needs. It has been replaced by stronger algorithms.
* Option B (Incorrect):AES provides strong encryption(confidentiality) but does not handle nonrepudiationon its own.
* Option C (Correct):PKI (Public Key Infrastructure)is the best solution because it provides encryption for confidentialityanddigital signatures for nonrepudiation, ensuring bothsecure transactions andauthenticationof parties involved.
* Option D (Incorrect):AVPN secures network traffic, but it does not address nonrepudiation, which is critical in online payments.
Reference:ISACA CISA Review Manual -Domain 5: Protection of Information Assets- Covers encryption, PKI, and secure payment processing.
CISA-KR 문제 197
Documentation of the service provider's security configuration controls is a source of evidence that a third- party service provider's information security controls are effective, but it is not the best evidence.
Documentation of the security configuration controls can show the settings and parameters of the service provider's information systems and networks, but it may not reflect the actual implementation and operation of the controls. Documentation of the security configuration controls may also be outdated, incomplete, or in accurate.
An interview with the service provider's information security officer is a source of evidence that a third-party service provider's information security controls are effective, but it is not the best evidence. An interview with the information security officer can provide insights into the service provider's information security strategy, policies, and procedures, but it may not verify the actual performance and compliance of the information security controls. An interview with the information security officer may also be biased, subjective, or misleading.
A review of the service provider's policies and procedures is a source of evidence that a third-party service provider's information security controls are effective, but it is not the best evidence. A review of the policies and procedures can show the service provider's information security objectives, requirements, and guidelines, but it may not demonstrate the actual execution and enforcement of the information security controls. A review of the policies and procedures may also be insufficient, inconsistent, or outdated.
References:
* ISACA, CISA Review Manual, 27th Edition, 2019, p. 284
* ISACA, CISA Review Questions, Answers & Explanations Database - 12 Month Subscription
CISA-KR 문제 198
CISA-KR 문제 199
Conducting vulnerability assessmentsonly once per year, right before an audit,creates a false sense of securityandleaves systems exposedbetween assessments.
* Annual Testing Before Audit (Correct Answer - A)
* Risksundetected vulnerabilitiesfor extended periods.
* Example:A company only tests security before acompliance audit, allowingzero-day threatsto persist for months.
* Internal Team Conducting Assessments (Incorrect - B)
* Not ideal, butregular assessmentsare more critical.
* Focusing on Critical Systems (Incorrect - C)
* Not perfect, butbetter than no testing at all.
* Using Open-Source Tools (Incorrect - D)
* Open-source toolscan be effective ifproperly configured.
References:
* ISACA CISA Review Manual
* NIST 800-115 (Technical Guide to Security Testing)
CISA-KR 문제 200
Option C is correct because validation checks are a common and effective method of ensuring data integrity for a system interface. Validation checks can be performed at various stages of the data lifecycle, such as input, processing, output, or storage. Validation checks can also be applied to different types of data, such as data types, codes, ranges, formats, consistency, and uniqueness.
Option A is incorrect because system interface testing is a type of software testing that verifies the interaction between two separate systems or components of a system. System interface testing does not directly ensure the integrity of data for a system interface, but rather the functionality and reliability of the interface itself.
System interface testing may use validation checks as part of its test cases, but it is not the same as validation checks.
Option B is incorrect because user acceptance testing (UAT) is a type of software testing that evaluates whether the system meets the user's expectations and requirements. UAT does not directly ensure the integrity of data for a system interface, but rather the usability and acceptability of the system from the user's perspective. UAT may use validation checks as part of its test scenarios, but it is not the same as validation checks.
Option D is incorrect because audit logs are records of events and activities that occur within a system or network. Audit logs do not directly ensure the integrity of data for a system interface, but rather provide evidence and accountability for the system's operations and security. Audit logs may use validation checks as part of their analysis or reporting, but they are not the same as validation checks.
References:
CISA Online Review Course1, Module 5: Protection of Information Assets, Lesson 4: Data Quality Management, slide 5-6.
CISA Review Manual (Digital Version)2, Chapter 5: Protection of Information Assets, Section 5.3: Data Quality Management, p. 281-282.
CISA Review Manual (Print Version), Chapter 5: Protection of Information Assets, Section 5.3: Data Quality Management, p. 281-282.
CISA Questions, Answers & Explanations Database3, Question ID: QAE_CISA_722.
Data Validation - Overview, Types, Practical Examples4
Data Validity: The Best Practice for Your Business5
Validation - Data validation6
What is Data Validation? Types, Techniques, Tools7
- 다른 버전
- 4019ISACA.CISA-KR.v2026-05-16.q709
- 1812ISACA.CISA-KR.v2026-05-06.q261
- 3124ISACA.CISA-KR.v2026-03-16.q665
- 4490ISACA.CISA-KR.v2026-03-07.q651
- 4453ISACA.CISA-KR.v2025-04-03.q628
- 3700ISACA.CISA-KR.v2025-04-02.q544
- 4223ISACA.CISA-KR.v2025-03-31.q534
- 5321ISACA.CISA-KR.v2025-03-28.q617
- 3152ISACA.CISA-KR.v2025-03-19.q581
- 4006ISACA.CISA-KR.v2025-03-03.q807
- 5135ISACA.CISA-KR.v2024-02-07.q421
- 2868ISACA.CISA-KR.v2024-01-31.q392
- 5295ISACA.CISA-KR.v2023-10-24.q329
- 5215ISACA.CISA-KR.v2023-07-31.q266
- 3144ISACA.CISA-KR.v2023-06-23.q324
- 최근 업로드
- 119Microsoft.AZ-305-KR.v2026-08-14.q177
- 161Microsoft.DP-900-KR.v2026-08-13.q130
- 262Microsoft.PL-600.v2026-08-11.q206
- 200Microsoft.DP-100.v2026-08-11.q160
- 177Oracle.1Z0-1048-25.v2026-08-11.q68
- 145ISQI.CTAL-TAE.v2026-08-11.q37
- 195ServiceNow.CIS-HR.v2026-08-11.q84
- 259Salesforce.Plat-Arch-201.v2026-08-10.q101
- 247Databricks.Databricks-Machine-Learning-Professional.v2026-08-10.q76
- 192F5.F5CAB2.v2026-08-10.q41
PDF 파일 다운로드
메일 주소를 입력하시고 다운로드 하세요. ISACA.CISA-KR.v2025-04-07.q633 모의시험 시험자료를 다운 받으세요.
