CISA-KR 문제 226
Management's commitment to information security also demonstrates leadership, sets the tone and culture, and establishes the strategic direction and objectives for information security. User accountability for information security, alignment of information security with IT objectives, and integration of business and information security are also important factors for the success of an information security program, but they are not as critical as management's commitment to information security, as they depend on or derive from it. References: Info Technology and Systems Resources | COBIT, Risk, Governance ... - ISACA, IT Governance and Process Maturity
CISA-KR 문제 227
A testing environment is a separate environment that is used to perform various types of testing on software, such as functional testing, performance testing, security testing, etc. A testing environment may not have the same software version as production, as it may undergo frequent changes or updates based on testing results or feedback. An integration environment is a separate environment that is used to combine and test software components or modules from different developers or sources, to ensure that they work together as expected.
An integration environment may not have the same software version as production, as it may involve different versions or branches of software from different sources. A development environment is a separate environment that is used by developers to create and modify software code. A development environment may not have the same software version as production, as it may contain unfinished or untested code that has not been released yet.
CISA-KR 문제 228
References:
Service Level Agreement (SLA)Examples and Template
What is an SLA? Best practices for service-level agreements
CISA-KR 문제 229
Requiring visitors to use biometric authentication, monitoring visitors online by security cameras, and requiring visitors to enter through dead-man doors are all examples of technical controls that can enhance visitor access control, but they are not as effective as escorting visitors. Biometric authentication can provide a high level of identity verification, but it does not prevent visitors from accessing unauthorized areas or compromising security in other ways. Security cameras can provide a record of visitor movements and actions, but they may not deter or detect security breaches in real time. Dead-man doors can prevent unauthorized entry by requiring two-factor authentication, but they do not ensure that visitors are accompanied by authorized personnel.
References:
ISC Best Practices for Facility Access Control1
Visitor Management Best Practices From Top Organizations2
8 Best Practices for Setting Up a Visitor Management System3
CISA-KR 문제 230
Option A is correct because separating initiation from closure helps ensure independent review, proper follow- up, and accountability in the incident process. This aligns with classic CISA logic: one role records or raises the issue, while another role validates resolution and closure.
Option B is less compelling because collecting and analyzing logs are closely related operational security activities and are often performed within the same monitoring function.
Option C is also less appropriate to separate in this context because identifying root causes and recommending workarounds are naturally linked problem-management activities. ISACA guidance on root cause analysis connects these activities to incident and problem handling.
Option D is not the best answer because recording and classifying incidents are typically performed together at intake or triage. Separating them would usually add process friction without the same control benefit as separating initiation from closure.
Therefore, A is the best answer because it best reflects appropriate segregation of duties in incident handling.
References (Official ISACA):
* ISACA Journal, IS Audit Basics: Trust but Verify - highlights the importance of segregation of duties.
* ISACA Journal, Trends, Challenges and Strategies for Effective Audit in a Rapidly Changing Landscape - reinforces segregation of duties as a continuing control requirement.
* ISACA Journal, Resilient GRC: Tackling Contemporary Challenges With a Robust Delivery Model - discusses bias and segregation-of-duties concerns.
* ISACA, Root Cause Analysis / ISACA Glossary - supports the linkage between root cause analysis and incident/problem processes.
- 다른 버전
- 1743ISACA.CISA-KR.v2026-05-06.q261
- 3091ISACA.CISA-KR.v2026-03-16.q665
- 4441ISACA.CISA-KR.v2026-03-07.q651
- 9177ISACA.CISA-KR.v2025-04-07.q633
- 4433ISACA.CISA-KR.v2025-04-03.q628
- 3633ISACA.CISA-KR.v2025-04-02.q544
- 4190ISACA.CISA-KR.v2025-03-31.q534
- 5298ISACA.CISA-KR.v2025-03-28.q617
- 3068ISACA.CISA-KR.v2025-03-19.q581
- 3954ISACA.CISA-KR.v2025-03-03.q807
- 5041ISACA.CISA-KR.v2024-02-07.q421
- 2790ISACA.CISA-KR.v2024-01-31.q392
- 5260ISACA.CISA-KR.v2023-10-24.q329
- 5159ISACA.CISA-KR.v2023-07-31.q266
- 3091ISACA.CISA-KR.v2023-06-23.q324
- 최근 업로드
- 216Microsoft.PL-600.v2026-08-11.q206
- 153Microsoft.DP-100.v2026-08-11.q160
- 155Oracle.1Z0-1048-25.v2026-08-11.q68
- 130ISQI.CTAL-TAE.v2026-08-11.q37
- 171ServiceNow.CIS-HR.v2026-08-11.q84
- 254Salesforce.Plat-Arch-201.v2026-08-10.q101
- 240Databricks.Databricks-Machine-Learning-Professional.v2026-08-10.q76
- 189F5.F5CAB2.v2026-08-10.q41
- 285APA.CPP-Remote.v2026-08-08.q109
- 149SAP.C_BCBAI_2601.v2026-08-08.q9
PDF 파일 다운로드
메일 주소를 입력하시고 다운로드 하세요. ISACA.CISA-KR.v2026-05-16.q709 모의시험 시험자료를 다운 받으세요.
