CISA-CN Exam Question 116
在對IT組織結構進行審計時,下列哪一項發現對組織構成最大風險?
Correct Answer: A
High employee turnover (A) poses the greatest risk because it leads to knowledge loss, operational disruptions, and potential security risks from departing employees. A constantly changing workforce can also impact compliance, training, and overall IT stability.
Other options:
Lack of customer satisfaction surveys (B) is a business issue but not a critical IT risk.
Aging staff (C) may be a long-term risk but does not have an immediate impact.
Frequent software upgrades (D) can be beneficial if managed correctly.
Reference: ISACA CISA Review Manual, IT Governance and Management of IT
Other options:
Lack of customer satisfaction surveys (B) is a business issue but not a critical IT risk.
Aging staff (C) may be a long-term risk but does not have an immediate impact.
Frequent software upgrades (D) can be beneficial if managed correctly.
Reference: ISACA CISA Review Manual, IT Governance and Management of IT
CISA-CN Exam Question 117
下列何者最能指導資訊系統審計師確定安排針對已報告審計問題商定的糾正措施後續跟進的適當時間?
Correct Answer: B
This is because the follow-up of agreed corrective actions for reported audit issues should be done after the auditee has had enough time to implement the corrective actions and demonstrate their effectiveness and sustainability. The follow-up audit should not be too soon or too late, but based on a reasonable and realistic timeframe that allows for adequate testing and verification of the control operation12.
Answer A. Progress updates indicate that the implementation of agreed actions is on track. is not the best answer, because progress updates are not sufficient to guide the follow-up audit timing. Progress updates are useful for monitoring and communicating the status and challenges of the corrective actions, but they do not provide conclusive evidence of the control operation. The follow-up audit should be based on actual results and outcomes, not on expectations or projections12.
Answer C. Business management has completed the implementation of agreed actions on schedule. is not the best answer, because the completion of the implementation of agreed actions is not enough to guide the follow-up audit timing. The completion of the implementation only indicates that the auditee has taken the necessary steps to address the audit issues, but it does not guarantee that the corrective actions are effective and sustainable. The follow-up audit should be based on the evaluation and validation of the control operation, not on the completion of the control implementation12.
Answer D. Regulators have announced a timeline for an inspection visit. is not the best answer, because the regulators' inspection visit is not relevant to guide the follow-up audit timing. The regulators' inspection visit is an external factor that may or may not coincide with the internal follow-up audit schedule. The follow-up audit should be based on the internal audit plan and objectives, not on the external audit requirements or expectations12.
Answer A. Progress updates indicate that the implementation of agreed actions is on track. is not the best answer, because progress updates are not sufficient to guide the follow-up audit timing. Progress updates are useful for monitoring and communicating the status and challenges of the corrective actions, but they do not provide conclusive evidence of the control operation. The follow-up audit should be based on actual results and outcomes, not on expectations or projections12.
Answer C. Business management has completed the implementation of agreed actions on schedule. is not the best answer, because the completion of the implementation of agreed actions is not enough to guide the follow-up audit timing. The completion of the implementation only indicates that the auditee has taken the necessary steps to address the audit issues, but it does not guarantee that the corrective actions are effective and sustainable. The follow-up audit should be based on the evaluation and validation of the control operation, not on the completion of the control implementation12.
Answer D. Regulators have announced a timeline for an inspection visit. is not the best answer, because the regulators' inspection visit is not relevant to guide the follow-up audit timing. The regulators' inspection visit is an external factor that may or may not coincide with the internal follow-up audit schedule. The follow-up audit should be based on the internal audit plan and objectives, not on the external audit requirements or expectations12.
CISA-CN Exam Question 118
某組織採用虛擬機器 (VM) 複製取代對其關鍵伺服器進行每日備份。
在評估恢復程序的充分性時,下列哪一項驗證最為重要?
在評估恢復程序的充分性時,下列哪一項驗證最為重要?
Correct Answer: B
The most important validation point is whether the VM replication process is periodically tested to confirm that recovery will actually work. ISACA guidance on backup and recovery states that when using new backup methodologies or technologies, management should test the data afterward to ensure the process is reliably recording all required data, and auditors should ensure periodic health checks are performed.
Option B is correct because recovery adequacy is not proven by the mere existence of replication. ISACA specifically warns that replication alone can increase risk, since corruption can be replicated as well, and it emphasizes validating the reliability of the backup or replication process through testing and health checks.
Option A is important for resilience, but offsite location alone does not prove recoverability. A replica that is never tested may still fail when needed.
Option C is not the most important factor for evaluating recovery procedures. Load balancing supports performance and availability, but it is not the key evidence that replicated systems can be recovered successfully.
Option D is a useful security precaution. ISACA does note that VM backup administrators should not have Internet access to reduce ransomware exposure, but that is a security-hardening issue, not the primary validation of recovery adequacy.
Therefore, B is the best answer because periodic testing is the most important way to validate that VM replication will support actual recovery.
References (Official ISACA):
ISACA Journal, IS Audit Basics: Backup and Recovery - replication can increase risk if corruption is copied; auditors should ensure backup/recovery processes are tested and health checks are performed.
ISACA Journal, A Five-Layer View of Data Center Systems Security - disaster recovery design should consider criticality and RPO/RTO.
