CISA-CN Exam Question 361
IT平衡計分卡是監控最有效的手段:
Correct Answer: A
An IT balanced scorecard is a strategic management tool that aligns IT objectives with business goals and measures the performance of IT processes using key performance indicators (KPIs). It is the most effective means of monitoring governance of enterprise IT, which is the process of ensuring that IT supports the organization's strategy and objectives. Governance of enterprise IT covers aspects such as IT value delivery, IT risk management, IT resource management, and IT performance measurement. An IT balanced scorecard can help monitor these aspects and provide feedback to improve IT governance. References: ISACA Frameworks: Blueprints for Success, CISA Review Manual (Digital Version)
CISA-CN Exam Question 362
在規劃滲透測試時,下列哪一項應先執行?
Correct Answer: D
The first step when planning a penetration test is to obtain management consent for the testing. This is because a penetration test involves simulating a cyberattack against theorganization's systems and networks, which may have legal, ethical, and operational implications. Without proper authorization from management, a penetration test may violate laws, policies, contracts, or service level agreements. Management consent also helps define the objectives, scope, and boundaries of the test, as well as the roles and responsibilities of the testers and the stakeholders. Obtaining management consent for the testing also demonstrates due care and due diligence on the part of the testers and the organization.
Executing nondisclosure agreements (NDAs), determining reporting requirements for vulnerabilities, and defining the testing scope are important steps when planning a penetration test, but they are not the first step.
These steps should be done after obtaining management consent for the testing, as they depend on the approval and involvement of management and other parties.
Executing nondisclosure agreements (NDAs), determining reporting requirements for vulnerabilities, and defining the testing scope are important steps when planning a penetration test, but they are not the first step.
These steps should be done after obtaining management consent for the testing, as they depend on the approval and involvement of management and other parties.
CISA-CN Exam Question 363
在評估包含多個巨集的電子表格的準確性時,資訊系統審計員最需要審查下列哪一項內容?
Correct Answer: C
The most important thing for an IS auditor to review when evaluating the accuracy of a spreadsheet that contains several macros is the formulas within macros. Macros are sequences of commands or instructions that can automate tasks or calculations in a spreadsheet. Formulas are expressions that perform calculations on values or data in a spreadsheet. The accuracy of a spreadsheet depends largely on whether the formulas within macros are correct, consistent, and complete. The IS auditor should review the formulas within macros to verify that they produce the expected results and do not contain any errors or inconsistencies. The other options are not as important as formulas within macros, as they do not directly affect the accuracy of a spreadsheet. Encryption of the spreadsheet is a security control that can protect the confidentiality and integrity of the spreadsheet, but it does not ensure its accuracy. Version history is a document control feature that can track and manage changes to the spreadsheet, but it does not verify its accuracy. Reconciliation of key calculations is a validation technique that can compare and confirm the results of calculations with other sources, but it does not evaluate the accuracy of formulas within macros. References: CISA Review Manual (Digital Version), Chapter 3, Section 3.2
CISA-CN Exam Question 364
下列哪一項是確保線上訂單完整性的最適當控制措施?
Correct Answer: B
A digital signature is the most appropriate control to ensure integrity of online orders because it provides a way to verify the authenticity and integrity of the data sent by the sender. A digital signature is created by applying a cryptographic algorithm to the data and attaching the result to the data. The receiver can then use the sender's public key to verify that the data has not been altered or tampered with during transmission. A digital signature also provides non-repudiation, which means that the sender cannot deny sending the data.
Data Encryption Standard (DES) is a symmetric encryption algorithm that can provide confidentiality of online orders, but not integrity. DES uses the same key to encrypt and decrypt the data, which means that anyone who has the key can modify the data without detection.
Public key encryption is an asymmetric encryption algorithm that can also provide confidentiality of online orders, but not integrity. Public key encryption uses a pair of keys: a public key and a private key. The sender encrypts the data with the receiver's public key, and the receiver decrypts it with their own private key.
However, public key encryption does not prevent anyone from modifying the encrypted data.
Multi-factor authentication is a control that can provide authentication and authorization of online orders, but not integrity. Multi-factor authentication requires the user to provide two or more pieces of evidence to prove their identity, such as a password, a token, or a biometric factor. Multi-factor authentication can prevent unauthorized access to online orders, but it does not protect the data from being modified after being sent.
References:
ISACA, CISA Review Manual, 27th Edition, 2019, p. 281 1
ISACA, CISA Review Questions, Answers and Explanations Database - 12 MonthSubscription 2
Data Encryption Standard (DES) is a symmetric encryption algorithm that can provide confidentiality of online orders, but not integrity. DES uses the same key to encrypt and decrypt the data, which means that anyone who has the key can modify the data without detection.
Public key encryption is an asymmetric encryption algorithm that can also provide confidentiality of online orders, but not integrity. Public key encryption uses a pair of keys: a public key and a private key. The sender encrypts the data with the receiver's public key, and the receiver decrypts it with their own private key.
However, public key encryption does not prevent anyone from modifying the encrypted data.
Multi-factor authentication is a control that can provide authentication and authorization of online orders, but not integrity. Multi-factor authentication requires the user to provide two or more pieces of evidence to prove their identity, such as a password, a token, or a biometric factor. Multi-factor authentication can prevent unauthorized access to online orders, but it does not protect the data from being modified after being sent.
References:
ISACA, CISA Review Manual, 27th Edition, 2019, p. 281 1
ISACA, CISA Review Questions, Answers and Explanations Database - 12 MonthSubscription 2
CISA-CN Exam Question 365
下列哪一項是管理階層在批准大量 IT 策略例外時最令人擔憂的問題?
Correct Answer: B
The greatest concern associated with a high number of IT policy exceptions approved by management is that the exceptions may result in noncompliance. IT policy exceptions are deviations from the established IT policies that are granted by management for specific reasons and circumstances. However, if there are too many exceptions, it may indicate that the IT policies are not aligned with the business needs, regulatory requirements, or best practices. This may expose the organization to legal, contractual, or reputational risks due to noncompliance. The other options are not as concerning as noncompliance, as they do not have the same potential impact or consequences. The exceptions are likely to continue indefinitely is a possible outcome of a high number of exceptions, but it does not necessarily imply a negative effect on the organization. The exceptions may elevate the level of operational risk is a valid concern, but it can be mitigated by implementing compensating controls or monitoring mechanisms. The exceptions may negatively impact process efficiency is a minor concern, as it does not affect the effectiveness or reliability of the IT processes. References: CISA Review Manual (Digital Version), Chapter 3, Section 3.2
- Other Version
- 523ISACA.CISA-CN.v2026-09-15.q708
- 1444ISACA.CISA-CN.v2026-05-16.q320
- 3236ISACA.CISA-CN.v2025-12-21.q601
- 3492ISACA.CISA-CN.v2025-12-17.q626
- Latest Upload
- 148Microsoft.MS-700.v2026-09-18.q195
- 119Symantec.250-587.v2026-09-18.q44
- 124Oracle.1Z0-1066-26.v2026-09-18.q67
- 142Google.Associate-Cloud-Engineer.v2026-09-18.q160
- 123Microsoft.AI-300.v2026-09-18.q53
- 130SAP.C_TS452.v2026-09-18.q86
- 129Salesforce.Slack-Con-201.v2026-09-17.q40
- 163AAPC.CPC.v2026-09-17.q182
- 140NetworkAppliance.NS0-094.v2026-09-17.q70
- 130PaloAltoNetworks.XSIAM-Engineer.v2026-09-17.q28
[×]
Download PDF File
Enter your email address to download ISACA.CISA-CN.v2026-05-19.q615 Practice Test
