正解:C
A service level agreement (SLA) is a contract between a service provider and a customer that defines the expected level of performance, risks, and capabilities of an IT infrastructure. An IS auditor can use an SLA to measure how well the IT infrastructure meets the business needs and objectives, as well as to identify any gaps or issues that need to be addressed. The other options are not directly related to measuring the performance, risks, and capabilities of an IT infrastructure. References:
* CISA Review Manual (Digital Version), Chapter 5, Section 5.2.11
* CISA Review Questions, Answers & Explanations Database, Question ID 203