[2025年更新]CCZT試験問題集でテストエンジン練習テスト問題 [Q24-Q45]

Share

[2025年更新]CCZT試験問題集でテストエンジン練習テスト問題

合格できるCCZT試験[2025年03月09日]最新62問題


Cloud Security Alliance CCZT 認定試験の出題範囲:

トピック出題範囲
トピック 1
  • ソフトウェア定義境界: このトピックでは、ゼロ トラストにおけるソフトウェア定義境界 (SDP) の利点、SDP の導入に関する考慮事項、ゼロ トラストにおける SDP の使用例について質問します。
トピック 2
  • ゼロ トラストの基本概念: ゼロ トラスト セキュリティの中核となる原則について説明します。
トピック 3
  • ゼロ トラストの実装: このトピックでは、ゼロ トラスト アーキテクチャの展開に焦点を当てます。

 

質問 # 24
Which architectural consideration needs to be taken into account
while deploying SDP? Select the best answer.

  • A. How SDP deployment fits into external vendor assessment.
  • B. How SDP deployment fits into existing human resource
    management systems.
  • C. How SDP deployment fits into existing network topologies and
    technologies.
  • D. How SDP deployment fits into application validation.

正解:C

解説:
A key architectural consideration that needs to be taken into account while deploying SDP is how SDP deployment fits into existing network topologies and technologies. This is because SDP deployment may require changes or adaptations to the existing network infrastructure, such as routers, switches, firewalls, VPNs, etc. SDP deployment may also affect the network performance, availability, scalability, and resilience.
Therefore, it is important to assess the impact and compatibility of SDP deployment with the existing network topologies and technologies, and to plan and design the SDP deployment accordingly.
References = Certificate of Competence in Zero Trust (CCZT) - Cloud Security Alliance, Zero Trust Training (ZTT) - Module 7: Network Infrastructure and SDP


質問 # 25
ZTA utilizes which of the following to improve the network's security posture?

  • A. Encryption and compliance analytics
  • B. Micro-segmentation and encryption
  • C. Compliance analytics and network communication
  • D. Network communication and micro-segmentation

正解:B

解説:
ZTA uses micro-segmentation to divide the network into smaller, isolated segments that can prevent unauthorized access and contain lateral movement. ZTA also uses encryption to protect data in transit and at rest from eavesdropping and tampering.


質問 # 26
Scenario: A multinational org uses ZTA to enhance security. They
collaborate with third-party service providers for remote access to
specific resources. How can ZTA policies authenticate third-party
users and devices for accessing resources?

  • A. ZTA policies should primarily educate users about secure practices
    and promote strong authentication for services accessed via mobile devices to prevent data compromise.
  • B. ZTA policies can implement robust encryption and secure access
    controls to prevent access to services from stolen devices, ensuring
    that only legitimate users can access mobile services.
  • C. ZTA policies should prioritize securing remote users through
    technologies like virtual desktop infrastructure (VDI) and corporate
    cloud workstation resources to reduce the risk of lateral movement via
    compromised access controls.
  • D. ZTA policies can be configured to authenticate third-party users
    and their devices, determining the necessary access privileges for
    resources while concealing all other assets to minimize the attack
    surface.

正解:D

解説:
ZTA is based on the principle of never trusting any user or device by default, regardless of their location or ownership. ZTA policies can use various methods to verify the identity and context of third-party users and devices, such as tokens, certificates, multifactor authentication, device posture assessment, etc. ZTA policies can also enforce granular and dynamic access policies that grant the minimum necessary privileges to third-party users and devices for accessing specific resources, while hiding all other assets from their view.
This reduces the attack surface and prevents unauthorized access and lateral movement within the network.


質問 # 27
Network architects should consider__________ before selecting an SDP model.
Select the best answer.

  • A. gateways
  • B. leadership buy-in
  • C. their use case
  • D. cost

正解:C

解説:
Explanation
Different SDP deployment models have different advantages and disadvantages depending on the organization's use case, such as the type of resources to be protected, the location of the clients and servers, the network topology, the scalability, the performance, and the security requirements. Network architects should consider their use case before selecting an SDP model that best suits their needs and goals.
References =
Certificate of Competence in Zero Trust (CCZT) prepkit, page 21, section 3.1.2
6 SDP Deployment Models to Achieve Zero Trust | CSA, section "Deployment Models Explained" Software-Defined Perimeter (SDP) and Zero Trust | CSA, page 7, section 3.1 Why SDP Matters in Zero Trust | SonicWall, section "SDP Deployment Models"


質問 # 28
In SaaS and PaaS, which access control method will ZT help define
for access to the features within a service?

