CISA-KR 문제 276
Option B is not correct because identifying approved data workflows across the enterprise is a subsequent step after conducting data inventory and classification. Data workflows are the processes and channels through which data are created, stored, accessed, shared, or transmitted within or outside the organization4. Identifying approved data workflows helps to define the normal and legitimate use of data, as well as to detect and prevent unauthorized or anomalous data activities5. However, before identifying approved data workflows, the organization needs to know what data it has and how it should be classified.
Option C is not correct because conducting a threat analysis against sensitive data usage is another subsequent step after conducting data inventory and classification. Threat analysis is the process of identifying and assessing the potential sources, methods, and impacts of data loss or leakage incidents. Threat analysis helps to design and implement effective DLP controls and countermeasures based on the risk profile of each data category. However, before conducting threat analysis, the organization needs to know what data it has and how it should be classified.
Option D is not correct because creating the DLP policies and templates is the final step after conducting data inventory and classification, identifying approved data workflows, and conducting threat analysis. DLP policies and templates are the rules and configurations that specify how the DLP solution should monitor, detect, report, and respond to data loss or leakage events. DLP policies and templates should be aligned with the organization's business needs, regulatory obligations, and risk appetite. However, before creating the DLP policies and templates, the organization needs to know what data it has, how it should be classified, how it should be used, and what threats it faces.
References:
Data Inventory & Classification: The First Step in Data Protection1
Data Classification: What It Is And Why You Need It2
How to Prioritize Your Data Loss Prevention Strategy in 20203
What Is Data Workflow? Definition & Examples4
How to Identify Data Workflows for Your Business5
Threat Analysis: A Comprehensive Guide for Beginners
How to Conduct a Threat Assessment for Your Business
What Is Data Loss Prevention (DLP)? Definition & Examples
How to Create Effective Data Loss Prevention Policies
CISA-KR 문제 277
RAID (redundant array of independent disks) is a technology that combines multiple disks into a logical unit that can tolerate disk failures and improve data access speed. Configuring each authentication server and ensuring that the disks of each server form part of a duplex does not address the issue of performance degradation, but rather the issue of data backup and recovery. A duplex is a pair of disks that store identical copies of data, so that if one disk fails, the other disk can be used to restore the data. References: ISACA CISA Review Manual 27th Edition, page 310
CISA-KR 문제 278
References
ISACA CISA Review Manual, 27th Edition, page 255
What is an incident response plan? And why do you need one?
ISACA CISA Certified Information Systems Auditor Exam ... - PUPUWEB
CISA-KR 문제 279
CISA-KR 문제 280
This approach would involve the following steps:
Extract the data of new account applications from the source system, such as a database or a web service, using appropriate tools and methods.
Transform and clean the data to ensure its accuracy, completeness, consistency, and validity, using techniques such as data profiling, data cleansing, data mapping, and data validation2.
Analyze the data to identify any anomalies, errors, or outliers in the date of birth field, using methods such as descriptive statistics, exploratory data analysis, hypothesis testing, or anomaly detection3.
Visualize the data to present the findings and insights in a clear and understandable way, using tools and techniques such as charts, graphs, dashboards, or reports.
By reviewing new account applications submitted in the past month for invalid dates of birth, the tester can use data analytics to:
Verify if the new account creation process is working as expected and meets the business requirements and specifications for the date of birth field.
Detect any defects or issues in the new account creation process that may cause invalid dates of birth to be accepted or rejected incorrectly.
Measure and monitor the performance and reliability of the new account creation process in terms of data quality, accuracy, and completeness.
Evaluate and improve the test coverage and effectiveness of the new account creation process by identifying any gaps or risks in the test cases or scenarios.
Therefore, option C is the correct answer.
Option A is not correct because attempting to submit new account applications with invalid dates of birth is not a data analytics approach, but a functional testing approach that involves executing test cases or scenarios manually or automatically to validate the behavior and functionality of the new account creation process.
Option B is not correct because reviewing the business requirements document for date of birth field requirements is not a data analytics approach, but a requirements analysis approach that involves examining and understanding the needs and expectations of the stakeholders for the new account creation process.
Option D is not correct because evaluating configuration settings for date of birth field requirements is not a data analytics approach, but a configuration testing approach that involves verifying if the settings and parameters of the new account creation process are correct and consistent with the requirements.
References:
What is Data Analytics? Definition & Examples1
Data Transformation: Definition & Examples2
Data Analysis: Definition & Examples3
Data Visualization: Definition & Examples
Functional Testing: Definition & Examples
Requirements Analysis: Definition & Examples
Configuration Testing: Definition & Examples
- 다른 버전
- 4060ISACA.CISA-KR.v2026-05-16.q709
- 1818ISACA.CISA-KR.v2026-05-06.q261
- 3146ISACA.CISA-KR.v2026-03-16.q665
- 4522ISACA.CISA-KR.v2026-03-07.q651
- 4465ISACA.CISA-KR.v2025-04-03.q628
- 3711ISACA.CISA-KR.v2025-04-02.q544
- 4243ISACA.CISA-KR.v2025-03-31.q534
- 5339ISACA.CISA-KR.v2025-03-28.q617
- 3175ISACA.CISA-KR.v2025-03-19.q581
- 4033ISACA.CISA-KR.v2025-03-03.q807
- 5173ISACA.CISA-KR.v2024-02-07.q421
- 2869ISACA.CISA-KR.v2024-01-31.q392
- 5327ISACA.CISA-KR.v2023-10-24.q329
- 5219ISACA.CISA-KR.v2023-07-31.q266
- 3173ISACA.CISA-KR.v2023-06-23.q324
- 최근 업로드
- 120Microsoft.AZ-305-KR.v2026-08-14.q177
- 162Microsoft.DP-900-KR.v2026-08-13.q130
- 266Microsoft.PL-600.v2026-08-11.q206
- 200Microsoft.DP-100.v2026-08-11.q160
- 179Oracle.1Z0-1048-25.v2026-08-11.q68
- 145ISQI.CTAL-TAE.v2026-08-11.q37
- 196ServiceNow.CIS-HR.v2026-08-11.q84
- 259Salesforce.Plat-Arch-201.v2026-08-10.q101
- 247Databricks.Databricks-Machine-Learning-Professional.v2026-08-10.q76
- 193F5.F5CAB2.v2026-08-10.q41
PDF 파일 다운로드
메일 주소를 입력하시고 다운로드 하세요. ISACA.CISA-KR.v2025-04-07.q633 모의시험 시험자료를 다운 받으세요.
