CISA-KR 문제 371
Historical transactions are transactions that have been processed and recorded by the old system in the past.
Running historical transactions through the new system can provide the most assurance over the completeness and accuracy of loan application processing, by comparing the results and outputs of the new system with those of the old system, and verifying whether they match or differ. This can help identify and resolve any errors or issues that may arise from the new system, such as data conversion, functionality, compatibility, etc.
Comparing code between old and new systems is a possible way to obtain some assurance over the completeness and accuracy of loan application processing with respect to the implementation of a new system, but it is not the most effective one. Code is a set of instructions or commands that define how a system operates or functions. Comparing code between old and new systems can provide some assurance over the completeness and accuracy of loan application processing, by checking whether the logic, algorithms, or functions of the new system are consistent or equivalent with those of the old system. However, this may not be sufficient or reliable, as code may not reflect the actual performance or outcomes of the system, and may not detect any errors or issues that may occur at the data or user level. Reviewing quality assurance (QA) procedures is a possible way to obtain some assurance over the completeness and accuracy of loan application processing with respect to the implementation of a new system, but it is not the most effective one. QA procedures are steps or activities that ensure that a system meets its quality standards and requirements, such as testing, verification, validation, etc. Reviewing QA procedures can provide some assurance over the completeness and accuracy of loan application processing, by evaluating whether the new system has been properly tested and verified before implementation. However, this may not be adequate or accurate, as QA procedures may not cover all aspects or scenarios of loan application processing, and may not reveal any errors or issues that may arise after implementation. Loading balance and transaction data to the new system is a possible way to obtain some assurance over the completeness and accuracy of loan application processing with respect to the implementation of a new system, but it is not the most effective one. Balance and transaction data are data that reflect the status and history of loan applications in a system, such as amounts, dates, payments, etc. Loading balance and transaction data to the new system can provide some assurance over the completeness and accuracy of loan application processing, by transferring data from the old system to the new system and ensuring that they are consistent and correct. However, this may not be enough or valid, as balance and transaction data may not represent all aspects or features of loan application processing, and may not indicate any errors or issues that may arise
CISA-KR 문제 372
CISA-KR 문제 373
References
1: Balanced Scorecard - Overview, Four Perspectives 2: The IT Balanced Scorecard (BSC) Explained - BMC Software 3: A BALANCED SCORECARD (BSC) FOR IT PERFORMANCE MANAGEMENT - SAS Support
CISA-KR 문제 374
CISA-KR 문제 375
A role-based model can help prevent segregation of duties (SoD) issues in an ERP system by restricting user access to conflicting activities within the application. SoD is a central issue for enterprises to ensure compliance with laws and regulations, and to reduce the risk of fraud and unauthorized transactions3. SoD requires that no single individual or group of individuals should have control over two or more parts of a process or an asset3. For example, a user who can create and approve purchase orders should not be able to process payments or modify vendor records.
By using a role-based model, user access provisioning is based on the needs of a group (e.g., accounting department) based on common responsibilities and needs1. This means each role has a given set of permissions, and individuals can be assigned to one or more roles. For example, you may designate a user as an accounts payable clerk, an accounts receivable clerk, or a financial manager, and limit access to specific resources or tasks. The user-role and role-permissions relationships make it easy to perform role assignment because individual users no longer have unique access rights, rather they have privileges that conform to the permissions assigned to their specific role or job function1.
The other options are not the best way to prevent the misconfiguration from recurring. Monitoring access rights on a regular basis (option A) is a detective control that can help identify SoD issues after they occur, but it does not prevent them from happening in the first place. Referencing a standard user-access matrix (option B) is a tool that can help document and analyze user access rights, but it does not ensure that the user access rights are configured correctly or consistently. Correcting the segregation of duties conflicts (option D) is a corrective action that can resolve SoD issues once they are detected, but it does not prevent them from happening again.
References: 3: Implementing Segregation of Duties: A Practical Experience Based on Best Practices 1: What is Role-Based Access Control (RBAC)? Examples, Benefits, and More 2: What is Azure role-based access control (Azure RBAC)?
- 다른 버전
- 264ISACA.CISA-KR.v2026-08-15.q712
- 4293ISACA.CISA-KR.v2026-05-16.q709
- 1855ISACA.CISA-KR.v2026-05-06.q261
- 4721ISACA.CISA-KR.v2026-03-07.q651
- 9430ISACA.CISA-KR.v2025-04-07.q633
- 4539ISACA.CISA-KR.v2025-04-03.q628
- 3803ISACA.CISA-KR.v2025-04-02.q544
- 4308ISACA.CISA-KR.v2025-03-31.q534
- 5502ISACA.CISA-KR.v2025-03-28.q617
- 3303ISACA.CISA-KR.v2025-03-19.q581
- 4184ISACA.CISA-KR.v2025-03-03.q807
- 5242ISACA.CISA-KR.v2024-02-07.q421
- 2918ISACA.CISA-KR.v2024-01-31.q392
- 5427ISACA.CISA-KR.v2023-10-24.q329
- 5252ISACA.CISA-KR.v2023-07-31.q266
- 3253ISACA.CISA-KR.v2023-06-23.q324
- 최근 업로드
- 264ISACA.CISA-KR.v2026-08-15.q712
- 228Microsoft.MS-700-KR.v2026-08-15.q203
- 157Microsoft.AZ-305-KR.v2026-08-14.q177
- 227Microsoft.DP-900-KR.v2026-08-13.q130
- 295Microsoft.PL-600.v2026-08-11.q206
- 236Microsoft.DP-100.v2026-08-11.q160
- 196Oracle.1Z0-1048-25.v2026-08-11.q68
- 163ISQI.CTAL-TAE.v2026-08-11.q37
- 204ServiceNow.CIS-HR.v2026-08-11.q84
- 285Salesforce.Plat-Arch-201.v2026-08-10.q101
PDF 파일 다운로드
메일 주소를 입력하시고 다운로드 하세요. ISACA.CISA-KR.v2026-03-16.q665 모의시험 시험자료를 다운 받으세요.
