CISA-CN Exam Question 21
為了降低透過應用程式介面(API)查詢外洩資料的風險,下列哪項設計考量最為重要?
Correct Answer: B
The answer B is correct because data minimization is the most important design consideration to mitigate the risk of exposing data through application programming interface (API) queries. An API is a set of rules and protocols that allows different software components or systems to communicate and exchange data. API queries are requests sent by users or applications to an API to retrieve or manipulate data. For example, a user may query an API to get information about a product, a service, or a location.
Data minimization is the principle of collecting, processing, and storing only the minimum amount of data that are necessary for a specific purpose. Data minimization can help to reduce the risk of exposing data through API queries by limiting the amount and type of data that are available or accessible through the API.
Data minimization can also help to protect the privacy and security of the data subjects and the data providers, as well as to comply with the relevant laws and regulations.
Some of the benefits of data minimization for API design are:
Privacy: Data minimization can enhance the privacy of the data subjects by ensuring that only the data that are relevant and essential for the API purpose are collected and processed. This can prevent unnecessary or excessive collection or disclosure of personal or sensitive data, such as names, addresses, phone numbers, email addresses, etc. Data minimization can also help to comply with the privacy laws and regulations that require data protection by design and by default, such as GDPR (General Data Protection Regulation) or CCPA (California Consumer Privacy Act).
Security: Data minimization can improve the security of the data providers by reducing the attack surface and the potential damage of a data breach. If less data are stored or transmitted through the API, there are fewer opportunities for attackers to access or compromise the data. Data minimization can also help to implement security controls such as encryption, access control, or logging more efficiently and effectively.
Performance: Data minimization can increase the performance of the API by optimizing the use of resources and bandwidth. If less data are stored or transmitted through the API, there are less storage space and network traffic required. Data minimization can also help to improve the speed and reliability of the API responses.
Some of the techniques for data minimization in API design are:
Define clear and specific purposes for the API and document them in the API specification or documentation.
Identify and classify the data that are needed for each purpose and assign them appropriate labels or levels, such as public, internal, confidential, or restricted.
Implement filters or parameters in the API queries that allow users or applications to specify or limit the data fields or attributes they want to retrieve or manipulate.
Use pagination or throttling in the API responses that limit the number or size of data items returned per request.
Use anonymization or pseudonymization techniques that remove or replace any identifying information from the data before sending them through the API.
Some examples of web resources that discuss data minimization in API design are:
Data Minimization in Web APIs - World Wide Web Consortium (W3C)
Adding Privacy by Design in Secure Application Development
Chung-ju/Data-Minimization: A repository of related papers. - GitHub
Data minimization is the principle of collecting, processing, and storing only the minimum amount of data that are necessary for a specific purpose. Data minimization can help to reduce the risk of exposing data through API queries by limiting the amount and type of data that are available or accessible through the API.
Data minimization can also help to protect the privacy and security of the data subjects and the data providers, as well as to comply with the relevant laws and regulations.
Some of the benefits of data minimization for API design are:
Privacy: Data minimization can enhance the privacy of the data subjects by ensuring that only the data that are relevant and essential for the API purpose are collected and processed. This can prevent unnecessary or excessive collection or disclosure of personal or sensitive data, such as names, addresses, phone numbers, email addresses, etc. Data minimization can also help to comply with the privacy laws and regulations that require data protection by design and by default, such as GDPR (General Data Protection Regulation) or CCPA (California Consumer Privacy Act).
Security: Data minimization can improve the security of the data providers by reducing the attack surface and the potential damage of a data breach. If less data are stored or transmitted through the API, there are fewer opportunities for attackers to access or compromise the data. Data minimization can also help to implement security controls such as encryption, access control, or logging more efficiently and effectively.
Performance: Data minimization can increase the performance of the API by optimizing the use of resources and bandwidth. If less data are stored or transmitted through the API, there are less storage space and network traffic required. Data minimization can also help to improve the speed and reliability of the API responses.
Some of the techniques for data minimization in API design are:
Define clear and specific purposes for the API and document them in the API specification or documentation.
Identify and classify the data that are needed for each purpose and assign them appropriate labels or levels, such as public, internal, confidential, or restricted.
Implement filters or parameters in the API queries that allow users or applications to specify or limit the data fields or attributes they want to retrieve or manipulate.
Use pagination or throttling in the API responses that limit the number or size of data items returned per request.
Use anonymization or pseudonymization techniques that remove or replace any identifying information from the data before sending them through the API.
Some examples of web resources that discuss data minimization in API design are:
Data Minimization in Web APIs - World Wide Web Consortium (W3C)
Adding Privacy by Design in Secure Application Development
Chung-ju/Data-Minimization: A repository of related papers. - GitHub
CISA-CN Exam Question 22
在評估事件回應計畫的有效性時,資訊系統稽核員注意到,大量報告的事件都涉及員工發現的可移動儲存媒體中的惡意軟體。下列哪一項是向管理階層提出的最恰當的建議?
