CISA-KR 문제 81
A DRP should include steps for obtaining replacement supplies, as this is an essential part of restoring the normal operation of the organization after a disaster. Replacement supplies may include hardware, software, data, network components, office equipment, or other resources that are needed to resume the business functions and processes that were disrupted by the disaster. Obtaining replacement supplies may involve contacting vendors, suppliers, or partners; activating backup or alternative systems; or purchasing or renting new equipment. A DRP should identify the sources, locations, and costs of the replacement supplies, as well as the procedures and responsibilities for acquiring and installing them.
The other three options are not steps that a DRP should include, as they are either part of the pre-disaster planning process or not directly related to the disaster recovery objectives. Assessing and quantifying risk is a step that should be done before creating a DRP, as it helps identify the potential threats and vulnerabilities that could affect the organization and determine the likelihood and impact of each scenario2. Negotiating contracts with disaster planning consultants is also a pre-disaster activity that may help the organization design, implement, test, and maintain a DRP with external expertise and guidance3. Identifying application control requirements is not a step in a DRP, but rather a part of the application development and maintenance process that ensures the quality, security, and reliability of the software applications used by the organization.
Therefore, obtaining replacement supplies is the correct answer.
References:
What is a DisasterRecovery Plan? + Complete Checklist
Risk Assessment- ISACA
Disaster Recovery Planning - ISACA
[Application Controls - ISACA]
CISA-KR 문제 82
Option A is correct because granted rights directly show whether programmers can update, modify, or otherwise alter production data. If those privileges are present, the permission exists; if not, it does not. This is more direct than reviewing configuration or implementation history.
Option B is not the best answer because reviewing how recent changes were implemented may indicate whether developers were involved in production changes, but it does not directly confirm whether they currently have permission to alter production data. It is indirect evidence.
Option C is also weaker than A. Access control system configuration may reveal how permissions are structured, but the clearest evidence is still the actual rights granted to the programmers or their roles.
Option D is incorrect because log settings show what may be recorded, not what access is authorized. Logs may help detect misuse, but they do not define whether permission exists.
Therefore, A is the best answer because reviewing granted access rights is the most direct and reliable way to determine whether programmers can alter production data.
References (Official ISACA):
* ISACA Journal, An Approach Toward Sarbanes-Oxley ITGC Risk Assessment - logical access and direct database access are central audit concerns.
* ISACA Journal, Auditing Amazon Web Services - audit focus includes how access is restricted and how administrative activity is segregated.
* ISACA, Selected COBIT 5 Processes for Essential Enterprise Security - access should be justified, authorized, logged, and monitored.
CISA-KR 문제 83
CISA-KR 문제 84
CISA-KR 문제 85
Agile development is iterative, adaptive, and designed to respond to changing requirements. Unlike traditional linear development models, Agile expects feedback and change throughout the project. ISACA's discussion of Agile principles states that changing requirements should be welcomed, even late in development, because Agile processes harness change for the customer's competitive advantage.
Option A is incorrect because Agile values working software and useful outcomes more than extensive documentation as the primary measure of progress. Option B is incorrect because Agile encourages collaboration and iteration rather than isolated phases. Option C describes a waterfall-style approach, not Agile.
This maps to Information Systems Acquisition, Development and Implementation because ISACA's CISA Exam Content Outline includes system development methodologies under Domain 3.
References: ISACA CISA Exam Content Outline, Domain 3; ISACA Journal discussion of Agile principles.
- 다른 버전
- 4171ISACA.CISA-KR.v2026-05-16.q709
- 1823ISACA.CISA-KR.v2026-05-06.q261
- 3168ISACA.CISA-KR.v2026-03-16.q665
- 4578ISACA.CISA-KR.v2026-03-07.q651
- 9334ISACA.CISA-KR.v2025-04-07.q633
- 4485ISACA.CISA-KR.v2025-04-03.q628
- 3724ISACA.CISA-KR.v2025-04-02.q544
- 4259ISACA.CISA-KR.v2025-03-31.q534
- 5402ISACA.CISA-KR.v2025-03-28.q617
- 3251ISACA.CISA-KR.v2025-03-19.q581
- 4056ISACA.CISA-KR.v2025-03-03.q807
- 5218ISACA.CISA-KR.v2024-02-07.q421
- 2871ISACA.CISA-KR.v2024-01-31.q392
- 5388ISACA.CISA-KR.v2023-10-24.q329
- 5230ISACA.CISA-KR.v2023-07-31.q266
- 3229ISACA.CISA-KR.v2023-06-23.q324
- 최근 업로드
- 212ISACA.CISA-KR.v2026-08-15.q712
- 156Microsoft.MS-700-KR.v2026-08-15.q203
- 126Microsoft.AZ-305-KR.v2026-08-14.q177
- 188Microsoft.DP-900-KR.v2026-08-13.q130
- 279Microsoft.PL-600.v2026-08-11.q206
- 218Microsoft.DP-100.v2026-08-11.q160
- 187Oracle.1Z0-1048-25.v2026-08-11.q68
- 159ISQI.CTAL-TAE.v2026-08-11.q37
- 200ServiceNow.CIS-HR.v2026-08-11.q84
- 278Salesforce.Plat-Arch-201.v2026-08-10.q101
PDF 파일 다운로드
메일 주소를 입력하시고 다운로드 하세요. ISACA.CISA-KR.v2026-08-15.q712 모의시험 시험자료를 다운 받으세요.
