CISA-CN Exam Question 1
下列哪一項能為新入職的資訊系統審計員提供評估整體IT績效的最有用資訊?
Correct Answer: C
An IT balanced scorecard (BSC) is a performance metric that is used to identify, improve, and control the various functions and outcomes of an IT department or organization. An IT BSC is based on the concept of the balanced scorecard, which was introduced by Robert Kaplan and David Norton in 1992 as a strategic management system that translates the vision and strategy of an organization into measurable objectives and actions. An IT BSC adapts the balanced scorecard framework to the specific needs and goals of the IT function, aligning it with the business strategy and value proposition.
An IT BSC typically consists of four perspectives that help managers plan, implement, and evaluate the IT performance: customer, internal process, learning and growth, and financial. Each perspective defines a set of objectives, measures, targets, and initiatives that reflect the IT contribution to the organization's success. For example, the customer perspective may measure the satisfaction and retention of internal and external customers who use IT services or products; the internal process perspective may measure the efficiency and effectiveness of IT processes such as development, delivery, support, or security; the learning and growth perspective may measure the skills, knowledge, innovation, and culture of the IT staff; and the financial perspective may measure the costs, benefits, and return on investment of IT projects or assets.
An IT BSC provides a new IS auditor with the most useful information to evaluate overall IT performance because it:
Provides a comprehensive and balanced view of the IT function from multiple angles and stakeholders Links the IT objectives and activities to the business strategy and value creation Enables a clear communication and alignment of expectations and priorities among IT managers, staff, customers, and other stakeholders Facilitates a continuous monitoring and improvement of IT performance based on data-driven feedback and analysis Supports a holistic and integrated approach to IT governance, risk management, and compliance Therefore, an IT BSC is a valuable tool for a new IS auditor to assess how well the IT function is fulfilling its mission and delivering value to the organization.
References:
The IT Balanced Scorecard (BSC) Explained - BMC Software
What Is a Balanced Scorecard (BSC), How Is it Used in Business?
Lost in the Woods: COBIT 2019 and the IT Balanced Scorecard - ISACA
An IT BSC typically consists of four perspectives that help managers plan, implement, and evaluate the IT performance: customer, internal process, learning and growth, and financial. Each perspective defines a set of objectives, measures, targets, and initiatives that reflect the IT contribution to the organization's success. For example, the customer perspective may measure the satisfaction and retention of internal and external customers who use IT services or products; the internal process perspective may measure the efficiency and effectiveness of IT processes such as development, delivery, support, or security; the learning and growth perspective may measure the skills, knowledge, innovation, and culture of the IT staff; and the financial perspective may measure the costs, benefits, and return on investment of IT projects or assets.
An IT BSC provides a new IS auditor with the most useful information to evaluate overall IT performance because it:
Provides a comprehensive and balanced view of the IT function from multiple angles and stakeholders Links the IT objectives and activities to the business strategy and value creation Enables a clear communication and alignment of expectations and priorities among IT managers, staff, customers, and other stakeholders Facilitates a continuous monitoring and improvement of IT performance based on data-driven feedback and analysis Supports a holistic and integrated approach to IT governance, risk management, and compliance Therefore, an IT BSC is a valuable tool for a new IS auditor to assess how well the IT function is fulfilling its mission and delivering value to the organization.
References:
The IT Balanced Scorecard (BSC) Explained - BMC Software
What Is a Balanced Scorecard (BSC), How Is it Used in Business?
Lost in the Woods: COBIT 2019 and the IT Balanced Scorecard - ISACA
CISA-CN Exam Question 2
下列哪一項最能描述在組織中實施資料分類策略時文件擁有者的角色?
Correct Answer: A
The role of a document owner when implementing a data classification policy in an organization is to classify documents to correctly reflect the level of sensitivity of information they contain. A document owner is the person who is ultimately responsible for the creation, maintenance, and protection of a document, usually a member of senior management or a business unit1. A data classification policy is a plan that defines how the organization categorizesits data based on its value, risk, and regulatory requirements, and how it handles and secures each data category2.
