CISSP日本語事前に試験練習テストで使おう(最新1795問題) [Q212-Q236]

Share

CISSP日本語事前に試験練習テストで使おう(最新1795問題)

有効なCISSP日本語試験解答PDF一年無料更新

質問 # 212
ある組織は、中核となるビジネス サービスをサポートするために、従来の産業用制御システム (ICS) を運用しています。その管理は、管理コンソール ソフトウェアを使用してリモートで実行する必要があります。このソフトウェアは、多くの攻撃に対して脆弱であることが知られている古いバージョンの Java ランタイム環境 (JPE) に依存しています。このリスクはどのように管理するのが最善ですか?

  • A. ICS を廃止し、モデム テクノロジーに緩和するよう経営陣を説得します。
  • B. 管理目的で使用されるホストをエアギャップして強化します。
  • C. 完全な ICS を独自のネットワーク セグメントに移動して分離します。
  • D. すべてのクライアントと脆弱な管理ステーションの間に制限的なプロキシを展開します。

正解:B

解説:
Air-gapping and hardening the host used for management purposes is the best way to manage the risk of a legacy Industrial Control System (ICS) that depends on a vulnerable version of the Java Runtime Environment (JRE). Air-gapping means disconnecting the host from any network or internet connection, so that it can only be accessed physically. Hardening means applying security patches, disabling unnecessary services, and configuring security settings to reduce the attack surface of the host. This way, the risk of remote exploitation of the JRE vulnerability is minimized, and the host is protected from other potential threats. Isolating the full ICS by moving it onto its own network segment may reduce the exposure of the system, but it does not eliminate the possibility of network-based attacks. Convincing the management to decommission the ICS and migrate to a modern technology may be the ideal solution, but it may not be feasible or cost-effective, especially if the ICS cannot be replaced. Deploying a restrictive proxy between all clients and the vulnerable management station may also help to filter and monitor the network traffic, but it does not address the root cause of the vulnerability, and it may introduce additional complexity and overhead to the system. References:
CISSP All-in-One Exam Guide, Eighth Edition, Chapter 4: Security Architecture and Engineering, page 447.
Official (ISC)2 CISSP CBK Reference, Fifth Edition, Chapter 4: Security Architecture and Engineering, page
321.


質問 # 213

  • A. Option D
  • B. Option C
  • C. Option B
  • D. Option A

正解:B


質問 # 214
セキュリティ意識向上プログラムをサポートするセキュリティ意識向上の期待される結果は何ですか?

  • A. 意識向上活動は、セキュリティの懸念に焦点を合わせ、それに応じてそれらの懸念に対応するために使用する必要があります
  • B. 意識はトレーニングの活動または一部ではなく、プログラムをサポートするための永続性の状態です。
  • C. 意識は訓練ではありません。意識向上のプレゼンテーションの目的は、単にセキュリティに注意を集中することです。
  • D. 意識はトレーニングです。意識向上プレゼンテーションの目的は、セキュリティの注目を広げることです。

正解:C

解説:
The expected outcome of security awareness in support of a security awareness program is that awareness is not training, but the purpose of awareness presentation is simply to focus attention on security. A security awareness program is a set of activities and initiatives that aim to raise the awareness and understanding of the security policies, standards, procedures, and guidelines among the employees, contractors, partners, or customers of an organization. A security awareness program can provide some benefits for security, such as improving the knowledge and the skills of the parties, changing the attitudes and the behaviors of the parties, and empowering the parties to make informed and secure decisions regarding the security activities. A security awareness program can involve various methods and techniques, such as posters, newsletters, emails, videos, quizzes, games, or rewards. Security awareness is not training, but the purpose of awareness presentation is simply to focus attention on security. Security awareness is the state or condition of being aware or conscious of the security issues and incidents, and the importance and implications of security. Security awareness is not the same as training, as it does not aim to teach or instruct the parties on how to perform specific tasks or functions related to security, but rather to inform and remind the parties of the security policies, standards, procedures, and guidelines, and their roles and responsibilities in complying and supporting them. The purpose of awareness presentation is simply to focus attention on security, as it does not provide detailed or comprehensive information or guidance on security, but rather to highlight or emphasize the key or relevant points or messages of security, and to motivate or persuade the parties to pay attention and care about security.
Awareness activities should be used to focus on security concerns and respond to those concerns accordingly, awareness is not an activity or part of the training but rather a state of persistence to support the program, and awareness is training, the purpose of awareness presentations is to broaden attention of security are not the expected outcomes of security awareness in support of a security awareness program, although they may be related or possible statements. Awareness activities should be used to focus on security concerns and respond to those concerns accordingly is a statement that describes one of the possible objectives or functions of awareness activities, but it is not the expected outcome of security awareness, as it does not define or differentiate security awareness from training, and it does not specify the purpose of awareness presentation.
Awareness is not an activity or part of the training but rather a state of persistence to support the program is a statement that partially defines security awareness, but it is not the expected outcome of security awareness, as it does not differentiate security awareness from training, and it does not specify the purpose of awareness presentation. Awareness is training, the purpose of awareness presentations is to broaden attention of security is a statement that contradicts the definition of security awareness, as it confuses security awareness with training, and it does not specify the purpose of awareness presentation.


