更新された2024年11月テストエンジン練習CISSP日本語問題集と練習試験合格させます
問題集お試しセットCISSP日本語テストエンジンで問題集トレーニングには1795問あります
質問 # 446
生体認証を扱うとき、次のどれがリプレイ攻撃の一般的指標ですか。
- A. 本人拒否率(FRR)は100で5より大きいです。
- B. 不適切な指定テンプレート
- C. 完全に一致します。
- D. 他人受入率(FAR)は100,000で1より大きいです。
正解:C
質問 # 447
次のどれが最低特権の概念を表していますか?
- A. オブジェクトへのアクセスは所有者だけが利用できます。
- B. オブジェクトへのアクセスは、情報セキュリティポリシーによって保護されていない限り許可されます。
- C. オブジェクトへのアクセスは、アクセスコントロールリスト(ACL)を介してのみ認証されたユーザーに許可されます。
- D. アクセスが特に許可されない限り、オブジェクトへのアクセスは拒否されます。
正解:D
解説:
According to the CISSP CBK Official Study Guide1, the concept of least privilege means that users and processes should only have the minimum access required to perform their tasks, and no more. This reduces the risk of unauthorized or malicious actions, as well as the impact of potential incidents. One way to implement the principle of least privilege is to use a default-deny policy, which means that access to an object is denied unless access is specifically allowed. This is also known as a whitelist approach, which only grants access to predefined and authorized entities. Access to an object is only available to the owner is not a good representation of the concept of least privilege, as it may prevent legitimate access by other authorized users or processes. Access to an object is allowed unless it is protected by the information security policy is not a good representation of the concept of least privilege, as it may allow unnecessary or excessive access by default.
This is also known as a blacklist approach, which only denies access to predefined and unauthorized entities.
Access to an object is only allowed to authenticated users via an Access Control List (ACL) is not a good representation of the concept of least privilege, as it may not consider the authorization and accountability aspects of access control. Authentication is the process of verifying the identity of a user or process, while authorization is the process of granting or denying access based on the identity and the access policy. An ACL is a mechanism that defines the permissions and restrictions for accessing an object, but it does not necessarily enforce the principle of least privilege. References: 1
質問 # 448
次のうちインシデント対応プロセスの最初のステップはどれですか?
- A. 関連するシステムを分離して含む
- B. ネットワークから関係するシステムの接続を切断する
- C. すべての症状を調査して事件を確認する
- D. 事件の原因を特定する
正解:C
質問 # 449
質問に答えるために、以下の情報を参照してください。
セキュリティインシデントの調査中に、不正な個人の金融情報を含むデータベースをホストするシステムにアクセスしていると判断されます。
侵入がシステムプロセスがハングアップの原因である場合、次のどれが影響を受けていますか。
- A. システムの機密性
- B. システムの可用性
- C. システム監査能力
- D. システム保全
正解:B
質問 # 450
なぜすべてのユーザーが積極的にマルチユーザのコンピュータを使用する前に特定されなければなりませんか。
- A. オペレーティングシステムへのアクセスを提供するために
- B. 権限のない者がコンピュータにアクセスすることができないことを確認するために
- C. システム権限へのアクセスを提供するために
- D. 管理はどのユーザーが現在ログオンしていますかを知っていることを確認するために
正解:B
質問 # 451
オンラインバンキングを使用しているときの中間者(MITM)攻撃に対する最も効果的な対策は、次のうちどれですか?
- A. セキュアシェル(SSH)
- B. トランスポート層セキュリティ(TLS)
- C. Secure Sockets Layer(SSL)
- D. Pretty Good Privacy(PGP)
正解:B
解説:
A Man-in-the-Middle (MITM) attack is a type of attack that involves intercepting, modifying, or redirecting the communication between two parties without their knowledge or consent. A MITM attack can compromise the confidentiality, integrity, or availability of the data or the connection. A MITM attack can be performed on various types of networks or protocols, such as wireless, wired, or web. One of the scenarios where a MITM attack can be performed is while using online banking, where the attacker can intercept the communication between the user and the bank website, and steal or manipulate the sensitive information, such as account details, passwords, or transactions. The most effective countermeasure against MITM attacks while using online banking is Transport Layer Security (TLS). TLS is a network protocol that provides a secure and encrypted communication channel between two hosts over an unsecured network, such as the internet. TLS can prevent MITM attacks by using various security features, such as authentication, encryption, integrity, and certificates. Authentication is the process of verifying the identity and credential of the hosts or users involved in the communication. Encryption is the process of transforming the data into an unreadable form to prevent unauthorized access or disclosure of the data. Integrity is the process of ensuring that the data is not modified or corrupted during the transmission. Certificates are the digital documents that contain the public key and the identity information of the hosts or users, and are issued and verified by a trusted third party, such as a Certificate Authority (CA). TLS can help to protect the user and the bank website from MITM attacks by authenticating each other using certificates, encrypting the data using a symmetric key, and ensuring the integrity of the data using a message authentication code (MAC). Secure Sockets Layer (SSL), Pretty Good Privacy (PGP), or Secure Shell (SSH) are not the most effective countermeasures against MITM attacks while using online banking, as they are either outdated, less secure, or less applicable than TLS. References: CISSP All-in-One Exam Guide, Eighth Edition, Chapter 5: Cryptography and Symmetric Key Algorithms, page
272; CISSP Official (ISC)2 Practice Tests, Third Edition, Domain 4: Communication and Network Security, Question 4.14, page 188.
