CISA-CN Exam Question 181
在部署前評估中,什麼是判斷一項商業案例能否達成業務目標的最佳指標?
Correct Answer: A
During a pre-deployment assessment, the best indication that a business case will lead to the achievement of business objectives is that the business case reflects stakeholder requirements. A business case is a document that explains the rationale, benefits, costs, and risks of a proposed project or initiative. A business case should align with the strategic goals and vision of the organization and address the needs and expectations of the stakeholders who are involved in or affected by the project12.
Stakeholder requirements are the conditions or capabilities that stakeholders expect from a project or its outcomes. Stakeholders can include customers, users, employees, managers, suppliers, regulators, and others who have an interest or stake in the project. Stakeholder requirements should be identified, analyzed, prioritized, validated, and documented throughout the project lifecycle34.
The business case should reflect stakeholder requirements because they provide the basis for defining the project scope, objectives, deliverables, quality standards, success criteria, and benefits realization. By reflecting stakeholder requirements, the business case can demonstrate how the project will add value to the organization and its stakeholders, justify the investment and resources required for the project, and facilitate the decision-making and approval process for the project5 .
Therefore, during a pre-deployment assessment, an IS auditor should look for evidence that the business case reflects stakeholder requirements as the best indication that the business case will lead to the achievement of business objectives.
References:
How to Write a Business Case (Template Included) - ProjectManager
How to Write a Business Case | Smartsheet
What are Stakeholder Requirements? | PM Study Circle
Stakeholder Requirements - Project Management Knowledge
Business Case vs Business Requirements - Difference Between
[Business Case Development - Project Management Docs]
Stakeholder requirements are the conditions or capabilities that stakeholders expect from a project or its outcomes. Stakeholders can include customers, users, employees, managers, suppliers, regulators, and others who have an interest or stake in the project. Stakeholder requirements should be identified, analyzed, prioritized, validated, and documented throughout the project lifecycle34.
The business case should reflect stakeholder requirements because they provide the basis for defining the project scope, objectives, deliverables, quality standards, success criteria, and benefits realization. By reflecting stakeholder requirements, the business case can demonstrate how the project will add value to the organization and its stakeholders, justify the investment and resources required for the project, and facilitate the decision-making and approval process for the project5 .
Therefore, during a pre-deployment assessment, an IS auditor should look for evidence that the business case reflects stakeholder requirements as the best indication that the business case will lead to the achievement of business objectives.
References:
How to Write a Business Case (Template Included) - ProjectManager
How to Write a Business Case | Smartsheet
What are Stakeholder Requirements? | PM Study Circle
Stakeholder Requirements - Project Management Knowledge
Business Case vs Business Requirements - Difference Between
[Business Case Development - Project Management Docs]
CISA-CN Exam Question 182
漏洞掃描相對於滲透測試的最大優勢是什麼?
Correct Answer: D
The greatest advantage of vulnerability scanning over penetration testing is that the testing process can be automated to cover large groups of assets. Vulnerability scanning is an automated, high-level security test that reports its findings of known vulnerabilities in systems, networks, applications, and devices. Vulnerability scanning can be performed frequently, quickly, and efficiently to scan a large number of assets and identify potential weaknesses that need to be addressed. Vulnerability scanning can also help organizations comply with security standards and regulations, such as PCI DSS1.
The other options are not as advantageous as option D, as they may not reflect the true benefits or limitations of vulnerability scanning compared to penetration testing. The testing produces a lower number of false positive results, but this is not necessarily true, as vulnerability scanning may report vulnerabilities that are not exploitable or relevant in the context of the organization. Network bandwidth is utilized more efficiently, but this may not be a significant advantage, as vulnerability scanning may still consume considerable network resources depending on the scope and frequency of the scans. Custom-developed applications can be tested more accurately, but this is also not true, as vulnerability scanning may not be able to detect complex or unknown vulnerabilities that require manual analysis or exploitation.
References:
1: Vulnerability scanning vs penetration testing: What's the difference? | TechRepublic
2: Vulnerability Scanning vs. Penetration Testing - Fortinet
3: Penetration Test Vs Vulnerability Scan | Digital Defense
4: Penetration Testing vs. Vulnerability Scanning: What's the difference?
5: Penetration Testing vs. Vulnerability Scanning | Secureworks
6: PCI DSS Quick Reference Guide - PCI Security Standards Council
The other options are not as advantageous as option D, as they may not reflect the true benefits or limitations of vulnerability scanning compared to penetration testing. The testing produces a lower number of false positive results, but this is not necessarily true, as vulnerability scanning may report vulnerabilities that are not exploitable or relevant in the context of the organization. Network bandwidth is utilized more efficiently, but this may not be a significant advantage, as vulnerability scanning may still consume considerable network resources depending on the scope and frequency of the scans. Custom-developed applications can be tested more accurately, but this is also not true, as vulnerability scanning may not be able to detect complex or unknown vulnerabilities that require manual analysis or exploitation.
