CISA-KR 문제 481
Data Encryption Standard (DES) is a symmetric encryption algorithm that can provide confidentiality of online orders, but not integrity. DES uses the same key to encrypt and decrypt the data, which means that anyone who has the key can modify the data without detection.
Public key encryption is an asymmetric encryption algorithm that can also provide confidentiality of online orders, but not integrity. Public key encryption uses a pair of keys: a public key and a private key. The sender encrypts the data with the receiver's public key, and the receiver decrypts it with their own private key.
However, public key encryption does not prevent anyone from modifying the encrypted data.
Multi-factor authentication is a control that can provide authentication and authorization of online orders, but not integrity. Multi-factor authentication requires the user to provide two or more pieces of evidence to prove their identity, such as a password, a token, or a biometric factor. Multi-factor authentication can prevent unauthorized access to online orders, but it does not protect the data from being modified after being sent.
References:
* ISACA, CISA Review Manual, 27th Edition, 2019, p. 281 1
* ISACA, CISA Review Questions, Answers & Explanations Database - 12 Month Subscription 2
CISA-KR 문제 482
CISA-KR 문제 483
ISACA CISA Reference: According to ISACA's BCP and DRP guidelines, BIA should involve input from multiple business functions, including finance, operations, and risk management, rather than relying solely on IT.
Risk Implication: Without broader business input, the criticality of systems may be misclassified, leading to incorrect recovery priorities and potential business disruption.
Alternative Choices:
Option A: While a risk assessment is important, a BIA can still be completed without it and later validated.
Option C: The use of questionnaires is a valid method if responses are verified.
Option D: Lack of executive sign-off is concerning but does not directly impact the accuracy of system criticality assessment.
CISA-KR 문제 484
The other options are not the first step when developing a DLP solution, but rather subsequent steps that depend on the outcome of the data inventory and classification exercise. Identifying approved data workflows across the enterprise is a step that helps to design and implement the DLP policies and controls that match the business processes and data flows. Conducting a threat analysis against sensitive data usage is a step that helps to assess and mitigate the risks associated with data leakage, theft, or misuse. Creating the DLP policies and templates is a step that helps to enforce the data protection rules and standards across the organization.
References:
* ISACA CISA Review Manual 27th Edition (2019), page 247
* Data Loss Prevention-Next Steps - ISACA1
* What is data loss prevention (DLP)? | Microsoft Security
CISA-KR 문제 485
* Communicate the organization's policies and expectations regarding BYOD, such as which devices are allowed, what data can be accessed or stored, and what security measures are required.
* Raise the employees' awareness of the potential threats and vulnerabilities that affect their mobile devices, such as malware, phishing, data leakage, or device loss.
* Provide the employees with guidance and tips on how to protect their mobile devices and the organization's data, such as using strong passwords, encryption, antivirus software, remote wipe, or VPN.
* Encourage the employees to report any incidents or issues related to their mobile devices, such as suspicious messages, unauthorized access, or device damage.
A mobile device awareness program can help the organization to reduce the security risks associated with BYOD by enhancing the employees' knowledge, skills, and behavior in using their mobile devices securely and responsibly. A mobile device awareness program can also help the organization to comply with relevant regulations and standards that govern data privacy and security in the cloud1.
The other options are not as effective as a mobile device awareness program in enabling an organization to address the security risks associated with BYOD. Option A, mobile device tracking program, is a tool that allows the organization to monitor and locate the employees' mobile devices in case of loss or theft. However, this tool may not prevent or detect other types of security risks, such as malware infection or data breach.
Option B, mobile device upgrade program, is a process that ensures that the employees' mobile devices are running the latest versions of operating systems and applications. However, this process may not address other aspects of security, such as user behavior or data protection. Option C, mobile device testing program, is a method that verifies the functionality and compatibility of the employees' mobile devices with the organization's systems and networks. However, this method may not cover all the scenarios or factors that may affect the security of the mobile devices or the organization's data2.
References:
* Mobile Device Security Awareness Topics3
* Security Awareness Top Ten Topics - #8 Mobile Devices
- 다른 버전
- 223ISACA.CISA-KR.v2026-08-15.q712
- 4195ISACA.CISA-KR.v2026-05-16.q709
- 1824ISACA.CISA-KR.v2026-05-06.q261
- 3190ISACA.CISA-KR.v2026-03-16.q665
- 9339ISACA.CISA-KR.v2025-04-07.q633
- 4491ISACA.CISA-KR.v2025-04-03.q628
- 3732ISACA.CISA-KR.v2025-04-02.q544
- 4273ISACA.CISA-KR.v2025-03-31.q534
- 5420ISACA.CISA-KR.v2025-03-28.q617
- 3253ISACA.CISA-KR.v2025-03-19.q581
- 4058ISACA.CISA-KR.v2025-03-03.q807
- 5218ISACA.CISA-KR.v2024-02-07.q421
- 2871ISACA.CISA-KR.v2024-01-31.q392
- 5389ISACA.CISA-KR.v2023-10-24.q329
- 5230ISACA.CISA-KR.v2023-07-31.q266
- 3229ISACA.CISA-KR.v2023-06-23.q324
- 최근 업로드
- 223ISACA.CISA-KR.v2026-08-15.q712
- 165Microsoft.MS-700-KR.v2026-08-15.q203
- 130Microsoft.AZ-305-KR.v2026-08-14.q177
- 190Microsoft.DP-900-KR.v2026-08-13.q130
- 288Microsoft.PL-600.v2026-08-11.q206
- 218Microsoft.DP-100.v2026-08-11.q160
- 187Oracle.1Z0-1048-25.v2026-08-11.q68
- 159ISQI.CTAL-TAE.v2026-08-11.q37
- 200ServiceNow.CIS-HR.v2026-08-11.q84
- 281Salesforce.Plat-Arch-201.v2026-08-10.q101
PDF 파일 다운로드
메일 주소를 입력하시고 다운로드 하세요. ISACA.CISA-KR.v2026-03-07.q651 모의시험 시험자료를 다운 받으세요.
