[2024年07月最新リリース] 合格できるNIST-COBIT-2019試験にはリアル問題とアンサー [Q23-Q43]

Share

[2024年07月最新リリース] 合格できるNIST-COBIT-2019試験にはリアル問題とアンサー

合格できるNIST-COBIT-2019レビューガイド、頼もしいNIST-COBIT-2019テストエンジン

質問 # 23
Which function of the CSF is addressed by incorporating governance, risk, and compliance (GRC) elements into the implementation plan?

  • A. Protect
  • B. Detect
  • C. Identify

正解:C

解説:
The function of the CSF that is addressed by incorporating governance, risk, and compliance (GRC) elements into the implementation plan is Identify, which assists in developing an organizational understanding to managing cybersecurity risk to systems, people, assets, data, and capabilities. GRC elements help to define the governance program, the legal and regulatory requirements, the risk management strategy, and the supply chain risk management strategy of the organization12.
ReferencesThe Five Functions | NISTNIST Cybersecurity Framework 2.0: Understanding the "Govern" Function


質問 # 24
Which of the following is the MOST important input for prioritizing resources during program initiation?

  • A. Replacement cost
  • B. Business impact assessment
  • C. Risk register

正解:B

解説:
A business impact assessment (BIA) is the most important input for prioritizing resources during program initiation, because it helps to identify and evaluate the potential effects of disruptions to critical business functions and processes12. A BIA can help to determine the recovery objectives, priorities, and strategies for the program, as well as the resource requirements and dependencies34.
References: 1: Business Impact Analysis | Ready.gov 2: Business Impact Analysis - ISACA 3: COBIT 2019 Implementation Guide 4: COBIT 2019 Implementation - ISACA


質問 # 25
Which of the following should be a PRIMARY consideration when creating an action plan to address gaps identified in CSF Step 6: Determine, Analyze, and Prioritize Gaps?

  • A. IT process descriptions
  • B. Mission drivers
  • C. Stakeholder map

正解:B

解説:
According to the NIST Cybersecurity Framework, mission drivers are a primary consideration when creating an action plan to address gaps identified in CSF Step 6, as they help to align the cybersecurity program with the organization's objectives, priorities, and risk appetite. Mission drivers also help to determine the resources needed and the cost-benefit analysis of the proposed solutions12.
References7 Steps to Implement & Improve Cybersecurity with NISTCybersecurity Framework v1.1 - CSF Tools - Identity Digital, page 7.


質問 # 26
Which information should be collected for a Current Profile?

  • A. Recommended Actions
  • B. Implementation Status
  • C. Resource Required

正解:B

解説:
The implementation status is the information that should be collected for a Current Profile, because it indicates the degree to which the cybersecurity outcomes defined by the CSF Subcategories are currently being achieved by the organization12. The implementation status can be expressed using a four-level scale: Not Performed, Partially Performed, Performed, and Informative References Not Applicable34.
References: 1: Cybersecurity Framework Components | NIST 2: Implementing the NIST Cybersecurity Framework Using COBIT 2019 | ISACA 3: Framework Documents | NIST 4: REVIEW OF IMPLEMENTING THE NIST CYBERSECURITY FRAMEWORK USING COBIT 2019.


質問 # 27
Which CSF step corresponds to the COBIT objective of knowledge and understanding of enterprise goals?

  • A. Step 4: Conduct a Risk Assessment
  • B. Step 1: Prioritize and Scope
  • C. Step 6: Determine, Analyze, and Prioritize Gaps

正解:B

解説:
This CSF step corresponds to the COBIT objective of knowledge and understanding of enterprise goals, because it involves identifying the business drivers, mission, objectives, and risk appetite of the organization, as well as the scope and boundaries of the cybersecurity program12. This step helps to ensure that the cybersecurity activities and outcomes are aligned with the enterprise goals and strategy34.
References: 1: Cybersecurity Framework Components | NIST 2: Implementing the NIST Cybersecurity Framework Using COBIT 2019 | ISACA 3: COBIT 2019 Design and Implementation COBIT Implementation5 4: COBIT 2019 Foundation | Skillsoft Global Knowledge6


質問 # 28
The seven high-level CSF steps generally align to which of the following in COBIT 2019?

