CISA-CN Exam Question 316
對某組織的IT資產組合進行審查後發現,其中一些應用程式未使用。防止這種情況再次發生的最佳方法是實施這些應用程式。
Correct Answer: D
Asset life cycle management is a technique of asset management where facility managers maximize the usable life of assets throughplanning, purchasing, using, maintaining, and disposing of assets1. The mainaim of assetlife cycle management is to reduce costs and increase productivity by optimizing the performance, reliability, and lifespan of assets2. Asset life cycle management can help prevent the situation of having unused applications by ensuring that the applications are aligned with the business needs, objectives, and strategies, and that they are regularly reviewed, updated, or retired as necessary3.
The other options are not as effective as asset life cycle management for preventing unused applications. A formal request for proposal (RFP) process is a method of soliciting bids from potential vendors or suppliers for a project or service. A RFP process can help select the best application for a specific requirement, but it does not ensure that the application will be used or maintained throughout its lifecycle. Business case development procedures are a set of steps that involve defining the problem, analyzing the alternatives, and proposing a solution for a project or initiative. Business case development procedures can help justify the need and value of an application, but they do not guarantee that the application will be utilized or supported after its implementation. An information asset acquisition policy is a document that outlines the rules and standards for acquiring information assets such as applications. An information asset acquisition policy can help ensure that the applications are acquired in a consistent and compliant manner, but it does not address how the applications will be managed or disposed of after their acquisition.
The other options are not as effective as asset life cycle management for preventing unused applications. A formal request for proposal (RFP) process is a method of soliciting bids from potential vendors or suppliers for a project or service. A RFP process can help select the best application for a specific requirement, but it does not ensure that the application will be used or maintained throughout its lifecycle. Business case development procedures are a set of steps that involve defining the problem, analyzing the alternatives, and proposing a solution for a project or initiative. Business case development procedures can help justify the need and value of an application, but they do not guarantee that the application will be utilized or supported after its implementation. An information asset acquisition policy is a document that outlines the rules and standards for acquiring information assets such as applications. An information asset acquisition policy can help ensure that the applications are acquired in a consistent and compliant manner, but it does not address how the applications will be managed or disposed of after their acquisition.
CISA-CN Exam Question 317
某组织最近发现其所有处理器都存在一个影响范围广泛的芯片级安全漏洞。以下哪项是防止该漏洞被利用的最佳方法?
Correct Answer: C
The correct answer is C. Install vendor patches.
A chip-level processor vulnerability is a technical vulnerability affecting hardware/firmware or processor- related software components. The most effective preventive action is to apply the vendor-provided patch, microcode update, firmware update, operating system update, or other vendor-approved remediation. ISACA defines vulnerability management as a proactive, continuous process for identifying, assessing, prioritizing, and remediating vulnerabilities, and the CISA Exam Content Outline specifically includes evaluation of change, configuration, release, and patch management programs.
Option A is not the best answer because reviewing security logs may help detect attempted exploitation after activity has occurred, but it does not prevent exploitation. Option B is not the best answer because vendor contracts may define support obligations, but contract review does not technically remediate the vulnerability.
Option D is not the best answer because security awareness training is helpful for human-behavior risks such as phishing, but it does not address a processor-level technical flaw.
This question maps mainly to Information Systems Operations and Business Resilience because patch management is listed under Domain 4 in the CISA Exam Content Outline.
References: ISACA CISA Exam Content Outline, Domain 4; ISACA Interactive Glossary, "Vulnerability management," "Vulnerability scanning," and "Remediation."
A chip-level processor vulnerability is a technical vulnerability affecting hardware/firmware or processor- related software components. The most effective preventive action is to apply the vendor-provided patch, microcode update, firmware update, operating system update, or other vendor-approved remediation. ISACA defines vulnerability management as a proactive, continuous process for identifying, assessing, prioritizing, and remediating vulnerabilities, and the CISA Exam Content Outline specifically includes evaluation of change, configuration, release, and patch management programs.
Option A is not the best answer because reviewing security logs may help detect attempted exploitation after activity has occurred, but it does not prevent exploitation. Option B is not the best answer because vendor contracts may define support obligations, but contract review does not technically remediate the vulnerability.
Option D is not the best answer because security awareness training is helpful for human-behavior risks such as phishing, but it does not address a processor-level technical flaw.
This question maps mainly to Information Systems Operations and Business Resilience because patch management is listed under Domain 4 in the CISA Exam Content Outline.
References: ISACA CISA Exam Content Outline, Domain 4; ISACA Interactive Glossary, "Vulnerability management," "Vulnerability scanning," and "Remediation."
CISA-CN Exam Question 318
下列哪一項是確定災難復原計畫 (DRP) 測試是否成功的最佳方法?
Correct Answer: A
The best way to determine whether a test of a disaster recovery plan (DRP) was successful is to analyze whether predetermined test objectives were met. Test objectives are specific, measurable, achievable, relevant, and time-bound (SMART) goals that define what the test aims to accomplish and how it will be evaluated. Test objectives should be aligned with the DRP objectives and scope, and should cover aspects such as recovery time objectives (RTOs), recovery point objectives (RPOs), critical business functions, roles and responsibilities, communication channels, backup systems, and contingency procedures. By comparing the actual test results with the expected test objectives, the IS auditor can measure the effectiveness and efficiency of the DRP and identify any gaps or weaknesses that need to be addressed.
