CISA-CN Exam Question 396
資訊系統審計員發現,一個仍在正常使用的軟體系統已經過時多年且不再受支援。受審計方表示,需要六個月的時間才能將軟體升級到最新版本。下列哪一項是降低使用不受支援的軟體版本所帶來的直接風險的最佳方法?
Correct Answer: D
The best way to reduce the immediate risk associated with using an unsupported version of the software is to segregate the outdated software system from the main network. This will limit the exposure of the system to potential attacks and prevent it from compromising other systems on the network. Segregating the system will also reduce the impact of any security incidents that may occur on the system.
Monitoring network traffic attempting to reach the outdated software system (option C) is not the best way to reduce the risk, as it will not prevent or stop any attacks on the system. It will only provide visibility into the network activity and alert the auditee of any suspicious or malicious traffic.
Verifying all patches have been applied to the software system's outdated version (option A) and closing all unused ports on the outdated software system (option B) are also not the best ways to reduce the risk, as they will not address the underlying issue of using an unsupported version of the software. Patches and ports may still have vulnerabilities that are not fixed by the vendor, and attackers may exploit them to gain access to the system.
Therefore, option D is the correct answer.
References:
Introduction (Part 1 of 7: Mitigating Risks of Unsupported Operating Systems) Summary (Part 7of 7: Mitigating Risks of Unsupported Operating Systems) Upgrade, Retire, or Replace Unsupported Software (Part 4 of 7: Mitigating Risks of Unsupported Operating Systems)
Monitoring network traffic attempting to reach the outdated software system (option C) is not the best way to reduce the risk, as it will not prevent or stop any attacks on the system. It will only provide visibility into the network activity and alert the auditee of any suspicious or malicious traffic.
Verifying all patches have been applied to the software system's outdated version (option A) and closing all unused ports on the outdated software system (option B) are also not the best ways to reduce the risk, as they will not address the underlying issue of using an unsupported version of the software. Patches and ports may still have vulnerabilities that are not fixed by the vendor, and attackers may exploit them to gain access to the system.
Therefore, option D is the correct answer.
References:
Introduction (Part 1 of 7: Mitigating Risks of Unsupported Operating Systems) Summary (Part 7of 7: Mitigating Risks of Unsupported Operating Systems) Upgrade, Retire, or Replace Unsupported Software (Part 4 of 7: Mitigating Risks of Unsupported Operating Systems)
CISA-CN Exam Question 397
對 IS 審計師來說,在進行法務調查時,下列何者是確保資訊保存的最有效方法?
Correct Answer: B
The forensic principle is to preserve evidence in its original state. Imaging-including capturing residual and deleted data-ensures that the full contents of a storage device are preserved for analysis while maintaining the chain of custody. Hardening (A) may alter system state. Encoding logs (C) is not preservation but transformation. Documenting APIs (D) helps investigation scope but does not preserve evidence. ISACA guidance on digital forensics stresses the importance of bit-level imaging and ensuring evidence integrity through hashing and proper custody documentation.
References (ISACA): ISACA Incident Response and Forensics Guidance; ISACA Journal - Forensic Readiness.
References (ISACA): ISACA Incident Response and Forensics Guidance; ISACA Journal - Forensic Readiness.
CISA-CN Exam Question 398
下列哪一項審計證據蒐集程序最可靠?
Correct Answer: D
The most reliable evidence is evidence obtained directly by the auditor through independent performance of procedures. ISACA guidance notes that higher-assurance audit work is achieved when evidence is produced directly by auditors, or at least strictly under their control, rather than being supplied by the entity being audited.
Option D is correct because independently performing manual procedures gives the auditor direct control over the evidence-gathering process and reduces reliance on the auditee or control owner. In audit theory and in ISACA-aligned practice, evidence obtained directly by the auditor is generally more reliable than evidence merely provided by the auditee.
Option A is strong evidence because it comes from an independent third party, but it is still inspected rather than generated directly by the auditor. It is generally very reliable, but not as strong as auditor-generated evidence through independent reperformance.
Option B is less reliable because system-generated evidence provided by a control owner still depends on the completeness and integrity of what was selected and presented by the auditee.
Option C is the least reliable among the plausible choices because critical data received from an auditee is subject to the greatest dependence on management representation and auditee-controlled extraction.
Therefore, D is the best answer because evidence generated through procedures performed independently by the auditor is the most reliable.
References (Official ISACA):
* ISACA Journal, Capability Maturity Model and Risk Register Integration - "evidence is produced directly by the auditors or, if strictly under the auditors' control, by the entity's staff."
* ISACA Journal, A Factory Model Approach to Technology Control Testing - emphasizes gathering evidence, analyzing it, and substantiating results within a governed testing process.
* ISACA, ITAF update announcement - confirms ITAF as ISACA's professional framework for audit standards and guidance.
Option D is correct because independently performing manual procedures gives the auditor direct control over the evidence-gathering process and reduces reliance on the auditee or control owner. In audit theory and in ISACA-aligned practice, evidence obtained directly by the auditor is generally more reliable than evidence merely provided by the auditee.
