CISA-CN Exam Question 201
資訊系統審計員在審查資料中心的威脅評估時,最關注下列哪一項?
Correct Answer: C
An IS auditor reviewing the threat assessment for a data center would be most concerned if the exercise was completed by local management, because this could introduce bias, conflict of interest, or lack of expertise in the assessment process. A threat assessment is a systematic method of identifying and evaluating the potential threats that could affect the availability, integrity, or confidentiality of the data center and its assets. A threat assessmentshould be conducted by an independent and qualified team that has the necessary skills, knowledge, and experience to perform a comprehensive and objective analysis of the data center's environment, vulnerabilities, and risks1.
The other options are not as concerning as option C for an IS auditor reviewing the threat assessment for a data center. Option A, some of the identified threats are unlikely to occur, is not a problem as long as the likelihood and impact of each threat are properly estimated and prioritized. A threat assessment should consider all possible scenarios, even if they have a low probability of occurrence, to ensure that the data center is prepared for any eventuality2. Option B, all identified threats relate to external entities, is not a flaw as long as the assessment also considers internal threats, such as human errors, malicious insiders, or equipment failures. External threats are often more visible and severe than internal threats, butthey are not the only source of risk for a data center3. Option D, neighboring organizations' operations have been included, is not a mistake as long as the assessment also focuses on the data center's own operations. Neighboring organizations' operations may have an impact on the data center's security and availability, especially if they share physical or network infrastructure or resources. A threat assessmentshould take into account the interdependencies and interactions between the data center and its external environment4.
References:
ISACA, CISA Review Manual, 27th Edition, 2019
ISACA, CISA Review Questions, Answers and Explanations Database - 12 Month Subscription Data Center Threats and Vulnerabilities1 Datacenter threat, vulnerability, and risk assessment2 Data Centre Risk Assessment3
The other options are not as concerning as option C for an IS auditor reviewing the threat assessment for a data center. Option A, some of the identified threats are unlikely to occur, is not a problem as long as the likelihood and impact of each threat are properly estimated and prioritized. A threat assessment should consider all possible scenarios, even if they have a low probability of occurrence, to ensure that the data center is prepared for any eventuality2. Option B, all identified threats relate to external entities, is not a flaw as long as the assessment also considers internal threats, such as human errors, malicious insiders, or equipment failures. External threats are often more visible and severe than internal threats, butthey are not the only source of risk for a data center3. Option D, neighboring organizations' operations have been included, is not a mistake as long as the assessment also focuses on the data center's own operations. Neighboring organizations' operations may have an impact on the data center's security and availability, especially if they share physical or network infrastructure or resources. A threat assessmentshould take into account the interdependencies and interactions between the data center and its external environment4.
References:
ISACA, CISA Review Manual, 27th Edition, 2019
ISACA, CISA Review Questions, Answers and Explanations Database - 12 Month Subscription Data Center Threats and Vulnerabilities1 Datacenter threat, vulnerability, and risk assessment2 Data Centre Risk Assessment3
CISA-CN Exam Question 202
下列哪一項是實施 IT 容量管理流程的主要好處?
Correct Answer: A
Comprehensive and Detailed Explanation:
The primary purpose of IT capacity management is to ensure that IT infrastructure can meet current and future performance requirements in a cost-effective manner.
Option A is correct because it directly relates to capacity management goals.
Option B (rapid deployment) relates more to change management.
Option C (security concerns) is outside the scope of capacity management.
Option D (reducing cost/time) may be a secondary benefit but not the primary objective.
# ISACA Reference: CISA Review Manual 27th Edition, Domain 2, section on capacity management and IT service performance.
The primary purpose of IT capacity management is to ensure that IT infrastructure can meet current and future performance requirements in a cost-effective manner.
Option A is correct because it directly relates to capacity management goals.
Option B (rapid deployment) relates more to change management.
Option C (security concerns) is outside the scope of capacity management.
Option D (reducing cost/time) may be a secondary benefit but not the primary objective.
# ISACA Reference: CISA Review Manual 27th Edition, Domain 2, section on capacity management and IT service performance.
CISA-CN Exam Question 203
全球組織的政策規定,所有工作站必須每天進行惡意軟體掃描。下列何者能為資訊系統審計員提供持續遵守該政策的最佳證據?
Correct Answer: C
Anti-malware tool audit logs would provide an IS auditor with the best evidence of continuous compliance with the global organization's policy that states that all workstations must be scanned for malware each day. Anti-malware tool audit logs are records that capture the activities and events related to the anti-malware software installed on the workstations, such as scan schedules, scan results, updates, alerts, and actions taken1. These logs can help the IS auditor to verify that the anti-malware software is functioning properly, that the scans are performed regularly and effectively, and that any malware incidents are detected and resolved in a timely manner2. Anti-malware tool audit logs can also help the IS auditor to identify any gaps or weaknesses in the anti-malware policy or implementation, and to provide recommendations for improvement3.
The other options are not the best evidence of continuous compliance with the anti-malware policy. Penetration testing results are reports that show the vulnerabilities and risks of the workstations and network from an external or internal attacker's perspective4. While penetration testing can help to assess the security posture and resilience of the organization, it does not provide information on the daily anti-malware scans or their outcomes. Management attestation is a statement or declaration from the management that they have complied with the anti-malware policy5. While management attestation can demonstrate commitment and accountability, it does not provide objective or verifiable evidence of compliance. Recent malware scan reports are documents that show the summary or details of the latest anti-malware scans performed on the workstations. While recent malware scan reports can indicate the current status and performance of the anti- malware software, they do not provide historical or comprehensive evidence of compliance.
References:
Malwarebytes Anti-Malware (MBAM) log collection and threat reports ...
