時間限定無料ダウンロード 最新のCISSP日本語問題集で2025年最新のCISSP日本語試験問題
最新のISC CISSP日本語認定の練習テスト問題
質問 # 738
ゼロデイ マルウェアの脅威に対して最も効果的な防御方法は次のうちどれですか?
- A. クライアント イベントのログ記録
- B. クライアント アプリケーションのホワイトリスト
- C. クライアント アンチウイルス
- D. クライアント ファイアウォール
正解:B
質問 # 739
次のシナリオのうち、サーバーキャビネットをロックし、キーへのアクセスを制限して、不正アクセスを防ぐためにサーバールームをロックするよりも望ましいのはどれですか?
- A. サーバーハードウェアはリモートエリアにあります。
- B. サーバーキャビネットは複数のプロジェクトとワークスペースを共有します。
- C. サーバーキャビネットは非共有ワークスペースにあります。
- D. サーバーキャビネットは隔離されたサーバーファームにあります。
正解:B
質問 # 740 
- A. Option D
- B. Option A
- C. Option C
- D. Option B
正解:A
質問 # 741
ケルベロスの 4 つの基本原則は何ですか?
- A. セキュリティ、信頼性、透明性、およびスケーラビリティ
- B. セキュリティ、信頼性、拡張性、整合性
- C. セキュリティ、匿名性、透明性、可用性
- D. セキュリティ、完全性、可用性、透明性
正解:D
質問 # 742
パッチ管理サイクルには変更管理が重要です。企業環境でのパッチ適用にはどのような種類の計画を提供する必要がありますか?
- A. バックアップ
- B. フォローアップ
- C. バックアウト
- D. クリティカルパス
正解:A
質問 # 743 
- A. Option D
- B. Option A
- C. Option C
- D. Option B
正解:A
質問 # 744 
- A. Option A
- B. Option D
- C. Option B
- D. Option C
正解:D
質問 # 745
ペイメントカード業界データセキュリティ標準 (PCI-DSS) に基づいて、組織がデータの機密性を分類するときに実践されるコアセキュリティ原則は次のどれですか?
- A. アクセシビリティ
- B. 機密性
- C. 誠実さ
- D. 可用性
正解:B
質問 # 746
ソフトウェアエンジニアは、自動化されたツールを使用して、アプリケーションコードを確認し、アプリケーションの欠陥、バックドア、またはその他の悪意のあるコードを検索します。これが行われる最初のソフトウェア開発ライフサイクル(SDLC)フェーズは次のうちどれですか?
- A. 開発
- B. テスト
- C. 展開
- D. デザイン
正解:A
解説:
The development phase is the first Software Development Life Cycle (SDLC) phase where a software engineer uses automated tools to review application code and search for application flaws, back doors, or other malicious code. The development phase is the phase where the software engineer writes, compiles, and tests the application code, based on the design specifications and requirements. The development phase is also the phase where the software engineer performs code review and analysis, using automated tools, such as static or dynamic analysis tools, to identify and eliminate any errors, vulnerabilities, or malicious code in the application code. Code review and analysis is an important security activity in the development phase, as it can help to improve the quality, functionality, and security of the application, and to prevent or mitigate any potential attacks or exploits on the application12. References: CISSP CBK, Fifth Edition, Chapter 3, page
217; CISSP Practice Exam - FREE 20 Questions and Answers, Question 11.
質問 # 747
オリジナルの改変されていない証拠を説明するために使用される用語は次のどれですか?
- A. 間接的な証拠
- B. 最良の証拠
- C. 直接的な証拠
- D. 決定的な証拠
正解:C
質問 # 748
モバイル通信の暗号化技術のうち、キーの転送やデジタル署名などの小さなデータに通常使用される非対称暗号化スキームに依存するものはどれですか?
- A. リベスト・シャミール・アデルマン (RSA)
- B. セキュア ハッシュ アルゴリズム (SHA)
- C. 三重データ暗号化標準 (3DES)
- D. 高度暗号化標準 (AES)
正解:A
質問 # 749 
- A. Option B
- B. Option A
- C. Option C
- D. Option D
正解:A
質問 # 750
変更管理された環境で、本番プログラムへの不正な変更につながる可能性が最も高いのは次のうちどれですか?
- A. 承認なしでプログラムを本番にプロモートする
- B. 承認なしでRapid Application Development(RAD)手法を使用する開発者
- C. 開発者が承認なしにソースコードをチェックアウトする
- D. 承認なしでソースコードを変更する
正解:A
質問 # 751
産業用制御(ICS)ソフトウェアの欠陥が発見された場合、パッチの展開を妨げる最大の障害は何ですか?
