CISA-KR 문제 696
ISACA guidance notes that, when auditing policy documents, one of the quickest indicators of trouble is the absence of current reviews, changes, approvals, and alignment with actual practice. If policies are outdated, they may no longer reflect the organization's control environment, regulatory obligations, technologies, or business processes. That creates a direct governance and compliance risk.
Option A is generally a positive sign, not a concern, because formal review and approval supports governance. Option C can matter, but lack of direct mapping to best practices is usually less serious than having stale policies that no longer reflect reality. Option D is not ideal if policies exclude broader stakeholders, but IT policies are often primarily directed toward IT staff while still being supported by wider governance documents. The most serious issue is that outdated policies may be ineffective, unenforceable, or inconsistent with current controls.
References (Official ISACA):
* ISACA, Do Your Policy Documents Represent Current Practices?
* ISACA Journal, IS Audit Basics: The Auditors, IS/IT Policies and Compliance
CISA-KR 문제 697
Encrypting in-scope data sets can protect the confidentiality of the data, but not necessarily the integrity.
Encryption algorithms can be broken or bypassed by malicious actors, or encryption keys can be compromised or lost. Moreover, encryption adds overhead to the communication process and may affect the performance of the big data analytics system.
Running and comparing the count function within the in-scope data sets can only verify the number of records or elements in the data sets, but not the content or quality of the data. The count function cannot detect any changes or errors in the data values, such as missing, duplicated, corrupted, or manipulated data.
Hosting a digital certificate for in-scope data sets can provide authentication and non-repudiation for the data sources, but not integrity for the data itself. A digital certificate is a document that contains information about the identity and public key of an entity, such as a person, organization, or device. A digital certificate does not contain or verify the actual data that is communicated between production databases and a big data analytics system.
References:
Ensuring Data Integrity with Hash Codes
Database Security: An Essential Guide
Control methods of Database Security
CISA-KR 문제 698
CISA-KR 문제 699
To ensure that a DRP is effective, it should betested regularly and thoroughly to identify and resolve any issues or gaps that might hinder itsexecution2345. Testing a DRP can help evaluate its feasibility, validity, reliability, and compatibility with the organization's environment and needs4. Testing can also help prepare the staff, stakeholders, and vendors involved in the DRP for their roles and responsibilities during a disaster3.
There are different methods and levels of testing a DRP, depending on the scope, complexity, and objectives of the test4. Some of the common testing methods are:
Walkthrough testing: This is a step-by-step review of the DRP by the disaster recovery team and relevant stakeholders. It aims to verify the completeness and accuracy of the plan, as well as to clarify any doubts or questions among the participants45.
Simulation testing: This is a mock exercise of the DRP in a simulated disaster scenario. It aims to assess the readiness and effectiveness of the plan, as well as to identify any challenges or weaknesses that might arise during a real disaster45.
Checklist testing: This is a verification of the availability and functionality of the resources and equipment required for the DRP. It aims toensure that the backup systems, data, anddocumentation are accessible and up- to-date45.
Full interruption testing: This is the most realistic and rigorous method of testing a DRP. It involves shutting down the primary site and activating the backup site for a certain period of time. It aims to measure the actual impact andperformance of the DRP under real conditions45.
Parallel testing: This is a less disruptive method of testing a DRP. It involves running the backup site in parallel with the primary site without affecting the normal operations. It aims to compare and validate the results and outputs of both sites45.
Amongthese methods, full interruption testing would best demonstrate that an effectiveDRP is in place, as it provides the most accurate and comprehensive evaluation ofthe plan's capabilities and limitations4. Full interruption testing can reveal any hidden or unforeseen issues or risks that might affect the recovery process, such as data loss, system failure, compatibility problems, or human errors4. Full interruption testing can also verify that the backup site can support the critical operations and services ofthe organization without compromising its quality or security4.
