CISA-CN Exam Question 171
對訊息應用雜湊函數並獲取和加密摘要的過程是指:
Correct Answer: B
CISA-CN Exam Question 172
評估新開發應用程式有效性的最佳方法是:
Correct Answer: D
The best way to evaluate the effectiveness of a newly developed application is to review acceptance testing results. Acceptance testing is a process of verifying that the application meets the specified requirements and expectations of the users and stakeholders. Acceptance testing results can provide evidence of the functionality, usability, reliability, performance, security and quality of the application. Performing a post- implementation review, analyzing load testing results, and performing a secure code review are also important activities for evaluating an application, but they are not as comprehensive or conclusive as acceptance testing results.
References: Info Technology and Systems Resources | COBIT, Risk, Governance ... - ISACA, IT Governance and Process Maturity
References: Info Technology and Systems Resources | COBIT, Risk, Governance ... - ISACA, IT Governance and Process Maturity
CISA-CN Exam Question 173
哪種類型的攻擊對組織最敏感的資料構成最大風險?
Correct Answer: C
An insider attack poses the greatest risk to an organization's most sensitive data. An insider attack is a type of cyberattack that is carried out by someone who has legitimate access to the organization's network, systems, or data, such as an employee, contractor, or business partner. An insider attack can be intentional or unintentional, malicious or negligent, and can have various motives, such as financial gain, revenge, espionage, sabotage, or curiosity.
An insider attack poses the greatest risk to an organization's most sensitive data because:
An insider has a high level of trust and privilege within the organization, which allows them to bypass security controls and access confidential or restricted data without raising suspicion or detection.
An insider has a deep knowledge of the organization's operations, processes, policies, and vulnerabilities, which enables them to exploit them effectively and cause maximum damage or disruption.
An insider can use various techniques and tools to conceal their identity and actions, such as encryption, steganography, deletion, or alteration of logs or evidence.
An insider can cause significant harm or loss to the organization in terms of data integrity, availability, confidentiality, reputation, compliance, and profitability.
According to the 2023 Cost of Insider Threats Global Report by Ponemon Institute and ObserveIT 1, the average annual cost of insider threats for organizations worldwide was $11.45 million in 2022, a 31% increase from 2018. The report also found that the average number of incidents per organization was 77 in 2022, a
47% increase from 2018. The report classified insider threats into three categories: careless or negligent employees or contractors, criminal or malicious insiders, and credential thieves. The report revealed that careless or negligent insiders were the most common and costly type of insider threat, accounting for 62% of all incidents and $4.58 million in costs.
The other options are not the greatest risk to an organization's most sensitive data, although they can still pose significant threats.
A password attack is a type of cyberattack that attempts to guess or crack a user's password to gain unauthorized access to their account or system. A password attack can use various methods, such as brute force, dictionary, rainbow table, phishing, keylogging, or social engineering. A password attack can compromise the security and privacy of the user's data and information. However, a password attack can be prevented or mitigated by using strong and unique passwords, changing passwords frequently, enabling multi- factor authentication (MFA), and avoiding clicking on suspicious links or attachments.
An eavesdropping attack is a type of cyberattack that intercepts or monitors the communication between two parties without their knowledge or consent. An eavesdropping attack can use various techniques, such as wiretapping, packet sniffing, man-in-the-middle (MITM), or side-channel. An eavesdropping attack can expose the content and metadata of the communication, such as messages, files, voice calls, emails, etc.
However, an eavesdropping attack can be prevented or mitigated by using encryption, authentication, digital signatures, VPNs (virtual private networks), or secure protocols.
A spear phishing attack is a type of phishing attack that targets a specific individual or group with personalized and convincing emails that appear to come from a trusted source. A spear phishing attack aims to trick the recipient into clicking on a malicious link or attachment that can infect their device with malware or steal their credentials or data. A spear phishing attack can compromise the security and privacy of the recipient's data and information. However, a spear phishing attack can be prevented or mitigated by verifying the sender's identity and email address, checking the email content for spelling and grammar errors, hovering over links before clicking on them (or not clicking at all), scanning attachments for viruses before opening them (or not opening at all), and reporting suspicious emails to IT security staff.
An insider attack poses the greatest risk to an organization's most sensitive data because:
An insider has a high level of trust and privilege within the organization, which allows them to bypass security controls and access confidential or restricted data without raising suspicion or detection.
