CISA-CN Exam Question 211
在基於雲端的訊息傳遞和協作平台採購的規劃階段,下列何者最重要?
Correct Answer: A
The most important thing to determine during the planning phase of a cloud-based messaging and collaboration platform acquisition is the types of data that can be uploaded to the platform. This is because different types of data may have different security, privacy, and compliance requirements, depending on the nature, sensitivity, and value of the data. For example, personal data, financial data, health data, or intellectual property data may be subject to various laws and regulations thatgovern how they can be collected, stored, processed, and shared in the cloud. Therefore, it is essential to identify and classify the types of data that will be uploadedto the platform, and ensure that the platform meets the organization's policies and standards for data protection1.
The other options are not as important as the types of data that can be uploaded to the platform during the planning phase of a cloud-based messaging and collaboration platform acquisition. Option A, role-based access control policies, is a mechanism that defines who can access what data and resources on the platform based on their roles and responsibilities. Role-based access control policies are important for ensuring data security and accountability, but they can be designed and implemented after the platform is acquired2. Option C, processes for on-boarding and off-boarding users to the platform, are procedures that enable or disable user accounts and access rights on the platform. Processes for on-boarding and off-boarding users are important for managing user identities and lifecycles, but they can be developed and executed after the platform is acquired3. Option D, processes for reviewing administrator activity, are methods that monitor and audit the actions and events performed by administrators on the platform. Processes for reviewing administrator activity are important for detecting and preventing unauthorized or malicious activities, but they can be established and performed after the platform is acquired4.
References:
Cloud Messaging and Collaboration Services - Maryland.gov DoIT4
MessageBird acquires real-time notifications and in-app messaging platform Pusher for$35M | TechCrunch2 Symphony to lead financial market communicationswith the acquisition of Cloud9 Technologies3 Cloud messaging and collaboration | Sumo Logic
The other options are not as important as the types of data that can be uploaded to the platform during the planning phase of a cloud-based messaging and collaboration platform acquisition. Option A, role-based access control policies, is a mechanism that defines who can access what data and resources on the platform based on their roles and responsibilities. Role-based access control policies are important for ensuring data security and accountability, but they can be designed and implemented after the platform is acquired2. Option C, processes for on-boarding and off-boarding users to the platform, are procedures that enable or disable user accounts and access rights on the platform. Processes for on-boarding and off-boarding users are important for managing user identities and lifecycles, but they can be developed and executed after the platform is acquired3. Option D, processes for reviewing administrator activity, are methods that monitor and audit the actions and events performed by administrators on the platform. Processes for reviewing administrator activity are important for detecting and preventing unauthorized or malicious activities, but they can be established and performed after the platform is acquired4.
References:
Cloud Messaging and Collaboration Services - Maryland.gov DoIT4
MessageBird acquires real-time notifications and in-app messaging platform Pusher for$35M | TechCrunch2 Symphony to lead financial market communicationswith the acquisition of Cloud9 Technologies3 Cloud messaging and collaboration | Sumo Logic
CISA-CN Exam Question 212
下列哪一項是大型金融機構持續審計的最佳流程?
Correct Answer: B
The best process for continuous auditing for a large financial institution is validating access controls for real- time data systems. This is because access controls are critical for ensuring the confidentiality, integrity, and availability of the financial data that is processed and transmitted by the real-time data systems. Real-time data systems are systems that provide timely and accurate information to support decision-making and transactions in a dynamic and complex environment. Examples of real-time data systems in the financial sector include payment systems, trading platforms, risk management systems, and fraud detection systems.
Continuous auditing of access controls can help detect and prevent unauthorized access, data leakage, data manipulation, or data loss that could compromise the security, reliability, or compliance of the real-time data systems.
Testing encryption standards on the disaster recovery system is not the best process for continuous auditing for a large financial institution. Encryption standards are important for protecting the data stored or transmitted by the disaster recovery system, which is a system that provides backup and recovery capabilities in case of a disruption or disaster. However, testing encryption standards is not a continuous process, but rather a periodic or event-driven process that can be performed as part of the disaster recovery plan testing or validation.
Performing parallel testing between systems is not the best process for continuous auditing for a large financial institution. Parallel testing is a process of comparing the results of two or more systems that perform the same function or task, such as a new system and an old system, or a primary system and a backup system.
Parallel testing can help verify the accuracy, consistency, and compatibility of the systems. However, parallel testing is not a continuous process, but rather a temporary or transitional process that can be performed as part of the system implementation or migration.
Validating performance of help desk metrics is not the best process for continuous auditing for a large financial institution. Help desk metrics are indicators that measure the efficiency, effectiveness, and quality of the help desk service, which is a service that provides technical support and assistance to the users of information systems and technology. Help desk metrics can include metrics such as response time, resolution time, customer satisfaction, and service level agreement (SLA) compliance. Validating performance of help desk metrics can help evaluate and improve the help desk service. However, validating performance of help desk metrics is not a continuous auditing process, but rather a continuous monitoring process that can be performed by the help desk management or quality assurance team.
