CISA-CN Exam Question 331
在檢視專案風險管理實務時,下列哪一項發現最令人擔憂?
Correct Answer: C
The best answer is C. Qualitative risk analyses have not been updated.
ISACA guidance describes the risk register as a living document that should be regularly reviewed and amended so management has an up-to-date picture of risk when making decisions. If qualitative risk analyses are not updated, the project may be working from outdated assumptions about probability, impact, and priority, which undermines the entire risk management process.
Option A is a concern, but issue tracking is not as central to project risk management as keeping risk analysis current. Option B is not inherently a weakness because effective risk management does not depend on a specific software tool. Option D is a governance concern, but stale risk analysis more directly damages the organization's ability to identify, assess, prioritize, and respond to project risk.
References (Official ISACA):
* ISACA Journal, Mitigating Technical Vulnerabilities With Risk Assessment - the risk register is a living document that should be regularly reviewed and amended.
* ISACA, Making Risk Management for Agile Projects Effective - risk registers are updated throughout the project lifecycle.
ISACA guidance describes the risk register as a living document that should be regularly reviewed and amended so management has an up-to-date picture of risk when making decisions. If qualitative risk analyses are not updated, the project may be working from outdated assumptions about probability, impact, and priority, which undermines the entire risk management process.
Option A is a concern, but issue tracking is not as central to project risk management as keeping risk analysis current. Option B is not inherently a weakness because effective risk management does not depend on a specific software tool. Option D is a governance concern, but stale risk analysis more directly damages the organization's ability to identify, assess, prioritize, and respond to project risk.
References (Official ISACA):
* ISACA Journal, Mitigating Technical Vulnerabilities With Risk Assessment - the risk register is a living document that should be regularly reviewed and amended.
* ISACA, Making Risk Management for Agile Projects Effective - risk registers are updated throughout the project lifecycle.
CISA-CN Exam Question 332
資訊系統審計師在審計過程中何時最需要應用重要性概念?
Correct Answer: A
The concept of materiality is most important for an IS auditor to apply when planning an audit engagement, because it helps the auditor to determine the scope, objectives, procedures and resources of the audit.
Materiality is the degree to which an omission or misstatement of information could affect the users' decisions or the achievement of the audit objectives. By applying the concept of materiality, the auditor can focus on the most significant and relevant areas of the audit and avoid wasting time and effort on trivial or immaterial matters. The other options are not as important as planning an audit engagement, because they are either based on or affected by the materiality assessment done during the planning phase. References:
ISACA, CISA Review Manual, 27th Edition, chapter 1, section 1.31
ISACA, IT Audit and Assurance Standards, Guidelines and Tools and Techniques forIS Audit and Assurance Professionals, section 12022
Materiality is the degree to which an omission or misstatement of information could affect the users' decisions or the achievement of the audit objectives. By applying the concept of materiality, the auditor can focus on the most significant and relevant areas of the audit and avoid wasting time and effort on trivial or immaterial matters. The other options are not as important as planning an audit engagement, because they are either based on or affected by the materiality assessment done during the planning phase. References:
ISACA, CISA Review Manual, 27th Edition, chapter 1, section 1.31
ISACA, IT Audit and Assurance Standards, Guidelines and Tools and Techniques forIS Audit and Assurance Professionals, section 12022
CISA-CN Exam Question 333
當被審計方在後續審計時仍無法完成所有審計建議時,資訊系統審計師的最佳做法是什麼?
Correct Answer: D
The best course of action for an IS auditor when an auditee is unable to close all audit recommendations by the time of the follow-up audit is to evaluate the residual risk due to open issues. Residual risk is the risk that remains after the implementation of controls or mitigating actions. Evaluating the residual risk due to open issues can help the IS auditor assess the impact and likelihood of the potential threats and vulnerabilities that have not been addressed by the auditee, as well as the adequacy and effectiveness of the existing controls or mitigating actions. Evaluating the residual risk due to open issues can also help the IS auditor prioritize and communicate the open issues to the auditee and other stakeholders, such as senior management or audit committee, and recommend appropriate actions or escalation procedures.
Ensuring the open issues are retained in the audit results is a course of action for an IS auditor when an auditee is unable to close all audit recommendations by the time of the follow-up audit, but it is not the best one. Ensuring the open issues are retained in the audit results can help the IS auditor document and report the status and progress of the audit recommendations, as well as provide a basis for future follow-up audits.
However, ensuring the open issues are retained in the audit results does not provide an analysis or evaluation of the residual risk due to open issues, which is more important for informing decision-making and action- taking.
Terminating the follow-up because open issues are not resolved is not a course of action for an IS auditor when an auditee is unable to close all audit recommendations by the time of the follow-up audit, but rather a consequence or outcome of it. Terminating the follow-up because open issues are not resolved may indicate that the auditee has failed to comply with the agreed-upon actions or deadlines, or that the IS auditor has encountered significant obstacles or resistance from the auditee. Terminating the follow-up because open issues are not resolved may also trigger further actions or sanctions from the IS auditor or other authorities, such as issuing a qualified or adverse opinion, withholding certification, or imposing penalties.