  • A. High-level functions
  • B. High-level phases
  • C. High-level categories

正解:B

解説:
The seven high-level CSF steps generally align to the high-level phases of the COBIT 2019 implementation guide, which are: What are the drivers?; Where are we now?; Where do we want to be?; What needs to be done?; How do we get there?; Did we get there?; and How do we keep the momentum going?12. These phases provide a structured approach for implementing a governance system using COBIT 2019, and can be mapped to the CSF steps of Prioritize and Scope, Orient, Create a Current Profile, Conduct a Risk Assessment, Create a Target Profile, Determine, Analyze and Prioritize Gaps, and Implement Action Plan34.
References: 1: COBIT 2019 Implementation Guide 2: COBIT 2019 Implementation - ISACA 3: Implementing the NIST Cybersecurity Framework Using COBIT 2019 | ISACA 4: REVIEW OF IMPLEMENTING THE NIST CYBERSECURITY FRAMEWORK USING COBIT 2019.


質問 # 29
During CSF life cycle action plan review, which of the following tasks is associated with realizing benefits?

  • A. Developing business cases indicating success factors
  • B. Monitoring performance against objectives
  • C. Documenting risk issues and remediation plans

正解:B

解説:
According to the ISACA guide, monitoring performance against objectives is one of the tasks associated with realizing benefits, as it helps to measure the outcomes and value of the CSF implementation, and to identify and address any issues or gaps that may arise1. This task also involves reporting and communicating the results and feedback to the relevant stakeholders and ensuring continuous improvement2.
ReferencesConnecting COBIT 2019 to the NIST Cybersecurity Framework - ISACAManage Enterprise Cyberrisk by Applying the NIST CSF With COBIT ... - ISACA


質問 # 30
Which COBIT implementation phase directs the development of an action plan based on the outcomes described in the Target Profile?

  • A. Phase 4 -What Needs to Be Done?
  • B. Phase 5 -How Do We Get There?
  • C. Phase 3 -Where Do We Want to Be?

正解:B

解説:
The COBIT implementation phase that directs the development of an action plan based on the outcomes described in the Target Profile is Phase 5 - How Do We Get There? This phase involves defining the detailed steps, resources, roles, and responsibilities for executing the implementation plan and achieving the desired outcomes12.
References7 Phases in COBIT Implementation | COBIT Certification - SimplilearnCOBIT 2019 Design and Implementation COBIT Implementation, page 31.


質問 # 31
Which of the following COBIT and NIST implementation steps may be reversed depending on the culture of the organization?

  • A. Step 3: Create a Current Profile and Step 5: Create a Target Profile
  • B. Step 4: Conduct a Risk Assessment and Step 6: Determine, Analyze, and Prioritize Gaps
  • C. Step 1: Prioritize and Scope and Step 2: Orient

正解:C

解説:
According to the ISACA guide, the order of these two steps may be reversed depending on the culture of the organization and the level of stakeholder engagement1. Some organizations may prefer to start with a broad orientation of the NIST CSF and COBIT 2019 before scoping and prioritizing the implementation, while others may want to define the scope and priorities first and then orient the stakeholders accordingly.
ReferencesImplementing the NIST Cybersecurity Framework Using COBIT 2019, page 17.


質問 # 32
During Step 3: Create a Current Profile, an enterprise outcome has reached a 95% subcategory maturity level.
How would this level of achievement be
described in the COBIT Performance Management Rating Scale?

  • A. Largely Achieved
  • B. Partially Achieved
  • C. Fully Achieved

正解:C

解説:
According to the COBIT Performance Management Rating Scale, a subcategory maturity level of 95% corresponds to the rating of Fully Achieved, which means that the outcome is achieved above 85%12. This indicates that the enterprise has a high degree of capability and maturity in the subcategory, and that the practices and activities are performed consistently and effectively34.
References:
1: Performance Management of Processes - Testprep Training Tutorials
2: COBIT 2019 and COBIT 5 Comparison - ISACA
3: COBIT 2019 Performance Management: Principles and Processes
4: Effective Capability and Maturity Assessment Using COBIT 2019 - ISACA


質問 # 33
Which of the following COBIT 2019 governance principles corresponds to the CSF application stating that CSF profiles support flexibility in content and structure?

  • A. A governance system should be customized to the enterprise needs, using a set of design factors as parameters.
  • B. A governance system should focus primarily on the enterprise's IT function and information processing.
  • C. A governance system should clearly distinguish between governance and management activities and structures.

