CISA-KR 문제 11
The other options are not as good as option B, as they may not capture the full scope or benefits of using an IT governance framework. Frameworks enable IT benchmarks against competitors, but this is not the main purpose or advantage of using an IT governance framework. Frameworks help facilitate control self- assessments (CSAs), but this is only one aspect or tool of an IT governance framework. Frameworks help organizations understand and manage IT risk, but this is also only one outcome or objective of an IT governance framework.
References:
1: What is ITIL? Your guide to the IT Infrastructure Library | CIO
2: IT Governance Framework | Components | Framework | Terminology - EDUCBA
3: IT Governance: Definitions, Frameworks and Planning - ProjectManager
4: What Is IT Governance? - Definition from Techopedia
5: What is IT Governance? A formal way to align IT and business strategy | CIO
6: What Is IT Governance? - Definition from WhatIs.com
7: ISO/IEC 20000 Information Technology Service Management Systems Standard - ISO/IEC 20000 Portal
8: COBIT | Control Objectives for Information Technologies | ISACA
CISA-KR 문제 12
References (ISACA): CISA Review Manual - Cryptography Concepts; ISACA Glossary.
CISA-KR 문제 13
Periodic network vulnerability assessments (B) can also help to detect unauthorized wireless access points, but they are not as effective as continuous network monitoring, because they are performed at fixed intervals and may miss some devices that are added or removed between the assessments. Review of electronic access logs can provide some information about the devices that access the network, but they may not be able to detect devices that use fake or stolen credentials or devices that do not generate any logs. Physical security reviews (D) can help to prevent unauthorized physical access to the network ports or devices, but they may not be able to detect wireless access points that are hidden or disguised as legitimate devices.
CISA-KR 문제 14
Option B is correct because evaluating impact is what determines the seriousness of the deficiency and the appropriate audit response. Without understanding the effect of the deviation, the auditor cannot appropriately decide whether to escalate it, report it, or recommend redesign.
Option C is important and usually happens during audit communication, but discussion with control owners is not the primary analytical step. The auditor must first understand the risk and significance of the partial compliance.
Option D is incorrect because not every partial deviation should automatically become a final-report finding.
The auditor should first evaluate whether the issue is significant and reportable. ISACA follow-up guidance specifically refers to significant issues/findings.
Option A is also incorrect because recommending redesign may be appropriate later, but only after the auditor understands the impact and whether the problem is design-related, operating-related, or user-adoption-related.
Therefore, B is the best answer because impact evaluation comes before escalation, formal reporting, or redesign recommendations.
References (Official ISACA):
* ISACA Journal, Enhancing the Audit Follow-up Process Using COBIT 5 - significant issues/findings should be captured and followed up.
* ISACA Journal, An Approach Toward Sarbanes-Oxley ITGC Risk Assessment - supports a risk-based evaluation approach focused on control process areas.
* ISACA, How Effective Is Your Cybersecurity Audit - effectiveness depends on evaluating gaps and their implications.
CISA-KR 문제 15
- 다른 버전
- 1684ISACA.CISA-KR.v2026-08-15.q712
- 4807ISACA.CISA-KR.v2026-05-16.q709
- 2020ISACA.CISA-KR.v2026-05-06.q261
- 3486ISACA.CISA-KR.v2026-03-16.q665
- 4956ISACA.CISA-KR.v2026-03-07.q651
- 9541ISACA.CISA-KR.v2025-04-07.q633
- 4693ISACA.CISA-KR.v2025-04-03.q628
- 3903ISACA.CISA-KR.v2025-04-02.q544
- 4380ISACA.CISA-KR.v2025-03-31.q534
- 5698ISACA.CISA-KR.v2025-03-28.q617
- 3474ISACA.CISA-KR.v2025-03-19.q581
- 4297ISACA.CISA-KR.v2025-03-03.q807
- 5307ISACA.CISA-KR.v2024-02-07.q421
- 2978ISACA.CISA-KR.v2024-01-31.q392
- 5478ISACA.CISA-KR.v2023-10-24.q329
- 5291ISACA.CISA-KR.v2023-07-31.q266
- 3295ISACA.CISA-KR.v2023-06-23.q324
- 최근 업로드
- 145PMI.PMP-KR.v2026-08-27.q1110
- 122ISACA.CISA-KR.v2026-08-27.q676
- 129Workday.Workday-Procure-to-Pay.v2026-08-26.q20
- 189Microsoft.DP-300-KR.v2026-08-26.q212
- 218EC-COUNCIL.312-49.v2026-08-25.q265
- 347Microsoft.AZ-204-KR.v2026-08-25.q295
- 194Microsoft.PL-900-KR.v2026-08-25.q169
- 310Microsoft.AI-102-KR.v2026-08-24.q197
- 371Microsoft.MS-102-KR.v2026-08-24.q284
- 226Databricks.Databricks-Certified-Professional-Data-Engineer-KR.v2026-08-24.q101
PDF 파일 다운로드
메일 주소를 입력하시고 다운로드 하세요. ISACA.CISA-KR.v2026-08-27.q676 모의시험 시험자료를 다운 받으세요.
