CISA-JPN 試験問題 21
次のどれが構成およびリリース管理システムのコア機能ですか?
正解: D
CISA-JPN 試験問題 22
主要業績評価指標 (KPI) を実装する前に、まず最初に実行する必要があるのは次のどれですか?
正解: B
The first thing that should be performed before key performance indicators (KPIs) can be implemented is the identification of organizational goals. This is because KPIs are measurable values that demonstrate how effectively an organization is achieving its key business objectives4. Therefore, it is necessary that the organization defines its goals clearly and aligns them with its vision, mission, and strategy. By identifying its goals, the organization can then determine what KPIs are relevant and meaningful to measure its progress and performance . References: 4: CISA Review Manual (Digital Version), Chapter 2: Governance and Management of IT, Section 2.3: Benefits Realization, page 77 : CISA Online Review Course, Module 2:
Governance and Management of IT, Lesson 2.3: Benefits Realization : ISACA Journal Volume 1, 2020, Article: How to Measure Anything in IT Governance
Governance and Management of IT, Lesson 2.3: Benefits Realization : ISACA Journal Volume 1, 2020, Article: How to Measure Anything in IT Governance
CISA-JPN 試験問題 23
監査により、ビジネス ユニットが IP サポートなしでクラウドベースのアプリケーションを購入したことが判明しました。この状況に関連する最大のリスクは何ですか?
正解: B
The greatest risk associated with the situation of business units purchasing cloud-based applications without IT support is that the applications may not reasonably protect data. Cloud-based applications are software applications that run on the internet, rather than on a local device or network. Cloud-based applications offer many benefits, such as scalability, accessibility, and cost-effectiveness, but they also pose many challenges and risks, especially for data security1.
Data security is the process of protecting data from unauthorized access, use, modification, disclosure, or destruction. Data security is essential for ensuring the confidentiality, integrity, and availability of data, as well as complying with legal and regulatory requirements. Data security is especially important for cloud- based applications, as data are stored and processed on remote servers that are owned and managed by third- party cloud service providers (CSPs)2.
When business units purchase cloud-based applications without IT support, they may not be aware of or follow the best practices and standards for data security in the cloud. They may not perform adequate risk assessments, vendor evaluations, contract reviews, or audits to ensure that the CSPs and the applications meet the organization's data security policies and expectations. They may not implement appropriate data encryption, backup, recovery, or disposal methods to protect the data in transit and at rest. They may not monitor or control the access and usage of the data by internal or external users. They may not report or respond to any data breaches or incidents that may occur3.
These actions or inactions may expose the organization's data to various threats and vulnerabilities in the cloud, such as cyberattacks, human errors, malicious insiders, misconfigurations, or legal disputes. These threats and vulnerabilities may result in data loss, leakage, corruption, or compromise, which may have serious consequences for the organization's reputation, operations, performance, compliance, and liability4.
Therefore, it is essential that business units consult and collaborate with IT support before purchasing any cloud-based applications, and follow the organization's guidelines and procedures for cloud security. IT support can help business units to select and use cloud-based applications that are suitable and secure for their needs and objectives.
References:
* Top 5 Risks With Cloud Software and How to Mitigate Them4
* Mitigate risks and secure your cloud-native applications3
* 12 Risks, Threats & Vulnerabilities in Moving to the Cloud2
* Best Practices to Manage Risks in the Cloud1
Data security is the process of protecting data from unauthorized access, use, modification, disclosure, or destruction. Data security is essential for ensuring the confidentiality, integrity, and availability of data, as well as complying with legal and regulatory requirements. Data security is especially important for cloud- based applications, as data are stored and processed on remote servers that are owned and managed by third- party cloud service providers (CSPs)2.
When business units purchase cloud-based applications without IT support, they may not be aware of or follow the best practices and standards for data security in the cloud. They may not perform adequate risk assessments, vendor evaluations, contract reviews, or audits to ensure that the CSPs and the applications meet the organization's data security policies and expectations. They may not implement appropriate data encryption, backup, recovery, or disposal methods to protect the data in transit and at rest. They may not monitor or control the access and usage of the data by internal or external users. They may not report or respond to any data breaches or incidents that may occur3.
These actions or inactions may expose the organization's data to various threats and vulnerabilities in the cloud, such as cyberattacks, human errors, malicious insiders, misconfigurations, or legal disputes. These threats and vulnerabilities may result in data loss, leakage, corruption, or compromise, which may have serious consequences for the organization's reputation, operations, performance, compliance, and liability4.
Therefore, it is essential that business units consult and collaborate with IT support before purchasing any cloud-based applications, and follow the organization's guidelines and procedures for cloud security. IT support can help business units to select and use cloud-based applications that are suitable and secure for their needs and objectives.
References:
* Top 5 Risks With Cloud Software and How to Mitigate Them4
* Mitigate risks and secure your cloud-native applications3
* 12 Risks, Threats & Vulnerabilities in Moving to the Cloud2
* Best Practices to Manage Risks in the Cloud1
CISA-JPN 試験問題 24
エンタープライズ IT のガバナンスを実装する際に IS 監査を導入することの最も重要な利点は次のどれですか?