Malicious Behavior Detection using Windows Audit Logs
PCI Requirement 5.2 - Ensure all Anti-Virus Mechanisms are Current ...
Management Attestation - an overview | ScienceDirect Topics
How to Read a Malware Scan Report | Techwalla
The other options are not the best evidence of continuous compliance with the anti-malware policy. Penetration testing results are reports that show the vulnerabilities and risks of the workstations and network from an external or internal attacker's perspective4. While penetration testing can help to assess the security posture and resilience of the organization, it does not provide information on the daily anti-malware scans or their outcomes. Management attestation is a statement or declaration from the management that they have complied with the anti-malware policy5. While management attestation can demonstrate commitment and accountability, it does not provide objective or verifiable evidence of compliance. Recent malware scan reports are documents that show the summary or details of the latest anti-malware scans performed on the workstations. While recent malware scan reports can indicate the current status and performance of the anti- malware software, they do not provide historical or comprehensive evidence of compliance.
References:
Malwarebytes Anti-Malware (MBAM) log collection and threat reports ...
Malicious Behavior Detection using Windows Audit Logs
PCI Requirement 5.2 - Ensure all Anti-Virus Mechanisms are Current ...
Management Attestation - an overview | ScienceDirect Topics
How to Read a Malware Scan Report | Techwalla
CISA-CN Exam Question 204
業務部門出售後,員工將轉移到新公司,但仍可繼續使用原公司的IT設備。資訊系統審計師建議兩家公司就設備的合理使用政策達成一致並形成文件。建議採取何種控制措施?
Correct Answer: B
An acceptable use policy (AUP) is a preventive control that sets out rules and guidelines for using an organization's IT resources, including networks, devices, and software1. It defines acceptable and prohibited behaviors, aiming to protect assets, ensure security, and maintain a productive work environment1. By agreeing to and documenting an AUP for the equipment, both organizations can prevent potential misuse of IT resources2345.
References:
ISO 27001 Acceptable Use Policy Beginner's Guide - High Table
Acceptable Use Policy for Information Technology Resources
Acceptable Use Policies for Workplace Technology | Verizon
IT Governance: Your Must-Have Policies - How-To Geek
Acceptable use policy template - Workable
References:
ISO 27001 Acceptable Use Policy Beginner's Guide - High Table
Acceptable Use Policy for Information Technology Resources
Acceptable Use Policies for Workplace Technology | Verizon
IT Governance: Your Must-Have Policies - How-To Geek
Acceptable use policy template - Workable
CISA-CN Exam Question 205
在規劃雲端服務審計時,審計管理層發現指定的IT審計員不熟悉所使用的技術及其對業務帶來的相關風險。為確保審計質量,審計管理階層應先考慮下列哪些措施?
Correct Answer: C
The best action that audit management should consider first is to reassign the audit to an internal audit subject matter expert. This is because cloud service audits require specialized knowledge and skills to assess the risks and controls associated with the cloud service provider and the cloud service customer. An IS auditor who is unfamiliar with the technologies in use and their associated risks to the business may not be able to perform an effective and efficient audit, and may miss important issues or provide inaccurate recommendations.
Therefore, it is important to ensure that the IS auditor assigned to the cloud service audit has the appropriate competence and experience.
The other options are not as good as reassigning the audit to an internal audit subject matter expert.
Conducting a follow-up audit after a suitable period has elapsed may not address the quality issues of the initial audit, and may also delay the identification and remediation of any problems. Rescheduling the audit assignment for the next financial year may expose the organization to unnecessary risks and may not meet the audit objectives or expectations. Extending the duration of the audit to give the auditor more time may not be feasible or cost-effective, and may not guarantee that the auditor will acquire the necessary knowledge and skills in time.
References:
ISACA, CISA Review Manual, 27th Edition, 2019, p. 1391
ISACA, Cloud Computing: Business Benefits With Security, Governance and Assurance Perspectives, 2009, p. 14
Therefore, it is important to ensure that the IS auditor assigned to the cloud service audit has the appropriate competence and experience.
The other options are not as good as reassigning the audit to an internal audit subject matter expert.
Conducting a follow-up audit after a suitable period has elapsed may not address the quality issues of the initial audit, and may also delay the identification and remediation of any problems. Rescheduling the audit assignment for the next financial year may expose the organization to unnecessary risks and may not meet the audit objectives or expectations. Extending the duration of the audit to give the auditor more time may not be feasible or cost-effective, and may not guarantee that the auditor will acquire the necessary knowledge and skills in time.
References:
ISACA, CISA Review Manual, 27th Edition, 2019, p. 1391
ISACA, Cloud Computing: Business Benefits With Security, Governance and Assurance Perspectives, 2009, p. 14
- Other Version
- 3270ISACA.CISA-CN.v2026-05-19.q615
- 1422ISACA.CISA-CN.v2026-05-16.q320
- 3103ISACA.CISA-CN.v2025-12-21.q601
- 3386ISACA.CISA-CN.v2025-12-17.q626
- Latest Upload
- 131Workday.Workday-Pro-Integrations.v2026-09-16.q48
- 133Cisco.350-801.v2026-09-16.q298
- 134SAP.C_ARCIG.v2026-09-16.q35
- 336ISACA.CISA-CN.v2026-09-15.q708
- 141EMC.NCA.v2026-09-15.q38
- 150Netskope.NSK300.v2026-09-14.q35
- 235CompTIA.CV0-004.v2026-09-14.q232
- 194Microsoft.AZ-801.v2026-09-14.q135
- 177NVIDIA.NCA-AIIO.v2026-09-12.q52
- 240CompTIA.220-1202.v2026-09-12.q122
[×]
Download PDF File
Enter your email address to download ISACA.CISA-CN.v2026-09-15.q708 Practice Test
