CISA-CN Exam Question 341
與內部開發系統相比,獲取軟體包意味著最終用戶測試的需求是:
Correct Answer: B
Compared to developing a system in-house, acquiring a software package means that the need for testing by end users is unchanged. This is because end users are still the ultimate customers and beneficiaries of the system, and they need to ensure that the software package meets their requirements, expectations, and satisfaction. End user testing, also known as user acceptance testing (UAT) or beta testing, is the final stage of testing performed by the user or client to determine whether the software can be accepted or not1. End user testing is important for both in-house developed and acquired software packages, as it helps to verify the functionality, usability, performance, and reliability of the system2. End user testing also helps to identify and resolve any defects, errors, or issues that may not have been detected by the developers or vendors3.
Therefore, option B is the correct answer.
Option A is not correct because end user testing is not eliminated by acquiring a software package. Even though the software package may have been tested by the vendor or supplier, it may still have bugs, compatibility issues, or configuration problems that need to be fixed before deployment4. Option C is not correct because end user testing is not increased by acquiring a software package. The scope and extent of end user testing depend on various factors, such as the complexity, criticality, and customization of the system, and not on whether it is developed in-house or acquired. Option D is not correct because end user testing is not reduced by acquiring a software package. The software package may still require modifications or integrations to suit the specific needs and environment of the organization, and these changes need to be tested by the end users.
References:
Chapter 4 Methods of Software Acquisition5
What is User Acceptance Testing (UAT): A Complete Guide1
What Is End-to-End Testing? (With How-To and Example)3
How to Evaluate New Software in 5 Steps4
User Acceptance Testing (UAT) in ERP Projects
User Acceptance Testing for Packaged Software
Therefore, option B is the correct answer.
Option A is not correct because end user testing is not eliminated by acquiring a software package. Even though the software package may have been tested by the vendor or supplier, it may still have bugs, compatibility issues, or configuration problems that need to be fixed before deployment4. Option C is not correct because end user testing is not increased by acquiring a software package. The scope and extent of end user testing depend on various factors, such as the complexity, criticality, and customization of the system, and not on whether it is developed in-house or acquired. Option D is not correct because end user testing is not reduced by acquiring a software package. The software package may still require modifications or integrations to suit the specific needs and environment of the organization, and these changes need to be tested by the end users.
References:
Chapter 4 Methods of Software Acquisition5
What is User Acceptance Testing (UAT): A Complete Guide1
What Is End-to-End Testing? (With How-To and Example)3
How to Evaluate New Software in 5 Steps4
User Acceptance Testing (UAT) in ERP Projects
User Acceptance Testing for Packaged Software
CISA-CN Exam Question 342
下列哪一項應該是管理最近發現的零時差攻擊影響的第一步?
Correct Answer: C
The first step in managing the impact of a recently discovered zero-day attack is to identify vulnerable assets.
A zero-day attack is a cyberattack that exploits a previously unknown or unpatched vulnerability in a software or system, before the vendor or developer has had time to fix it. Identifying vulnerable assets is crucial for managing the impact of a zero-day attack, because it helps to determine the scope and severity of the attack, prioritize the protection and mitigation measures, and isolate or quarantine the affected assets from further damage or compromise. The other options are not the first steps in managing the impact of a zero-day attack, because they either require more information about the vulnerable assets, or they are part of the subsequent steps of assessing, responding, or recovering from the attack. References: CISA Review Manual (Digital Version)1, Chapter 5, Section 5.2.4
A zero-day attack is a cyberattack that exploits a previously unknown or unpatched vulnerability in a software or system, before the vendor or developer has had time to fix it. Identifying vulnerable assets is crucial for managing the impact of a zero-day attack, because it helps to determine the scope and severity of the attack, prioritize the protection and mitigation measures, and isolate or quarantine the affected assets from further damage or compromise. The other options are not the first steps in managing the impact of a zero-day attack, because they either require more information about the vulnerable assets, or they are part of the subsequent steps of assessing, responding, or recovering from the attack. References: CISA Review Manual (Digital Version)1, Chapter 5, Section 5.2.4
CISA-CN Exam Question 343
在測試磁帶備份程序的充分性時,哪一步最能驗證定期安排的備份是否及時且執行完成?