質問 # 215
実証済みのアプリケーションセキュリティ原則には、次のうちどれが含まれますか。

  • A. インフラストラクチャセキュリティ管理の受け入れ
  • B. 攻撃面積の最小化
  • C. ネットワーク境界を強化する
  • D. 独立したモジュールを開発する

正解:B


質問 # 216

  • A. Option D
  • B. Option B
  • C. Option C
  • D. Option A

正解:A


質問 # 217
情報セキュリティ管理システム (ISMS) を開発する際に最初に考慮すべき点は次のうちどれですか?

  • A. 経営陣が許容できる残留リスクのレベルを特定する
  • B. 情報資産の価値を理解する
  • C. 関連する法律および規制のコンプライアンス要件を特定する
  • D. 組織に適用される契約上のセキュリティ義務を特定します。

正解:B


質問 # 218

  • A. Option A
  • B. Option D
  • C. Option B
  • D. Option C

正解:A


質問 # 219
インターネット プロトコル (IP) データグラムに追加すると、機密性と整合性の両方を提供するインターネット プロトコル セキュリティ (IPSec) メカニズムはどれですか?

  • A. 認証ヘッダー (AH)
  • B. メッセージ認証コード (MAC)
  • C. セキュリティ ペイロードのカプセル化 (ESP)
  • D. インターネット キー交換 (IKE)

正解:C


質問 # 220
次のうち、認証システムに対してDoS(サービス拒否)を引き起こす可能性のあるものはどれですか?

  • A. Remote access audit logs
  • B. Hashing of audit logs
  • C. No archiving of audit logs
  • D. Encryption of audit logs

正解:A


質問 # 221

  • A. Option B
  • B. Option D
  • C. Option C
  • D. Option A

正解:A


質問 # 222
デバイスに対する簡易電力分析 (SPA) 攻撃は、次のどれを直接観察しますか?

  • A. 世代
  • B. 磁気
  • C. 消費量
  • D. 静電気放電

正解:C

解説:
A Simple Power Analysis (SPA) attack against a device directly observes the consumption of power by the device. SPA is a type of side channel attack that exploits the variations in the power consumption of a device, such as a smart card or a cryptographic module, to infer information about the operations or data processed by the device. SPA can reveal the type, length, or sequence of instructions executed by the device, or the value of the secret key or data used by the device. The other options are not directly observed by SPA, but rather different aspects or effects of power. Static discharge is the sudden flow of electricity between two objects with different electric potentials. Generation is the process of producing electric power from other sources of energy. Magnetism is the physical phenomenon of attraction or repulsion between magnetic materials or fields. References: CISSP All-in-One Exam Guide, Eighth Edition, Chapter 10, p. 525; Official (ISC)2 CISSP CBK Reference, Fifth Edition, Chapter 3, p. 163.


質問 # 223
次のうち、ボーダーゲートウェイプロトコル(BGP)の目的を最もよく表しているのはどれですか?

  • A. インターネットルーター間のネットワークパスのリストを維持します。
  • B. クラウド対応アプリケーションにファイアウォールサービスを提供します。
  • C. ルーティング情報プロトコル(RIP)バージョン2アドバタイズメントを隣接するレイヤー3デバイスに提供します。
  • D. 自律システム間の効率的なネットワークパスのリストを維持します。

正解:D

解説:
The best description of the purpose of Border Gateway Protocol (BGP) is that it maintains a list of efficient network paths between autonomous systems. BGP is a type of routing protocol that is used to exchange routing and reachability information among different networks or autonomous systems on the internet. An autonomous system is a collection of networks or routers that are under the same administrative control or authority, and that share a common routing policy. BGP maintains a list of efficient network paths between autonomous systems, by selecting the best routes based on various factors, such as the number of hops, the bandwidth, the latency, or the policy preferences. BGP can improve the performance, reliability, and security of the internet, and support the scalability and diversity of the internet topology12. References: CISSP CBK, Fifth Edition, Chapter 4, page 353; CISSP Practice Exam - FREE 20 Questions and Answers, Question 17.


