CISA-KR 문제 251
CISA-KR 문제 252
/IEC 270371, which provide guidelines for ensuring the integrity, authenticity, reliability, and admissibility of the evidence2.
The other possible options are:
* A. Communication with law enforcement: This is the process of reporting, cooperating, and coordinating with law enforcement agencies that have the jurisdiction and authority to investigate and prosecute cybercrimes. Communication with law enforcement is an important aspect of the response process for cybercrimes, but it is not an IS auditor's primary focus when evaluating it. Communication with law enforcement depends on the legal and regulatory requirements, the nature and severity of the incident, and the organizational policies and procedures. Communication with law enforcement should be done after evidence collection, to avoid compromising or contaminating the evidence3.
* B. Notification to regulators: This is the process of informing and updating the relevant regulatory bodies or authorities that oversee or supervise the organization's activities or industry sector about the cybercrime incident. Notification to regulators is an important aspect of the response process for cybercrimes, but it is not an IS auditor's primary focus when evaluating it. Notification to regulators depends on the legal and regulatory requirements, the nature and impact of the incident, and the organizational policies and procedures. Notification to regulators should be doneafter evidence collection, to avoid disclosing sensitiveor confidential information4.
* C. Root cause analysis: This is the process of identifying and analyzing the underlying factors or causes that led to or contributed to the cybercrime incident. Root cause analysis is an important aspect of the response process for cybercrimes, but it is not an IS auditor's primary focus when evaluating it. Root cause analysis helps to prevent or mitigate future incidents, improve security controls and processes, and learn from mistakes. Root cause analysis should be done after evidence collection, to avoid interfering with or affecting theinvestigation5.
CISA-KR 문제 253
CISA-KR 문제 254
Risk management techniques are an essential part of an IS development methodology, as they help to identify, assess, prioritize, mitigate, monitor, and communicate the risks that may affect the success of the system development project. Risk management techniques can also help to ensure that the system meets the requirements and expectations of the stakeholders, complies with the relevant laws and regulations, and delivers value to the organization2.
The other options are not as relevant or appropriate as risk management techniques for an IS development methodology. Value-added activity analysis is a technique for evaluating the efficiency and effectiveness of business processes, but it is not specific to IS development3. Access control rules are policies and mechanisms for restricting or granting access to information systems and resources, but they are more related to security management than IS development4. Incident management techniques are methods for handling and resolving incidents that disrupt the normal operation of information systems and services, but they are more related to service management than IS development5.
References:
ISACA, CISA Review Manual, 27th Edition, 2019, p. 1911
ISACA, CISA Review Manual, 27th Edition, 2019, p. 1942
Value-Added Activity Analysis3
Access Control Rules4
Incident Management Techniques5
CISA-KR 문제 255
- 다른 버전
- 286ISACA.CISA-KR.v2026-08-15.q712
- 4300ISACA.CISA-KR.v2026-05-16.q709
- 1857ISACA.CISA-KR.v2026-05-06.q261
- 4726ISACA.CISA-KR.v2026-03-07.q651
- 9432ISACA.CISA-KR.v2025-04-07.q633
- 4541ISACA.CISA-KR.v2025-04-03.q628
- 3804ISACA.CISA-KR.v2025-04-02.q544
- 4310ISACA.CISA-KR.v2025-03-31.q534
- 5507ISACA.CISA-KR.v2025-03-28.q617
- 3304ISACA.CISA-KR.v2025-03-19.q581
- 4188ISACA.CISA-KR.v2025-03-03.q807
- 5242ISACA.CISA-KR.v2024-02-07.q421
- 2918ISACA.CISA-KR.v2024-01-31.q392
- 5427ISACA.CISA-KR.v2023-10-24.q329
- 5255ISACA.CISA-KR.v2023-07-31.q266
- 3254ISACA.CISA-KR.v2023-06-23.q324
- 최근 업로드
- 286ISACA.CISA-KR.v2026-08-15.q712
- 234Microsoft.MS-700-KR.v2026-08-15.q203
- 163Microsoft.AZ-305-KR.v2026-08-14.q177
- 230Microsoft.DP-900-KR.v2026-08-13.q130
- 303Microsoft.PL-600.v2026-08-11.q206
- 239Microsoft.DP-100.v2026-08-11.q160
- 200Oracle.1Z0-1048-25.v2026-08-11.q68
- 167ISQI.CTAL-TAE.v2026-08-11.q37
- 206ServiceNow.CIS-HR.v2026-08-11.q84
- 286Salesforce.Plat-Arch-201.v2026-08-10.q101
PDF 파일 다운로드
메일 주소를 입력하시고 다운로드 하세요. ISACA.CISA-KR.v2026-03-16.q665 모의시험 시험자료를 다운 받으세요.