According to the data classification policy template by Netwrix3, one of the roles and responsibilities of the document owner is to assign data classification labels based on the data's potential impact level. Data classification labels are tags or markings that indicate the sensitivity level of the data, such as public, internal, confidential, or restricted. The document owner should apply the data classification labels to the documents that contain the data, either manually or automatically, using tools and methods such as metadata, watermarks, headers, footers, or encryption. The document owner should also review and update the data classification labels periodically or whenever there is a change in the data's sensitivity level.
By classifying documents to correctly reflect the level of sensitivity of information they contain, the document owner can help to ensure that the documents are handled in accordance with the data classification policy.
This means that the documents are stored, accessed, shared, transmitted, and disposed of in a secure and appropriate manner, based on the rules and controls defined for each data category. This can also help to prevent data loss, leakage, or breach incidents that may cause harm or damage to the organization or its stakeholders.
Therefore, option A is the correct answer.
References:
Data Classification Policy: Definition, Examples, and Free Template2
Data Classification Policy Template - Netwrix3
Data Classification and Handling Policy - University of Hull1
According to the data classification policy template by Netwrix3, one of the roles and responsibilities of the document owner is to assign data classification labels based on the data's potential impact level. Data classification labels are tags or markings that indicate the sensitivity level of the data, such as public, internal, confidential, or restricted. The document owner should apply the data classification labels to the documents that contain the data, either manually or automatically, using tools and methods such as metadata, watermarks, headers, footers, or encryption. The document owner should also review and update the data classification labels periodically or whenever there is a change in the data's sensitivity level.
By classifying documents to correctly reflect the level of sensitivity of information they contain, the document owner can help to ensure that the documents are handled in accordance with the data classification policy.
This means that the documents are stored, accessed, shared, transmitted, and disposed of in a secure and appropriate manner, based on the rules and controls defined for each data category. This can also help to prevent data loss, leakage, or breach incidents that may cause harm or damage to the organization or its stakeholders.
Therefore, option A is the correct answer.
References:
Data Classification Policy: Definition, Examples, and Free Template2
Data Classification Policy Template - Netwrix3
Data Classification and Handling Policy - University of Hull1
CISA-CN Exam Question 3
下列哪一種方法是銷毀儲存在電子媒體上的敏感資料的最有效方法?
Correct Answer: C
The most effective method of destroying sensitive data stored on electronic media is physical destruction, which involves breaking, shredding, melting, or incinerating the media to make it unreadable and unrecoverable. Degaussing, random character overwrite, and low-level formatting are methods of sanitizing or erasing data from electronic media, but they do not guarantee complete destruction of data and may leave some traces that can be recovered by advanced techniques. Therefore, physical destruction is the most secure and reliable method of data disposal for sensitive data. References: CISA Review Manual (Digital Version), Chapter 5: Protection of Information Assets, Section 5.4: Data Disposal
CISA-CN Exam Question 4
在審查以人工智慧(AI)系統取代多個手動資料輸入系統的專案時,資訊系統稽核員最應該關注的是人工智慧將對以下方面產生的影響:
Correct Answer: B
The auditor should be most concerned with the impact AI will have on enterprise architecture (EA) when reviewing a project to replace multiple manual data entry systems with an AI system. EA is a comprehensive framework that defines the structure, components, relationships, and principles of an organization's IT environment. EA can help to align the IT strategy with the business strategy and ensure the coherence, consistency, and integration of the IT systems and services. Replacing manual data entry systems with an AI system may have significant implications for the EA, such aschanging the business processes, data flows, security requirements, performance standards, or governance models. The auditor should assess whether the project has considered the impact of AI on EA and whether the EA has been updated accordingly. References:
CISA Review Manual (Digital Version), Chapter 1, Section 1.41
CISA Online Review Course, Domain 5, Module 1, Lesson 22
CISA Review Manual (Digital Version), Chapter 1, Section 1.41
CISA Online Review Course, Domain 5, Module 1, Lesson 22
CISA-CN Exam Question 5
在對組織的資料隱私實務進行審計時,下列何者最重要?