Correct Answer: D
CISA-CN Exam Question 23
下列哪一項是最大限度降低抽樣風險的最佳方法?
Correct Answer: B
Sampling risk is the risk that the auditor's conclusion based on a sample may be different from the conclusion that would be reached if the entire population was tested using the same audit procedure. Sampling risk can lead to either incorrect rejection or incorrect acceptance of the audit objective. The best way to minimize sampling risk is to perform statistical sampling. Statistical sampling is a method of selecting and evaluating a sample using probability theory and mathematical calculations. Statistical sampling allows auditors to measure and control the sampling risk by determining the appropriate sample size and selection method, and evaluating the results using confidence levels and precision intervals. Statistical sampling can also provide more objective and consistent results than judgmental sampling, which relies on the auditor's professional judgment and experience.
References:
6: Sampling Risks: Definition, Example, and Explanation - Wikiaccounting
7: Sampling Risk in Audit | Sampling vs non sampling risk - Accountinguide
9: Audit sampling | ACCA Qualification | Students | ACCA Global
References:
6: Sampling Risks: Definition, Example, and Explanation - Wikiaccounting
7: Sampling Risk in Audit | Sampling vs non sampling risk - Accountinguide
9: Audit sampling | ACCA Qualification | Students | ACCA Global
CISA-CN Exam Question 24
下列哪一種方法能提供最可靠的審計證據?
Correct Answer: C
The best answer is C. Re-performance of controls.
Under ISACA audit principles, evidence obtained directly by the auditor is generally more reliable than evidence provided by management or gathered indirectly. Re-performance allows the auditor to independently execute the control or procedure and verify whether it works as intended, making it stronger than inquiry, observation, or management attestation.
Option A is the least reliable because inquiry depends on what people say. Option B is stronger than simple inquiry but still relies on management representation. Option D can be useful, but observation only shows what happened at a point in time and may not prove consistent operation. Re-performance gives the auditor the highest level of assurance because the evidence is generated through the auditor's own independent work.
References (Official ISACA):
* ISACA, Follow-Up Audits and Follow-Up Process: The Auditor's Impact Litmus Tool
* ISACA, The Top-Five Audit Essentials for Driving Efficiency and Value
Under ISACA audit principles, evidence obtained directly by the auditor is generally more reliable than evidence provided by management or gathered indirectly. Re-performance allows the auditor to independently execute the control or procedure and verify whether it works as intended, making it stronger than inquiry, observation, or management attestation.
Option A is the least reliable because inquiry depends on what people say. Option B is stronger than simple inquiry but still relies on management representation. Option D can be useful, but observation only shows what happened at a point in time and may not prove consistent operation. Re-performance gives the auditor the highest level of assurance because the evidence is generated through the auditor's own independent work.
References (Official ISACA):
* ISACA, Follow-Up Audits and Follow-Up Process: The Auditor's Impact Litmus Tool
* ISACA, The Top-Five Audit Essentials for Driving Efficiency and Value
CISA-CN Exam Question 25
就IT治理而言,價值交付的首要目標是:
Correct Answer: C
The primary objective of value delivery in reference to IT governance is to optimize investments. Value delivery is one of the five focus areas of IT governance that aims to ensure that IT delivers expected benefits to stakeholders and enables business value creation. Value delivery involves aligning IT investments with business objectives and strategies, managing IT performance and benefits realization, optimizing IT costs and risks, and enhancing IT innovation and agility. Value delivery helps to maximize the return on investment (ROI) and value for money (VFM) of IT resources and capabilities. References:
CISA Review Manual (Digital Version)
CISA Questions, Answers and Explanations Database
CISA Review Manual (Digital Version)
CISA Questions, Answers and Explanations Database
- Other Version
- 259ISACA.CISA-CN.v2026-09-15.q708
- 1363ISACA.CISA-CN.v2026-05-16.q320
- 2977ISACA.CISA-CN.v2025-12-21.q601
- 3307ISACA.CISA-CN.v2025-12-17.q626
- Latest Upload
- 259ISACA.CISA-CN.v2026-09-15.q708
- 127EMC.NCA.v2026-09-15.q38
- 122Netskope.NSK300.v2026-09-14.q35
- 202CompTIA.CV0-004.v2026-09-14.q232
- 160Microsoft.AZ-801.v2026-09-14.q135
- 153NVIDIA.NCA-AIIO.v2026-09-12.q52
- 196CompTIA.220-1202.v2026-09-12.q122
- 176SAP.C_CT325_2601.v2026-09-11.q26
- 384ECCouncil.312-50v13.v2026-09-11.q327
- 275Microsoft.AZ-801.v2026-09-11.q140
[×]
Download PDF File
Enter your email address to download ISACA.CISA-CN.v2026-05-19.q615 Practice Test
