CISA-CN Exam Question 496
在審查以人工智慧(AI)系統取代多個手動資料輸入系統的專案時,資訊系統稽核員最應該關注的是人工智慧將對以下方面產生的影響:
Correct Answer: B
The auditor should be most concerned with the impact AI will have on enterprise architecture (EA) when reviewing a project to replace multiple manual data entry systems with an AI system. EA is a comprehensive framework that defines the structure, components, relationships, and principles of an organization's IT environment. EA can help to align the IT strategy with the business strategy and ensure the coherence, consistency, and integration of the IT systems and services. Replacing manual data entry systems with an AI system may have significant implications for the EA, such aschanging the business processes, data flows, security requirements, performance standards, or governance models. The auditor should assess whether the project has considered the impact of AI on EA and whether the EA has been updated accordingly. References:
CISA Review Manual (Digital Version), Chapter 1, Section 1.41
CISA Online Review Course, Domain 5, Module 1, Lesson 22
CISA Review Manual (Digital Version), Chapter 1, Section 1.41
CISA Online Review Course, Domain 5, Module 1, Lesson 22
CISA-CN Exam Question 497
現行法規要求組織在發現重大安全事件後 24 小時內向監管機構報告。下列哪一項是資訊系統審計師為促進組織遵守法規而提出的最佳建議?
Correct Answer: D
The best recommendation for the IS auditor to facilitate compliance with the new regulation is to include the requirement in the incident management response plan. An incident management response plan is a document that defines the roles, responsibilities, processes, and procedures for responding to security incidents. By including the new regulation in the plan, the IS auditor can ensure that the organization is aware of the reporting obligation, has a clear workflow for notifying the regulator within 24 hours, and has the necessary documentation and evidence to support the report.
The other options are not as effective as including the requirement in the incident management response plan:
Establishing key performance indicators (KPIs) for timely identification of security incidents is a good practice, but it does not guarantee compliance with the regulation. KPIs are metrics that measure the performance of a process or activity, but they do not specify how to perform it. The IS auditor should also provide guidance on how to identify and report security incidents within 24 hours.
Engaging an external security incident response expert for incident handling is a possible option, but it may not be feasible or cost-effective. The organization may not have the budget or time to hire an external expert, or may prefer to handle the incidents internally. The IS auditor should also evaluate the qualifications and trustworthiness of the external expert, and ensure that they comply with the regulation and other contractual or legal obligations.
Enhancing the alert functionality of the intrusion detection system (IDS) is a useful measure, but it is not sufficient to comply with the regulation. An IDS is a tool that monitors network traffic for malicious activity and alerts the network administrator or takes preventive action. However, an IDS may not detect all types of security incidents, or may generate false positives or negatives. The IS auditor should also consider other sources of incident detection, such as logs, reports, audits, or user feedback.
The other options are not as effective as including the requirement in the incident management response plan:
Establishing key performance indicators (KPIs) for timely identification of security incidents is a good practice, but it does not guarantee compliance with the regulation. KPIs are metrics that measure the performance of a process or activity, but they do not specify how to perform it. The IS auditor should also provide guidance on how to identify and report security incidents within 24 hours.
Engaging an external security incident response expert for incident handling is a possible option, but it may not be feasible or cost-effective. The organization may not have the budget or time to hire an external expert, or may prefer to handle the incidents internally. The IS auditor should also evaluate the qualifications and trustworthiness of the external expert, and ensure that they comply with the regulation and other contractual or legal obligations.
Enhancing the alert functionality of the intrusion detection system (IDS) is a useful measure, but it is not sufficient to comply with the regulation. An IDS is a tool that monitors network traffic for malicious activity and alerts the network administrator or takes preventive action. However, an IDS may not detect all types of security incidents, or may generate false positives or negatives. The IS auditor should also consider other sources of incident detection, such as logs, reports, audits, or user feedback.
CISA-CN Exam Question 498
下列哪項審計程序最能有效評估電子商務應用程式系統編輯流程的有效性?
Correct Answer: B
The most conclusive audit procedure for evaluating the effectiveness of an e-commerce application system's edit routine is to use test transactions. A test transaction is a simulated input that is processed by the system to verify its output and performance1. By using test transactions, an auditor can directly observe how the edit routine checks the validity, accuracy, and completeness of data entered by users, and how it handles incorrect or invalid data. A test transaction can also help measure the efficiency, reliability, and security of the edit routine, as well as identify any errors or weaknesses in the system.
The other options are not as conclusive as using test transactions, as they rely on indirect or secondary sources of information. Reviewing program documentation is an audit procedure that involves examining the written description of the system's design, specifications, and functionality2. However, program documentation may not reflect the actual implementation or operation of the system, and it may not reveal any discrepancies or defects in the edit routine. Interviews with knowledgeable users is an audit procedure that involves asking questions to the people who use or manage the system3. However, interviews with knowledgeable users may not provide sufficient or objective evidence of the edit routine's effectiveness, and they may be influenced by personal opinions or biases. Reviewing source code is an audit procedurethat involves analyzing the programming language and logic of the system4. However, reviewing source code may not be feasible or practical for complex or large systems, and it may not demonstrate how the edit routine performs in real scenarios.
