CISA-CN Exam Question 211
衡量一個組織安全計畫有效性的最重要指標是:
Correct Answer: C
CISA-CN Exam Question 212
下列何者最有利於發生事故時啟動法律程序?
Correct Answer: C
The best way to facilitate the legal process in the event of an incident is to preserve the chain of custody of the evidence. The chain of custody is a record of who handled, accessed, or modified the evidence, when, where, how, and why. The chain of custody helps to ensure the integrity, authenticity, and admissibility of the evidence in a court of law. The chain of custody also helps to prevent tampering, alteration, or loss of evidence that could compromise the investigation or the prosecution. References:
CISAReview Manual (Digital Version)
CISA Questions, Answers and Explanations Database
CISAReview Manual (Digital Version)
CISA Questions, Answers and Explanations Database
CISA-CN Exam Question 213
下列哪一項是確定基於風險的審計計劃的關鍵領域的最佳方法?
Correct Answer: C
The best answer is C. Interview relevant stakeholders in the business.
ISACA guidance on risk-based audit planning emphasizes understanding the business context, identifying risk themes, and engaging stakeholders to determine what matters most. One ISACA example describes interviewing hundreds of leaders to identify risk themes for audit planning. Stakeholder interviews give the auditor a direct view of business objectives, current risks, process changes, emerging concerns, and management priorities across the enterprise.
Option A. Review peer benchmarking results can provide context, but benchmarking does not reveal the organization's own risk drivers.
Option B. Review open issues from recent audit reports is useful input, but it is backward-looking and incomplete by itself.
Option D. Conduct a risk survey with the CIO is too narrow because risk-based audit planning should reflect the broader business, not only the CIO's perspective.
Therefore, C is the correct answer because interviewing relevant business stakeholders is the best way to identify the key areas that should shape a risk-based audit plan.
References (Official ISACA):
* ISACA Journal, Transforming the IT Audit Function-Taking the Digital Journey.
* ISACA Journal, IS Audit Basics: Risk-based Audit Planning for Beginners.
* ISACA Journal, Business Skills for the IT Audit and Assurance Professional.
* ISACA, The Future of Cybersecurity Assessments Is Here - includes stakeholder interviews as part of risk assessment.
ISACA guidance on risk-based audit planning emphasizes understanding the business context, identifying risk themes, and engaging stakeholders to determine what matters most. One ISACA example describes interviewing hundreds of leaders to identify risk themes for audit planning. Stakeholder interviews give the auditor a direct view of business objectives, current risks, process changes, emerging concerns, and management priorities across the enterprise.
Option A. Review peer benchmarking results can provide context, but benchmarking does not reveal the organization's own risk drivers.
Option B. Review open issues from recent audit reports is useful input, but it is backward-looking and incomplete by itself.
Option D. Conduct a risk survey with the CIO is too narrow because risk-based audit planning should reflect the broader business, not only the CIO's perspective.
Therefore, C is the correct answer because interviewing relevant business stakeholders is the best way to identify the key areas that should shape a risk-based audit plan.
References (Official ISACA):
* ISACA Journal, Transforming the IT Audit Function-Taking the Digital Journey.
* ISACA Journal, IS Audit Basics: Risk-based Audit Planning for Beginners.
* ISACA Journal, Business Skills for the IT Audit and Assurance Professional.
* ISACA, The Future of Cybersecurity Assessments Is Here - includes stakeholder interviews as part of risk assessment.
CISA-CN Exam Question 214
下列哪一項最能描述數位簽章?
Correct Answer: D
A digital signature is a type of electronic signature that uses cryptographic techniques to provide authentication, integrity, and non-repudiation of digital documents. A digital signature is created by applying a mathematical function (called a hash function) to the document and then encrypting the result with the sender's private key. The encrypted hash, along with the sender's public key and other information, forms the digital signature. The receiver can verify the digital signature by decrypting it with the sender's public key and comparing the hash with the one computed from the document. If they match, it means that the document has not been altered and that it was signed by the owner of the private key.
Option D is correct because a digital signature is unique to the sender using it, as it depends on the sender's private key, which only the sender knows and controls. No one else can create a valid digital signature with the same private key, and no one can forge or modify a digital signature without being detected.
Option A is incorrect because a digital signature is not under control of the receiver, but rather under control of the sender. The receiver can only verify the digital signature, but cannot create or modify it.
Option B is incorrect because a digital signature is not capable of authorization, but rather capable of authentication. Authorization is the process of granting or denying access to resources based on predefined rules or policies. Authentication is the process of verifying the identity or legitimacy of a person or entity. A digital signature can authenticate the sender of a document, but it cannot authorize what actions the receiver can perform on the document.
Option C is incorrect because a digital signature does not dynamically validate modifications of data, but rather statically validates the integrity of data. A digital signature is based on a snapshot of the document at the time of signing, and any subsequent changes to the document will invalidate the digital signature. A digital signature does not monitor or update itself based on data modifications.
References:
CISA Online Review Course1, Module 5: Protection of Information Assets, Lesson 2: Encryption Basics, slide 13-14.
CISA Review Manual (Digital Version)2, Chapter 5: Protection of Information Assets, Section 5.2:
Encryption Basics, p. 273-274.
