CISA-KR 문제 231
References:
* 5: What is Wi-Fi? - Definition from WhatIs.com
* 6: Understanding Bluetooth Range | Bluetooth Technology Website
* 7: What is Bluetooth Range? What You Need to Know
* 8: How far can LTE signals travel? - Quora
CISA-KR 문제 232
* Understand the purpose, scope, objectives, and deliverables of the project
* Assess the alignment of the project with the organization's strategy, vision, and goals
* Evaluate the value proposition and return on investment of the project
* Identify the key stakeholders, sponsors, and owners of the project
* Analyze the potential risks and issues associated with the project
* Compare and prioritize the project with other competing projects
The other possible options are:
* A. Project charter: A project charter is a document that formally authorizes and defines the high-level scope, roles, responsibilities, and authority of a project. A project charter provides some useful information to an IS auditor when selecting projects for inclusion in an IT audit plan, but it is not the most useful information. A project charter does not provide enough details about the costs, benefits, risks, and feasibility of the project, which are essential for evaluating its suitability for an IT audit plan.
* B. Project plan: A project plan is a document that outlines the detailed scope, schedule, budget, resources, quality, and communication plans of a project. A project plan provides some useful information to an IS auditor when selecting projects for inclusion in an IT audit plan, but it is not the most useful information. A project plan does not provide enough information about the rationale, justification, value proposition, and alignment of the project with the organization's strategy and goals, which are important for assessing its relevance for an IT audit plan.
* C. Project issue log: A project issue log is a document that records and tracks the issues that arise during a project's execution and how they are resolved. A project issue log provides some useful information to an IS auditor when selecting projects for inclusion in an IT audit plan, but it is not the most useful information. A project issue log does not provide enough information about the purpose, objectives, benefits, and feasibility of the project, which are critical for determining its priority for an IT audit plan.
CISA-KR 문제 233
다음 중 감사인의 가장 좋은 권고사항은 무엇인가?
Line management is responsible for overseeing and supervising the activities and performance of their staff, and ensuring that they comply with the organization's policies and standards3. Therefore, line management should regularly review and request modification of access rights for their staff, as they are in the best position to:
Understand the roles and functions of their staff, and determine the appropriate level of access rights needed for them to perform their duties effectively and efficiently.
Monitor and evaluate the usage and behavior of their staff, and identify any changes or anomalies that may indicate excessive or inappropriate access rights.
Communicate and collaborate with IT security or system administrators, who are responsible for granting, revoking, or modifying access rights, and request any necessary adjustments or corrections.
CISA-KR 문제 234
CISA-KR 문제 235
* A. The use of cloud negatively impacting IT availability is not an associated risk of mobile computing that an IS auditor should identify during the planning phase of a DLP audit, as it is more related to cloud computing than mobile computing. Cloud computing refers to the delivery of computing services, such as data storage or processing, over the Internet from remote servers. Cloud computing may enable or support mobile computing by providing access to data and applications from any device or location, but it does not necessarily imply mobile computing. The use of cloud may negatively impact IT availability if there are disruptions or outages in the cloud service provider's network or infrastructure, but this is not a direct consequence of mobile computing.
* B. Increased need for user awareness training is not an associated risk of mobile computing that an IS auditor should identify during the planning phase of a DLP audit, as it is more of a control or mitigation measure than a risk. User awareness training refers to educating users about security policies, procedures, and best practices for using mobile devices and protecting data. User awareness training may help to reduce the risk of data loss or breach due to mobile computing by increasing user knowledge and responsibility, but it does not eliminate or prevent the risk.
* D. Lack of governance and oversight for IT infrastructure and applications is not an associated risk of mobile computing that an IS auditor should identify during the planning phase of a DLP audit, as it is more of a general or organizational risk than a specific or technical risk. Governance and oversight refer to the establishment and implementation of policies, standards, and procedures for managing IT resources and aligning them with business objectives. Lack of governance and oversight for IT infrastructure and applications may affect the security and performance of mobile devices and data, but it is not a direct or inherent result of mobile computing. References: Mobile Computing - ISACA, Mobile Computing Device Threats, Vulnerabilities and Risk Factors Are Ubiquitous - ISACA, Data Loss Prevention-Next Steps - ISACA, [Cloud Computing - ISACA], [Cloud Computing Risk Assessment - ISACA], [User Awareness Training - ISACA], [Governance and Oversight - ISACA]
- 다른 버전
- 288ISACA.CISA-KR.v2026-08-15.q712
- 4303ISACA.CISA-KR.v2026-05-16.q709
- 1857ISACA.CISA-KR.v2026-05-06.q261
- 4727ISACA.CISA-KR.v2026-03-07.q651
- 9433ISACA.CISA-KR.v2025-04-07.q633
- 4541ISACA.CISA-KR.v2025-04-03.q628
- 3804ISACA.CISA-KR.v2025-04-02.q544
- 4310ISACA.CISA-KR.v2025-03-31.q534
- 5508ISACA.CISA-KR.v2025-03-28.q617
- 3306ISACA.CISA-KR.v2025-03-19.q581
- 4190ISACA.CISA-KR.v2025-03-03.q807
- 5242ISACA.CISA-KR.v2024-02-07.q421
- 2918ISACA.CISA-KR.v2024-01-31.q392
- 5427ISACA.CISA-KR.v2023-10-24.q329
- 5257ISACA.CISA-KR.v2023-07-31.q266
- 3254ISACA.CISA-KR.v2023-06-23.q324
- 최근 업로드
- 104Microsoft.AZ-305-KR.v2026-08-17.q162
- 113IIA.IAA-IAP-KR.v2026-08-17.q41
- 288ISACA.CISA-KR.v2026-08-15.q712
- 234Microsoft.MS-700-KR.v2026-08-15.q203
- 163Microsoft.AZ-305-KR.v2026-08-14.q177
- 230Microsoft.DP-900-KR.v2026-08-13.q130
- 304Microsoft.PL-600.v2026-08-11.q206
- 240Microsoft.DP-100.v2026-08-11.q160
- 201Oracle.1Z0-1048-25.v2026-08-11.q68
- 167ISQI.CTAL-TAE.v2026-08-11.q37
PDF 파일 다운로드
메일 주소를 입력하시고 다운로드 하세요. ISACA.CISA-KR.v2026-03-16.q665 모의시험 시험자료를 다운 받으세요.
