2025年最新のCISM日本語実際問題集には試験のコツがあるPDF試験材料 [Q144-Q169]

Share

2025年最新のCISM日本語実際問題集には試験のコツがあるPDF試験材料

心強いCISM日本語のPDF問題集問題

質問 # 144
複数年計画を策定する際に、情報セキュリティ マネージャーが最も重要な考慮事項は何でしょうか?

  • A. 情報セキュリティプログラムの機能を拡張できるようにする
  • B. 毎年の予算増加の予測を示す
  • C. 他の事業部門の計画との整合性を確保する
  • D. 潜在的な情報セキュリティリスクに対する緊急時対応計画を確実に実施する

正解:C

解説:
= The most important consideration when developing a multi-year plan for information security is to ensure alignment with the plans of other business units. Alignment means that the information security plan supports and enables the achievement of the business objectives, strategies, and priorities of the organization and its various units. Alignment also means that the information security plan is consistent and compatible with the plans of other business units, and that it addresses the needs, expectations, and requirements of the relevant stakeholders1 .
By ensuring alignment with the plans of other business units, the information security manager can achieve the following benefits1 :
* Increase the value and effectiveness of information security: By aligning the information security plan with the business goals and drivers, the information security manager can demonstrate the value and contribution of information security to the organization's performance, growth, and competitiveness.
The information security manager can also ensure that the information security plan addresses the most critical and relevant risks and opportunities for the organization and its units, and that it provides adequate and appropriate protection and support for the organization's assets, processes, and activities.
* Enhance the communication and collaboration with other business units: By aligning the information security plan with the plans of other business units, the information security manager can enhance the communication and collaboration with the other business unit leaders and managers, who are the key stakeholders and partners in information security. The information security manager can also solicit and incorporate their input, feedback, and suggestions into the information security plan, and provide them with timely and relevant information, guidance, and support. The information security manager can also foster a culture of trust, respect, and cooperation among the different business units, and promote a shared vision and commitment to information security.
* Optimize the use and allocation of resources for information security: By aligning the information security plan with the plans of other business units, the information security manager can optimize the use and allocation of resources for information security, such as budget, staff, time, or technology. The information security manager can also avoid duplication, conflict, or waste of resources among the different business units, and ensure that the information security plan is feasible, realistic, and sustainable. The information security manager can also leverage the resources and capabilities of other business units to enhance the information security plan, and provide them with the necessary resources and capabilities to implement and maintain the information security plan.
The other options are not the most important consideration when developing a multi-year plan for information security, as they are less strategic, comprehensive, or impactful than ensuring alignment with the plans of other business units. Ensuring contingency plans are in place for potential information security risks is an important component of the information security plan, but it is not the most important consideration, as it focuses on the reactive and preventive aspects of information security, rather than the proactive and enabling aspects. Allowing the information security program to expand its capabilities is an important objective of the information security plan, but it is not the most important consideration, as it depends on the availability and suitability of the resources, technologies, and opportunities for information security, and it may not align with the organization's needs, priorities, or constraints. Demonstrating projected budget increases year after year is an important outcome of the information security plan, but it is not the most important consideration, as it reflects the cost and demand of information security, rather than the value and benefit of information security, and it may not be justified or supported by the organization's financial situation or expectations1 . References = CISM Domain 1: Information Security Governance (ISG) [2022 update], CISM Domain 2: Information Risk Management (IRM) [2022 update], Aligning Information Security with Business Strategy - ISACA, [Aligning Information Security with Business Objectives - ISACA]


質問 # 145
インシデント対応プロセスにおける撲滅フェーズの主な目標は次のとおりです。

  • A. 効果的なトリアージとインシデントの封じ込めを提供します。
  • B. 影響を受けるシステムから法医学的証拠を取得します。
  • C. 脅威を除去し、影響を受けたシステムを復元します。
  • D. 厳格な保管過程を維持します。

正解:C

解説:
The primary goal of the eradication phase in an incident response process is to remove the threat and restore affected systems because it eliminates any traces or remnants of malicious activity or compromise from the systems or network, and returns them to their normal or secure state. Maintaining a strict chain of custody is not a goal of the eradication phase, but rather a requirement for preserving and documenting digital evidence throughout the incident response process. Providing effective triage and containment of the incident is not a goal of the eradication phase, but rather a goal of the containment phase, which isolates and stops the spread of malicious activity or compromise. Obtaining forensic evidence from the affected system is not a goal of the eradication phase, but rather a goal of the identification phase, which collects and analyzes data or artifacts related to malicious activity or compromise. Reference: https://www.isaca.org/resources/isaca-journal/issues/2017/volume-5/incident-response-lessons-learned https://www.isaca.org/resources/isaca-journal/issues/2018/volume-3/incident-response-lessons-learned


質問 # 146
今後の新しいデータプライバシー規制に対処するためのポリシーを実装するときに、最初に実行する必要があるのは次のうちどれですか?

