CompTIA CAS-001 試験概要:
| 認定ベンダー: | CompTIA |
|---|---|
| 試験名: | CompTIA Advanced Security Practitioner (CASP) CAS-001 |
| 試験番号: | CAS-001 |
| 関連資格: | CompTIA PenTest+ CompTIA Security+ CompTIA CySA+ |
| 試験形式: | 多肢選択式問題, 実技形式問題(PBQ) |
| 合格点: | 750点(100点~900点のスケールに基づく) |
| 受験料: | 349米ドル(過去の料金であり、地域や時期によって変動する場合があります) |
| 出題数: | 約80問(多肢選択式および実技形式の問題) |
| 対応言語: | 英語 |
| 認定の有効期間: | 3年間 |
| 試験時間: | 165 分 |
| 推奨トレーニング: | CompTIA公式 CASP対策トレーニング CompTIA 学習用リソース |
| 受験申し込み: | Pearson VUE CompTIA試験関連情報 CompTIA認定試験の申込み |
| サンプル問題: | CompTIA CAS-001 サンプル問題 |
| 受験方法: | Pearson VUEの試験会場または遠隔監督付きのオンライン形式で実施されます(受験方式の可否は地域や試験バージョンの状況によって異なります)。 |
| 前提条件: | 受験に必須の資格要件はありません。推奨条件:IT業界での実務経験10年以上、うち技術的なセキュリティ関連の実務経験5年以上。 |
| 公式シラバスのURL: | https://www.comptia.org/certifications |
CompTIA CAS-001 試験シラバストピック:
| セクション | 目標 |
|---|---|
| トピック 1: 調査・開発および連携 | - 新興技術とそれに伴うセキュリティ上の影響 - セキュリティ調査および脅威情報の分析 |
| トピック 2: リスク管理およびインシデント対応 | - 事業継続および災害復旧計画の策定 - リスク評価および低減戦略 - インシデント対応の手順とライフサイクル |
| トピック 3: 情報処理、通信技術、業務分野の統合 | - 安全なエンタープライズシステム統合の戦略 - セキュリティに関するガバナンスとコンプライアンスの整合化 - 領域を横断したセキュリティアーキテクチャの計画立案 |
| トピック 4: エンタープライズセキュリティ | - エンタープライズ向けセキュリティ制御策の実装 - ID管理およびアクセス制御の戦略 - セキュリティアーキテクチャおよび設計原則 |
CompTIA Advanced Security Practitioner 認定 CAS-001 試験問題:
問題 #1
The Chief Executive Officer (CEO) has asked the IT administrator to protect the externally facing web server from SQL injection attacks and ensure the backend database server is monitored for unusual behavior while enforcing rules to terminate unusual behavior. Which of the following would BEST meet the CEO's requirements?
A. UTM and HSM
B. DAM and SIEM
C. WAF and SIEM
D. UTM and NIDS
E. WAF and DAM
問題 #2
Which of the following does SAML uses to prevent government auditors or law enforcement from identifying specific entities as having already connected to a service provider through an SSO operation?
A. Restful interfaces
B. Directory services
C. Security bindings
D. Transient identifiers
問題 #3
A new company requirement mandates the implementation of multi-factor authentication to access network resources. The security administrator was asked to research and implement the most cost-effective solution that would allow for the authentication of both hardware and users. The company wants to leverage the PKI infrastructure which is already well established. Which of the following solutions should the security administrator implement?
A. Issue each user one hardware token. Configure the token serial number in the user properties of the central authentication system for each user and require token authentication with PIN for network logon.
B. Deploy USB fingerprint scanners on all desktops, and enable the fingerprint scanner on all laptops. Require all network users to register their fingerprint using the reader and store the information in the central authentication system.
C. Issue individual private/public key pairs to each user, install the private key on the central authentication system, and protect the private key with the user's credentials. Require each user to install the public key on their computer.
D. Issue individual private/public key pairs to each user, install the public key on the central authentication system, and require each user to install the private key on their computer and protect it with a password.
問題 #4
A University uses a card transaction system that allows students to purchase goods using their student ID. Students can put money on their ID at terminals throughout the campus. The security administrator was notified that computer science students have been using the network to illegally put money on their cards. The administrator would like to attempt to reproduce what the students are doing. Which of the following is the BEST course of action?
A. Contact the computer science students and threaten disciplinary action if they continue their actions.
B. Notify the transaction system vendor of the security vulnerability that was discovered.
C. Use a protocol analyzer to reverse engineer the transaction system's protocol.
D. Install a NIDS in front of all the transaction system terminals.
問題 #5
A newly-appointed risk management director for the IT department at Company XYZ, a major pharmaceutical manufacturer, needs to conduct a risk analysis regarding a new system which the developers plan to bring on-line in three weeks. The director begins by reviewing the thorough and well-written report from the independent contractor who performed a security assessment of the system. The report details what seems to be a manageable volume of infrequently exploited security vulnerabilities. The likelihood of a malicious attacker exploiting one of the vulnerabilities is low; however, the director still has some reservations about approving the system because of which of the following?
A. The resulting impact of even one attack being realized might cripple the company financially.
B. The director is new and is being rushed to approve a project before an adequate assessment has been performed.
C. The director should be uncomfortable accepting any security vulnerabilities and should find time to correct them before the system is deployed.
D. Government health care regulations for the pharmaceutical industry prevent the director from approving a system with vulnerabilities.
解説:
| 問題 #1 正解: E | 問題 #2 正解: D | 問題 #3 正解: D | 問題 #4 正解: C | 問題 #5 正解: A |














725 お客様のコメント
品質保証JPexamはIT認定試験のシラバスに従って、試験問題の範囲を正確に絞って、的中率が99%の最新問題集を捧げます。
1年間の無料更新サービスJPexamは1年以内に問題集の無料更新サービスを提供し、お客様がいつでも最新版の問題集を持つことを保証いたします。もし試験の内容が変更されたら、弊社は直ちにお客様にお知らせします。それに、弊社の問題集が更新されたら、早速メールで最新バージョンを送付いたします。
全額返金JPexamの問題集を利用すると、短時間で勉強しても試験に合格できるのを保証いたします。試験に不合格になってしまった場合、弊社は全額返金いたします。(
ご購入前のお試しJPexamは問題集のサンプルを無料で提供いたします。ご購入前にサンプルを試用して製品の品質を確認することができます。ご遠慮なく利用してください。
