ISC CISSP-ISSEP 試験概要:
| 認定ベンダー: | ISC2 |
|---|---|
| 試験名: | CISSP-ISSEP - 情報システムセキュリティエンジニアリングプロフェッショナル |
| 試験番号: | CISSP-ISSEP |
| 認定の有効期間: | 3年間 |
| 試験時間: | 180 分 |
| 対応言語: | English |
| 試験形式: | 多肢選択式問題, シナリオ設定型問題 |
| 合格点: | 満点1000点中700点以上 |
| 出題数: | 125 |
| 関連資格: | CISSP-ISSMP CISSP CISSP-ISSAP |
| 受験料: | 599米ドル |
| 推奨トレーニング: | ISC2公式トレーニングコース |
| 受験申し込み: | Pearson VUE受験手続きページ ISC2公式試験登録ページ |
| サンプル問題: | ISC CISSP-ISSEP サンプル問題 |
| 受験方法: | コンピューターベース試験。Pearson VUE試験会場での受験、またはオンライン監督付き受験に対応 |
| 前提条件: | 有効なCISSP資格を保有していること |
| 公式シラバスのURL: | https://www.isc2.org/certifications/issep/issep-certification-exam-outline |
ISC CISSP-ISSEP 試験シラバストピック:
| セクション | 比重 | 目標 |
|---|---|---|
| システムセキュリティエンジニアリングの基礎 | 24% | - 調達プロセスにおける技術的管理の実施 - システムセキュリティエンジニアリングの基本原則の適用
|
| 安全な運用・変更管理・廃棄処理 | 14% | - 安全な廃棄処理の計画と実施
- 安全な運用体制の支援
|
| システムセキュリティの実装・検証・妥当性確認 | 20% | - 実装状況の妥当性の検証
|
| リスクマネジメント | 20% | - セキュリティリスクマネジメントの原則の適用 - 業務運用に関するリスクの管理
|
| セキュリティの計画立案とエンジニアリング | 22% | - 組織体制および業務運用環境の分析 - システムのセキュリティ要件の定義
|
ISC CISSP-ISSEP - Information Systems Security Engineering Professional 認定 CISSP-ISSEP 試験問題:
問題 #1
Which of the following guidelines is recommended for engineering, protecting, managing, processing, and controlling national security and sensitive (although unclassified) information?
A. DIACAP by the United States Department of Defense (DoD)
B. NISTIRs (Internal Reports)
C. Federal Information Processing Standard (FIPS)
D. Special Publication (SP)
問題 #2
Which of the following NIST documents describes that minimizing negative impact on an organization and a need for sound basis in decision making are the fundamental reasons organizations implement a risk management process for their IT systems?
A. NIST SP 800-37
B. NIST SP 800-30
C. NIST SP 800-53
D. NIST SP 800-60
問題 #3
What is the MOST critical factor to achieve the goals of a security program?
A. Executive management support
B. Effectiveness of security management
C. Budget approved for security resources
D. Capabilities of security resources
問題 #4
Which of the following acts is used to recognize the importance of information security to the economic and national security interests of the United States?
A. Computer Misuse Act
B. FISMA
C. Computer Fraud and Abuse Act
D. Lanham Act
問題 #5
The phase 3 of the Risk Management Framework (RMF) process is known as mitigation planning. Which of the following processes take place in phase 3? Each correct answer represents a complete solution. Choose all that apply.
A. Evaluate mitigation progress and plan next assessment.
B. Identify threats, vulnerabilities, and controls that will be evaluated.
C. Agree on a strategy to mitigate risks.
D. Document and implement a mitigation plan.
解説:
| 問題 #1 正解: D | 問題 #2 正解: B | 問題 #3 正解: A | 問題 #4 正解: B | 問題 #5 正解: A、C、D |














923 お客様のコメント
品質保証JPexamはIT認定試験のシラバスに従って、試験問題の範囲を正確に絞って、的中率が99%の最新問題集を捧げます。
1年間の無料更新サービスJPexamは1年以内に問題集の無料更新サービスを提供し、お客様がいつでも最新版の問題集を持つことを保証いたします。もし試験の内容が変更されたら、弊社は直ちにお客様にお知らせします。それに、弊社の問題集が更新されたら、早速メールで最新バージョンを送付いたします。
全額返金JPexamの問題集を利用すると、短時間で勉強しても試験に合格できるのを保証いたします。試験に不合格になってしまった場合、弊社は全額返金いたします。(
ご購入前のお試しJPexamは問題集のサンプルを無料で提供いたします。ご購入前にサンプルを試用して製品の品質を確認することができます。ご遠慮なく利用してください。