  • A. Role-based access control (RBAC)
  • B. Privilege-based access control (PBAC)
  • C. Data-based access control (DBAC)
  • D. Attribute-based access control (ABAC)

正解:D


質問 # 29
SDP features, like multi-factor authentication (MFA), mutual
transport layer security (mTLS), and device fingerprinting, protect
against

  • A. code injections
  • B. domain name system (DNS) poisoning
  • C. certificate forgery
  • D. phishing

正解:D

解説:
SDP features, like multi-factor authentication (MFA), mutual transport layer security (mTLS), and device fingerprinting, protect against phishing attacks by verifying the identity and authenticity of both the user and the device before granting access to a resource. Phishing attacks are attempts to trick users into revealing their credentials or other sensitive information by impersonating a legitimate entity or service1. SDP features can prevent phishing attacks by:
* MFA: MFA is a security mechanism that requires a user to provide more than one piece of evidence to prove their identity, such as a password, a one-time code, a biometric factor, or a physical token2. MFA can protect against phishing attacks by making it harder for attackers to access a resource even if they manage to obtain the user's password or other credentials2.
* mTLS: mTLS is a security protocol that enables mutual authentication and encryption between two parties, such as a client and a server3. mTLS can protect against phishing attacks by ensuring that both the client and the server have valid and trusted certificates, and by preventing attackers from intercepting or modifying the communication between them3.
* Device fingerprinting: Device fingerprinting is a technique that identifies and verifies a device based on its unique characteristics, such as its operating system, browser, IP address, or hardware configuration4. Device fingerprinting can protect against phishing attacks by allowing only authorized devices to access a resource, and by detecting any anomalies or changes in the device's attributes that may indicate a compromise4.
References =
* What is Phishing? | How to Identify & Prevent Phishing Attacks | Cloudflare
* What is Multi-Factor Authentication (MFA)? | Cloudflare
* What is Mutual TLS (mTLS)? | Cloudflare
* What is Device Fingerprinting? | Cloudflare


質問 # 30
Which security tools or capabilities can be utilized to automate the
response to security events and incidents?

  • A. Security information and event management (SIEM)
  • B. Single packet authorization (SPA)
  • C. Multi-factor authentication (MFA)
  • D. Security orchestration, automation, and response (SOAR)

正解:D

解説:
SOAR is a collection of software programs developed to bolster an organization's cybersecurity posture.
SOAR tools can automate the response to security events and incidents by executing predefined workflows or playbooks, which can include tasks such as alert triage, threat detection, containment, mitigation, and remediation. SOAR tools can also orchestrate the integration of various security tools and data sources, and provide centralized dashboards and reporting for security operations.
References =
* Certificate of Competence in Zero Trust (CCZT) prepkit, page 23, section 3.2.2
* Security Orchestration, Automation and Response (SOAR) - Gartner
* Security Automation: Tools, Process and Best Practices - Cynet, section "What are the different types of security automation tools?"
* Introduction to automation in Microsoft Sentinel


質問 # 31
ZTA reduces management overhead by applying a consistent
access model throughout the environment for all assets. What can
be said about ZTA models in terms of access decisions?

  • A. The traffic of the access workflow must contain all the parameters
    for the policy enforcement points.
  • B. Access revocation data will be passed from the policy decision
    points to the policy enforcement points.
  • C. The traffic of the access workflow must contain all the parameters
    for the policy decision points.
  • D. Each access request is handled just-in-time by the policy decision
    points.

正解:D

解説:
Explanation
ZTA models in terms of access decisions are based on the principle of "never trust, always verify", which means that each access request is handled just-in-time by the policy decision points. The policy decision points are the components in a ZTA that evaluate the policies and the contextual data collected from various sources, such as the user identity, the device posture, the network location, the resource attributes, and the environmental factors, and then generate an access decision. The access decision is communicated to the policy enforcement points, which enforce the decision on the resource. This way, ZTA models apply a consistent access model throughout the environment for all assets, regardless of their location, type, or ownership.
References =
Certificate of Competence in Zero Trust (CCZT) prepkit, page 14, section 2.2.2 What Is Zero Trust Architecture (ZTA)? - F5, section "Policy Engine" Zero trust security model - Wikipedia, section "What Is Zero Trust Architecture?" Zero Trust Maturity Model | CISA, section "Zero trust security model"


質問 # 32
In a ZTA, what is a key difference between a policy decision point
(PDP) and a policy enforcement point (PEP)?

