[2024年更新]無料CISM日本語試験問題集は試験を合格するには超簡単 [Q370-Q393]

Share

[2024年更新]無料CISM日本語試験問題集はパス試験は超簡単

CISM日本語試験問題集でCISM日本語練習テスト問題

質問 # 370
組織には、すべての犯罪行為を訴追するポリシーがあります。従業員が会社のコンピューターを使用して詐欺を犯した疑いがある場合、情報セキュリティマネージャーにとって最も重要なことは何ですか?

  • A. 上級管理職に状況が通知されます。
  • B. 従業員のログファイルがバックアップされます。
  • C. インシデント対応計画が開始されます。
  • D. フォレンジックプロセスがすぐに開始されます。

正解:B


質問 # 371
アプリケーションシステムは顧客の機密データを保存し、暗号化は実用的ではありません。データ開示から保護するための最善の方法は次のとおりです。

  • A. シングルサインオン。
  • B. 機密保持契約(NDA)。
  • C. 多要素アクセス制御。
  • D. アクセスログの定期的なレビュー。

正解:D


質問 # 372
ビジネスユニットが情報セキュリティガバナンスフレームワークに準拠していることを確認するための最も効果的な方法は次のうちどれですか?

  • A. ビジネス影響分析(BIA)の実施
  • B. セキュリティ評価とギャップ分析の実行
  • C. セキュリティ要件とプロセスの統合
  • D. 情報セキュリティ意識向上トレーニングの実施

正解:D


質問 # 373
次のうち、ソーシャルエンジニアリング攻撃の潜在的な影響を減らすものはどれですか?

  • A. 倫理的理解の促進
  • B. 効果的なパフォーマンスインセンティブ
  • C. 規制要件の順守
  • D. セキュリティ認識プログラム

正解:D

解説:
説明
ソーシャルエンジニアリングはユーザーの欺ceptionに基づいているため、最善の対策または防御はセキュリティ認識プログラムです。他の選択肢はユーザー中心ではありません。


質問 # 374
次のMOSTのうち、組織が情報セキュリティガバナンスとコーポレートガバナンスを調整するのに効果的に役立つのはどれですか?

  • A. セキュリティパフォーマンスメトリクスの開発
  • B. ビジネス目標を達成するためにグローバルセキュリティ標準を採用する
  • C. IT戦略に基づくセキュリティイニシアチブの優先順位付け
  • D. イネーブラー10がビジネス目標を達成する際のセキュリティの促進

正解:D


質問 # 375
情報セキュリティマネージャーは、新しい情報セキュリティ戦略を開発しています。次の機能のうち、戦略をレビューし、ビジネスの調整のためのガイダンスを提供するための最良のリソースとして役立つのはどれですか?

  • A. 取締役会
  • B. 法務部門
  • C. 運営委員会
  • D. 内部監査

正解:C


質問 # 376
次のうちどれが企業のウェブサイトの違反を処理するための最良の準備を提供しますか?

  • A. サイバー賠償責任保険の補償範囲のレビュー
  • B. Webサーバー侵入テスト
  • C. 文書化されたデータ復旧手順
  • D. インシデント対応テスト

正解:D


質問 # 377
Webアプリケーション開発で脅威モデリングを使用する主な目的は、次のとおりです。

  • A. デザインにセキュリティを組み込みます。
  • B. アプリケーション開発標準を開発します。
  • C. アプリケーションのソースコードを確認します。
  • D. 侵入テストが必要かどうかを判断します。

正解:A


質問 # 378
組織は、認証局による大幅な改訂を受けたセキュリティ標準を使用しています。古いバージョンの標準は、認定を維持したい組織には使用されなくなります。
次のうちどれを最初にすべきか
行動方針?

  • A. 新しい標準を上級幹部に伝えます。
  • B. ビジネスへの適用性について新しい標準を検討します。
  • C. ポリシーを変更して、新しい要件が確実にカバーされるようにします。
  • D. 認定を維持するためのコストを評価します。

正解:B

解説:
Explanation
Reviewing the new standard for applicability to the business is the first course of action, as it helps to understand the changes, gaps, and impacts of the revision on the organization's security posture, compliance status, and business objectives. Evaluating the cost of maintaining the certification, modifying policies to ensure new requirements are covered, and communicating the new standard to senior leadership are important steps, but they should be done after reviewing the new standard for applicability to the business.
References = CISM Review Manual 2022, page 361; CISM Exam Content Outline, Domain 1, Task 1.2


質問 # 379
次のうち、セキュリティインシデントエスカレーションポリシーの構成要素である可能性が最も高いのはどれですか?

