CISA-KR 문제 406
One of the aspects that an IS auditor should review when evaluating information systems governance for a large organization is the approval processes for new system implementations. This is because new system implementations are significant IT investments that require careful planning, analysis, design, development, testing, deployment, and evaluation to ensure that they meet the business requirements, deliver the expected benefits, comply with the relevant standards and regulations, and minimize the potential risks2. The approval processes for new system implementations should involve the appropriate stakeholders, such as senior management, business owners, IT managers, project managers, users, and auditors, who have the authority and responsibility to approve or reject the proposed system implementations based on predefined criteria and metrics3. The approval processes for new system implementations should also be documented, transparent, consistent, and timely to ensure accountability and traceability4. Therefore, an IS auditor should review the approval processes for new system implementations to assess whether they are aligned with the information systems governance framework and objectives.
The other possible options are:
* Procedures for adding a new user to the invoice processing system: This is an operational task that involves granting access rights and permissions to a specific user for a specific system based on the principle of least privilege. This is not a strategic or high-level function that falls under information systems governance. Therefore, an IS auditor should not review this aspect when evaluating information systems governance for a large organization.
* Approval processes for updating the corporate website: This is a tactical task that involves making changes or enhancements to the content or design of the corporate website based on the business needs and feedback. This is not a strategic or high-level function that falls under information systems governance. Therefore, an IS auditor should not review this aspect when evaluating information systems governance for a large organization.
* Procedures for regression testing system changes: This is a technical task that involves verifying that existing system functionalities are not adversely affected by new system changes or updates. This is not a strategic or high-level function that falls under information systems governance. Therefore, an IS auditor should not review this aspect when evaluating information systems governance for a large organization. References: 1: What is IT Governance? - Definition from Techopedia 2: System Implementation - an overview | ScienceDirect Topics 3: Project Approval Process - Project Management Knowledge 4: 5 Best Practices For A Successful Project Approval Process | Kissflow Project : Principle of Least Privilege (POLP) | Imperva : How to Update Your Website Content - 7 Step Guide | HostGator Blog : What Is Regression Testing? Definition & Best Practices | BrowserStack
CISA-KR 문제 407
The other options are not as important as the business objectives, because they do not directly reflect the organization's purpose and direction. IT steering committee minutes are records of the discussions and decisions made by a group of senior executives who oversee the IT strategy and governance of the organization. They may provide some insights into the information security policy, but they are not sufficientto evaluate its adequacy3. Alignment with the IT tactical plan is a measure of how well the information security policy supports the short-term actions and projects that implement the IT strategy. However, the IT tactical plan itself shouldbe aligned with the business objectives, and not vice versa4. Compliance with industry best practice is a desirable quality of an information security policy, but it is not a guarantee of its effectiveness or suitability for the organization. Industry best practices are general guidelines or recommendations that may not apply to every organization or situation. An information security policy should be customized and tailored to the specific context and needs of the organization. References:
* The 12 Elements of an Information Security Policy | Exabeam1
* 11 Key Elements of an Information Security Policy | Egnyte2
* What is an IT steering committee? Definition, roles & responsibilities ...3
* What is IT Strategy? Definition, Components & Best Practices | BMC ...4
* IT Security Policy: Key Components & Best Practices for Every Business
CISA-KR 문제 408
Biometrics (option A) is a method of verifying the identity of a person based on their physical or behavioral characteristics, such as fingerprints, iris scans, or voice recognition. Biometrics can provide a high level of security, but they are not sufficient to prevent piggybacking or tailgating, as an unauthorized person can still follow an authorized person who has been authenticated by the biometric system.
Procedures for escorting visitors (option B) is a policy that requires all visitors to the data center to be accompanied by an authorized employee at all times. This can help prevent unauthorized access by visitors, but it does not address the risk of piggybacking or tailgating by other employees or contractors who may have legitimate access to the building but not to the data center.
Intruder alarms (option D) are devices that detect and alert when an unauthorized person enters a restricted area. Intruder alarms can provide a deterrent and a response mechanism for unauthorized access, but they are not effective in preventing piggybacking or tailgating, as they rely on the detection of the intruder after they have already entered the data center.
References: 1: CISA Certification | Certified Information Systems Auditor | ISACA 2: CISA Certified Information Systems Auditor Study Guide, 4th Edition 3: CISA - Certified Information Systems Auditor Study Guide [Book]
CISA-KR 문제 409
The greatest risk when relying on reports generated by EUC is that the data may be inaccurate. Data accuracy refers to the extent to which the data in the reports reflect the true values of the underlying information4.
Inaccurate data can lead to erroneous decisions, misleading analysis, unreliable reporting, and compliance violations. Some of the factors that can cause data inaccuracy in EUC reports are:
Lack of rigorous testing: EUC tools may not undergo the same level of testing and validation as IT-developed applications, which can result in errors, bugs, or inconsistencies in the data processing and output3.
