
Get Sep-2026 updated CISA-CN Certification Exam Sample Questions
CISA-CN Study Guide Cover to Cover as Literally
NEW QUESTION # 604
下列哪一項示範了數據分析在貸款發放流程中的使用?
- A. 評估貸款記錄是否包含在批次文件中並由服務系統驗證
- B. 將原始系統中輸入的貸款總體與服務系統上預訂的貸款進行比較
- C. 驗證兩個系統之間是否執行協調並調查差異
- D. 檢查錯誤處理控制,以便在傳輸失敗時通知對應人員
Answer: B
Explanation:
Data analytics can be used to compare data from different sources and identify any discrepancies or anomalies. In this case, comparing a population of loans input in the origination system to loans booked on the servicing system can help detect any errors or frauds in the loan origination process. The other options are not examples of data analytics, but rather controls for data integrity, reconciliation, and error handling. References: CISA Review Manual (Digital Version), Chapter 3, Section 3.3.2
NEW QUESTION # 605
下列哪一項是保護資料中心實體資訊資產最重要的先決條件?
- A. IT 員工對資料保護要求的了解
- B. 已部署的資訊資產的完整且準確的列表
- C. 訂購人員與接收資訊資產的人員之間的職責分離
- D. 現場備用發電機的可用性和測試
Answer: B
Explanation:
The most important prerequisite for the protection of physical information assets in a data center is a complete and accurate list of information assets that have been deployed. Information assets are any data, devices, systems, or software that have value for the organization and need to be protected from unauthorized access, use, disclosure, modification, or destruction4. A data center is a facility that houses various information assets such as servers, storage devices, network equipment, etc., that support the organization's IT operations and services5. A complete and accurate list of information assets that have been deployed in a data center can help to identify and classify the assets based on their importance, sensitivity, or criticality for the organization. This can help to determine the appropriate level of protection and security measures that need to be applied to each asset. A complete and accurate list of information assets can also help to track and monitor the location, status, ownership, usage, configuration, maintenance, etc., of each asset. This can help to prevent or detect any unauthorized or inappropriate changes or movements of assets that may compromise their security or integrity. Segregation of duties between staff ordering and staff receiving information assets, availability and testing of onsite backup generators, and knowledge of the IT staff regarding data protection requirements are also important prerequisites for the protection of physical information assets in a data center, but not as important as a complete and accurate list of information assets that have been deployed. These factors are more related to the implementation and maintenance of security controls and procedures that depend on having a complete and accurate list of information assets as a starting point. References: ISACA CISA Review Manual 27th Edition, page 308
NEW QUESTION # 606
受審核方不同意業務報告草案中提出的糾正措施建議。
下列哪一項是 IS 審計員在準備最終報告時的最佳行動方案?
- A. 在發布最終報告之前達成協議。
- B. 在最終參與報告中包含高階管理層支持的立場
- C. 從最終參與報告中排除有爭議的推薦
- D. 確保受審核方的意見包含在工作底稿中
Answer: B
Explanation:
The IS auditor's best course of action when preparing the final report is to include the position supported by senior management in the final engagement report. The IS auditor should communicate the audit findings and recommendations to senior management and obtain their feedback and approval before issuing the final report. If there is a disagreement between the auditee and the IS auditor regarding a recommendation for corrective action, the IS auditor should present both sides of the argument and the supporting evidence, and seek senior management's opinion and decision. The IS auditor should respect and follow senior management' s position, and include it in the final engagement report, along with the auditee's comments if applicable. The other options arenot the best course of action, because they either do not resolve the disagreement, do notreflect senior management's authority, or do not report the audit results accurately and completely. References: CISA Review Manual (Digital Version)1, Chapter 2, Section 2.2.5
NEW QUESTION # 607
下列何者為資訊系統審計專業人員提供了執行審計職能的最佳指導來源?
- A. IT 指導委員會
- B. 審核最佳實踐
- C. 資訊安全策略
- D. 審計章程
Answer: D
Explanation:
The audit charter is the document that defines the purpose, authority and responsibility of the IS audit function. It provides IS audit professionals with the best source of direction for performing audit functions, as it establishes the scope, objectives, reporting lines, independence, accountability and resources of the IS audit function. The IT steering committee is a governance body that oversees the strategic alignment, prioritization and direction of IT initiatives, but it does not provide specific guidance for IS audit functions. The information security policy is a document that defines the rules and principles for protecting information assets in the organization, but it does not cover all aspects of IS audit functions. Audit best practices are general guidelines and recommendations for conducting effective and efficient audits, but they are not binding or authoritative sources of direction for IS audit functions. References: CISA Review Manual (Digital Version) 1, Chapter 1: Information Systems Auditing Process, Section 1.1: Audit Charter.