- A. ベンダーは、操作性パッチを検証する必要があります。
- B. IGでパッチをテストするには、組織がコミットできる以上のリソースが必要になる場合があります。
- C. 多くのIGシステムには、ベンダーが管理していないソフトウェアがあります。
- D. 補正制御は、IGのパフォーマンスに影響を与える可能性があります。
正解:B
解説:
Industrial control systems (ICS) are critical for the operation of many sectors such as energy, transportation, manufacturing, and water. Patching ICS software is a challenging task because it may require extensive testing, validation, and coordination to ensure that the patch does not introduce new vulnerabilities, affect the functionality, performance, or availability of the system, or cause any adverse impacts on the physical processes or safety. Testing a patch in an ICS may require more resources than the organization can commit, such as time, personnel, equipment, or budget. Therefore, this is the greatest impediment to deploying a patch for ICS software. References: Recommended Practice for Patch Management of Control Systems, ICS Security Patching: Never, Next, Now, Patching and Change Management: CISSP Domain 7
質問 # 752
システムの制約により、システム管理者のグループは、資格情報の高レベルのアクセスセットを共有する必要があります。
次のうち、実装するのに最も適切なものはどれですか?
- A. 影響を受けるシステムでの完全なロギング
- B. グループのサイズを縮小します
- C. ログオン試行に失敗した場合のコンソールロックアウト時間の増加
- D. 使用ごとの資格情報チェックアウトプロセス
正解:D
解説:
Explanation
Section: Security Operations
質問 # 753
侵入検知システム(IDS)がファイアウォールで保護された内部ネットワークの内部にインストールされているとどうなりますか?
- A. IDSは分析するパケット数を増やすことができます。
- B. IDSはサーバからの失敗した管理者ログオンの試みを検出できます。
- C. ファイアウォールはサーバーからの失敗した管理者ログイン試行を検出できます
- D. ファイアウォールは分析するパケットの数を増やすことができます。
正解:B
質問 # 754
セキュリティ監査を実行するには、次のうちどれが存在する必要がありますか?
- A. 内部認定監査人
- B. 監査する業界フレームワーク
- C. 外部(サードパーティ)監査人
- D. 監査人の中立性
正解:B
解説:
The thing that should exist in order to perform a security audit is an industry framework to audit against. A security audit is a systematic and independent examination of the security policies, procedures, controls, and practices of an organization, system, or network, to verify their compliance, effectiveness, and efficiency. A security audit requires an industry framework to audit against, which is a set of standards, guidelines, or best practices that define the security requirements, objectives, and criteria for the audit. An industry framework to audit against can help to establish the scope, methodology, and expectations of the security audit, as well as to measure and report the performance, gaps, and recommendations of the security audit. An industry framework to audit against can also help to ensure the consistency, reliability, and validity of the security audit, as well as to facilitate the comparison, benchmarking, and improvement of the security audit. Some examples of industry frameworks to audit against are ISO/IEC 27001, NIST SP 800-53, COBIT, or CIS Controls. An external (third-party) auditor, an internal certified auditor, and the neutrality of the auditor are not things that should exist in order to perform a security audit. These are some of the factors or attributes that may affect the quality, credibility, and independence of the security audit, but they are not prerequisites or conditions for the security audit. A security audit can be performed by an external or internal auditor, depending on the purpose, scope, and resources of the audit. A security audit can be performed by a certified or non-certified auditor, depending on the qualifications, skills, and experience of the auditor. A security audit should be performed by a neutral or unbiased auditor, to avoid any conflict of interest, influence, or pressure from the auditee or other parties.
References: Official (ISC)2 CISSP CBK Reference, Fifth Edition, Domain 1, Security and Risk Management, page 28. CISSP All-in-One Exam Guide, Eighth Edition, Chapter 1, Security Governance Through Principles and Policies, page 29.
質問 # 755
セキュリティアーキテクトは、実装のために強制アクセス制御(MAC)モデルを参照する予定です。 これは、次のプロパティのどれが優先順位付けされているかを示します。
- A. Accessibility
- B. Confidentiality
- C. Integrity
- D. Availability
正解:B
解説:
According to the CISSP Official (ISC)2 Practice Tests, the property that is prioritized by a Mandatory Access Control (MAC) model for implementation is confidentiality. Confidentiality is the property that ensures that the data or information is only accessible or disclosed to the authorized parties, and is protected from unauthorized or unintended access or disclosure. A MAC model is a type of access control model that grants or denies access to an object based on the security labels of the subject and the object, and the security policy enforced by the system. A security label is a tag or a marker that indicates the classification, sensitivity, or clearance of the subject or the object, such as top secret, secret, or confidential. A security policy is a set of rules or criteria that defines how the access decisions are made based on the security labels, such as the Bell-LaPadula model or the Biba model. A MAC model prioritizes confidentiality, as it ensures that the data or information is only accessible or disclosed to the subjects that have the appropriate security labels and clearance, and that the data or information is not leaked or compromised by the subjects that have lower security labels or clearance. Integrity is not the property that is prioritized by a MAC model for implementation, although it may be a property that is supported or enhanced by a MAC model. Integrity is the property that ensures that the data or information is accurate, complete, and consistent, and is protected from unauthorized or unintended modification or corruption. A MAC model may support or enhance integrity, as it ensures that the data or information is only modified or corrupted by the subjects that have the appropriate security labels and clearance, and that the data or information is not altered or damaged by the subjects that have lower security labels or clearance. However, a MAC model does not prioritize integrity, as it does not prevent or detect the modification or corruption of the data or information by the subjects that have the same or higher security labels or clearance, or by the external factors or events, such as errors, failures, or accidents.