質問 # 224
マルチユーザー コンピュータを使用する前に、すべてのユーザーを明確に識別する必要があるのはなぜですか?

  • A. 現在ログオンしているユーザーを管理者が確実に把握できるようにするため
  • B. オペレーティング システムへのアクセスを提供するため
  • C. 権限のない人がコンピュータにアクセスできないようにするため
  • D. システム権限へのアクセスを提供するため

正解:C

解説:
The main reason why all users must be positively identified prior to using multi-user computers is to ensure that unauthorized persons cannot access the computers. Positive identification is the process of verifying the identity of a user or a device before granting access to a system or a resource2. Positive identification can be achieved by using one or more factors of authentication, such as something the user knows, has, or is. Positive identification can enhance the security and accountability of the system, and prevent unauthorized or malicious access. Providing access to system privileges, providing access to the operating system, and ensuring that management knows what users are currently logged on are not the primary reasons why all users must be positively identified prior to using multi-user computers, as they are more related to the functionality or administration of the system, rather than the security. References: 2: CISSP For Dummies, 7th Edition, Chapter 4, page 89.


質問 # 225
使用される属性の観点から、属性ベースのアクセス制御(ABAC)の特性と見なす必要がある要素は次のうちどれですか?

  • A. 随意アクセス制御(DAC)およびアクセス制御リスト(ACL)
  • B. 強制アクセス制御(MAC)および随意アクセス制御(DAC)
  • C. 役割ベースのアクセス制御(RBAC)および強制アクセス制御(MAC)
  • D. 役割ベースのアクセス制御(RBAC)およびアクセス制御リスト(ACL)

正解:D

解説:
RBAC Integration: Attribute-Based Access Control (ABAC) can be integrated with RBAC. User roles (from RBAC) can become one of the many attributes considered by an ABAC system when making access decisions.
* ACL Refinement: ABAC can leverage and refine the use of ACLs. With ABAC, permissions on an ACL can be granted or denied based on various attributes rather than solely on user identities or roles.


質問 # 226

  • A. Option D
  • B. Option C
  • C. Option B
  • D. Option A

正解:B


質問 # 227
ソフトウェア開発会社には、ソフトウェア製品を提供するための短いスケジュールがあります。ソフトウェア開発チームは、開発時間を短縮するためにオープンソースソフトウェアライブラリを使用することを決定しました。オープンソースソフトウェアライブラリを使用する場合、ソフトウェア開発者はどのような概念を考慮する必要がありますか?

  • A. オープンソースライブラリは常に更新されているため、攻撃者が悪用する脆弱性が存在する可能性はほとんどありません。
  • B. オープンソースライブラリには既知の脆弱性が含まれており、攻撃者はこれらの脆弱性を実際に悪用します。
  • C. オープンソースライブラリには未知の脆弱性が含まれているため、使用しないでください。
  • D. オープンソースライブラリは誰でも使用でき、これらのライブラリの脆弱性は悪用されないという共通の理解があります。

正解:B


質問 # 228
次のうちどれがアプリケーションインターフェイスのテストを実行する際の最も重要なセキュリティ目標ですか?

  • A. アプリケーション詳細の漏洩を防ぐために外部インターフェースに関連するエラー状態を調べる
  • B. ソフトウェア、ハードウェア、およびネットワーク接続の互換性を確認する
  • C. すべてのプラットフォームがサポートされ、正しく機能していることを確認します
  • D. システムまたはコンポーネントが互いにデータと制御を渡しているかどうかを評価する

正解:A

解説:
The most important security goal when performing application interface testing is to examine error conditions related to external interfaces to prevent application details leakage. Application interface testing is a type of testing that focuses on the interactions between different systems or components through their interfaces, such as APIs, web services, or protocols. Error conditions related to external interfaces can occur when the input, output, or communication is invalid, incomplete, or unexpected. These error conditions can cause the application to reveal sensitive or confidential information, such as error messages, stack traces, configuration files, or database queries, which can be exploited by attackers to gain access or compromise the system.
Therefore, it is important to examine these error conditions and ensure that the application handles them properly and securely. Confirming that all platforms are supported and function properly, evaluating whether systems or components pass data and control correctly to one another, and verifying compatibility of software, hardware, and network connections are not security goals, but functional or performance goals of application interface testing. References: CISSP All-in-One Exam Guide, Eighth Edition, Chapter 8: Software Development Security, page 1000; Official (ISC)2 Guide to the CISSP CBK, Fifth Edition, Chapter 7:
Software Development Security, page 922.