Option A is strong evidence because it comes from an independent third party, but it is still inspected rather than generated directly by the auditor. It is generally very reliable, but not as strong as auditor-generated evidence through independent reperformance.
Option B is less reliable because system-generated evidence provided by a control owner still depends on the completeness and integrity of what was selected and presented by the auditee.
Option C is the least reliable among the plausible choices because critical data received from an auditee is subject to the greatest dependence on management representation and auditee-controlled extraction.
Therefore, D is the best answer because evidence generated through procedures performed independently by the auditor is the most reliable.
References (Official ISACA):
* ISACA Journal, Capability Maturity Model and Risk Register Integration - "evidence is produced directly by the auditors or, if strictly under the auditors' control, by the entity's staff."
* ISACA Journal, A Factory Model Approach to Technology Control Testing - emphasizes gathering evidence, analyzing it, and substantiating results within a governed testing process.
* ISACA, ITAF update announcement - confirms ITAF as ISACA's professional framework for audit standards and guidance.
CISA-CN Exam Question 399
資訊資產分類的主要好處在於:
Correct Answer: D
The primary benefit of information asset classification is that it enables risk management decisions.
Information asset classification helps to identify the value, sensitivity and criticality of information assets, and to determine the appropriate level of protection and controls required for them. This facilitates risk assessment and risk treatment processes, and ensures that information assets are aligned with business objectives and regulatory requirements. Preventing loss of assets, helping to align organizational objectives or facilitating budgeting accuracy are secondary benefits of information asset classification, but not the main purpose. References: ISACA, CISA Review Manual, 27th Edition, 2018, page 300
Information asset classification helps to identify the value, sensitivity and criticality of information assets, and to determine the appropriate level of protection and controls required for them. This facilitates risk assessment and risk treatment processes, and ensures that information assets are aligned with business objectives and regulatory requirements. Preventing loss of assets, helping to align organizational objectives or facilitating budgeting accuracy are secondary benefits of information asset classification, but not the main purpose. References: ISACA, CISA Review Manual, 27th Edition, 2018, page 300
CISA-CN Exam Question 400
對於涉及資料傳輸的作業排程過程,下列何者是最佳的偵測控制措施?
Correct Answer: D
The best detective control for a job scheduling process involving data transmission is job failure alerts that are automatically generated and routed to support personnel. Job failure alerts are notifications that indicate when a scheduled job or task fails to execute or complete successfully, such as due to errors, interruptions, or delays. Job failure alerts can help detect and correct any issues or anomalies in the job scheduling process involving data transmission by informing and alerting the support personnel who can investigate and resolve the problem. The other options are not as effective as job failure alerts in detecting issues or anomalies in the job scheduling process involving data transmission, as they do not provide timely or specific information or feedback. Metrics denoting the volume of monthly job failures are reported and reviewed by senior management is a reporting technique that can help measure and improve the performance and reliability of the job scheduling process, but it does not provide immediate or detailed information on individual job failures.
Jobs are scheduled to be completed daily and data is transmitted using a Secure File Transfer Protocol (SFTP) is a preventive control that can help ensure the timeliness and security of the job scheduling process involving data transmission, but it does not detect any issues or anomalies that may occur during the process. Jobs are scheduled and a log of this activity is retained for subsequent review is a logging technique that can help record and track the status and results of the job scheduling process involving data transmission, but it does not provide real-time or proactive information on job failures. References: CISA Review Manual (Digital Version), Chapter 3, Section 3.2
Jobs are scheduled to be completed daily and data is transmitted using a Secure File Transfer Protocol (SFTP) is a preventive control that can help ensure the timeliness and security of the job scheduling process involving data transmission, but it does not detect any issues or anomalies that may occur during the process. Jobs are scheduled and a log of this activity is retained for subsequent review is a logging technique that can help record and track the status and results of the job scheduling process involving data transmission, but it does not provide real-time or proactive information on job failures. References: CISA Review Manual (Digital Version), Chapter 3, Section 3.2
- Other Version
- 432ISACA.CISA-CN.v2026-09-15.q708
- 1439ISACA.CISA-CN.v2026-05-16.q320
- 3194ISACA.CISA-CN.v2025-12-21.q601
- 3462ISACA.CISA-CN.v2025-12-17.q626
- Latest Upload
- 119Salesforce.Slack-Con-201.v2026-09-17.q40
- 146AAPC.CPC.v2026-09-17.q182
- 126NetworkAppliance.NS0-094.v2026-09-17.q70
- 115PaloAltoNetworks.XSIAM-Engineer.v2026-09-17.q28
- 154Workday.Workday-Pro-Integrations.v2026-09-16.q48
- 151Cisco.350-801.v2026-09-16.q298
- 141SAP.C_ARCIG.v2026-09-16.q35
- 432ISACA.CISA-CN.v2026-09-15.q708
- 165EMC.NCA.v2026-09-15.q38
- 169Netskope.NSK300.v2026-09-14.q35
[×]
Download PDF File
Enter your email address to download ISACA.CISA-CN.v2026-05-19.q615 Practice Test
