
最高で有効なCISA日本語試験問題と解答PDF CISA日本語問題集(最近更新された1151問あります)
試験問題解答はCISA日本語学習ガイド
質問 # 411
IT監査人がITセキュリティポリシーを検討するときに見つけることを期待すべきものは次のうちどれですか?
- A. 情報資産の目録
- B. システムのリスクベースの分類
- C. 会社の資産を保護するための割り当てられた責任
- D. ウイルス対策の実装戦略
正解:B
質問 # 412
組織の運用チームが IS セキュリティ攻撃を報告しました。セキュリティ インシデント対応チームの最初のステップは次のうちどれですか?
- A. 結果を管理者に報告する
- B. 学んだ教訓を文書化する
- C. 損傷評価を実行します。
- D. 是正措置のためのリソースの優先順位付け
正解:C
解説:
説明
IS セキュリティ攻撃が報告された後のセキュリティ インシデント対応チームの最初のステップは、被害評価を実行することです。これには、インシデントの範囲、影響、根本原因の特定に加え、さらなる分析と調査のための証拠の収集と保存が含まれます。経営陣への結果の報告、学んだ教訓の文書化、是正措置のためのリソースの優先順位付けは重要な手順ですが、これらは損害評価が完了した後に行う必要があります。参考文献: CISA レビューマニュアル (デジタル版)、第 6 章、セクション 6.31
質問 # 413
販売時点管理 (POS) システムと総勘定元帳の間のインターフェイスが販売データを完全かつ正確に転送していることを情報システム監査人が保証するのは次のうちどれですか?
- A. 顧客の売上レシートの電子コピーが保持されます。
- B. 毎月の銀行取引明細書は例外なく照合されます。
- C. POS インターフェイスを介して転送されるデータは暗号化されます。
- D. 毎晩のバッチ処理がリアルタイム処理に置き換えられました。
正解:A
解説:
Electronic copies of customer sales receipts are records that show the details of each sales transaction, such as the date, time, amount, item, and payment method12. Electronic copies of customer sales receipts can provide an IS auditor assurance that the interface between a point-of-sale (POS) system and the general ledger is transferring sales data completely and accurately, because:
Electronic copies of customer sales receipts can be used to verify and reconcile the sales data that is captured by the POS system and posted to the general ledger12.
Electronic copies of customer sales receipts can be used to detect and correct any errors, discrepancies, or frauds that may occur during the data transfer process12.
Electronic copies of customer sales receipts can be used to comply with accounting standards, tax regulations, and audit requirements12.
質問 # 414
情報情報監査人が最終報告書を提出する前に経営陣と所見について話し合うべき主な理由は次のうちどれですか?
- A. 観察に関連するビジネス リスクを特定します。
- B. 監査観察結果を検証します_
- C. 管理を強化して管理を支援します。
- D. 提案された是正措置の方針を記録します。
正解:B
解説:
Explanation
The primary reason an IS auditor should discuss observations with management before delivering a final report is A. Validate the audit observations. This is because discussing the observations with management can help the auditor to ensure that the findings are accurate, complete, and supported by sufficient evidence1. It can also help the auditor to obtain management's perspective and feedback on the issues and risks identified, and to avoid any misunderstandings or surprises when the final report is issued2.
質問 # 415
小売会社の倉庫従業員は、在庫システムに破損または紛失した在庫品目の調整を入力することにより、在庫品目の盗難を隠すことができました。小売環境でこのタイプの不正を最もよく防止できたのはどのコントロールですか?
- A. 調整トランザクションの統計的サンプリング
- B. トランザクションの入力に対する個別の承認
- C. 失われたストックラインの予定外の監査
- D. 在庫トランザクションの有効性の編集チェック
正解:B
解説:
Explanation
Separate authorization for input of transactions. This control would have best prevented this type of fraud in a retail environment by ensuring that the warehouse employee who handles the inventory items does not have the authority to enter adjustments to the inventory system. This would create a segregation of duties that would reduce the risk of collusion and concealment of theft.
The other options are not as effective as option A in preventing this type of fraud. Option B, statistical sampling of adjustment transactions, is a detective control that may help identify fraudulent transactions after they have occurred, but it does not prevent them from happening in the first place. Option C, unscheduled audits of lost stock lines, is also a detective control that may reveal discrepancies between the physical and recorded inventory, but it does not address the root cause of the fraud. Option D, an edit check for the validity of the inventory transaction, is a preventive control that may help verify the accuracy and completeness of the transaction data, but it does not prevent unauthorized or fraudulent adjustments.
