CISA-CN Exam Question 66
下列何者能為資訊系統審計專業人員提供執行審計職能的最佳指引?
Correct Answer: A
The audit charter is the document that defines the purpose, authority and responsibility of the IS audit function. It provides IS audit professionals with the best source of direction for performing audit functions, as it establishes the scope, objectives, reporting lines, independence, accountability and resources of the IS audit function. The IT steering committee is a governance body that oversees the strategic alignment, prioritization and direction of IT initiatives, but it does not provide specific guidance for IS audit functions. The information security policy is a document that defines the rules and principles for protecting information assets in the organization, but it does not cover all aspects of IS audit functions. Audit best practices are general guidelines and recommendations for conducting effective and efficient audits, but they are not binding or authoritative sources of direction for IS audit functions. References: CISA Review Manual (Digital Version) 1, Chapter 1: Information Systems Auditing Process, Section 1.1: Audit Charter.
CISA-CN Exam Question 67
如果發生導致內部伺服器無法存取、中斷正常業務運作的事件,下列哪一項操作應該先執行?
Correct Answer: C
CISA-CN Exam Question 68
資訊系統審計員在選擇軟體即服務 (SaaS) 供應商之前,應該向管理階層建議的最重要行動是什麼?
Correct Answer: B
Before selecting a SaaS vendor, the most important action is to complete a risk assessment. A risk assessment is a process of identifying, analyzing, and evaluating the potential risks associated with outsourcing software and IT infrastructure to a third-party provider. A risk assessment helps to determine the impact and likelihood of various threats, such as data breaches, service disruptions, vendor lock-in, compliance issues, and legal disputes. A risk assessment also helps to identify the mitigation strategies and controls that can reduce or eliminate the risks.
A risk assessment is more important than determining service level requirements, performing a business impact analysis (BIA), or conducting a vendor audit because it provides the basis for these other actions.
Service level requirements are the expectations and obligations that define the quality and quantity of service that the vendor must provide to the customer. A BIA is a process of assessing the potential effects of an interruption or disruption of critical business functions or processes due to an incident or disaster. A vendor audit is a process of verifying the vendor's compliance with the contract terms, service levels, security policies, and best practices.
Service level requirements, BIA, and vendor audit are all important actions for selecting a SaaS vendor, but they depend on the results of the risk assessment. For example, service level requirements should reflect the risk appetite and tolerance of the customer, which are determined by the risk assessment. A BIA should prioritize the recovery of the most critical and vulnerable business functions or processes, which are identified by the risk assessment. A vendor audit should focus on the areas of highest risk and concern, which are highlighted by the risk assessment.
Therefore, an IS auditor should recommend to management that completing a risk assessment is the most important action before selecting a SaaS vendor.
References:
SaaS checklist: Nine factors to consider when selecting a vendor
SaaS vendor management: 10 best practices to achieve success
Best Practices for Software SaaS Vendor Selection and Negotiation
How to Evaluate SaaS Providers and Solutions by Developing ... - Gartner
A risk assessment is more important than determining service level requirements, performing a business impact analysis (BIA), or conducting a vendor audit because it provides the basis for these other actions.
Service level requirements are the expectations and obligations that define the quality and quantity of service that the vendor must provide to the customer. A BIA is a process of assessing the potential effects of an interruption or disruption of critical business functions or processes due to an incident or disaster. A vendor audit is a process of verifying the vendor's compliance with the contract terms, service levels, security policies, and best practices.
Service level requirements, BIA, and vendor audit are all important actions for selecting a SaaS vendor, but they depend on the results of the risk assessment. For example, service level requirements should reflect the risk appetite and tolerance of the customer, which are determined by the risk assessment. A BIA should prioritize the recovery of the most critical and vulnerable business functions or processes, which are identified by the risk assessment. A vendor audit should focus on the areas of highest risk and concern, which are highlighted by the risk assessment.
Therefore, an IS auditor should recommend to management that completing a risk assessment is the most important action before selecting a SaaS vendor.
References:
SaaS checklist: Nine factors to consider when selecting a vendor
SaaS vendor management: 10 best practices to achieve success
Best Practices for Software SaaS Vendor Selection and Negotiation
How to Evaluate SaaS Providers and Solutions by Developing ... - Gartner
CISA-CN Exam Question 69
人事辦公室多台無人看管的筆記型電腦被盜,這些筆記型電腦中存有敏感的客戶資料。為防止此類事件再次發生,資訊系統審計員提出的下列哪一項是保護資料的最佳建議?
