CISA-KR 문제 261
IfIT is not involvedinstrategic planning,IT strategy may diverge from business needs, leading to misalignment and inefficiencies.
* Option A (Incorrect):Business strategy alignmentis important, but the greater risk is thatIT investments do not support business goals.
* Option B (Incorrect):Lack of emerging technology awareness is a risk, butIT-business misalignment has broader consequences.
* Option C (Correct):Thegreatest riskis when IT strategyfails to align with business objectives, leading towasted investments, inefficiencies, and competitive disadvantages.
* Option D (Incorrect):IT goals being overlooked is a concern, butmisalignment of IT and business strategies is a more critical risk.
Reference:ISACA CISA Review Manual -Domain 2: Governance and Management of IT- Covers strategic IT alignment and governance best practices.
CISA-KR 문제 262
The other options are less concerning because they do not directly affect the security of the data center. CCTV cameras are not required to be installed in break rooms, as they are not critical areas for data protection.
CCTV records can be deleted after one year, as long as they comply with the data retention policy of the organization and the applicable laws. CCTV footage does not need to be recorded 24 x 7, as long as there is sufficient coverage of the data center during operational hours and when access is granted to authorized personnel. References:
* ISACA Journal Article: Physical security of a data center1
* Data Center Security: Checklist and Best Practices | Kisi2
* Video Surveillance Best Practices | Taylored Systems
CISA-KR 문제 263
* Strong Encryption Algorithms (Option A):Encryption ensures confidentiality but does not address spoofing risks.
* Kerberos Authentication (Option B):Useful for mutual authentication but not central to public key infrastructure (PKI).
* Registration Authority (Option C):Supports the CA but does not directly prevent MITM attacks.
Reference:ISACA CISA Review Manual, Job Practice Area 4: Protection of Information Assets.
CISA-KR 문제 264
Incomplete processing can result in data loss, inconsistency, or incompleteness, which can affect the quality and reliability of the information system and its outputs. Incomplete processing can be caused by various factors, such as:
Hardware or software failures that interrupt the processing or transmission of data2 Human errors or omissions that skip or miss some data or transactions2 Malicious attacks or unauthorized access that delete or modify some data or transactions2 Environmental hazards or disasters that damage or destroy some data or transactions2 Control totals can help detect and prevent incomplete processing by:
Providing a benchmark or reference point to compare the input and output data or transactions1 Identifying any discrepancies or deviations from the expected or required totals1 Alerting the users or operators to investigate and resolve the causes of incomplete processing1 Ensuring that all the data or transactions are properly transmitted, converted, and processed1 The other options are not as relevant as control totals for reducing the risk of incomplete processing. Posting to the wrong record is the error of assigning or transferring data or transactions to an incorrect account, file, or record3. Improper backup is the failure to create, store, or restore copies of data or transactions in case of loss, corruption, or damage4. Improper authorization is the lack of proper permission or approval to access, modify, or process data or transactions. Control totals may not be able to prevent or detect these errors or failures, as they are not related to the completeness of data processing. Therefore, option B is the correct answer.
References:
control totals - Barrons Dictionary - AllBusiness.com
What is control total amount? - Sage Advice US
Posting Error Definition
Backup Definition
[Authorization Definition]
CISA-KR 문제 265
* Option A (Correct):The primary purpose of EA governance is to ensure that new technologies, processes, and systems align and harmonize with existing architecture to maintain operational efficiency and consistency.
* Option B (Incorrect):While adaptability to emerging technology trends is important, EA governance focuses more on structure, consistency, and compliance rather than just adaptability.
* Option C (Incorrect):Compliance with regulations is crucial, but it is just one component of governance.
EA governance has a broader scope, including strategic alignment and process integration.
* Option D (Incorrect):Ensuring ROI is an important financial consideration, but it is not themainobjective of EA governance.
Reference:ISACA CISA Review Manual -Domain 1: Information Systems Auditing Process- Covers governance, risk management, and ensuring alignment of EA with business objectives.
- 다른 버전
- 286ISACA.CISA-KR.v2026-08-15.q712
- 4300ISACA.CISA-KR.v2026-05-16.q709
- 1857ISACA.CISA-KR.v2026-05-06.q261
- 4726ISACA.CISA-KR.v2026-03-07.q651
- 9432ISACA.CISA-KR.v2025-04-07.q633
- 4541ISACA.CISA-KR.v2025-04-03.q628
- 3804ISACA.CISA-KR.v2025-04-02.q544
- 4310ISACA.CISA-KR.v2025-03-31.q534
- 5507ISACA.CISA-KR.v2025-03-28.q617
- 3304ISACA.CISA-KR.v2025-03-19.q581
- 4188ISACA.CISA-KR.v2025-03-03.q807
- 5242ISACA.CISA-KR.v2024-02-07.q421
- 2918ISACA.CISA-KR.v2024-01-31.q392
- 5427ISACA.CISA-KR.v2023-10-24.q329
- 5255ISACA.CISA-KR.v2023-07-31.q266
- 3254ISACA.CISA-KR.v2023-06-23.q324
- 최근 업로드
- 286ISACA.CISA-KR.v2026-08-15.q712
- 234Microsoft.MS-700-KR.v2026-08-15.q203
- 163Microsoft.AZ-305-KR.v2026-08-14.q177
- 230Microsoft.DP-900-KR.v2026-08-13.q130
- 302Microsoft.PL-600.v2026-08-11.q206
- 239Microsoft.DP-100.v2026-08-11.q160
- 200Oracle.1Z0-1048-25.v2026-08-11.q68
- 167ISQI.CTAL-TAE.v2026-08-11.q37
- 206ServiceNow.CIS-HR.v2026-08-11.q84
- 286Salesforce.Plat-Arch-201.v2026-08-10.q101
PDF 파일 다운로드
메일 주소를 입력하시고 다운로드 하세요. ISACA.CISA-KR.v2026-03-16.q665 모의시험 시험자료를 다운 받으세요.
