CISA-CN Exam Question 661
在組織制定資訊安全政策和程序時,下列哪個因素最為重要?
Correct Answer: D
Information security policies and procedures are the foundation of an organization's information security program. They define the roles, responsibilities, rules, and standards for protecting information assets from unauthorized access, use, disclosure, modification, or destruction. The most important factor when developing information security policies and procedures is to align them with an information security framework that provides a comprehensive and consistent approach to managing information security risks. An information security framework can also help ensure compliance with relevant regulations, inclusion of mission and objectives, and consultation with security staff. However, these factors are secondary to alignment with an information security framework. References: CISA Certification | Certified Information Systems Auditor | ISACA, CISA Review Manual (Digital Version)
CISA-CN Exam Question 662
下列哪一項措施可以最大限度地降低因災難導致交易遺失的風險?
Correct Answer: A
Sending a copy of the transaction logs to offsite storage on a daily basis would minimize the risk of losing transactions as a result of a disaster. This is because offsite storage provides a backup of the data that can be recovered in case of a catastrophic event that destroys or damages the onsite data. Storing a copy of the transaction logs onsite in a fireproof vault (B) would not protect the data from other types of disasters, such as floods, earthquakes, or theft. Encrypting or signing (D) a copy of the transaction logs and storing them on a local server would not prevent the loss of data if the server is affected by the disaster. Encryption and digital signatures are security measures that protect the confidentiality and integrity of the data, but not the availability.
Reference: CISA - Certified Information Systems Auditor Study Guide1, Chapter 5: Protection of Information Assets, Section 5.2: Backup and Recovery Concepts, Page 353.
Reference: CISA - Certified Information Systems Auditor Study Guide1, Chapter 5: Protection of Information Assets, Section 5.2: Backup and Recovery Concepts, Page 353.
CISA-CN Exam Question 663
對於正在對小型內部 IT 團隊開發的新複雜系統進行變更和發布管理控制審計的資訊系統審計師而言,以下哪項觀察結果最值得關注?
Correct Answer: D
Post-implementation testing is the process of verifying and validating the functionality, performance, and security of a system after it has been deployed to the production environment1. Post-implementation testing is important for ensuring that the system meets the user requirements and expectations, as well as the operational and business objectives. Post-implementation testing also helps to identify and resolve any defects, errors, or issues that may have occurred during the deployment process or that may have been missed during the previous testing stages2.
Therefore, the observation that post-implementation testing is not conducted for all system releases should be of greatest concern to an IS auditor performing an audit of change and release management controls for a new complex system developed by a small in-house IT team. This observation indicates that the system may have quality, reliability, or security problems that could affect the user satisfaction, system performance, or data integrity. This observation also suggests that the change and release management controls are not adequate or effective, as they do not ensure that all system releases are properly tested and validated before and after deployment.
Option A is not correct because access to change testing strategy and results is not restricted to staff outside the IT team is not a major concern for an IS auditor. While it is good practice to limit access to sensitive or confidential information, such as test data or test cases, to authorized personnel only, access to change testing strategy and results may not pose a significant risk to the system or the organization. Moreover, access to change testing strategy and results may be beneficial for some stakeholders outside the IT team, such as business users, project managers, or auditors, who may need to review or evaluate the testing process or outcomes.
Option B is not correct because some user acceptance testing (UAT) was completed by members of the IT team is not a major concern for an IS auditor. User acceptance testing is the process of verifying and validating that the system meets the user requirements and expectations by involving actual or representative users in the testing process3. While it is preferable to have independent and unbiased users perform UAT, it may not be feasible or practical for some organizations, especially those with small or limited resources.
Therefore, some UAT may be completed by members of the IT team, as long as they have sufficient knowledge and experience of the user needs and expectations, and as long as they follow the UAT plan and criteria.
Option C is not correct because IT administrators have access to the production and development environment is not a major concern for an IS auditor. IT administrators are responsible for managing and maintaining the IT infrastructure, including the production and development environments4. Therefore, it is reasonable and necessary for them to have access to both environments, as long as they follow the appropriate policies and procedures for accessing, using, and securing them. Moreover, IT administrators may need to perform tasks such as backup, restore, patching, or troubleshooting in both environments.
References:
What Is Post Implementation Testing?1
Post Implementation Review (PIR) - Definition and Process2
User Acceptance Testing (UAT): Definition and Examples3
What Is an IT Administrator? Definition and Examples4
Therefore, the observation that post-implementation testing is not conducted for all system releases should be of greatest concern to an IS auditor performing an audit of change and release management controls for a new complex system developed by a small in-house IT team. This observation indicates that the system may have quality, reliability, or security problems that could affect the user satisfaction, system performance, or data integrity. This observation also suggests that the change and release management controls are not adequate or effective, as they do not ensure that all system releases are properly tested and validated before and after deployment.
