CISA-KR 문제 36
References:
What Is Data Classification and Why Is It Important? - RiskOptics
Data Classification Policy: Definition, Examples, and Free Template - Hyperproof Data Classification Policy: Benefits, Examples, and Techniques - Satori What is a Data Classification Policy? - Digital Guardian Data Classification and Practices - NIST Data Classification as a Catalyst for Data Retention and Archiving ...
What is data classification? - Cloud Adoption Framework
Data Classification - Data Security Policies | ITS Policies ...
IMPLEMENTING DATA CLASSIFICATION PRACTICES - NIST
Best Practices for Data Classification | Forcepoint
CISA-KR 문제 37
CISA-KR 문제 38
ISACA guidance on shadow AI and emerging technology risk highlights data breaches, privacy risk, and data leakage as major concerns when employees use unapproved public AI tools. Public cloud AI use can expose sensitive data through prompts, uploads, or output handling, making data leakage the greatest immediate concern from an audit and control perspective.
Option A is a concern because AI outputs can be inaccurate, but poor reliability usually does not create the same immediate confidentiality exposure as leaking internal data. Option B is less severe. Option C can matter in some use cases, but the most significant enterprise risk identified in ISACA's public guidance is unauthorized disclosure of data.
References (Official ISACA):
* ISACA, From Shadow IT to Shadow AI: Navigating the New Frontier of Enterprise Risk.
* ISACA, Navigating the Hype and Risk of Emerging Technologies.
* ISACA, Collaboration and the New Triad of AI Governance.
CISA-KR 문제 39
ISACA, CISA Review Manual, 27thEdition, chapter 1, section 1.41
ISACA, IT Audit and Assurance Standards, Guidelines and Tools and Techniques for IS Audit and Assurance Professionals, section 12072
CISA-KR 문제 40
다음 중 어떤 작업을 먼저 해야 할까요?
Software errors, bugs, or vulnerabilities that can affect the functionality, reliability, or security of the applications3 Software failures, delays, or overruns that can affect the delivery, performance, or customer satisfaction of the applications3 Software non-compliance that can result in legal, regulatory, or contractual violations or penalties3 The next step that the IS auditor should do after identifying deficiencies in SDLC policies is to communicate the observation to the auditee. The auditee is the person or entity that is subject to the audit and is responsible for the area being audited4. In this case, the auditee could be the software development manager, the project manager, or the senior management of the organization. Communicating the observation to the auditee is important for several reasons:
It allows the IS auditor to verify the accuracy and validity of the observation and gather additional evidence or information from the auditee4 It gives the auditee an opportunity to respond to the observation and provide their perspective, explanation, or justification for the deficiencies4 It enables the IS auditor to discuss with the auditee the potential impact, root cause, and remediation plan for the deficiencies4 It fosters a collaborative and constructive relationship between the IS auditor and the auditee and promotes transparency and accountability in the audit process4 The other options are not as appropriate as communicating the observation to the auditee. Documenting the findings in the audit report is a later stepthat should be done after communicating with the auditee and finalizing the observation. Identifying who approved the policies is not relevant for addressing the deficiencies and may imply blame or fault on a specific person or group. Escalating the situation to the lead auditor is not necessary unless there is a serious disagreement or conflict with the auditee that cannot be resolved by normal communication. Therefore, option D is the correct answer.
References:
What Is The Software Development Life Cycle? | PagerDuty
Software Development Life Cycle (SDLC) Policy | StrongDM
What Is SDLC? Best Phases, Methodologies, and Benefits Revealed - Kellton Communicating Audit Findings
- 다른 버전
- 1795ISACA.CISA-KR.v2026-05-06.q261
- 3117ISACA.CISA-KR.v2026-03-16.q665
- 4484ISACA.CISA-KR.v2026-03-07.q651
- 9204ISACA.CISA-KR.v2025-04-07.q633
- 4447ISACA.CISA-KR.v2025-04-03.q628
- 3659ISACA.CISA-KR.v2025-04-02.q544
- 4217ISACA.CISA-KR.v2025-03-31.q534
- 5320ISACA.CISA-KR.v2025-03-28.q617
- 3149ISACA.CISA-KR.v2025-03-19.q581
- 3971ISACA.CISA-KR.v2025-03-03.q807
- 5133ISACA.CISA-KR.v2024-02-07.q421
- 2798ISACA.CISA-KR.v2024-01-31.q392
- 5263ISACA.CISA-KR.v2023-10-24.q329
- 5214ISACA.CISA-KR.v2023-07-31.q266
- 3100ISACA.CISA-KR.v2023-06-23.q324
- 최근 업로드
- 152Microsoft.DP-900-KR.v2026-08-13.q130
- 244Microsoft.PL-600.v2026-08-11.q206
- 183Microsoft.DP-100.v2026-08-11.q160
- 177Oracle.1Z0-1048-25.v2026-08-11.q68
- 145ISQI.CTAL-TAE.v2026-08-11.q37
- 195ServiceNow.CIS-HR.v2026-08-11.q84
- 258Salesforce.Plat-Arch-201.v2026-08-10.q101
- 244Databricks.Databricks-Machine-Learning-Professional.v2026-08-10.q76
- 192F5.F5CAB2.v2026-08-10.q41
- 299APA.CPP-Remote.v2026-08-08.q109
PDF 파일 다운로드
메일 주소를 입력하시고 다운로드 하세요. ISACA.CISA-KR.v2026-05-16.q709 모의시험 시험자료를 다운 받으세요.
