ISC CISSP-ISSMP 試験概要:
| 認定ベンダー: | ISC2 |
| 試験名: | Information Systems Security Management Professional (ISSMP) |
| 試験番号: | CISSP-ISSMP |
| 関連資格: | CISSP ISSAP ISSEP |
| 認定の有効期間: | 3年間(ISC2の継続的専門教育(CPE)および維持要件を通じて更新可能) |
| 受験料: | USD 599 |
| 試験形式: | コンピュータベース試験 (CBT), 多肢選択式問題 |
| 出題数: | 125 |
| 合格点: | 1000点中700点 |
| 試験時間: | 180 minutes |
| 対応言語: | 英語 |
| サンプル問題: | ISC CISSP-ISSMP サンプル問題 |
| 受験方法: | ISC2認定テストセンターで実施されるコンピュータベースの試験、または提供されている場合はISC2がサポートする試験配信オプションを通じて受験可能です。 |
| 前提条件: | 受験者は、(1) 有効なCISSP認定を保持し、1つ以上のISSMPドメインにおいて通算2年以上のフルタイムの実務経験を有していること、または (2) 2つ以上のISSMPドメインにおいて通算7年以上のフルタイムの実務経験を有していることのいずれかを満たす必要があります。関連する学位またはISC2が承認した資格により、実務経験要件のうち最大1年分を免除することができます。 |
| 公式シラバスのURL: | https://www.isc2.org/certifications/issmp/issmp-certification-exam-outline |
ISC CISSP-ISSMP 試験シラバストピック:
| セクション | 比重 | 目標 |
|---|---|---|
| トピック 1: 法律、倫理、およびセキュリティコンプライアンス管理 | 14% | - 法務およびコンプライアンスガバナンス
|
| トピック 2: コンティンジェンシー管理 | 12% | - ビジネス継続性とレジリエンス
|
| トピック 3: リーダーシップと組織管理 | 21% | - セキュリティ戦略と組織ガバナンスの整合
|
| トピック 4: セキュリティ運用 | 18% | - 運用のセキュリティ機能の管理
|
| トピック 5: リスクマネジメント | 20% | - リスクの特定、評価、および管理
|
| トピック 6: システムライフサイクル管理 | 15% | - システムライフサイクル全体におけるセキュリティの統合
|
ISC CISSP-ISSMP - Information Systems Security Management Professional 認定 CISSP-ISSMP 試験問題:
1. A CISO is asked to reduce the security budget by 20% for the upcoming fiscal year. What is the MOST appropriate FIRST step?
A) Refuse the budget cut outright
B) Resign from the position
C) Conduct a risk-based prioritization of current initiatives to identify which can be reduced/deferred with acceptable risk impact
D) Cut all security initiatives proportionally without analysis
2. Which of the following BEST describes why "artificial intelligence/machine learning" adoption introduces NEW categories of risk that a security manager must consider (e.g., model poisoning, adversarial inputs)?
A) AI/ML systems are inherently immune to traditional cybersecurity risks
B) AI/ML systems carry identical risk profiles to traditional software
C) AI/ML risk is purely a data science concern with no security management relevance
D) AI/ML systems introduce novel attack surfaces (training data integrity, model manipulation, adversarial inputs) beyond traditional software vulnerabilities
3. Which of the following BEST describes the relationship between "organizational risk tolerance" and "control selection"?
A) Control selection should be identical across all organizations regardless of context
B) Higher risk tolerance always requires more stringent controls
C) Controls should be selected and tailored based on the organization's specific risk tolerance, business context, and asset criticality
D) Risk tolerance has no bearing on which controls are implemented
4. Which of the following rate systems of the Orange book has no security controls?
A) D-rated
B) A-rated
C) C-rated
D) E-rated
5. Which of the following BEST describes the concept of "dwell time" in the context of an advanced persistent threat (APT) compromise?
A) The time it takes to patch a vulnerability after disclosure
B) The length of time an attacker remains undetected within a compromised environment
C) The time required to restore from backup
D) The duration of a penetration test engagement
質問と回答:
| 質問 # 1 正解: C | 質問 # 2 正解: D | 質問 # 3 正解: C | 質問 # 4 正解: A | 質問 # 5 正解: B |














1300 お客様のコメント
品質保証JPexamはIT認定試験のシラバスに従って、試験問題の範囲を正確に絞って、的中率が99%の最新問題集を捧げます。
1年間の無料更新サービスJPexamは1年以内に問題集の無料更新サービスを提供し、お客様がいつでも最新版の問題集を持つことを保証いたします。もし試験の内容が変更されたら、弊社は直ちにお客様にお知らせします。それに、弊社の問題集が更新されたら、早速メールで最新バージョンを送付いたします。
全額返金JPexamの問題集を利用すると、短時間で勉強しても試験に合格できるのを保証いたします。試験に不合格になってしまった場合、弊社は全額返金いたします。(
ご購入前のお試しJPexamは問題集のサンプルを無料で提供いたします。ご購入前にサンプルを試用して製品の品質を確認することができます。ご遠慮なく利用してください。