正解:A

解説:
This principle corresponds to the CSF application stating that CSF profiles support flexibility in content and structure, because both emphasize the need for tailoring the governance system to the specific context and requirements of the enterprise12. The CSF profiles are based on the enterprise's business drivers, risk appetite, and current and target cybersecurity posture3. The COBIT 2019 design factors are a set of parameters that influence the design and operation of the governance system, such as enterprise strategy, size, culture, and regulatory environment4.
References:
1: COBIT | Control Objectives for Information Technologies | ISACA
2: COBIT 2019 Framework - ITSM Docs - ITSM Documents & Templates
3: Framework Documents | NIST
4: Introduction to COBIT Principles - Testprep Training Tutorials


質問 # 34
The goals cascade supports prioritization of management objectives based on:

  • A. the prioritization of business objectives.
  • B. the prioritization of stakeholder needs.
  • C. the prioritization of enterprise goals.

正解:B

解説:
The goals cascade is a mechanism that translates the stakeholder needs into specific, actionable, and customized goals at different levels of the enterprise12. The stakeholder needs are the drivers of the governance system and reflect the expectations and requirements of the internal and external parties that have an interest or influence on the enterprise34. The goals cascade supports the prioritization of management objectives based on the stakeholder needs, as well as the alignment of the enterprise goals, the alignment goals, and the governance and management objectives12.
References: 1: COBIT 2019 Goals Cascade: A Blueprint for Success 2: COBIT 2019 Framework - ITSM Docs - ITSM Documents & Templates 3: COBIT | Control Objectives for Information Technologies | ISACA
4: Aligning IT goals using the COBIT5 Goals Cascade


質問 # 35
Which of the following is MOST important for successful execution of CSF implementation Step 6 - Determine, Analyze, and Prioritize Gaps?

  • A. Have management review and approve the gap analysis.
  • B. Engage external experts to perform a cost-benefit analysis.
  • C. Engage business and IT process owners for internal expertise.

正解:C

解説:
According to the ISACA guide, engaging business and IT process owners for internal expertise is most important for successful execution of CSF implementation Step 6, as they can provide valuable insights into the current and desired states of the processes, the gaps and potential solutions, and the costs and benefits of the implementation1. They can also help to align the cybersecurity program with the business objectives and risk appetite of the organization.
ReferencesImplementing the NIST Cybersecurity Framework Using COBIT 2019, page 17.


質問 # 36
Which of the following is an input to COBIT Implementation Phase 1: What Are the Drivers?

  • A. Program wake-up call
  • B. Risk response document
  • C. Current capability rating for selected processes

正解:A

解説:
A program wake-up call is an input to COBIT Implementation Phase 1: What Are the Drivers, because it is a trigger event that creates a sense of urgency and a need for change in the organization's governance and management of enterprise I&T12. A program wake-up call can be internal or external, positive or negative, such as a major incident, a new regulation, a strategic initiative, or a stakeholder feedback34.
References: 1: COBIT 2019 Implementation Guide 2: COBIT 2019 Implementation - ISACA 3: Tips for Implementing COBIT in a Continuously Changing Environment - ISACA 4: 7 Phases of COBIT Implementation: Explained - The Knowledge Academy


質問 # 37
Which of the following COBIT tasks and activities corresponds to CSF Step 1: Prioritize and Scope?

  • A. Determine ability to implement the change.
  • B. Understand the enterprise's capacity and capability for change.
  • C. Use change agents to communicate informally and formally.

正解:B

解説:
This COBIT task and activity corresponds to CSF Step 1: Prioritize and Scope, because it involves assessing the current state of the enterprise's governance and management system, as well as its readiness and ability to adopt changes12. This task and activity is part of the COBIT 2019 implementation phase "Where are we now?"3, which aligns with the CSF step of identifying the business drivers, mission, objectives, and risk appetite of the organization4.
References: 1: COBIT 2019 Implementation Guide 2: COBIT 2019 Implementation - ISACA 3: Connecting COBIT 2019 to the NIST Cybersecurity Framework - ISACA 4: Cybersecurity Framework Components | NIST


質問 # 38
What is the MOST important reason to compare framework profiles?

