CISA-KR 문제 221
Number of successful penetration tests, percentage of protected business applications, and number of security vulnerability patches are indicators of the security posture of the organization, but they do not reflect the effectiveness of the incident response program. References: ISACA Journal Article: Measuring Incident Response Effectiveness
CISA-KR 문제 222
Whether system delays result in more frequent use of manual processing (option A) is not the most important thing to consider before including an audit of IT capacity management in the program, as it is only one possible consequence of poor IT capacity management. Manual processing can introduce errors, delays, inefficiencies, and inconsistencies in the data and reports, which can affect the quality and accuracy of financial information. However, manual processing is not the only or the worst outcome of poor IT capacity management; there may be other more severe or frequent risks that need to be considered.
Whether stakeholders are committed to assisting with the audit (option C) is also not the most important thing to consider before including an audit of IT capacity management in the program, as it is a factor that affects the feasibility and effectiveness of the audit, not the necessity or priority of it. Stakeholder commitment is important for ensuring that the auditor has access to relevant information, documents, data, and personnel, as well as for facilitating communication, collaboration, and feedback during the audit process. However, stakeholder commitment is not a sufficient reason to conduct an audit of IT capacity management; there must be a clear risk-based rationale for selecting this area for audit.
Whether internal auditors have the required skills to perform the audit (option D) is also not the most important thing to consider before including an audit of IT capacity management in the program, as it is a factor that affects the quality and credibility of the audit, not the urgency or importance of it. Internal auditors should have the appropriate knowledge, skills, and experience to perform an audit of IT capacity management, which may include technical, business, analytical, and communication skills. However, internal auditors can also acquire or supplement these skills through training, coaching, consulting, or outsourcing.
Therefore, internal auditors' skills are not a decisive factor for choosing this area for audit.
Therefore, option B is the correct answer.
References:
Guide to IT Capacity Management | Smartsheet
ISO 27001 capacity management: How to implement control A.12.1.3 - Advisera ISO 27002:2022 - Control 8.6 - Capacity Management
CISA-KR 문제 223
CISA-KR 문제 224
The other options are not as good as option B, as they may not capture the full scope or benefits of using an IT governance framework. Frameworks enable IT benchmarks against competitors, but this is not the main purpose or advantage of using an IT governance framework. Frameworks help facilitate control self- assessments (CSAs), but this is only one aspect or tool of an IT governance framework. Frameworks help organizations understand and manage IT risk, but this is also only one outcome or objective of an IT governance framework.
References:
* 1: What is ITIL? Your guide to the IT Infrastructure Library | CIO
* 2: IT Governance Framework | Components | Framework | Terminology - EDUCBA
* 3: IT Governance: Definitions, Frameworks and Planning - ProjectManager
* 4: What Is IT Governance? - Definition from Techopedia
* 5: What is IT Governance? A formal way to align IT & business strategy | CIO
* 6: What Is IT Governance? - Definition from WhatIs.com
* 7: ISO/IEC 20000 Information Technology Service Management Systems Standard - ISO/IEC 20000 Portal
* 8: COBIT | Control Objectives for Information Technologies | ISACA
CISA-KR 문제 225
Record locking does not serve to allow database administrators (DBAs) to record the activities of users. This is a function of auditing or logging, which can track the actions performed by users on the database2. Record locking does not affect the ability of DBAs to monitor or audit user activities.
Record locking does not serve to restrict users from changing certain values within records. This is a function of access control or authorization, which can enforce rules or policies on what data users can view or modify2. Record locking does not affect the permissions or privileges of users on the database.
Record locking does not serve to allow users to lock others out of their files. This is a function of encryption or password protection, which can secure files from unauthorized access or modification3. Record locking does not affect the security or confidentiality of files on the database.
References:
Record locking - Wikipedia1
Database security - Wikipedia2
File system permissions - Wikipedia3
- 다른 버전
- 225ISACA.CISA-KR.v2026-08-15.q712
- 4244ISACA.CISA-KR.v2026-05-16.q709
- 1829ISACA.CISA-KR.v2026-05-06.q261
- 3198ISACA.CISA-KR.v2026-03-16.q665
- 9350ISACA.CISA-KR.v2025-04-07.q633
- 4499ISACA.CISA-KR.v2025-04-03.q628
- 3777ISACA.CISA-KR.v2025-04-02.q544
- 4292ISACA.CISA-KR.v2025-03-31.q534
- 5443ISACA.CISA-KR.v2025-03-28.q617
- 3272ISACA.CISA-KR.v2025-03-19.q581
- 4075ISACA.CISA-KR.v2025-03-03.q807
- 5232ISACA.CISA-KR.v2024-02-07.q421
- 2873ISACA.CISA-KR.v2024-01-31.q392
- 5403ISACA.CISA-KR.v2023-10-24.q329
- 5244ISACA.CISA-KR.v2023-07-31.q266
- 3244ISACA.CISA-KR.v2023-06-23.q324
- 최근 업로드
- 225ISACA.CISA-KR.v2026-08-15.q712
- 168Microsoft.MS-700-KR.v2026-08-15.q203
- 133Microsoft.AZ-305-KR.v2026-08-14.q177
- 202Microsoft.DP-900-KR.v2026-08-13.q130
- 290Microsoft.PL-600.v2026-08-11.q206
- 223Microsoft.DP-100.v2026-08-11.q160
- 189Oracle.1Z0-1048-25.v2026-08-11.q68
- 160ISQI.CTAL-TAE.v2026-08-11.q37
- 202ServiceNow.CIS-HR.v2026-08-11.q84
- 281Salesforce.Plat-Arch-201.v2026-08-10.q101
PDF 파일 다운로드
메일 주소를 입력하시고 다운로드 하세요. ISACA.CISA-KR.v2026-03-07.q651 모의시험 시험자료를 다운 받으세요.
