CISA-CN Exam Question 316
下列哪一個群體主要負責建立有利於有效和有效率的內部控制系統的文化?
Correct Answer: B
The best answer is B. Senior management.
The culture that supports an effective internal control system is set from the top. ISACA's governance and culture guidance consistently treats culture as a management and leadership responsibility. Senior leadership establishes tone, values, expectations, accountability, and behavioral norms that shape how controls are designed, followed, and enforced across the enterprise. A strong control culture depends on visible commitment from leadership, not just procedural ownership by operational teams.
Option A. HR supports the culture through hiring, training, and policy reinforcement, but HR does not have primary accountability for the overall control environment.
Option C. Line management plays an important role in day-to-day control execution, but enterprise culture is primarily driven by senior leadership.
Option D. Internal audit evaluates and provides assurance over the control system; it does not own or establish the control culture because doing so would impair independence.
Therefore, B is the correct answer because senior management is primarily accountable for establishing the tone and culture that enable an effective and efficient internal control system.
References (Official ISACA):
* ISACA Journal, Auditing Your Organizational Culture.
* ISACA Now Blog, Culture as a Corporate Asset.
* ISACA Digital Video/Podcast, Understanding and Assessing Organization Culture.
* ISACA Journal, Auditing Culture.
The culture that supports an effective internal control system is set from the top. ISACA's governance and culture guidance consistently treats culture as a management and leadership responsibility. Senior leadership establishes tone, values, expectations, accountability, and behavioral norms that shape how controls are designed, followed, and enforced across the enterprise. A strong control culture depends on visible commitment from leadership, not just procedural ownership by operational teams.
Option A. HR supports the culture through hiring, training, and policy reinforcement, but HR does not have primary accountability for the overall control environment.
Option C. Line management plays an important role in day-to-day control execution, but enterprise culture is primarily driven by senior leadership.
Option D. Internal audit evaluates and provides assurance over the control system; it does not own or establish the control culture because doing so would impair independence.
Therefore, B is the correct answer because senior management is primarily accountable for establishing the tone and culture that enable an effective and efficient internal control system.
References (Official ISACA):
* ISACA Journal, Auditing Your Organizational Culture.
* ISACA Now Blog, Culture as a Corporate Asset.
* ISACA Digital Video/Podcast, Understanding and Assessing Organization Culture.
* ISACA Journal, Auditing Culture.
CISA-CN Exam Question 317
在對網路設備管理進行審計時,資訊系統審計員最需要驗證下列哪一項?
Correct Answer: C
The most important thing for an IS auditor to validate when auditing network device management is that all devices have current security patches assessed. This is because security patches are essential for fixing known vulnerabilities and preventing unauthorized access, data breaches, or denial-of-service attacks on the network devices. If the network devices are not patched regularly, they may expose the network to various cyber threats and compromise the confidentiality, integrity, and availability of the network services and data12.
Devices cannot be accessed through service accounts is not the most important thing to validate because service accounts are typically used for automated tasks or processes that require privileged access to network devices. Service accounts can be secured by using strong passwords, limiting their permissions, and monitoring their activities. However, service accounts alone do not protect the network devices from external or internal attacks that exploit unpatched vulnerabilities3.
Backup policies include device configuration files is not the most important thing to validate because backup policies are mainly used for restoring the network devices in case of failure, disaster, or corruption. Backup policies can help with recovering the network functionality and data, but they do not prevent the network devices from being compromised or attacked in the first place. Backup policies should be complemented by security policies that ensure the network devices are patched and protected4.
All devices are located within a protected network segment is not the most important thing to validate because network segmentation is a technique that divides the network into smaller subnets or zones based on different criteria, such as function, security level, or access control. Network segmentation can help isolate and contain the impact of a potential attack on a network device, but it does not prevent the attack from happening.
Network segmentation should be combined with security patching and other security measures to ensure the network devices are secure.
Devices cannot be accessed through service accounts is not the most important thing to validate because service accounts are typically used for automated tasks or processes that require privileged access to network devices. Service accounts can be secured by using strong passwords, limiting their permissions, and monitoring their activities. However, service accounts alone do not protect the network devices from external or internal attacks that exploit unpatched vulnerabilities3.
Backup policies include device configuration files is not the most important thing to validate because backup policies are mainly used for restoring the network devices in case of failure, disaster, or corruption. Backup policies can help with recovering the network functionality and data, but they do not prevent the network devices from being compromised or attacked in the first place. Backup policies should be complemented by security policies that ensure the network devices are patched and protected4.
All devices are located within a protected network segment is not the most important thing to validate because network segmentation is a technique that divides the network into smaller subnets or zones based on different criteria, such as function, security level, or access control. Network segmentation can help isolate and contain the impact of a potential attack on a network device, but it does not prevent the attack from happening.
Network segmentation should be combined with security patching and other security measures to ensure the network devices are secure.
CISA-CN Exam Question 318
資訊系統審計員發現,為了提高效能,Web應用程式的驗證控制已從伺服器端移至瀏覽器端。這極有可能增加遭受攻擊成功的風險。
Correct Answer: C
Moving validation controls from the server side into the browser would most likely increase the risk of a successful attack by structured query language (SQL) injection. SQL injection is a technique that exploits a security vulnerability in an application's database layer by inserting malicious SQL statements into user input fields. Validation controls are used to check and filter user input before sending it to the database. If these controls are moved to the browser, they can be easily bypassed or modified by an attacker, who can then execute arbitrary SQL commands on the database. References: CISA Review Manual, 27th Edition, page 361
CISA-CN Exam Question 319
為大型組織開發資料遺失防護 (DLP) 解決方案時,下列哪一項應該是第一步?