NEW QUESTION # 608
某個組織計劃從第三方服務提供者接收自動資料饋送到其企業資料倉儲。下列哪一項是防止接受不良數據的最佳方法?
- A. 任命整個組織的資料品質冠軍。
- B. 從信譽良好的供應商購買資料清理工具。
- C. 取得指示資料饋送失敗的錯誤代碼。
- D. 實施業務規則以拒絕無效資料。
Answer: D
Explanation:
The best way to prevent accepting bad data from a third-party service provider is to implement business rules to reject invalid data. Business rules are logical statements that define the data quality requirements and standards for the organization. By implementing business rules, the organization can ensure that only data that meets the predefined criteria is accepted into the enterprise data warehouse. Obtaining error codes indicating failed data feeds, purchasing data cleansing tools from a reputable vendor, and appointing data quality champions across the organization are useful measures to improve data quality, but they do not prevent accepting bad data in the first place. References: ISACA Journal Article: Data Quality Management
NEW QUESTION # 609
在決定組織的資訊安全策略是否充分時,下列哪一項是資訊系統審計員所使用的最佳資訊來源?
- A. 產業基準
- B. 資訊安全計劃計劃
- C. 風險評估結果
- D. 滲透測試結果
Answer: C
Explanation:
The best source of information for an IS auditor to use when determining whether an organization's information security policy is adequate is the risk assessment results. The risk assessment results provide the auditor with an overview of the organization's risk profile, including the identification, analysis, and evaluation of the risks that affect the confidentiality, integrity, and availability of the information assets. The auditor can use the risk assessment results to compare the organization's information security policy with the risk appetite, risk tolerance, and risk treatment strategies of the organization. The auditor can also use the risk assessment results to evaluate if the information security policy is aligned with the organization's objectives, requirements, and regulations.
Some of the web sources that support this answer are:
* Performance Measurement Guide for Information Security
* ISO 27001 Annex A.5 - Information Security Policies
* [CISA Certified Information Systems Auditor - Question0551]
NEW QUESTION # 610
當組織決定為其外部客戶外包技術支援時,資訊系統審計師應建議將下列哪一項作為主要關注領域?
- A. 使服務等級協定 (SLA) 與目前需求保持一致。
- B. 確保合約中包含審計權。
- C. 最大限度地減少與第三方協議相關的成本。
- D. 監控客戶對變更的滿意度。
Answer: A
Explanation:
The primary area of focus when an organization decides to outsource technical support for its external customers is to align service level agreements (SLAs) with current needs. SLAs are contracts that define the scope, quality, and expectations of the services provided by the vendor, as well as the remedies or penalties for non-compliance. SLAs are essential for ensuring that the outsourced technical support meets the customer's requirements and satisfaction, as well as the organization's objectives and standards. By aligning SLAs with current needs, the organization can specify the key performance indicators (KPIs), metrics, and targets that reflect the desired outcomes and value of the technical support. This can also help to monitor and evaluate the vendor's performance, identify gaps or issues, and implement corrective actions or improvements.
References:
* Service Level Agreement (SLA) Examples and Template
* What is an SLA? Best practices for service-level agreements
NEW QUESTION # 611
下列哪一項最能描述數位簽章?
- A. 它動態驗證資料的修改。
- B. 它是使用它的發送者獨有的。
- C. 它由接收器控制。
- D. 它具備授權能力。
Answer: B
NEW QUESTION # 612
當生物辨識存取設備安裝在設施入口處時,正在實施哪種類型的控制?
- A. 預防性
- B. 偵探
- C. 修正
- D. 威懾
Answer: A
Explanation:
A biometric access device installed at the entrance to a facility is a type of preventive control. Preventive controls are designed to deter or prevent undesirable events from occurring12. They are proactive measures that aim to inhibit incidents before they happen12. In this case, the biometric access device prevents unauthorized individuals from gaining access to the facility by requiring unique biological characteristics for authentication12.
References:
* Guide to Biometric Access Control & Door Lock Security - Avigilon
* Biometric access control: meaning, types and implementation - Smowl
NEW QUESTION # 613
下列何者最能減輕部署新生產系統相關的風險?
