更新された検証済みのCISSP日本語問題集と解答には100%一発合格保証問題集はここ [Q941-Q963]

Share

更新された検証済みのCISSP日本語問題集と解答には100%一発合格保証問題集はここ

合格ISC Certification CISSP日本語試験問題には1795問があります

質問 # 941
効果的な情報セキュリティ意識向上プログラムを確立する上で最も重要な要素は何ですか?

  • A. マネジメントバイインを取得します。
  • B. 情報セキュリティのポスターを壁に掛けて、
  • C. セキュリティトレーニングを義務付けます。
  • D. 毎年セキュリティ意識向上イベントを実施します。

正解:C


質問 # 942

  • A. Option C
  • B. Option A
  • C. Option D
  • D. Option B

正解:A


質問 # 943
パスワードを「塩漬け」するプロセスは、次のうちどれを解読するのを難しくするように設計されていますか?

  • A. 特定のパスワード
  • B. パスワードアルゴリズム
  • C. パスワードハッシュ関数
  • D. パスワードの最大長

正解:C


質問 # 944
ある組織では、未公開のゲームをダウンロードするために、権限のない人物がセキュア ファイル転送プロトコル (SFTP) サーバーにアクセスしたことを発見しました。最近のセキュリティ監査で、組織の一般的な情報技術 (IT) 制御の一部に弱点が見つかりました。具体的には、ソフトウェア変更制御とセキュリティ パッチ管理に関する弱点ですが、他の制御領域には弱点が見つかりませんでした。
セキュリティ侵害で使用された攻撃ベクトルとして最も可能性が高いのは次のどれですか?

  • A. バッファオーバーフロー
  • B. 複雑さのルールがないため、パスワードが弱い
  • C. クロスサイトスクリプティング (XSS)
  • D. 分散型サービス拒否 (DDoS)

正解:A


質問 # 945
リカバリ時間目標 (RTO) を最もよく表しているのはどれですか?

  • A. 災害後のデータ検証の時間。
  • B. 災害後のアプリケーション再開時間
  • C. 災害後のアプリケーション検証の時間。
  • D. 災害後のバックアップからのデータ復元の時間。

正解:B


質問 # 946
データセキュリティおよびセキュリティ評価を実施するための事業運営に関連するベースラインリファレンスとして、業界で認められているどのドキュメントを使用できますか?

  • A. サービス組織管理(SOC)1タイプ1
  • B. サービス組織管理(SOC)2タイプ2
  • C. サービス組織管理(SOC)1タイプ2
  • D. サービス組織管理(SOC)2タイプ1

正解:B

解説:
The industry-recognized document that could be used as a baseline reference that is related to data security and business operations for conducting a security assessment is Service Organization Control (SOC) 2 Type 2. A security assessment is a process that involves evaluating and testing the security posture and performance of a system or a network, using various methods, such as audits, reviews, scans, or tests. A security assessment can provide various benefits, such as identifying and resolving the security risks or issues, and ensuring the compliance or alignment with the security standards or regulations. A baseline reference is a document or a source that provides the criteria, requirements, or guidelines for conducting a security assessment, and that can be used as a benchmark or a comparison for measuring or evaluating the security assessment results or outcomes. A baseline reference can be derived from various sources, such as industry standards, best practices, or frameworks. Service Organization Control (SOC) 2 Type 2 is an industry-recognized document that could be used as a baseline reference that is related to data security and business operations for conducting a security assessment. SOC 2 Type 2 is a type of report or attestation that is issued by an independent auditor or a third party, and that evaluates and verifies the security, availability, processing integrity, confidentiality, or privacy controls and practices of a service organization, such as a cloud service provider or a data center, over a period of time, usually six to twelve months. SOC 2 Type 2 is based on the Trust Services Criteria and Principles, which are a set of standards or guidelines that are developed and published by the American Institute of Certified Public Accountants (AICPA), and that define the minimum requirements or expectations for the service organization's controls and practices. SOC 2 Type 2 can be used as a baseline reference that is related to data security and business operations for conducting a security assessment, as it can provide the assurance and evidence that the service organization has implemented and maintained the effective and consistent security controls and practices, and that the service organization has met or exceeded the Trust Services Criteria and Principles12. References: CISSP CBK, Fifth Edition, Chapter 6, page 573; CISSP Practice Exam
- FREE 20 Questions and Answers, Question 18.


質問 # 947

  • A. Option A
  • B. Option C
  • C. Option D
  • D. Option B

正解:A


質問 # 948
ブルートフォースログイン攻撃するための最良の対策は、次のどれですか。

  • A. 失敗したシステムアクセスの試みの後に遅延を導入します。
  • B. 人のみで初期パスワードの配信を制限します。
  • C. 同時ユーザー・セッションの数を減らします。
  • D. すべての標準的なパスワードを変更します。

正解:A


質問 # 949

  • A. Option A
  • B. Option C
  • C. Option D
  • D. Option B

正解:A


質問 # 950
システムに複数の情報所有者からのデータが含まれている場合、各情報所有者は何をしなければなりませんか?

