CISA-KR 문제 571
Option D is correct because independently performing manual procedures gives the auditor direct control over the evidence-gathering process and reduces reliance on the auditee or control owner. In audit theory and in ISACA-aligned practice, evidence obtained directly by the auditor is generally more reliable than evidence merely provided by the auditee.
Option A is strong evidence because it comes from an independent third party, but it is still inspected rather than generated directly by the auditor. It is generally very reliable, but not as strong as auditor-generated evidence through independent reperformance.
Option B is less reliable because system-generated evidence provided by a control owner still depends on the completeness and integrity of what was selected and presented by the auditee.
Option C is the least reliable among the plausible choices because critical data received from an auditee is subject to the greatest dependence on management representation and auditee-controlled extraction.
Therefore, D is the best answer because evidence generated through procedures performed independently by the auditor is the most reliable.
References (Official ISACA):
* ISACA Journal, Capability Maturity Model and Risk Register Integration - "evidence is produced directly by the auditors or, if strictly under the auditors' control, by the entity's staff."
* ISACA Journal, A Factory Model Approach to Technology Control Testing - emphasizes gathering evidence, analyzing it, and substantiating results within a governed testing process.
* ISACA, ITAF update announcement - confirms ITAF as ISACA's professional framework for audit standards and guidance.
CISA-KR 문제 572
CISA-KR 문제 573
CISA-KR 문제 574
CISA-KR 문제 575
Option C is therefore the best answer because a privacy policy's core purpose is not just technical protection, but ensuring that employees understand the legal and regulatory requirements governing personal information. ISACA notes that modern privacy programs are strongly shaped by regulations such as GDPR and similar laws, which impose explicit obligations on organizations that collect and process personal data. A privacy protection policy helps communicate those obligations internally.
Option A is incorrect because cybercrime awareness belongs more to a general information security awareness program than to the primary purpose of a privacy protection policy. Privacy and cybersecurity overlap, but privacy policy is specifically about lawful and proper handling of personal information, not general awareness of network-targeting crimes.
Option B is incorrect because encryption is only one possible control for protecting personal data. A privacy policy may mention encryption, but its primary purpose is broader: defining privacy obligations, rights, responsibilities, and compliance expectations. Technical controls support the policy; they are not the policy's central awareness objective.
Option D is also incorrect because system configuration procedures belong to technical standards, baselines, or operating procedures. A privacy protection policy is a governance-level document that sets expectations regarding personal information protection and legal compliance, rather than detailing system configuration steps.
For CISA-style reasoning, when a question asks for the primary objective of a privacy policy, the best answer is the one that addresses the organization's obligation to protect personal data in accordance with legal requirements. That makes C the strongest and most defensible answer.
References (Official ISACA):
* ISACA Privacy Resource Center - privacy guidance focused on compliance and privacy program obligations.
* ISACA, The Evolving World of Data Privacy: Trends and Strategies - discusses legal obligations such as GDPR requirements for personal data protection.
* ISACA Privacy Notice - reflects the role of applicable law in handling personal data.
* ISACA Journal, Creating a Compliant and Accountable Data Culture - emphasizes accountability and compliance in data privacy.
- 다른 버전
- 208ISACA.CISA-KR.v2026-08-15.q712
- 1823ISACA.CISA-KR.v2026-05-06.q261
- 3165ISACA.CISA-KR.v2026-03-16.q665
- 4558ISACA.CISA-KR.v2026-03-07.q651
- 9324ISACA.CISA-KR.v2025-04-07.q633
- 4478ISACA.CISA-KR.v2025-04-03.q628
- 3720ISACA.CISA-KR.v2025-04-02.q544
- 4253ISACA.CISA-KR.v2025-03-31.q534
- 5394ISACA.CISA-KR.v2025-03-28.q617
- 3250ISACA.CISA-KR.v2025-03-19.q581
- 4053ISACA.CISA-KR.v2025-03-03.q807
- 5218ISACA.CISA-KR.v2024-02-07.q421
- 2871ISACA.CISA-KR.v2024-01-31.q392
- 5388ISACA.CISA-KR.v2023-10-24.q329
- 5229ISACA.CISA-KR.v2023-07-31.q266
- 3228ISACA.CISA-KR.v2023-06-23.q324
- 최근 업로드
- 208ISACA.CISA-KR.v2026-08-15.q712
- 155Microsoft.MS-700-KR.v2026-08-15.q203
- 126Microsoft.AZ-305-KR.v2026-08-14.q177
- 186Microsoft.DP-900-KR.v2026-08-13.q130
- 279Microsoft.PL-600.v2026-08-11.q206
- 218Microsoft.DP-100.v2026-08-11.q160
- 187Oracle.1Z0-1048-25.v2026-08-11.q68
- 159ISQI.CTAL-TAE.v2026-08-11.q37
- 200ServiceNow.CIS-HR.v2026-08-11.q84
- 275Salesforce.Plat-Arch-201.v2026-08-10.q101
PDF 파일 다운로드
메일 주소를 입력하시고 다운로드 하세요. ISACA.CISA-KR.v2026-05-16.q709 모의시험 시험자료를 다운 받으세요.