正解: D
The most important benefit of involving IS audit when implementing governance of enterprise IT is providing independent and objective feedback to facilitate improvement of IT processes.Governance of enterprise IT is the process of ensuring that IT supports the organization's strategy, goals, and objectives in an effective, efficient, ethical, and compliant manner. IS audit can provide value to governance of enterprise IT by assessing the alignment of IT with business needs, evaluating the performance and value delivery of IT, identifying risks and issues related to IT, recommending corrective actions and best practices, and monitoring the implementation and effectiveness of IT governance activities. IS audit can also provide assurance that IT governance processes are designed and operating in accordance with relevant standards, frameworks, laws, regulations, and contractual obligations. Identifying relevant roles for an enterprise IT governance framework is a benefit of involving IS audit when implementing governance of enterprise IT, but not the most important one. IS audit can help define and clarify the roles and responsibilities of various stakeholders involved in IT governance, such as board members, senior management, business units, IT function, external parties, etc. IS audit can also help ensure that these roles are aligned with the organization's strategy, goals, and objectives, and that they have adequate authority, accountability, communication, and reporting mechanisms. However, this benefit is more related to the design phase of IT governance implementation than to the ongoing monitoring and improvement phase. Making decisions regarding risk response and monitoring of residual risk is a benefit of involving IS audit when implementing governance of enterprise IT, but not the most important one. IS audit can help identify and assess the risks associated with IT activities and processes, such as strategic risks, operational risks, compliance risks, security risks, etc. IS audit can also help evaluate the effectiveness of risk management practices and controls implemented by management to mitigate or reduce these risks. However, this benefit is more related to the assurance function of IS audit than to its advisory function. Verifying that legal, regulatory, and contractual requirements are being met is a benefit of involving IS audit when implementing governance of enterprise IT, but not the most important one. IS audit can help verify that IT activities and processes comply with applicable laws, regulations, and contractual obligations, such as data protection laws, privacy laws, cybersecurity laws, industry standards, service level agreements, etc. IS audit can also help identify and report any instances of noncompliance or violations that could result in legal or reputational consequences for the organization. However, this benefit is more related to the assurance function of IS audit than to its advisory function. References: ISACA CISA Review Manual 27th Edition, page 283
CISA-JPN 試験問題 25
ストレージスペースが限られている場合、次のバックアップ方法のうちどれが最も適していますか?
正解: A
Comprehensive and Detailed Step-by-Step Explanation:
When storage space is limited,incremental backupsare the most efficient because they store only the changes made since the last backup, reducing storage requirements.
* Option A (Correct):Incremental backupsonly store data that has changed since the last backup, significantly reducing storage usage while maintaining a historical record of changes.
* Option B (Incorrect):Mirror backupscreate an exact copy of the entire system, consuming significant storage space andnot retaining historical versions.
* Option C (Incorrect):Full backupscapture everything and require large amounts of storage, making them impractical for space-constrained environments.
* Option D (Incorrect):Annual backupsrefer to frequency rather than method. They do not inherently optimize storage usage.
Reference:ISACA CISA Review Manual -Domain 4: Information Systems Operations and Business Resilience- Covers backup strategies, storage management, and disaster recovery.
When storage space is limited,incremental backupsare the most efficient because they store only the changes made since the last backup, reducing storage requirements.
* Option A (Correct):Incremental backupsonly store data that has changed since the last backup, significantly reducing storage usage while maintaining a historical record of changes.
* Option B (Incorrect):Mirror backupscreate an exact copy of the entire system, consuming significant storage space andnot retaining historical versions.
* Option C (Incorrect):Full backupscapture everything and require large amounts of storage, making them impractical for space-constrained environments.
* Option D (Incorrect):Annual backupsrefer to frequency rather than method. They do not inherently optimize storage usage.
Reference:ISACA CISA Review Manual -Domain 4: Information Systems Operations and Business Resilience- Covers backup strategies, storage management, and disaster recovery.
- 他のバージョン
- 3032ISACA.CISA-JPN.v2025-06-30.q593
- 1001ISACA.CISA-JPN.v2025-05-16.q572
- 2110ISACA.CISA-JPN.v2023-04-10.q297
- 1982ISACA.CISA-JPN.v2023-04-03.q306
- 2119ISACA.CISA-JPN.v2023-03-20.q319
- 2170ISACA.CISA-JPN.v2022-08-01.q273
- 2234ISACA.CISA-JPN.v2022-05-28.q253
- 最新アップロード
- 102PaloAltoNetworks.SecOps-Generalist.v2026-06-23.q81
- 105NetworkAppliance.NS0-005.v2026-06-23.q110
- 104Google.Generative-AI-Leader.v2026-06-23.q31
- 104Google.Google-Workspace-Administrator.v2026-06-23.q111
- 159Databricks.Databricks-Certified-Professional-Data-Engineer.v2026-06-22.q208
- 147Oracle.1z0-1054-25.v2026-06-22.q64
- 132Fortinet.NSE5_FSW_AD-7.6.v2026-06-22.q41
- 123Salesforce.MC-202.v2026-06-22.q57
- 125Nutanix.NCA-6.10.v2026-06-22.q43
- 142Workday.Workday-Pro-Talent-and-Performance.v2026-06-20.q18
