CISA-CN Exam Question 461
資訊系統審計員正在評估一個基於網路的客戶服務應用程式開發專案的進度。
下列哪一項對本次評估最有幫助?
下列哪一項對本次評估最有幫助?
Correct Answer: A
A backlog consumption report is a report that shows the amount of work that has been completed and the amount of work that remains to be done in a project. It is a useful tool for measuring the progress and performance of a web-based customer service application development project, as it can indicate whether the project is on track, ahead or behind schedule, and how much effort is required to finish the project. A backlog consumption report can also help identify any issues or risks that may affect the project delivery. Critical path analysis reports, developer status reports and change management logs are also helpful for evaluating a project, but they are not as helpful as a backlog consumption report, as they do not provide a clear picture of the overall project status and completion rate. References:
[Backlog Consumption Report Definition]
Backlog Consumption Report | ISACA
[Backlog Consumption Report Definition]
Backlog Consumption Report | ISACA
CISA-CN Exam Question 462
在完成对IT系统的渗透测试并得出测试结果后,下一步应该是:
Correct Answer: C
The correct answer is C. remediation and retesting.
After a penetration test identifies findings, the next step is for management or the responsible technical teams to remediate the identified vulnerabilities and then retest to confirm the vulnerabilities were properly addressed. The value of penetration testing comes not only from identifying weaknesses but from ensuring corrective action is completed and validated.
Option A is not the best answer because analyzing system changes may be part of change management, but it is not the direct next step after penetration test findings. Option B is not the best answer because vulnerability scanning may support validation, but the more complete answer is remediation and retesting. Option D is important because penetration test reports are sensitive, but confidentiality of the report is an ongoing requirement, not the next corrective step for findings.
ISACA defines penetration testing as a live test of security defenses by mimicking real-life attackers, and Domain 5 of the CISA Exam Content Outline includes security testing tools and techniques, vulnerability management, and security monitoring.
References: ISACA CISA Exam Content Outline, Domain 5; ISACA Interactive Glossary, "Penetration testing," "Vulnerability management," and "Remediation."
After a penetration test identifies findings, the next step is for management or the responsible technical teams to remediate the identified vulnerabilities and then retest to confirm the vulnerabilities were properly addressed. The value of penetration testing comes not only from identifying weaknesses but from ensuring corrective action is completed and validated.
Option A is not the best answer because analyzing system changes may be part of change management, but it is not the direct next step after penetration test findings. Option B is not the best answer because vulnerability scanning may support validation, but the more complete answer is remediation and retesting. Option D is important because penetration test reports are sensitive, but confidentiality of the report is an ongoing requirement, not the next corrective step for findings.
ISACA defines penetration testing as a live test of security defenses by mimicking real-life attackers, and Domain 5 of the CISA Exam Content Outline includes security testing tools and techniques, vulnerability management, and security monitoring.
References: ISACA CISA Exam Content Outline, Domain 5; ISACA Interactive Glossary, "Penetration testing," "Vulnerability management," and "Remediation."
CISA-CN Exam Question 463
在審查組織的資訊科技管理標準和指南時,下列哪些內容應該包含在資訊系統開發方法論中?
Correct Answer: B
Risk management techniques should be included in an IS development methodology. An IS development methodology is a set of guidelines, standards, and procedures that provide a structured and consistent approach to developinginformation systems. A good IS development methodology should cover all the phases of the system development life cycle (SDLC), from planning and analysis to design, implementation, testing, and maintenance1.
Risk management techniques are an essential part of an IS development methodology, as they help to identify, assess, prioritize, mitigate, monitor, and communicate the risks that may affect the success of the system development project. Risk management techniques can also help to ensure that the system meets the requirements and expectations of the stakeholders, complies with the relevant laws and regulations, and delivers value to the organization2.
The other options are not as relevant or appropriate as risk management techniques for an IS development methodology. Value-added activity analysis is a technique for evaluating the efficiency and effectiveness of business processes, but it is not specific to IS development3. Access control rules are policies and mechanisms for restricting or granting access to information systems and resources, but they are more related to security management than IS development4. Incident management techniques are methods for handling and resolving incidents that disrupt the normal operation of information systems and services, but they are more related to service management than IS development5.
