CISA-KR 문제 191
Inadequate or unclear service level agreements (SLAs) that do not specify the quality, timeliness, and accuracy of the payroll service.
Insufficient or vague security and confidentiality provisions that do not safeguard the client's data and information from unauthorized access, use, disclosure, or loss.
Unreasonable or excessive fees, penalties, or liabilities that may impose an undue financial burden on the client.
Limited or no audit rights that may prevent the client from verifying the effectiveness and compliance of the payroll provider's internal controls.
Inflexible or restrictive termination clauses that may limit the client's ability to cancel or switch to another payroll provider.
A third-party contract that has not been reviewed by the legal department may expose the client to various risks, such as:
Legal disputes or litigation with the payroll provider over contractual breaches or performance issues.
Regulatory fines or sanctions for noncompliance with tax, labor, or other laws and regulations related to payroll.
Financial losses or damages due to errors, fraud, or negligence by the payroll provider.
Reputation damage or customer dissatisfaction due to payroll errors or delays.
Therefore, an IS auditor should be highly concerned about a third-party contract that has not been reviewed by the legal department and recommend that the client seek legal advice before signing or renewing any contract with an outsourced payroll provider.
User access rights have not been periodically reviewed by the client is a moderate concern because it may indicate a lack of proper access control over the payroll system. User access rights are the permissions granted to users to access, view, modify, or delete data and information in the payroll system. User access rights should be periodically reviewed by the client to ensure that they are aligned with the user's roles and responsibilities, and that they are revoked or modified when a user changes roles or leaves the organization.
User access rights that are not periodically reviewed by the client may result in unauthorized or inappropriate access to payroll data and information, which may compromise its confidentiality, integrity, and availability.
Payroll processing costs have not been included in the IT budget is a minor concern because it may indicate a lack of proper planning and allocation of IT resources for payroll processing. Payroll processing costs are the expenses incurred by the client for using an outsourced payroll service, such as fees, charges, taxes, or penalties. Payroll processing costs should be included in the IT budget to ensure that they are adequately estimated, monitored, and controlled. Payroll processing costs that are not included in the IT budget may result in unexpected or excessive costs for payroll processing, which may affect the client's profitability and cash flow.
The third-party contract does not comply with the vendor management policy is a low concern because it may indicate a lack of alignment between the client's vendor management policy and its actual vendor selection and evaluation process. A vendor management policy is a set of guidelines and procedures that governs how the client manages its relationship with its vendors, such as how to select, monitor, evaluate, and terminate vendors. A vendor management policy should be consistent with the client's business objectives, risk appetite, and regulatory requirements. A third-party contract that does not comply with the vendor management policy may result in suboptimal vendor performance or service quality, but it does not necessarily imply a breach of contract or a violation of law.
CISA-KR 문제 192
CISA-KR 문제 193
In a PKI, the greatest practical risk in key management is failure to detect and respond when keys are compromised. If compromise is not detected promptly, confidentiality, integrity, authentication, and nonrepudiation can all be undermined. ISACA materials discussing PKI and cryptographic transition stress the importance of certificate revocation, rollout strategies, and careful key management because compromise of keys directly affects trust in the system.
Option D is important, but documentation alone does not prove that compromise can be detected in practice.
Option B may help monitoring, but it is narrower than the broader control objective of detecting compromised keys. Option A is not a core audit concern in comparison. From a CISA perspective, the most important focus is whether the organization can detect, contain, and revoke trust when keys are exposed or misused.
References (Official ISACA):
* ISACA Journal, Building Resilient Security in the Age of Quantum Computing - discusses PKI key management complexity and certificate revocation as critical control considerations.
CISA-KR 문제 194
CISA-KR 문제 195
The other options are not as concerning as option C. Target architecture is defined at a technical level is not a concern for an IS auditor reviewing an IT strategy document. Target architecture is the desired state of an organization's IT systems in terms of their structure, functionality, performance, security, interoperability, and integration. Defining target architecture at a technical level can help an IS auditor to understand how the organization plans to achieve its strategic IT goals and what technical requirements and standards it needs to follow. The previous year's IT strategic goals were not achieved is not a concern for an IS auditor reviewing an IT strategy document. The previous year's IT strategic goals are the outcomes that the organization intended to accomplish with its IT initiatives in the past year. Not achieving these goals may indicate some challenges or gaps in the organization's IT performance or execution. However, this does not necessarily affect the quality or validity of the current IT strategy document. An IS auditor should focus on evaluating whether the current IT strategy document is realistic, measurable, achievable, relevant, and time-bound.
Financial estimates of new initiatives are disclosed within the document is not a concern for an IS auditor reviewing an IT strategy document. Financial estimates are projections of the costs and benefits of new initiatives that are part of the IT strategy document. Disclosing financial estimates within the document can help an IS auditor to assess whether the new initiatives are aligned with the organization's budget and resources and whether they provide value for money. References: IT Strategy Template for a Successful Strategic Plan | Gartner, Definitive Guide to Developing anIT Strategy and Roadmap - CioPages, An Example of a Well-Developed IT Strategy Plan - Resolute
- 다른 버전
- 1742ISACA.CISA-KR.v2026-05-06.q261
- 3090ISACA.CISA-KR.v2026-03-16.q665
- 4440ISACA.CISA-KR.v2026-03-07.q651
- 9176ISACA.CISA-KR.v2025-04-07.q633
- 4431ISACA.CISA-KR.v2025-04-03.q628
- 3633ISACA.CISA-KR.v2025-04-02.q544
- 4189ISACA.CISA-KR.v2025-03-31.q534
- 5297ISACA.CISA-KR.v2025-03-28.q617
- 3067ISACA.CISA-KR.v2025-03-19.q581
- 3953ISACA.CISA-KR.v2025-03-03.q807
- 5040ISACA.CISA-KR.v2024-02-07.q421
- 2789ISACA.CISA-KR.v2024-01-31.q392
- 5259ISACA.CISA-KR.v2023-10-24.q329
- 5158ISACA.CISA-KR.v2023-07-31.q266
- 3089ISACA.CISA-KR.v2023-06-23.q324
- 최근 업로드
- 216Microsoft.PL-600.v2026-08-11.q206
- 153Microsoft.DP-100.v2026-08-11.q160
- 155Oracle.1Z0-1048-25.v2026-08-11.q68
- 130ISQI.CTAL-TAE.v2026-08-11.q37
- 171ServiceNow.CIS-HR.v2026-08-11.q84
- 254Salesforce.Plat-Arch-201.v2026-08-10.q101
- 240Databricks.Databricks-Machine-Learning-Professional.v2026-08-10.q76
- 189F5.F5CAB2.v2026-08-10.q41
- 284APA.CPP-Remote.v2026-08-08.q109
- 149SAP.C_BCBAI_2601.v2026-08-08.q9
PDF 파일 다운로드
메일 주소를 입력하시고 다운로드 하세요. ISACA.CISA-KR.v2026-05-16.q709 모의시험 시험자료를 다운 받으세요.
