CISA-KR 문제 541
ISACA CISA Reference: According to ISACA's BCP and DRP guidelines, BIA should involve input from multiple business functions, including finance, operations, and risk management, rather than relying solely on IT.
Risk Implication: Without broader business input, the criticality of systems may be misclassified, leading to incorrect recovery priorities and potential business disruption.
Alternative Choices:
Option A: While a risk assessment is important, a BIA can still be completed without it and later validated.
Option C: The use of questionnaires is a valid method if responses are verified.
Option D: Lack of executive sign-off is concerning but does not directly impact the accuracy of system criticality assessment.
CISA-KR 문제 542
* CISA Review Manual (Digital Version)
* CISA Questions, Answers & Explanations Database
CISA-KR 문제 543
* CISA Review Manual, 27th Edition, pages 475-4761
* CISA Review Questions, Answers & Explanations Database, Question ID: 2642
CISA-KR 문제 544
* CISA Review Manual, 27th Edition, pages 295-2961
* CISA Review Questions, Answers & Explanations Database, Question ID: 260
CISA-KR 문제 545
* A. Improving the change management process is not the best recommendation by the IS auditor for finding that application servers had inconsistent security settings leading to potential vulnerabilities, as it does not address the root cause of the problem or provide a specific solution. While improving the change management process may help to prevent future inconsistencies or misconfigurations in application server settings, it does not ensure that the existing ones are detected and corrected.
* B. Establishing security metrics is not the best recommendation by the IS auditor for finding that application servers had inconsistent security settings leading to potential vulnerabilities, as it does not address the root cause of the problem or provide a specific solution. While establishing security metrics may help to measure and monitor the security performance and posture of application servers, it does not ensure that the existing inconsistencies or misconfigurations in application server settings are detected and corrected.
* C. Performing a penetration test is not the best recommendation by the IS auditor for finding that application servers had inconsistent security settings leading to potential vulnerabilities, as it does not address the root cause of the problem or provide a specific solution. While performing a penetration test may help to simulate and evaluate the impact of an attack on application servers, it does not ensure that the existing inconsistencies or misconfigurations in application server settings are detected and corrected. References: Configuring system to useapplication server security - IBM, Application Security Risk: Assessment and Modeling - ISACA, Five Key Components of an Application SecurityProgram - ISACA, ISACA Practitioner Guidelines for Auditors - SSH, SCADA Cybersecurity Framework - ISACA
- 다른 버전
- 223ISACA.CISA-KR.v2026-08-15.q712
- 4200ISACA.CISA-KR.v2026-05-16.q709
- 1824ISACA.CISA-KR.v2026-05-06.q261
- 4617ISACA.CISA-KR.v2026-03-07.q651
- 9339ISACA.CISA-KR.v2025-04-07.q633
- 4491ISACA.CISA-KR.v2025-04-03.q628
- 3732ISACA.CISA-KR.v2025-04-02.q544
- 4274ISACA.CISA-KR.v2025-03-31.q534
- 5421ISACA.CISA-KR.v2025-03-28.q617
- 3253ISACA.CISA-KR.v2025-03-19.q581
- 4058ISACA.CISA-KR.v2025-03-03.q807
- 5218ISACA.CISA-KR.v2024-02-07.q421
- 2871ISACA.CISA-KR.v2024-01-31.q392
- 5389ISACA.CISA-KR.v2023-10-24.q329
- 5230ISACA.CISA-KR.v2023-07-31.q266
- 3229ISACA.CISA-KR.v2023-06-23.q324
- 최근 업로드
- 223ISACA.CISA-KR.v2026-08-15.q712
- 165Microsoft.MS-700-KR.v2026-08-15.q203
- 130Microsoft.AZ-305-KR.v2026-08-14.q177
- 190Microsoft.DP-900-KR.v2026-08-13.q130
- 288Microsoft.PL-600.v2026-08-11.q206
- 218Microsoft.DP-100.v2026-08-11.q160
- 187Oracle.1Z0-1048-25.v2026-08-11.q68
- 159ISQI.CTAL-TAE.v2026-08-11.q37
- 200ServiceNow.CIS-HR.v2026-08-11.q84
- 281Salesforce.Plat-Arch-201.v2026-08-10.q101
PDF 파일 다운로드
메일 주소를 입력하시고 다운로드 하세요. ISACA.CISA-KR.v2026-03-16.q665 모의시험 시험자료를 다운 받으세요.