  • A. 規制が実施されるまで、個人データのさらなる収集を禁止します。
  • B. 新しい規制の対象となる個人データの種類を理解します。
  • C. ネットワーク上の他のシステムから個人データを処理するシステムを分離します-
  • D. 個人データ保護に必要なテクノロジーを理解します。

正解:B


質問 # 147
次のうちどれが最近確立情報セキュリティプログラムが有効であることがBEST証拠を提供しますか?

  • A. ITインシデントに関連付けられたチケットの数が一致宿泊しています
  • B. 報告された事件の数が増加しています
  • C. 上級管理職が少ないジャンクメールを報告しています
  • D. レギュラーITバランススコアカードが通信されます

正解:D


質問 # 148
データベース内の情報をどのように分類するかを決定するのに最適な人は誰でしょうか?

  • A. データベース管理者 (DBA)
  • B. 情報セキュリティアナリスト
  • C. データベースアナリスト
  • D. データ所有者

正解:D


質問 # 149
次の指標のうち、組織のセキュリティ意識向上プログラムの有効性を最もよく示すものはどれですか?

  • A. エンドユーザーが閲覧したフィッシングメールの数
  • B. 定期的にセキュリティトレーニングに参加する従業員の割合
  • C. ヘルプデスクに報告されたセキュリティインシデントの数
  • D. マルウェアに感染した従業員のコンピュータとデバイスの割合

正解:B


質問 # 150
最高情報セキュリティ責任者(CISO)は、情報セキュリティ戦略を策定しましたが、戦略を実行するための資金に対する上級管理職のコミットメントを獲得するのに苦労しています。次のうち、最も可能性の高い理由はどれですか?

  • A. CISOはCIOに報告します。
  • B. 戦略には費用便益分析は含まれていません。
  • C. 開発中のビジネスとの関わりが不足していました。
  • D. 戦略はセキュリティ基準に準拠していません。

正解:B


質問 # 151
どのタイプのフェイルオーバー サイトを採用するかを決定する際に最も重要な考慮事項は次のどれですか。

  • A. データ保持要件
  • B. 相互合意
  • C. 災害復旧テスト結果
  • D. 復旧時間目標 (RTO)

正解:D


質問 # 152
クラウドコンピューティングベンダーとの責任を定義する場合、ユーザーとプロバイダーの間で共有される責任と見なすべきものは次のうちどれですか?

  • A. アクセスログレビュー
  • B. インシデント対応
  • C. データの所有権
  • D. アプリケーションログ

正解:B


質問 # 153
情報セキュリティ管理者がセキュリティとビジネスの目標を調整するための最善の行動方針は次のうちどれですか?

  • A. ステークホルダーとの積極的なエンゲージメント
  • B. 事業戦略の見直し
  • C. 重要業績評価指標 (KPI) の定義
  • D. 事業影響分析(BIA)の実施

正解:A


質問 # 154
プロジェクトのどの段階で、新しいシステムのセキュリティ制御を検証するためのテスト計画を作成する必要がありますか?

  • A. Initiation
  • B. Testing
  • C. Development
  • D. Design

正解:D

解説:
説明
設計段階では、セキュリティチェックポイントが定義され、テスト計画が作成されます。システムはすでに開発されており、実稼働テスト中であるため、テスト段階は遅すぎます。開始フェーズでは、プロジェクトの基本的なセキュリティ目標が確認されます。開発はコーディング段階であり、テスト計画を検討するには遅すぎます。


質問 # 155
情報セキュリティ ソリューションの組織的メリットを最もよく示すのは次のどれですか?

