問題集は全額返金保証付きのCISM日本語問題集最大50%オフ [Q134-Q151]

Share

問題集は全額返金保証付きのCISM日本語問題集最大50%オフ

更新されたのは2025年04月合格させるCISM日本語試験にはリアル練習テスト問題

質問 # 134
組織でセキュリティ意識向上プログラムを開発する際に考慮すべき最も重要なことは次のうちどれですか?

  • A. 確立された主要なリスク指標(KRI)
  • B. 業界ベンチマーク
  • C. ターゲットオーディエンスの人口統計
  • D. 対象となる月次成果物

正解:C


質問 # 135
次のBESTのうち、電子メールによる個人情報の漏洩の可能性を減らすものはどれですか?

  • A. メールの個人使用の禁止
  • B. 強力なユーザー認証プロトコル
  • C. メール暗号化
  • D. ユーザー認識トレーニング

正解:C


質問 # 136
侵入防止システム (IPS) は、過去 1 か月間でハッキングの試行回数が大幅に増加したと報告していますが、実際に侵害されたシステムはありません。情報セキュリティ管理者が最初に行うべきことは次のうちどれ?

  • A. ハッキングの試みの増加を上級管理職に報告してください。
  • B. IPS アラートを監視するためのリソースを追加します。
  • C. IPS によって識別されたイベントを検証します。
  • D. ハッキングの試みに関連するリスクを評価します。

正解:D


質問 # 137
組織内で新たなリスクを評価する上で、最も大きな課題は次のどれですか?

  • A. 効果のないセキュリティ制御
  • B. 脅威の特定が不完全
  • C. リスクフレームワークの欠如
  • D. 既知の脆弱性の存在

正解:B

解説:
The greatest challenge with assessing emerging risk in an organization is the incomplete identification of threats, as emerging risks are often new, unknown, or unfamiliar, and may not be fully understood or assessed. Incomplete identification of threats can lead to gaps in risk analysis and management, and expose the organization to unexpected or unprepared scenarios. The other options, such as lack of a risk framework, ineffective security controls, or presence of known vulnerabilities, are not specific to emerging risks, and may apply to any type of risk assessment. References:
* https://committee.iso.org/sites/tc262/home/projects/ongoing/iso-31022-guidelines-for-impl-2.html
* https://www.isaca.org/resources/news-and-trends/newsletters/atisaca/2023/volume-6/emerging-risk- analysis
* https://projectriskcoach.com/emerging-risks/


質問 # 138
最近のフィッシング攻撃の調査によると、何人かの従業員が仕事用の電子メールアドレスを使用して、侵害されたショッピングサイトに個人アカウントを作成していた。これを防ぐ最善の方法は何ですか

  • A. プロキシフィルタリングを使用して個人のショッピングサイトをブロックします。
  • B. 定期的に偽のフィッシングメールを従業員に送信し、応答を追跡します。
  • C. 従業員向けの情報セキュリティ意識向上トレーニングを実施します。
  • D. この状況に対処するためにインシデント対応計画を更新します。

正解:C


質問 # 139
情報セキュリティ予算の増加に関するビジネス ケースを最も適切にサポートするものは次のうちどれですか?

  • A. 費用対効果の分析結果
  • B. 同業組織との情報セキュリティ予算の比較
  • C. 情報セキュリティインシデントの発生頻度
  • D. ビジネスインパクト分析 (BIA) の結果

正解:A

解説:
Explanation
Cost-benefit analysis results are the best way to support the business case for an increase in the information security budget because they help to demonstrate the value and return on investment of the proposed security initiatives or projects. A cost-benefit analysis is a method of comparing the costs and benefits of different alternatives or options, taking into account both quantitative and qualitative factors. A cost-benefit analysis helps to justify the need and feasibility of the security budget, as well as to prioritize the security spending based on the expected outcomes and impacts. Therefore, cost-benefit analysis results are the correct answer.
References:
* https://www.cisa.gov/resources-tools/resources/business-case-security
* https://www.cisa.gov/resources-tools/resources/isc-best-practices-making-business-case-security
* https://risk3sixty.com/2020/09/21/how-to-build-a-business-case-for-security-initiatives-part-4/


質問 # 140
次のプロセスのどちらが新しい給与システムを実装する際に、情報セキュリティ上のリスクが評価されることを保証するための最良のに役立つだろうか?

  • A. 変更管理
  • B. 構成管理
  • C. インシデント管理
  • D. 問題管理

正解:A


質問 # 141
情報セキュリティ管理者は、最近のビジネスの変化に起因する新しい情報セキュリティリスクに対処する戦略を開発しました。次のうち、経営陣に戦略を提示するときに含めるべき最も重要なものはどれですか?

  • A. セキュリティリスクプロファイルに対する組織の変更の影響
  • B. 同業他社に対するベンチマークの結果
  • C. リスク軽減に必要なセキュリティ管理
  • D. ビジネスプロセスの変更に関連するコスト

正解:A


質問 # 142
次のどれが組織の情報セキュリティ戦略に最も大きな影響を与えますか?

