CISA-KR 문제 281
References:
Stress Testing Best Practices: A Seven Steps Model
CISA-KR 문제 282
CISA-KR 문제 283
User accounts are unique identifiers that grant access to an organization's financial business application based on the roles and responsibilities of the users. User accounts should be individualized and personalized to ensure accountability, traceability, and auditability of user actions and transactions. User accounts should not be shared between users, because this can compromise the confidentiality, integrity, and availability of the financial data and systems, and can enable unauthorized or fraudulent activities. If user accounts are shared between users, the IS auditor may not be able to determine who performed what action or transaction, or whether the user had the appropriate authorization or approval. The other findings are also concerning, but not as much as user account sharing, because they either affect the password strength or frequency rather than the useridentity, or they relate to monitoring rather than controlling user access. References: CISA Review Manual (Digital Version)1, Chapter 5, Section 5.2.2
CISA-KR 문제 284
Hardening is the process of applying security measures and configurations to reduce the vulnerabilities and risks of a system or device. Hardening for the hypervisor and guest machines is essential for protecting the virtualized environments from attacks, as they are exposed to various threats from both the physical and virtual layers. Hardening for the hypervisor and guest machines involves the following steps:
* Applying the latest patches and updates for the hypervisor and guest operating systems, as well as the applications and drivers running on them.
* Configuring the firewall and network settings for the hypervisor and guest machines, to restrict and monitor the network traffic and prevent unauthorized access or communication.
* Disabling or removing any unnecessary or unused features, services, accounts, or ports on the hypervisor and guest machines, to minimize the attack surface and reduce the potential entry points for attackers.
* Enforcing strong authentication and authorization policies for the hypervisor and guest machines, to ensure that only authorized users or administrators can access or manage them.
* Encrypting the data and communication for the hypervisor and guest machines, to protect the confidentiality and integrity of the information stored or transmitted on them.
* Implementing logging and auditing mechanisms for the hypervisor and guest machines, to record and track any activities or events that occur on them, and enable detection and investigation of any incidents or anomalies.
Hardening for the hypervisor and guest machines can help prevent or mitigate common attacks on virtualized environments, such as:
* Hypervisor escape: An attack where a malicious guest machine breaks out of its isolated environment and gains access to the hypervisor or other guest machines.
* Hypervisor compromise: An attack where an attacker exploits a vulnerability or misconfiguration in the hypervisor to gain control over it or its resources.
* Guest compromise: An attack where an attacker exploits a vulnerability or misconfiguration in a guest machine to gain access to its data or applications.
* Guest impersonation: An attack where an attacker creates a fake or cloned guest machine to trick other guests or users into interacting with it.
* Guest denial-of-service: An attack where an attacker consumes or exhausts the resources of a guest machine to disrupt its availability or performance.
Therefore, hardening for the hypervisor and guest machines is the most important control for virtualized environments, as it can enhance their security, reliability, and performance. For more information about hardening for virtualized environments, you can refer to some of these web sources:
* Hypervisor security on the Azure fleet
* Chapter 2: Hardening the Hyper-V host
* Plan for Hyper-V security in Windows Server
CISA-KR 문제 285
- 다른 버전
- 4060ISACA.CISA-KR.v2026-05-16.q709
- 1818ISACA.CISA-KR.v2026-05-06.q261
- 3146ISACA.CISA-KR.v2026-03-16.q665
- 4522ISACA.CISA-KR.v2026-03-07.q651
- 4465ISACA.CISA-KR.v2025-04-03.q628
- 3711ISACA.CISA-KR.v2025-04-02.q544
- 4243ISACA.CISA-KR.v2025-03-31.q534
- 5341ISACA.CISA-KR.v2025-03-28.q617
- 3175ISACA.CISA-KR.v2025-03-19.q581
- 4034ISACA.CISA-KR.v2025-03-03.q807
- 5181ISACA.CISA-KR.v2024-02-07.q421
- 2869ISACA.CISA-KR.v2024-01-31.q392
- 5332ISACA.CISA-KR.v2023-10-24.q329
- 5219ISACA.CISA-KR.v2023-07-31.q266
- 3192ISACA.CISA-KR.v2023-06-23.q324
- 최근 업로드
- 120Microsoft.AZ-305-KR.v2026-08-14.q177
- 162Microsoft.DP-900-KR.v2026-08-13.q130
- 266Microsoft.PL-600.v2026-08-11.q206
- 200Microsoft.DP-100.v2026-08-11.q160
- 179Oracle.1Z0-1048-25.v2026-08-11.q68
- 145ISQI.CTAL-TAE.v2026-08-11.q37
- 196ServiceNow.CIS-HR.v2026-08-11.q84
- 259Salesforce.Plat-Arch-201.v2026-08-10.q101
- 247Databricks.Databricks-Machine-Learning-Professional.v2026-08-10.q76
- 193F5.F5CAB2.v2026-08-10.q41
PDF 파일 다운로드
메일 주소를 입력하시고 다운로드 하세요. ISACA.CISA-KR.v2025-04-07.q633 모의시험 시험자료를 다운 받으세요.
