CISA-CN Exam Question 131
下列哪一項是確定檔案伺服器所需資料保護等級的最佳資訊來源?
Correct Answer: A
The best source of information to determine the required level of data protection on a file server is the data classification policy and procedures, which define the criteria and methods for classifying data according to its sensitivity, value, and criticality, and specify the appropriate security measures and controls for each data category. Data classification policy and procedures help to ensure that data is protected in proportion to its importance and risk exposure. Access rights of similar file servers, previous data breach incident reports, and acceptable use policy and privacy statements are not sufficient or reliable sources of information to determine the required level of data protection on a file server, as they do not provide clear and consistent guidance on how to classify and protect data. References: CISA Review Manual (Digital Version), Chapter 5: Protection of Information Assets, Section 5.1: Information Asset Security Framework
CISA-CN Exam Question 132
制定服務等級協定 (SLAP) 時最需要考慮下列哪一項?
Correct Answer: D
The most important factor to consider when developing a service level agreement (SLA) is the description of the services from the viewpoint of the client organization, because the SLA shouldreflect the needs and expectations of the client and specify the measurable outcomes and performance indicators that the provider must deliver34. The description of the services from the viewpoint of the provider, the detailed identification of work to be completed, and the provisions for regulatory requirements that impact the end users' businesses are also important elements of an SLA, but not as crucial as the client'sperspective. References: 3: CISA Review Manual (Digital Version), Chapter 5, Section 5.3.1 4: CISA Online Review Course, Module 5, Lesson 3
CISA-CN Exam Question 133
如果使用下列哪一種滅火系統來保護資產儲藏室,IS 審計員應該最關心?
Correct Answer: D
A CO2 system could be a concern for an IS auditor when used to protect an asset storage closet. While CO2 systems are effective at suppressing fires, they can pose a significant safety risk to personnel. In the event of a fire, the CO2 system would fill the room with carbon dioxide, displacing the oxygen. This could be hazardous to anyone who might be in the room at the time12.
References: ISACA's Information Systems Auditor Study Materials1
References: ISACA's Information Systems Auditor Study Materials1
CISA-CN Exam Question 134
組織對其內部網路上儲存的資料進行分類的主要原因是什麼?
Correct Answer: B
The primary reason for an organization to classify the data stored on its internal networks is to implement data protection requirements1234. Data classification helps organizations understand what data they have, its characteristics, and what security and privacy requirements it needs to meet so that the necessary protections can be achieved3. While determining data retention policy56, complying with the organization's data policies27, and following industry best practices891011 are important aspects of data classification, they are secondary to the fundamental requirement of implementing data protection requirements.
References:
What Is Data Classification & Why Is It Important? - RiskOptics
Data Classification Policy: Definition, Examples, & Free Template - Hyperproof Data Classification Policy: Benefits, Examples, and Techniques - Satori What is a Data Classification Policy? - Digital Guardian Data Classification and Practices - NIST Data Classification as a Catalyst for Data Retention and Archiving ...
What is data classification? - Cloud Adoption Framework
Data Classification - Data Security Policies | ITS Policies ...
IMPLEMENTING DATA CLASSIFICATION PRACTICES - NIST
Best Practices for Data Classification | Forcepoint
References:
What Is Data Classification & Why Is It Important? - RiskOptics
Data Classification Policy: Definition, Examples, & Free Template - Hyperproof Data Classification Policy: Benefits, Examples, and Techniques - Satori What is a Data Classification Policy? - Digital Guardian Data Classification and Practices - NIST Data Classification as a Catalyst for Data Retention and Archiving ...
What is data classification? - Cloud Adoption Framework
Data Classification - Data Security Policies | ITS Policies ...
IMPLEMENTING DATA CLASSIFICATION PRACTICES - NIST
Best Practices for Data Classification | Forcepoint
CISA-CN Exam Question 135
IS 審計員正在審查客戶的外包薪資系統,以評估財務審計團隊是否可以依賴該應用程式。下列哪一項調查結果是審計師最關心的問題?
Correct Answer: C
The third-party contract has not been reviewed by the legal department is the auditor's greatest concern because it poses a significant legal and financial risk to the client. A third-party contract is a legally binding agreement between the client and the outsourced payroll provider that defines the scope, terms, and conditions of the service. A third-party contract should be reviewed by the legal department to ensure that it complies with the applicable laws and regulations, protects the client's interests and rights, and specifies the roles and responsibilities of both parties. A third-party contract that has not been reviewed by the legal department may contain clauses that are unfavorable, ambiguous, or contradictory to the client, such as:
* Inadequate or unclear service level agreements (SLAs) that do not specify the quality, timeliness, and accuracy of the payroll service.
* Insufficient or vague security and confidentiality provisions that do not safeguard the client's data and information from unauthorized access, use, disclosure, or loss.
* Unreasonable or excessive fees, penalties, or liabilities that may impose an undue financial burden on the client.
* Limited or no audit rights that may prevent the client from verifying the effectiveness and compliance of the payroll provider's internal controls.
* Inflexible or restrictive termination clauses that may limit the client's ability to cancel or switch to another payroll provider.
A third-party contract that has not been reviewed by the legal department may expose the client to various risks, such as:
* Legal disputes or litigation with the payroll provider over contractual breaches or performance issues.
* Regulatory fines or sanctions for noncompliance with tax, labor, or other laws and regulations related to payroll.
* Financial losses or damages due to errors, fraud, or negligence by the payroll provider.
* Reputation damage or customer dissatisfaction due to payroll errors or delays.