  • A. データのセキュリティ要件に関する情報システム(IS)の所有者に情報を提供する
  • B. 情報システム(IS)のセキュリティ評価レポート(SAR)を確認して、ISの運用を承認します。
  • C. データを含む情報システム(IS)のためのシステムセキュリティ計画(SSP)を作成し維持する。
  • D. 他の情報所有者が所有するデータが含まれていない情報システム(IS)にデータを移動する

正解:C


質問 # 951
ドラッグアンドドロップの質問
ハイパーテキスト転送プロトコル(HTTP)認証タイプを、相対的な強度の順に以下にランク付けします。
強度に応じて、認証タイプを右側の正しい位置にドラッグします。

正解:

解説:


質問 # 952

  • A. Option C
  • B. Option A
  • C. Option D
  • D. Option B

正解:A


質問 # 953
テスト データのソースとして適切なのは次のうちどれですか?

  • A. 実稼働環境でのみ保護および維持される実稼働データ。
  • B. 運用データ A と類似性のないテスト データ。
  • C. ミラーリングされ、実稼働データと最新の状態に保たれるテスト データ。
  • D. テスト環境にロードされる前にサニタイズされた実稼働データ。

正解:D

解説:
The most appropriate source for test data is production data that has been sanitized before loading into a test environment. Sanitization is the process of removing or modifying sensitive or confidential information from the data, such as personal identifiers, financial records, or trade secrets. Sanitized data preserves the characteristics and structure of the original data, but reduces the risk of exposing or compromising the data in the test environment. Production data that is secured and maintained only in the production environment is not a suitable source for test data, as it may not be accessible or available for testing purposes. Test data that has no similarities to production data is not a realistic or reliable source for test data, as it may not reflect the actual scenarios or conditions that the system will encounter in the production environment. Test data that is mirrored and kept up-to-date with production data is not a secure or ethical source for test data, as it may violate the privacy or confidentiality of the data owners or subjects, and expose the data to unauthorized access or modification in the test environment. References: 4: Data Sanitization: What It Is and How to Implement It55: Test Data Management: Best Practices and Methodologies


質問 # 954
重要なデータセットが開発され、維持され、定義された仕様内でアクセス可能であることを保証する責任があるのは、次のどの役割ですか?

  • A. データレビューア
  • B. データユーザー
  • C. データ管理者
  • D. データ所有者

正解:D


質問 # 955
自動パッチ管理ではなく手動パッチインストールを使用する理由は次のうちどれですか?

  • A. システムまたはアプリケーションの非互換性が発生する可能性が低くなります。
  • B. パッチのインストールに必要なコストが削減されます。
  • C. システムがエクスプロイトに対して脆弱なままになる時間が短縮されます。
  • D. 広大な地理的領域をカバーする能力が向上します。

正解:A

解説:
Manual patch installation allows for thorough testing before deployment to ensure that the patch does not introduce new vulnerabilities or incompatibilities. Automated patch management can sometimes lead to unexpected issues if patches are not fully compatible with all systems and applications12 References: CISSP All-in-One Exam Guide, Eighth Edition, Chapter 7: Security Operations, p. 452; Official (ISC)2 CISSP CBK Reference, Fifth Edition, Domain 7: Security Operations, p. 863.


質問 # 956
インターネット上でコンテンツの暗号化された転送を許可するプロトコルは次のうちどれですか?

  • A. ハイパーテキスト転送プロトコル (HTTP)
  • B. リモート コピー
  • C. サーバー メッセージ ブロック (SMB)
  • D. 安全なコピー

正解:D

解説:
Secure copy (SCP) is a protocol that allows the encrypted transfer of content on the Internet. SCP uses Secure Shell (SSH) to provide authentication and encryption for the data transfer. SCP can be used to copy files between local and remote hosts, or between two remote hosts. References: Unable to provide specific references due to browsing limitations.


質問 # 957
IDおよびアクセスプロビジョニングのライフサイクルにおける2番目のステップは何ですか?

  • A. 失効
  • B. プロビジョニング
  • C. レビュー
  • D. 承認

正解:C


質問 # 958
組織は、すべての新規ユーザーが作成時に事前定義された部門アクセステンプレートを確実に適用できるようにしたいと考えています。組織はまた、プロジェクトごとにユーザーに追加のアクセス権を付与することを望んでいます。組織のニーズを満たすには、どのタイプのユーザーアクセス管理が最適ですか?