- A. 事件管理
- B. 發布管理
- C. 問題管理
- D. 設定管理
Answer: B
NEW QUESTION # 614
下列哪一項是實施資料遺失防護(DLP)工具最重要的成功因素?
- A. 以監聽模式運行該工具,以避免不必要的通訊阻塞。
- B. 在部署到生產環境之前,先在測試環境中測試該工具。
- C. 定義與設定策略及工具規則集,以監控敏感資料移動
- D. 將工具維護責任分配給對應的資料擁有者和利害關係人。
Answer: C
Explanation:
The success of a DLP implementation relies heavily on accurately defining and configuring the policies and rule sets. These configurations ensure that the DLP tool effectively monitors and controls the movement of sensitive data within the organization, thereby preventing data loss.
References
ISACA CISA Review Manual 27th Edition, Page 301-302 (Data Loss Prevention)
NEW QUESTION # 615
在駭客利用網域控制站中的一個眾所周知的漏洞發生安全漏洞後,IS 稽核員被要求進行控制評估。審核員的最佳行動方案是確定是否:
- A. 監控日誌。
- B. 補丁已更新。
- C. 正在監控網路流量。
- D. 網域控制器被分類為高可用性。
Answer: B
NEW QUESTION # 616
作為網路銀行的一部分,銀行擁有企業客戶帳戶(貨幣價值較高)和小型企業帳戶(貨幣價值較低)的組合。下列哪一項是資訊系統審計師對這些帳戶所使用的最佳抽樣方法?
- A. 每單位抽樣的分層平均值
- B. 每單位抽樣的未分層平均值
- C. 差異估計採樣
- D. 客戶單位抽樣
Answer: A
Explanation:
Stratified mean per unit sampling is a method of audit sampling that divides the population into subgroups (strata) based on some characteristic, such as monetary value, and then selects a sample from each stratum using mean per unit sampling. Mean per unit sampling is a method of audit sampling that estimates the total value of a population by multiplying the average value of the sample items by the number of items in the population. Stratified mean per unit sampling is suitable for populations that have a high variability or a skewed distribution, such as the bank accounts in this question. By stratifying the population, the auditor can reduce the sampling error and increase the precision of the estimate.
Difference estimation sampling (option A) is not the best sampling approach for these accounts. Difference estimation sampling is a method of audit sampling that estimates the total error or misstatement in a population by multiplying the average difference between the book value and the audited value of the sample items by the number of items in the population. Difference estimation sampling is suitable for populations that have a low variability and a symmetrical distribution, which is not the case for the bank accounts in this question.
Customer unit sampling (option C) is not a sampling approach, but a type of monetary unit sampling.
Monetary unit sampling is a method of audit sampling that selects sample items based on their monetary value, rather than their physical units. Customer unit sampling is a variation of monetary unit sampling that treats each customer account as a single unit, regardless of how many transactions or balances it contains. Customer unit sampling may be appropriate for testing existence or occurrence assertions, but not for estimating total values.
Unstratified mean per unit sampling (option D) is not the best sampling approach for these accounts.
Unstratified mean per unit sampling is a method of audit sampling that applies mean per unit sampling to the entire population without dividing it into subgroups. Unstratified mean per unit sampling may result in a larger sample size and a lower precision than stratified mean per unit sampling, especially for populations that have a high variability or a skewed distribution, such as the bank accounts in this question.
Therefore, option B is the correct answer.
References:
* Audit Sampling - AICPA
* Audit Sampling: Examples and Guidance To The Sampling Methods
* Audit Sampling | Audit | Financial Audit - Scribd
NEW QUESTION # 617
下列哪項管理決策會帶來最大的資料外洩風險?
- A. 未提供員工安全意識訓練。
- B. 安全策略在過去一年未更新
- C. 員工可以遠距辦公
- D. 桌上型電腦無需加密。
Answer: D
Explanation:
The management decision that presents the greatest risk associated with data leakage is not providing security awareness training to staff. This is because staff are often the weakest link in the information security chain, and they may unintentionally or maliciously leak sensitive data through various channels, such as email, social media, cloud storage, or removable media. Security awareness training is essential to educate staff on the importance of protecting data, the policies and procedures for handling data, and the best practices for preventing and reporting data leakage incidents. Not requiring desktops to be encrypted, allowing staff to work remotely, and not updating security policies in the past year are also management decisions that may increase the risk of data leakage, but they are not as significant as not providing security awareness training to staff. Encryption, remote work, and security policies are technical or administrative controls that can be implemented or enforced by management, but they cannot fully prevent or mitigate human errors or malicious actions by staff. References: CISA Review Manual (Digital Version), [ISACA Privacy Principles and Program Management Guide]
NEW QUESTION # 618
在選擇要納入 IT 審計計劃的項目時,下列哪一項為 IS 審計師提供了最有用的資訊?