References:
ISACA, CISA Review Manual, 27th Edition, 2019, p. 1911
ISACA, CISA Review Manual, 27th Edition, 2019, p. 1942
Value-Added Activity Analysis3
Access Control Rules4
Incident Management Techniques5
Risk management techniques are an essential part of an IS development methodology, as they help to identify, assess, prioritize, mitigate, monitor, and communicate the risks that may affect the success of the system development project. Risk management techniques can also help to ensure that the system meets the requirements and expectations of the stakeholders, complies with the relevant laws and regulations, and delivers value to the organization2.
The other options are not as relevant or appropriate as risk management techniques for an IS development methodology. Value-added activity analysis is a technique for evaluating the efficiency and effectiveness of business processes, but it is not specific to IS development3. Access control rules are policies and mechanisms for restricting or granting access to information systems and resources, but they are more related to security management than IS development4. Incident management techniques are methods for handling and resolving incidents that disrupt the normal operation of information systems and services, but they are more related to service management than IS development5.
References:
ISACA, CISA Review Manual, 27th Edition, 2019, p. 1911
ISACA, CISA Review Manual, 27th Edition, 2019, p. 1942
Value-Added Activity Analysis3
Access Control Rules4
Incident Management Techniques5
CISA-CN Exam Question 464
一項新法規已頒布,該法規強制要求採取特定的資訊安全措施來保護客戶資料。在根據該法規進行審計時,下列哪一項對資訊系統審計員最有用?
Correct Answer: A
A compliance gap analysis is a detailed review of an organization's current state of compliance against a specific regulation or standard. It helps identify the areas and controls that are not meeting the requirements, assess their risk levels, and determine the corrective actions that can be taken to achieve compliance12. A compliance gap analysis is the most useful tool for an IS auditor to review when auditing against a new regulation, as it provides a clear and comprehensive picture of the compliance status, gaps, and remediation plan of the organization.
References
1: Information Security Architecture: Gap Assessment and Prioritization - ISACA
2: How to perform Compliance Gap Analysis? - Sprinto
References
1: Information Security Architecture: Gap Assessment and Prioritization - ISACA
2: How to perform Compliance Gap Analysis? - Sprinto
CISA-CN Exam Question 465
當被審計方在後續審計時仍無法完成所有審計建議時,資訊系統審計師的最佳做法是什麼?
Correct Answer: D
The best course of action for an IS auditor when an auditee is unable to close all audit recommendations by the time of the follow-up audit is to evaluate the residual risk due to open issues. Residual risk is the risk that remains after the implementation of controls or mitigating actions. Evaluating the residual risk due to open issues can help the IS auditor assess the impact and likelihood of the potential threats and vulnerabilities that have not been addressed by the auditee, as well as the adequacy and effectiveness of the existing controls or mitigating actions. Evaluating the residual risk due to open issues can also help the IS auditor prioritize and communicate the open issues to the auditee and other stakeholders, such as senior management or audit committee, and recommend appropriate actions or escalation procedures.
Ensuring the open issues are retained in the audit results is a course of action for an IS auditor when an auditee is unable to close all audit recommendations by the time of the follow-up audit, but it is not the best one. Ensuring the open issues are retained in the audit results can help the IS auditor document and report the status and progress of the audit recommendations, as well as provide a basis for future follow-up audits.
However, ensuring the open issues are retained in the audit results does not provide an analysis or evaluation of the residual risk due to open issues, which is more important for informing decision-making and action- taking.
Terminating the follow-up because open issues are not resolved is not a course of action for an IS auditor when an auditee is unable to close all audit recommendations by the time of the follow-up audit, but rather a consequence or outcome of it. Terminating the follow-up because open issues are not resolved may indicate that the auditee has failed to comply with the agreed-upon actions or deadlines, or that the IS auditor has encountered significant obstacles or resistance from the auditee. Terminating the follow-up because open issues are not resolved may also trigger further actions or sanctions from the IS auditor or other authorities, such as issuing a qualified or adverse opinion, withholding certification, or imposing penalties.
