試験CISA-JPN トピック2 問題107 スレッド
ISACA CISA-JPNのリアル試験問題集
問題 #: 107
トピック #: 2
問題 #: 107
トピック #: 2
スプレッドシートからコア財務システムへのデータ入力を確認する際に、監査人が最も懸念するのは次のどれでしょうか?
おすすめの解答:A 解答を投票する
The auditor's greatest concern when reviewing data inputs from spreadsheets into the core finance system would be undocumented code that formats data and transmits directly to the database. This is because undocumented code can introduce errors, inconsistencies, and security risks in the data processing and reporting. Undocumented code can also make it difficult to verify the accuracy, completeness, and validity of the data inputs and outputs, as well as to trace the source and destination of the data. Undocumented code can also violate the principles of segregation of duties, as the same person who creates the code may also have access to the data and the database.
The other options are not as concerning as undocumented code, although they may also pose some risks. A lack of complete inventory of spreadsheets and inconsistent file naming may make it challenging to identify and locate the relevant spreadsheets, but they do not directly affect the quality or integrity of the data inputs.
The department data protection policy not being reviewed or updated for two years may indicate a lack of awareness or compliance with the current data protection regulations, but it does not necessarily imply that the data inputs are compromised or inaccurate. Spreadsheets being accessible by all members of the finance department may increase the risk of unauthorized or accidental changes to the data, but it can be mitigated by implementing access controls, password protection, and audit trails.
References:
ISACA, CISA Review Manual, 27th Edition, 2019, p. 2261
Five Common Spreadsheet Risks and Ways to Control Them2
GREATEST Concerns When Reviewing Data Inputs from Spreadsheets3
The other options are not as concerning as undocumented code, although they may also pose some risks. A lack of complete inventory of spreadsheets and inconsistent file naming may make it challenging to identify and locate the relevant spreadsheets, but they do not directly affect the quality or integrity of the data inputs.
The department data protection policy not being reviewed or updated for two years may indicate a lack of awareness or compliance with the current data protection regulations, but it does not necessarily imply that the data inputs are compromised or inaccurate. Spreadsheets being accessible by all members of the finance department may increase the risk of unauthorized or accidental changes to the data, but it can be mitigated by implementing access controls, password protection, and audit trails.
References:
ISACA, CISA Review Manual, 27th Edition, 2019, p. 2261
Five Common Spreadsheet Risks and Ways to Control Them2
GREATEST Concerns When Reviewing Data Inputs from Spreadsheets3
森*子 2025-08-29 09:39:40
コメント
他人の解答コメントを賛成するのも、その解答に一票を入れることになります。したがって、すでに同じ意見の投票コメントが存在する場合、新規コメントをする代わりに賛成することもできます。
コメントを通報する
コメント中
今すぐ 新規登録 / ログイン (無料です)。