- A. 專案業務案例
- B. 專案計劃
- C. 專案問題日誌
- D. 專案章程
Answer: A
Explanation:
A project business case is a document that describes the rationale and justification for initiating a project, based on its expected costs, benefits, risks, and feasibility. A project business case provides the most useful information to an IS auditor when selecting projects for inclusion in an IT audit plan, because it helps the IS auditor to:
Understand the purpose, scope, objectives, and deliverables of the project Assess the alignment of the project with the organization's strategy, vision, and goals Evaluate the value proposition and return on investment of the project Identify the key stakeholders, sponsors, and owners of the project Analyze the potential risks and issues associated with the project Compare and prioritize the project with other competing projects The other possible options are:
A). Project charter: A project charter is a document that formally authorizes and defines the high-level scope, roles, responsibilities, and authority of a project. A project charter provides some useful information to an IS auditor when selecting projects for inclusion in an IT audit plan, but it is not the most useful information. A project charter does not provide enough details about the costs, benefits, risks, and feasibility of the project, which are essential for evaluating its suitability for an IT audit plan.
B). Project plan: A project plan is a document that outlines the detailed scope, schedule, budget, resources, quality, and communication plans of a project. A project plan provides some useful information to an IS auditor when selecting projects for inclusion in an IT audit plan, but it is not the most useful information. A project plan does not provide enough information about the rationale, justification, value proposition, and alignment of the project with the organization's strategy and goals, which are important for assessing its relevance for an IT audit plan.
C). Project issue log: A project issue log is a document that records and tracks the issues that arise during a project's execution and how they are resolved. A project issue log provides some useful information to an IS auditor when selecting projects for inclusion in an IT audit plan, but it is not the most useful information. A project issue log does not provide enough information about the purpose, objectives, benefits, and feasibility of the project, which are critical for determining its priority for an IT audit plan.
NEW QUESTION # 619
下列哪一項有助於確保系統介面資料的完整性?
- A. 驗證檢查
- B. 使用者驗收測試 (IJAT)
- C. 審核日誌
- D. 系統介面測試
Answer: A
Explanation:
Validation checks are a type of data quality control that helps to ensure the integrity of data for a system interface. Validation checks verify that the data entered or transferred between systems is correct, consistent, and conforms to predefined rules or standards. Validation checks can prevent or detect errors, anomalies, or inconsistencies in the data that may affect the system's functionality, performance, or security.
Option C is correct because validation checks are a common and effective method of ensuring data integrity for a system interface. Validation checks can be performed at various stages of the data lifecycle, such as input, processing, output, or storage. Validation checks can also be applied to different types of data, such as data types, codes, ranges, formats, consistency, and uniqueness.
Option A is incorrect because system interface testing is a type of software testing that verifies the interaction between two separate systems or components of a system. System interface testing does not directly ensure the integrity of data for a system interface, but rather the functionality and reliability of the interface itself.
System interface testing may use validation checks as part of its test cases, but it is not the same as validation checks.
Option B is incorrect because user acceptance testing (UAT) is a type of software testing that evaluates whether the system meets the user's expectations and requirements. UAT does not directly ensure the integrity of data for a system interface, but rather the usability and acceptability of the system from the user's perspective. UAT may use validation checks as part of its test scenarios, but it is not the same as validation checks.
Option D is incorrect because audit logs are records of events and activities that occur within a system or network. Audit logs do not directly ensure the integrity of data for a system interface, but rather provide evidence and accountability for the system's operations and security. Audit logs may use validation checks as part of their analysis or reporting, but they are not the same as validation checks.
References:
CISA Online Review Course1, Module 5: Protection of Information Assets, Lesson 4: Data Quality Management, slide 5-6.
CISA Review Manual (Digital Version)2, Chapter 5: Protection of Information Assets, Section 5.3: Data Quality Management, p. 281-282.
