CISA-KR 문제 81
CISA-KR 문제 82
An integrated audit combines IT, operational, and financial audits into a single coordinated review. The primary benefit is the optimization of audit efforts across functions, eliminating duplication and providing a holistic risk perspective.
Option A: QA enhancement is a byproduct but not the primary benefit.
Option C: Skills improvement occurs, but it's not the main objective.
Option D: Applicability to different areas is true, but not the primary benefit.
# ISACA Reference: CISA Review Manual 27th Edition, Domain 1, section on integrated audit benefits and efficiencies.
CISA-KR 문제 83
Therefore, the observation that post-implementation testing is not conducted for all system releases should be of greatest concern to an IS auditor performing an audit of change and release management controls for a new complex system developed by a small in-house IT team. This observation indicates that the system may have quality, reliability, or security problems that could affect the user satisfaction, system performance, or data integrity. This observation also suggests that the change and release management controls are not adequate or effective, as they do not ensure that all system releases are properly tested and validated before and after deployment.
Option A is not correct because access to change testing strategy and results is not restricted to staff outside the IT team is not a major concern for an IS auditor. While it is good practice to limit access to sensitive or confidential information, such as test data or test cases, to authorized personnel only, access to change testing strategy and results may not pose a significant risk to the system or the organization. Moreover, access to change testing strategy and results may be beneficial for some stakeholders outside the IT team, such as business users, project managers, or auditors, who may need to review or evaluate the testing process or outcomes.
Option B is not correct because some user acceptance testing (UAT) was completed by members of the IT team is not a major concern for an IS auditor. User acceptance testing is the process of verifying and validating that the system meets the user requirements and expectations by involving actual or representative users in the testing process3. While it is preferable to have independent and unbiased users perform UAT, it may not be feasible or practical for some organizations, especially those with small or limited resources.
Therefore, some UAT may be completed by members of the IT team, as long as they have sufficient knowledge and experience of the user needs and expectations, and as long as they follow the UAT plan and criteria.
Option C is not correct because IT administrators have access to the production and development environment is not a major concern for an IS auditor. IT administrators are responsible for managing and maintaining the IT infrastructure, including the production and development environments4. Therefore, it is reasonable and necessary for them to have access to both environments, as long as they follow the appropriate policies and procedures for accessing, using, and securing them. Moreover, IT administrators may need to perform tasks such as backup, restore, patching, or troubleshooting in both environments.
References:
What Is Post Implementation Testing?1
Post Implementation Review (PIR) - Definition and Process2
User Acceptance Testing (UAT): Definition and Examples3
What Is an IT Administrator? Definition and Examples4
CISA-KR 문제 84
The other options are not as good as option B, as they may not capture the full scope or benefits of using an IT governance framework. Frameworks enable IT benchmarks against competitors, but this is not the main purpose or advantage of using an IT governance framework. Frameworks help facilitate control self- assessments (CSAs), but this is only one aspect or tool of an IT governance framework. Frameworks help organizations understand and manage IT risk, but this is also only one outcome or objective of an IT governance framework.
References:
1: What is ITIL? Your guide to the IT Infrastructure Library | CIO
2: IT Governance Framework | Components | Framework | Terminology - EDUCBA
3: IT Governance: Definitions, Frameworks and Planning - ProjectManager
4: What Is IT Governance? - Definition from Techopedia
5: What is IT Governance? A formal way to align IT and business strategy | CIO
6: What Is IT Governance? - Definition from WhatIs.com
7: ISO/IEC 20000 Information Technology Service Management Systems Standard - ISO/IEC 20000 Portal
8: COBIT | Control Objectives for Information Technologies | ISACA
CISA-KR 문제 85
- 다른 버전
- 1797ISACA.CISA-KR.v2026-05-06.q261
- 3118ISACA.CISA-KR.v2026-03-16.q665
- 4487ISACA.CISA-KR.v2026-03-07.q651
- 9212ISACA.CISA-KR.v2025-04-07.q633
- 4451ISACA.CISA-KR.v2025-04-03.q628
- 3673ISACA.CISA-KR.v2025-04-02.q544
- 4221ISACA.CISA-KR.v2025-03-31.q534
- 5320ISACA.CISA-KR.v2025-03-28.q617
- 3151ISACA.CISA-KR.v2025-03-19.q581
- 3977ISACA.CISA-KR.v2025-03-03.q807
- 5133ISACA.CISA-KR.v2024-02-07.q421
- 2815ISACA.CISA-KR.v2024-01-31.q392
- 5270ISACA.CISA-KR.v2023-10-24.q329
- 5215ISACA.CISA-KR.v2023-07-31.q266
- 3116ISACA.CISA-KR.v2023-06-23.q324
- 최근 업로드
- 115Microsoft.AZ-305-KR.v2026-08-14.q177
- 155Microsoft.DP-900-KR.v2026-08-13.q130
- 244Microsoft.PL-600.v2026-08-11.q206
- 183Microsoft.DP-100.v2026-08-11.q160
- 177Oracle.1Z0-1048-25.v2026-08-11.q68
- 145ISQI.CTAL-TAE.v2026-08-11.q37
- 195ServiceNow.CIS-HR.v2026-08-11.q84
- 259Salesforce.Plat-Arch-201.v2026-08-10.q101
- 245Databricks.Databricks-Machine-Learning-Professional.v2026-08-10.q76
- 192F5.F5CAB2.v2026-08-10.q41
PDF 파일 다운로드
메일 주소를 입력하시고 다운로드 하세요. ISACA.CISA-KR.v2026-05-16.q709 모의시험 시험자료를 다운 받으세요.