Correct Answer: A
According to the CISA - Certified Information Systems Auditor Study Guide1, the correct answer to your question is A. Encrypt the disk drive. This is because encryption is a logical security measure that can protect data even if the physical device is stolen or lost. Encryption makes thedata unreadable and inaccessible without the proper key or password. The other options are not as effective as encryption in this scenario. Two- factor authentication is a user authentication method that requires two pieces of evidence to verify the user's identity, such as a password and a code sent to a phone. However, this does not prevent unauthorized access to the data if the laptop is already logged in or if the attacker can bypass the authentication. Enhancing physical security is a preventive measure that can reduce the risk of theft, but it does not guarantee that theft will not occur or that the data will be safe if it does. Requiring the use of cable locks is another preventive measure that can deter thieves, but it can also be easily cut or removed by a determined attacker.
CISA-CN Exam Question 70
在规划黑盒渗透测试时,以下哪项最重要?
Correct Answer: D
The correct answer is D. The management of the client organization has approved the scope of testing.
Before any penetration test begins, especially a black-box test, the most important requirement is formal management approval of the scope. Penetration testing can be disruptive and may involve activities that resemble real attacks. Therefore, the tester must have clear authorization, approved scope, rules of engagement, timing, target systems, restrictions, and escalation procedures before testing starts.
ISACA guidance on penetration testing emphasizes the importance of clear documentation of project scope, rules of engagement, and client authorization to demonstrate that testing is being conducted legally and ethically. ISACA also explains that planning security testing requires defining scope and out-of-scope items, including what will be tested, where testing will occur from, when testing should not be performed, which hosts are restricted, and who will perform the testing.
Option A is useful because tactics, techniques, and procedures help define how the test will be performed, but they should not override approved scope and authorization. Option B is not required for a black-box penetration test because black-box testing intentionally gives the tester little or no internal knowledge of the environment. Option C is important because results must be documented and communicated, but reporting happens after testing; formal authorization and scope approval must come first.
This question maps mainly to Protection of Information Assets, because penetration testing is a security testing technique used to evaluate vulnerabilities and the effectiveness of security controls. ISACA's CISA Exam Content Outline includes security testing tools and techniques, threat and vulnerability management, and security monitoring under Domain 5.
References: ISACA CISA Exam Content Outline, Domain 5; ISACA white paper on penetration testing scope, rules of engagement, and client authorization; ISACA Journal, Planning for Information Security Testing: A Practical Approach.
Before any penetration test begins, especially a black-box test, the most important requirement is formal management approval of the scope. Penetration testing can be disruptive and may involve activities that resemble real attacks. Therefore, the tester must have clear authorization, approved scope, rules of engagement, timing, target systems, restrictions, and escalation procedures before testing starts.
ISACA guidance on penetration testing emphasizes the importance of clear documentation of project scope, rules of engagement, and client authorization to demonstrate that testing is being conducted legally and ethically. ISACA also explains that planning security testing requires defining scope and out-of-scope items, including what will be tested, where testing will occur from, when testing should not be performed, which hosts are restricted, and who will perform the testing.
Option A is useful because tactics, techniques, and procedures help define how the test will be performed, but they should not override approved scope and authorization. Option B is not required for a black-box penetration test because black-box testing intentionally gives the tester little or no internal knowledge of the environment. Option C is important because results must be documented and communicated, but reporting happens after testing; formal authorization and scope approval must come first.
This question maps mainly to Protection of Information Assets, because penetration testing is a security testing technique used to evaluate vulnerabilities and the effectiveness of security controls. ISACA's CISA Exam Content Outline includes security testing tools and techniques, threat and vulnerability management, and security monitoring under Domain 5.
References: ISACA CISA Exam Content Outline, Domain 5; ISACA white paper on penetration testing scope, rules of engagement, and client authorization; ISACA Journal, Planning for Information Security Testing: A Practical Approach.
- Other Version
- 3181ISACA.CISA-CN.v2026-05-19.q615
- 1379ISACA.CISA-CN.v2026-05-16.q320
- 2988ISACA.CISA-CN.v2025-12-21.q601
- 3319ISACA.CISA-CN.v2025-12-17.q626
- Latest Upload
- 278ISACA.CISA-CN.v2026-09-15.q708
- 128EMC.NCA.v2026-09-15.q38
- 122Netskope.NSK300.v2026-09-14.q35
- 202CompTIA.CV0-004.v2026-09-14.q232
- 160Microsoft.AZ-801.v2026-09-14.q135
- 153NVIDIA.NCA-AIIO.v2026-09-12.q52
- 197CompTIA.220-1202.v2026-09-12.q122
- 178SAP.C_CT325_2601.v2026-09-11.q26
- 384ECCouncil.312-50v13.v2026-09-11.q327
- 278Microsoft.AZ-801.v2026-09-11.q140
[×]
Download PDF File
Enter your email address to download ISACA.CISA-CN.v2026-09-15.q708 Practice Test
