CISA-JPN 試験問題 321
情報情報監査人は、経営陣が新しいシステムを運用モードで使用する前にテストすることを推奨しました。テスト計画を開発する際の管理者にとって最善のアプローチは、次のような処理パラメータを使用することです。
正解: D
The best approach for management in developing a test plan is to use processing parameters that are simulated by production entities and customers. This is because using realistic data and scenarios can help to evaluate the functionality, performance, reliability, and security of the new system under actual operating conditions and expectations. Using processing parameters that are randomly selected by a test generator, provided by the vendor of the application, or randomly selected by the user may not be sufficient or representative of the production environment and may not reveal all the potential issues or defects of the new system. References: [ISACA CISA Review Manual 27th Edition], page 266.
CISA-JPN 試験問題 322
IS 監査人は、パッチ ログから、対象範囲内の一部のシステムが定期的なパッチ適用スケジュールに準拠していないことを発見しました。監査人は次に何をすべきでしょうか?
正解: C
The IS auditor should review the organization's patch management policy to determine the expected frequency and scope of patching, as well as the roles and responsibilities of the patch management team. This will help the auditor assess the severity and impact of the non-compliance, and identify the root cause and possible remediation actions12.
References
1: How to Create a Patch Management Policy: Complete Guide 2: Free Patch Management Policy Template (+Examples)
References
1: How to Create a Patch Management Policy: Complete Guide 2: Free Patch Management Policy Template (+Examples)
CISA-JPN 試験問題 323
監査対象者が、高リスクの発見事項に対する是正措置計画に予想よりも時間がかかることを示した場合、情報システム監査人が取るべき最善の行動はどれですか?
正解: C
CISA-JPN 試験問題 324
IT とビジネス目標を整合させるための IT フレームワークを実装することで、最も効果的に対処できる懸念事項は次のどれですか。
正解: D
An IT framework for alignment between IT and business objectives is a set of principles, guidelines, and practices that help an organization to ensure that its IT investments support its strategic goals, deliver value, manage risks, and optimize resources. One of the benefits of implementing such a framework is that it enables an effective IT portfolio management, which is the process of selecting, prioritizing, monitoring, and evaluating the IT projects and services that comprise the IT portfolio. An IT portfolio is a collection of IT assets, such as applications, infrastructure, data, and capabilities, that are aligned with the business needs and objectives. An IT portfolio management helps an organization to achieve the following outcomes:
* Align the IT portfolio with the business strategy and vision
* Balance the IT portfolio among different types of investments, such as innovation, growth, maintenance, and compliance
* Optimize the IT portfolio performance, value, and risk
* Enhance the IT portfolio decision-making and governance
* Improve the IT portfolio communication and transparency
Therefore, an inadequate IT portfolio management is a major concern that can be addressed by implementing an IT framework for alignment between IT and business objectives. An inadequate IT portfolio management can result in the following issues:
* Misalignment of the IT portfolio with the business needs and expectations
* Imbalance of the IT portfolio among competing demands and priorities
* Suboptimal use of the IT resources and capabilities
* Lack of visibility and accountability of the IT portfolio outcomes and impacts
* Poor communication and collaboration among the IT portfolio stakeholders The other possible options are:
* Inaccurate business impact analysis (BIA): A BIA is a process of identifying and assessing the potential effects of a disruption or disaster on the critical business functions and processes. A BIA helps an organization to determine the recovery priorities, objectives, and strategies for its business continuity plan. A BIA is not directly related to an IT framework for alignment between IT and business objectives, although it may use some inputs from the IT portfolio management. Therefore, an inaccurate BIA is not a concern that can be effectively addressed by implementing an IT framework for alignment between IT and business objectives.
* Inadequate IT change management practices: IT change management is a process of controlling and managing the changes to the IT environment, such as hardware, software, configuration, or documentation. IT change management helps an organization to minimize the risks and disruptions caused by the changes, ensure the quality and consistency of the changes, and align the changes with the business requirements. IT change management is not directly related to an IT framework for alignment between IT and business objectives, although it may support some aspects of the IT portfolio management. Therefore, inadequate IT change management practices are not a concern that can be effectively addressed by implementing an IT framework for alignment between IT and business objectives.
