CISA-CN Exam Question 171
下列何者最有利於系統開發專案的效益實現過程?
Correct Answer: A
A benefits realization process is a systematic way of identifying, defining, planning, tracking and realizing the benefits from a project or program. Benefits are the measurable improvements that result from the delivery of project outputs and outcomes. Benefits realization management (BRM) is the practice of ensuring that benefits are derived from outputs and outcomes.
One of the best practices for BRM is to select metrics for the project before it begins. Metrics are the indicators that measure the performance and value of the project and its benefits. By selecting metrics in advance, the project team can align the project objectives with the expected benefits, establish a baseline for comparison, and monitor and evaluate the progress and results of the project. Metrics also help to communicate the value of the project to stakeholders and justify the investment.
The other options are not as effective as selecting metrics before the project begins. Project budget is an important factor for BRM, but it does not enable the benefits realization process by itself. It only reflects the costs of executing the project and delivering the solution, not the benefits or value that are expected from them. Estimates of business benefits are useful for planning and forecasting, but they are not sufficient for BRM. They need to be validated by actual data and evidence from similar projects or other sources. Metrics are evaluated after the project has been implemented, but this is only one part of the benefits realization process. BRM requires continuous monitoring and evaluation throughout the project life cycle and beyond, to ensure that benefits are sustained and optimized.
References:
ISACA, CISA Review Manual, 27th Edition, 2019, p. 3261
PMI, Benefits Realization Management: A Practice Guide, 20192
APM, What is benefits management and project success?, 20213
One of the best practices for BRM is to select metrics for the project before it begins. Metrics are the indicators that measure the performance and value of the project and its benefits. By selecting metrics in advance, the project team can align the project objectives with the expected benefits, establish a baseline for comparison, and monitor and evaluate the progress and results of the project. Metrics also help to communicate the value of the project to stakeholders and justify the investment.
The other options are not as effective as selecting metrics before the project begins. Project budget is an important factor for BRM, but it does not enable the benefits realization process by itself. It only reflects the costs of executing the project and delivering the solution, not the benefits or value that are expected from them. Estimates of business benefits are useful for planning and forecasting, but they are not sufficient for BRM. They need to be validated by actual data and evidence from similar projects or other sources. Metrics are evaluated after the project has been implemented, but this is only one part of the benefits realization process. BRM requires continuous monitoring and evaluation throughout the project life cycle and beyond, to ensure that benefits are sustained and optimized.
References:
ISACA, CISA Review Manual, 27th Edition, 2019, p. 3261
PMI, Benefits Realization Management: A Practice Guide, 20192
APM, What is benefits management and project success?, 20213
CISA-CN Exam Question 172
資訊系統審計師受命審查組織的技術關係、介面和資料。下列哪一個企業架構(EA)領域最適合進行此審查? (請從《CISA認證-資訊系統審計師》官方教材中選出正確答案並加以解釋)
Correct Answer: C
The lack of system documentation should be of most concern to an IS auditor reviewing the information systems acquisition, development, and implementation process. This is because system documentation is a vital source of information that describes the system's purpose, functionality, design, architecture, testing, deployment, operation, and maintenance. System documentation helps the IS auditor to understand and evaluate the system's quality, performance, security, compliance, and alignment with the business requirements and objectives. Without system documentation, the IS auditor may not be able to perform a thorough and effective audit of the system, aswell as identify any issues or risks that may affect the system's reliability or integrity12.
Data owners are not trained on the use of data conversion tools is not the most concerning issue, although it may indicate a lack of user readiness or competence for the system implementation. Data conversion tools are software applications that help users to transform data from one format or structure to another, such as from legacy systems to new systems. Data owners are users who have the responsibility and authority to manage and control the data within their domain. Data owners should be trained on how to use data conversion tools to ensure that the data is accurately and securely transferred to the new system, as well as to avoid any data loss, corruption, or inconsistency. However, data owners are not the only users who need training for the system implementation, and data conversion tools are not the only tools that need training34.
A post-implementation lessons-learned exercise was not conducted is not the most concerning issue, although it may indicate a lack of continuous improvement or learning culture for the system development and implementation process. A post-implementation lessons-learned exercise is a meeting or a session that takes place after the completion of a system implementation project, where the project team and stakeholders discuss and document the successes and failures of the project, as well as identify any best practices or areas for improvement for future projects. Apost-implementation lessons-learned exercise can help to enhance the project management skills, knowledge, and performance of the project team and stakeholders, as well as to avoid repeating the same mistakes or problems in future projects56.
