CISA-CN Exam Question 96
在審計外包人力資源應用程式時,資訊系統審計師首先應該執行下列哪項操作?
Correct Answer: B
The correct answer is B. Review the terms and provisions in the contract.
When auditing an outsourced application, the auditor should first understand the contractual responsibilities, service scope, control expectations, reporting requirements, audit rights, compliance obligations, and security commitments. ISACA guidance on outsourcing and third-party assurance emphasizes that contracts are foundational because they define what the service provider is obligated to do and what the customer is entitled to review.
Option A is not first because billing validation is secondary to understanding the service arrangement and obligations.
Option C is incorrect because implementing access rights is a management responsibility, not an audit procedure.
Option D is important, but the auditor must first know whether such reporting is required, how it is defined, and under what timelines, all of which are typically governed by the contract or related agreement.
Therefore, the correct answer is B, because contract review establishes the basis for all further audit work over the outsourced HR application.
References (Official ISACA):
* ISACA Journal, Third Party Assurance - highlights the importance of understanding outsourced service arrangements and related assurance expectations.
* ISACA Now Blog, The Challenging Task of Auditing Social Media - states that when a function is outsourced, the contract should be reviewed to ensure it specifies required activities and expectations.
When auditing an outsourced application, the auditor should first understand the contractual responsibilities, service scope, control expectations, reporting requirements, audit rights, compliance obligations, and security commitments. ISACA guidance on outsourcing and third-party assurance emphasizes that contracts are foundational because they define what the service provider is obligated to do and what the customer is entitled to review.
Option A is not first because billing validation is secondary to understanding the service arrangement and obligations.
Option C is incorrect because implementing access rights is a management responsibility, not an audit procedure.
Option D is important, but the auditor must first know whether such reporting is required, how it is defined, and under what timelines, all of which are typically governed by the contract or related agreement.
Therefore, the correct answer is B, because contract review establishes the basis for all further audit work over the outsourced HR application.
References (Official ISACA):
* ISACA Journal, Third Party Assurance - highlights the importance of understanding outsourced service arrangements and related assurance expectations.
* ISACA Now Blog, The Challenging Task of Auditing Social Media - states that when a function is outsourced, the contract should be reviewed to ensure it specifies required activities and expectations.
CISA-CN Exam Question 97
系統管理員最近向資訊系統審計員報告了多次來自組織外部的入侵嘗試,但都沒有成功。下列哪項措施最能有效偵測此類入侵?
Correct Answer: A
The most effective way to detect an intrusion attempt is to periodically review log files, which record the activities and events on a system or network. Log files can provide evidence of unauthorized access attempts, malicious activities, or system errors. Configuring the router as a firewall, using smart cards with one-time passwords, and installing biometrics-basedauthentication are preventive controls that can reduce the likelihood of an intrusion, but they do not detect it. References: ISACA CISA Review Manual 27th Edition, page 301
CISA-CN Exam Question 98
瀑布式軟體開發生命週期模型最適合下列哪一種情況?
Correct Answer: A
The waterfall life cycle model of software development is best suited for situations where the project requirements are well understood. The waterfall life cycle model is a sequential and linear approach to software development that consists of several phases, such as planning, analysis, design, implementation, testing, and maintenance. Each phase depends on the completion and approval of the previous phase before proceeding to the next phase. The waterfall life cycle model is best suited for situations where the project requirements are well understood, as it assumes that the requirements are clear, stable, and fixed at the beginning of the project, and do not change significantly throughout the project. The project is subject to time pressures is not a situation where the waterfall life cycle model of software development is best suited, as it may not be flexible or agile enough to accommodate changes or adjustments in the project schedule or timeline. The waterfall life cycle model may involve long delays or dependencies between phases, and may not allow for early feedback or delivery of software products. The project intends to apply an object-oriented design approach is not a situation where the waterfall life cycle model of software development is best suited, as it may not be compatible or effective with the object-oriented design approach. The object-oriented design approach is a technique that models software as a collection of interacting objects that have attributes and behaviors. The object-oriented design approach may require iterative and incremental development methods that allow for dynamic and adaptive changes in software design and functionality. The project will involve the use of new technology is not a situation where the waterfall life cycle model of software development is best suited, as it may not be able to cope with the uncertainty or complexity of new technology. The waterfall life cycle model may not allow for sufficient exploration or experimentation with new technology, and may not be able to handle changes or issues that arise from new technology.
CISA-CN Exam Question 99
資訊系統審計員正在對一家醫療機構進行實體安全審計,發現病人照護區域安裝了閉路電視監控系統。下列哪一項是最令人擔憂的問題?
Correct Answer: B
The greatest concern with finding closed-circuit television (CCTV) systems located in a patient care area is that there are no notices indicating recording is in progress. This is because CCTV systems in healthcare settings can pose a threat to the privacy and confidentiality of patients, staff, and visitors, especially in sensitive areas where personal or medical information may be exposed. According to the government's Surveillance camera code of practice1, CCTV operators must be as transparent as possible in the use of CCTV, and inform people that they are being recorded by using clear and visible signs. The signs should also provide contact details of the CCTV operator and the purpose of the surveillance. By providing notices, CCTV operators can comply with data protection law and respect the rights and expectations of individuals.
