
CISM日本語試験問題を今すぐ試そう!最新の[2024年最新] 正解回答付き
練習できるCISM日本語には認定ガイド問題と解答とトレーニングを提供しています
質問 # 19
次のうち、新しいシステムで情報セキュリティが適切に対処されることを保証する上で最も効果的なものはどれですか?
- A. ビジネス要件にはセキュリティ対策方針を含める必要があります。
- B. 内部監査は実装前にセキュリティを承認します
- C. 情報セキュリティスタッフがシステムセキュリティの設計に責任を負います
- D. 生産開始前に情報セキュリティスタッフがコンプライアンスレビューを実施
正解:A
質問 # 20
顧客情報の不正開示に関して法務当局と連絡を取る主な責任は、次のように定義する必要があります。
- A. 災害復旧計画(DRP)。
- B. リスク軽減計画
- C. 情報セキュリティポリシー。
- D. インシデント対応計画
正解:D
質問 # 21
セキュリティガバナンスの枠組みの中で、情報セキュリティ委員会の最も重要な特徴は次のうちどれですか?委員会:
- A. 外部の専門家との関係を確立しています。
- B. 明確に定義されたチャリエおよび会議プロトコルがあります。
- C. セキュリティポリシーの頻繁なレビューを行っています。
- D. すべての管理レベルのメンバーが混在しています。
正解:D
質問 # 22
Web ベースのアプリケーションのデータ入力機能は、リモート サイトから作業するサード パーティのサービス プロバイダーにアウトソーシングされています。次の問題のうち、情報セキュリティ マネージャーにとって最大の関心事はどれですか?
- A. アプリケーションは安全な通信プロトコルを使用していません
- B. ビジネス プロセスには、1 レベルのエラー チェックしかありません。
- C. アプリケーションは制限付きのアクセス制御で構成されています
- D. サーバーベースのマルウェア保護は適用されません
正解:C
解説:
The greatest concern for an information security manager in this situation would be the security of the data that is being processed by the third-party service provider working from a remote site. This could be a concern because the data may not be adequately protected from unauthorized access, manipulation, or theft. A secure communications protocol should be used to ensure the confidentiality and integrity of the data in transit. Additionally, the information security manager should ensure that the third-party service provider has appropriate security controls in place to protect the data, such as access controls, error checking, and malware protection. This information can be found in the ISACA's Certified Information Security Manager (CISM) Study Manual, Section 5.2.
質問 # 23
情報セキュリティ戦略を検討する際に考慮すべき最も重要な要素は次のうちどれですか?
- A. 進化するビジネス目標
- B. セキュリティインシデントの頻度
- C. 同業他社へのベンチマーキング
- D. 緩和されていないリスク
正解:A
質問 # 24
新しいベンダーの脆弱性を識別する最も費用対効果の高い方法は何ですか?
- A. コンサルタントが定期的に実施する脆弱性評価
- B. 外部脆弱性報告ソース
- C. 侵入防止ソフトウェア
- D. DMZにあるハニーポット
正解:B
解説:
説明
外部の脆弱性ソースは、これらの脆弱性を識別する最も費用対効果の高い方法になるでしょう。選択肢BとCにかかるコストは、特に定期的に実行する場合は特に高くなります。ハニーポットはすべてのベンダーの脆弱性を特定しません。さらに、DMZにあるハニーポットは、運用ネットワークがハニーポットからのトラフィックから十分に保護されていない場合、セキュリティリスクを引き起こす可能性があります。
質問 # 25
インシデント管理チームのリーダーは、組織がサイバー攻撃から正常に回復したことを示す通知を送信します。次に行うべきことは次のうちどれですか?