  • A. A PDP measures incoming signals against a set of access
    determination criteria. A PEP uses incoming signals to open or close a
    connection.
  • B. A PDP measures incoming signals and makes dynamic risk
    determinations. A PEP uses incoming signals to make static risk
    determinations.
  • C. A PDP measures incoming control plane authentication signals. A
    PEP measures incoming data plane authorization signals.
  • D. A PDP measures incoming signals in an untrusted zone. A PEP
    measures incoming signals in an implicit trust zone.

正解:A

解説:
In a ZTA, a policy decision point (PDP) is a logical component that evaluates the incoming signals from an entity requesting access to a resource against a set of access determination criteria, such as identity, context, device, location, and behavior1. A PDP then makes a decision to grant or deny access, or to request additional information or verification, based on the policies defined by the policy administrator1. A policy enforcement point (PEP) is a logical component that uses the incoming signals from the PDP to open or close a connection between the entity and the resource1. A PEP acts as a gateway or intermediary that enforces the decision made by the PDP and prevents unauthorized or risky access2.
References =
* Zero Trust Architecture | NIST
* Policy Enforcement Point (PEP) - Pomerium


質問 # 33
When implementing ZTA, why is it important to collect logs from
different log sources?

  • A. Collecting logs supports change management, incident
    management, visibility and analytics.
  • B. Collecting logs supports micro-segmentation, device security, and
    governance.
  • C. Collecting logs supports investigations, dashboard creation, and
    policy adjustments.
  • D. Collecting logs supports recording transaction flows, mapping
    transaction flows, and detecting changes in transaction flows.

正解:A

解説:
Explanation
Log collection is an essential component of ZTA, as it provides the data needed to monitor, audit, and improve the security posture of the network. By collecting logs from different sources, such as devices, applications, firewalls, gateways, and policies, ZTA can support various functions, such as:
Change management: Logs can help track and document any changes made to the network configuration, policies, or resources, and assess their impact on the security and performance of the network. Logs can also help identify and revert any unauthorized or erroneous changes that may compromise the network integrity1.
Incident management: Logs can help detect and respond to any security incidents, such as breaches, attacks, or anomalies, that may occur in the network. Logs can provide the evidence and context needed to investigate the root cause, scope, and impact of the incident, and to take appropriate remediation actions2.
Visibility and analytics: Logs can help provide a comprehensive and granular view of the network activity, performance, and behavior. Logs can be used to generate dashboards, reports, and alerts that can help measure and improve the network security and efficiency. Logs can also be used to apply advanced analytics techniques, such as machine learning, to identify patterns, trends, and insights that can help optimize the network operations and security3.
References =
Zero Trust Architecture: Data Sources
Zero Trust Architecture: Incident Response
Zero Trust Architecture: Visibility and Analytics


質問 # 34
Of the following options, which risk/threat does SDP mitigate by
mandating micro-segmentation and implementing least privilege?

  • A. Broken access control
  • B. Identification and authentication failures
  • C. Injection
  • D. Security logging and monitoring failures

正解:A

解説:
Explanation
SDP mitigates the risk of broken access control by mandating micro-segmentation and implementing least privilege. Micro-segmentation divides the network into smaller, isolated segments that can prevent unauthorized access and contain lateral movement. Least privilege grants the minimum necessary access to users and devices for specific resources, while hiding all other assets from their view. This reduces the attack surface and prevents attackers from exploiting weak or misconfigured access controls


質問 # 35
What should an organization's data and asset classification be based on?

  • A. Recovery of data
  • B. History of data
  • C. Location of data
  • D. Sensitivity of data

正解:D

解説:
Explanation
Data and asset classification should be based on the sensitivity of data, which is the degree to which the data requires protection from unauthorized access, modification, or disclosure. Data sensitivity is determined by the potential impact of data loss, theft, or corruption on the organization, its customers, and its partners. Data sensitivity can also be influenced by legal, regulatory, and contractual obligations.
References =
Certificate of Competence in Zero Trust (CCZT) prepkit, page 10, section 2.1.1 Identify and protect sensitive business data with Zero Trust, section 1 Secure data with Zero Trust, section 1 SP 800-207, Zero Trust Architecture, page 9, section 3.2.1


質問 # 36
According to NIST, what are the key mechanisms for defining,
managing, and enforcing policies in a ZTA?