References:
All eyes on: Continuous auditing - KPMG Global 1
Internal audit's role at financial institutions: PwC 2
The Fed - Supervisory Policy and Guidance Topics - Large Banking ... 3
Continuous Audit: Definition, Steps, Advantages and Disadvantages 4
Continuous auditing of access controls can help detect and prevent unauthorized access, data leakage, data manipulation, or data loss that could compromise the security, reliability, or compliance of the real-time data systems.
Testing encryption standards on the disaster recovery system is not the best process for continuous auditing for a large financial institution. Encryption standards are important for protecting the data stored or transmitted by the disaster recovery system, which is a system that provides backup and recovery capabilities in case of a disruption or disaster. However, testing encryption standards is not a continuous process, but rather a periodic or event-driven process that can be performed as part of the disaster recovery plan testing or validation.
Performing parallel testing between systems is not the best process for continuous auditing for a large financial institution. Parallel testing is a process of comparing the results of two or more systems that perform the same function or task, such as a new system and an old system, or a primary system and a backup system.
Parallel testing can help verify the accuracy, consistency, and compatibility of the systems. However, parallel testing is not a continuous process, but rather a temporary or transitional process that can be performed as part of the system implementation or migration.
Validating performance of help desk metrics is not the best process for continuous auditing for a large financial institution. Help desk metrics are indicators that measure the efficiency, effectiveness, and quality of the help desk service, which is a service that provides technical support and assistance to the users of information systems and technology. Help desk metrics can include metrics such as response time, resolution time, customer satisfaction, and service level agreement (SLA) compliance. Validating performance of help desk metrics can help evaluate and improve the help desk service. However, validating performance of help desk metrics is not a continuous auditing process, but rather a continuous monitoring process that can be performed by the help desk management or quality assurance team.
References:
All eyes on: Continuous auditing - KPMG Global 1
Internal audit's role at financial institutions: PwC 2
The Fed - Supervisory Policy and Guidance Topics - Large Banking ... 3
Continuous Audit: Definition, Steps, Advantages and Disadvantages 4
CISA-CN Exam Question 213
某銀行的網路銀行業務包含企業客戶帳戶(金額較高)和小型企業客戶帳戶(金額較低)。對於資訊系統審計師而言,下列哪一種抽樣方法最適合用於這些帳戶?
Correct Answer: B
Stratified mean per unit sampling is a method of audit sampling that divides the population into subgroups (strata) based on some characteristic, such as monetary value, and then selects a sample from each stratum using mean per unit sampling. Mean per unit sampling is a method of audit sampling that estimates the total value of a population by multiplying the average value of the sample items by the number of items in the population. Stratified mean per unit sampling is suitable for populations that have a high variability or a skewed distribution, such as the bank accounts in this question. By stratifying the population, the auditor can reduce the sampling error and increase the precision of the estimate.
Difference estimation sampling (option A) is not the best sampling approach for these accounts. Difference estimation sampling is a method of audit sampling that estimates the total error or misstatement in a population by multiplying the average difference between the book value and the audited value of the sample items by the number of items in the population. Difference estimation sampling is suitable for populations that have a low variability and a symmetrical distribution, which is not the case for the bank accounts in this question.
Customer unit sampling (option C) is not a sampling approach, but a type of monetary unit sampling.
Monetary unit sampling is a method of audit sampling that selects sample items based on their monetary value, rather than their physical units. Customer unit sampling is a variation of monetary unit sampling that treats each customer account as a single unit, regardless of how many transactions or balances it contains.
Customer unit sampling may be appropriate for testing existence or occurrence assertions, but not for estimating total values.
Unstratified mean per unit sampling (option D) is not the best sampling approach for these accounts.
Unstratified mean per unit sampling is a method of audit sampling that applies mean per unit sampling to the entire population without dividing it into subgroups. Unstratified mean per unit sampling may result in a larger sample size and a lower precision than stratified mean per unit sampling, especially for populations that have a high variability or a skewed distribution, such as the bank accounts in this question.
Therefore, option B is the correct answer.
References:
Audit Sampling - AICPA
Audit Sampling: Examples and Guidance To The Sampling Methods
Audit Sampling |Audit | Financial Audit - Scribd
Difference estimation sampling (option A) is not the best sampling approach for these accounts. Difference estimation sampling is a method of audit sampling that estimates the total error or misstatement in a population by multiplying the average difference between the book value and the audited value of the sample items by the number of items in the population. Difference estimation sampling is suitable for populations that have a low variability and a symmetrical distribution, which is not the case for the bank accounts in this question.
Customer unit sampling (option C) is not a sampling approach, but a type of monetary unit sampling.
Monetary unit sampling is a method of audit sampling that selects sample items based on their monetary value, rather than their physical units. Customer unit sampling is a variation of monetary unit sampling that treats each customer account as a single unit, regardless of how many transactions or balances it contains.
Customer unit sampling may be appropriate for testing existence or occurrence assertions, but not for estimating total values.
Unstratified mean per unit sampling (option D) is not the best sampling approach for these accounts.
