最新版無料体験を掴み取れ!ISACA CISM日本語問題集PDFは更新されたのは2024年 [Q126-Q146]

Share

最新版無料体験を掴み取れ!ISACA CISM日本語問題集PDFは更新されたのは2024年

最新リリースのCISM日本語問題集はIsaca Certification認証済みです

質問 # 126
資産の機密性を特定して分類する最も重要な理由は次のうちどれですか?

  • A. 情報セキュリティプログラムの予算を割り当てる
  • B. 保護制御のコストを削減するため
  • C. 情報セキュリティプログラムの範囲を決定する
  • D. 適切なコントロールを割り当てる

正解:D


質問 # 127
次のうち、情報セキュリティガバナンスとコーポレートガバナンスの整合性を示すベストはどれですか?

  • A. ビジネスユニット全体のセキュリティインシデントの平均数
  • B. ビジネス価値の観点から提供されるセキュリティプロジェクトの正当化
  • C. 企業規模のセキュリティインシデントの解決までの平均時間
  • D. 高リスク情報資産について特定された脆弱性の数

正解:B


質問 # 128
インシデント対応プログラム内で効果的なエスカレーションプロセスを可能にする次のBESTはどれですか?

  • A. 監視対象プログラムの指標
  • B. インシデント管理のための専用資金
  • C. 定義されたインシデントのしきい値
  • D. 適切なインシデント対応スタッフ

正解:C


質問 # 129
組織が災害復旧サービス (DRaaS) を使用する最も良い理由は次のうちどれですか?

  • A. オフサイトの設備を維持する必要がなくなります。
  • B. ビジネスがテストを実行する必要がなくなります。
  • C. ビジネスの年間コストを削減します。
  • D. 回収に伴うリスクを第三者に転嫁する。

正解:C


質問 # 130
ビジネスアプリケーションは、以下に基づいてディザスタリカバリテスト用に選択する必要があります。

  • A. テストされている障害点の数。
  • B. 緊急時のデスクトップチェックの結果。
  • C. 回復時間目標(RTO)。
  • D. 企業にとっての重要性。

正解:D


質問 # 131
リスク管理プログラムの主な目標は次のうちどれですか?

  • A. 組織のリスク選好度を下げる
  • B. 組織のポリシーへのコンプライアンスを管理します。
  • C. 脅威に対する予防管理を実施する
  • D. 固有のリスクによるビジネスへの影響を管理します。

正解:D


質問 # 132
パスワード標準への準拠を確保するための最善の方法は次のうちどれですか?

  • A. ユーザー認識プログラム
  • B. パスワード構文規則の自動適用
  • C. パスワード解読ソフトの使用
  • D. パスワード同期ソフトウェアの実装

正解:B


質問 # 133
事業継続計画 (BCP) のテストを実施する際に、最も重要な考慮事項は次のうちどれですか?

  • A. テストは重要なコンポーネントに対処します。
  • B. このテストは、実際のゴールデンタイムの処理条件をシミュレートします。
  • C. テストには IT メンバーがテスト プロセスに参加します。
  • D. テストは運用への影響を軽減するために計画されています。

正解:A

解説:
Explanation
The test addresses the critical components is the most important consideration while conducting a test of a business continuity plan (BCP), as it ensures that the test covers the essential functions, processes, and resources that are required to maintain or resume the organization's operations in the event of a disruption.
The test should also verify that the recovery objectives, such as recovery time objective (RTO) and recovery point objective (RPO), are met. (From CISM Review Manual 15th Edition) References: CISM Review Manual 15th Edition, page 178, section 4.3.2.1; CISSP Exam Cram: Business Continuity and Disaster Recovery Planning1, page 5, section Testing the Plan.


質問 # 134
インシデント後の情報セキュリティ レビューで最も優先度が高いのは次のうちどれですか?