An insider has a deep knowledge of the organization's operations, processes, policies, and vulnerabilities, which enables them to exploit them effectively and cause maximum damage or disruption.
An insider can use various techniques and tools to conceal their identity and actions, such as encryption, steganography, deletion, or alteration of logs or evidence.
An insider can cause significant harm or loss to the organization in terms of data integrity, availability, confidentiality, reputation, compliance, and profitability.
According to the 2023 Cost of Insider Threats Global Report by Ponemon Institute and ObserveIT 1, the average annual cost of insider threats for organizations worldwide was $11.45 million in 2022, a 31% increase from 2018. The report also found that the average number of incidents per organization was 77 in 2022, a
47% increase from 2018. The report classified insider threats into three categories: careless or negligent employees or contractors, criminal or malicious insiders, and credential thieves. The report revealed that careless or negligent insiders were the most common and costly type of insider threat, accounting for 62% of all incidents and $4.58 million in costs.
The other options are not the greatest risk to an organization's most sensitive data, although they can still pose significant threats.
A password attack is a type of cyberattack that attempts to guess or crack a user's password to gain unauthorized access to their account or system. A password attack can use various methods, such as brute force, dictionary, rainbow table, phishing, keylogging, or social engineering. A password attack can compromise the security and privacy of the user's data and information. However, a password attack can be prevented or mitigated by using strong and unique passwords, changing passwords frequently, enabling multi- factor authentication (MFA), and avoiding clicking on suspicious links or attachments.
An eavesdropping attack is a type of cyberattack that intercepts or monitors the communication between two parties without their knowledge or consent. An eavesdropping attack can use various techniques, such as wiretapping, packet sniffing, man-in-the-middle (MITM), or side-channel. An eavesdropping attack can expose the content and metadata of the communication, such as messages, files, voice calls, emails, etc.
However, an eavesdropping attack can be prevented or mitigated by using encryption, authentication, digital signatures, VPNs (virtual private networks), or secure protocols.
A spear phishing attack is a type of phishing attack that targets a specific individual or group with personalized and convincing emails that appear to come from a trusted source. A spear phishing attack aims to trick the recipient into clicking on a malicious link or attachment that can infect their device with malware or steal their credentials or data. A spear phishing attack can compromise the security and privacy of the recipient's data and information. However, a spear phishing attack can be prevented or mitigated by verifying the sender's identity and email address, checking the email content for spelling and grammar errors, hovering over links before clicking on them (or not clicking at all), scanning attachments for viruses before opening them (or not opening at all), and reporting suspicious emails to IT security staff.
CISA-CN Exam Question 174
在后续审计过程中,信息系统审计员发现管理层推迟了之前商定的一项建议的实施。审计员的职责是什么?
Correct Answer: A
The correct answer is A. Assess the impact of any risks the decision may pose to the organization.
During follow-up, the auditor's responsibility is to determine whether management's actions have sufficiently addressed the identified risk. If management defers an agreed corrective action, the auditor should assess whether the remaining risk is acceptable or whether the deferral exposes the organization to unacceptable risk.
ISACA guidance on audit follow-up states that IS audit and assurance professionals should monitor relevant information to conclude whether management has planned or taken appropriate and timely action to address reported audit findings and recommendations. It also identifies deferring follow-up activities and assuming the risk of not taking corrective action as part of the follow-up process.
Option B is not the best answer because simply amending the final report does not evaluate the risk impact.
Option C is not the best answer because management, not the auditor, owns corrective action. The auditor can recommend and follow up but should not force management commitment. Option D may be appropriate later if the risk is significant or exceeds risk appetite, but the auditor should first assess the impact.
This question maps to Information Systems Auditing Process, because ISACA's CISA Exam Content Outline includes conducting post-audit follow-up to evaluate whether identified risk has been sufficiently addressed.
References: ISACA CISA Exam Content Outline, Domain 1; ISACA Journal, Enhancing the Audit Follow-up Process Using COBIT 5.
During follow-up, the auditor's responsibility is to determine whether management's actions have sufficiently addressed the identified risk. If management defers an agreed corrective action, the auditor should assess whether the remaining risk is acceptable or whether the deferral exposes the organization to unacceptable risk.
ISACA guidance on audit follow-up states that IS audit and assurance professionals should monitor relevant information to conclude whether management has planned or taken appropriate and timely action to address reported audit findings and recommendations. It also identifies deferring follow-up activities and assuming the risk of not taking corrective action as part of the follow-up process.