References:
ISACA, CISA Review Manual, 27th Edition, 2019
ISACA, CISA Review Questions, Answers & Explanations Database - 12 Month Subscription Different Types of Inventory Fraud and How to Prevent Them1
6 Ways to Prevent Inventory Fraud in Your Business2
質問 # 416
Management has requested a post-implementation review of a newly implemented purchasing package to determine to what extent business requirements are being met. Which of the following is MOST likely to be assessed?
- A. Results of line processing
- B. Implementation methodology
- C. Purchasing guidelines and policies
- D. Test results
正解:A
解説:
Explanation
A post-implementation review is a process of evaluating the outcome and benefits of a project or a system after it has been implemented. The main purpose of a post-implementation review is to determine to what extent the business requirements are being met by the new system. Therefore, the most likely aspect to be assessed is the results of line processing, which refers to the actual performance and functionality of the system in the operational environment.
質問 # 417
ビジネス アプリケーションのデータと構成ファイルの詳細なテストに使用するのに最も適しているのは次のうちどれですか?
- A. 監査分析ツール
- B. バージョン管理ソフトウェア
- C. 監査フック
- D. ユーティリティソフトウェア
正解:A
解説:
説明
ビジネス アプリケーションのデータと構成ファイルの詳細なテストに最適なツールは、監査分析ツールです。監査分析ツールは、監査人が大量のデータを分析し、監査目的に関連する異常、傾向、パターンを特定するのに役立つソフトウェアです。監査分析ツールは、監査証拠を提供し、監査人の専門的な判断と結論をサポートすることもできます。
監査分析ツールを使用する利点は次のとおりです。
手動のテストと手順の実行に必要な時間と労力を削減することで、監査の効率と有効性を向上させることができます。
データ分析とテストの対象範囲と精度を高めることで、監査の品質と信頼性を向上させることができます。
これにより、監査人は、従来の方法では不可能または実現不可能な、より複雑で洗練されたテストや手順を実行できるようになります。
これは、監査人が従来の方法では明らかではなかった、または検出できなかった新しい洞察やリスクを発見するのに役立ちます。
監査分析ツールの例は次のとおりです。
IDEA: 監査人がさまざまなソースや形式からデータをインポート、分析、視覚化できるデータ分析ソフトウェア。また、サンプリング、階層化、ギャップ分析、重複検出、ベンフォードの法則、回帰分析などの機能も提供します。1 ACL: 監査人がさまざまなソースや形式のデータにアクセスし、分析し、レポートするのに役立つデータ分析ソフトウェアです。また、サンプリング、階層化、ギャップ分析、重複検出、ベンフォードの法則、回帰分析、スクリプト作成などの機能も提供します。2 TeamMate Analytics: Microsoft Excel と統合され、監査人にさまざまなツールと機能を提供するデータ分析ソフトウェアです。データの分析とテスト。また、サンプリング、層別化、ギャップ分析、重複検出、ベンフォードの法則、回帰分析、スクリプト作成などの機能も提供します。3
質問 # 418
IS監査人は、過去2年間にフィッシング攻撃が増加したにもかかわらず、成功率が大幅に低下していることを発見しました。この減少の最も可能性の高い理由は次のうちどれですか?
- A. インシデントレスポンダー向けの強化されたトレーニング
- B. 侵入検知システム(IDS)の実装
- C. セキュリティ意識向上プログラムの実施
- D. インシデント対応計画の作成
正解:D
質問 # 419
社内で開発された新しく変更されたITアプリケーションの実装後のレビュー中に、情報システム監査人が評価するのに最も重要なのは次のうちどれですか?
- A. 変更のロールバック計画
- B. リソース管理計画
- C. 実装されたコントロールの十分性
- D. エンドユーザーマニュアルに必要な更新
正解:A
質問 # 420
電子商取引アプリケーション システムの編集ルーチンの有効性を評価する上で、最も決定的な監査手順は次のうちどれですか?
