CISA-CN Exam Question 381
資訊系統品質保證(OA)小組負責:
Correct Answer: A
The IS quality assurance (QA) group is responsible for ensuring that program changes adhere to established standards. Program changes are modifications made to software applications or systems to fix errors, improve performance, add functionality, or meet changing requirements. Program changes should follow established standards for documentation, authorization, testing, implementation, and review. The IS QA group is responsible for verifying that program changes comply with these standards and meet the expected quality criteria. Designing procedures to protect dataagainst accidental disclosure; ensuring that the output received from system processing is complete; and monitoring the execution of computer processing tasks are not responsibilities of the IS QA group. References: [ISACA CISA Review Manual 27th Edition], page 304.
CISA-CN Exam Question 382
下列哪一項最適合防止未經授權的人取得儲存在業務應用系統中的機密資訊?
Correct Answer: C
The most appropriate control to prevent unauthorized retrieval of confidential information stored in a business application system is to enforce an internal data access policy. A data access policy defines who can access what data, under what conditions and for what purposes. It also specifies the roles and responsibilities of data owners, custodians and users, as well as the security measures and controls to protect data confidentiality, integrity and availability. By enforcing a data access policy, the organization can ensure that only authorized personnel can retrieve confidential informationfrom the business application system. Applying single sign-on for access control, implementing segregation of duties and enforcing the use of digital signatures are also useful controls, but they are not sufficient to prevent unauthorized data retrieval without a clear and comprehensive data access policy. References:
CISA Review Manual, 27th Edition, page 2301
CISA Review Questions, Answers and Explanations Database - 12 Month Subscription2
CISA Review Manual, 27th Edition, page 2301
CISA Review Questions, Answers and Explanations Database - 12 Month Subscription2
CISA-CN Exam Question 383
一項網路安全審查發現,使用者在網路服務供應商 (ISP) 處擁有個人使用者帳戶,並使用這些帳戶下載業務資料。該組織希望確保僅使用公司網路。組織首先應該:
Correct Answer: D
The first step that the organization should take to ensure that only the corporate network is used for downloading business data is to include a statement in its security policy about Internet use. A security policy is a document that defines the rules, expectations, and overall approach that an organization uses to maintain the confidentiality, integrity, and availability of its data1. A security policy should clearly state the acceptable and unacceptable use of Internet resources, such as personalaccounts with ISPs, and the consequences of violating the policy. A security policy also helps to guide the implementation of technical controls, such as proxy servers, firewalls, or monitoring tools, that can enforce the policy and prevent or detect unauthorized Internet access.
The other options are not the first step that the organization should take, but rather subsequent or complementary steps that depend on the security policy. Using a proxy server to filter out Internet sites that should not be accessed is a technical control that can help implement the security policy, but it does not address the root cause of why users are using personal accounts with ISPs. Keeping a manual log of Internet access is a monitoring technique that can help audit the compliance with the security policy, but it does not prevent or deter users from using personal accounts with ISPs. Monitoring remote access activities is another monitoring technique that can help detect unauthorized Internet access, but it does not specify what constitutes unauthorized access or how to respond to it.
References:
ISACA CISA Review Manual 27th Edition (2019), page 247
What is a Security Policy? Definition, Elements, and Examples - Varonis1
The other options are not the first step that the organization should take, but rather subsequent or complementary steps that depend on the security policy. Using a proxy server to filter out Internet sites that should not be accessed is a technical control that can help implement the security policy, but it does not address the root cause of why users are using personal accounts with ISPs. Keeping a manual log of Internet access is a monitoring technique that can help audit the compliance with the security policy, but it does not prevent or deter users from using personal accounts with ISPs. Monitoring remote access activities is another monitoring technique that can help detect unauthorized Internet access, but it does not specify what constitutes unauthorized access or how to respond to it.
References:
ISACA CISA Review Manual 27th Edition (2019), page 247
What is a Security Policy? Definition, Elements, and Examples - Varonis1
CISA-CN Exam Question 384
下列哪一項措施能為管理階層提供最合理的保證,確保新的資料倉儲能滿足組織的需求?
Correct Answer: A
A data warehouse is a centralized repository of data that is collected from various sources and organized for analysis and reporting purposes. A data warehouse can help an organization gain insights into its business performance, trends, and opportunities. However, building a data warehouse requires careful planning, design, and implementation to ensure that it meets the needs of the organization.