Option B is not the best answer because simply amending the final report does not evaluate the risk impact.
Option C is not the best answer because management, not the auditor, owns corrective action. The auditor can recommend and follow up but should not force management commitment. Option D may be appropriate later if the risk is significant or exceeds risk appetite, but the auditor should first assess the impact.
This question maps to Information Systems Auditing Process, because ISACA's CISA Exam Content Outline includes conducting post-audit follow-up to evaluate whether identified risk has been sufficiently addressed.
References: ISACA CISA Exam Content Outline, Domain 1; ISACA Journal, Enhancing the Audit Follow-up Process Using COBIT 5.
CISA-CN Exam Question 175
與自主開發系統相比,購買軟體包意味著最終用戶無需進行測試:
Correct Answer: B
Compared to developing a system in-house, acquiring a software package means that the need for testing by end users is unchanged. This is because end users are still the ultimate customers and beneficiaries of the system, and they need to ensure that the software package meets their requirements, expectations, and satisfaction. End user testing, also known as user acceptance testing (UAT) or beta testing, is the final stage of testing performed by the user or client to determine whether the software can be accepted or not1. Enduser testing is important for both in-house developed and acquired software packages, as it helps to verify the functionality, usability, performance, and reliability of the system2. End user testing also helps to identify and resolve any defects, errors, or issues that may not have been detected by the developers or vendors3.
Therefore, option B is the correct answer.
Option A is not correct because end user testing is not eliminated by acquiring a software package. Even though the software package may have been tested by the vendor or supplier, it may still have bugs, compatibility issues, or configuration problems that need to be fixed before deployment4. Option C is not correct because end user testing is not increased by acquiring a software package. The scope and extent of end user testing depend on various factors, such as the complexity, criticality, and customization of the system, and not on whether it is developed in-house or acquired. Option D is not correct because end user testing is not reduced by acquiring a software package. The software package may still require modifications or integrations to suit the specific needs and environment of the organization, and these changes need to be tested by the end users.
References:
Chapter 4 Methods of Software Acquisition5
What is User Acceptance Testing (UAT): A Complete Guide1
What Is End-to-End Testing? (With How-To and Example)3
How to Evaluate New Software in 5 Steps4
User Acceptance Testing (UAT) in ERP Projects
User Acceptance Testing for Packaged Software
Therefore, option B is the correct answer.
Option A is not correct because end user testing is not eliminated by acquiring a software package. Even though the software package may have been tested by the vendor or supplier, it may still have bugs, compatibility issues, or configuration problems that need to be fixed before deployment4. Option C is not correct because end user testing is not increased by acquiring a software package. The scope and extent of end user testing depend on various factors, such as the complexity, criticality, and customization of the system, and not on whether it is developed in-house or acquired. Option D is not correct because end user testing is not reduced by acquiring a software package. The software package may still require modifications or integrations to suit the specific needs and environment of the organization, and these changes need to be tested by the end users.
References:
Chapter 4 Methods of Software Acquisition5
What is User Acceptance Testing (UAT): A Complete Guide1
What Is End-to-End Testing? (With How-To and Example)3
How to Evaluate New Software in 5 Steps4
User Acceptance Testing (UAT) in ERP Projects
User Acceptance Testing for Packaged Software
- Other Version
- 3258ISACA.CISA-CN.v2026-05-19.q615
- 1421ISACA.CISA-CN.v2026-05-16.q320
- 3096ISACA.CISA-CN.v2025-12-21.q601
- 3374ISACA.CISA-CN.v2025-12-17.q626
- Latest Upload
- 131Workday.Workday-Pro-Integrations.v2026-09-16.q48
- 133Cisco.350-801.v2026-09-16.q298
- 134SAP.C_ARCIG.v2026-09-16.q35
- 331ISACA.CISA-CN.v2026-09-15.q708
- 141EMC.NCA.v2026-09-15.q38
- 150Netskope.NSK300.v2026-09-14.q35
- 234CompTIA.CV0-004.v2026-09-14.q232
- 194Microsoft.AZ-801.v2026-09-14.q135
- 176NVIDIA.NCA-AIIO.v2026-09-12.q52
- 239CompTIA.220-1202.v2026-09-12.q122
[×]
Download PDF File
Enter your email address to download ISACA.CISA-CN.v2026-09-15.q708 Practice Test
