CISA-KR 문제 666
Jobs are scheduled to be completed daily and data is transmitted using a Secure File Transfer Protocol (SFTP) is a preventive control that can help ensure the timeliness and security of the job scheduling process involving data transmission, but it does not detect any issues or anomalies that may occur during the process. Jobs are scheduled and a log of this activity is retained for subsequent review is a logging technique that can help record and track the status and results of the job scheduling process involving data transmission, but it does not provide real-time or proactive information on job failures. References: CISA Review Manual (Digital Version), Chapter 3, Section 3.2
CISA-KR 문제 667
A system-generated list of staff and their project assignments, roles, and responsibilities can help the IS auditor to perform the following tasks:
Identify the users who have access to the document management system and their level of access (e.g., read- only, edit, delete, etc.).
Compare the actual access rights of the users with their expected or authorized access rights based on their roles and responsibilities.
Detect any anomalies, discrepancies, or violations in the access rights of the users, such as excessive or unauthorized access, segregation of duties conflicts, or dormant or inactive accounts.
Evaluate the effectiveness and efficiency of the access control policies and procedures, such as user provisioning, deprovisioning, authentication, authorization, auditing, etc.
The other options are not as useful as option B. Policies and procedures for managing documents provided by department heads (option A) are not reliable sources of information for an IS auditor because they may not reflect the actual practices or compliance status of the document management system. Previous audit reports related to other departments' use of the same system (option C) are not relevant for an IS auditor because they may not address the specific issues or risks associatedwith the current department's use of the document management system. Information provided by the audit team lead on the authentication systems used by the department (option D) is not sufficient for an IS auditor because authentication is only one aspect of access control and it does not provide information on the authorization or auditing of the document access.
References:
Overview of document management in SharePoint
Setting Up a Document Control System: 6 Basic Steps
Access Control Management: Purpose, Types,Tools, and Benefits
9 Best Document Management Systems of 2023
CISA-KR 문제 668
CISA-KR 문제 669
다음 중 감사인의 독립성을 저해하는 것은 무엇입니까?
Designing audit modules (D) is also permissible since they are for audit use and do not affect operational processes. ISACA's Code of Professional Ethics and IS Audit Standards emphasize independence and objectivity as fundamental requirements to maintain credibility and avoid conflicts of interest.
References (ISACA): ISACA Standards for IS Audit and Assurance; ISACA Code of Professional Ethics.
CISA-KR 문제 670
Complex password policy for mobile devices, triggering of remote data wipe capabilities, and awareness training for mobile device users are useful measures to enhance data security on mobile devices, but they do not prevent data leakage as effectively as data encryption. A complex password policy can be bypassed by brute force attacks or password cracking tools. Remote data wipe capabilities depend on network connectivity and device power availability. Awareness training for mobile device users can reduce human errors or negligence, but it cannot guarantee compliance or behavior change. References: CISA Review Manual (Digital Version): Chapter 5 - Information Systems Operations and Business Resilience
- 다른 버전
- 1793ISACA.CISA-KR.v2026-05-06.q261
- 3108ISACA.CISA-KR.v2026-03-16.q665
- 4473ISACA.CISA-KR.v2026-03-07.q651
- 9201ISACA.CISA-KR.v2025-04-07.q633
- 4444ISACA.CISA-KR.v2025-04-03.q628
- 3649ISACA.CISA-KR.v2025-04-02.q544
- 4215ISACA.CISA-KR.v2025-03-31.q534
- 5320ISACA.CISA-KR.v2025-03-28.q617
- 3146ISACA.CISA-KR.v2025-03-19.q581
- 3968ISACA.CISA-KR.v2025-03-03.q807
- 5129ISACA.CISA-KR.v2024-02-07.q421
- 2793ISACA.CISA-KR.v2024-01-31.q392
- 5262ISACA.CISA-KR.v2023-10-24.q329
- 5209ISACA.CISA-KR.v2023-07-31.q266
- 3099ISACA.CISA-KR.v2023-06-23.q324
- 최근 업로드
- 143Microsoft.DP-900-KR.v2026-08-13.q130
- 244Microsoft.PL-600.v2026-08-11.q206
- 183Microsoft.DP-100.v2026-08-11.q160
- 177Oracle.1Z0-1048-25.v2026-08-11.q68
- 145ISQI.CTAL-TAE.v2026-08-11.q37
- 195ServiceNow.CIS-HR.v2026-08-11.q84
- 258Salesforce.Plat-Arch-201.v2026-08-10.q101
- 244Databricks.Databricks-Machine-Learning-Professional.v2026-08-10.q76
- 192F5.F5CAB2.v2026-08-10.q41
- 298APA.CPP-Remote.v2026-08-08.q109
PDF 파일 다운로드
메일 주소를 입력하시고 다운로드 하세요. ISACA.CISA-KR.v2026-05-16.q709 모의시험 시험자료를 다운 받으세요.