Recommending compensating controls for open issues is not a course of action for an IS auditor when an auditee is unable to close all audit recommendations by the time of the follow-up audit, but rather a possible outcome or result of it. Compensating controls are alternative or additional controls that are implemented to reduce or eliminate the risk associated with a weakness or deficiency in another control. Recommending compensating controls for open issues may be appropriate when the auditee is unable to implement the original audit recommendations due to technical, operational,financial, or other constraints, and when the compensating controls can provide a similar or equivalent level of assurance. However, recommending compensating controls for open issues requires a prior evaluation of the residual risk due to open issues, which is more important for determining whether compensating controls are necessary and feasible.
References:
Follow-up Audits - Canadian Audit and Accountability Foundation 1
Conducting The Audit Follow-Up: When To Verify - TheAuditor 2
Internal Audit Follow Ups: Are They Really Worth The Effort
Ensuring the open issues are retained in the audit results is a course of action for an IS auditor when an auditee is unable to close all audit recommendations by the time of the follow-up audit, but it is not the best one. Ensuring the open issues are retained in the audit results can help the IS auditor document and report the status and progress of the audit recommendations, as well as provide a basis for future follow-up audits.
However, ensuring the open issues are retained in the audit results does not provide an analysis or evaluation of the residual risk due to open issues, which is more important for informing decision-making and action- taking.
Terminating the follow-up because open issues are not resolved is not a course of action for an IS auditor when an auditee is unable to close all audit recommendations by the time of the follow-up audit, but rather a consequence or outcome of it. Terminating the follow-up because open issues are not resolved may indicate that the auditee has failed to comply with the agreed-upon actions or deadlines, or that the IS auditor has encountered significant obstacles or resistance from the auditee. Terminating the follow-up because open issues are not resolved may also trigger further actions or sanctions from the IS auditor or other authorities, such as issuing a qualified or adverse opinion, withholding certification, or imposing penalties.
Recommending compensating controls for open issues is not a course of action for an IS auditor when an auditee is unable to close all audit recommendations by the time of the follow-up audit, but rather a possible outcome or result of it. Compensating controls are alternative or additional controls that are implemented to reduce or eliminate the risk associated with a weakness or deficiency in another control. Recommending compensating controls for open issues may be appropriate when the auditee is unable to implement the original audit recommendations due to technical, operational,financial, or other constraints, and when the compensating controls can provide a similar or equivalent level of assurance. However, recommending compensating controls for open issues requires a prior evaluation of the residual risk due to open issues, which is more important for determining whether compensating controls are necessary and feasible.
References:
Follow-up Audits - Canadian Audit and Accountability Foundation 1
Conducting The Audit Follow-Up: When To Verify - TheAuditor 2
Internal Audit Follow Ups: Are They Really Worth The Effort
- Other Version
- 3328ISACA.CISA-CN.v2026-05-19.q615
- 1439ISACA.CISA-CN.v2026-05-16.q320
- 3194ISACA.CISA-CN.v2025-12-21.q601
- 3462ISACA.CISA-CN.v2025-12-17.q626
- Latest Upload
- 119Salesforce.Slack-Con-201.v2026-09-17.q40
- 146AAPC.CPC.v2026-09-17.q182
- 126NetworkAppliance.NS0-094.v2026-09-17.q70
- 115PaloAltoNetworks.XSIAM-Engineer.v2026-09-17.q28
- 154Workday.Workday-Pro-Integrations.v2026-09-16.q48
- 151Cisco.350-801.v2026-09-16.q298
- 141SAP.C_ARCIG.v2026-09-16.q35
- 432ISACA.CISA-CN.v2026-09-15.q708
- 165EMC.NCA.v2026-09-15.q38
- 169Netskope.NSK300.v2026-09-14.q35
[×]
Download PDF File
Enter your email address to download ISACA.CISA-CN.v2026-09-15.q708 Practice Test