System deployment is routinely performed by contractors is not the most concerning issue, although it may pose some challenges or risks for the system implementation process. System deployment is the final stage of the system development life cycle (SDLC), where the system is installed and configured on the target environment and made available for use by end-users. System deployment can be performed by internal staff or external contractors, depending on the availability, expertise, and cost of resources. System deployment by contractors may offer some benefits such as faster delivery, lower cost, or higher quality than internal staff. However, system deployment by contractors mayalso introduce some risks such as loss of control, dependency, or security breaches over the system implementation process
Data owners are not trained on the use of data conversion tools is not the most concerning issue, although it may indicate a lack of user readiness or competence for the system implementation. Data conversion tools are software applications that help users to transform data from one format or structure to another, such as from legacy systems to new systems. Data owners are users who have the responsibility and authority to manage and control the data within their domain. Data owners should be trained on how to use data conversion tools to ensure that the data is accurately and securely transferred to the new system, as well as to avoid any data loss, corruption, or inconsistency. However, data owners are not the only users who need training for the system implementation, and data conversion tools are not the only tools that need training34.
A post-implementation lessons-learned exercise was not conducted is not the most concerning issue, although it may indicate a lack of continuous improvement or learning culture for the system development and implementation process. A post-implementation lessons-learned exercise is a meeting or a session that takes place after the completion of a system implementation project, where the project team and stakeholders discuss and document the successes and failures of the project, as well as identify any best practices or areas for improvement for future projects. Apost-implementation lessons-learned exercise can help to enhance the project management skills, knowledge, and performance of the project team and stakeholders, as well as to avoid repeating the same mistakes or problems in future projects56.
System deployment is routinely performed by contractors is not the most concerning issue, although it may pose some challenges or risks for the system implementation process. System deployment is the final stage of the system development life cycle (SDLC), where the system is installed and configured on the target environment and made available for use by end-users. System deployment can be performed by internal staff or external contractors, depending on the availability, expertise, and cost of resources. System deployment by contractors may offer some benefits such as faster delivery, lower cost, or higher quality than internal staff. However, system deployment by contractors mayalso introduce some risks such as loss of control, dependency, or security breaches over the system implementation process
CISA-CN Exam Question 173
如果執行相關任務的人員同時擁有審核權,那麼下列哪個職責領域會導致最大的職責分離衝突?
Correct Answer: D
The greatest segregation of duties conflict would occur if the individual who performs the related tasks also has approval authority for purchase requisitions and purchase orders. This is because these two tasks are directly related to each other and involve financial transactions. If the same person is responsible for both tasks, it could lead to potential fraud or error12. For instance, the individual could approve a purchase order for a personal need and then also approve the payment for it, leading to misuse of company funds12.
References:
Segregation of Duties: Examples of Roles, Duties and Violations - Pathlock Functions in the Purchasing Process and how to Segregate Purchasing Duties
References:
Segregation of Duties: Examples of Roles, Duties and Violations - Pathlock Functions in the Purchasing Process and how to Segregate Purchasing Duties
CISA-CN Exam Question 174
個人資料的保留期限和銷毀條件應由相關機構決定。
Correct Answer: D
The business owner is the person or entity that has the authority and responsibility for defining the purpose and scope of the processing of personal data, as well as the expected outcomes and benefits. The business owner is also accountable for ensuring that the processing of personal data complies with the applicable laws and regulations, such as the General Data Protection Regulation (GDPR) or the Data Protection Act 2018 (DPA 2018).
One of the requirements of the GDPR and the DPA 2018 is to adhere to the principle of storage limitation, which states that personal data should be kept for no longer than is necessary for the purposes for which it is processed1. This means that the business owner should determine and justify how long they need to retain personal data, based on factors such as:
The nature and sensitivity of the personal data
The legal or contractual obligations or rights that apply to the personal data The business or operational needs and expectations that depend on the personal data The risks and impacts that may arise from retaining or deleting the personal data The business owner should also establish and document the conditions and methods for the destruction of personal data, such as:
The criteria and triggers for deciding when to destroy personal data
The procedures and tools for securely erasing or anonymising personal data The roles and responsibilities for carrying out and overseeing the destruction of personal data The records and reports for verifying and evidencing the destruction of personal data Therefore, retention periods and conditions for the destruction of personal data should be determined by the business owner, as they are in charge of defining and managing the processing of personal data, as well as ensuring its compliance with the law.
One of the requirements of the GDPR and the DPA 2018 is to adhere to the principle of storage limitation, which states that personal data should be kept for no longer than is necessary for the purposes for which it is processed1. This means that the business owner should determine and justify how long they need to retain personal data, based on factors such as:
The nature and sensitivity of the personal data
The legal or contractual obligations or rights that apply to the personal data The business or operational needs and expectations that depend on the personal data The risks and impacts that may arise from retaining or deleting the personal data The business owner should also establish and document the conditions and methods for the destruction of personal data, such as:
The criteria and triggers for deciding when to destroy personal data
The procedures and tools for securely erasing or anonymising personal data The roles and responsibilities for carrying out and overseeing the destruction of personal data The records and reports for verifying and evidencing the destruction of personal data Therefore, retention periods and conditions for the destruction of personal data should be determined by the business owner, as they are in charge of defining and managing the processing of personal data, as well as ensuring its compliance with the law.
CISA-CN Exam Question 175
從風險管理的角度來看,在實施大型複雜資料中心 IT 基礎架構時,下列哪一種方法是最佳方法?