Recommending compensating controls for open issues is not a course of action for an IS auditor when an auditee is unable to close all audit recommendations by the time of the follow-up audit, but rather a possible outcome or result of it. Compensating controls are alternative or additional controls that are implemented to reduce or eliminate the risk associated with a weakness or deficiency in another control. Recommending compensating controls for open issues may be appropriate when the auditee is unable to implement the original audit recommendations due to technical, operational,financial, or other constraints, and when the compensating controls can provide a similar or equivalent level of assurance. However, recommending compensating controls for open issues requires a prior evaluation of the residual risk due to open issues, which is more important for determining whether compensating controls are necessary and feasible.
References:
Follow-up Audits - Canadian Audit and Accountability Foundation 1
Conducting The Audit Follow-Up: When To Verify - TheAuditor 2
Internal Audit Follow Ups: Are They Really Worth The Effort
Ensuring the open issues are retained in the audit results is a course of action for an IS auditor when an auditee is unable to close all audit recommendations by the time of the follow-up audit, but it is not the best one. Ensuring the open issues are retained in the audit results can help the IS auditor document and report the status and progress of the audit recommendations, as well as provide a basis for future follow-up audits.
However, ensuring the open issues are retained in the audit results does not provide an analysis or evaluation of the residual risk due to open issues, which is more important for informing decision-making and action- taking.
Terminating the follow-up because open issues are not resolved is not a course of action for an IS auditor when an auditee is unable to close all audit recommendations by the time of the follow-up audit, but rather a consequence or outcome of it. Terminating the follow-up because open issues are not resolved may indicate that the auditee has failed to comply with the agreed-upon actions or deadlines, or that the IS auditor has encountered significant obstacles or resistance from the auditee. Terminating the follow-up because open issues are not resolved may also trigger further actions or sanctions from the IS auditor or other authorities, such as issuing a qualified or adverse opinion, withholding certification, or imposing penalties.
Recommending compensating controls for open issues is not a course of action for an IS auditor when an auditee is unable to close all audit recommendations by the time of the follow-up audit, but rather a possible outcome or result of it. Compensating controls are alternative or additional controls that are implemented to reduce or eliminate the risk associated with a weakness or deficiency in another control. Recommending compensating controls for open issues may be appropriate when the auditee is unable to implement the original audit recommendations due to technical, operational,financial, or other constraints, and when the compensating controls can provide a similar or equivalent level of assurance. However, recommending compensating controls for open issues requires a prior evaluation of the residual risk due to open issues, which is more important for determining whether compensating controls are necessary and feasible.
References:
Follow-up Audits - Canadian Audit and Accountability Foundation 1
Conducting The Audit Follow-Up: When To Verify - TheAuditor 2
Internal Audit Follow Ups: Are They Really Worth The Effort
CISA-CN Exam Question 334
當員工使用公共社群網站時,下列哪一項對組織構成最大的風險?
Correct Answer: C
Social engineering is the manipulation of people to perform actions or divulge confidential information. It is a common technique used by attackers to gain unauthorized access to systems or data. Employees who use public social networking sites may be vulnerable to social engineering attacks, such as phishing, baiting, or pretexting, which pose the greatest risk to the organization's security. The other options are not as serious as social engineering, as they relate to web application vulnerabilities, intellectual property rights, and reputation management, which are less likely to compromise the organization's assets or operations. References: CISA Review Manual (Digital Version), Domain 5: Protection of Information Assets, Section 5.3 Security Awareness Training1
CISA-CN Exam Question 335
資訊系統審計員發現日誌管理系統充斥著大量誤報。審計員的最佳建議是:
Correct Answer: D
Fine tuning the intrusion detection system (IDS) is the best recommendation to reduce the number of false positive alerts that overwhelm the log management system, because it can help adjust the sensitivity and accuracy of the IDS rules and signatures to match the network environment and traffic patterns. Establishing criteria for reviewing alerts, recruiting more monitoring personnel, and reducing thefirewall rules are not effective solutions to address theroot cause of the false positive alerts, but rather ways to cope with the consequences. References: CISA Review Manual (Digital Version), Chapter 5, Section5.4.3
- Other Version
- 616ISACA.CISA-CN.v2026-09-15.q708
- 1457ISACA.CISA-CN.v2026-05-16.q320
- 3264ISACA.CISA-CN.v2025-12-21.q601
- 3516ISACA.CISA-CN.v2025-12-17.q626
- Latest Upload
- 127VMware.3V0-24.25.v2026-09-19.q35
- 227IIA.IIA-CIA-Part1-CN.v2026-09-19.q369
- 167Microsoft.MS-700.v2026-09-18.q195
- 133Symantec.250-587.v2026-09-18.q44
- 131Oracle.1Z0-1066-26.v2026-09-18.q67
- 150Google.Associate-Cloud-Engineer.v2026-09-18.q160
- 149Microsoft.AI-300.v2026-09-18.q53
- 141SAP.C_TS452.v2026-09-18.q86
- 156Salesforce.Slack-Con-201.v2026-09-17.q40
- 217AAPC.CPC.v2026-09-17.q182
[×]
Download PDF File
Enter your email address to download ISACA.CISA-CN.v2026-05-19.q615 Practice Test
