CISA-KR 문제 691
Option D is correct because without documented assumptions and formulas, neither management nor the auditor can effectively understand how the AI system reaches conclusions, validate whether it is working as intended, assess bias or error, or confirm whether controls are adequate. ISACA's AI-related guidance highlights that assumptions embedded in AI systems must be examined because changing environments, unreliable data, or hidden logic can create serious control weaknesses.
Option A is not the greatest concern by itself. Outsourcing development to vendors may introduce third-party risk, but vendor use is common and can be controlled through contracts, review, validation, and oversight.
The mere fact of outsourcing does not create as severe a control weakness as undocumented decision logic.
Option B is a potential concern because annual review might be too infrequent depending on the system's risk and rate of change. However, even with infrequent review, the organization would still have documented policy and decision logic to examine. A complete lack of documentation of assumptions and formulas is more serious because it prevents meaningful review altogether.
Option C is also a concern, but vendor maintenance access can be managed through access controls, logging, approvals, segregation, and monitoring. Access by contracted developers is not inherently unacceptable. The more fundamental weakness is the absence of documented logic foundations, which affects governance and auditability at the core.
Therefore, the greatest concern is D because undocumented assumptions and formulas make the AI system insufficiently transparent and far harder to audit, validate, and control.
References (Official ISACA):
* ISACA Journal, AI Risk and Mitigation: Tips and Tricks for Auditing in the AI Era - stresses questioning assumptions and identifying taken-for-granted conditions in AI systems.
* ISACA Journal, Algorithms and the Auditor - supports the auditor's role in questioning algorithmic reliability and possible errors.
* ISACA White Paper, Leveraging COBIT for Effective AI System Governance - highlights risk assessment and governance throughout the AI life cycle.
CISA-KR 문제 692
The chain of custody ensures that the evidence is authentic, reliable, andtrustworthy, and that it has not been tampered with or altered. The person who collected the evidence, whether qualified or not, is not relevant to the admissibility of the evidence, as long as they followed the proper procedures and protocols. The evidence collected by the internal forensics team can be admissible in court, as long as they are independent, objective, and competent. The evidence does not need to be fully backed up using a cloud-based solution prior to the trial, as long as it is preserved and protected from damage or loss. References: ISACA Journal Article: Digital Forensics: Chain of Custody
CISA-KR 문제 693
References
1: The Business Case for Security - CISA
2: Beyond the Business Case: New Approaches to IT Investment
3: #HowTo: Build a Business Case for Cybersecurity Investment
4: ISACA CISA Certified Information Systems Auditor Exam ... - PUPUWEB
5: The Business Case for Security | CISA
CISA-KR 문제 694
A virtual firewall is a software-based firewall that protects a virtual network or environment from unauthorized access and malicious attacks. A virtualfirewall can enhance the security of the agency's network, but it does not improve the performance of its servers.
A proxy server is an intermediary server that acts as a gateway between the client and the destination server, hiding the client's IP address and providing caching and filtering functions. A proxy server can improve the security and privacy of the agency's network, but it does not improve the performance of its servers.
A virtual private network (VPN) is a secure connection between two or more devices over a public network, such as the internet. A VPN can encrypt and protect the data transmitted over the network, but it does not improve the performance of the agency's servers.
CISA-KR 문제 695
Crawlers for Sensitive Data (Option B):While crawlers may pose a performance impact, they are essential for discovering sensitive data.
Deep Packet Inspection (Option C):Though it introduces privacy considerations, it is a standard DLP functionality for inspecting data in transit.
Encryption Key Management (Option D):While important for security, improper management does not immediately prevent DLP functionality.
Reference:ISACA CISA Review Manual, Job Practice Area 4: Protection of Information Assets.
- 다른 버전
- 1793ISACA.CISA-KR.v2026-05-06.q261
- 3108ISACA.CISA-KR.v2026-03-16.q665
- 4473ISACA.CISA-KR.v2026-03-07.q651
- 9201ISACA.CISA-KR.v2025-04-07.q633
- 4444ISACA.CISA-KR.v2025-04-03.q628
- 3648ISACA.CISA-KR.v2025-04-02.q544
- 4215ISACA.CISA-KR.v2025-03-31.q534
- 5319ISACA.CISA-KR.v2025-03-28.q617
- 3146ISACA.CISA-KR.v2025-03-19.q581
- 3968ISACA.CISA-KR.v2025-03-03.q807
- 5129ISACA.CISA-KR.v2024-02-07.q421
- 2793ISACA.CISA-KR.v2024-01-31.q392
- 5262ISACA.CISA-KR.v2023-10-24.q329
- 5209ISACA.CISA-KR.v2023-07-31.q266
- 3099ISACA.CISA-KR.v2023-06-23.q324
- 최근 업로드
- 143Microsoft.DP-900-KR.v2026-08-13.q130
- 244Microsoft.PL-600.v2026-08-11.q206
- 183Microsoft.DP-100.v2026-08-11.q160
- 177Oracle.1Z0-1048-25.v2026-08-11.q68
- 145ISQI.CTAL-TAE.v2026-08-11.q37
- 195ServiceNow.CIS-HR.v2026-08-11.q84
- 258Salesforce.Plat-Arch-201.v2026-08-10.q101
- 244Databricks.Databricks-Machine-Learning-Professional.v2026-08-10.q76
- 192F5.F5CAB2.v2026-08-10.q41
- 298APA.CPP-Remote.v2026-08-08.q109
PDF 파일 다운로드
메일 주소를 입력하시고 다운로드 하세요. ISACA.CISA-KR.v2026-05-16.q709 모의시험 시험자료를 다운 받으세요.