CISA Review Manual (Print Version), Chapter 5: Protection of Information Assets, Section 5.2: Encryption Basics, p. 273-274.
CISA Questions, Answers and Explanations Database3, Question ID: QAE_CISA_712.
What Is a Digital Signature (and How Does it Work)1
What are digital signatures and certificates?2
Digital Signature Definition3
Examples and uses of electronic signatures4
What is an Electronic Signature?5
Option D is correct because a digital signature is unique to the sender using it, as it depends on the sender's private key, which only the sender knows and controls. No one else can create a valid digital signature with the same private key, and no one can forge or modify a digital signature without being detected.
Option A is incorrect because a digital signature is not under control of the receiver, but rather under control of the sender. The receiver can only verify the digital signature, but cannot create or modify it.
Option B is incorrect because a digital signature is not capable of authorization, but rather capable of authentication. Authorization is the process of granting or denying access to resources based on predefined rules or policies. Authentication is the process of verifying the identity or legitimacy of a person or entity. A digital signature can authenticate the sender of a document, but it cannot authorize what actions the receiver can perform on the document.
Option C is incorrect because a digital signature does not dynamically validate modifications of data, but rather statically validates the integrity of data. A digital signature is based on a snapshot of the document at the time of signing, and any subsequent changes to the document will invalidate the digital signature. A digital signature does not monitor or update itself based on data modifications.
References:
CISA Online Review Course1, Module 5: Protection of Information Assets, Lesson 2: Encryption Basics, slide 13-14.
CISA Review Manual (Digital Version)2, Chapter 5: Protection of Information Assets, Section 5.2:
Encryption Basics, p. 273-274.
CISA Review Manual (Print Version), Chapter 5: Protection of Information Assets, Section 5.2: Encryption Basics, p. 273-274.
CISA Questions, Answers and Explanations Database3, Question ID: QAE_CISA_712.
What Is a Digital Signature (and How Does it Work)1
What are digital signatures and certificates?2
Digital Signature Definition3
Examples and uses of electronic signatures4
What is an Electronic Signature?5
CISA-CN Exam Question 215
在採用資料虛擬化的環境中,下列哪一項提供了最佳的災難復原解決方案?
Correct Answer: C
A virtual tape library (VTL) is a disk-based backup system that emulates a tape library. It provides faster backup and recovery than traditional tape systems, and it can be integrated with data deduplication and replication technologies to enhance disaster recovery. A VTL can also be replicated to an offsite location for additional protection. A VTL is the best disaster recovery solution for an environment where data virtualization is used, because it can handle large volumes of data, support multiple backup applications, and provide consistent performance.
Onsite disk-based backup systems (A) are not the best disaster recovery solution, because they are vulnerable to the same risks as the primary data center, such as fire, flood, power outage, or sabotage. Tape-based backup systems (B) are not the best disaster recovery solution, because they are slow, prone to errors, and require manual intervention. Redundant array of independent disks (RAID) (D) is not a backup system, but a storage technology that improves performance and fault tolerance by distributing data across multiple disks. RAID does not protect against data corruption, human error, or malicious attacks.
References:
Virtualization Disaster Recovery Overview: Definitions and Guides
Disaster Recovery Virtualization - VMware
What is Virtual Disaster Recovery? - Definition from Techopedia
How Does Virtualization Help With A Disaster Recovery Plan
Onsite disk-based backup systems (A) are not the best disaster recovery solution, because they are vulnerable to the same risks as the primary data center, such as fire, flood, power outage, or sabotage. Tape-based backup systems (B) are not the best disaster recovery solution, because they are slow, prone to errors, and require manual intervention. Redundant array of independent disks (RAID) (D) is not a backup system, but a storage technology that improves performance and fault tolerance by distributing data across multiple disks. RAID does not protect against data corruption, human error, or malicious attacks.
References:
Virtualization Disaster Recovery Overview: Definitions and Guides
Disaster Recovery Virtualization - VMware
What is Virtual Disaster Recovery? - Definition from Techopedia
How Does Virtualization Help With A Disaster Recovery Plan
- Other Version
- 523ISACA.CISA-CN.v2026-09-15.q708
- 1444ISACA.CISA-CN.v2026-05-16.q320
- 3236ISACA.CISA-CN.v2025-12-21.q601
- 3492ISACA.CISA-CN.v2025-12-17.q626
- Latest Upload
- 148Microsoft.MS-700.v2026-09-18.q195
- 119Symantec.250-587.v2026-09-18.q44
- 124Oracle.1Z0-1066-26.v2026-09-18.q67
- 142Google.Associate-Cloud-Engineer.v2026-09-18.q160
- 123Microsoft.AI-300.v2026-09-18.q53
- 130SAP.C_TS452.v2026-09-18.q86
- 129Salesforce.Slack-Con-201.v2026-09-17.q40
- 163AAPC.CPC.v2026-09-17.q182
- 140NetworkAppliance.NS0-094.v2026-09-17.q70
- 130PaloAltoNetworks.XSIAM-Engineer.v2026-09-17.q28
[×]
Download PDF File
Enter your email address to download ISACA.CISA-CN.v2026-05-19.q615 Practice Test