Option B is correct because recovery adequacy is not proven by the mere existence of replication. ISACA specifically warns that replication alone can increase risk, since corruption can be replicated as well, and it emphasizes validating the reliability of the backup or replication process through testing and health checks.
Option A is important for resilience, but offsite location alone does not prove recoverability. A replica that is never tested may still fail when needed.
Option C is not the most important factor for evaluating recovery procedures. Load balancing supports performance and availability, but it is not the key evidence that replicated systems can be recovered successfully.
Option D is a useful security precaution. ISACA does note that VM backup administrators should not have Internet access to reduce ransomware exposure, but that is a security-hardening issue, not the primary validation of recovery adequacy.
Therefore, B is the best answer because periodic testing is the most important way to validate that VM replication will support actual recovery.
References (Official ISACA):
ISACA Journal, IS Audit Basics: Backup and Recovery - replication can increase risk if corruption is copied; auditors should ensure backup/recovery processes are tested and health checks are performed.
ISACA Journal, A Five-Layer View of Data Center Systems Security - disaster recovery design should consider criticality and RPO/RTO.
CISA-CN Exam Question 119
下列哪一項是企業架構(EA)在組織中的主要目的?
Correct Answer: D
The best answer is D. To structure IT projects to achieve desired business results.
ISACA guidance describes enterprise architecture as a top-down, business-driven discipline focused on business capabilities, strategy, and alignment of people, process, and technology. Enterprise architecture is not primarily about individual systems or day-to-day operations. Its purpose is to ensure that change initiatives and IT investments are organized in a way that supports the enterprise's strategic and business outcomes.
Option A is too narrow because EA is broader than designing single systems. Option B is only one specialized area within the overall architecture landscape. Option C is more aligned with operations management than enterprise architecture. The strongest answer is the one linking EA to business-driven structuring of initiatives and results.
Therefore, the correct answer is D, because enterprise architecture exists to align and structure IT initiatives so the organization can achieve desired business results.
References (Official ISACA):
ISACA, Developing Business Capabilities Using COBIT 5 - enterprise architecture focuses on business capabilities supporting strategy.
ISACA Journal, Enterprise Security Architecture-A Top-down Approach - architecture bridges business risk, process requirements, and technical issues.
ISACA Journal, Information Security Architecture: Gap Assessment and Prioritization - supports business- driven architectural alignment.
ISACA, Using COBIT 2019 to Plan and Execute an Organization Transformation Strategy - IT governance and management should create value from IT initiatives.
ISACA guidance describes enterprise architecture as a top-down, business-driven discipline focused on business capabilities, strategy, and alignment of people, process, and technology. Enterprise architecture is not primarily about individual systems or day-to-day operations. Its purpose is to ensure that change initiatives and IT investments are organized in a way that supports the enterprise's strategic and business outcomes.
Option A is too narrow because EA is broader than designing single systems. Option B is only one specialized area within the overall architecture landscape. Option C is more aligned with operations management than enterprise architecture. The strongest answer is the one linking EA to business-driven structuring of initiatives and results.
Therefore, the correct answer is D, because enterprise architecture exists to align and structure IT initiatives so the organization can achieve desired business results.
References (Official ISACA):
ISACA, Developing Business Capabilities Using COBIT 5 - enterprise architecture focuses on business capabilities supporting strategy.
ISACA Journal, Enterprise Security Architecture-A Top-down Approach - architecture bridges business risk, process requirements, and technical issues.
ISACA Journal, Information Security Architecture: Gap Assessment and Prioritization - supports business- driven architectural alignment.
ISACA, Using COBIT 2019 to Plan and Execute an Organization Transformation Strategy - IT governance and management should create value from IT initiatives.
CISA-CN Exam Question 120
關鍵績效指標(KPI)要發揮作用,必須具備以下條件:
Correct Answer: D
A key performance indicator (KPI) is a quantifiable measure of performance over time for a specific objective1. KPIs help organizations and teams track their progress and achievements towards their strategic goals. To be useful, a KPI must have a target value, which is the desired level of performance or outcome that the organization or team aims to achieve. A target value provides a clear direction and a benchmark for measuring success or failure. Without a target value, a KPI is meaningless, as it does not indicate whether the performance is good or bad, or how far or close the organization or team is from reaching their objective.
- Other Version
- 3238ISACA.CISA-CN.v2026-05-19.q615
- 1402ISACA.CISA-CN.v2026-05-16.q320
- 3074ISACA.CISA-CN.v2025-12-21.q601
- 3351ISACA.CISA-CN.v2025-12-17.q626
- Latest Upload
- 131Workday.Workday-Pro-Integrations.v2026-09-16.q48
- 133Cisco.350-801.v2026-09-16.q298
- 134SAP.C_ARCIG.v2026-09-16.q35
- 313ISACA.CISA-CN.v2026-09-15.q708
- 140EMC.NCA.v2026-09-15.q38
- 148Netskope.NSK300.v2026-09-14.q35
- 233CompTIA.CV0-004.v2026-09-14.q232
- 194Microsoft.AZ-801.v2026-09-14.q135
- 175NVIDIA.NCA-AIIO.v2026-09-12.q52
- 235CompTIA.220-1202.v2026-09-12.q122
[×]
Download PDF File
Enter your email address to download ISACA.CISA-CN.v2026-09-15.q708 Practice Test
