CISA-KR 문제 401
One of the requirements of the GDPR and the DPA 2018 is to adhere to the principle of storage limitation, which states that personal data should be kept for no longer than is necessary for the purposes for which it is processed1. This means that the business owner should determine and justify how long they need to retain personal data, based on factors such as:
The nature and sensitivity of the personal data
The legal or contractual obligations or rights that apply to the personal data The business or operational needs and expectations that depend on the personal data The risks and impacts that may arise from retaining or deleting the personal data The business owner should also establish and document the conditions and methods for the destruction of personal data, such as:
The criteria and triggers for deciding when to destroy personal data
The procedures and tools for securely erasing or anonymising personal data The roles and responsibilities for carrying out and overseeing the destruction of personal data The records and reports for verifying and evidencing the destruction of personal data Therefore, retention periods and conditions for the destruction of personal data should be determined by the business owner, as they are in charge of defining and managing the processing of personal data, as well as ensuring its compliance with the law.
CISA-KR 문제 402
Option A (Incorrect):While senior management involvement is essential, it is abyproductof alignment rather than the primary goal.
Option B (Correct):Themain purposeof alignment is tooptimize IT investmentsby ensuring that IT initiatives directly support business needs, reducing waste and improving ROI.
Option C (Incorrect):Risk awareness is important but is not theprimaryreason for IT-business alignment.
Option D (Incorrect):Monitoring IT effectiveness is part of governance but not the main objective of IT- business alignment.
Reference:ISACA CISA Review Manual -Domain 1: Information Systems Auditing Process- Covers IT governance, strategy alignment, and value realization.
CISA-KR 문제 403
The configuration phase is not the phase where the IS auditor should first examine requirements from an in- house SDLC project that has not met user specifications. The configuration phase is the phase where the system is installed and configured on the target environment, such as hardware, software, network, etc., to prepare it for deployment and operation. The configuration phase may involve activities such as installation, customization, migration, integration, etc., to ensure that the system is compatible and interoperable with the existinginfrastructure and systems34.
The user training phase is not the phase where the IS auditor should first examine requirements from an in- house SDLC project that has not met user specifications. The user training phase is the phase where the end- users are trained and educated on how to use the system effectively and efficiently. The user training phase may involve activities such as developing training materials, conducting training sessions, providing feedback and support, etc., to ensure that the users are familiar and comfortable with the system features and functions56.
The development phase is not the phase where the IS auditor should first examine requirements from an in- house SDLC project that has not met user specifications. The development phase is the phase where the system is coded and built based on the design specifications and the user specifications. The development phase may involve activities such as programming, debugging, documenting, etc., to create a working prototype or a final product of the system
CISA-KR 문제 404
CISA-KR 문제 405
The other options are less concerning for the IS auditor:
Test results were not communicated to staff members. This is not ideal, as staff members should receive feedback on their performance and learn from the test results. However, this does not necessarily mean that they did not receive any training or education on how to avoid phishing attacks.
Staff members were not notified about the test beforehand. This is a common practice for phishing simulation tests, as it mimics the real-world scenario where staff members do not know when they will receive a phishing email. The purpose of the test is to measure their spontaneous reaction and awareness, not their preparedness or compliance.
Security awareness training was not provided prior to the test. This is not a major concern, as the test can serve as a baseline measurement of the current level of awareness and susceptibility of staff members, and as a starting point for providing tailored training and education based on the test results.
- 다른 버전
- 303ISACA.CISA-KR.v2026-08-15.q712
- 1866ISACA.CISA-KR.v2026-05-06.q261
- 3332ISACA.CISA-KR.v2026-03-16.q665
- 4742ISACA.CISA-KR.v2026-03-07.q651
- 9445ISACA.CISA-KR.v2025-04-07.q633
- 4553ISACA.CISA-KR.v2025-04-03.q628
- 3810ISACA.CISA-KR.v2025-04-02.q544
- 4313ISACA.CISA-KR.v2025-03-31.q534
- 5523ISACA.CISA-KR.v2025-03-28.q617
- 3313ISACA.CISA-KR.v2025-03-19.q581
- 4197ISACA.CISA-KR.v2025-03-03.q807
- 5245ISACA.CISA-KR.v2024-02-07.q421
- 2921ISACA.CISA-KR.v2024-01-31.q392
- 5430ISACA.CISA-KR.v2023-10-24.q329
- 5260ISACA.CISA-KR.v2023-07-31.q266
- 3259ISACA.CISA-KR.v2023-06-23.q324
- 최근 업로드
- 126Microsoft.AZ-305-KR.v2026-08-17.q162
- 140IIA.IAA-IAP-KR.v2026-08-17.q41
- 303ISACA.CISA-KR.v2026-08-15.q712
- 238Microsoft.MS-700-KR.v2026-08-15.q203
- 173Microsoft.AZ-305-KR.v2026-08-14.q177
- 238Microsoft.DP-900-KR.v2026-08-13.q130
- 315Microsoft.PL-600.v2026-08-11.q206
- 267Microsoft.DP-100.v2026-08-11.q160
- 209Oracle.1Z0-1048-25.v2026-08-11.q68
- 177ISQI.CTAL-TAE.v2026-08-11.q37
PDF 파일 다운로드
메일 주소를 입력하시고 다운로드 하세요. ISACA.CISA-KR.v2026-05-16.q709 모의시험 시험자료를 다운 받으세요.