  • A. Data access policy, public key infrastructure (PKI), and identity and access management (IAM)
  • B. Policy decision point (PDP), policy enforcement point (PEP), and
    policy information point (PIP)
  • C. Control plane, data plane, and application plane
  • D. Policy engine (PE), policy administrator (PA), and policy broker (PB)

正解:B

解説:
Explanation
According to NIST, the key mechanisms for defining, managing, and enforcing policies in a ZTA are the policy decision point (PDP), the policy enforcement point (PEP), and the policy information point (PIP). The PDP is the component that evaluates the policies and the contextual data collected from various sources and generates an access decision. The PEP isthe component that enforces the access decision on the resource. The PIP is the component that provides the contextual data to the PDP, such as the user identity, the device posture, the network location, the resource attributes, and the environmental factors.
References =
Zero Trust Architecture Project - NIST Computer Security Resource Center, slide 9 What Is Zero Trust Architecture (ZTA)? - F5, section "Policy Engine" Zero Trust Frameworks Architecture Guide - Cisco, page 4, section "Policy Decision Point"


質問 # 37
To successfully implement ZT security, two crucial processes must
be planned and aligned with existing access procedures that the ZT
implementation might impact. What are these two processes?

  • A. Business continuity planning (BCP) and disaster recovery (DR)
  • B. Incident and response management
  • C. Training and awareness programs
  • D. Vulnerability disclosure and patching management

正解:C


質問 # 38
Which of the following is a key principle of ZT and is required for its implementation?

  • A. Implementing strong anti-phishing email filters
  • B. Making no assumptions about an entity's trustworthiness when it
    requests access to a resource
  • C. Encrypting all communications between any two endpoints
  • D. Requiring that authentication and explicit authorization must occur
    after network access has been granted

正解:B

解説:
Explanation
One of the core principles of Zero Trust (ZT) is to "never trust, always verify" every request for access to a resource, regardless of where it originates or what resource it accesses1. This means that ZT does not rely on implicit trust based on network perimeters, device types, or user roles, but rather on explicit verification based on multiple data points, such as user identity, device health, location, service, data classification, and anomalies1.
References =
Zero Trust Architecture | NIST
Zero Trust Model - Modern Security Architecture | Microsoft Security
How To Implement Zero Trust: 5-steps Approach & its challenges - Fortinet


質問 # 39
In SaaS and PaaS, which access control method will ZT help define
for access to the features within a service?

  • A. Role-based access control (RBAC)
  • B. Privilege-based access control (PBAC)
  • C. Data-based access control (DBAC)
  • D. Attribute-based access control (ABAC)

正解:D

解説:
ABAC is an access control method that uses attributes of the requester, the resource, the environment, and the action to evaluate and enforce policies. ABAC allows for fine-grained and dynamic access control based on the context of the request, rather than predefined roles or privileges. ABAC is suitable for SaaS and PaaS, where the features within a service may vary depending on the customer's needs, preferences, and subscription level. ABAC can help implement ZT by enforcing the principle of least privilege and verifying every request based on multiple factors.
References =
* Attribute-Based Access Control (ABAC) Definition
* General Access Control Guidance for Cloud Systems
* A Guide to Secure SaaS Access Control Within an Organization


質問 # 40
Scenario: A multinational org uses ZTA to enhance security. They
collaborate with third-party service providers for remote access to
specific resources. How can ZTA policies authenticate third-party
users and devices for accessing resources?

  • A. ZTA policies should primarily educate users about secure practices
    and promote strong authentication for services accessed via mobile
    devices to prevent data compromise.
  • B. ZTA policies can implement robust encryption and secure access
    controls to prevent access to services from stolen devices, ensuring
    that only legitimate users can access mobile services.
  • C. ZTA policies should prioritize securing remote users through
    technologies like virtual desktop infrastructure (VDI) and corporate
    cloud workstation resources to reduce the risk of lateral movement via
    compromised access controls.
  • D. ZTA policies can be configured to authenticate third-party users
    and their devices, determining the necessary access privileges for
    resources while concealing all other assets to minimize the attack
    surface.

正解:D

解説:
Explanation
ZTA is based on the principle of never trusting any user or device by default, regardless of their location or ownership. ZTA policies can use various methods to verify the identity and context of third-party users and devices, such as tokens, certificates, multifactor authentication, device posture assessment, etc. ZTA policies can also enforce granular and dynamic access policies that grant the minimum necessary privileges to third-party users and devices for accessing specific resources, while hiding all other assets from their view.
This reduces the attack surface and prevents unauthorized access and lateral movement within the network.


