CISA-KR 문제 536
CISA-KR 문제 537
Some of the benefits of UAM are:
Prevention: UAM can deter employees from engaging in inappropriate activity by making them aware that their actions are monitored and recorded. UAM can also prevent unauthorized access or use of sensitive data or resources by implementing access controls, encryption, or alerts.
Detection: UAM can detect any anomalies, deviations, or violations in user activity by analyzing the data collected from various sources, such as logs, keystrokes, screenshots, or video recordings. UAM can also use artificial intelligence or machine learning to identify patterns, trends, or risks in user behavior.
Response: UAM can respond to any incidents or issues related to user activity by notifying the relevant stakeholders, such as managers, security teams, or auditors. UAM can also provide evidence or proof of user activity for investigation or remediation purposes.
Some examples of UAM tools are:
Teramind: Teramind is a cloud-based UAM platform that offers features such as user behavior analytics, risk scoring, policy enforcement, data loss prevention, and productivity optimization.
Digital Guardian: Digital Guardian is a data protection platform that offers UAM capabilities such as endpoint detection and response, data classification and tagging, and threat hunting and incident response.
XPLG: XPLG is a log management and analysis platform that offers UAM features such as log aggregation and correlation, user behavior profiling and anomaly detection, and real-time alerts and dashboards.
The other options are not as effective as option A. Two-factor authentication (option B) is a security mechanism that requires users to provide two pieces of evidence to verify their identity before accessing a system or resource. Two-factor authentication can enhance the security and privacy of user accounts, but it does not monitor or record the user activity after the authentication. Network segmentation (option C) is a technique that divides a network into smaller subnetworks based on criteria such as function, location, or security level. Network segmentation can improve the performance, security, and manageability of a network by reducing congestion, isolating threats, and enforcing policies. However, network segmentation does not track or record the user activity within each segment of the network. Access recertification (option D) is a process that verifies and validates the access rights of users to systems or resources periodically or on- demand. Access recertification can ensure that users have the appropriate level of access based on their roles and responsibilities, but it does not monitor or record the user activity with the access rights.
References:
[User Activity Monitoring: Examples and Best Practices | SEON]
Top 10 user activity monitoring tools: software features and tracking price - Dashly blog Whatis User Activity Monitoring? How It Works, Benefits, Best Practices and More - Digital Guardian What Is User Activity Monitoring? Learn the What, Why, and How - XPLG
CISA-KR 문제 538
The other options are not as good as option A. Conducting a post-implementation review immediately after deployment is too soon, because it does not allow enough time for the project's product or service to operate in the real world and generate measurable results. Conducting a post-implementation review after the warranty period is too late, because it may miss some important feedback or opportunities for improvement that could have been addressed earlier. Conducting a post-implementation review prior to the annual performance review is irrelevant, because it does not align with the project's life cycle or objectives. References: What is Post-Implementation Review in Project Management?, What Is the Post- Implementation Review (PIR) Process?, Post-implementation review in project management?
CISA-KR 문제 539
CISA-KR 문제 540
The greatest concern is if the vendor is excluded from the organization's third-party due diligence process.
Without proper due diligence, the organization has no assurance that the vendor meets minimum security and privacy requirements, exposing PII to significant risk.
* Option A: External-facing services carry risk but can be mitigated by proper controls.
* Option B: Lack of dedicated privacy staff may increase risk, but controls may still exist.
* Option C: Fourth-party hosting adds risk but is acceptable if included in due diligence.
* Option D: Correct - exclusion from due diligence represents a fundamental breakdown in vendor risk management.
# ISACA Reference: CISA Review Manual 27th Edition, Domain 5, section on third-party/vendor risk management and data privacy.
- 다른 버전
- 209ISACA.CISA-KR.v2026-08-15.q712
- 4163ISACA.CISA-KR.v2026-05-16.q709
- 1823ISACA.CISA-KR.v2026-05-06.q261
- 3166ISACA.CISA-KR.v2026-03-16.q665
- 9334ISACA.CISA-KR.v2025-04-07.q633
- 4483ISACA.CISA-KR.v2025-04-03.q628
- 3724ISACA.CISA-KR.v2025-04-02.q544
- 4255ISACA.CISA-KR.v2025-03-31.q534
- 5401ISACA.CISA-KR.v2025-03-28.q617
- 3250ISACA.CISA-KR.v2025-03-19.q581
- 4055ISACA.CISA-KR.v2025-03-03.q807
- 5218ISACA.CISA-KR.v2024-02-07.q421
- 2871ISACA.CISA-KR.v2024-01-31.q392
- 5388ISACA.CISA-KR.v2023-10-24.q329
- 5229ISACA.CISA-KR.v2023-07-31.q266
- 3229ISACA.CISA-KR.v2023-06-23.q324
- 최근 업로드
- 209ISACA.CISA-KR.v2026-08-15.q712
- 156Microsoft.MS-700-KR.v2026-08-15.q203
- 126Microsoft.AZ-305-KR.v2026-08-14.q177
- 188Microsoft.DP-900-KR.v2026-08-13.q130
- 279Microsoft.PL-600.v2026-08-11.q206
- 218Microsoft.DP-100.v2026-08-11.q160
- 187Oracle.1Z0-1048-25.v2026-08-11.q68
- 159ISQI.CTAL-TAE.v2026-08-11.q37
- 200ServiceNow.CIS-HR.v2026-08-11.q84
- 276Salesforce.Plat-Arch-201.v2026-08-10.q101
PDF 파일 다운로드
메일 주소를 입력하시고 다운로드 하세요. ISACA.CISA-KR.v2026-03-07.q651 모의시험 시험자료를 다운 받으세요.