However, full interruption testing also has some drawbacks, such as being costly, time-consuming, risky, and disruptive to the normaloperations4. Therefore, it should be planned carefullyand conducted periodically with proper coordination and communication among all parties involved4.
The other options are not as effective as full interruption testing in demonstrating that an effective DRP is in place. Frequent testing of backups is only one aspect of checklist testing, which does not cover other components or scenarios of the DRP4. Annual walk-through testing is only atheoretical review of the DRP, which does not test its practical implementation or outcomes4. Periodic risk assessment is only a preparatory step for developing or updating the DRP, which does not test its functionality or performance4.
References: 2: Best Practices For Disaster Recovery Testing | Snyk 3: Disaster Recovery Plan (DR) Testing
- Methods and Must-haves -US Signal 4: Disaster Recovery Testing: What You Need toKnow - Enterprise Storage Forum 5: Disaster Recovery Testing Best Practices - MSP360 1: How to Test a Disaster Recovery Plan - Abacus
CISA-KR 문제 700
The other options are not the primary purpose of performing a parallel run of a new system. A. To train the end users and supporting staff on the new system. Training is an important part of system implementation, but it is not the main reason for doing a parallel run. Training can be done before, during, or after the parallel run, depending on the needs and preferences of the organization. B. To verify the new system provides required business functionality. Verifying the business functionality of the new system is part of user acceptance testing (UAT), which is a formal and structured process of testing whether the new system meets the specifications and expectations of the users and stakeholders. UAT is usually done before the parallel run, as a prerequisite for system changeover. C. To reduce the need for additional testing. Reducing the need for additional testing is not the primary purpose of performing a parallel run, but rather a possible benefit or outcome of doing so. A parallel run can help ensure that the new system is thoroughly tested and validated in a real-worldenvironment, which may reduce the likelihood of encountering major issues or defects later on.
However, additional testing may still be needed after the parallel run, depending on the feedback and evaluation of the users and stakeholders.
References:
ISACA, CISA Review Manual, 27th Edition, 2019, p. 2471
IS
- 다른 버전
- 1743ISACA.CISA-KR.v2026-05-06.q261
- 3091ISACA.CISA-KR.v2026-03-16.q665
- 4441ISACA.CISA-KR.v2026-03-07.q651
- 9177ISACA.CISA-KR.v2025-04-07.q633
- 4433ISACA.CISA-KR.v2025-04-03.q628
- 3633ISACA.CISA-KR.v2025-04-02.q544
- 4190ISACA.CISA-KR.v2025-03-31.q534
- 5298ISACA.CISA-KR.v2025-03-28.q617
- 3068ISACA.CISA-KR.v2025-03-19.q581
- 3954ISACA.CISA-KR.v2025-03-03.q807
- 5041ISACA.CISA-KR.v2024-02-07.q421
- 2790ISACA.CISA-KR.v2024-01-31.q392
- 5260ISACA.CISA-KR.v2023-10-24.q329
- 5159ISACA.CISA-KR.v2023-07-31.q266
- 3091ISACA.CISA-KR.v2023-06-23.q324
- 최근 업로드
- 216Microsoft.PL-600.v2026-08-11.q206
- 153Microsoft.DP-100.v2026-08-11.q160
- 155Oracle.1Z0-1048-25.v2026-08-11.q68
- 130ISQI.CTAL-TAE.v2026-08-11.q37
- 171ServiceNow.CIS-HR.v2026-08-11.q84
- 254Salesforce.Plat-Arch-201.v2026-08-10.q101
- 240Databricks.Databricks-Machine-Learning-Professional.v2026-08-10.q76
- 189F5.F5CAB2.v2026-08-10.q41
- 285APA.CPP-Remote.v2026-08-08.q109
- 149SAP.C_BCBAI_2601.v2026-08-08.q9
PDF 파일 다운로드
메일 주소를 입력하시고 다운로드 하세요. ISACA.CISA-KR.v2026-05-16.q709 모의시험 시험자료를 다운 받으세요.