Correct Answer: D
From a risk management standpoint, the best approach for implementing a large and complex data center infrastructure is a deployment plan based on sequenced phases. ISACA guidance repeatedly supports phased implementation for complex, high-risk changes because it allows the organization to manage dependencies, reduce disruption, validate results incrementally, and maintain operational continuity while lessons from earlier phases can inform later ones.
Option D is correct because phased deployment reduces concentration of implementation risk. Instead of exposing the organization to a single large-scale failure point, phased rollout allows testing, adjustment, monitoring, and controlled transition. ISACA material discussing complex implementations emphasizes structured, phased approaches to handle technical debt, compatibility issues, and continuity concerns.
Option A is incorrect because a big bang deployment concentrates risk, even if a proof of concept was successful. A proof of concept demonstrates feasibility in limited conditions, but it does not eliminate the operational risks of a full-scale one-time cutover in a complex environment. For large infrastructure changes, CISA logic generally prefers phased approaches over big bang implementations.
Option B is useful, but simulation alone is not the best answer. Simulation can support planning and testing, yet it does not by itself provide the controlled risk reduction that phased deployment offers during actual implementation. In CISA questions, the best risk-management choice is usually the one that combines control and gradual exposure reduction, which is phased rollout.
Option C is incorrect because "prototyping and a one-phase deployment" still culminates in a single-phase rollout, which is riskier than sequenced deployment. A prototype can improve design understanding, but it does not replace the value of incremental implementation in a complex production environment.
Therefore, D is the best answer because a sequenced, phased deployment is the most effective risk- management approach for large and complex infrastructure implementations.
References (Official ISACA):
* ISACA, Passwordless Authentication: Risk, Reward, and Readiness - supports a carefully crafted phased implementation to manage complexity and maintain continuity.
* ISACA Journal, Working Toward a White Box Approach - highlights the risks created by complexity in large IT initiatives.
* ISACA Journal, Essential Frameworks and Methodologies to Maximize the Value of IT - supports structured project and program management sequencing.
* ISACA Journal, A Strategic Risk-Based Approach to Systems Security Engineering - supports using a risk-based approach for complex systems change.
Option D is correct because phased deployment reduces concentration of implementation risk. Instead of exposing the organization to a single large-scale failure point, phased rollout allows testing, adjustment, monitoring, and controlled transition. ISACA material discussing complex implementations emphasizes structured, phased approaches to handle technical debt, compatibility issues, and continuity concerns.
Option A is incorrect because a big bang deployment concentrates risk, even if a proof of concept was successful. A proof of concept demonstrates feasibility in limited conditions, but it does not eliminate the operational risks of a full-scale one-time cutover in a complex environment. For large infrastructure changes, CISA logic generally prefers phased approaches over big bang implementations.
Option B is useful, but simulation alone is not the best answer. Simulation can support planning and testing, yet it does not by itself provide the controlled risk reduction that phased deployment offers during actual implementation. In CISA questions, the best risk-management choice is usually the one that combines control and gradual exposure reduction, which is phased rollout.
Option C is incorrect because "prototyping and a one-phase deployment" still culminates in a single-phase rollout, which is riskier than sequenced deployment. A prototype can improve design understanding, but it does not replace the value of incremental implementation in a complex production environment.
Therefore, D is the best answer because a sequenced, phased deployment is the most effective risk- management approach for large and complex infrastructure implementations.
References (Official ISACA):
* ISACA, Passwordless Authentication: Risk, Reward, and Readiness - supports a carefully crafted phased implementation to manage complexity and maintain continuity.
* ISACA Journal, Working Toward a White Box Approach - highlights the risks created by complexity in large IT initiatives.
* ISACA Journal, Essential Frameworks and Methodologies to Maximize the Value of IT - supports structured project and program management sequencing.
* ISACA Journal, A Strategic Risk-Based Approach to Systems Security Engineering - supports using a risk-based approach for complex systems change.
- Other Version
- 346ISACA.CISA-CN.v2026-09-15.q708
- 1422ISACA.CISA-CN.v2026-05-16.q320
- 3111ISACA.CISA-CN.v2025-12-21.q601
- 3388ISACA.CISA-CN.v2025-12-17.q626
- Latest Upload
- 131Workday.Workday-Pro-Integrations.v2026-09-16.q48
- 133Cisco.350-801.v2026-09-16.q298
- 134SAP.C_ARCIG.v2026-09-16.q35
- 346ISACA.CISA-CN.v2026-09-15.q708
- 141EMC.NCA.v2026-09-15.q38
- 152Netskope.NSK300.v2026-09-14.q35
- 235CompTIA.CV0-004.v2026-09-14.q232
- 194Microsoft.AZ-801.v2026-09-14.q135
- 179NVIDIA.NCA-AIIO.v2026-09-12.q52
- 241CompTIA.220-1202.v2026-09-12.q122
[×]
Download PDF File
Enter your email address to download ISACA.CISA-CN.v2026-05-19.q615 Practice Test
