ISC CGRC 試験概要:
| 認定ベンダー: | ISC2 |
|---|---|
| 試験名: | ガバナンス、リスク、コンプライアンスの認定資格(CGRC) |
| 試験番号: | CGRC |
| 受験料: | $599 USD |
| 合格点: | 700/1000 |
| 認定の有効期間: | 3年(継続専門教育および年次維持費の要件あり) |
| 試験時間: | 180 分 |
| 試験形式: | 高度な設問形式, 多肢選択式 |
| 対応言語: | 英語 |
| 出題数: | 125 |
| 関連資格: | ISC2 Associate CISSP CGRC |
| サンプル問題: | ISC CGRC サンプル問題 |
| 受験方法: | Pearson VUEテストセンターおよびオンライン監督試験。 |
| 前提条件: | CGRC試験アウトラインの1つ以上の分野において、合計2年以上の有給実務経験が必要です。必要な経験を満たしていない受験者は、試験合格後にISC2 Associateとなり、3年以内に経験要件を満たすことができます。 |
| 公式シラバスのURL: | https://www.isc2.org/certifications/cgrc/cgrc-certification-exam-outline |
ISC CGRC 試験シラバストピック:
| セクション | 比重 | 目標 |
|---|---|---|
| セキュリティおよびプライバシー管理策の評価/監査 | 16% | - 評価と監査
|
| セキュリティおよびプライバシー管理策の実装 | 17% | - 管理策の展開
|
| コンプライアンス維持 | 13% | - 継続的な監視と維持
|
| システムのスコープ | 10% | - システムのスコーピング活動
|
| セキュリティとプライバシーのガバナンス、リスク管理、およびコンプライアンス・プログラム | 16% | - ガバナンスとリスク管理
|
| システムコンプライアンス | 14% | - 認可およびコンプライアンス活動
|
| フレームワーク、セキュリティ、およびプライバシー管理策の選定と承認 | 14% | - 管理策選定プロセス
|
ISC Certified in Governance Risk and Compliance 認定 CGRC 試験問題:
問題 #1
Which NIST Special publication provides guidance on security assessment reports? Response:
A. NIST SP 800-53A
B. NIST SP 800-37
C. NIST SP 800-18
D. NIST SP 800-53
問題 #2
What is the objective of the Security Accreditation Decision task? Response:
A. To accredit the information system
B. To approve revisions of NIACAP
C. To determine whether the agency-level risk is acceptable or not.
D. To make an accreditation decision
問題 #3
Significant changes to a system may trigger an event-driven authorization action which may include by are not limited to all of the following except one. Choose the exception.
Response:
A. Moving to a new facility
B. Modifications to security and privacy controls
C. Modifications to how information, including PII, is processed
D. Modifications to system ports protocols and services
E. Changes in information types processed, stored, or transmitted by the system
F. Installation of a new or upgraded operating system, middleware component, or application
問題 #4
The official management decision given by a senior organizational official to authorize operation of an information system and to explicitly accept the risk to organizational operations (including mission, functions, image, or reputation), organizational assets, individuals, other organizations, and the Nation based on the implementation of an agreed-upon set of security controls.
Response:
A. Authorization (to operate)
B. Security Authorization
C. Systems operated
D. Senior Organizational
問題 #5
FIPS 200 provides how many minimum security requirements for federal information and information systems?
The requirements represent a broad based, balanced information security program that addresses the management, operational, and technical aspects of protecting the CIA of federal information and information systems.
Response:
A. 17
B. 5
C. 21
D. 10
解説:
| 問題 #1 正解: A | 問題 #2 正解: C | 問題 #3 正解: A | 問題 #4 正解: A | 問題 #5 正解: A |














985 お客様のコメント
品質保証JPexamはIT認定試験のシラバスに従って、試験問題の範囲を正確に絞って、的中率が99%の最新問題集を捧げます。
1年間の無料更新サービスJPexamは1年以内に問題集の無料更新サービスを提供し、お客様がいつでも最新版の問題集を持つことを保証いたします。もし試験の内容が変更されたら、弊社は直ちにお客様にお知らせします。それに、弊社の問題集が更新されたら、早速メールで最新バージョンを送付いたします。
全額返金JPexamの問題集を利用すると、短時間で勉強しても試験に合格できるのを保証いたします。試験に不合格になってしまった場合、弊社は全額返金いたします。(
ご購入前のお試しJPexamは問題集のサンプルを無料で提供いたします。ご購入前にサンプルを試用して製品の品質を確認することができます。ご遠慮なく利用してください。