- A. ソースコードのレビュー
- B. テスト トランザクションの使用
- C. 知識豊富なユーザーへのインタビュー
- D. プログラム ドキュメントのレビュー
正解:B
質問 # 421
フォローアップ監査中に、情報システム監査人は、最初の監査以降に一部の主要な管理者が交代したことを知り、現在の管理者は以前に受け入れられた推奨事項を実装しないことを決定しました。監査人の最善の行動方針は何ですか?
- A. 監査マネージャーに通知します。
- B. コントロールを再テストします。
- C. 監査結果を閉じます。
- D. 監査委員会の委員長に通知します。
正解:A
解説:
Explanation
The auditor's best course of action in this situation is to notify the audit manager. The audit manager is responsible for overseeing the audit follow-up process and ensuring that audit issues are resolved in a timely and satisfactory manner. The audit manager can then decide whether to escalate the matter to higher authorities, such as the chair of the audit committee, or to accept management's decision and close the audit finding. The other options are not appropriate for the auditor to do without consulting with the audit manager first. Notifying the chair of the audit committee is a drastic step that may undermine the relationship between the auditor and management, and it should be done only after exhausting other means of resolving the issue.
Retesting the control is not necessary, as management has already decided not to implement the recommendations. Closing the audit finding is premature, as management's decision may not be aligned with the audit objectives or risk appetite. References: CISA Review Manual (Digital Version), Chapter 2, Section
2.4
質問 # 422
重要なWebアプリケーションのパフォーマンスを評価するときに確認することが最も重要なのは次のうちどれですか?
- A. クラウドでのアプリケーションパフォーマンス監視の戦略
- B. 報告の役割と責任
- C. ビジネス定義のアプリケーション応答時間
- D. 顧客満足度調査からのフィードバック
正解:D
質問 # 423
外国に拠点を置く支店の決済サービスの監査中に、世界規模の大手銀行の監査チームは、異常な支払いを特定するためにデータ分析技術を使用する機会を特定しました。チームの最も重要な行動方針は次のうちどれですか?
- A. 監査対象支店の IT チームとデータ抽出および共有戦略に同意します。
- B. チーム監査憲章は拠点を置く国を対象としているため、支店にデータを要求します。
- C. 異なる管轄区域からのデータを要求する手順については、法務部門に問い合わせてください。
- D. 監査対象支店の関係者と分析戦略のウォークスルーを実施し、同意を獲得します。
正解:C
解説:
Explanation
The audit team's most important course of action is to consult the legal department to understand the procedure for requesting data from a different jurisdiction, as this will ensure that the data analytics techniques are compliant with the applicable laws and regulations of both countries12. Requesting data from a foreign branch may involve legal risks such as data privacy, data sovereignty, and data protection34, and the audit team should seek legal guidance before proceeding with the data extraction and analysis.
References
1: Data Analytics and Auditing Standards 2: Data Analytics and the Audit Process 3: Data Privacy and Data Protection: US Law and Legislation 4: Data Sovereignty: What It Is and Why It Matters
質問 # 424
侵入検知システム(IDS)によって最もよく検出される攻撃は次のうちどれですか?
- A. システムスキャン
- B. スパム。
- C. 論理爆弾
- D. なりすまし
正解:D
質問 # 425
IT 戦略が組織のビジョンと使命をサポートしているかどうかを評価する準備をする際に、情報システム監査人にとって最良のアプローチは次のうちどれですか?
- A. 組織の主要業績評価指標 (KPls) を確認します。
- B. 投資収益率 (ROl) に関する戦略的プロジェクトをレビューします。
- C. ビジネス目標を理解するために上級管理者と会う
- D. 組織の成熟度を測るために他の部門からのフィードバックを求めます。
正解:C
解説:
説明
情報システム監査人が IT 戦略が組織のビジョンと使命をサポートしているかどうかを評価するための最良のアプローチは、経営陣と会い、ビジネス目標とそれを IT がどのように実現できるかを理解することです。これは、情報情報監査人が IT とビジネス戦略の整合性と統合を評価し、ギャップや改善の機会を特定するのに役立ちます。ROI、KPI、または他の部門からのフィードバックを検討すると、何らかの洞察が得られる可能性がありますが、IT 戦略を評価するには十分ではありません。参考資料: IS 監査および保証基準、セクション「基準 1201: 契約計画」
質問 # 426
......
認定問題集でIsaca Certification CISA日本語ガイド100%有効な:https://www.goshiken.com/ISACA/CISA-JPN-mondaishu.html