References:
1: Vulnerability scanning vs penetration testing: What's the difference? | TechRepublic
2: Vulnerability Scanning vs. Penetration Testing - Fortinet
3: Penetration Test Vs Vulnerability Scan | Digital Defense
4: Penetration Testing vs. Vulnerability Scanning: What's the difference?
5: Penetration Testing vs. Vulnerability Scanning | Secureworks
6: PCI DSS Quick Reference Guide - PCI Security Standards Council
CISA-CN Exam Question 183
一位負責制定年度內部審計計劃的資訊系統審計師得知,首席資訊長 (CIO) 要求來年暫停所有資訊系統審計,因為需要更多時間來處理上一年遺留的大量建議。審計師首先該做什麼?
Correct Answer: A
The auditor should first escalate to audit management to discuss the audit plan. This is because the audit plan should be based on a risk assessment and aligned with the organization's objectives and strategies. The auditor should not accept the CIO's request without proper justification and approval from the audit management, who are responsible for ensuring the audit plan's quality and independence. The auditor should also communicate the potential risks and implications of not conducting IS audits in the upcoming year, such as missing new or emerging threats, vulnerabilities, or compliance issues. References:
CISA Review Manual (Digital Version), Chapter 2, Section 2.11
CISA Online Review Course, Domain 1, Module 1, Lesson 22
CISA Review Manual (Digital Version), Chapter 2, Section 2.11
CISA Online Review Course, Domain 1, Module 1, Lesson 22
CISA-CN Exam Question 184
審計工作結束後,但在出具最終報告前,審計師應:
Correct Answer: B
Before issuing the final audit report, the auditor should confirm factual findings with the auditee. ISACA audit guidance emphasizes that findings should be vetted, communicated, and reviewed with client management prior to final publication so that the report is factually accurate and misunderstandings are resolved.
Option B is correct because confirming factual findings with the auditee is a key step just before final issuance. ISACA guidance notes that findings may be discussed with auditees as they are gathered and should be verified with them where possible. ISACA also stresses that draft reports should be reviewed by client management before publication to ensure factual accuracy.
Option A is incorrect because the audit committee is generally a report recipient or governance body, not the party with whom the auditor first validates factual accuracy of detailed findings. The auditee is in the best position to confirm whether the facts, context, and operational details are accurate before the report becomes final.
Option C is an important audit responsibility, but it should already have been completed during fieldwork and evidence-gathering. By the conclusion of the audit, the auditor should already possess sufficient, appropriate evidence to support findings. The question asks what should be done at the conclusion of the audit, but before issuing the final report, which points to factual confirmation with the auditee.
Option D is not the best answer because management is responsible for developing action plans. While auditors may discuss recommendations, they should not take ownership of management's corrective action plan in a way that compromises independence. The more immediate and proper pre-issuance step is confirming the factual accuracy of findings.
Thus, in classic CISA logic, the auditor should first ensure that the report is factually correct by validating findings with the auditee before the final report is issued. That makes B the correct answer.
References (Official ISACA):
* ISACA, The Top-Five Audit Essentials for Driving Efficiency and Value - findings should be vetted and communicated with the client; draft report reviewed by client management prior to final publication.
* ISACA Journal, Agile Audit - findings may be shared and verified with auditees before the final report.
* ISACA Journal, Future Ready: Toward a Sound Agile Audit Framework - auditee feedback at the final reporting stage is important.
* ISACA Journal case study - draft report sent to auditee and comments/amendments accepted before issuing report.
Option B is correct because confirming factual findings with the auditee is a key step just before final issuance. ISACA guidance notes that findings may be discussed with auditees as they are gathered and should be verified with them where possible. ISACA also stresses that draft reports should be reviewed by client management before publication to ensure factual accuracy.
Option A is incorrect because the audit committee is generally a report recipient or governance body, not the party with whom the auditor first validates factual accuracy of detailed findings. The auditee is in the best position to confirm whether the facts, context, and operational details are accurate before the report becomes final.
Option C is an important audit responsibility, but it should already have been completed during fieldwork and evidence-gathering. By the conclusion of the audit, the auditor should already possess sufficient, appropriate evidence to support findings. The question asks what should be done at the conclusion of the audit, but before issuing the final report, which points to factual confirmation with the auditee.
