CISA-KR 문제 306
By conducting compliance audits at major system milestones, the auditor can provide assurance that the project is adhering to the project plan by:
Verifying that the project's scope, schedule, budget, quality, and risks are aligned with the project plan and its objectives1 Identifying any deviations, discrepancies, or non-compliances that may affect the project's performance or outcome1 Recommending and monitoring corrective and preventive actions to address the identified issues and improve the project's compliance1 Reporting and communicating the audit findings, conclusions, and recommendations to the relevant stakeholders1 The other options are not as effective as conducting compliance audits at major system milestones for providing assurance that the project is adhering to the project plan. Requiring design reviews at appropriate points in the life cycle is a useful technique for ensuring that the project's design meets the user and business requirements and follows the design standards and best practices3. However, design reviews are not sufficient for providing assurance that the project is adhering to the project plan, as they do not cover other aspects of the project such as schedule, budget, quality, or risks. Having an IS auditor participate on the steering committee is a possible way for providing assurance that the project is adhering to the project plan, as the auditor can provide independent advice and oversight to the steering committee on quality management issues and remediation efforts4. However, this may not be feasible or appropriate for every project, as it may create a conflict of interest or compromise the auditor's objectivity and independence. Having an IS auditor participate on the quality assurance (QA) team is another possible way for providing assurance that the project is adhering to the project plan, as the auditor can assist the QA team in implementing procedures to facilitate adoption of quality management best practices5. However, this may also not be feasible or appropriate for every project, as it may create a conflict of interest or compromise the auditor's objectivity and independence.
Therefore, option D is the correct answer.
References:
What Is Compliance Audit? Definition & Process | ASQ
What Is A Project Milestone? - The Basics
Design Review - an overview | ScienceDirect Topics
Project success through project assurance - Project Management Institute Quality Assurance Team: Roles & Responsibilities
CISA-KR 문제 307
By involving business stakeholders in approving the IT strategy, the organization can ensure that the IT strategy reflects and supports the business needs, expectations, and priorities. The other options do not necessarily indicate that IT strategy is aligned with organizational goals and objectives, as they do not involve the participation or feedback of business stakeholders. References: CISA Review Manual, 27th Edition, page
97
CISA-KR 문제 308
Data collection and obtaining consentis themost critical regulatory requirementwhen using customer data for AI training, especially under laws likeGDPR, CCPA, and ISO 27701.
* Collection of Data and Obtaining Consent (Correct Answer - C)
* Ensures compliance withprivacy lawsthat require explicit customer consent.
* Example:UnderGDPR, companies mustinform usershow their data will be used and allow them toopt out.
* AI Algorithm Accuracy (Incorrect - A)
* Important formodel performancebutnot a primary legal concern.
* Ethical Use of Computing Resources (Incorrect - B)
* Ethical considerations are valuable butnot a regulatory priority.
* Continuous Monitoring of AI (Incorrect - D)
* Ensuresperformance, butregulatory compliance focuses on data privacy.
References:
* ISACA CISA Review Manual
* GDPR & CCPA Compliance Guidelines
* ISO 27701 (Privacy Information Management System)
CISA-KR 문제 309
It provides an opportunity to identify and correct any issues or conflicts that may have arisen during the development and implementation process. While other options like adding developers to the change approval board, limiting code deployment access to a small number of people, and creating staging environments can also serve as compensating controls, a post-implementation change review provides a more comprehensive and effective control mechanism21.
References:
Review and Close Change process ST 2 5 - Micro Focus
Change Management for SOC: Risks, Controls, Audits, Guidance
CISA-KR 문제 310
* ISACA, CISA Review Manual, 27th Edition, 2020, p. 3091
* ISACA, CISA Review Questions, Answers & Explanations Database - 12 Month Subscription
- 다른 버전
- 225ISACA.CISA-KR.v2026-08-15.q712
- 4218ISACA.CISA-KR.v2026-05-16.q709
- 1827ISACA.CISA-KR.v2026-05-06.q261
- 3194ISACA.CISA-KR.v2026-03-16.q665
- 9347ISACA.CISA-KR.v2025-04-07.q633
- 4493ISACA.CISA-KR.v2025-04-03.q628
- 3758ISACA.CISA-KR.v2025-04-02.q544
- 4285ISACA.CISA-KR.v2025-03-31.q534
- 5432ISACA.CISA-KR.v2025-03-28.q617
- 3257ISACA.CISA-KR.v2025-03-19.q581
- 4061ISACA.CISA-KR.v2025-03-03.q807
- 5218ISACA.CISA-KR.v2024-02-07.q421
- 2872ISACA.CISA-KR.v2024-01-31.q392
- 5391ISACA.CISA-KR.v2023-10-24.q329
- 5231ISACA.CISA-KR.v2023-07-31.q266
- 3231ISACA.CISA-KR.v2023-06-23.q324
- 최근 업로드
- 225ISACA.CISA-KR.v2026-08-15.q712
- 168Microsoft.MS-700-KR.v2026-08-15.q203
- 132Microsoft.AZ-305-KR.v2026-08-14.q177
- 191Microsoft.DP-900-KR.v2026-08-13.q130
- 290Microsoft.PL-600.v2026-08-11.q206
- 221Microsoft.DP-100.v2026-08-11.q160
- 188Oracle.1Z0-1048-25.v2026-08-11.q68
- 160ISQI.CTAL-TAE.v2026-08-11.q37
- 202ServiceNow.CIS-HR.v2026-08-11.q84
- 281Salesforce.Plat-Arch-201.v2026-08-10.q101
PDF 파일 다운로드
메일 주소를 입력하시고 다운로드 하세요. ISACA.CISA-KR.v2026-03-07.q651 모의시험 시험자료를 다운 받으세요.
