CISA-KR 문제 46
The other options are not as advantageous as option D, as they may not reflect the true benefits or limitations of vulnerability scanning compared to penetration testing. The testing produces a lower number of false positive results, but this is not necessarily true, as vulnerability scanning may report vulnerabilities that are not exploitable or relevant in the context of the organization. Network bandwidth is utilized more efficiently, but this may not be a significant advantage, as vulnerability scanning may still consume considerable network resources depending on the scope and frequency of the scans. Custom-developed applications can be tested more accurately, but this is also not true, as vulnerability scanning may not be able to detect complex or unknown vulnerabilities that require manual analysis or exploitation.
References:
1: Vulnerability scanning vs penetration testing: What's the difference? | TechRepublic
2: Vulnerability Scanning vs. Penetration Testing - Fortinet
3: Penetration Test Vs Vulnerability Scan | Digital Defense
4: Penetration Testing vs. Vulnerability Scanning: What's the difference?
5: Penetration Testing vs. Vulnerability Scanning | Secureworks
6: PCI DSS Quick Reference Guide - PCI Security Standards Council
CISA-KR 문제 47
A). The BCP's contact information needs to be updated is not a great concern for an IS auditor reviewing an organization's BCP, as it is a minor issue that can be easily fixed. Contact information refers to the names, phone numbers, email addresses, or other details of the people involved in the BCP execution or communication. Contact information needs to be updated regularly to reflect any changes in personnel or roles. While having outdated contact information may cause some delays or confusion during a BCP activation, it does not affect the overall validity or effectiveness of the BCP.
B). The BCP is not version controlled is not a great concern for an IS auditor reviewing an organization's BCP, as it is a moderate issue that can be improved. Version control refers to the process of tracking and managing changes made to the BCP over time. Version control helps to ensure that only authorized changes are made to the BCP and that there is a clear record of who made what changes when and why. Version control also helps to avoid conflicts or inconsistencies among different versions of the BCP. While having no version control may cause some difficulties or risks in maintaining and updating the BCP, it does not affect the overall validity or effectiveness of the BCP.
C). The BCP has not been approved by senior management is not a great concern for an IS auditor reviewing an organization's BCP, as it is a high-level issue that can be resolved. Approval by senior management refers to the formal endorsement and support of the BCP by the top executives or leaders of the organization.
Approval by senior management helps to ensure that the BCP is aligned with the organization's strategy, objectives, and priorities, and that it has sufficient resources and authority to be implemented. Approval by senior management also helps to increase the awareness and commitment of the organization's stakeholders to the BCP. While having no approval by senior management may affect the credibilityand acceptance of the BCP, it does not affect the overall validity or effectiveness of the BCP. References: Working Toward a Managed, Mature Business Continuity Plan - ISACA, ISACA Introduces New Audit Programs for Business Continuity/Disaster ..., Disaster Recovery and Business Continuity Preparedness for Cloud-based ...
CISA-KR 문제 48
References:
1 explains what is a business continuity plan and why it is important.
2 defines what is a workaround process and how it can be used in a BCP.
3 provides examples of workaround processes for different business functions.
CISA-KR 문제 49
CISA-KR 문제 50
Difference estimation sampling (option A) is not the best sampling approach for these accounts. Difference estimation sampling is a method of audit sampling that estimates the total error or misstatement in a population by multiplying the average difference between the book value and the audited value of the sample items by the number of items in the population. Difference estimation sampling is suitable for populations that have a low variability and a symmetrical distribution, which is not the case for the bank accounts in this question.
Customer unit sampling (option C) is not a sampling approach, but a type of monetary unit sampling.
Monetary unit sampling is a method of audit sampling that selects sample items based on their monetary value, rather than their physical units. Customer unit sampling is a variation of monetary unit sampling that treats each customer account as a single unit, regardless of how many transactions or balances it contains.
Customer unit sampling may be appropriate for testing existence or occurrence assertions, but not for estimating total values.
Unstratified mean per unit sampling (option D) is not the best sampling approach for these accounts.
Unstratified mean per unit sampling is a method of audit sampling that applies mean per unit sampling to the entire population without dividing it into subgroups. Unstratified mean per unit sampling may result in a larger sample size and a lower precision than stratified mean per unit sampling, especially for populations that have a high variability or a skewed distribution, such as the bank accounts in this question.
Therefore, option B is the correct answer.
References:
Audit Sampling - AICPA
Audit Sampling: Examples and Guidance To The Sampling Methods
Audit Sampling |Audit | Financial Audit - Scribd
- 다른 버전
- 1687ISACA.CISA-KR.v2026-08-15.q712
- 4807ISACA.CISA-KR.v2026-05-16.q709
- 2021ISACA.CISA-KR.v2026-05-06.q261
- 3487ISACA.CISA-KR.v2026-03-16.q665
- 4956ISACA.CISA-KR.v2026-03-07.q651
- 9541ISACA.CISA-KR.v2025-04-07.q633
- 4695ISACA.CISA-KR.v2025-04-03.q628
- 3903ISACA.CISA-KR.v2025-04-02.q544
- 4380ISACA.CISA-KR.v2025-03-31.q534
- 5699ISACA.CISA-KR.v2025-03-28.q617
- 3474ISACA.CISA-KR.v2025-03-19.q581
- 4298ISACA.CISA-KR.v2025-03-03.q807
- 5308ISACA.CISA-KR.v2024-02-07.q421
- 2978ISACA.CISA-KR.v2024-01-31.q392
- 5478ISACA.CISA-KR.v2023-10-24.q329
- 5291ISACA.CISA-KR.v2023-07-31.q266
- 3295ISACA.CISA-KR.v2023-06-23.q324
- 최근 업로드
- 164PMI.PMP-KR.v2026-08-27.q1110
- 136ISACA.CISA-KR.v2026-08-27.q676
- 129Workday.Workday-Procure-to-Pay.v2026-08-26.q20
- 202Microsoft.DP-300-KR.v2026-08-26.q212
- 220EC-COUNCIL.312-49.v2026-08-25.q265
- 349Microsoft.AZ-204-KR.v2026-08-25.q295
- 194Microsoft.PL-900-KR.v2026-08-25.q169
- 310Microsoft.AI-102-KR.v2026-08-24.q197
- 371Microsoft.MS-102-KR.v2026-08-24.q284
- 227Databricks.Databricks-Certified-Professional-Data-Engineer-KR.v2026-08-24.q101
PDF 파일 다운로드
메일 주소를 입력하시고 다운로드 하세요. ISACA.CISA-KR.v2026-08-27.q676 모의시험 시험자료를 다운 받으세요.