Correct Answer: A
The first step when developing a DLP solution for a large organization is to conduct a data inventory and classification exercise. This step involves identifying and locating all the data assets that the organization owns, generates, or handles, and assigning them to different categories based on their sensitivity, value, and regulatory requirements1. Data inventory and classification is essential for DLP because it helps to determine the scope and objectives of the DLP solution, as well as the appropriate level of protection and monitoring for each data category2. Data inventory and classification also enables the organization to prioritize its DLP efforts based on the risk and impact of data loss or leakage3.
Option B is not correct because identifying approved data workflows across the enterprise is a subsequent step after conducting data inventory and classification. Data workflows are the processes and channels through which data are created, stored, accessed, shared, or transmitted within or outside the organization4. Identifying approved data workflows helps to define the normal and legitimate use of data, as well as to detect and prevent unauthorized or anomalous data activities5. However, before identifying approved data workflows, the organization needs to know what data it has and how it should be classified.
Option C is not correct because conducting a threat analysis against sensitive data usage is another subsequent step after conducting data inventory and classification. Threat analysis is the process of identifying and assessing the potential sources, methods, and impacts of data loss or leakage incidents. Threat analysis helps to design and implement effective DLP controls and countermeasures based on the risk profile of each data category. However, before conducting threat analysis, the organization needs to know what data it has and how it should be classified.
Option D is not correct because creating the DLP policies and templates is the final step after conducting data inventory and classification, identifying approved data workflows, and conducting threat analysis. DLP policies and templates are the rules and configurations that specify how the DLP solution should monitor, detect, report, and respond to data loss or leakage events. DLP policies and templates should be aligned with the organization's business needs, regulatory obligations, and risk appetite. However, before creating the DLP policies and templates, the organization needs to know what data it has, how it should be classified, how it should be used, and what threats it faces.
References:
Data Inventory and Classification: The First Step in Data Protection1
Data Classification: What It Is And Why You Need It2
How to Prioritize Your Data Loss Prevention Strategy in 20203
What Is Data Workflow? Definition and Examples4
How to Identify Data Workflows for Your Business5
Threat Analysis: A Comprehensive Guide for Beginners
How to Conduct a Threat Assessment for Your Business
What Is Data Loss Prevention (DLP)? Definition and Examples
How to Create Effective Data Loss Prevention Policies
Option B is not correct because identifying approved data workflows across the enterprise is a subsequent step after conducting data inventory and classification. Data workflows are the processes and channels through which data are created, stored, accessed, shared, or transmitted within or outside the organization4. Identifying approved data workflows helps to define the normal and legitimate use of data, as well as to detect and prevent unauthorized or anomalous data activities5. However, before identifying approved data workflows, the organization needs to know what data it has and how it should be classified.
Option C is not correct because conducting a threat analysis against sensitive data usage is another subsequent step after conducting data inventory and classification. Threat analysis is the process of identifying and assessing the potential sources, methods, and impacts of data loss or leakage incidents. Threat analysis helps to design and implement effective DLP controls and countermeasures based on the risk profile of each data category. However, before conducting threat analysis, the organization needs to know what data it has and how it should be classified.
Option D is not correct because creating the DLP policies and templates is the final step after conducting data inventory and classification, identifying approved data workflows, and conducting threat analysis. DLP policies and templates are the rules and configurations that specify how the DLP solution should monitor, detect, report, and respond to data loss or leakage events. DLP policies and templates should be aligned with the organization's business needs, regulatory obligations, and risk appetite. However, before creating the DLP policies and templates, the organization needs to know what data it has, how it should be classified, how it should be used, and what threats it faces.
References:
Data Inventory and Classification: The First Step in Data Protection1
Data Classification: What It Is And Why You Need It2
How to Prioritize Your Data Loss Prevention Strategy in 20203
What Is Data Workflow? Definition and Examples4
How to Identify Data Workflows for Your Business5
Threat Analysis: A Comprehensive Guide for Beginners
How to Conduct a Threat Assessment for Your Business
What Is Data Loss Prevention (DLP)? Definition and Examples
How to Create Effective Data Loss Prevention Policies
CISA-CN Exam Question 320
對於評估組織設計的資訊系統審計師而言,下列何者最為重要?
的事件管理流程?
的事件管理流程?
Correct Answer: D
he design of an incident management process should include prioritization criteria to ensure that incidents are handled according to their impact and urgency. Without prioritization criteria, the organization may not be able to allocate resources effectively and respond to incidents in a timely manner. Expected time to resolve incidents, service management standards, and metrics reporting are important aspects of incident management, but they are not as critical as prioritization criteria for the design of the process. References: ISACA Journal Article: Incident Management: A Practical Approach
- Other Version
- 616ISACA.CISA-CN.v2026-09-15.q708
- 1457ISACA.CISA-CN.v2026-05-16.q320
- 3264ISACA.CISA-CN.v2025-12-21.q601
- 3516ISACA.CISA-CN.v2025-12-17.q626
- Latest Upload
- 127VMware.3V0-24.25.v2026-09-19.q35
- 227IIA.IIA-CIA-Part1-CN.v2026-09-19.q369
- 167Microsoft.MS-700.v2026-09-18.q195
- 133Symantec.250-587.v2026-09-18.q44
- 131Oracle.1Z0-1066-26.v2026-09-18.q67
- 150Google.Associate-Cloud-Engineer.v2026-09-18.q160
- 149Microsoft.AI-300.v2026-09-18.q53
- 141SAP.C_TS452.v2026-09-18.q86
- 156Salesforce.Slack-Con-201.v2026-09-17.q40
- 217AAPC.CPC.v2026-09-17.q182
[×]
Download PDF File
Enter your email address to download ISACA.CISA-CN.v2026-05-19.q615 Practice Test
