CISA-KR 문제 541
ISACA guidance describes enterprise architecture as a top-down, business-driven discipline focused on business capabilities, strategy, and alignment of people, process, and technology. Enterprise architecture is not primarily about individual systems or day-to-day operations. Its purpose is to ensure that change initiatives and IT investments are organized in a way that supports the enterprise's strategic and business outcomes.
Option A is too narrow because EA is broader than designing single systems. Option B is only one specialized area within the overall architecture landscape. Option C is more aligned with operations management than enterprise architecture. The strongest answer is the one linking EA to business-driven structuring of initiatives and results.
Therefore, the correct answer is D, because enterprise architecture exists to align and structure IT initiatives so the organization can achieve desired business results.
References (Official ISACA):
* ISACA, Developing Business Capabilities Using COBIT 5 - enterprise architecture focuses on business capabilities supporting strategy.
* ISACA Journal, Enterprise Security Architecture-A Top-down Approach - architecture bridges business risk, process requirements, and technical issues.
* ISACA Journal, Information Security Architecture: Gap Assessment and Prioritization - supports business-driven architectural alignment.
* ISACA, Using COBIT 2019 to Plan and Execute an Organization Transformation Strategy - IT governance and management should create value from IT initiatives.
CISA-KR 문제 542
Materiality is the degree to which an omission or misstatement of information could affect the users' decisions or the achievement of the audit objectives. By applying the concept of materiality, the auditor can focus on the most significant and relevant areas of the audit and avoid wasting time and effort on trivial or immaterial matters. The other options are not as important as planning an audit engagement, because they are either based on or affected by the materiality assessment done during the planning phase. References:
ISACA, CISA Review Manual, 27th Edition, chapter 1, section 1.31
ISACA, IT Audit and Assurance Standards, Guidelines and Tools and Techniques forIS Audit and Assurance Professionals, section 12022
CISA-KR 문제 543
One of the possible charging methods is to charge specific costs that can be tied back to specific usage. This means that the IS function tracks and measures the actual consumption of each user or business unit for each IS service, and charges them accordingly. For example, if a user uses 10 GB of storage space, 5 hours of CPU time, and 100 MB of network bandwidth, the IS function will charge them based on the unit costs of these resources. This charging method has the advantage of encouraging the most efficient use of IS resources, as it provides clear and accurate feedback to the users about their consumption and costs, and motivates them to optimize their usage and avoid waste or overuse. This charging method also aligns the interests of the IS function and the users, as both parties benefit from reducing costs and improving efficiency.
The other possible charging methods are:
Total utilization to achieve full operating capacity: This means that the IS function charges a fixed amount to each user or business unit based on their proportion of the total operating capacity of the IS resources. For example, if a user or business unit has 10% of the total computing power allocated to them, they will pay 10% of the total IS costs. This charging method has the disadvantage of discouraging efficient use of IS resources, as it does not reflect the actual consumption or usage of each user or business unit, and does not provide any incentive to reduce costs or improve efficiency. This charging method also creates a mismatch between the interests of the IS function and the users, as the IS function benefits from increasing costs and capacity, while the users bear the burden of paying for them.
Residual income in excess of actual incurred costs: This means that the IS function charges a markup or profit margin on top of its actual incurred costs to each user or business unit.For example, if a user or business unit consumes $100 worth of IS resources, the IS function will charge them $120, where $20 is the residual income for the IS function. This charging method has the disadvantage of discouraging efficient use of IS resources, as it increases the costs for the users and reduces their value for money. This charging method also creates a conflict between the interests of the IS function and the users, as the IS function benefits from increasing costs and profits, while the users suffer from paying more than they should.
Allocations based on the ability to absorb charges: This means that the IS function charges different amounts to different users or business units based on their ability to pay or their profitability. For example, if a user or business unit is more profitable or has a higher budget than another user or business unit, they will pay more for the same amount of IS resources. This charging method has the disadvantage of discouraging efficient use of IS resources, as it does not reflect the actual consumption or usage of each user or business unit, and does not provide any incentive to reduce costs or improve efficiency. This charging method also creates an unfair and arbitrary distribution of costs among the users or business units, as some paymore than others for no valid reason. References: 1: Charging Methods for IT Services - IT Process Wiki 2: IT Chargeback Methods - CIO Wiki 3: IT Chargeback - Wikipedia
CISA-KR 문제 544
No Policy to Revoke Access (Correct Answer - A)
A terminated employee retaining access can lead todata breaches or insider threats.
Example:A former employee misuses active credentials to access financial systems.
Lack of Security Awareness Training (Incorrect - B)
Important but does not pose an immediate security risk like an active ex-employee account.
No NDAs (Incorrect - C)
Protects intellectual property but is not as critical as system access.
No Access Revocation for Role Changes (Incorrect - D)
Still a concern, but ex-employees with active access are ahigherrisk.
References:
ISACA CISA Review Manual
NIST 800-53 (Access Control)
CISA-KR 문제 545
- 다른 버전
- 209ISACA.CISA-KR.v2026-08-15.q712
- 1823ISACA.CISA-KR.v2026-05-06.q261
- 3166ISACA.CISA-KR.v2026-03-16.q665
- 4568ISACA.CISA-KR.v2026-03-07.q651
- 9334ISACA.CISA-KR.v2025-04-07.q633
- 4483ISACA.CISA-KR.v2025-04-03.q628
- 3724ISACA.CISA-KR.v2025-04-02.q544
- 4255ISACA.CISA-KR.v2025-03-31.q534
- 5401ISACA.CISA-KR.v2025-03-28.q617
- 3250ISACA.CISA-KR.v2025-03-19.q581
- 4055ISACA.CISA-KR.v2025-03-03.q807
- 5218ISACA.CISA-KR.v2024-02-07.q421
- 2871ISACA.CISA-KR.v2024-01-31.q392
- 5388ISACA.CISA-KR.v2023-10-24.q329
- 5229ISACA.CISA-KR.v2023-07-31.q266
- 3228ISACA.CISA-KR.v2023-06-23.q324
- 최근 업로드
- 209ISACA.CISA-KR.v2026-08-15.q712
- 156Microsoft.MS-700-KR.v2026-08-15.q203
- 126Microsoft.AZ-305-KR.v2026-08-14.q177
- 188Microsoft.DP-900-KR.v2026-08-13.q130
- 279Microsoft.PL-600.v2026-08-11.q206
- 218Microsoft.DP-100.v2026-08-11.q160
- 187Oracle.1Z0-1048-25.v2026-08-11.q68
- 159ISQI.CTAL-TAE.v2026-08-11.q37
- 200ServiceNow.CIS-HR.v2026-08-11.q84
- 275Salesforce.Plat-Arch-201.v2026-08-10.q101
PDF 파일 다운로드
메일 주소를 입력하시고 다운로드 하세요. ISACA.CISA-KR.v2026-05-16.q709 모의시험 시험자료를 다운 받으세요.