  • A. ソリューションにより情報セキュリティ部門にもたらされるコスト削減
  • B. セキュリティトレーニング要件の削減
  • C. 時間の経過に伴って計算されたソリューションのコストと利点
  • D. セキュリティの脅威とリスクへの対応

正解:C

解説:
The best option to indicate the organizational benefit of an information security solution is D. Costs and benefits of the solution calculated over time. This is because costs and benefits of the solution calculated over time, also known as the return on security investment (ROSI), can help to measure and demonstrate the value and effectiveness of the information security solution in terms of reducing risks, enhancing performance, and achieving strategic goals. ROSI can also help to justify the allocation and optimization of the resources and budget for the information security solution, and to compare and prioritize different security alternatives. ROSI can be calculated by using various methods and formulas, such as the annualized loss expectancy (ALE), the annualized rate of occurrence (ARO), and the cost-benefit analysis (CBA).
Costs and benefits of the solution calculated over time, also known as the return on security investment (ROSI), can help to measure and demonstrate the value and effectiveness of the information security solution in terms of reducing risks, enhancing performance, and achieving strategic goals. (From CISM Manual or related resources) Reference = CISM Review Manual 15th Edition, Chapter 3, Section 3.1.3, page 1311; CISM Review Questions, Answers & Explanations Manual 9th Edition, Question 99, page 26; How to Calculate Return on Security Investment (ROSI) - Infosec2


質問 # 156
効果的な情報セキュリティ指標を確立する際に最も重要なものは次のうちどれですか?

  • A. 各メトリックを特定のコントロールにマッピングする
  • B. 上級管理職の承認を受ける
  • C. 各メトリックを情報セキュリティ目標にマッピングする
  • D. ビジネス目標を理解する

正解:D


質問 # 157
取締役会に主要なリスクを提示するための情報セキュリティマネージャーの主な目的は、次のとおりです。

  • A. 適切な情報セキュリティガバナンスを確保し、
  • B. 情報セキュリティコンプライアンス要件を満たします。
  • C. リスクアペタイトを再評価する
  • D. 評判リスクを定量化する

正解:A


質問 # 158
組織のSoftwareasa Service(SaaS)ベンダーに違反した後の上級管理職に対する、情報セキュリティマネージャーの最良の推奨事項は次のうちどれですか?

  • A. ベンダーのリスク評価を更新します。
  • B. ベンダー契約を再交渉します。
  • C. 弁護士に相談してください。
  • D. ベンダーとの関係を終了します。

正解:A


質問 # 159
情報セキュリティ管理者がサードパーティのリスクを効果的に管理するための最良のアプローチは次のうちどれですか。

  • A. 上級管理職がベンダーとの関係を承認したことを確認します。
  • B. リスクの変化に対処するためのコントロールが実装されていることを確認します。
  • C. リスク管理の取り組みがリスクの露出に見合っていることを確認します。
  • D. ベンダーガバナンス管理が実施されていることを確認します。

正解:A


質問 # 160
情報セキュリティ管理者が全機能の継続性テストを実施する前に検証することが最も重要なのは、次のうちどれですか?

  • A. 復旧およびインシデント対応計画のコピーをオフサイトに保管
  • B. 復旧を担当するチームと個人が特定されている
  • C. 事業者によるリスク受容が文書化されている
  • D. インシデント対応と復旧計画が簡単な言葉で文書化されている

正解:B

解説:
Before conducting full-functional continuity testing, an information security manager should verify that teams and individuals responsible for recovery have been identified and trained on their roles and responsibilities. This will ensure that the testing can be executed effectively and efficiently, as well as identify any gaps or issues in the recovery process. Risk acceptance by the business, copies of plans kept offsite and plans documented in simple language are all good practices for continuity management, but they are not as important as having clear roles and responsibilities defined before testing.


質問 # 161
セキュリティガバナンスの実装を成功させるための最も重要な要件は次のうちどれですか?

  • A. セキュリティバランススコアカードの実装
  • B. 組織へのマッピング
  • C. 国際的な安全保障の枠組みに合わせる
  • D. 全社的なリスク評価のパフォーマンス

正解:B


質問 # 162
情報セキュリティマネージャーは、重要なビジネスプロセスをサポートするサーバーで潜在的なセキュリティ違反を発見しました。次のうち、情報セキュリティマネージャーの最初の行動方針はどれですか?

  • A. インシデントが発生したことを検証します
  • B. 上級管理職にインシデントを通知します。
  • C. ビジネスプロセスの所有者に通知します。
  • D. サーバーを整理された方法でシャットダウンします。

正解:A


質問 # 163
情報リスクに関して上級管理職に伝えるのに最も適切なのは次のどれですか?