Therefore, an IS auditor should be highly concerned about a third-party contract that has not been reviewed by the legal department and recommend that the client seek legal advice before signing or renewing any contract with an outsourced payroll provider.
User access rights have not been periodically reviewed by the client is a moderate concern because it may indicate a lack of proper access control over the payroll system. User access rights are the permissions granted to users to access, view, modify, or delete data and information in the payroll system. User access rights should be periodically reviewed by the client to ensure that they are aligned with the user's roles and responsibilities, and that they are revoked or modified when a user changes roles or leaves the organization.
User access rights that are not periodically reviewed by the client may result in unauthorized or inappropriate access to payroll data and information, which may compromise its confidentiality, integrity, and availability.
Payroll processing costs have not been included in the IT budget is a minor concern because it may indicate a lack of proper planning and allocation of IT resources for payroll processing. Payroll processing costs are the expenses incurred by the client for using an outsourced payroll service, such as fees, charges, taxes, or penalties. Payroll processing costs should be included in the IT budget to ensure that they are adequately estimated, monitored, and controlled. Payroll processing costs that are not included in the IT budget may result in unexpected or excessive costs for payroll processing, which may affect the client's profitability and cash flow.
The third-party contract does not comply with the vendor management policy is a low concern because it may indicate a lack of alignment between the client's vendor management policy and its actual vendor selection and evaluation process. A vendor management policy is a set of guidelines and procedures that governs how the client manages its relationship with its vendors, such as how to select, monitor, evaluate, and terminate vendors. A vendor management policy should be consistent with the client's business objectives, risk appetite, and regulatory requirements. A third-party contract that does not comply with the vendor management policy may result in suboptimal vendor performance or service quality, but it does not necessarily imply a breach of contract or a violation of law.
* Inadequate or unclear service level agreements (SLAs) that do not specify the quality, timeliness, and accuracy of the payroll service.
* Insufficient or vague security and confidentiality provisions that do not safeguard the client's data and information from unauthorized access, use, disclosure, or loss.
* Unreasonable or excessive fees, penalties, or liabilities that may impose an undue financial burden on the client.
* Limited or no audit rights that may prevent the client from verifying the effectiveness and compliance of the payroll provider's internal controls.
* Inflexible or restrictive termination clauses that may limit the client's ability to cancel or switch to another payroll provider.
A third-party contract that has not been reviewed by the legal department may expose the client to various risks, such as:
* Legal disputes or litigation with the payroll provider over contractual breaches or performance issues.
* Regulatory fines or sanctions for noncompliance with tax, labor, or other laws and regulations related to payroll.
* Financial losses or damages due to errors, fraud, or negligence by the payroll provider.
* Reputation damage or customer dissatisfaction due to payroll errors or delays.
Therefore, an IS auditor should be highly concerned about a third-party contract that has not been reviewed by the legal department and recommend that the client seek legal advice before signing or renewing any contract with an outsourced payroll provider.
User access rights have not been periodically reviewed by the client is a moderate concern because it may indicate a lack of proper access control over the payroll system. User access rights are the permissions granted to users to access, view, modify, or delete data and information in the payroll system. User access rights should be periodically reviewed by the client to ensure that they are aligned with the user's roles and responsibilities, and that they are revoked or modified when a user changes roles or leaves the organization.
User access rights that are not periodically reviewed by the client may result in unauthorized or inappropriate access to payroll data and information, which may compromise its confidentiality, integrity, and availability.
Payroll processing costs have not been included in the IT budget is a minor concern because it may indicate a lack of proper planning and allocation of IT resources for payroll processing. Payroll processing costs are the expenses incurred by the client for using an outsourced payroll service, such as fees, charges, taxes, or penalties. Payroll processing costs should be included in the IT budget to ensure that they are adequately estimated, monitored, and controlled. Payroll processing costs that are not included in the IT budget may result in unexpected or excessive costs for payroll processing, which may affect the client's profitability and cash flow.
The third-party contract does not comply with the vendor management policy is a low concern because it may indicate a lack of alignment between the client's vendor management policy and its actual vendor selection and evaluation process. A vendor management policy is a set of guidelines and procedures that governs how the client manages its relationship with its vendors, such as how to select, monitor, evaluate, and terminate vendors. A vendor management policy should be consistent with the client's business objectives, risk appetite, and regulatory requirements. A third-party contract that does not comply with the vendor management policy may result in suboptimal vendor performance or service quality, but it does not necessarily imply a breach of contract or a violation of law.
- Other Version
- 322ISACA.CISA-CN.v2026-09-15.q708
- 3254ISACA.CISA-CN.v2026-05-19.q615
- 1417ISACA.CISA-CN.v2026-05-16.q320
- 3088ISACA.CISA-CN.v2025-12-21.q601
- Latest Upload
- 131Workday.Workday-Pro-Integrations.v2026-09-16.q48
- 133Cisco.350-801.v2026-09-16.q298
- 134SAP.C_ARCIG.v2026-09-16.q35
- 322ISACA.CISA-CN.v2026-09-15.q708
- 140EMC.NCA.v2026-09-15.q38
- 149Netskope.NSK300.v2026-09-14.q35
- 234CompTIA.CV0-004.v2026-09-14.q232
- 194Microsoft.AZ-801.v2026-09-14.q135
- 176NVIDIA.NCA-AIIO.v2026-09-12.q52
- 237CompTIA.220-1202.v2026-09-12.q122
[×]
Download PDF File
Enter your email address to download ISACA.CISA-CN.v2025-12-17.q626 Practice Test