質問 # 452 
- A. Option C
- B. Option A
- C. Option B
- D. Option D
正解:B
質問 # 453
組織は、追跡を改善するために、資産管理システムにモバイルデバイスを含めることを検討しています。参照アーキテクチャのどのシステム層でモバイルデバイスを追跡しますか?
- A. 0
- B. 1
- C. 2
- D. 3
正解:B
質問 # 454
安全なアーキテクチャを設計する際に、基本的に理解する必要があることは何ですか?
- A. システム管理者のスキルセット
- B. システム内の信頼レベル
- C. プロジェクトの予算
- D. システムの規制要件
正解:D
質問 # 455
大企業のセキュリティコンプライアンスマネージャーは、結果の品質と有効性を高めながら、ネットワーク、システム、およびアプリケーションのセキュリティコンプライアンス監査の実行にかかる時間を短縮したいと考えています。
望ましい結果を最もよく達成するには、何を実装する必要がありますか?
- A. 構成管理計画(CMP)
- B. ソースコードリポジトリ
- C. システムパフォーマンスモニタリングアプリケーション
- D. 構成管理データベース(CMDB)
正解:D
解説:
A Configuration Management Database (CMDB) is a database that stores information about configuration items (CIs) for use in change, release, incident, service request, problem, and configuration management processes. A CI is any component or resource that is part of a system or a network, such as hardware, software, documentation, or personnel. A CMDB can provide some benefits for security compliance audits, such as:
* Reducing the time it takes to perform network, system, and application security compliance audits, by providing a centralized and updated source of information about the CIs, their attributes, their relationships, and their dependencies, which can help to identify and locate the CIs that are subject to the audit, and to avoid duplication or omission of the audit tasks.
* Increasing the quality and effectiveness of the results of network, system, and application security compliance audits, by providing a consistent and accurate view of the current and historical state of the CIs, their compliance status, and their changes, which can help to verify and validate the compliance of the CIs with the policies and standards, and to detect and report any deviations or violations.
A source code repository, a configuration management plan (CMP), and a system performance monitoring application are not the best options to achieve the desired results of reducing the time and increasing the quality and effectiveness of network, system, and application security compliance audits, although they may be related or useful tools or techniques. A source code repository is a database or a system that stores and manages the source code of a software or an application, and that supports version control, collaboration, and documentation of the code. A source code repository can provide some benefits for security compliance audits, such as:
* Reducing the time it takes to perform application security compliance audits, by providing a centralized and accessible source of information about the code, its versions, its changes, and its history, which can help to identify and locate the code that is subject to the audit, and to avoid duplication or omission of the audit tasks.
* Increasing the quality and effectiveness of the results of application security compliance audits, by providing a consistent and accurate view of the current and historical state of the code, its compliance status, and its changes, which can help to verify and validate the compliance of the code with the policies and standards, and to detect and report any deviations or violations.
However, a source code repository is not the best option to achieve the desired results of reducing the time and increasing the quality and effectiveness of network, system, and application security compliance audits, as it is only applicable to the application layer, and it does not provide information about the other CIs that are part of the system or the network, such as hardware, documentation, or personnel. A configuration management plan (CMP) is a document or a policy that defines and describes the objectives, scope, roles, responsibilities, processes, and procedures of configuration management, which is the process of identifying, controlling, tracking, and auditing the changes to the CIs. A CMP can provide some benefits for security compliance audits, such as:
* Reducing the time it takes to perform network, system, and application security compliance audits, by providing a clear and comprehensive guidance and direction for the configuration management activities, which can help to ensure the consistency and the efficiency of the configuration management process, and to avoid confusion or conflicts among the configuration management stakeholders.
* Increasing the quality and effectiveness of the results of network, system, and application security compliance audits, by providing a framework and a standard for the configuration management activities, which can help to ensure the alignment and the compliance of the configuration management process with the policies and standards, and to support the audit and the compliance activities.
However, a CMP is not the best option to achieve the desired results of reducing the time and increasing the quality and effectiveness of network, system, and application security compliance audits, as it is not a database or a system that stores and provides information about the CIs, but rather a document or a policy that defines and describes the configuration management process. A system performance monitoring application is a software or a tool that collects and analyzes data and metrics about the performance and the behavior of a system or a network, such as availability, reliability, throughput, response time, or resource utilization. A system performance monitoring application can provide some benefits for security compliance audits, such as:
* Reducing the time it takes to perform network and system security compliance audits, by providing a real-time and automated source of information about the performance and the behavior of the system or the network, which can help to identify and locate the issues or the problems that may affect the compliance of the system or the network, and to avoid manual or tedious audit tasks.
