CISA-KR 문제 1
CISA-KR 문제 2
CISA Review Manual (Digital Version), Chapter 4, Section 4.11
CISA Online Review Course, Domain 1, Module 2, Lesson 12
CISA-KR 문제 3
Therefore, a firewall is vulnerable to flooding attacks that exploit its limited resources. Phishing is an attack technique that involves sending fraudulent emails or messages that appear to come from legitimate sources, such as banks, government agencies, online services, etc., in order to trick recipients into revealing their personal or financial information, such as passwords, credit card numbers, bank account details, etc., or into clicking on malicious links or attachments that can infect their systems with malware or ransomware.
Phishing does not exploit an inherent security weakness in an Internet firewall, but rather exploits human psychology and social engineering techniques. A firewall cannot prevent phishing emails or messages from reaching their intended targets, unless they contain some identifiable features that can be filtered out by the firewall rules. However, a firewall cannot detect or prevent users from responding to phishing emails or messages or from opening malicious links or attachments. Using a dictionary attack of encrypted passwords is an attack technique that involves trying to guess or crack passwords by using a list of common or likely passwords or by using a brute-force method that tries all possible combinations of characters. This type of attack does not exploit an inherent security weakness in an Internet firewall, but rather exploits weak or poorly chosen passwords or weak encryption algorithms. A firewall cannot prevent a dictionary attack of encrypted passwords, unless it has some mechanisms to detect and block repeated or suspicious login attempts or to enforce strong password policies. However, a firewall cannot protect passwords from being stolen or intercepted by other means, such as phishing, malware, keylogging, etc. Intercepting packets and viewing passwords is an attack technique that involves capturing and analyzing network traffic that contains sensitive information, such as passwords, credit card numbers, bank account details, etc., in order to use them for malicious purposes. This type of attack does not exploit an inherent security weakness in an Internet firewall, but rather exploits insecure or unencrypted network communication protocols or channels. A firewall cannot prevent packets from being intercepted and viewed by unauthorized parties, unless it has some mechanisms to encrypt or obfuscate the network traffic or to authenticate the source and destination of the traffic. However, a firewall cannot protect packets from being modified or tampered with by other means, such as man-in-the- middle attacks, replay attacks, etc. References: ISACA CISA Review Manual 27th Edition, page 300
CISA-KR 문제 4
CISA-KR 문제 5
Option C is correct because data definition standards are about consistency of data structure and representation. When an organization enforces common definitions for fields and attributes, it improves the consistency and usability of data across systems and applications. ISACA governance and data management material emphasizes that defining the format in which data are presented is part of giving data meaning and ensuring quality and usability.
Option A is incorrect because data disposal concerns end-of-life handling of data, such as destruction, archival expiration, and secure deletion. Those activities are governed by retention, records management, privacy, and disposal requirements, not by database data definition standards. ISACA privacy and data lifecycle guidance treats disposal as a separate lifecycle issue.
Option B is incorrect because data retention relates to how long data should be kept for business, legal, regulatory, or operational purposes. Retention policies may rely on data classification and legal obligations, but they are not what data definition standards primarily address.
Option D is incorrect because data confidentiality is mainly supported by access controls, encryption, classification, segregation of duties, and related security controls. Although well-defined data may indirectly help governance, confidentiality is not the main purpose of data definition standards.
Therefore, the best answer is C because enforcing data definition standards within a database most directly supports correct and consistent data formatting.
References (Official ISACA):
ISACA Glossary - Format checking.
ISACA, Unearthing and Enhancing Intelligence and Wisdom Within the COBIT 5 Governance of Information Model - discusses defining the format in which data are presented.
ISACA Journal, IS Audit Basics: Data Management Body of Knowledge-A Summary for Auditors - supports the role of data management standards and quality.
ISACA, SOC Reports for Cloud Security and Privacy - distinguishes use, retention, and disposal from data structure concerns.
- 다른 버전
- 1682ISACA.CISA-KR.v2026-08-15.q712
- 4807ISACA.CISA-KR.v2026-05-16.q709
- 2019ISACA.CISA-KR.v2026-05-06.q261
- 3486ISACA.CISA-KR.v2026-03-16.q665
- 4952ISACA.CISA-KR.v2026-03-07.q651
- 9541ISACA.CISA-KR.v2025-04-07.q633
- 4693ISACA.CISA-KR.v2025-04-03.q628
- 3903ISACA.CISA-KR.v2025-04-02.q544
- 4380ISACA.CISA-KR.v2025-03-31.q534
- 5698ISACA.CISA-KR.v2025-03-28.q617
- 3474ISACA.CISA-KR.v2025-03-19.q581
- 4297ISACA.CISA-KR.v2025-03-03.q807
- 5307ISACA.CISA-KR.v2024-02-07.q421
- 2977ISACA.CISA-KR.v2024-01-31.q392
- 5478ISACA.CISA-KR.v2023-10-24.q329
- 5291ISACA.CISA-KR.v2023-07-31.q266
- 3295ISACA.CISA-KR.v2023-06-23.q324
- 최근 업로드
- 128PMI.PMP-KR.v2026-08-27.q1110
- 115ISACA.CISA-KR.v2026-08-27.q676
- 129Workday.Workday-Procure-to-Pay.v2026-08-26.q20
- 178Microsoft.DP-300-KR.v2026-08-26.q212
- 216EC-COUNCIL.312-49.v2026-08-25.q265
- 347Microsoft.AZ-204-KR.v2026-08-25.q295
- 194Microsoft.PL-900-KR.v2026-08-25.q169
- 310Microsoft.AI-102-KR.v2026-08-24.q197
- 370Microsoft.MS-102-KR.v2026-08-24.q284
- 226Databricks.Databricks-Certified-Professional-Data-Engineer-KR.v2026-08-24.q101
PDF 파일 다운로드
메일 주소를 입력하시고 다운로드 하세요. ISACA.CISA-KR.v2026-08-27.q676 모의시험 시험자료를 다운 받으세요.
