CISA-KR 문제 316
* BCP (Business Continuity Plan):
* Focuses on ensuring that critical business processes continue operating during and after a disruption.
* It includes strategies for maintaining operations (e.g., alternative work locations, manual procedures, supplier dependencies).
* Activated immediately when a disruption occurs to keep the business running.
* DRP (Disaster Recovery Plan):
* Primarily focuses on the recovery of IT systems and infrastructure after a disruption.
* It includes steps for restoring data, servers, and applications to bring IT operations back to normal.
* Activated after the disaster event to restore normal IT operations.
The timeframe for activation is the key difference because:
* BCP is implemented immediately to ensure business continuity.
* DRP is implemented after the disaster to restore IT operations.
* A. The annual testing requirements # Both BCP and DRP require regular testing, so this is not the key differentiator.
* B. The focus on system recovery # Only DRP focuses on system recovery, but the BCP covers more than just IT. The key difference is still the timeframe.
* D. The involvement of senior management # Senior management is involved in both plans, so this is not the primary distinction.
References:ISACA CISA Review Manual, 28th Edition, Chapter 4: Information Systems Operations and Business Resilience
CISA-KR 문제 317
CISA-KR 문제 318
One of the key aspects of change management is measuring its effectiveness, which means assessing whether the changes have achieved the desired outcomes and met the expectations of the stakeholders. There are various indicators that can be used to measure change management effectiveness, such as time, cost, quality, scope, satisfaction, and performance.
Among the four options given, the most appropriate indicator of change management effectiveness is the number of incidents resulting from changes. An incident is an unplanned event or interruption that affects the normal operation or service delivery of an information system. Incidents can be caused by various factors, such as errors, defects, failures, malfunctions, or malicious attacks. Incidents can have negative impacts on the organization, such as loss of data, productivity, reputation, or revenue.
The number of incidents resulting from changes is a direct measure of how well the changes have been planned, implemented, monitored, and evaluated. A high number of incidents indicates that the changes have not been properly tested, verified, communicated, or controlled. A low number of incidents indicates that the changes have been executed smoothly and successfully. Therefore, the number of incidents resulting from changes reflects the quality and effectiveness of the change management process.
The other three options are not as appropriate indicators of change management effectiveness as the number of incidents resulting from changes. The time lag between changes to the configuration and the update of records is a measure of how timely and accurate the configuration management process is. Configuration management is a subset of change management that focuses on identifying, documenting, and controlling the configuration items (CIs) that make up an information system. The time lag between changes and updates of documentation materials is a measure of how well the documentation process is aligned with the change management process. Documentation is an important aspect of change management that provides information and guidance to the stakeholders involved in or affected by the changes. The number of system software changes is a measure of how frequently and extensively the system software is modified or updated. System software changes are a type of change that affects the operating system, middleware, or utilities that support an information system.
While these three indicators are relevant and useful for measuring certain aspects of change management, they do not directly measure the outcomes or impacts of the changes on the organization. They are more related to the inputs or activities of change management than to its outputs or results. Therefore, they are not as appropriate indicators of change management effectiveness as the number of incidents resulting from changes.
References:
Metrics for Measuring Change Management - Prosci
How to Measure Change Management Effectiveness: Metrics, Tools & Processes Metrics for Measuring Change Management 2023 - Zendesk
CISA-KR 문제 319
References:
Auditor Independence - What is it, Rules, Importance, Examples
CISA-KR 문제 320
* CISA Review Manual, 27th Edition, page 2951
* CISA Review Questions, Answers & Explanations Database - 12 Month Subscription
- 다른 버전
- 268ISACA.CISA-KR.v2026-08-15.q712
- 4298ISACA.CISA-KR.v2026-05-16.q709
- 1856ISACA.CISA-KR.v2026-05-06.q261
- 4724ISACA.CISA-KR.v2026-03-07.q651
- 9431ISACA.CISA-KR.v2025-04-07.q633
- 4541ISACA.CISA-KR.v2025-04-03.q628
- 3804ISACA.CISA-KR.v2025-04-02.q544
- 4309ISACA.CISA-KR.v2025-03-31.q534
- 5505ISACA.CISA-KR.v2025-03-28.q617
- 3303ISACA.CISA-KR.v2025-03-19.q581
- 4186ISACA.CISA-KR.v2025-03-03.q807
- 5242ISACA.CISA-KR.v2024-02-07.q421
- 2918ISACA.CISA-KR.v2024-01-31.q392
- 5427ISACA.CISA-KR.v2023-10-24.q329
- 5255ISACA.CISA-KR.v2023-07-31.q266
- 3254ISACA.CISA-KR.v2023-06-23.q324
- 최근 업로드
- 268ISACA.CISA-KR.v2026-08-15.q712
- 230Microsoft.MS-700-KR.v2026-08-15.q203
- 162Microsoft.AZ-305-KR.v2026-08-14.q177
- 230Microsoft.DP-900-KR.v2026-08-13.q130
- 299Microsoft.PL-600.v2026-08-11.q206
- 238Microsoft.DP-100.v2026-08-11.q160
- 196Oracle.1Z0-1048-25.v2026-08-11.q68
- 166ISQI.CTAL-TAE.v2026-08-11.q37
- 206ServiceNow.CIS-HR.v2026-08-11.q84
- 286Salesforce.Plat-Arch-201.v2026-08-10.q101
PDF 파일 다운로드
메일 주소를 입력하시고 다운로드 하세요. ISACA.CISA-KR.v2026-03-16.q665 모의시험 시험자료를 다운 받으세요.
