CISA-KR 문제 211
SHA-1 does not encrypt information, but rather verifies its integrity by detecting any changes or modifications. Digital signatures are electronic signatures that use encryption and hash functions to authenticate the identity of the sender and the integrity of the message. Digital signatures do not protect the confidentiality of information, but rather ensure its authenticity and non-repudiation. Digital certificates are electronic documents that contain the public key and identity information of an entity, such as a person, organization or device. Digital certificates are issued by trusted third parties called certificate authorities (CAs). Digital certificates do not protect the confidentiality of information, but rather enable secure communication and encryption by verifying the identity and public key of an entity. References:
[Encryption Definition]
[Secure Hash Algorithm 1 (SHA-1) Definition]
[Digital Signature Definition]
[Digital Certificate Definition]
CISA-KR 문제 212
ISACA, CISA Review Manual, 27th Edition, chapter 4, section 4.21
ISACA, COBIT 2019 Framework: Introduction and Methodology, section 3.23
CISA-KR 문제 213
CISA-KR 문제 214
SOD is especially important in IT security, where granting excessive system access to one person or group can lead to harmful consequences, such as data breaches, identity theft, or bypassing security controls2. SOD breaks IT-related tasks into four separate function categories: authorization, custody, recordkeeping, and reconciliation1. Ideally, no one person or department holds responsibility in multiple categories.
In a role-based environment, where access privileges are granted based on predefined roles, it is important to ensure that the roles are designed and assigned in a way that supports SOD. For example, the person who develops an application should not also be the one who tests it, deploys it, or maintains it.
Therefore, an application developer should not be assigned the roles of IT operator, system administration, or database administration, as these roles may conflict with their development role and create opportunities for misuse or abuse of the system. The only role that may be assigned to an application developer without violating SOD is emergency support, which is a temporary role that allows the developer to access the system in case of a critical issue that requires immediate resolution3. However, even this role should be granted with caution and monitored closely to ensure compliance with SOD policies.
References:
ISACA, CISA Review Manual, 27th Edition, 2019, page 2824
ISACA, CISA Review Questions, Answers and Explanations Database - 12 Month Subscription, QID
1066692
Hyperproof Blog, Segregation of Duties: What it is and Why it's Important1 Advisera Blog, Segregation of duties in your ISMS according to ISO 27001 A.6.1.23
CISA-KR 문제 215
/assurancereview is to provide management with an independent assessment relating to the effectiveness of information security management within the enterprise." The guideline also states that "the audit/assurance professional should evaluate whether there is an appropriate level of awareness throughout the enterprise regarding information security policies, standards, procedures and guidelines." According to a web search result from Microsoft Security, "Information security programs need to: ... Support the execution of decisions." 2 One of the ways to support the execution of decisions is to ensure that everyone in the organization understands their security responsibilities and follows the security policies and procedures.
- 다른 버전
- 1742ISACA.CISA-KR.v2026-05-06.q261
- 3090ISACA.CISA-KR.v2026-03-16.q665
- 4440ISACA.CISA-KR.v2026-03-07.q651
- 9176ISACA.CISA-KR.v2025-04-07.q633
- 4431ISACA.CISA-KR.v2025-04-03.q628
- 3633ISACA.CISA-KR.v2025-04-02.q544
- 4189ISACA.CISA-KR.v2025-03-31.q534
- 5297ISACA.CISA-KR.v2025-03-28.q617
- 3067ISACA.CISA-KR.v2025-03-19.q581
- 3953ISACA.CISA-KR.v2025-03-03.q807
- 5040ISACA.CISA-KR.v2024-02-07.q421
- 2789ISACA.CISA-KR.v2024-01-31.q392
- 5259ISACA.CISA-KR.v2023-10-24.q329
- 5158ISACA.CISA-KR.v2023-07-31.q266
- 3089ISACA.CISA-KR.v2023-06-23.q324
- 최근 업로드
- 216Microsoft.PL-600.v2026-08-11.q206
- 153Microsoft.DP-100.v2026-08-11.q160
- 155Oracle.1Z0-1048-25.v2026-08-11.q68
- 130ISQI.CTAL-TAE.v2026-08-11.q37
- 171ServiceNow.CIS-HR.v2026-08-11.q84
- 254Salesforce.Plat-Arch-201.v2026-08-10.q101
- 240Databricks.Databricks-Machine-Learning-Professional.v2026-08-10.q76
- 189F5.F5CAB2.v2026-08-10.q41
- 284APA.CPP-Remote.v2026-08-08.q109
- 149SAP.C_BCBAI_2601.v2026-08-08.q9
PDF 파일 다운로드
메일 주소를 입력하시고 다운로드 하세요. ISACA.CISA-KR.v2026-05-16.q709 모의시험 시험자료를 다운 받으세요.