- A. 上級管理職向けに概要を作成する
- B. 分析用のデジタル証拠を保護および保存します。
- C. 会議を実施して、学んだ教訓を把握します。
- D. ビジネスへの影響に関するフィードバックを収集する
正解:C
解説:
Conducting a meeting to capture lessons learned is the next step after an incident management team leader sends out a notification that the organization has successfully recovered from a cyberattack because it helps to identify the strengths and weaknesses of the current incident response plan, capture the feedback and recommendations from the incident responders and stakeholders, and implement the necessary improvements and corrective actions for future incidents. Preparing an executive summary for senior management is not the next step, but rather a subsequent step that involves reporting the incident details, impact, and resolution to the senior management. Gathering feedback on business impact is not the next step, but rather a concurrent step that involves assessing the extent and severity of the damage or disruption caused by the incident. Securing and preserving digital evidence for analysis is not the next step, but rather a previous step that involves collecting and documenting the relevant data or artifacts related to the incident. Reference: https://www.isaca.org/resources/isaca-journal/issues/2017/volume-5/incident-response-lessons-learned https://www.isaca.org/resources/isaca-journal/issues/2018/volume-3/incident-response-lessons-learned
質問 # 26
損失が発生した場合に会社のデータを保護するためのBYOD(Bring Your Own Device)プログラムで最も重要な考慮事項は、次のうちどれですか?
- A. デバイスをリモートで見つける機能
- B. 未承認のアプリケーションを制限する機能
- C. デバイスを一元管理する機能
- D. デバイスのタイプを分類する機能
正解:C
質問 # 27
次のうち、組織内の情報セキュリティ機能の有効性について最も包括的なビューを提供するのはどれですか?
- A. バランススコアカード
- B. インシデント報告システム
- C. セキュリティプロセスへの準拠の例
- D. 上級管理職へのインタビュー
正解:B
質問 # 28
インシデントエスカレーションプロセスを開発する場合、最善のアプローチは、以下に基づいてインシデントを分類することです。
- A. 根本原因。
- B. 回復までの推定時間。
- C. 目標復旧時点(RPO)。
- D. 影響を受ける情報資産。
正解:C
質問 # 29
経営陣が企業のビジネス戦略を変更する場合、次のプロセスのどれを使用して、既存の情報セキュリティ管理を評価し、新しい情報セキュリティ管理を選択する必要がありますか?
- A. アクセス制御管理
- B. 変更管理
- C. 構成管理
- D. リスク管理
正解:C
質問 # 30
組織には、すべての犯罪行為を訴追するポリシーがあります。従業員が会社のコンピューターを使用して詐欺を犯した疑いがある場合、情報セキュリティマネージャーにとって最も重要なことは何ですか?
- A. 従業員のログファイルがバックアップされます。
- B. インシデント対応計画が開始されます。
- C. フォレンジックプロセスがすぐに開始されます。
- D. 上級管理職に状況が通知されます。
正解:A
質問 # 31
ITシステムで処理される情報の適切な制御を確実にするために、セキュリティ保護は主に以下に基づく必要があります。
- A. 全体的なIT容量と運用上の制約、
- B. 分類レベルと一致する基準
- C. 効率的な技術的処理の考慮事項、
- D. 確立されたガイドライン
正解:B
質問 # 32
情報セキュリティ戦略を提示する際に上級リーダーのサポートを得るために最も重要なのは次のうちどれですか?
- A. この戦略は、組織の成熟度と脅威環境に対処します。
- B. 戦略は業界のベンチマークおよび標準と一致しています。
- C. この戦略は、非効果的な情報セキュリティ管理に対処します。
- D. 戦略は経営陣の許容リスクレベルと一致しています。
正解:D
解説:
Explanation
The most important factor to obtain senior leadership support when presenting an information security strategy is that the strategy aligns with management's acceptable level of risk because it ensures that the strategy is consistent and compatible with the organization's risk appetite and thresholds, and reflects management's expectations and priorities for security risk management. The strategy addresses ineffective information security controls is not a very important factor because it does not indicate how the strategy will improve or enhance the security controls or performance. The strategy aligns with industry benchmarks and standards is not a very important factor because it does not indicate how the strategy will differentiate or innovate the organization's security capabilities or practices. The strategy addresses organizational maturity and the threat environment is not a very important factor because it does not indicate how the strategy will advance or adapt the organization's security posture or resilience. References:
https://www.isaca.org/resources/isaca-journal/issues/2016/volume-4/technical-security-standards-for-information
https://www.isaca.org/resources/isaca-journal/issues/2017/volume-2/how-to-align-security-initiatives-with-busin
質問 # 33
新しい情報セキュリティプログラムの実装の進捗状況を主要な利害関係者に効果的に伝えるための最も重要な推進力はどれですか?
