ISA ISA-IEC-62443 試験概要:
| 認定ベンダー: | ISA |
|---|---|
| 試験名: | ISA/IEC 62443 サイバーセキュリティ基礎スペシャリスト |
| 試験番号: | IC32 |
| 出題数: | 90 |
| 関連資格: | ISA/IEC 62443 サイバーセキュリティリスクアセスメントスペシャリスト ISA/IEC 62443 サイバーセキュリティ保守スペシャリスト ISA/IEC 62443 サイバーセキュリティ設計スペシャリスト |
| 認定の有効期間: | 3年 |
| 試験形式: | 多肢選択問題 |
| 受験料: | $2160 USD(非会員、講習および試験料を含む。会員価格:$1728 USD) |
| 対応言語: | 英語 |
| 合格点: | 合否判定のみ(ISAでは具体的なスコアは公表していません。第三者情報に基づく推奨最低基準は75%です) |
| 試験時間: | 90 分 |
| サンプル問題: | ISA ISA-IEC-62443 サンプル問題 |
| 受験方法: | オンライン(監督付き)またはMeazure Learningを通じた指定試験会場 |
| 前提条件: | 必須の前提条件はありません。推奨:サイバーセキュリティ分野で1~3年の経験、特に産業分野での経験。ISA/IEC 62443規格シリーズに精通していると有用です。 |
| 公式シラバスのURL: | https://www.isa.org/certification/certificate-programs/isa-iec-62443-cybersecurity-certificate-program |
ISA ISA-IEC-62443 試験シラバストピック:
| セクション | 目標 |
|---|---|
| トピック 1: サイバー攻撃はどのように発生するか | - 産業サイバーインシデントの事例 - サイバー脅威と攻撃ベクトル - 産業システムにおける脆弱性 |
| トピック 2: 導入対策によるリスク対応 | - アクセス制御の原則 - 産業用ネットワークアーキテクチャとセグメンテーション - 防御の多層化戦略 - ゾーンおよびコンジットモデル |
| トピック 3: セキュリティポリシー、組織、認識向上によるリスク対応 | - セキュリティの認識向上と教育 - 組織におけるセキュリティ上の役割と責任 - セキュリティポリシーと手順 |
| トピック 4: 現在の産業セキュリティ環境を理解する | - 産業用制御システムセキュリティの現状 - OT環境におけるセキュリティ上の課題 - ITとOTの融合 |
| トピック 5: セキュリティプログラムの策定 | - セキュリティ管理組織 - 情報セキュリティ方針の定義 - 長期的なセキュリティプログラムの策定 |
| トピック 6: 選択したセキュリティ対策によるリスク対応 | - 仮想プライベートネットワーク(VPNs) - パッチ管理 - ファイアウォールおよびネットワークセキュリティデバイス - アンチウイルスおよびエンドポイント保護 |
| トピック 7: システムのセキュリティの妥当性確認または検証 | - セキュリティの妥当性確認および検証手法 - 監査とコンプライアンス - セキュリティ対策の継続的改善 |
| トピック 8: CSMSの監視と改善 | - IACSサイバーセキュリティの継続的監視 - セキュリティライフサイクル管理 - インシデントの検知と対応 |
| トピック 9: リスク分析 | - リスクマネジメントの基礎 - リスクおよび脆弱性の分析手法 - サイバーセキュリティリスクアセスメントの概念 |
ISA/IEC 62443 Cybersecurity Fundamentals Specialist 認定 ISA-IEC-62443 試験問題:
問題 #1
What type of security level defines what a component or system is capable of meeting?
Available Choices (select all choices that are correct)
A. Achieved security level
B. Target security level
C. Capability security level
D. Design security level
問題 #2
What caution is advised when using the vector approach to security levels?
A. Vector approaches are always more accurate than qualitative methods.
B. Vector values should be ignored if they do not match industry standards.
C. Vector approaches eliminate the need for risk models.
D. Vector values must align with the asset owner's risk matrix and risk appetite.
問題 #3
Which of the following provides the overall conceptual basis in the design of an appropriate security program?
Available Choices (select all choices that are correct)
A. Reference model
B. Zone model
C. Asset model
D. Reference architecture
問題 #4
What are the two elements of the risk analysis category of an IACS?
A. Business rationale and risk reduction and avoidance
B. Business recovery and risk elimination or mitigation
C. Business rationale and risk identification and classification
D. Risk evaluation and risk identification
問題 #5
An industrial control system requires strong protection against intentional violations using sophisticated means and moderate skills. According to the Security Level (SL) definitions, which SL should be targeted?
A. SL 3
B. SL 2
C. SL 1
D. SL 4
解説:
| 問題 #1 正解: C | 問題 #2 正解: D | 問題 #3 正解: A | 問題 #4 正解: C | 問題 #5 正解: A |














790 お客様のコメント
品質保証JPexamはIT認定試験のシラバスに従って、試験問題の範囲を正確に絞って、的中率が99%の最新問題集を捧げます。
1年間の無料更新サービスJPexamは1年以内に問題集の無料更新サービスを提供し、お客様がいつでも最新版の問題集を持つことを保証いたします。もし試験の内容が変更されたら、弊社は直ちにお客様にお知らせします。それに、弊社の問題集が更新されたら、早速メールで最新バージョンを送付いたします。
全額返金JPexamの問題集を利用すると、短時間で勉強しても試験に合格できるのを保証いたします。試験に不合格になってしまった場合、弊社は全額返金いたします。(
ご購入前のお試しJPexamは問題集のサンプルを無料で提供いたします。ご購入前にサンプルを試用して製品の品質を確認することができます。ご遠慮なく利用してください。
