正解:A
Regular scanning of hard drives is the most effective way to detect installation of unauthorized software packages by employees because it can identify any software that is not approved by the organization and may pose a security risk or violate the software policy. Communicating the policy to employees is important, but it may not prevent or detect unauthorized software installation. Logging of activity on the network can monitor network traffic, but it may not capture all software installation events. Maintaining current antivirus software can protect the system from malicious software, but it may not detect all unauthorized software packages. References:
* ISACA, CISA Review Manual, 27th Edition, 2020, p. 2381
* ISACA, CISA Review Questions, Answers & Explanations Database - 12 Month Subscription