CISA-CN Exam Question 326
在審查組織的架構(EA)時,資訊系統稽核員最有可能在EA文件中發現下列哪一項內容?
Correct Answer: C
Enterprise Architecture (EA) documentation primarily includes strategic and operational blueprints outlining the evolution of IT infrastructure to align with business goals. Roadmaps showing the evolution from current state to future state (C) are essential for understanding how the organization's IT environment will change over time to support business strategy.
Other options:
Contact information for key resources (A) is more of an operational or administrative document rather than an EA component.
Detailed encryption standards (B) would typically be found in security policies or system-specific documentation rather than in EA documentation.
Protocols used to communicate between systems (D) are typically documented within network or system architecture diagrams rather than high-level EA documentation.
Reference: ISACA CISA Review Manual, IT Governance and Management of IT
Other options:
Contact information for key resources (A) is more of an operational or administrative document rather than an EA component.
Detailed encryption standards (B) would typically be found in security policies or system-specific documentation rather than in EA documentation.
Protocols used to communicate between systems (D) are typically documented within network or system architecture diagrams rather than high-level EA documentation.
Reference: ISACA CISA Review Manual, IT Governance and Management of IT
CISA-CN Exam Question 327
資訊系統審計員應確保應用程式的審計追蹤:
Correct Answer: A
An application's audit trail is a record of all actions or events that occur within or affect an application, such as user activities, system operations, data changes, errors, exceptions, etc. An audit trail can provide evidence and accountability for an application's functionality and performance, and support auditing, monitoring, troubleshooting, and investigation purposes. An IS auditor should ensure that an application's audit trail has adequate security, which means that it is protected from unauthorized access, modification, deletion, or disclosure. Adequate security can help ensure that an audit trail maintains its integrity, reliability, and availability, and prevents tampering or manipulation by attackers or insiders who want to hide their tracks or evidence of their actions. Logs all database records is a possible feature of an application's audit trail, but it is not the most important thing for an IS auditor to ensure, as logging all database records may not be necessary or feasible for some applications, and may generate excessive or irrelevant data that can affect the storage or analysis of the audit trail. Is accessible online is a possible feature of an application's audit trail, but it is not the most important thing for an IS auditor to ensure, as online accessibility may not be required or desirable for some applications, and may introduce security or privacy risks for the audit trail. Does not impact operational efficiency is a desirable outcome of an application's audit trail, but it is not the most important thing for an IS auditor to ensure, as operational efficiency may not be the primary objective or concern of an application's audit trail, and may depend on other factors or trade-offs such as storage capacity, performance speed, or data quality.
CISA-CN Exam Question 328
資訊系統審計員發現,為多個業務部門服務的IT組織對所有項目賦予相同的優先級,這可能導致專案資金的獲取出現延誤。下列哪一項最有助於以支援業務目標的方式,將專案和服務需求與可用資源相匹配?
Correct Answer: D
The most helpful tool in matching demand for projects and services with available resources in a way that supports business objectives is portfolio management. Portfolio management is the process of selecting, prioritizing, balancing and aligning IT projects and services with the strategic goals and value proposition of the organization3. Portfolio management helps the IT organization to allocate resources efficiently and effectively, to deliver value to the business units, and to align IT initiatives with business strategies. Project management, risk assessment results and IT governance framework are also important tools, but they are not as helpful as portfolio management in matching demand and supply of IT projects and services. References:
CISA Review Manual, 27th Edition, page 721
CISA Review Questions, Answers and Explanations Database - 12 Month Subscription
CISA Review Manual, 27th Edition, page 721
CISA Review Questions, Answers and Explanations Database - 12 Month Subscription
CISA-CN Exam Question 329
某內部稽核部門最近建立了一個品質保證(QA)專案。下列哪一項活動對於QA專案的要求最為重要?
Correct Answer: B
Ongoing monitoring of the audit activities is the most important activity to include as part of the quality assurance (QA) program requirements for an internal audit department. An IS auditor should perform regular reviews and evaluations of the audit processes, methods, standards, and outcomes to ensure that they comply with the QA program objectives and criteria. This will help to maintain and improve the quality and consistency of the audit services and deliverables. The other options are less important activities to include as part of the QA program requirements, as they may involve long-term resource planning, user satisfaction reports, or feedback from internal audit staff. References:
CISA Review Manual (Digital Version), Chapter 2, Section2.61
CISA Review Questions, Answers and Explanations Database, Question ID 224
CISA Review Manual (Digital Version), Chapter 2, Section2.61
CISA Review Questions, Answers and Explanations Database, Question ID 224
CISA-CN Exam Question 330
某組織最近在其內部會計軟體系統中採用敏捷模型部署自訂程式碼。在檢視生產程式碼部署流程時,下列哪一項是需要解決的最重要的安全問題?