One of the best practices that would provide management with the most reasonable assurance that a new data warehouse will meet the needs of the organization is A. Integrating data requirements into the system development life cycle (SDLC). The SDLC is a framework that defines the phases and activities involved in developing a software system, such as planning, analysis, design, testing, deployment, and maintenance1. By integrating data requirements into the SDLC, an organization can ensure that the data warehouse is aligned with the business objectives and expectations, and that it delivers value to the end users.
Some of the benefits of integrating data requirements into the SDLC are:
It helps to identify and prioritize the key business questions and metrics that the data warehouse should support2.
It helps to define and validate the data sources, models, structures, and quality standards that the data warehouse should follow3.
It helps to design and implement the data integration, transformation, and loading processes that the data warehouse should use4.
It helps to test and verify the functionality, performance, and accuracy of the data warehouse before deploying it to production.
It helps to monitor and maintain the data warehouse after deployment and incorporate feedback and changes as needed.
One of the best practices that would provide management with the most reasonable assurance that a new data warehouse will meet the needs of the organization is A. Integrating data requirements into the system development life cycle (SDLC). The SDLC is a framework that defines the phases and activities involved in developing a software system, such as planning, analysis, design, testing, deployment, and maintenance1. By integrating data requirements into the SDLC, an organization can ensure that the data warehouse is aligned with the business objectives and expectations, and that it delivers value to the end users.
Some of the benefits of integrating data requirements into the SDLC are:
It helps to identify and prioritize the key business questions and metrics that the data warehouse should support2.
It helps to define and validate the data sources, models, structures, and quality standards that the data warehouse should follow3.
It helps to design and implement the data integration, transformation, and loading processes that the data warehouse should use4.
It helps to test and verify the functionality, performance, and accuracy of the data warehouse before deploying it to production.
It helps to monitor and maintain the data warehouse after deployment and incorporate feedback and changes as needed.
CISA-CN Exam Question 385
在執行後續活動時,資訊系統審計師發現管理階層實施的糾正措施與最初與審計部門討論並達成一致的措施有所不同。為了解決這種情況,資訊系統審計師的最佳做法是:
Correct Answer: D
The IS auditor's best course of action in this situation is to determine whether the alternative controls sufficiently mitigate the risk. Alternative controls are different from those originally discussed and agreed with the audit function, but they may still achieve the same objective of addressing the audit issue or reducing the risk to an acceptable level. The IS auditor should evaluate whether the alternative controls are appropriate, effective, and sustainable before closing the audit finding or escalating it to senior management. The other options are not appropriate for resolving this situation, as they do not consider whether the alternative controls are adequate or reasonable. Re-prioritizing the original issue as high risk and escalating to senior management is a drastic step that may undermine the relationship between the auditor and management, and it should be done only after exhausting other means of resolving the issue. Scheduling a follow-up audit in the next audit cycle is unnecessary, as follow-up activities should be performed as soon as possible after management has implemented corrective actions. Postponing follow-up activities and escalating the alternative controls to senior audit management is premature, as follow-up activities should be completed before reporting any findings or recommendations to senior audit management. References: CISA Review Manual (Digital Version), Chapter 2, Section 2.4
- Other Version
- 549ISACA.CISA-CN.v2026-09-15.q708
- 1445ISACA.CISA-CN.v2026-05-16.q320
- 3256ISACA.CISA-CN.v2025-12-21.q601
- 3505ISACA.CISA-CN.v2025-12-17.q626
- Latest Upload
- 149Microsoft.MS-700.v2026-09-18.q195
- 121Symantec.250-587.v2026-09-18.q44
- 125Oracle.1Z0-1066-26.v2026-09-18.q67
- 143Google.Associate-Cloud-Engineer.v2026-09-18.q160
- 125Microsoft.AI-300.v2026-09-18.q53
- 131SAP.C_TS452.v2026-09-18.q86
- 134Salesforce.Slack-Con-201.v2026-09-17.q40
- 168AAPC.CPC.v2026-09-17.q182
- 142NetworkAppliance.NS0-094.v2026-09-17.q70
- 133PaloAltoNetworks.XSIAM-Engineer.v2026-09-17.q28
[×]
Download PDF File
Enter your email address to download ISACA.CISA-CN.v2026-05-19.q615 Practice Test