  • A. 重要なリスク指標 (KRI) の更新
  • B. 実行されたアクションを十分に詳細に文書化する
  • C. インシデント対応の有効性の評価
  • D. インシデント対応チームのメンバーのパフォーマンスを評価する

正解:C

解説:
Explanation
During post-incident reviews, the highest priority should be given to evaluating the effectiveness of the incident response effort. This includes assessing the accuracy of the response to the incident, the timeliness of the response, and the efficiency of the response. It is important to assess the effectiveness of the response in order to identify areas for improvement and ensure that future responses can be more effective. Documenting the actions taken in sufficient detail, updating key risk indicators (KRIs), and evaluating the performance of incident response team members are all important components of a post-incident review, but evaluating incident response effectiveness should be given the highest priority.


質問 # 135
次のうちどれがベスト助け、情報セキュリティ管理の優先順位付けの修復活動は、規制要件を満たすためでしょうか?

  • A. 違反の年間トス期待(ALE)
  • B. 関連する制御のコスト
  • C. IT戦略との整合
  • D. 能力成熟度モデル行列

正解:D


質問 # 136
クラウドテクノロジー環境で、セキュリティインシデントの調査に最も大きな課題をもたらすのは次のうちどれですか?

  • A. ハードウェアへのアクセス
  • B. 圧縮された顧客データ
  • C. 非標準のイベントログ
  • D. データの暗号化

正解:C


質問 # 137
外部委託ベンダーが組織のビジネスクリティカルなデータを処理します
a。次のうちどれがクライアントの組織がベンダーのセキュリティ慣行の保証を取得するための最も効果的な方法ですか?

  • A. ベンダーが保有するセキュリティ証明書の確認
  • B. ベンダーのセキュリティ監査レポートの確認
  • C. 定期的な独立した第三者によるレビューが必要
  • D. ベンダーからのビジネス継続性プラン(BCP)が必要

正解:B


質問 # 138
スピアフィッシング攻撃は、ユーザーを騙してワークステーションにトロイの木馬をインストールさせるために使用されました。この攻撃を阻止するのに最も効果的だったのは次のうちどれでしょうか。

  • A. アプリケーション制御
  • B. ウェブサイトのブロック
  • C. ネットワーク暗号化
  • D. インターネットフィルタリング

正解:A


質問 # 139
組織の情報セキュリティ ガバナンス モードに最も大きな影響を与える要因は次のうちどれですか?

  • A. 外部委託プロセス
  • B. 企業文化
  • C. 従業員数
  • D. セキュリティ予算

正解:B

解説:
Explanation
The corporate culture of an organization is the set of values, beliefs, norms, and behaviors that shape how the organization operates and interacts with its stakeholders. The corporate culture can have a significant impact on an organization's information security governance mode, which is the way the organization establishes, implements, monitors, and evaluates its information security policies, standards, and objectives. A strong information security governance mode requires a supportive corporate culture that fosters a shared vision, commitment, and accountability for information security among all levels of the organization. A supportive corporate culture can also help to overcome resistance to change, promote collaboration and communication, encourage innovation and learning, and enhance trust and confidence in information security12. References = CISM Review Manual (Digital Version), Chapter 1: Information Security Governance CISM Review Manual (Print Version), Chapter 1: Information Security Governance


質問 # 140
アクセス制御ソフトウェアへの最近の投資が成功したかどうかを判断するための最良の方法はどれですか?

  • A. アクセス制御ソフトウェアの上級管理職による承認
  • B. ソフトウェアに実装された主要リスク指標 (KRI) の数のレビュー
  • C. ソフトウェアによって保護されるシステムのビジネス影響分析 (BIA)
  • D. ソフトウェアのインストール前後のセキュリティインシデントの比較

正解:D


質問 # 141
頻繁に発生するインシデントがユーザーのセキュリティ意識向上トレーニング プログラムに反映されるようにする最善の方法は、次のことを含めることです。

  • A. ヘルプ デスク リクエストの例。
  • B. 出口面接の結果。
  • C. 以前のトレーニング セッション。
  • D. セキュリティアンケートへの回答。