Option A is not correct because access to change testing strategy and results is not restricted to staff outside the IT team is not a major concern for an IS auditor. While it is good practice to limit access to sensitive or confidential information, such as test data or test cases, to authorized personnel only, access to change testing strategy and results may not pose a significant risk to the system or the organization. Moreover, access to change testing strategy and results may be beneficial for some stakeholders outside the IT team, such as business users, project managers, or auditors, who may need to review or evaluate the testing process or outcomes.
Option B is not correct because some user acceptance testing (UAT) was completed by members of the IT team is not a major concern for an IS auditor. User acceptance testing is the process of verifying and validating that the system meets the user requirements and expectations by involving actual or representative users in the testing process3. While it is preferable to have independent and unbiased users perform UAT, it may not be feasible or practical for some organizations, especially those with small or limited resources.
Therefore, some UAT may be completed by members of the IT team, as long as they have sufficient knowledge and experience of the user needs and expectations, and as long as they follow the UAT plan and criteria.
Option C is not correct because IT administrators have access to the production and development environment is not a major concern for an IS auditor. IT administrators are responsible for managing and maintaining the IT infrastructure, including the production and development environments4. Therefore, it is reasonable and necessary for them to have access to both environments, as long as they follow the appropriate policies and procedures for accessing, using, and securing them. Moreover, IT administrators may need to perform tasks such as backup, restore, patching, or troubleshooting in both environments.
References:
What Is Post Implementation Testing?1
Post Implementation Review (PIR) - Definition and Process2
User Acceptance Testing (UAT): Definition and Examples3
What Is an IT Administrator? Definition and Examples4
CISA-CN Exam Question 664
量子運算的出現對傳統資料加密方法有何影響?
Correct Answer: A
Quantum algorithms, such as Shor's algorithm, can factor large prime numbers exponentially faster than classical computers, threatening the security of RSA and elliptic-curve cryptography. Similarly, Grover's algorithm reduces the effective strength of symmetric key algorithms by half, requiring larger key sizes.
While post-quantum cryptography is being developed, current algorithms may become obsolete once practical quantum computers exist. Options B, C, and D are incorrect because quantum does not inherently improve encryption, nor is training the key issue-it is the fundamental breakage of cryptographic assumptions.
References (ISACA): ISACA Journal - Cryptographic Risks and Quantum Computing; CISA Review Manual, Cryptography.
While post-quantum cryptography is being developed, current algorithms may become obsolete once practical quantum computers exist. Options B, C, and D are incorrect because quantum does not inherently improve encryption, nor is training the key issue-it is the fundamental breakage of cryptographic assumptions.
References (ISACA): ISACA Journal - Cryptographic Risks and Quantum Computing; CISA Review Manual, Cryptography.
CISA-CN Exam Question 665
下列哪一種類型的環境設備最有可能部署在資料中心的地板磚下方?
Correct Answer: C
Water sensors are devices that can detect the presence of water or moisture in a given area. They are often deployed below the floor tiles of a data center to monitor for any water leaks that may damage the equipment or cause electrical hazards. Water sensors can alert the data center staff or trigger an automatic response to prevent or mitigate the water leakage.
The other options are not likely to be deployed below the floor tiles of a data center. Temperature sensors and humidity sensors are usually deployed above the floor tiles to measure the ambient conditions of the data center and ensure optimal cooling and ventilation. Air pressure sensors are typically deployed at the air vents or ducts to monitor the airflow and pressure distribution in the data center.
References:
Data Center Environmental Monitoring
Water Detection in Data Centers
The other options are not likely to be deployed below the floor tiles of a data center. Temperature sensors and humidity sensors are usually deployed above the floor tiles to measure the ambient conditions of the data center and ensure optimal cooling and ventilation. Air pressure sensors are typically deployed at the air vents or ducts to monitor the airflow and pressure distribution in the data center.
References:
Data Center Environmental Monitoring
Water Detection in Data Centers
- Other Version
- 3167ISACA.CISA-CN.v2026-05-19.q615
- 1367ISACA.CISA-CN.v2026-05-16.q320
- 2977ISACA.CISA-CN.v2025-12-21.q601
- 3314ISACA.CISA-CN.v2025-12-17.q626
- Latest Upload
- 271ISACA.CISA-CN.v2026-09-15.q708
- 128EMC.NCA.v2026-09-15.q38
- 122Netskope.NSK300.v2026-09-14.q35
- 202CompTIA.CV0-004.v2026-09-14.q232
- 160Microsoft.AZ-801.v2026-09-14.q135
- 153NVIDIA.NCA-AIIO.v2026-09-12.q52
- 196CompTIA.220-1202.v2026-09-12.q122
- 176SAP.C_CT325_2601.v2026-09-11.q26
- 384ECCouncil.312-50v13.v2026-09-11.q327
- 275Microsoft.AZ-801.v2026-09-11.q140
[×]
Download PDF File
Enter your email address to download ISACA.CISA-CN.v2026-09-15.q708 Practice Test