CISA Review Manual (Print Version), Chapter 5: Protection of Information Assets, Section 5.3: Data Quality Management, p. 281-282.
CISA Questions, Answers & Explanations Database3, Question ID: QAE_CISA_722.
Data Validation - Overview, Types, Practical Examples4
Data Validity: The Best Practice for Your Business5
Validation - Data validation6
What is Data Validation? Types, Techniques, Tools7
NEW QUESTION # 620
資訊系統審計員正在審查一個基於網路的客戶關係管理(CRM)系統的安全性,該系統可透過網際網路直接供客戶存取。下列哪一項應引起審計員的注意?
- A. 此系統託管在由服務供應商管理的混合雲平台上。
- B. 此系統託管在企業網路的非軍事區 (DMZ) 內
- C. 此系統託管在外部第三方服務提供者的伺服器上。
- D. 此系統託管在企業網路內部網段中。
Answer: D
Explanation:
Hosting a web-based CRM system within the internal segment of a corporate network poses significant security risks. Direct access from the Internet to the internal network increases the attack surface and exposes internal systems to potential external threats. A more secure architecture would involve hosting such systems in a demilitarized zone (DMZ) or on a cloud platform with appropriate security controls to isolate the internal network from direct exposure.
NEW QUESTION # 621
在製定以風險為基礎的審計策略時,下列哪一項是資訊系統審計師最重要的關注領域?
- A. 最近的審核結果
- B. 業務流程
- C. 現有 IT 控制
- D. 關鍵業務應用程式
Answer: B
Explanation:
This is because the business processes are the core activities and functions that enable the organization to achieve its objectives and create value for its stakeholders. The business processes are also the sources and drivers of various risks that may affect the organization's performance, compliance, and reputation. Therefore, the IS auditor should focus on understanding, assessing, and prioritizing the business processes that are most critical, complex, or vulnerable to the organization's success, and align the audit objectives, scope, and resources accordingly12.
Critical business applications (A) are not the most important area of focus for an IS auditor when developing a risk-based audit strategy, but rather a specific aspect of the business processes that may require attention.
Critical business applications are the software systems that support the execution and automation of the business processes, such as enterprise resource planning (ERP), customer relationship management (CRM), or accounting systems. Critical business applications may pose significant risks to the organization if they are not reliable, secure, or efficient. Therefore, the IS auditor should consider the criticality, functionality, and dependency of the business applications when planning the audit, but not as the primary focus12.
Existing IT controls © are not the most important area of focus for an IS auditor when developing a risk- based audit strategy, but rather an outcome or output of the risk assessment process. Existing IT controls are the policies, procedures, practices, and technologies that are implemented to manage and mitigate the IT- related risks that may affect the organization's business processes and objectives. Existing IT controls may vary in their design, effectiveness, and maturity. Therefore, the IS auditor should evaluate and testthe existing IT controls as part of the audit execution and reporting process, but not as the main focus12.
Recent audit results (D) are not the most important area of focus for an IS auditor when developing a risk- based audit strategy, but rather an input or source of information for the risk assessment process. Recent audit results are the findings, recommendations, and opinions of previous audits that may provide insights or feedback on the organization's business processes, risks, and controls. Recent audit results may also indicate any changes or trends in the organization's risk profile or environment. Therefore, the IS auditor should review and consider the recent audit results as part of the audit planning and scoping process, but not as the main focus12.
NEW QUESTION # 622
下列哪一項對於 IS 審計員對文件管理系統的存取控制進行審查最有用?
- A. 由審計團隊領導和部門使用的身份驗證系統提供的信息
- B. 管理部門負責人提供的文件的政策和程序
- C. 系統產生的員工清單及其專案任務。角色和職責
- D. 與其他部門使用相同系統相關的先前審核報告
Answer: C
Explanation:
The answer B is correct because a system-generated list of staff and their project assignments, roles, and responsibilities is the most useful to an IS auditor performing a review of access controls for a document management system. A document management system is a software that helps organizations store, manage, and share documents electronically. Access controls are the mechanisms that restrict or allow access to the documents based on predefined criteria, such as user identity, role, or project. An IS auditor needs to verify that the access controls are properly configured and implemented to ensure the security, confidentiality, and integrity of the documents.
A system-generated list of staff and their project assignments, roles, and responsibilities can help the IS auditor to perform the following tasks:
* Identify the users who have access to the document management system and their level of access (e.g., read-only, edit, delete, etc.).