Option B is correct because the lack of notices indicating recording is in progress is a clear violation of the Surveillance camera code of practice1, which applies to local authorities and the police, and is encouraged to be adopted by other CCTV operators in England and Wales. The code also applies to Scotland, along with the National Strategy for Public Space CCTV2. The code is intended to be used in conjunction with the guidance provided by the Information Commissioner's Office (ICO)3, which applies across the UK. The ICO states that CCTV operators must inform people that they are being recorded by using prominent signs at the entrance of the CCTV zone and reinforcing this with further signs inside the area.
Option A is incorrect because cameras not being monitored 24/7 is not the greatest concern, as it does not necessarily affect the privacy and confidentiality of individuals. CCTV systems may have different purposes and objectives, such as deterring or monitoring crime, enhancing security, or improving patient care.
Depending on the purpose, CCTV systems may not require constant monitoring, but rather periodic review or analysis. However, CCTV operators should still ensure that they have adequate security measures to protect the CCTV systems from unauthorized access or tampering.
Option C is incorrect because the retention period for video recordings being undefined is not the greatest concern, as it does not directly affect the privacy and confidentiality of individuals. However, CCTV operators should still define and document their retention policy, and ensure that they do not keep video recordings for longer than necessary, unless they are needed for a specific purpose or as evidence. The retention period should be based on a clear and justifiable rationale, and comply with data protection law and industry guidelines.
Option D is incorrect because there being no backups of the videos is not the greatest concern, as it does not affect the privacy and confidentiality of individuals. However, CCTV operators should still consider having backups of their videos, especially if they are needed for a specific purpose or as evidence. Backups can help to prevent data loss or corruption due to system failures, disasters, or malicious attacks. Backups should also be stored securely and encrypted to prevent unauthorized access or disclosure.
Option B is correct because the lack of notices indicating recording is in progress is a clear violation of the Surveillance camera code of practice1, which applies to local authorities and the police, and is encouraged to be adopted by other CCTV operators in England and Wales. The code also applies to Scotland, along with the National Strategy for Public Space CCTV2. The code is intended to be used in conjunction with the guidance provided by the Information Commissioner's Office (ICO)3, which applies across the UK. The ICO states that CCTV operators must inform people that they are being recorded by using prominent signs at the entrance of the CCTV zone and reinforcing this with further signs inside the area.
Option A is incorrect because cameras not being monitored 24/7 is not the greatest concern, as it does not necessarily affect the privacy and confidentiality of individuals. CCTV systems may have different purposes and objectives, such as deterring or monitoring crime, enhancing security, or improving patient care.
Depending on the purpose, CCTV systems may not require constant monitoring, but rather periodic review or analysis. However, CCTV operators should still ensure that they have adequate security measures to protect the CCTV systems from unauthorized access or tampering.
Option C is incorrect because the retention period for video recordings being undefined is not the greatest concern, as it does not directly affect the privacy and confidentiality of individuals. However, CCTV operators should still define and document their retention policy, and ensure that they do not keep video recordings for longer than necessary, unless they are needed for a specific purpose or as evidence. The retention period should be based on a clear and justifiable rationale, and comply with data protection law and industry guidelines.
Option D is incorrect because there being no backups of the videos is not the greatest concern, as it does not affect the privacy and confidentiality of individuals. However, CCTV operators should still consider having backups of their videos, especially if they are needed for a specific purpose or as evidence. Backups can help to prevent data loss or corruption due to system failures, disasters, or malicious attacks. Backups should also be stored securely and encrypted to prevent unauthorized access or disclosure.
CISA-CN Exam Question 100
下列何者最能減輕部署新生產系統相關的風險?
Correct Answer: A
- Other Version
- 309ISACA.CISA-CN.v2026-09-15.q708
- 1401ISACA.CISA-CN.v2026-05-16.q320
- 3074ISACA.CISA-CN.v2025-12-21.q601
- 3350ISACA.CISA-CN.v2025-12-17.q626
- Latest Upload
- 131Workday.Workday-Pro-Integrations.v2026-09-16.q48
- 133Cisco.350-801.v2026-09-16.q298
- 134SAP.C_ARCIG.v2026-09-16.q35
- 309ISACA.CISA-CN.v2026-09-15.q708
- 140EMC.NCA.v2026-09-15.q38
- 148Netskope.NSK300.v2026-09-14.q35
- 233CompTIA.CV0-004.v2026-09-14.q232
- 194Microsoft.AZ-801.v2026-09-14.q135
- 175NVIDIA.NCA-AIIO.v2026-09-12.q52
- 235CompTIA.220-1202.v2026-09-12.q122
[×]
Download PDF File
Enter your email address to download ISACA.CISA-CN.v2026-05-19.q615 Practice Test