The other options are not as conclusive as using test transactions, as they rely on indirect or secondary sources of information. Reviewing program documentation is an audit procedure that involves examining the written description of the system's design, specifications, and functionality2. However, program documentation may not reflect the actual implementation or operation of the system, and it may not reveal any discrepancies or defects in the edit routine. Interviews with knowledgeable users is an audit procedure that involves asking questions to the people who use or manage the system3. However, interviews with knowledgeable users may not provide sufficient or objective evidence of the edit routine's effectiveness, and they may be influenced by personal opinions or biases. Reviewing source code is an audit procedurethat involves analyzing the programming language and logic of the system4. However, reviewing source code may not be feasible or practical for complex or large systems, and it may not demonstrate how the edit routine performs in real scenarios.
CISA-CN Exam Question 499
在完成對IT系統的滲透測試並得出測試結果後,下一步應該是:
Correct Answer: C
The correct answer is C. Remediation and retesting.
ISACA guidance explains that penetration testing identifies exploitable weaknesses and provides guidance to address them. Once findings are identified, the next logical and control-appropriate step is to remediate the weaknesses and then retest to confirm they have been effectively resolved.
Option A is not the best next step because vulnerability scanning may supplement testing, but after a completed penetration test with findings, the priority is to fix what was found and verify closure.
Option B may be part of root cause work, but it is not the primary next step.
Option D is important from an information-handling perspective, but it does not address the control weaknesses identified by the test.
Therefore, the correct answer is C, because findings from a penetration test should drive remediation followed by retesting to validate that the identified weaknesses have been corrected.
References (Official ISACA):
* ISACA, The Future of Cybersecurity Assessments Is Here - VAPT identifies weaknesses and provides guidance to address them.
* ISACA, Taking a Risk-Based Approach to Pen Testing - findings should be evaluated and acted on according to business impact.
* ISACA, Smarter Testing Equals Safer Digital Experiences - findings should be assessed for exploitability and impact, supporting focused remediation.
ISACA guidance explains that penetration testing identifies exploitable weaknesses and provides guidance to address them. Once findings are identified, the next logical and control-appropriate step is to remediate the weaknesses and then retest to confirm they have been effectively resolved.
Option A is not the best next step because vulnerability scanning may supplement testing, but after a completed penetration test with findings, the priority is to fix what was found and verify closure.
Option B may be part of root cause work, but it is not the primary next step.
Option D is important from an information-handling perspective, but it does not address the control weaknesses identified by the test.
Therefore, the correct answer is C, because findings from a penetration test should drive remediation followed by retesting to validate that the identified weaknesses have been corrected.
References (Official ISACA):
* ISACA, The Future of Cybersecurity Assessments Is Here - VAPT identifies weaknesses and provides guidance to address them.
* ISACA, Taking a Risk-Based Approach to Pen Testing - findings should be evaluated and acted on according to business impact.
* ISACA, Smarter Testing Equals Safer Digital Experiences - findings should be assessed for exploitability and impact, supporting focused remediation.
CISA-CN Exam Question 500
在高容量、即時系統中,持續監控和分析交易處理最有效的技術是:
Correct Answer: C
Transaction tagging is a technique by which transactions are marked with unique identifiers or headers and traced through the system using agents or sensors at each processing point1. Transaction tagging allows for continuous monitoring and analysis of transaction processing in a high-volume, real-time system by providing visibility into the performance, availability, and reliability of each transaction and its components1. Transaction tagging can also help to identify and isolate errors, bottlenecks, anomalies, and security issues in the system1.
- Other Version
- 313ISACA.CISA-CN.v2026-09-15.q708
- 1411ISACA.CISA-CN.v2026-05-16.q320
- 3078ISACA.CISA-CN.v2025-12-21.q601
- 3354ISACA.CISA-CN.v2025-12-17.q626
- Latest Upload
- 131Workday.Workday-Pro-Integrations.v2026-09-16.q48
- 133Cisco.350-801.v2026-09-16.q298
- 134SAP.C_ARCIG.v2026-09-16.q35
- 313ISACA.CISA-CN.v2026-09-15.q708
- 140EMC.NCA.v2026-09-15.q38
- 149Netskope.NSK300.v2026-09-14.q35
- 234CompTIA.CV0-004.v2026-09-14.q232
- 194Microsoft.AZ-801.v2026-09-14.q135
- 175NVIDIA.NCA-AIIO.v2026-09-12.q52
- 237CompTIA.220-1202.v2026-09-12.q122
[×]
Download PDF File
Enter your email address to download ISACA.CISA-CN.v2026-05-19.q615 Practice Test
