CISA-CN Exam Question 531
某組織實施了一項新的資料分類方案,並要求資訊系統審計師評估其有效性。下列何者最能引起審計師的注意?
Correct Answer: C
CISA-CN Exam Question 532
資訊系統審計員正在審查負責智慧財產權和專利的業務部門的協作工具相關的安全控制措施。下列哪一項觀察結果最應引起審計員的注意?
Correct Answer: B
The observation that should be of most concern to the auditor when reviewing security controls related to collaboration tools for a business unit responsible for intellectual property and patents is that employees can share files with users outside the company through collaboration tools. Collaboration tools are software or hardware devices that enable users to communicate, cooperate, and coordinate with each other on a common task or project. Collaboration tools can facilitate information sharing and knowledge exchange among users, but they can also pose security risks if not properly controlled or managed. Employees can share files with users outside the company through collaboration tools, as this can compromise the security and confidentiality of intellectual property and patents, which are valuable and sensitive assets of the organization. Employees may share files with unauthorized or untrusted users who may misuse or disclose the intellectual property and patents, either intentionally or unintentionally. This can cause harm or damage to the organization, such as loss of competitive advantage, reputation, revenue, or legal rights. Training was not provided to the department that handles intellectual property and patents is a possible observation that could indicate a security issue related to collaboration tools for a business unit responsible for intellectual property and patents, but it is not the most concerning one. Training is anactivity that educates and instructs users on how to use collaboration tools effectively and securely, such as how to access, share, store, and protect information using collaboration tools. Training was not provided to the department that handles intellectual property and patents, as this can affect the awareness and competence of users on collaboration tools, and increase the likelihood of errors or mistakes that may compromise the security or quality of information. However, this observation may not be directly related to collaboration tools, as it may apply to any information system or resource used by the department. Logging and monitoring for content filtering is not enabled is a possible observation that could indicate a security issue related to collaboration tools for a business unit responsible for intellectual property and patents, but it is not the most concerning one. Logging and monitoring are processes that record and analyze the events or activities that occur on an information system or network, such as user actions, system operations, data changes, errors, alerts, etc. Content filtering is a technique that blocks or allows access to certain types of information based on predefined criteria or rules, such as keywords, categories, sources, etc. Logging and monitoring for content filtering is not enabled, as this can affect the auditability, accountability, and visibility of collaboration tools, and prevent detection or investigation of security incidents or violations related to information sharing using collaboration tools. However, this observation may not be specific to collaboration tools, as it may affect any information system or network that uses content filtering. The collaboration tool is hosted and can only be accessed via an Internet browser is a possible observation that could indicate a security issue related to collaboration tools for a business unit responsible for intellectual property and patents, but it is not the most concerning one. A hosted collaboration tool is a type of cloud-based service that provides collaboration functionality over the Internet without requiring installation or maintenance on local devices. An Internet browser is a software application that enables users to access and interact with web-based content or services. The collaboration tool is hosted and can only be accessed via an Internet browser, as this can affect the availability and reliability of collaboration tools, and introduce security or privacy risks for information sharing using collaboration tools. However, this observation may not be unique to collaboration tools, as it may apply to any cloud-based service that uses an Internet browser.
CISA-CN Exam Question 533
組織的營運團隊報告了 IS 安全攻擊 下列哪一項應該是安全事件回應團隊的第一步?
Correct Answer: C
The first step for the security incident response team after an IS security attack is reported is to perform a damage assessment. This involves identifying the scope, impact and root cause of the incident, as well as collecting and preserving evidence for further analysis and investigation. Reporting results to management, documenting lessons learned and prioritizing resources for corrective action are important steps, but they should be done after the damage assessment is completed. References: CISA Review Manual (DigitalVersion), Chapter 6, Section 6.31
CISA-CN Exam Question 534
在確定漏洞掃描過程是否完整時,下列哪一項驗證最為重要?
