CISA-KR 문제 451
ISACA CISA Reference: Data replication strategies in disaster recovery planning emphasize mirroring for high-availability systems.
Risk Implication: If mirroring is not implemented for critical systems, significant data loss may occur in the event of a failure.
Alternative Choices:
Option A: Snapshots capture data at specific points in time, leading to potential data loss.
Option C: Log shipping has delays due to batch processing.
Option D: Backups are periodic and not suitable for short RPO needs.
CISA-KR 문제 452
Re-evaluating the organization's risk and control framework is the best recommendation to management because it can help them to:
Review the current risk environment and the sources, causes, and impacts of potential threats and vulnerabilities.
Update the risk assessment and analysis methods and criteria, such as likelihood, impact, severity, and priority.
Reconsider the risk response and treatment options, such as avoidance, reduction, transfer, or acceptance.
Realign the security controls with the risk profile and the business needs and expectations.
Evaluate the performance and effectiveness of the security controls using key indicators and metrics.
Identify the gaps, weaknesses, or inefficiencies in the security controls and implement corrective or improvement actions.
Communicate and report the risk and control status and results to relevant stakeholders.
Re-evaluating the organization's risk and control framework can help management to determine whether the current security controls are excessive or not, and to make informed and rational decisions on how to adjust them accordingly.
CISA-KR 문제 453
Therefore, the use of CMMs would best enhance a process improvement program, as they provide a systematic and structured approach to evaluate and improve processes based on proven principles and practices. Option C is the correct answer.
Option A is not correct because model-based design notations are graphical or textual languages that help designers specify, visualize, and document the structure and behavior of systems4. While they can be useful for designing and communicating complex systems, they do not directly address the process improvement aspect of a program.
Option B is not correct because balanced scorecard is a strategic management tool that helps organizations translate their vision and mission into measurable objectives and indicators. While it can be useful for monitoring and evaluating the performance of a program, it does not provide specific guidance on how to improve processes.
Option D is not correct because project management methodologies are sets of principles and practices that help organizations plan, execute, and control projects. While they can be useful for managing the scope, schedule, cost, quality, and risk of a program, they do not focus on the process improvement aspect of a program.
References:
Guide to Process Maturity Models2
What is CMMI? A model for optimizing development processes1
Capability Maturity Model (CMM): A Definitive Guide3
Model-Based Design Notations4
Balanced Scorecard
Project Management Methodologies
CISA-KR 문제 454
Option A (Incorrect):UAT focuses on functionalityfrom anend-user perspective, not source code errors.
Option B (Incorrect):Black box testingexamines software behaviorwithout reviewing code, making it less effective for code-level optimization.
Option C (Correct):White box testing(also known asclear box or structural testing)analyzes source codefor vulnerabilities, logic errors, and optimization opportunities.
Option D (Incorrect):Penetration testingidentifiessecurity weaknesses, but it does notfocus on code efficiency.
Reference:ISACA CISA Review Manual -Domain 3: Information Systems Acquisition, Development, and Implementation- Coverssoftware testing methodologies and secure coding practices.
CISA-KR 문제 455
Periodic review of access profiles by management: This is a type of logical access control that involves verifying that the access rights assigned to each cardholder are appropriate, necessary, and consistent with the organization's policies and procedures. Periodic review of access profiles can help to detect and correct any errors, inconsistencies, or violations in the access control system, such as outdated, excessive, or redundant access rights, segregation of duties conflicts, or unauthorized changes. Periodic review of access profiles can also help to ensure compliance with internal and external audit requirements and regulations.
Implementation of additional PIN pads: This is a type of multi-factor authentication (MFA) that requires the cardholder to enter a personal identification number (PIN) in addition to swiping their card. MFA can enhance the security of the access control system by adding another layer of verificationand reducing the risk of lost, stolen, or cloned cards being used by unauthorized persons.
Installation of closed-circuit television (CCTV): This is a type of surveillance system that uses cameras and monitors to record and display the images of the people and activities in the restricted areas. CCTV can deter potential intruders, provide evidence of any security incidents or breaches, and enable real-time monitoring and response by security personnel.
The other options are not as effective or relevant as periodic review of access profiles by management for an additional control when using swipe cards. Physical sign-in of all employees for access to restricted areas is a redundant and inefficient control that can be easily bypassed or manipulated. It also does not provide any assurance or verification of the identity or access rights of the cardholders. Audit hooks are software routines embedded in an application that can trigger an alert or a report when certain conditions are met. Audit hooks can help to detect anomalies or exceptions in access control lists, but they do not provide a comprehensive or integrated view of them.
References:
ISACA, CISA Review Manual, 27th Edition, 2019, p. 236
ISACA, ITAF: A Professional Practices Framework for IS Audit/Assurance, 3rd Edition, 2014, p. 88 Data Analytics for Auditing Access Control
- 다른 버전
- 223ISACA.CISA-KR.v2026-08-15.q712
- 1825ISACA.CISA-KR.v2026-05-06.q261
- 3191ISACA.CISA-KR.v2026-03-16.q665
- 4628ISACA.CISA-KR.v2026-03-07.q651
- 9340ISACA.CISA-KR.v2025-04-07.q633
- 4491ISACA.CISA-KR.v2025-04-03.q628
- 3734ISACA.CISA-KR.v2025-04-02.q544
- 4276ISACA.CISA-KR.v2025-03-31.q534
- 5426ISACA.CISA-KR.v2025-03-28.q617
- 3254ISACA.CISA-KR.v2025-03-19.q581
- 4058ISACA.CISA-KR.v2025-03-03.q807
- 5218ISACA.CISA-KR.v2024-02-07.q421
- 2871ISACA.CISA-KR.v2024-01-31.q392
- 5389ISACA.CISA-KR.v2023-10-24.q329
- 5230ISACA.CISA-KR.v2023-07-31.q266
- 3229ISACA.CISA-KR.v2023-06-23.q324
- 최근 업로드
- 223ISACA.CISA-KR.v2026-08-15.q712
- 165Microsoft.MS-700-KR.v2026-08-15.q203
- 130Microsoft.AZ-305-KR.v2026-08-14.q177
- 190Microsoft.DP-900-KR.v2026-08-13.q130
- 289Microsoft.PL-600.v2026-08-11.q206
- 219Microsoft.DP-100.v2026-08-11.q160
- 188Oracle.1Z0-1048-25.v2026-08-11.q68
- 159ISQI.CTAL-TAE.v2026-08-11.q37
- 200ServiceNow.CIS-HR.v2026-08-11.q84
- 281Salesforce.Plat-Arch-201.v2026-08-10.q101
PDF 파일 다운로드
메일 주소를 입력하시고 다운로드 하세요. ISACA.CISA-KR.v2026-05-16.q709 모의시험 시험자료를 다운 받으세요.