- A. プログラムの目的に影響を与える利害関係者のニーズを理解する
- B. 利害関係者がプログラム関連のテクノロジーの概念を要求しないようにする
- C. プログラムの目標の達成に影響を与える可能性のあるリスクを文書化する
- D. プログラムのユニバーサルキーパフォーマンスインジケーター(KPI)の設計
正解:A
質問 # 34
次のBESTのどれが、アプリケーション開発の変更が行われたときにセキュリティリスクが再評価されることを保証しますか?
- A. 変更管理プロセス
- B. 問題管理プロセス
- C. ビジネス影響分析(BIA)
- D. バックグラウンドスクリーニング
正解:A
解説:
説明
変更管理プロセスは、開発の変更によって影響を受ける可能性のあるものを再評価することを保証する方法論です。問題管理は、特にセキュリティに関連する問題ではなく、すべての問題を管理することを目的とした一般的なプロセスです。バックグラウンドスクリーニングは、従業員の参照が採用されたときに評価するプロセスです。 BIAは、ビジネス継続プロセスのリスクを評価するために使用される方法論です。
質問 # 35
重要なビジネス アプリケーションの可用性を損なう可能性のある脆弱性の導入を防ぐのに最も効果的なのは、次のうちどれですか?
- A. パッチ管理プロセス
- B. バージョン管理
- C. 変更管理コントロール
- D. 論理アクセス制御
正解:C
解説:
Explanation
= Change management controls are the most effective in preventing the introduction of vulnerabilities that may disrupt the availability of a critical business application. Change management controls are the policies, procedures, and practices that govern the initiation, approval, implementation, testing, and documentation of changes to the information systems and infrastructure. Change management controls help to ensure that changes are authorized, planned, controlled, and monitored, and that they do not introduce any unintended or adverse effects on the security, functionality, performance, or reliability of the system or application. Change management controls also help to identify and mitigate any potential risks or issues that may arise from the changes, and to ensure that the changes are aligned with the business objectives and requirements. By implementing change management controls, the organization can prevent the introduction of vulnerabilities that may disrupt the availability of a critical business application, as well as enhance the quality and efficiency of the change process. References = CISM Review Manual 15th Edition, page 105, page 106.
質問 # 36
リスクプロファイルは、主に次の理由で効果的なセキュリティ決定をサポートします。
- A. 将来のリスクを最も軽減する方法を定義します。
- B. セキュリティの脅威について説明します。
- C. 業界のベストプラクティスとの比較を可能にします。
- D. リスク削減の優先順位を特定します。
正解:D
質問 # 37
組織では、ITセキュリティの責任が明確に割り当てられ、実施され、ITセキュリティのリスクと影響の分析が一貫して実行されます。これは、情報セキュリティガバナンスの成熟度モデルのどのレベルのランキングを表しますか?
- A. 最適化
- B. 繰り返し可能
- C. 定義済み
- D. 管理
正解:D
解説:
説明
取締役会および経営陣は、情報セキュリティガバナンスの成熟度モデルを使用して、組織のセキュリティのランキングを確立できます。ランクは存在せず、初期、反復可能、定義、管理、および最適化されています。組織内のITセキュリティの責任が明確に割り当てられ、実施され、ITセキュリティのリスクと影響の分析が一貫して実行される場合、それは「管理され、測定可能な」と言われます。
質問 # 38
......
試験準備には欠かさない!トップクラスのISACA CISM日本語試験アプリ学習ガイド練習問題最新版:https://www.jpntest.com/shiken/CISM-JPN-mondaishu