CISA-CN Exam Question 319
下列哪一項是確保業務連續性計劃 (BCP) 在發生重大災難時有效運作的最佳方法?
Correct Answer: B
The best way to ensure that business continuity plans (BCPs) will work effectively in the event of a major disaster is to involve staff at all levels in periodic paper walk-through exercises. This means that the BCPs are tested and validated by the people who will execute them in a real situation, and any gaps, errors, or inconsistencies can be identified and corrected. Paper walk-through exercises are also a good way to raise awareness and train staff on their roles and responsibilities in a BCP scenario, as well as to evaluate the feasibility and effectiveness of the recovery strategies1.
The other options are not the best ways to ensure that BCPs will work effectively, because they do not involve testing or validating the plans. Preparing detailed plans for each business function is important, but it does not guarantee that the plans are realistic, practical, or aligned with the overall business objectives and priorities2. Regularly updating business impact assessments is also essential, but it does not ensure that the BCPs are aligned with the current business environment and risks2. Making senior managers responsible for their plan sections is a good way to assign accountability and authority, but it does not ensure that the plansections are coordinated and integrated with each other2. References:
Best Practice Guide: Business Continuity Planning (BCP)3
Best Practices for Creating a Business Continuity Plan1
Business Continuity Plan Best Practices
The other options are not the best ways to ensure that BCPs will work effectively, because they do not involve testing or validating the plans. Preparing detailed plans for each business function is important, but it does not guarantee that the plans are realistic, practical, or aligned with the overall business objectives and priorities2. Regularly updating business impact assessments is also essential, but it does not ensure that the BCPs are aligned with the current business environment and risks2. Making senior managers responsible for their plan sections is a good way to assign accountability and authority, but it does not ensure that the plansections are coordinated and integrated with each other2. References:
Best Practice Guide: Business Continuity Planning (BCP)3
Best Practices for Creating a Business Continuity Plan1
Business Continuity Plan Best Practices
CISA-CN Exam Question 320
在組織中,下列哪一個角色所展現的支持對資訊安全治理的影響最大?
Correct Answer: C
Information security governance is the subset of enterprise governance that provides strategic direction, ensures that objectives are achieved, manages risk appropriately, uses organizational resources responsibly, and monitors the success or failure of the enterprise security program. Information security governance is essential for ensuring that an organization's information assets are protected from internal and external threats, and that the organization complies with relevant laws and standards.
Demonstrated support from which of the following roles in an organization has the most influence over information security governance? The answer is C, the board of directors. The board of directors is the highest governing body of an organization, responsible for overseeing its strategic direction, performance, and accountability. The board of directors sets the tone at the top for information security governance by:
Establishing a clear vision, mission, and values for information security Approving and reviewing information security policies and standards Allocating sufficient resources and budget for information security Appointing and empowering a chief information security officer (CISO) or equivalent role Holding management accountable for information security performance and compliance Communicating and promoting information security awareness and culture The board of directors has the most influence over information security governance because it has the ultimate authority and responsibility for ensuring that information security is aligned with the organization's business objectives, risks, and stakeholder expectations.
References:
10: What is Information Security Governance? - RiskOptics - Reciprocity
11: Information Security Governance and Risk Management | Moss Adams
12: ISO/IEC 27014:2020 - Information security, cybersecurity and privacy ...
Demonstrated support from which of the following roles in an organization has the most influence over information security governance? The answer is C, the board of directors. The board of directors is the highest governing body of an organization, responsible for overseeing its strategic direction, performance, and accountability. The board of directors sets the tone at the top for information security governance by:
Establishing a clear vision, mission, and values for information security Approving and reviewing information security policies and standards Allocating sufficient resources and budget for information security Appointing and empowering a chief information security officer (CISO) or equivalent role Holding management accountable for information security performance and compliance Communicating and promoting information security awareness and culture The board of directors has the most influence over information security governance because it has the ultimate authority and responsibility for ensuring that information security is aligned with the organization's business objectives, risks, and stakeholder expectations.
References:
10: What is Information Security Governance? - RiskOptics - Reciprocity
11: Information Security Governance and Risk Management | Moss Adams
12: ISO/IEC 27014:2020 - Information security, cybersecurity and privacy ...
- Other Version
- 3458ISACA.CISA-CN.v2026-05-19.q615
- 1457ISACA.CISA-CN.v2026-05-16.q320
- 3265ISACA.CISA-CN.v2025-12-21.q601
- 3516ISACA.CISA-CN.v2025-12-17.q626
- Latest Upload
- 128VMware.3V0-24.25.v2026-09-19.q35
- 228IIA.IIA-CIA-Part1-CN.v2026-09-19.q369
- 168Microsoft.MS-700.v2026-09-18.q195
- 134Symantec.250-587.v2026-09-18.q44
- 133Oracle.1Z0-1066-26.v2026-09-18.q67
- 157Google.Associate-Cloud-Engineer.v2026-09-18.q160
- 149Microsoft.AI-300.v2026-09-18.q53
- 141SAP.C_TS452.v2026-09-18.q86
- 157Salesforce.Slack-Con-201.v2026-09-17.q40
- 219AAPC.CPC.v2026-09-17.q182
[×]
Download PDF File
Enter your email address to download ISACA.CISA-CN.v2026-09-15.q708 Practice Test