  • A. メディアへの声明のサンプルスクリプトとプレスリリース
  • B. さまざまなグループに警告するタイミングの決定基準
  • C. 停止期間のみに関連する重大度ランク付けメカニズム
  • D. 主要な管理者の名前と電話番号

正解:B


質問 # 380
情報セキュリティガバナンスのフレームワークを実装する際に、最初に確立する必要があるのは次のうちどれですか?

  • A. セキュリティポリシー
  • B. セキュリティインシデント管理チーム
  • C. セキュリティアーキテクチャ
  • D. セキュリティ意識向上トレーニング プログラム

正解:C

解説:
Explanation
This is the most urgent and effective action to prevent further damage or compromise of the organization's network and data. The other options are less important or irrelevant in this situation.
According to How to identify suspicious insider activity using Active Directory, one of the steps to detect and respond to suspicious activity is to isolate the affected device from the network. This can be done by disabling the network adapter, unplugging the network cable, or blocking the device's IP address on the firewall1. This will prevent the device from communicating with any malicious actors or spreading malware to other devices on the network.
`


質問 # 381
残留リスクを受け入れるかどうかを決定する際に最も重要な基準は次のうちどれですか?

  • A. 追加緩和のコスト
  • B. 年間損失期待値 (ALE)
  • C. 年間発生率
  • D. 資産の入れ替えにかかる費用

正解:D


質問 # 382
セキュリティ戦略を継続的に監視する主な理由は次のとおりです。

  • A. リソース割り当てを最適化します。
  • B. 情報セキュリティのための資金を割り当てる
  • C. 戦略の実装を評価します。
  • D. メリットが実現されていることを確認します。

正解:C


質問 # 383
外部向けのWebページおよび主要な金融サービスのための特定の暗号化プロトコルを使用する組織。セキュリティ会社は、暗号化マネージャーの重大なセキュリティ欠陥を公表しますか?

  • A. インシデント対応チームを活性化します。
  • B. 潜在的に脆弱なシステムを分離します。
  • C. リスク評価を実行します。
  • D. 脆弱性を修正します。

正解:B


質問 # 384
情報セキュリティの有効性に関する指標の開発において最も重要なものは次のうちどれですか?

  • A. 定性的リスク評価結果の使用
  • B. 標準のレポートツールを使用する
  • C. 定量的測定の使用
  • D. 明確に定義された目標を使用する

正解:D


質問 # 385
オフィスでのカメラの使用を禁止するポリシーに違反して、従業員には Web カメラが有効になっているスマートフォンとタブレット コンピューターが支給されました。次のうち、情報セキュリティ管理者の最初の行動方針はどれですか?

  • A. 根本原因分析を実行します。
  • B. リスク評価を実施し、
  • C. ポリシーを修正します。
  • D. 利用規定を伝えます。

正解:B

解説:
Explanation
= The information security manager's first course of action in this situation should be to conduct a risk assessment, which is a process of identifying, analyzing, and evaluating the information security risks that arise from the violation of the policy prohibiting the use of cameras at the office. The risk assessment can help to determine the likelihood and impact of the unauthorized or inappropriate use of the cameras on the smartphones and tablet computers, such as capturing, transmitting, or disclosing sensitive or confidential information, compromising the privacy or security of the employees, customers, or partners, or violating the legal or regulatory requirements. The risk assessment can also help to identify and prioritize the appropriate risk treatment options, such as implementing technical, administrative, or physical controls to disable, restrict, or monitor the camera usage, enforcing the policy compliance and awareness, or revising the policy to reflect the current business needs and environment. The risk assessment can also help to communicate and report the risk level and status to the senior management and the relevant stakeholders, and to provide feedback and recommendations for improvement and optimization of the policy and the risk management process.
Revising the policy, performing a root cause analysis, and communicating the acceptable use policy are all possible courses of action that the information security manager can take after conducting the risk assessment, but they are not the first ones. Revising the policy is a process of updating and modifying the policy to align with the business objectives and strategy, to address the changes and challenges in the business and threat environment, and to incorporate the feedback and suggestions from the risk assessment and the stakeholders.
Performing a root cause analysis is a process of investigating and identifying the underlying causes and factors that led to the violation of the policy, such as the lack of awareness, training, or enforcement, the inconsistency or ambiguity of the policy, or the conflict or gap between the policy and the business requirements or expectations. Communicating the acceptable use policy is a process of informing and educating the employees and the other users of the smartphones and tablet computers about the purpose, scope, and content of the policy, the roles and responsibilities of the users, the benefits and consequences of complying or violating the policy, and the methods and channels of reporting or resolving any policy issues or incidents. References = CISM Review Manual 15th Edition, pages 51-531; CISM Practice Quiz, question 1482


質問 # 386
成熟した情報セキュリティ プログラムを最もよく示すものは次のうちどれですか?