Correct Answer: A
The completeness of the vulnerability scanning process depends on the accuracy and currency of the organization's systems inventory, which is a list of all the hardware and software assets that are owned or used by the organization. A complete and up-to-date systems inventory can help ensure that all the systems are identified and scanned for vulnerabilities, and that no system is missed or overlooked. Vulnerability scanning results are reported to the CISO is a good practice for ensuring accountability and visibility of the vulnerability management process, but it is not the most important thing to verify when determining the completeness of the vulnerability scanning process, as reporting does not guarantee that all the systems are scanned. The organization is using a cloud-hosted scanning tool for identification of vulnerabilities is a possible option for conducting vulnerability scanning, but it is not the most important thing to verify when determining the completeness of the vulnerability scanning process, as the type of scanning tool does not affect the scope or coverage of the scanning. Access to the vulnerability scanning tool is periodically reviewed is a critical control for ensuring the security and integrity of the vulnerability scanning tool, but it is not the most important thing to verify when determining the completeness of the vulnerability scanning process, as access review does not ensure that all the systems are scanned.
CISA-CN Exam Question 535
以下哪个群体主要负责建立一种有利于有效和高效的内部控制系统的文化?
Correct Answer: B
The correct answer is B. Senior management.
Senior management is primarily accountable for establishing the organization's control culture, commonly described as setting the "tone at the top." Senior management is responsible for designing, implementing, communicating, and enforcing the internal control environment through policies, procedures, accountability, performance expectations, and ethical conduct.
Option A has ultimate oversight responsibility, but senior management is the group primarily accountable for establishing and operating the control culture. Option C is responsible for executing controls within business processes, but line management does not set the overall enterprise culture alone. Option D is incorrect because internal audit evaluates and provides assurance over controls; it does not own or establish the internal control system.
This maps to Governance and Management of IT because ISACA's CISA Exam Content Outline includes organizational structure, IT governance, IT policies, standards, procedures, practices, and enterprise risk management under Domain 2.
References: ISACA CISA Exam Content Outline, Domain 2; ISACA governance and internal control concepts.
Senior management is primarily accountable for establishing the organization's control culture, commonly described as setting the "tone at the top." Senior management is responsible for designing, implementing, communicating, and enforcing the internal control environment through policies, procedures, accountability, performance expectations, and ethical conduct.
Option A has ultimate oversight responsibility, but senior management is the group primarily accountable for establishing and operating the control culture. Option C is responsible for executing controls within business processes, but line management does not set the overall enterprise culture alone. Option D is incorrect because internal audit evaluates and provides assurance over controls; it does not own or establish the internal control system.
This maps to Governance and Management of IT because ISACA's CISA Exam Content Outline includes organizational structure, IT governance, IT policies, standards, procedures, practices, and enterprise risk management under Domain 2.
References: ISACA CISA Exam Content Outline, Domain 2; ISACA governance and internal control concepts.
- Other Version
- 3254ISACA.CISA-CN.v2026-05-19.q615
- 1418ISACA.CISA-CN.v2026-05-16.q320
- 3095ISACA.CISA-CN.v2025-12-21.q601
- 3366ISACA.CISA-CN.v2025-12-17.q626
- Latest Upload
- 131Workday.Workday-Pro-Integrations.v2026-09-16.q48
- 133Cisco.350-801.v2026-09-16.q298
- 134SAP.C_ARCIG.v2026-09-16.q35
- 328ISACA.CISA-CN.v2026-09-15.q708
- 140EMC.NCA.v2026-09-15.q38
- 149Netskope.NSK300.v2026-09-14.q35
- 234CompTIA.CV0-004.v2026-09-14.q232
- 194Microsoft.AZ-801.v2026-09-14.q135
- 176NVIDIA.NCA-AIIO.v2026-09-12.q52
- 237CompTIA.220-1202.v2026-09-12.q122
[×]
Download PDF File
Enter your email address to download ISACA.CISA-CN.v2026-09-15.q708 Practice Test
