CISA-KR 문제 361
The other options are not as effective as access controls for source libraries in protecting against unauthorized updating of source code. Option A, required approvals at each life cycle step, is a good practice but may not be sufficient to prevent unauthorized updates if the approval process is bypassed or compromised. Option B, date and time stamping of source and object code, is a useful feature but may not prevent unauthorized updates if the date and time stamps are altered or ignored. Option D, release-to-release comparison of source code, is a helpful feature but may not prevent unauthorized updates if the comparison results are not reviewed or acted upon.
References:
ISACA, CISA Review Manual, 27th Edition, 2019
ISACA, CISA Review Questions, Answers & Explanations Database - 12 Month Subscription How to protect your source code from attackers2 How to Stop Unauthorized Use of Open Source Code
CISA-KR 문제 362
CISA-KR 문제 363
IS 감사자가 최종 보고서를 준비할 때 취하는 가장 좋은 조치는 다음 중 무엇입니까?
CISA-KR 문제 364
Data classification typically involves assigning labels or tags to data assets, such as public, internal, confidential, or restricted. These labels indicate the level of protection and handling required for the data.
Based on the data classification, organizations can implement appropriate controls to safeguard the data, such as encryption, access control lists, audit logs, backup policies, etc. These controls help to prevent unauthorized access, disclosure, modification, or loss of data, and to ensure compliance with relevant laws and regulations.
If a data owner assigns an incorrect classification level to data, it can result in either underprotection or overprotection of the data. Underprotection means that the data is classified at a lower level than it should be, which exposes it to higher risks of compromise or breach. For example, if a data owner classifies personal health information (PHI) as public instead of confidential, it may allow anyone to access or share the data without proper authorization or consent. This can violate the privacy rights of the data subjects and the compliance requirements of regulations such as HIPAA (Health Insurance Portability and Accountability Act). Overprotection means that the data is classified at a higher level than it should be, which limits its availability or usability. For example, if a data owner classifies marketing materials as restricted instead of public, it may prevent potential customers or partners from accessing or viewing the data. This can reduce the business value and opportunities of the data.
Therefore, an IS auditor should be concerned about the accuracy and consistency of data classification by data owners, as it affects the security and efficiency of data management. An IS auditor should review the policies and procedures for data classification, verify that the data owners have adequate knowledge and skills to classify their data, and test that the data classification labels match with the actual sensitivity and impact of the data.
References:
* Data Classification: What It Is and How to Implement It
* What Is Data Classification? - Definition, Levels & Examples ...
* Data Classification: A Guide for Data Security Leaders
CISA-KR 문제 365
- 다른 버전
- 225ISACA.CISA-KR.v2026-08-15.q712
- 4214ISACA.CISA-KR.v2026-05-16.q709
- 1826ISACA.CISA-KR.v2026-05-06.q261
- 3194ISACA.CISA-KR.v2026-03-16.q665
- 9343ISACA.CISA-KR.v2025-04-07.q633
- 4491ISACA.CISA-KR.v2025-04-03.q628
- 3742ISACA.CISA-KR.v2025-04-02.q544
- 4282ISACA.CISA-KR.v2025-03-31.q534
- 5432ISACA.CISA-KR.v2025-03-28.q617
- 3255ISACA.CISA-KR.v2025-03-19.q581
- 4059ISACA.CISA-KR.v2025-03-03.q807
- 5218ISACA.CISA-KR.v2024-02-07.q421
- 2871ISACA.CISA-KR.v2024-01-31.q392
- 5389ISACA.CISA-KR.v2023-10-24.q329
- 5230ISACA.CISA-KR.v2023-07-31.q266
- 3231ISACA.CISA-KR.v2023-06-23.q324
- 최근 업로드
- 225ISACA.CISA-KR.v2026-08-15.q712
- 167Microsoft.MS-700-KR.v2026-08-15.q203
- 131Microsoft.AZ-305-KR.v2026-08-14.q177
- 190Microsoft.DP-900-KR.v2026-08-13.q130
- 290Microsoft.PL-600.v2026-08-11.q206
- 219Microsoft.DP-100.v2026-08-11.q160
- 188Oracle.1Z0-1048-25.v2026-08-11.q68
- 159ISQI.CTAL-TAE.v2026-08-11.q37
- 200ServiceNow.CIS-HR.v2026-08-11.q84
- 281Salesforce.Plat-Arch-201.v2026-08-10.q101
PDF 파일 다운로드
메일 주소를 입력하시고 다운로드 하세요. ISACA.CISA-KR.v2026-03-07.q651 모의시험 시험자료를 다운 받으세요.