  • A. ハイブリッド
  • B. 連合
  • C. 分散型
  • D. 一元化

正解:A

解説:
The type of user access administration that is best suited to meet the organization's needs is hybrid. User access administration is the process that involves defining, implementing, and managing the access rights or permissions of the users or the roles that access a system or a network, using various methods, such as passwords, tokens, or biometrics. User access administration can be classified into four types, which are:
* Centralized: The access rights or permissions of the users or the roles are controlled and managed by a single authority or entity, such as a central server or a database, and are applied uniformly and consistently across the system or the network.
* Decentralized: The access rights or permissions of the users or the roles are controlled and managed by multiple authorities or entities, such as local servers or databases, and are applied differently and independently across the system or the network.
* Federated: The access rights or permissions of the users or the roles are controlled and managed by different authorities or entities, such as different organizations or domains, and are shared and exchanged across the system or the network, using a common standard or protocol, such as SAML or OAuth.
* Hybrid: The access rights or permissions of the users or the roles are controlled and managed by a combination of the above types, such as centralized and decentralized, or federated and decentralized, and are applied flexibly and adaptively across the system or the network. Hybrid user access
* administration is the type that is best suited to meet the organization's needs, as it can provide the benefits of both centralized and decentralized user access administration, such as efficiency, consistency, scalability, and flexibility. Hybrid user access administration can allow the organization to ensure that all new users have a predefined departmental access template applied upon creation, using a centralized user access administration, and to grant additional access for users on a per-project basis, using a decentralized user access administration12. References: CISSP CBK, Fifth Edition, Chapter 5, page 457; CISSP Practice Exam - FREE 20 Questions and Answers, Question 19.


質問 # 959
最近のセキュリティ監査では、インターネットに接続された認証サーバーで、1日の特定の時間に何度かログイン試行が失敗したことが報告されています。セキュリティ情報およびイベント管理(SIEM)システムによってアラートは生成されていません。SIEMのパフォーマンスを向上させるために取るべき主要なアクションは何ですか?

  • A. 役割ベースのシステム監視を実装する
  • B. ファイアウォールログを監査して、ログイン試行のソースを特定します
  • C. アラームしきい値を確認します
  • D. ロギングの詳細を強化する

正解:C

解説:
The primary action that should be taken to improve SIEM performance in a situation where several unsuccessful login attempts are reported by a security audit but not by the SIEM system is to confirm alarm thresholds. A SIEM system is a tool that collects, correlates, analyzes, and reports on security events and incidents from various sources, such as logs, sensors, or agents. A SIEM system can also generate alerts or alarms based on predefined rules or thresholds that indicate a potential security issue or violation. However, if the SIEM system is not configured properly, it may miss some important events or incidents, or generate too many false positives or negatives. Therefore, it is important to confirm that the alarm thresholds are set appropriately, based on the risk appetite, the baseline behavior, and the security objectives of the organization.
The alarm thresholds should be neither too high nor too low, to avoid missing or ignoring real threats, or overwhelming or desensitizing the security analysts. References: CISSP All-in-One Exam Guide, Chapter 7:
Security Operations, Section: Security Information and Event Management, pp. 837-838.


質問 # 960
セキュリティ チームは、組織所有のモバイル デバイスを監視してポリシーを適用する能力が不足していると判断しました。これらのデバイスを保護するためにセキュリティ チームが行うべき最善の策は次のどれですか。

  • A. BYOD(個人所有デバイス持ち込み)ポリシーを確立する
  • B. 各エンドユーザーと協力して安全でないソフトウェアをアンインストールする
  • C. モバイルデバイス管理 (MDM) ソリューションを実装する
  • D. 最も安全なモバイルデバイスを調査し、使用を許可する

正解:C


質問 # 961
データ所有者の責任を最も適切に説明しているものは次のうちどれですか?

  • A. 継続的なデータ整合性のための定期的な監査による品質の確保と検証
  • B. データのストレージとアーカイブを含む、基本的なデータの可用性の維持
  • C. 情報が組織の使命に与える影響の判断
  • D. 適切なユーザーへのアクセスを確保し、適切なレベルのデータ セキュリティを維持します。

正解:C

解説:
The best description of the responsibilities of data owner is determining the impact the information has on the mission of the organization. A data owner is a person who has the authority and accountability for the data assets of the organization. A data owner is responsible for defining the business value, classification, and protection requirements of the data, as well as granting the access rights and privileges to the data users. A data owner should also determine the impact the information has on the mission of the organization, which means assessing how the information supports the business objectives, processes, and functions, and how the loss or compromise of the information would affect the organization's operations, reputation, or compliance.
References: CISSP All-in-One Exam Guide, Eighth Edition, Chapter 2: Asset Security, page 51; [Official (ISC)2 CISSP CBK Reference, Fifth Edition, Chapter 2: Asset Security, page 113]


質問 # 962
さらなる分析のためにセキュリティ オペレーション センター (SC) を利用する場合、セキュリティ情報およびイベント管理 (SIEM) システムを設計および採用する最良の方法は次のうちどれですか?

  • A. 実行およびレポート用のコンテキスト依存タスクを開発します。
  • B. 収集および報告されるイベントの数を制限します。
  • C. 機能をシンプルにして、最も重要なイベントを報告します。
  • D. 精緻な監査削減システムを設計し、すべてのイベントをレポートします。

正解:C


質問 # 963
......

合格させるCISSP日本語テストエンジンPDFで完全版無料問題集がここに:https://jp.fast2test.com/CISSP-JP-premium-file.html


弊社を連絡する

我々は12時間以内ですべてのお問い合わせを答えます。

我々の働いている時間: ( GMT 0:00-15:00 )
月曜日から土曜日まで

サポート: 現在連絡 

English Deutsch 繁体中文 한국어