* Lack of a benchmark analysis: A benchmark analysis is a process of comparing an organization's performance, processes, or practices with those of other organizations or industry standards. A benchmark analysis helps an organization to identify its strengths and weaknesses, set realistic goals and targets, and implement best practices for improvement. A benchmark analysis is not directly related to an IT framework for alignment between IT and business objectives, although it may provide some insights for the IT portfolio management. Therefore, lack of a benchmark analysis is not a concern that can be effectively addressed by implementing an IT framework for alignment between IT and business objectives. References: 1: What is Portfolio Management? | Smartsheet 2: What Is Portfolio Management? - Definition from Techopedia 3: What Is Project Portfolio Management (PPM)? | ProjectManager.com 4: What Is Business Impact Analysis? | Smartsheet 5: What Is Change Management? - Definition from Techopedia 6: Benchmarking - Wikipedia
* Align the IT portfolio with the business strategy and vision
* Balance the IT portfolio among different types of investments, such as innovation, growth, maintenance, and compliance
* Optimize the IT portfolio performance, value, and risk
* Enhance the IT portfolio decision-making and governance
* Improve the IT portfolio communication and transparency
Therefore, an inadequate IT portfolio management is a major concern that can be addressed by implementing an IT framework for alignment between IT and business objectives. An inadequate IT portfolio management can result in the following issues:
* Misalignment of the IT portfolio with the business needs and expectations
* Imbalance of the IT portfolio among competing demands and priorities
* Suboptimal use of the IT resources and capabilities
* Lack of visibility and accountability of the IT portfolio outcomes and impacts
* Poor communication and collaboration among the IT portfolio stakeholders The other possible options are:
* Inaccurate business impact analysis (BIA): A BIA is a process of identifying and assessing the potential effects of a disruption or disaster on the critical business functions and processes. A BIA helps an organization to determine the recovery priorities, objectives, and strategies for its business continuity plan. A BIA is not directly related to an IT framework for alignment between IT and business objectives, although it may use some inputs from the IT portfolio management. Therefore, an inaccurate BIA is not a concern that can be effectively addressed by implementing an IT framework for alignment between IT and business objectives.
* Inadequate IT change management practices: IT change management is a process of controlling and managing the changes to the IT environment, such as hardware, software, configuration, or documentation. IT change management helps an organization to minimize the risks and disruptions caused by the changes, ensure the quality and consistency of the changes, and align the changes with the business requirements. IT change management is not directly related to an IT framework for alignment between IT and business objectives, although it may support some aspects of the IT portfolio management. Therefore, inadequate IT change management practices are not a concern that can be effectively addressed by implementing an IT framework for alignment between IT and business objectives.
* Lack of a benchmark analysis: A benchmark analysis is a process of comparing an organization's performance, processes, or practices with those of other organizations or industry standards. A benchmark analysis helps an organization to identify its strengths and weaknesses, set realistic goals and targets, and implement best practices for improvement. A benchmark analysis is not directly related to an IT framework for alignment between IT and business objectives, although it may provide some insights for the IT portfolio management. Therefore, lack of a benchmark analysis is not a concern that can be effectively addressed by implementing an IT framework for alignment between IT and business objectives. References: 1: What is Portfolio Management? | Smartsheet 2: What Is Portfolio Management? - Definition from Techopedia 3: What Is Project Portfolio Management (PPM)? | ProjectManager.com 4: What Is Business Impact Analysis? | Smartsheet 5: What Is Change Management? - Definition from Techopedia 6: Benchmarking - Wikipedia
CISA-JPN 試験問題 325
データセンター内の物理的な情報資産を保護するために最も重要な前提条件は次のどれですか?
正解: B
The most important prerequisite for the protection of physical information assets in a data center is a complete and accurate list of information assets that have been deployed. Information assets are any data, devices, systems, or software that have value for the organization and need to be protected from unauthorized access, use, disclosure, modification, or destruction4. A data center is a facility that houses various infor mation assets such as servers, storage devices, network equipment, etc., that support the organization's IT operations and services5. A complete and accurate list of information assets that have been deployed in a data center can help to identify and classify the assets based on their importance, sensitivity, or criticality for the organization. This can help to determine the appropriate level of protection and security measures that need to be applied to each asset. A complete and accurate list of information assets can also help to track and monitor the location, status, ownership, usage, configuration, maintenance, etc., of each asset. This can help to prevent or detect any unauthorized or inappropriate changes or movements of assets that may compromise their security or integrity. Segregation of duties between staff ordering and staff receiving information assets, availability and testing of onsite backup generators, and knowledge of the IT staff regarding data protection requirements are also important prerequisites for the protection of physical information assets in a data center, but not as important as a complete and accurate list of information assets that have been deployed.
These factors are more related to the implementation and maintenance of security controls and procedures that depend on having a complete and accurate list of information assets as a starting point. References:
ISACA CISA Review Manual 27th Edition, page 308
These factors are more related to the implementation and maintenance of security controls and procedures that depend on having a complete and accurate list of information assets as a starting point. References:
ISACA CISA Review Manual 27th Edition, page 308
- 他のバージョン
- 1179ISACA.CISA-JPN.v2025-06-05.q596
- 1112ISACA.CISA-JPN.v2025-05-16.q572
- 2172ISACA.CISA-JPN.v2023-04-10.q297
- 2047ISACA.CISA-JPN.v2023-04-03.q306
- 2185ISACA.CISA-JPN.v2023-03-20.q319
- 2226ISACA.CISA-JPN.v2022-08-01.q273
- 2286ISACA.CISA-JPN.v2022-05-28.q253
- 最新アップロード
- 141NCLEX.NCLEX-RN.v2026-06-27.q583
- 113Juniper.JN0-232.v2026-06-27.q23
- 111BICSI.INSTC_V8.v2026-06-27.q59
- 152Cisco.300-710.v2026-06-26.q474
- 142ISACA.CISM.v2026-06-26.q913
- 126Salesforce.Integration-Architect.v2026-06-26.q116
- 154Cisco.350-401.v2026-06-26.q363
- 137Salesforce.MC-101.v2026-06-26.q44
- 130CheckPoint.156-315.81.v2026-06-26.q678
- 196Peoplecert.MSP-Practitioner.v2026-06-24.q75