* Increasing the quality and effectiveness of the results of network and system security compliance audits, by providing a quantitative and objective view of the performance and the behavior of the system or the network, which can help to measure and evaluate the compliance of the system or the network with the policies and standards, and to detect and report any anomalies or deviations.
However, a system performance monitoring application is not the best option to achieve the desired results of reducing the time and increasing the quality and effectiveness of network, system, and application security compliance audits, as it is only applicable to the network and system layers, and it does not provide information about the other CIs that are part of the system or the network, such as software, documentation, or personnel.
質問 # 456
Webベースのアプリケーションの脆弱性を最小限に抑えるために、次の最初のアクションのどれがシステムをロックダウンし、攻撃のリスクを最小限に抑えますか?
- A. 脆弱性スキャナーを実行します
- B. アクセス制御を確認する
- C. サーバーにアンチウイルスをインストールします
- D. 最新のベンダーパッチとアップデートを適用します
正解:D
質問 # 457
次のどれがIDフェデレーションとセキュリティアサーションマークアップ言語(SAML)の実装を使用して、システムに対するリプレイ攻撃を最も良く軽減しますか。
- A. 証明書とハードウェアトークンデジタル
- B. 英数字と特殊文字を含むパスワード
- C. 二要素認証
- D. 時限セッションとセキュア・ソケット・レイヤー(SSL)
正解:D
質問 # 458
エンドポイントセキュリティの最小限の実装には、次のうちどれが含まれますか?
- A. 信頼できるプラットフォーム
- B. トークンベースの認証
- C. ワイヤレスアクセスポイント(AP)
- D. ホストベースのファイアウォール
正解:A
質問 # 459
機密データの保管に関するデータ処理ポリシーのベスト プラクティスは次のうちどれですか?
- A. 暗号化キーは暗号化されたデータとは別に保存する必要があります
- B. データ アクセス制御は、Lightweight Directory Access Protocol (LDAP) ソースに関連付けられる必要があります
- C. データ ストアを他のシステムから分離するには、ファイアウォールを使用する必要があります。
- D. ハードドライブは廃棄するために消磁器に通す必要があります
正解:A
質問 # 460
次のうち、情報技術(IT)ガバナンスの責任があるのはどれですか?
- A. 上級IT管理
- B. 最高情報セキュリティ責任者(CISO)
- C. 取締役会
- D. 最高情報責任者(CIO)
正解:C
解説:
The role that has the responsibility of information technology (IT) governance is the Board of Directors. IT governance is the process that involves defining, implementing, and monitoring the policies, standards, and procedures for the management and oversight of the IT resources and activities of an organization, and for ensuring the alignment and integration of the IT objectives and outcomes with the business goals and strategy of the organization. The Board of Directors is the role that has the responsibility of IT governance, as it is the highest governing body of the organization, and it is accountable for the performance, direction, and control of the organization. The Board of Directors can establish and enforce the IT governance framework, and delegate the authority and responsibility for the IT governance to the other roles, such as the Chief Information Officer (CIO), the Chief Information Security Officer (CISO), or the Senior IT Management34. References: CISSP CBK, Fifth Edition, Chapter 1, page 24; 2024 Pass4itsure CISSP Dumps, Question 19.
質問 # 461
リモートユーザーが使用するエンドポイントデバイスが、ネットワークで許可される前に組織の承認済みポリシーに準拠していることを確認するための最も効果的な方法は、次のうちどれですか?
- A. グループポリシーオブジェクト(GPO)
- B. ネットワークアクセス制御(NAC)
- C. モバイルデバイス管理(MDM)
- D. 特権アクセス管理(PAM)
正解:B
質問 # 462
次のどれがフォールト トレラント システムの必須要件ですか?
- A. 複数の管理者が必要です。
- B. 修復するにはシステムをオフラインにする必要があります。
- C. すべてのハードウェア コンポーネントが複製されます。
- D. システムはホット バックアップ サイトに複製されます。
正解:B
質問 # 463 
- A. Option B
- B. Option C
- C. Option A
- D. Option D
正解:A
質問 # 464
先駆者やその他の指標に基づいてネットワークへの侵入を検出するセキュリティ管理者にとって、最初のアクションは何でしょうか?
- A. オペレーティングシステム(OS)にパッチを適用します。
- B. 侵入を隔離して封じ込めます。
- C. 侵入を文書化して確認します。
- D. システムとアプリケーションの所有者に通知します。
正解:A
質問 # 465
......
ISC CISSP日本語問題集カバー率リアル試験問題:https://jp.fast2test.com/CISSP-JP-premium-file.html