Availability is not the property that is prioritized by a MAC model for implementation, although it may be a property that is supported or enhanced by a MAC model. Availability is the property that ensures that the data or information is accessible and usable by the authorized parties, and is protected from unauthorized or unintended denial or disruption of access or use. A MAC model may support or enhance availability, as it ensures that the data or information is accessible and usable by the subjects that have the appropriate security labels and clearance, and that the data or information is not denied or disrupted by the subjects that have lower security labels or clearance. However, a MAC model does not prioritize availability, as it does not prevent or detect the denial or disruption of access or use of the data or information by the subjects that have the same or higher security labels or clearance, or by the external factors or events, such as attacks, failures, or disasters.
Accessibility is not the property that is prioritized by a MAC model for implementation, as it is not a security property, but a usability property. Accessibility is the property that ensures that the data or information is accessible and usable by the users with different abilities, needs, or preferences, such as the users with disabilities, impairments, or limitations. Accessibility is not a security property, as it does not protect the data or information from unauthorized or unintended access, disclosure, modification, corruption, denial, or disruption. Accessibility is a usability property, as it enhances the user experience and satisfaction of the data or information.
質問 # 756 
- A. Option D
- B. Option A
- C. Option C
- D. Option B
正解:A
質問 # 757
市販の(COTS)製品を使用するリスクは何ですか?
- A. COTS製品は、組織のセキュリティ要件に直接マッピングされない場合があります。
- B. COTS製品は通常、社内でソフトウェアを開発するよりも費用がかかります。
- C. ベンダーは、ソースコードの共有をためらうことがよくあります。
- D. COTS製品を実装するためのコストを予測することは困難です。
正解:A
解説:
A risk of using commercial off-the-shelf (COTS) products is that they may not map directly to an organization's security requirements. COTS products are software or hardware products that are ready-made and available for purchase from vendors or suppliers, without any customization or modification. COTS products can offer some advantages, such as lower cost, faster deployment, or better compatibility, but they can also pose some risks, such as:
* COTS products may not map directly to an organization's security requirements, as they are designed for general or common purposes, and they may not meet the specific or unique needs or expectations of the organization. For example, a COTS product may not support the organization's preferred encryption algorithm, authentication method, or access control model, or it may have some security vulnerabilities or weaknesses that could compromise the organization's security posture or compliance.
* COTS products are typically more difficult to secure or update, as the organization does not have full control or visibility over the product's source code, configuration, or functionality. The organization has to rely on the vendor or the supplier to provide security patches, fixes, or enhancements, which may not be timely, reliable, or compatible. The organization may also face some compatibility or interoperability issues with other systems or products, or some legal or contractual constraints or obligations, when using COTS products.
* COTS products may introduce some hidden or unexpected costs or risks, as the organization may have to pay for additional licenses, fees, or services, or deal with some performance, quality, or usability issues, when using COTS products. The organization may also have to share or disclose some sensitive or confidential information with the vendor or the supplier, or accept some terms or conditions that may limit the organization's rights or options, when using COTS products.
The other options are not risks of using COTS products. COTS products are typically cheaper than developing software in-house, as the organization does not have to invest in the development, testing, or maintenance of the software. Cost to implement COTS products is not difficult to predict, as the organization can estimate the cost based on the product's price, features, or specifications. Vendors are not often hesitant to share their source code, as they may offer some level of customization or integration for their COTS products, or they may use open source or standard code for their COTS products. References: CISSP All-in-One Exam Guide, Eighth Edition, Chapter 4: Security Architecture and Engineering, page 439. Official (ISC)2 CISSP CBK Reference, Fifth Edition, Chapter 4: Security Architecture and Engineering, page 440.
質問 # 758
災害復旧計画(DRP)をテストするための最小基準は何ですか?
- A. 監査部門の要件に応じて、毎年またはそれ以下の頻度
- B. 半年ごとに、半年ごとの景気循環に沿って
- C. 環境の安定性とビジネス要件に応じて必要な頻度で
- D. 情報セキュリティマネージャーのアドバイスに応じて、四半期ごとまたはそれ以上の頻度で
正解:C
質問 # 759
第三者による処理のために、個人を特定できる情報(PII)を準備するためにどのような手順を実行できますか?
- A. クラウドサービスプロバイダー(CSP)とのセキュリティ契約が必要だったため、心配はありません。
- B. PIIがプロバイダーの手にある限り、PIIを保護する必要はありません。
- C. 個人情報は、一方向の参照を使用して個別に管理する必要があります。
- D. 個人情報をハッシュし、データを外部のプロセッサに送信できます。
正解:C
質問 # 760
......
検証済みのCISSP日本語問題集と解答で一年間無料最速更新:https://www.goshiken.com/ISC/CISSP-JP-mondaishu.html