Correct Answer: D
The answer D is correct because the most important thing to determine when conducting an audit of an organization's data privacy practices is whether the systems inventory containing personal data is maintained.
A systems inventory is a list of all the systems, applications, databases, and devices that store, process, or transmit personal data within the organization. Maintaining a systems inventory is essential for data privacy because it helps the organization to identify, classify, and protect the personal data it holds, as well as to comply with the relevant privacy laws and regulations. A systems inventory also enables the organization to perform data protection impact assessments (DPIAs), data breach notifications, data subject access requests, and data retention and disposal policies.
The other options are not as important as option D. Whether a disciplinary process is established for data privacy violations (option A) is a policy issue that may deter or sanction the employees who violate the data privacy rules, but it does not directly affect the data privacy practices of the organization. Whether strong encryption algorithms are deployed for personal data protection (option B) is a technical issue that may enhance the security and confidentiality of the personal data, but it does not address the other aspects of data privacy, such as accuracy, consent, and purpose limitation.Whether privacy technologies are implemented for personal data protection (option C) is also a technical issue that may support the data privacy practices of the organization, but it does not guarantee that the organization follows the best practices or complies with the applicable laws and regulations.
References:
IS Audit Basics: Auditing Data Privacy
Best Practices for Privacy Audits
ISACA Produces New Audit and Assurance Programs for Data Privacy and Mobile Computing
A systems inventory is a list of all the systems, applications, databases, and devices that store, process, or transmit personal data within the organization. Maintaining a systems inventory is essential for data privacy because it helps the organization to identify, classify, and protect the personal data it holds, as well as to comply with the relevant privacy laws and regulations. A systems inventory also enables the organization to perform data protection impact assessments (DPIAs), data breach notifications, data subject access requests, and data retention and disposal policies.
The other options are not as important as option D. Whether a disciplinary process is established for data privacy violations (option A) is a policy issue that may deter or sanction the employees who violate the data privacy rules, but it does not directly affect the data privacy practices of the organization. Whether strong encryption algorithms are deployed for personal data protection (option B) is a technical issue that may enhance the security and confidentiality of the personal data, but it does not address the other aspects of data privacy, such as accuracy, consent, and purpose limitation.Whether privacy technologies are implemented for personal data protection (option C) is also a technical issue that may support the data privacy practices of the organization, but it does not guarantee that the organization follows the best practices or complies with the applicable laws and regulations.
References:
IS Audit Basics: Auditing Data Privacy
Best Practices for Privacy Audits
ISACA Produces New Audit and Assurance Programs for Data Privacy and Mobile Computing
- Other Version
- 3155ISACA.CISA-CN.v2026-05-19.q615
- 1356ISACA.CISA-CN.v2026-05-16.q320
- 2970ISACA.CISA-CN.v2025-12-21.q601
- 3305ISACA.CISA-CN.v2025-12-17.q626
- Latest Upload
- 249ISACA.CISA-CN.v2026-09-15.q708
- 118EMC.NCA.v2026-09-15.q38
- 122Netskope.NSK300.v2026-09-14.q35
- 198CompTIA.CV0-004.v2026-09-14.q232
- 157Microsoft.AZ-801.v2026-09-14.q135
- 149NVIDIA.NCA-AIIO.v2026-09-12.q52
- 195CompTIA.220-1202.v2026-09-12.q122
- 174SAP.C_CT325_2601.v2026-09-11.q26
- 381ECCouncil.312-50v13.v2026-09-11.q327
- 266Microsoft.AZ-801.v2026-09-11.q140
[×]
Download PDF File
Enter your email address to download ISACA.CISA-CN.v2026-09-15.q708 Practice Test
