
[2025年04月]に更新されたIsaca Certification CISM日本語試験練習問題集お試しセット
2025年最新のCISM日本語プレミアム資料テストPDF無料問題集お試しセット
質問 # 211
情報セキュリティマネージャーが上級管理職のコミットメントを求めている場合、次のうちどれが最も重要かを知っていますか?
- A. 技術的な脆弱性
- B. セキュリティ技術の要件
- C. 実装タスク
- D. セキュリティコスト
正解:C
質問 # 212
ある組織は、最近発見された脆弱性に対応するために、新しいセキュリティ制御を導入しました。数人の従業員が、この制御によって業務に支障が出ると懸念を表明しています。情報セキュリティ マネージャーにとって最善の対応策は次のどれでしょうか。
- A. 脆弱性についてユーザーに教育します。
- B. 脆弱性を受け入れます。
- C. 補正制御オプションを評価します。
- D. 管理リスクを上級管理職に報告します。
正解:D
質問 # 213
ビジネスに支障をきたす可能性のある重大なセキュリティ インシデントに対応する際に、情報セキュリティ マネージャーが取る最も重要な行動はどれですか。
- A. 侵害の兆候を特定します。
- B. エスカレーション プロセスに従います。
- C. 法医学調査員に連絡してください。
- D. 法執行機関に通報します。
正解:B
解説:
When responding to a major security incident that could disrupt the business, the information security manager's most important course of action is to follow the escalation process. The escalation process is a predefined set of steps and procedures that define who should be notified, when, how, and with what information in the event of a security incident. The escalation process helps to ensure that the appropriate stakeholders, such as senior management, business units, legal counsel, public relations, and external parties, are informed and involved in the incident response process. The escalation process also helps to coordinate the actions and decisions of the incident response team and the business continuity team, and to align the incident response objectives with the business priorities and goals. The escalation process should be documented and communicated as part of the incident response plan, and should be reviewed and updated regularly to reflect the changes in the organization's structure, roles, and responsibilities.
Reference =
CISM Review Manual 15th Edition, page 1631
CISM 2020: Incident Management and Response, video 32
Incident Response Models3
質問 # 214
次のうちどれが情報セキュリティ戦略の主要な基礎となるべきですか?
- A. 組織のビジョンと使命
- B. 監査および規制要件
- C. 包括的なギャップ分析の結果
- D. 情報セキュリティポリシー
正解:A
質問 # 215
管理を実装する際にリスク所有者からの意見を得る最も重要な理由はどれですか?
- A. リスク軽減コストを削減するため
- B. エンタープライズアーキテクチャ(EA)の脆弱性を解決する
- C. ビジネスに影響を与える脅威を排除する
- D. リスクを許容できるレベルに管理する
正解:D
解説:
According to the Certified Information Security Manager (CISM) Study Manual, risk owners are responsible for managing a risk, including taking corrective action to reduce the risk to an acceptable level. When implementing controls, it is essential to obtain input from risk owners to ensure that the controls are effective in managing the risk to an acceptable level.
By obtaining input from risk owners, the organization can ensure that the controls are tailored to the specific risks and are effective in reducing the risk to an acceptable level. This can help to minimize the impact of the risk on the organization and reduce the potential for financial or reputational damage.
質問 # 216
組織は、情報セキュリティガバナンスフレームワークを実装しています。プログラムの有効性を利害関係者に伝えるには、以下を確立することが最も重要です。
- A. コントロールの自己評価プロセス。
- B. セキュリティポリシーの監視プロセス。
- C. 利害関係者への自動レポート。
- D. 各マイルストーンのメトリック。
正解:D
質問 # 217
情報セキュリティ管理者が情報セキュリティの考慮事項を主要なビジネスプロセスに統合することを促進するための最良の方法は、次のうちどれですか?
- A. 情報セキュリティ意識向上トレーニングを提供します。
- B. 経営幹部向けの情報セキュリティブリーフィングを実施
- C. ビジネス影響分析(BIA)を実施します。
- D. 情報セキュリティ運営グループの作成を促進する
正解:D
質問 # 218
次のうち、セキュリティ意識向上プログラムの有効性を評価するための最も効果的な方法はどれですか?
- A. ソーシャルエンジニアリングテスト
- B. 卓上テスト
- C. 脆弱性スキャン
- D. インシデント後のレビュー
正解:A
質問 # 219
組織内で堅牢な情報セキュリティ文化を構築するために最も重要なことは、次のうちどれですか?
- A. 情報セキュリティ ポリシーの上級管理職の承認
- B. 組織全体の成熟した情報セキュリティ意識向上トレーニング
- C. 従業員による組織のセキュリティ ポリシーの遵守の厳格な実施
- D. IT 環境の開発と運用に組み込まれたセキュリティ管理策
正解:B
解説:
Explanation
= Mature information security awareness training across the organization is the most important factor for building a robust information security culture, because it helps to educate and motivate the employees to understand and adopt the security policies, procedures, and best practices that are aligned with the organizational goals and values. Information security awareness training should be tailored to the specific roles, responsibilities, and needs of the employees, and should cover the relevant topics, such as:
The importance and value of information assets and the potential risks and threats to them The legal, regulatory, and contractual obligations and compliance requirements related to information security The organizational security policies, standards, and guidelines that define the expected and acceptable behaviors and actions regarding information security The security controls and tools that are implemented to protect the information assets and how to use them effectively and efficiently The security incidents and breaches that may occur and how to prevent, detect, report, and respond to them The security best practices and tips that can help to enhance the security posture and culture of the organization Information security awareness training should be delivered through various methods and channels, such as:
Online courses, webinars, videos, podcasts, and quizzes that are accessible and interactive Classroom sessions, workshops, seminars, and simulations that are engaging and practical Posters, flyers, newsletters, emails, and social media that are informative and catchy Games, competitions, rewards, and recognition that are fun and incentivizing Information security awareness training should be conducted regularly and updated frequently, to ensure that the employees are aware of the latest security trends, challenges, and solutions, and that they can demonstrate their knowledge and skills in a consistent and effective manner.