Unstratified mean per unit sampling is a method of audit sampling that applies mean per unit sampling to the entire population without dividing it into subgroups. Unstratified mean per unit sampling may result in a larger sample size and a lower precision than stratified mean per unit sampling, especially for populations that have a high variability or a skewed distribution, such as the bank accounts in this question.
Therefore, option B is the correct answer.
References:
Audit Sampling - AICPA
Audit Sampling: Examples and Guidance To The Sampling Methods
Audit Sampling |Audit | Financial Audit - Scribd
CISA-CN Exam Question 214
以下哪项最有助于证明数字证据是原始形式且未被篡改?
Correct Answer: C
The correct answer is C. Hash values.
Hash values are the best way to establish that digital evidence remains unchanged. A hash is a fixed value mathematically generated from data. If even a small change is made to the evidence, the hash value changes.
Therefore, comparing the hash value calculated when evidence was collected with the hash value calculated later helps prove whether the evidence is still in its original form.
ISACA's glossary defines hashing as a cryptographic process that converts input data into a fixed-length hash value, ensuring data integrity and authentication. This directly supports the use of hash values to verify that digital evidence has not been altered.
Option A is not the best answer because imaging creates a forensic copy of the media, but the image still needs to be validated using hash values. Option B helps prevent accidental or intentional modification during examination, but it does not by itself prove the evidence is unchanged. Option D is important because chain of custody documents who handled evidence, when, and how it was protected. However, chain of custody is a procedural control; hash values provide the stronger technical proof of integrity. ISACA defines chain of custody as the evidence-handling process needed to maintain evidence validity and integrity, including documentation of who had access to the evidence and when.
This question maps mainly to Information Systems Auditing Process because it concerns audit evidence reliability, digital evidence handling, and support for audit conclusions. ISACA's CISA Exam Content Outline includes audit evidence collection techniques and reporting under Domain 1.
References: ISACA CISA Exam Content Outline, Domain 1; ISACA Interactive Glossary, "Hashing" and
"Chain of custody."
Hash values are the best way to establish that digital evidence remains unchanged. A hash is a fixed value mathematically generated from data. If even a small change is made to the evidence, the hash value changes.
Therefore, comparing the hash value calculated when evidence was collected with the hash value calculated later helps prove whether the evidence is still in its original form.
ISACA's glossary defines hashing as a cryptographic process that converts input data into a fixed-length hash value, ensuring data integrity and authentication. This directly supports the use of hash values to verify that digital evidence has not been altered.
Option A is not the best answer because imaging creates a forensic copy of the media, but the image still needs to be validated using hash values. Option B helps prevent accidental or intentional modification during examination, but it does not by itself prove the evidence is unchanged. Option D is important because chain of custody documents who handled evidence, when, and how it was protected. However, chain of custody is a procedural control; hash values provide the stronger technical proof of integrity. ISACA defines chain of custody as the evidence-handling process needed to maintain evidence validity and integrity, including documentation of who had access to the evidence and when.
This question maps mainly to Information Systems Auditing Process because it concerns audit evidence reliability, digital evidence handling, and support for audit conclusions. ISACA's CISA Exam Content Outline includes audit evidence collection techniques and reporting under Domain 1.
References: ISACA CISA Exam Content Outline, Domain 1; ISACA Interactive Glossary, "Hashing" and
"Chain of custody."
CISA-CN Exam Question 215
作業排程透過以下方式影響系統可用性和可靠性:
Correct Answer: C
Job scheduling is a core operational control that ensures workloads are executed in an orderly and efficient manner, balancing demands across processing resources. Its primary benefit is optimization of system resources-CPU, memory, I/O, and network bandwidth-leading to improved throughput and consistent service levels. While scheduling may indirectly reduce downtime (A) or support scalability (B), its direct impact is ensuring resources are allocated efficiently. Decreasing complexity (D) is not the key purpose of scheduling. ISACA's DSS01 (Managed Operations) recognizes workload and job scheduling as crucial practices for sustaining reliable, high-performance IT services.
References (ISACA): COBIT 2019, DSS01 Managed Operations.
References (ISACA): COBIT 2019, DSS01 Managed Operations.
- Other Version
- 3278ISACA.CISA-CN.v2026-05-19.q615
- 1422ISACA.CISA-CN.v2026-05-16.q320
- 3113ISACA.CISA-CN.v2025-12-21.q601
- 3388ISACA.CISA-CN.v2025-12-17.q626
- Latest Upload
- 131Workday.Workday-Pro-Integrations.v2026-09-16.q48
- 133Cisco.350-801.v2026-09-16.q298
- 134SAP.C_ARCIG.v2026-09-16.q35
- 348ISACA.CISA-CN.v2026-09-15.q708
- 141EMC.NCA.v2026-09-15.q38
- 152Netskope.NSK300.v2026-09-14.q35
- 235CompTIA.CV0-004.v2026-09-14.q232
- 194Microsoft.AZ-801.v2026-09-14.q135
- 179NVIDIA.NCA-AIIO.v2026-09-12.q52
- 242CompTIA.220-1202.v2026-09-12.q122
[×]
Download PDF File
Enter your email address to download ISACA.CISA-CN.v2026-09-15.q708 Practice Test
