IT業界で広く認められるISC Certified Information Systems Security Professional (CISSP)は、ISC公式の認定資格です。JPNTestのCISSP練習問題はISCの公式出題ガイドに基づいて構成されており、1811の問題で試験範囲を体系的に学べます。
ISC CISSP 試験概要:
| 認定ベンダー: | ISC2 |
|---|---|
| 試験名: | Certified Information Systems Security Professional (CISSP) |
| 試験番号: | CISSP |
| 試験時間: | 180 分 |
| 対応言語: | スペイン語, 日本語, 中国語, ドイツ語, 英語 |
| 受験料: | USD $749 |
| 出題数: | 100-150 |
| 関連資格: | ISC2 Certified in Cybersecurity (CC) ISC2 Systems Security Certified Practitioner (SSCP) ISC2 Certified Cloud Security Professional (CCSP) |
| 認定の有効期間: | 3年間 |
| 合格点: | 1000点中700点 |
| 試験形式: | 多肢選択式, 高度な革新的問題, Computerized Adaptive Testing (CAT) |
| サンプル問題: | ISC CISSP サンプル問題 |
| 受験方法: | Pearson VUEテストセンターにおけるComputerized Adaptive Testing (CAT) |
| 前提条件: | CISSPドメインのうち2つ以上における最低5年間の累積有給実務経験。関連する4年制の学位または承認された資格は、1年間の経験に代わることができます。 |
| 公式シラバスのURL: | https://www.isc2.org/certifications/cissp/cissp-certification-exam-outline |
ISC CISSP 試験シラバストピック:
| セクション | 比重 | 目標 |
|---|---|---|
| ソフトウェア開発セキュリティ | 11% | - ソフトウェアセキュリティの有効性評価
|
| セキュリティ評価とテスト | 12% | - セキュリティコントロールテストの実施
|
| セキュリティとリスクマネジメント | 15% | - リスクマネジメントの概念の適用
|
| アセットセキュリティ | 10% | - 情報取り扱い要件の確立
|
| アイデンティティとアクセス管理 | 13% | - 識別と認証の管理
|
| セキュリティ運用 | 13% | - 予防措置の運用と維持
|
| コミュニケーションとネットワークセキュリティ | 13% | - 安全な通信チャネルの実装
|
| セキュリティアーキテクチャとエンジニアリング | 13% | - セキュリティモデルの調査と実装
|
CISSP試験についてよくあるご質問
「CISSP」は、ISC2が実施する「Certified Information Systems Security Professional (CISSP)」の試験コードです。この試験に合格すると、「ISC Certification」の認定を取得できます。認定レベルはエキスパートに位置づけられています。関連する認定としては、ISC2 Certified Cloud Security Professional (CCSP)・ISC2 Systems Security Certified Practitioner (SSCP)・ISC2 Certified in Cybersecurity (CC)などが挙げられます。JPNTestでは、CISSP試験対策として1811の練習問題をご用意しています。
CISSP試験の出題数は100-150、制限時間は180 分です。限られた時間内で全問に取り組む必要があるため、1問にかけられる時間を常に意識し、難しい問題に長く留まりすぎないペース配分が求められます。本番で時間不足に慌てないよう、JPNTestのテストエンジンで制限時間つきの模擬試験に挑戦し、時間配分の感覚を体に覚えさせておくことをおすすめします。
CISSP試験の合格ラインは1000点中700点、受験料はUSD $749です。万が一不合格だった場合、再受験には改めて全額の受験料が必要になるため、費用面の負担も無視できません。受験前にJPNTestの1811の練習問題で模擬試験に取り組み、安定して合格ラインを超えられることを確認してから本番に臨むと安心です。
CISSPドメインのうち2つ以上における最低5年間の累積有給実務経験。関連する4年制の学位または承認された資格は、1年間の経験に代わることができます。
受験条件は変更される場合があります。最新かつ正確な情報は、ISCの公式ページで必ずご確認ください。
はい、ご購入前にJPNTestのCISSP問題集の無料サンプル(PDFデモ)をダウンロードして、問題の品質や形式をご確認いただけます。ご購入後は365日間の無料更新が付帯し、更新期間の終了後も50%割引で継続更新をご利用いただけるため、常に最新の出題傾向に沿った内容で学習を続けられます。
JPNTestでは「返金保証」制度をご用意しています。ご購入後60日以内にCISSP試験を受験して不合格となった場合、全額返金をご申請いただけます。なお、ご購入後3日以内の受験や、ダウンロード後に実際の受験をしていない場合、無料資料や期限切れのご注文は対象外となり、受験者氏名とお支払い者氏名が一致している必要があります。ご申請の際は、受験票(enrollment slip)の写しと公式スコアレポート(Score Report)のPDFを試験後2日以内にご提出いただき、受理後7日以内に手続きが完了します。返金をご希望でない場合は、同等価値の試験資料2点を無料でお受け取りいただき、元の製品の更新サービスを継続する選択肢もございます。
また、ご購入いただいた製品はお支払い完了後すぐにダウンロードでき、メールでも1分以内にお届けします。2時間以内に届かない場合はカスタマーサポートまでご連絡ください。インストール可能なパソコンの台数に制限はありません。
CISSP試験の出題範囲は、全部で8分野で構成されています。主な分野としては、「セキュリティとリスクマネジメント」(15%)、「コミュニケーションとネットワークセキュリティ」(13%)、「セキュリティアーキテクチャとエンジニアリング」(13%)などが挙げられます。各分野の詳細なトピックと配点は、上記の試験大綱をご確認ください。JPNTestのCISSP練習問題は、これらの出題分野を幅広くカバーしています。
ISC Certified Information Systems Security Professional (CISSP) 認定 CISSP 試験問題:
問題 #1
Which of the following is the PRIMARY risk with using open source software in a commercial software construction?
A. Costs associated with support of the software
B. Lack of software documentation
C. Expiration of the license agreement
D. License agreements requiring release of modified code
問題 #2
Which of the following secure startup mechanisms are PRIMARILY designed to thwart attacks?
A. Side channel
B. Cold boot
C. Acoustic cryptanalysis
D. Timing
問題 #3
Which of the following BEST describes "Living-off-the-Cloud" attack techniques?
A. An attack that can only be performed by an insider with physical data center access
B. A technique used exclusively to attack on-premises, non-cloud infrastructure
C. Attacks in which adversaries abuse legitimate, native cloud provider services, APIs, and administrative tools already available within a compromised cloud environment to carry out malicious activity, making detection more difficult by blending in with normal cloud administrative behavior
D. Attacks that require the attacker to physically access a cloud data center
問題 #4
Which of the following activities BEST identifies operational problems, security misconfigurations, and malicious attacks?
A. Authentication validation
B. Periodic log reviews
C. Policy documentation review
D. Interface testing
問題 #5
An organization has a short-term agreement with a public Cloud Service Provider (CSP). Which of the following BEST protects sensitive data once the agreement expires and the assets are reused?
A. Use a contractual agreement to ensure the CSP wipes the data from the storage environment.
B. Use a National Institute of Standards and Technology (NIST) recommendation for wiping data on the storage environment.
C. Recommend that the business data owners use internal encryption keys for data-at-rest and data- in-transit to the storage environment.
D. Recommended that the business data owners use continuous monitoring and analysis of applications to prevent data loss.
解説:
| 問題 #1 正解: D | 問題 #2 正解: A | 問題 #3 正解: C | 問題 #4 正解: B | 問題 #5 正解: A |
469 お客様のコメント
クリック」