正解:A

解説:
Explanation
The best way to ensure that frequently encountered incidents are reflected in the user security awareness training program is to include examples of help desk requests. Help desk requests are requests for assistance or support from users who encounter problems or issues related to information security, such as password resets, malware infections, phishing emails, unauthorized access, data loss, or system errors. Help desk requests can provide valuable insights into the types, frequencies, and impacts of the incidents that affect the users, as well as the users' knowledge, skills, and behaviors regarding information security. By including examples of help desk requests in the user security awareness training program, the information security manager can achieve the following benefits12:
Increase the relevance and effectiveness of the training content: By using real-life scenarios and cases that the users have experienced or witnessed, the information security manager can make the training content more relevant, engaging, and applicable to the users' needs and situations. The information security manager can also use the examples of help desk requests to illustrate the consequences and costs of the incidents, and to highlight the best practices and solutions to prevent or resolve them. This can help the users to understand the importance and value of information security, and to improve their knowledge, skills, and attitudes accordingly.
Identify and address the gaps and weaknesses in the training program: By analyzing the patterns and trends of the help desk requests, the information security manager can identify and address the gaps and weaknesses in the existing training program, such as outdated or inaccurate information, insufficient or ineffective coverage of topics, or lack of feedback or evaluation. The information security manager can also use the examples of help desk requests to measure and monitor the impact and outcomes of the training program, such as changes in the number, type, or severity of the incidents, or changes in the users' satisfaction, performance, or behavior.
Enhance the communication and collaboration with the users and the help desk staff: By including examples of help desk requests in the user security awareness training program, the information security manager can enhance the communication and collaboration with the users and the help desk staff, who are the key stakeholders and partners in information security. The information security manager can use the examples of help desk requests to solicit feedback, suggestions, or questions from the users and the help desk staff, and to provide them with timely and relevant information, guidance, or support. The information security manager can also use the examples of help desk requests to recognize and appreciate the efforts and contributions of the users and the help desk staff in reporting, responding, or resolving the incidents, and to encourage and motivate them to continue their involvement and participation in information security.
The other options are not the best way to ensure that frequently encountered incidents are reflected in the user security awareness training program, as they are less reliable, relevant, or effective sources of information.
Results of exit interviews are feedback from employees who are leaving the organization, and they may not reflect the current or future incidents that the remaining or new employees may face. Previous training sessions are records of the past training activities, and they may not capture the changes or updates in the information security environment, threats, or requirements. Responses to security questionnaires are answers to predefined questions or surveys, and they may not cover all the possible or emerging incidents that the users may encounter or experience12. References = Information Security Awareness Training: Best Practices - Infosec Resources, How to Create an Effective Security Awareness Training Program - Infosec Resources, Security Awareness Training: How to Build a Successful Program - ISACA, Security Awareness Training: How to Educate Your Employees - ISACA


質問 # 142
情報セキュリティマネージャーが上級管理職のコミットメントを求めている場合、次のうちどれが最も重要かを知っていますか?

  • A. 実装タスク
  • B. セキュリティコスト
  • C. セキュリティ技術の要件
  • D. 技術的な脆弱性

正解:A


質問 # 143
上級管理職は、仮想プライベートネットワーク(VPN)接続を使用して、オフサイトで働く従業員を承認しています。情報セキュリティ管理者が定期的に行うことは最も重要です:

  • A. リスク評価を実行します。
  • B. セキュリティポリシーを確認します。
  • C. 費用便益分析を実行します。
  • D. ファイアウォールの構成を確認します。

正解:A


質問 # 144
インシデント対応チームのメンバー向けのトレーニングカリキュラムの主な焦点は次のとおりです。

  • A. 特定のロールトレーニング
  • B. セキュリティ意識
  • C. 技術トレーニング
  • D. 外部企業コミュニケーション

正解:A


質問 # 145
次のうち、情報セキュリティ管理者になるべきものはどれですか。
情報資産が適切に分類されているかどうかを判断する際の最も重要な考慮事項は?

  • A. 保護レベル
  • B. 情報の所有権
  • C. ビジネスへの価値
  • D. セキュリティポリシーの要件

正解:C


質問 # 146
......

最新のCISM日本語試験問題集でISACA試験問題にトレーニング:https://www.jpntest.com/shiken/CISM-JPN-mondaishu

弊社を連絡する

我々は12時間以内ですべてのお問い合わせを答えます。

オンラインサポート時間:( UTC+9 ) 9:00-24:00
月曜日から土曜日まで

サポート:現在連絡