Option D is not the best answer because management is responsible for developing action plans. While auditors may discuss recommendations, they should not take ownership of management's corrective action plan in a way that compromises independence. The more immediate and proper pre-issuance step is confirming the factual accuracy of findings.
Thus, in classic CISA logic, the auditor should first ensure that the report is factually correct by validating findings with the auditee before the final report is issued. That makes B the correct answer.
References (Official ISACA):
* ISACA, The Top-Five Audit Essentials for Driving Efficiency and Value - findings should be vetted and communicated with the client; draft report reviewed by client management prior to final publication.
* ISACA Journal, Agile Audit - findings may be shared and verified with auditees before the final report.
* ISACA Journal, Future Ready: Toward a Sound Agile Audit Framework - auditee feedback at the final reporting stage is important.
* ISACA Journal case study - draft report sent to auditee and comments/amendments accepted before issuing report.
CISA-CN Exam Question 185
某組織已實施分散式安全管理系統以取代先前的集中式系統。下列哪一項存在最大的潛在問題?
Correct Answer: A
A distributed security administration system is a system that allows different administrators to manage the security of different parts of the network or organization. This can provide more flexibility, scalability, and efficiency than a centralized system, where one administrator is responsible for the entire security. However, a distributed security administration system also presents some potential challenges and risks, such as:
Inconsistency and conflict among different security policies and standards Lack of coordination and communication among different administrators Difficulty in monitoring and auditing the overall security status and performance Increased complexity and cost of security management and maintenance Therefore, the greatest potential concern for implementing a distributed security administration system is that the security procedures may be inadequate to support the change. Security procedures are the rules and guidelines that define how security is implemented and enforced in an organization. They include policies, standards, processes, roles, responsibilities, controls, and metrics. Security procedures should be aligned with the business objectives, risks, and requirements of the organization, as well as the best practices and regulations in the industry. Security procedures should also be reviewed and updated regularly to reflect the changes in the environment, technology, and threats.
If the security procedures are not adequate to support the change from a centralized to a distributed security administration system, the organization may face increased security risks, such as unauthorized access, data breaches, compliance violations, reputation damage, and financial losses. Therefore, it is essential to ensure that the security procedures are revised and adapted to suit the new system, and that they are communicated and enforced effectively across the organization.
References:
1: Security in Distributed System - GeeksforGeeks
2: Distributed System Security Architecture - Wikipedia
3: Distributed Systems Security: Issues, Processes and Solutions
Inconsistency and conflict among different security policies and standards Lack of coordination and communication among different administrators Difficulty in monitoring and auditing the overall security status and performance Increased complexity and cost of security management and maintenance Therefore, the greatest potential concern for implementing a distributed security administration system is that the security procedures may be inadequate to support the change. Security procedures are the rules and guidelines that define how security is implemented and enforced in an organization. They include policies, standards, processes, roles, responsibilities, controls, and metrics. Security procedures should be aligned with the business objectives, risks, and requirements of the organization, as well as the best practices and regulations in the industry. Security procedures should also be reviewed and updated regularly to reflect the changes in the environment, technology, and threats.
If the security procedures are not adequate to support the change from a centralized to a distributed security administration system, the organization may face increased security risks, such as unauthorized access, data breaches, compliance violations, reputation damage, and financial losses. Therefore, it is essential to ensure that the security procedures are revised and adapted to suit the new system, and that they are communicated and enforced effectively across the organization.
References:
1: Security in Distributed System - GeeksforGeeks
2: Distributed System Security Architecture - Wikipedia
3: Distributed Systems Security: Issues, Processes and Solutions
- Other Version
- 346ISACA.CISA-CN.v2026-09-15.q708
- 1422ISACA.CISA-CN.v2026-05-16.q320
- 3111ISACA.CISA-CN.v2025-12-21.q601
- 3388ISACA.CISA-CN.v2025-12-17.q626
- Latest Upload
- 131Workday.Workday-Pro-Integrations.v2026-09-16.q48
- 133Cisco.350-801.v2026-09-16.q298
- 134SAP.C_ARCIG.v2026-09-16.q35
- 346ISACA.CISA-CN.v2026-09-15.q708
- 141EMC.NCA.v2026-09-15.q38
- 152Netskope.NSK300.v2026-09-14.q35
- 235CompTIA.CV0-004.v2026-09-14.q232
- 194Microsoft.AZ-801.v2026-09-14.q135
- 179NVIDIA.NCA-AIIO.v2026-09-12.q52
- 241CompTIA.220-1202.v2026-09-12.q122
[×]
Download PDF File
Enter your email address to download ISACA.CISA-CN.v2026-05-19.q615 Practice Test