  • A. 情報セキュリティ意識
  • B. 組織構造
  • C. 組織のリスク許容度
  • D. 業界のセキュリティ標準

正解:C

解説:
An organization's information security strategy should be aligned with its risk tolerance, which is the level of risk that an organization is willing to accept in pursuit of its objectives. The strategy should aim to balance the cost of security controls with the potential impact of security incidents on the organization's objectives.
Therefore, an organization's risk tolerance has the greatest influence on its information security strategy.
The organization's risk tolerance has the greatest influence on its information security strategy because it determines how much risk the organization is willing to accept and how much resources it will allocate to mitigate or transfer risk. The organizational structure, industry security standards, and information security awareness are important factors that affect the implementation and effectiveness of an information security strategy but not as much as the organization's risk tolerance.
An information security strategy is a high-level plan that defines how an organization will achieve its information security objectives and address its information security risks. An information security strategy should align with the organization's business strategy and reflect its mission, vision, values, and culture. An information security strategy should also consider the external and internal factors that influence the organization's information security environment such as laws, regulations, competitors, customers, suppliers, partners, stakeholders, employees etc.


質問 # 143
ビルド/購入の決定に情報セキュリティ要件を含めないと、次のことが必要になる可能性があります。

  • A. より厳格なソースプログラミング標準。
  • B. 企業標準に準拠した商用製品。
  • C. 運用プラットフォームのセキュリティスキャン
  • D. 運用環境での制御の補正。

正解:D


質問 # 144
ITシステムで処理される情報の適切な制御を確保するために、セキュリティ保護は主に以下に基づいている必要があります。

  • A. 全体的なITキャパシティと運用上の制約
  • B. 分類レベルと一致する基準
  • C. 効率的な技術処理の考慮事項
  • D. 確立されたガイドライン

正解:D


質問 # 145
インシデント対応テスト中の指定されたスポークスマンの主な責任は次のうちどれですか?

  • A. インシデント対応チームからの連絡の承認
  • B. インシデントの重大度を取締役会に伝える
  • C. 組織全体にコミュニケーションチャネルを確立する
  • D. コミュニケーションプロセスの有効性の評価

正解:C


質問 # 146
情報セキュリティ戦略を策定する最初のステップは次のうちどれですか?

  • A. 情報セキュリティリスクの許容レベルを決定する
  • B. 現在の状態に基づいてギャップ分析を実行します。
  • C. セキュリティのベースラインと制御を特定するためのロードマップを作成する
  • D. 情報セキュリティを推進する主要な関係者を特定する

正解:D

解説:
The first step in developing an information security strategy is to identify key stakeholders who can provide support, guidance and resources for information security initiatives. These stakeholders may include senior management, business unit leaders, legal counsel, audit and compliance officers and other relevant parties. By engaging these stakeholders early on, an information security manager can ensure that the strategy aligns with business objectives and expectations, as well as gain buy-in and commitment from them. Determining acceptable levels of risk, creating a roadmap and performing a gap analysis are all important steps in developing an information security strategy, but they should follow after identifying key stakeholders.


質問 # 147
サードパーティのセキュリティオペレーションセンターを選択する際に最も重要なものは次のうちどれですか?

  • A. インシデント対応計画
  • B. 補償条項
  • C. 独立したコントロールの評価
  • D. 事業継続計画

正解:C


質問 # 148
情報セキュリティ ガバナンス フレームワークを承認する責任は誰にありますか?

  • A. 取締役会
  • B. 企業リスク委員会
  • C. 最高情報責任者 (CIO)
  • D. 最高情報セキュリティ責任者 (ClSO)

正解:A

解説:
Explanation
The board of directors is ultimately responsible for the governance of the organization, including the approval of the information security governance framework and the oversight of its implementation and performance. References = CISM Review Manual, 16th Edition, Domain 1: Information Security Governance, Chapter 2: Establish and Maintain an Information Security Governance Framework, Section: Roles and Responsibilities of Senior Management and the Board of Directors1


質問 # 149
効果的な情報セキュリティガバナンスフレームワークを設計するための最も重要な考慮事項は次のうちどれですか?

  • A. 継続的監査サイクル
  • B. 定義されたセキュリティメトリック
  • C. セキュリティ管理の自動化
  • D. セキュリティポリシーの規定

正解:B


質問 # 150
アプリケーションのデータアクセス要件は、以下によって決定される必要があります。

  • A. コンプライアンス責任者。
  • B. 情報セキュリティマネージャー。
  • C. 事業主。
  • D. 法務部。

正解:C

解説:
説明
企業の所有者は、アプリケーションの最終的な責任を負います。法務部、コンプライアンス責任者、情報セキュリティ管理者はすべて助言できますが、最終的な責任は負いません。


質問 # 151
......

無料ダウンロードISACA CISM日本語リアル試験問題:https://www.jpntest.com/shiken/CISM-JPN-mondaishu

弊社を連絡する

我々は12時間以内ですべてのお問い合わせを答えます。

オンラインサポート時間:( UTC+9 ) 9:00-24:00
月曜日から土曜日まで

サポート:現在連絡