  • A. リスクプロファイルの変更
  • B. 新たなセキュリティ技術
  • C. 定義されたリスク許容度
  • D. 脆弱性スキャンの進行状況

正解:A

解説:
The most appropriate information to communicate to senior management regarding information risk is the risk profile changes, which reflect the current level and nature of the risks that the organization faces. The risk profile changes can help senior management to understand the impact of the risks on the business objectives, the effectiveness of the risk management strategy, and the need for any adjustments or improvements. The risk profile changes can also help senior management to prioritize the allocation of resources and to make informed decisions.
References = CISM Review Manual, 16th Edition eBook1, Chapter 2: Information Risk Management, Section: Risk Communication, Subsection: Risk Reporting, Page 97.


質問 # 164
組織のプライバシー責任者をサポートする場合、プライバシー要件に関する情報セキュリティマネージャーの主な役割は次のうちどれですか?

  • A. 個人データの転送を監視する
  • B. 適切な管理が行われていることを確認する
  • C. データ分類の決定
  • D. プライバシー意識向上プログラムの実施

正解:B


質問 # 165
情報セキュリティの主な目標は次のうちどれですか?

  • A. 規制順守
  • B. データガバナンス
  • C. 情報管理
  • D. ビジネスの連携

正解:A


質問 # 166
組織は、クライアントをサポートするためにより多くのビジネスリソースを必要とするビジネスアプリケーション用の強化されたパスワードポリシーを実装しています。ビジネス管理のサポートを得るための最良のアプローチは次のとおりです。

  • A. 業界のベンチマーク結果をビジネスユニットに提示する
  • B. 実装されていない場合のセキュリティインシデントのリスクと影響について話し合う
  • C. 変更のコストと利点の分析を提示する
  • D. 情報セキュリティへのプラスの影響について詳しく説明する

正解:C


質問 # 167
情報セキュリティプログラムの有効性の最良の測定基準は次のどれですか。

  • A. 組織のリスク改善のコストの削減
  • B. リスクにさらされる人の臓器の量の減少
  • C. 組織の脆弱性の数の削減
  • D. 組織に対する脅威の数の削減

正解:B


質問 # 168
情報セキュリティ マネージャーは、セキュリティ インシデントに関する最新情報を取締役会、規制当局、およびメディアに伝える資料を作成する任務を負っています。情報セキュリティ マネージャーが最初に行うべきことは何でしょうか。

  • A. 対象ユーザー向けのコミュニケーション チャネルを設定します。
  • B. 組織のインシデント対応計画を呼び出します。
  • C. 包括的な単一のコミュニケーションを作成する
  • D. 各対象者のニーズと要件を決定します。

正解:B

解説:
The information security manager should do FIRST invoke the organization's incident response plan, which is a predefined set of procedures and guidelines for handling security incidents in a timely and effective manner. The incident response plan should include the roles and responsibilities of the incident response team, the communication protocols and channels, the escalation and reporting procedures, and the documentation and evidence collection requirements. By invoking the incident response plan, the information security manager can ensure that the incident is properly contained, analyzed, resolved, and reported, and that the appropriate stakeholders are informed and involved. The other options are not the first actions that the information security manager should take, as they are part of the communication process that follows the incident response plan. Setting up communication channels for the target audience, determining the needs and requirements of each audience, and creating a comprehensive singular communication are all important steps for communicating effectively with the board, regulatory agencies, and the media, but they are not the first priority in the event of a security incident. The information security manager should first follow the incident response plan to manage the incident and its impact, and then communicate the relevant information to the target audience according to the plan. Reference = CISM Review Manual, 16th Edition, page 2261; CISM Review Questions, Answers & Explanations Manual, 10th Edition, page 1012 Determining the needs and requirements of each audience should be the FIRST step in developing materials to update the board, regulatory agencies, and the media about a security incident. This is because different audiences have different expectations, interests, and concerns regarding the incident and its impact. By understanding the needs and requirements of each audience, the information security manager can tailor the communication materials to address them effectively and appropriately. This will also help to avoid confusion, misinformation, or misinterpretation of the incident details and response actions


質問 # 169
......

結果を保証するには2025年09月最新の無料版提供しています:https://www.goshiken.com/ISACA/CISM-JPN-mondaishu.html