Lack of version and change control: EUC tools may not have a clear record of the changes made to them over time, which can create confusion, duplication, or loss of data. Users may also modify or overwrite the data without proper authorization or documentation3.
Lack of documentation and reliance on end-user who developed it: EUC tools may not have sufficient documentation to explain their purpose, functionality, assumptions, limitations, and dependencies. Users may also rely on the knowledge and expertise of the original developer, who may not be available or may not have followed best practices3.
Lack of maintenance processes: EUC tools may not have regular updates, backups, or reviews to ensure their functionality and security. Users may also neglect to delete or archive obsolete or redundant data3.
Lack of security: EUC tools may not have adequate access controls, encryption, or authentication mechanisms to protect the data from unauthorized access, modification, or disclosure. Users may also store or share the data in insecure locations or devices3.
Lack of audit trail: EUC tools may not have a traceable history of the data sources, inputs, outputs, calculations, and transformations. Users may also manipulate or falsify the data without detection or accountability3.
Overreliance on manual controls: EUC tools may depend on human intervention to input, verify, or correct the data, which can introduce errors, delays, or biases. Users may also lack the skills or training to use the EUC tools effectively and efficiently3.
The other options are not as great as data inaccuracy when relying on EUC reports. Reports may not work efficiently, reports may not be timely, and historical data may not be available are all potential risks associated with EUC tools, but they are less severe and less frequent than data inaccuracy. Moreover, these risks can be mitigated by improving the performance, scheduling, and storage of the EUC tools. However, data inaccuracy can have a pervasive and lasting impact on the quality and credibility of the reports and the decisions based on them. Therefore, option A is the correct answer.
References:
What is Data Accuracy?
What Is End User Computing (EUC) Risk?
End-user computing
End-User Computing (EUC) Risks: A Comprehensive Guide
CISA-KR 문제 410
Thebiggest concernwhen implementing aglobal data privacy policyis thatlocal regulations may contradictthe global policy, leading tolegal and compliance risks.
* Local Regulations May Contradict the Policy (Correct Answer - B)
* Different countries havevarying data privacy laws(e.g.,GDPR in Europe,CCPA in California, PDPA in Singapore).
* A global policy mayconflict with stricter local laws, making compliancechallenging.
* Example:GDPR requiresexplicit consentfor data processing, but other jurisdictions may allowimplied consent.
* Requirements May Become Unreasonable (Incorrect - A)
* Not a primary risk; compliance is more critical.
* Conflicts with Application Requirements (Incorrect - C)
* Applications shouldadapt to regulations, not the other way around.
* Local Management Resistance (Incorrect - D)
* Management acceptance is important but can beaddressed through training.
References:
* ISACA CISA Review Manual
* GDPR (General Data Protection Regulation)
* ISO 27701 (Privacy Information Management System)
- 다른 버전
- 239ISACA.CISA-KR.v2026-08-15.q712
- 4249ISACA.CISA-KR.v2026-05-16.q709
- 1832ISACA.CISA-KR.v2026-05-06.q261
- 3201ISACA.CISA-KR.v2026-03-16.q665
- 4691ISACA.CISA-KR.v2026-03-07.q651
- 4499ISACA.CISA-KR.v2025-04-03.q628
- 3792ISACA.CISA-KR.v2025-04-02.q544
- 4293ISACA.CISA-KR.v2025-03-31.q534
- 5446ISACA.CISA-KR.v2025-03-28.q617
- 3273ISACA.CISA-KR.v2025-03-19.q581
- 4100ISACA.CISA-KR.v2025-03-03.q807
- 5235ISACA.CISA-KR.v2024-02-07.q421
- 2903ISACA.CISA-KR.v2024-01-31.q392
- 5412ISACA.CISA-KR.v2023-10-24.q329
- 5244ISACA.CISA-KR.v2023-07-31.q266
- 3244ISACA.CISA-KR.v2023-06-23.q324
- 최근 업로드
- 239ISACA.CISA-KR.v2026-08-15.q712
- 181Microsoft.MS-700-KR.v2026-08-15.q203
- 134Microsoft.AZ-305-KR.v2026-08-14.q177
- 203Microsoft.DP-900-KR.v2026-08-13.q130
- 290Microsoft.PL-600.v2026-08-11.q206
- 225Microsoft.DP-100.v2026-08-11.q160
- 189Oracle.1Z0-1048-25.v2026-08-11.q68
- 160ISQI.CTAL-TAE.v2026-08-11.q37
- 202ServiceNow.CIS-HR.v2026-08-11.q84
- 282Salesforce.Plat-Arch-201.v2026-08-10.q101
PDF 파일 다운로드
메일 주소를 입력하시고 다운로드 하세요. ISACA.CISA-KR.v2025-04-07.q633 모의시험 시험자료를 다운 받으세요.