Mature information security awareness training can help to create a positive and proactive security culture that fosters trust, collaboration, and innovation among the employees and the organization, and that supports the achievement of the strategic objectives and the mission and vision of the organization.
References = CISM Review Manual, 16th Edition, ISACA, 2021, pages 144-146, 149-150.
質問 # 220
許容可能なリスク レベルを決定する際に、最も重要な考慮事項は次のどれですか。
- A. リスクマトリックス
- B. 脆弱性スコア
- C. システムの重要度
- D. 脅威プロファイル
正解:C
質問 # 221
情報セキュリティステータスレポート管理に含めることが最も重要なのは次のどれですか?
- A. 情報セキュリティ予算要求
- B. 最近のセキュリティイベントのリスト
- C. 情報セキュリティポリシーの見直し
- D. 主要リスク指標 (KRI)
正解:D
解説:
Key risk indicators (KRIs) are the most useful to include in an information security status report for management because they measure and report the level of risk exposure or performance against predefined risk thresholds or targets, and alert management of any deviations or issues that may require attention or action. List of recent security events is not very useful to include in an information security status report for management because it does not provide any analysis or evaluation of the events or their impact on the organization's objectives or performance. Review of information security policies is not very useful to include in an information security status report for management because it does not reflect any progress or results of implementing or enforcing the policies. Information security budget requests are not very useful to include in an information security status report for management because they do not indicate any value or benefit of investing in information security initiatives or controls. References: https://www.isaca.org/resources/isaca- journal/issues/2016/volume-6/how-to-measure-the-effectiveness-of-information-security-using-iso-27004
質問 # 222
次のどれが技術的な変化に応じてほとんど変更されないでしょうか?
- A. 手順
- B. ポリシー
- C. ガイドライン
- D. 標準
正解:B
解説:
Policies are high-level statements of objectives. Because of their high-level nature and statement of broad operating principles, they are less subject to periodic change. Security standards and procedures as well as guidelines must be revised and updated based on the impact of technology changes.
質問 # 223
次のうち、情報セキュリティを脅かす可能性のある変更管理プロセスの悪用の指標となる指標はどれですか?
- A. コード行の合計行数に対する変更されたコード行の割合が高い
- B. 月次変更要求の大幅な減少
- C. 承認後の補足アドオンを含む変更の割合
- D. 少数の変更要求
正解:B
質問 # 224
可用性が主な関心事である組織では、パッチ管理手順の最も重要な成功要因は次のとおりです。
- A. 展開の有効性の証明。
- B. すべてのサーバーへの自動展開。
- C. 展開前のテスト時間枠。
- D. 担当チームの技術スキル。
正解:C
解説:
説明
重要なシステムに実装する前にパッチをテストすることは、可用性が主な関心事である絶対的な前提条件です。システムの障害を引き起こす可能性のあるパッチの展開は、パッチによって修正される脆弱性よりも悪いからです。すべてのシステムにパッチを展開することは意味がありません。脆弱性のあるシステムがパッチ適用の唯一の候補であるべきです。パッチは自動ツールを介して適用されることが多いため、パッチ適用スキルは必要ありません。
質問 # 225
ビジネス システムの更新後に脆弱性評価を実行する主な目的は何ですか?
- A. コントロールの有効性を確認します。
- B. 脅威の状況を更新します。
- C. 運用上の損失を決定します。
- D. 変更管理プロセスを改善します。
正解:A
質問 # 226
インシデント対応プロセスにおける撲滅フェーズの主な目標は次のとおりです。
- A. 影響を受けるシステムから法医学的証拠を取得します。
- B. 厳格な保管過程を維持します。
- C. 効果的なトリアージとインシデントの封じ込めを提供します。
- D. 脅威を除去し、影響を受けたシステムを復元します。
正解:D
解説:
The primary goal of the eradication phase in an incident response process is to remove the threat and restore affected systems because it eliminates any traces or remnants of malicious activity or compromise from the systems or network, and returns them to their normal or secure state. Maintaining a strict chain of custody is not a goal of the eradication phase, but rather a requirement for preserving and documenting digital evidence throughout the incident response process. Providing effective triage and containment of the incident is not a goal of the eradication phase, but rather a goal of the containment phase, which isolates and stops the spread of malicious activity or compromise. Obtaining forensic evidence from the affected system is not a goal of the eradication phase, but rather a goal of the identification phase, which collects and analyzes data or artifacts related to malicious activity or compromise. Reference: https://www.isaca.org/resources/isaca-journal/issues/2017/volume-5/incident-response-lessons-learned https://www.isaca.org/resources/isaca-journal/issues/2018/volume-3/incident-response-lessons-learned
質問 # 227
セキュリティ意識向上プログラムの有効性を評価するための最も効果的な方法は次のうちどれですか?
- A. ソーシャルエンジニアリングテスト
- B. 卓上テスト
- C. 脆弱性スキャン
- D. インシデント後のレビュー
正解:A
質問 # 228
情報セキュリティ戦略の実装を成功させるには、次のうちどれが最も重要ですか?
- A. 上級管理職からの継続的な取り組み
- B. 情報セキュリティプログラムのためにサイズの大きい資金
- C. 規制の遵守
- D. 確立された情報セキュリティポリシー
正解:A
質問 # 229
......
今すぐ弊社のIsaca Certification試験パッケージ使って試験準備してCISM日本語をパスせよ:https://www.jpntest.com/shiken/CISM-JPN-mondaishu