  • A. セキュリティインシデントは適切に管理されています。
  • B. セキュリティ監査の結果が減少します。
  • C. セキュリティリソースが最適化されています。
  • D. 安全保障支出が予算を下回っています。

正解:C

解説:
Explanation
A mature information security program is one that is aligned with the business strategy, objectives, and culture, and that delivers value to the organization by effectively managing the information security risks and enhancing the security posture. Optimizing the security resources means that the program uses the available human, financial, and technical resources in the most efficient and effective way, and that it continuously monitors and improves the performance and maturity of the security processes and controls.
References = CISM Review Manual 2022, page 331; CISM Exam Content Outline, Domain 1, Knowledge Statement 1.22; What is a Mature Information Security Program?; How to Measure the Maturity of Your Cybersecurity Program


質問 # 387
事前の承認なしに、トレーニング部門が無料のクラウドベースのコラボレーションサイトに会社を登録し、従業員に使用を依頼しました。情報セキュリティ管理者の最良の対応は次のうちどれですか?

  • A. 活動を上級管理職に報告します。
  • B. リスク記録を更新し、情報セキュリティ戦略を確認します。
  • C. リスク評価を実施し、影響分析を開発します。
  • D. サイトの一時的な使用を許可し、データ漏洩を監視します。

正解:B


質問 # 388
情報セキュリティ管理者は、実稼働サーバーへの特権のある従業員のアクセス要求が承認されていることを特定しました。ただし、ユーザーのアクションは記録されません。この状況で最も懸念すべき点は次のうちどれですか?

  • A. 説明責任の欠如
  • B. 可用性の欠如
  • C. 不正な認証
  • D. 認証が不十分です

正解:A

解説:
Explanation
The greatest concern with the situation of privileged employee access requests to production servers being approved but not logged is the lack of accountability, which means the inability to trace or verify the actions and decisions of the privileged users. Lack of accountability can lead to security risks such as unauthorized changes, data breaches, fraud, or misuse of privileges. Logging user actions is a key component of privileged access management (PAM), which helps to monitor, detect, and prevent unauthorized privileged access to critical resources. The other options, such as lack of availability, improper authorization, or inadequate authentication, are not directly related to the situation of not logging user actions. References:
* https://www.microsoft.com/en-us/security/business/security-101/what-is-privileged-access-management-p
* https://www.ekransystem.com/en/blog/privileged-user-monitoring-best-practices
* https://www.beyondtrust.com/resources/glossary/privileged-access-management-pam


質問 # 389
機密性の高いシステムのシステムログと監査ログを保存する必要があります

  • A. 共有内部サーバー上
  • B. 各サーバーの暗号化されたフォルダー内。
  • C. コールドサイトサーバー上。
  • D. 専用の暗号化されたストレージサーバー上で、

正解:D


質問 # 390
モノのインターネット(loT)デバイスを保護する上で最も難しい側面は次​​のうちどれですか?

  • A. ポリシーを更新してloTデバイスを含める
  • B. loTアーキテクチャの多様性の管理
  • C. 多くのベンダーの評判を評価する
  • D. loTアーキテクチャに関するスタッフのトレーニング

正解:B


質問 # 391
ベンダーのリスク管理プロセスについて報告するパフォーマンスメトリックを選択するときに、最初に実行する必要があるのは次のうちどれですか?

  • A. データの所有者を特定します。
  • B. データソースを選択します
  • C. 機密保持要件を確認します。
  • D. 対象読者を特定します。

正解:D

解説:
"A better approach is the development of operational metrics, which are usually easily discovered and measured. The next step is to transform those operational metrics into different metrics, stated in business terms, FOR BUSINESS AUDIENCES. In a given organization, a security program might employ two, three, or more layers of metrics, usually related to each other, and stated in relevant technical or business terms for each RESPECTIVE AUDIENCE." - CISM All-In-One Study Guide, P.H. Gregory, 1st Edition


質問 # 392
リスクを許容レベルまで軽減するための最適なコントロールを選択する場合、情報セキュリティ管理者の決定は、主に次の要因によって行われる必要があります。

  • A. 制御フレームワーク
  • B. 費用便益分析、
  • C. 規制要件。
  • D. ベスト プラクティス。

正解:C


質問 # 393
......

CISM日本語試験問題集でCISM日本語練習テスト問題:https://www.jpntest.com/shiken/CISM-JPN-mondaishu

弊社を連絡する

我々は12時間以内ですべてのお問い合わせを答えます。

オンラインサポート時間:( UTC+9 ) 9:00-24:00
月曜日から土曜日まで

サポート:現在連絡