Correct Answer: B
Change control is the process of managing and documenting changes to an information system or its components. Change control aims to ensure that changes are authorized, tested, approved, implemented, and reviewed in a controlled and consistent manner. Change control is an essential part of ensuring the security, reliability, and quality of an information system.
One of the key elements of change control is testing and approval from quality assurance (QA). QA is the function that verifies that the changes meet the requirements and specifications, comply with the standards and policies, and do not introduce any errors or vulnerabilities. QA testing and approval provide assurance that the changes are fit for purpose, function as expected, and do not compromise the security or performance of the system.
An organization that has recently moved to an agile model for deploying custom code to its in-house accounting software system should still follow change control procedures, including QA testing and approval.
Agile development methods emphasize flexibility, speed, and collaboration, but they do not eliminate the need for quality and security checks. In fact, agile methods can facilitate change control by enabling frequent and iterative testing and feedback throughout the development cycle.
However, if change control does not include testing and approval from QA, this poses a significant security concern for the organization. Without QA testing and approval, the changes may not be properly validated, verified, or evaluated before being deployed to production. This could result in introducing bugs, defects, or vulnerabilities that could affect the functionality, availability, integrity, or confidentiality of the accounting software system. For example, a change could cause data corruption, performance degradation, unauthorized access, or data leakage. These risks could have serious consequences for the organization's financial operations, compliance obligations, reputation, or legal liabilities.
Therefore, change control that does not include testing and approval from QA is the most significant security concern to address when reviewing the procedures in place for production code deployment in an agile model.
References:
Change Control - ISACA
Quality Assurance - ISACA
Agile Development - ISACA
10 Agile Software Development Security Concerns You Need to Know
One of the key elements of change control is testing and approval from quality assurance (QA). QA is the function that verifies that the changes meet the requirements and specifications, comply with the standards and policies, and do not introduce any errors or vulnerabilities. QA testing and approval provide assurance that the changes are fit for purpose, function as expected, and do not compromise the security or performance of the system.
An organization that has recently moved to an agile model for deploying custom code to its in-house accounting software system should still follow change control procedures, including QA testing and approval.
Agile development methods emphasize flexibility, speed, and collaboration, but they do not eliminate the need for quality and security checks. In fact, agile methods can facilitate change control by enabling frequent and iterative testing and feedback throughout the development cycle.
However, if change control does not include testing and approval from QA, this poses a significant security concern for the organization. Without QA testing and approval, the changes may not be properly validated, verified, or evaluated before being deployed to production. This could result in introducing bugs, defects, or vulnerabilities that could affect the functionality, availability, integrity, or confidentiality of the accounting software system. For example, a change could cause data corruption, performance degradation, unauthorized access, or data leakage. These risks could have serious consequences for the organization's financial operations, compliance obligations, reputation, or legal liabilities.
Therefore, change control that does not include testing and approval from QA is the most significant security concern to address when reviewing the procedures in place for production code deployment in an agile model.
References:
Change Control - ISACA
Quality Assurance - ISACA
Agile Development - ISACA
10 Agile Software Development Security Concerns You Need to Know
- Other Version
- 616ISACA.CISA-CN.v2026-09-15.q708
- 1457ISACA.CISA-CN.v2026-05-16.q320
- 3264ISACA.CISA-CN.v2025-12-21.q601
- 3516ISACA.CISA-CN.v2025-12-17.q626
- Latest Upload
- 127VMware.3V0-24.25.v2026-09-19.q35
- 227IIA.IIA-CIA-Part1-CN.v2026-09-19.q369
- 167Microsoft.MS-700.v2026-09-18.q195
- 133Symantec.250-587.v2026-09-18.q44
- 131Oracle.1Z0-1066-26.v2026-09-18.q67
- 150Google.Associate-Cloud-Engineer.v2026-09-18.q160
- 149Microsoft.AI-300.v2026-09-18.q53
- 141SAP.C_TS452.v2026-09-18.q86
- 156Salesforce.Slack-Con-201.v2026-09-17.q40
- 217AAPC.CPC.v2026-09-17.q182
[×]
Download PDF File
Enter your email address to download ISACA.CISA-CN.v2026-05-19.q615 Practice Test