質問 # 229
どのWebサービスセキュリティ(WS-Security)仕様が、セキュリティトークンの発行、更新、および検証の方法をネゴシエートしますか?下の画像で正しい仕様をクリックしてください。

正解:

解説:

Explanation
WS-Trust
The protocol used for issuing security tokens is based on WS-Trust. WS-Trust is a Web service specification that builds on WS-Security. It describes a protocol used for issuance, exchange, and validation of security tokens. WS-Trust provides a solution for interoperability by defining a protocol for issuing and exchanging security tokens, based on token format, namespace, or trust boundaries.
Reference: https://msdn.microsoft.com/en-us/library/ff650503.aspx


質問 # 230
組織のソーシャルメディアコンテンツの保存期間はどのように定義する必要がありますか?

  • A. 組織の記録保持ポリシーによる
  • B. 使用可能なストレージスペースの量による
  • C. 各ソーシャルメディアサービスの保持ポリシーによる
  • D. 最高情報責任者(CIO)による

正解:A


質問 # 231
セキュリティ評価の実行フェーズの直後に実行する必要があるアクションはどれですか?

  • A. 調査結果の最終分析を実施する
  • B. 修復推奨事項をテストします。
  • C. 推奨事項を提示するレポートを作成します。
  • D. 緩和活動を実行します。

正解:C


質問 # 232
ある組織が、ユーザーが匿名プロキシを使用して許可されていないWebサイトにアクセスしていることを発見しました。次のうちどれが将来の発生を防ぐための最良の方法ですか?

  • A. 既知の匿名プロキシのインターネットプロトコル(IP)アドレスをブロックする
  • B. プロキシから匿名性を削除します
  • C. プロキシ要求のインターネットプロトコル(IP)トラフィックを分析します
  • D. ファイアウォールのプロキシサーバーを無効にします

正解:A

解説:
Anonymous proxies are servers that act as intermediaries between the user and the internet, hiding the user's real IP address and allowing them to bypass network restrictions and access unauthorized websites. The best way to prevent users from visiting unauthorized websites using anonymous proxies is to block the IP address of known anonymous proxies on the firewall or router. This will prevent the user from establishing a connection with the proxy server and accessing the blocked content. Removing the anonymity from the proxy, analyzing IP traffic for proxy requests, or disabling the proxy server on the firewall are not effective ways to prevent future occurrences, as they do not address the root cause of the problem or require more resources and time to implement. References: The 17 Best Proxy Sites to Help You Browse Anonymously; Buy HTTP proxies and Socks5 | Anonymous Proxies; The Best Free Proxy Server List: Tested & Working! (2024).


質問 # 233

  • A. Option A
  • B. Option D
  • C. Option B
  • D. Option C

正解:A


質問 # 234
フェデレーションID管理(FIM)のアプリケーションプログラミングインターフェイス(API)アクセスを処理するために構築されている承認標準は次のうちどれですか?

  • A. セキュリティアサーションマークアップ言語(SAML)
  • B. ターミナルアクセスコントローラアクセスコントロールシステムプラス(TACACS +)
  • C. リモート認証ダイヤルインユーザーサービス(RADIUS)
  • D. オープン認証(OAuth)

正解:D


質問 # 235
フォレンジックスペシャリストは、ターゲットシステムのコピーにあるオペレーティングシステムファイルの大部分を調査から除外するにはどうすればよいですか?

  • A. ドライブイメージにメッセージダイジェスト(MD)またはセキュアハッシュを生成して、検査対象のメディアの改ざんを検出します。
  • B. オペレーティングシステムの無害なファイル、およびインストールされている既知のプログラムを破棄します。
  • C. 同じオペレーティングシステムとパッチレベルのシステムからのファイルの暗号化ハッシュの比較データベースを作成します。
  • D. 問題のメディアの別のバックアップを取り、関係のないオペレーティングシステムファイルをすべて削除します。

正解:C


質問 # 236
......

Certified Information Systems Security Professional (CISSP日本語版)無料更新認定サンプル問題:https://jp.fast2test.com/CISSP-JP-premium-file.html


弊社を連絡する

我々は12時間以内ですべてのお問い合わせを答えます。

我々の働いている時間: ( GMT 0:00-15:00 )
月曜日から土曜日まで

サポート: 現在連絡 

English Deutsch 繁体中文 한국어