CISA-KR 문제 496
CISA Review Manual, 27th Edition, page 2951
CISA Review Questions, Answers and Explanations Database - 12 Month Subscription
CISA-KR 문제 497
A). The BCP's contact information needs to be updated is not a great concern for an IS auditor reviewing an organization's BCP, as it is a minor issue that can be easily fixed. Contact information refers to the names, phone numbers, email addresses, or other details of the people involved in the BCP execution or communication. Contact information needs to be updated regularly to reflect any changes in personnel or roles. While having outdated contact information may cause some delays or confusion during a BCP activation, it does not affect the overall validity or effectiveness of the BCP.
B). The BCP is not version controlled is not a great concern for an IS auditor reviewing an organization's BCP, as it is a moderate issue that can be improved. Version control refers to the process of tracking and managing changes made to the BCP over time. Version control helps to ensure that only authorized changes are made to the BCP and that there is a clear record of who made what changes when and why. Version control also helps to avoid conflicts or inconsistencies among different versions of the BCP. While having no version control may cause some difficulties or risks in maintaining and updating the BCP, it does not affect the overall validity or effectiveness of the BCP.
C). The BCP has not been approved by senior management is not a great concern for an IS auditor reviewing an organization's BCP, as it is a high-level issue that can be resolved. Approval by senior management refers to the formal endorsement and support of the BCP by the top executives or leaders of the organization.
Approval by senior management helps to ensure that the BCP is aligned with the organization's strategy, objectives, and priorities, and that it has sufficient resources and authority to be implemented. Approval by senior management also helps to increase the awareness and commitment of the organization's stakeholders to the BCP. While having no approval by senior management may affect the credibilityand acceptance of the BCP, it does not affect the overall validity or effectiveness of the BCP. References: Working Toward a Managed, Mature Business Continuity Plan - ISACA, ISACA Introduces New Audit Programs for Business Continuity/Disaster ..., Disaster Recovery and Business Continuity Preparedness for Cloud-based ...
CISA-KR 문제 498
Data Owner (Correct Answer - B)
The data owner is responsible forsetting user permissionsbased on job roles and business requirements.
According toISACA's CISA Review Manual and COBIT 2019, the data owner determines access levels while IT personnel enforce them.
Example:A finance department head (data owner) determines that only certain accountants should access sensitive payroll data.
IT Operations Manager (Incorrect - A)
Oversees IT infrastructure but does not define data access controls.
Database Administrator (DBA) (Incorrect - C)
Implements and enforces security settings but follows rules set by the data owner.
Information Security Manager (Incorrect - D)
Provides security guidance but does not decide specific access permissions.
References:
ISACA CISA Review Manual
COBIT 2019 Framework
NIST 800-53 (Security and Privacy Controls for Federal Information Systems)
CISA-KR 문제 499
CISA-KR 문제 500
Buffer overflow, denial of service (DoS), and phishing are not directly related to the validation controls in a web application. Buffer overflow is a type of attack that exploits a memory management flaw in an application or system that allows an attacker to write data beyond the allocated buffer size and overwrite adjacent memory locations. DoS is a type of attack that prevents legitimate users from accessing a service or resource by overwhelming it with requests or traffic. Phishing is a type of attack that uses fraudulent emails or websites to trick users into revealing sensitive information or installing malware.
References:
Client-side form validation - Learn web development | MDN
JavaScript: client-side vs. server-side validation - Stack Overflow
SQL Injection - OWASP
- 다른 버전
- 221ISACA.CISA-KR.v2026-08-15.q712
- 1823ISACA.CISA-KR.v2026-05-06.q261
- 3182ISACA.CISA-KR.v2026-03-16.q665
- 4608ISACA.CISA-KR.v2026-03-07.q651
- 9336ISACA.CISA-KR.v2025-04-07.q633
- 4488ISACA.CISA-KR.v2025-04-03.q628
- 3724ISACA.CISA-KR.v2025-04-02.q544
- 4266ISACA.CISA-KR.v2025-03-31.q534
- 5416ISACA.CISA-KR.v2025-03-28.q617
- 3252ISACA.CISA-KR.v2025-03-19.q581
- 4057ISACA.CISA-KR.v2025-03-03.q807
- 5218ISACA.CISA-KR.v2024-02-07.q421
- 2871ISACA.CISA-KR.v2024-01-31.q392
- 5388ISACA.CISA-KR.v2023-10-24.q329
- 5230ISACA.CISA-KR.v2023-07-31.q266
- 3229ISACA.CISA-KR.v2023-06-23.q324
- 최근 업로드
- 221ISACA.CISA-KR.v2026-08-15.q712
- 165Microsoft.MS-700-KR.v2026-08-15.q203
- 130Microsoft.AZ-305-KR.v2026-08-14.q177
- 189Microsoft.DP-900-KR.v2026-08-13.q130
- 280Microsoft.PL-600.v2026-08-11.q206
- 218Microsoft.DP-100.v2026-08-11.q160
- 187Oracle.1Z0-1048-25.v2026-08-11.q68
- 159ISQI.CTAL-TAE.v2026-08-11.q37
- 200ServiceNow.CIS-HR.v2026-08-11.q84
- 279Salesforce.Plat-Arch-201.v2026-08-10.q101
PDF 파일 다운로드
메일 주소를 입력하시고 다운로드 하세요. ISACA.CISA-KR.v2026-05-16.q709 모의시험 시험자료를 다운 받으세요.