質問 # 41
Within the context of risk management, what are the essential
components of an organization's ongoing risk analysis?

  • A. Log scoping, log sources, and anomalies
  • B. Gap analysis, security policies, and migration
  • C. Incident management, change management, and compliance
  • D. Assessment frequency, metrics, and data

正解:D

解説:
The essential components of an organization's ongoing risk analysis are assessment frequency, metrics, and data. Assessment frequency refers to how often the organization conducts risk assessments to monitor and measure the effectiveness of the zero trust architecture and policies. Metrics refer to the quantitative and qualitative indicators that are used to evaluate the security posture, performance, and compliance of the zero trust architecture. Data refers to the information that is collected, analyzed, and reported from various sources, such as telemetry, logs, audits, and feedback, to support risk analysis and decision making.
References =
* Zero Trust Planning - Cloud Security Alliance, section "Monitor & Measure"
* How to improve risk management using Zero Trust architecture | Microsoft Security Blog, section
"Monitoring and reporting"
* Zero Trust Adoption: Managing Risk with Cybersecurity Engineering and Adaptive Risk Assessment - SEI Blog, section "Continuous Monitoring and Improvement"


質問 # 42
Which component in a ZTA is responsible for deciding whether to
grant access to a resource?

  • A. The policy administrator (PA)
  • B. The policy engine (PE)
  • C. The policy component
  • D. The policy enforcement point (PEP)

正解:B

解説:
The policy engine (PE) is the component in a ZTA that is responsible for deciding whether to grant access to a resource. The PE evaluates the policies and the contextual data collected from various sources, such as the user identity, the device posture, the network location, the resource attributes, and the environmental factors, and then generates an access decision. The PE communicates the access decision to the policy enforcement point (PEP), which enforces the decision on the resource.
References =
* Certificate of Competence in Zero Trust (CCZT) prepkit, page 14, section 2.2.2
* What Is Zero Trust Architecture (ZTA)? - F5, section "Policy Engine"
* What is Zero Trust Architecture (ZTA)? | NextLabs, section "Core Components"
* [SP 800-207, Zero Trust Architecture], page 11, section 3.3.1


質問 # 43
What measures are needed to detect and stop malicious access
attempts in real-time and prevent damage when using ZTA's
centralized authentication and policy enforcement?

  • A. Dynamic firewall policies
  • B. Dynamic access policies
  • C. Network segregation
  • D. Audit logging and monitoring

正解:D

解説:
To detect and stop malicious access attempts in real-time within a Zero Trust Architecture, comprehensive audit logging and continuous monitoring are essential. These measures provide visibility into all access attempts and activities within the network, allowing for the early detection of suspicious behavior. By analyzing logs and monitoring network traffic, security teams can identify and respond to potential threats in real-time, preventing unauthorized access and minimizing the impact of any security incidents.


質問 # 44
Which architectural consideration needs to be taken into account
while deploying SDP? Select the best answer.

  • A. How SDP deployment fits into external vendor assessment.
  • B. How SDP deployment fits into existing human resource
    management systems.
  • C. How SDP deployment fits into existing network topologies and
    technologies.
  • D. How SDP deployment fits into application validation.

正解:C

解説:
Explanation
A key architectural consideration that needs to be taken into account while deploying SDP is how SDP deployment fits into existing network topologies and technologies. This is because SDP deployment may require changes or adaptations to the existing network infrastructure, such as routers, switches, firewalls, VPNs, etc. SDP deployment may also affect the network performance, availability, scalability, and resilience.
Therefore, it is important to assess the impact and compatibility of SDP deployment with the existing network topologies and technologies, and to plan and design the SDP deployment accordingly.
References = Certificate of Competence in Zero Trust (CCZT) - Cloud Security Alliance, Zero Trust Training (ZTT) - Module 7: Network Infrastructure and SDP


質問 # 45
......

Cloud Security Alliance CCZTリアルな2025年最新の知能問題集模擬試験問題集:https://www.jpntest.com/shiken/CCZT-mondaishu

Cloud Security Alliance CCZTリアルな問題と100%カバーリアルな試験問題:https://drive.google.com/open?id=1lkEuXHt0BsyNJr15oJdI4XlH-eaZit2i

弊社を連絡する

我々は12時間以内ですべてのお問い合わせを答えます。

オンラインサポート時間:( UTC+9 ) 9:00-24:00
月曜日から土曜日まで

サポート:現在連絡