* Compare the actual access rights of the users with their expected or authorized access rights based on their roles and responsibilities.
* Detect any anomalies, discrepancies, or violations in the access rights of the users, such as excessive or unauthorized access, segregation of duties conflicts, or dormant or inactive accounts.
* Evaluate the effectiveness and efficiency of the access control policies and procedures, such as user provisioning, deprovisioning, authentication, authorization, auditing, etc.
The other options are not as useful as option B. Policies and procedures for managing documents provided by department heads (option A) are not reliable sources of information for an IS auditor because they may not reflect the actual practices or compliance status of the document management system. Previous audit reports related to other departments' use of the same system (option C) are not relevant for an IS auditor because they may not address the specific issues or risks associated with the current department's use of the document management system. Information provided by the audit team lead on the authentication systems used by the department (option D) is not sufficient for an IS auditor because authentication is only one aspect of access control and it does not provide information on the authorization or auditing of the document access.
References:
* Overview of document management in SharePoint
* Setting Up a Document Control System: 6 Basic Steps
* Access Control Management: Purpose, Types, Tools, & Benefits
* 9 Best Document Management Systems of 2023
NEW QUESTION # 623
當安全代碼審查作為部署程序的一部分進行時,實施了哪種類型的控制?
- A. 監控
- B. 修正
- C. 偵探
- D. 威懾
Answer: C
Explanation:
Comprehensive and Detailed Explanation:
Secure code reviews identify security flaws or vulnerabilities in code before deployment. This makes them detective controls, since they help find issues but do not directly prevent or correct them.
* Option A: Correct - they detect flaws.
* Option B: Corrective controls are applied after issues are detected.
* Option C: Monitoring is ongoing observation, not review-based.
* Option D: Deterrent controls discourage actions (e.g., policies, warnings), not detect issues.
# ISACA Reference: CISA Review Manual 27th Edition, Domain 3, section on software development controls and code review practices.
NEW QUESTION # 624
在調查電子商務應用程式的安全漏洞時,下列哪一項是最重要的考量因素?
- A. 監理鏈
- B. 分析證據的程序
- C. 向執法單位發出的通知
- D. 回應團隊的技能組合
Answer: A
NEW QUESTION # 625
資訊系統審計師進行後續審計時發現,被審計單位為解決審計發現的問題所採取的方法與上次審計中確認的約定方法不同。審計師下一步應該採取下列哪一項行動?
- A. 將方法的改變告知高階管理人員。
- B. 向審計委員會報告後續調查結果。
- C. 進行包含變更的風險分析。
- D. 評估所採取的補救措施是否適當。
Answer: D
Explanation:
The auditor's next course of action should be to evaluate the appropriateness of the remedial action taken by the auditee. The auditor should assess whether the alternative approach taken by the auditee is effective, efficient, and aligned with the audit objectives and recommendations. The auditor should also consider the impact of the change on the audit scope, criteria, and risk assessment. Conducting a risk analysis incorporating the change, reporting results of the follow-up to the audit committee, and informing senior management of the change in approach are possible subsequent actions that the auditor may take after evaluating the appropriateness of the remedial action taken. References: CISA Review Manual (Digital Version): Chapter 1 - Information Systems Auditing Process
NEW QUESTION # 626
資訊系統審計員發現,某組織在將一個面向互聯網的網頁投入生產環境部署之前,並未對其進行任何滲透測試。下列哪一項是審計員的最佳因應措施?
- A. 確認網頁部署後是否進行了漏洞掃描。
- B. 與 IT 和資訊安全團隊會面,確定測試未完成的原因。
- C. 報告控制缺陷,因為尚未進行滲透測試並記錄在案。
- D. 修改 IT 安全程序,要求在部署之前對內部開發的服務進行滲透測試。
Answer: B
Explanation:
Before flagging a deficiency, the auditor should first understand the context and reasons for the omission, such as alternative controls, risk acceptance decisions, or schedule constraints, by discussing the issue with IT and security. This information gathering informs whether a formal finding is warranted and what corrective actions are most appropriate.
NEW QUESTION # 627
......
100% Real & Accurate CISA-CN Questions and Answers with Free and Fast Updates: https://www.dumpexam.com/CISA-CN-valid-torrent.html
Get Unlimited Access to CISA-CN Certification Exam Cert Guide: https://drive.google.com/open?id=1M63Cd9fe4LFACLcuzjfjOrYxdwoSpAOY