  • A. To conduct a risk assessment
  • B. To identify gaps
  • C. To improve security posture

正解:B

解説:
The most important reason to compare framework profiles is to identify gaps between the current and target state of cybersecurity activities and outcomes, and to prioritize the actions needed to address them12.
Framework profiles are the alignment of the functions, categories, and subcategories of the NIST Cybersecurity Framework with the business requirements, risk tolerance, and resources of the organization3.
By comparing the current profile (what is being achieved) and the target profile (what is needed), an organization can assess its cybersecurity posture and develop a roadmap for improvement4.
References: 1: Cybersecurity Framework Components | NIST 2: Implementing the NIST Cybersecurity Framework Using COBIT 2019 | ISACA 3: Examples of Framework Profiles | NIST 4: Connecting COBIT
2019 to the NIST Cybersecurity Framework - ISACA


質問 # 39
The activity of determining an appropriate target capability level for each process occurs within which implementation phase?

  • A. Phase 4 - What Needs to Be Done?
  • B. Phase 3 - Where Do We Want to Be?
  • C. Phase 2 - Where Are We Now?

正解:B

解説:
The activity of determining an appropriate target capability level for each process occurs within Implementation Phase 3, as it helps to set an improvement target and identify gaps and potential solutions using COBIT's guidance. This involves creating a detailed business case and a high-level program plan for the implementation12.
ReferencesDefining Target Capability Levels in COBIT 2019: A Proposal for RefinementCOBIT 2019 Design and Implementation COBIT Implementation, page 31.


質問 # 40
When aligning to the NIST Cybersecurity Framework, what should occur after tier levels and framework core outcomes are determined?

  • A. Report discovered issues to senior management.
  • B. Compare current and target profiles.
  • C. Assign mitigating control development.

正解:B

解説:
According to the NIST Cybersecurity Framework, after determining the tier levels and framework core outcomes, the next step is to compare the current and target profiles, which describe the organization's current and desired cybersecurity posture based on the framework core functions, categories, and subcategories1. This comparison helps to identify the gaps and prioritize the actions for improvement2.
ReferencesCybersecurity Framework Components | NISTWhat is the NIST Cybersecurity Framework? | IBM


質問 # 41
During CSF implementation, when is an information security manager MOST likely to identify key enterprise and supporting alignment goals as previously understood?

  • A. CSF Step 1: Prioritize and Scope
  • B. CSF Steps 5: Create a Target Profile and 6: Determine, Analyze, and Prioritize Gaps
  • C. CSF Steps 2: Orient and 3: Create a Current Profile

正解:A

解説:
This CSF step corresponds to the COBIT objective of knowledge and understanding of enterprise goals, because it involves identifying the business drivers, mission, objectives, and risk appetite of the organization, as well as the scope and boundaries of the cybersecurity program12. This step helps to ensure that the cybersecurity activities and outcomes are aligned with the enterprise goals and strategy34.
References: 1: Cybersecurity Framework Components | NIST 2: Implementing the NIST Cybersecurity Framework Using COBIT 2019 | ISACA 3: COBIT 2019 Design and Implementation COBIT Implementation
4: COBIT 2019 Foundation | Skillsoft Global Knowledge


質問 # 42
Which of the following is an objective of Implementation Phase 3 - Where Do We Want to Be?

  • A. Create a detailed business case and high-level program plan from gathered information.
  • B. Monitor, measure, and report on project progress.
  • C. Integrate the improvement projects into the overall program plan.

正解:A

解説:
This is an objective of Implementation Phase 3: Where Do We Want to Be?, because it involves defining the desired state of the enterprise's governance and management system, based on the stakeholder needs, drivers, and scope12. This objective also includes developing a business case that provides the rationale and justification for the improvement program, and a high-level program plan that outlines the scope, objectives, approach, and resources of the program3 .
References: 1: COBIT 2019 Implementation Guide 2: COBIT 2019 Implementation - ISACA 3: Business Case Development - ISACA : How to Write a Business Case for Cybersecurity Projects | Infosec


質問 # 43
......

100%無料NIST-COBIT-2019日常練習試験50問題:https://www.goshiken.com/ISACA/NIST-COBIT-2019-mondaishu.html

NIST-COBIT-2019テストエンジン練習テスト問題試験問題集:https://drive.google.com/open?id=1Lfoel9ZfxzOxIlRFrBKbhfO8-fF70v0S