Correct Answer: D
Reviewing a sample of system-generated backup logs is the best step to verify that regularly scheduled backups are timely and run to completion. Backup logs are records that document the details and results of backup operations, such as the date, time, duration, status, errors, and exceptions. By reviewing a sample of backup logs, the IS auditor can check whether the backups are performed according to the schedule and whether they are completed successfully or not. The other steps do not provide as much evidence or assurance as reviewing backup logs, as they do not show the actual outcome or performance of backup operations. References: CISA Review Manual, 27th Edition, page 247
CISA-CN Exam Question 344
一項新法規已經頒布,強制要求採取特定的資訊安全實踐來保護客戶資料。在根據法規進行審計時,資訊系統審計師需要審查下列哪一項最有用?
Correct Answer: A
A compliance gap analysis is a detailed review of an organization's current state of compliance against a specific regulation or standard. It helps identify the areas and controls that are not meeting the requirements, assess their risk levels, and determine the corrective actions that can be taken to achieve compliance12. A compliance gap analysis is the most useful tool for an IS auditor to review when auditing against a new regulation, as it provides a clear and comprehensive picture of the compliance status, gaps, and remediation plan of the organization.
References
1: Information Security Architecture: Gap Assessment and Prioritization - ISACA
2: How to perform Compliance Gap Analysis? - Sprinto
References
1: Information Security Architecture: Gap Assessment and Prioritization - ISACA
2: How to perform Compliance Gap Analysis? - Sprinto
CISA-CN Exam Question 345
下列哪一項是資訊安全計畫最重要的成果?
Correct Answer: D
The most importantoutcome of an information security program is to improve the organizational awareness of security responsibilities, as this will foster a culture of security and ensure that all stakeholders are aware of their roles and obligations in protecting the information assets of the organization. An information security program should also aimto achieve other outcomes, such as identifying operating system weaknesses, understanding and accepting emerging security technologies, and reducing the cost to mitigate information security risk, but these are not as important as improving the awareness of security responsibilities, which is the foundation of any effective information security program. *References: According to the ISACA IT Audit and Assurance Standards, Guidelines and Tools and Techniques for IS Audit and Assurance Professionals, section 2402 Planning, "The IS audit and assurance professional should identify and assess risk relevant to the area under review." 1 One of the risk factors to consider is "the level of awareness of management and staff regarding IT risk management" 1. According to the ISACAIT Audit and Assurance Guideline G13 Information Security Management, "The objective of an information security management audit
/assurancereview is to provide management with an independent assessment relating to the effectiveness of information security management within the enterprise." The guideline also states that "the audit/assurance professional should evaluate whether there is an appropriate level of awareness throughout the enterprise regarding information security policies, standards, procedures and guidelines." According to a web search result from Microsoft Security, "Information security programs need to: ... Support the execution of decisions." 2 One of the ways to support the execution of decisions is to ensure that everyone in the organization understands their security responsibilities and follows the security policies and procedures.
/assurancereview is to provide management with an independent assessment relating to the effectiveness of information security management within the enterprise." The guideline also states that "the audit/assurance professional should evaluate whether there is an appropriate level of awareness throughout the enterprise regarding information security policies, standards, procedures and guidelines." According to a web search result from Microsoft Security, "Information security programs need to: ... Support the execution of decisions." 2 One of the ways to support the execution of decisions is to ensure that everyone in the organization understands their security responsibilities and follows the security policies and procedures.
- Other Version
- 360ISACA.CISA-CN.v2026-09-15.q708
- 3287ISACA.CISA-CN.v2026-05-19.q615
- 1423ISACA.CISA-CN.v2026-05-16.q320
- 3147ISACA.CISA-CN.v2025-12-21.q601
- Latest Upload
- 132Workday.Workday-Pro-Integrations.v2026-09-16.q48
- 134Cisco.350-801.v2026-09-16.q298
- 135SAP.C_ARCIG.v2026-09-16.q35
- 360ISACA.CISA-CN.v2026-09-15.q708
- 142EMC.NCA.v2026-09-15.q38
- 154Netskope.NSK300.v2026-09-14.q35
- 236CompTIA.CV0-004.v2026-09-14.q232
- 195Microsoft.AZ-801.v2026-09-14.q135
- 181NVIDIA.NCA-AIIO.v2026-09-12.q52
- 247CompTIA.220-1202.v2026-09-12.q122
[×]
Download PDF File
Enter your email address to download ISACA.CISA-CN.v2025-12-17.q626 Practice Test
