CISA-KR 문제 91
CISA-KR 문제 92
CISA-KR 문제 93
By conducting compliance audits at major system milestones, the auditor can provide assurance that the project is adhering to the project plan by:
Verifying that the project's scope, schedule, budget, quality, and risks are aligned with the project plan and its objectives1 Identifying any deviations, discrepancies, or non-compliances that may affect the project's performance or outcome1 Recommending and monitoring corrective and preventive actions to address the identified issues and improve the project's compliance1 Reporting and communicating the audit findings, conclusions, and recommendations to the relevant stakeholders1 The other options are not as effective as conducting compliance audits at major system milestones for providing assurance that the project is adhering to the project plan. Requiring design reviews at appropriate points in the life cycle is a useful technique for ensuring that the project's design meets the user and business requirements and follows the design standards and best practices3. However, design reviews are not sufficient for providing assurance that the project is adhering to the project plan, as they do not cover other aspects of the project such as schedule, budget, quality, or risks. Having an IS auditor participate on the steering committee is a possible way for providing assurance that the project is adhering to the project plan, as the auditor can provide independent advice and oversight to the steering committee on quality management issues and remediation efforts4. However, this may not be feasible or appropriate for every project, as it may create a conflict of interest or compromise the auditor's objectivity and independence. Having an IS auditor participate on the quality assurance (QA) team is another possible way for providing assurance that the project is adhering to the project plan, as the auditor can assist the QA team in implementing procedures to facilitate adoption of quality management best practices5. However, this may also not be feasible or appropriate for every project, as it may create a conflict of interest or compromise the auditor's objectivity and independence.
Therefore, option D is the correct answer.
References:
What Is Compliance Audit? Definition & Process | ASQ
What Is A Project Milestone? - The Basics
Design Review - an overview | ScienceDirect Topics
Project success through project assurance - Project Management Institute Quality Assurance Team: Roles & Responsibilities
CISA-KR 문제 94
The SLA has not been reviewed in more than a year is not the greatest concern, although it is a good practice to review and update the SLA periodically to ensure that it reflects the current business needs and expectations, as well as any changes in the service provider's capabilities or performance. However, a lack of review does not necessarily imply a lack of compliance or quality of service, as long as the SLA is still valid and enforceable34.
Backup data is hosted online only is not the greatest concern, although it may pose some security risks if the backup data is not encrypted or protected by adequate access controls. Online backup data means that the backup data is stored on a remote server that can be accessed via the Internet, which may offer some advantages such as faster recovery, lower cost, and higher availability than offline backup data that is stored on physical media such as tapes or disks. However, online backup data also requires reliable network connectivity and bandwidth, as well as proper security measures to prevent unauthorized access or tampering56.
The recovery point objective (RPO) has a shorter duration than documented in the DRP is not the greatest concern, although it may indicate some inconsistency or misalignment between the SLA and the DRP. The RPO is the maximum acceptable amount of data loss measured in time from a disaster or a disruption. A shorter RPO than the DRP means that the bank may lose less data than expected, which may be beneficial for its business continuity and recovery. However, a shorter RPO may also imply more frequent backups, which may increase the cost and complexity of the backup process
CISA-KR 문제 95
The other options are not the primary objective of a CSA. Ensuring appropriate access controls are implemented is a specific type of control that may be assessed by a CSA, but it is not the main goal of the technique. Eliminating the audit risk by leveraging management's analysis is not a realistic or desirable outcome of a CSA, as audit risk can never be completely eliminated, and management's analysis may not be sufficient or reliable without independent verification. Gaining assurance for business functions that cannot be audited is not a valid reason for conducting a CSA, as all business functions should be subject to audit, and a CSA is not a substitute for an audit.
References:
Control Self Assessments - PwC
Control self-assessment - Wikipedia
Control Self Assessment - AuditNet
- 다른 버전
- 244ISACA.CISA-KR.v2026-08-15.q712
- 4265ISACA.CISA-KR.v2026-05-16.q709
- 1839ISACA.CISA-KR.v2026-05-06.q261
- 4699ISACA.CISA-KR.v2026-03-07.q651
- 9418ISACA.CISA-KR.v2025-04-07.q633
- 4504ISACA.CISA-KR.v2025-04-03.q628
- 3795ISACA.CISA-KR.v2025-04-02.q544
- 4296ISACA.CISA-KR.v2025-03-31.q534
- 5448ISACA.CISA-KR.v2025-03-28.q617
- 3294ISACA.CISA-KR.v2025-03-19.q581
- 4142ISACA.CISA-KR.v2025-03-03.q807
- 5235ISACA.CISA-KR.v2024-02-07.q421
- 2904ISACA.CISA-KR.v2024-01-31.q392
- 5412ISACA.CISA-KR.v2023-10-24.q329
- 5247ISACA.CISA-KR.v2023-07-31.q266
- 3245ISACA.CISA-KR.v2023-06-23.q324
- 최근 업로드
- 244ISACA.CISA-KR.v2026-08-15.q712
- 189Microsoft.MS-700-KR.v2026-08-15.q203
- 140Microsoft.AZ-305-KR.v2026-08-14.q177
- 207Microsoft.DP-900-KR.v2026-08-13.q130
- 290Microsoft.PL-600.v2026-08-11.q206
- 231Microsoft.DP-100.v2026-08-11.q160
- 192Oracle.1Z0-1048-25.v2026-08-11.q68
- 160ISQI.CTAL-TAE.v2026-08-11.q37
- 202ServiceNow.CIS-HR.v2026-08-11.q84
- 283Salesforce.Plat-Arch-201.v2026-08-10.q101
PDF 파일 다운로드
메일 주소를 입력하시고 다운로드 하세요. ISACA.CISA-KR.v2026-03-16.q665 모의시험 시험자료를 다운 받으세요.
