CompTIA CY0-001 試験概要:
| 認定ベンダー: | CompTIA |
| 試験名: | CompTIA Security+ 認定試験 |
| 試験番号: | SY0-701 |
| 試験時間: | 90 minutes |
| 合格点: | 750(100~900点満点) |
| 試験形式: | 多肢選択式, Performance-Based Questions (PBQs) |
| 受験料: | $370 USD |
| 出題数: | 最大90 |
| 関連資格: | CompTIA A+ CompTIA Network+ CompTIA CySA+ CompTIA CASP+ |
| 対応言語: | English, Japanese, Spanish |
| 認定の有効期間: | 3年 |
| サンプル問題: | CompTIA CY0-001 サンプル問題 |
| 受験方法: | Pearson VUE 試験会場(会場受験)および Pearson VUE のオンライン監督試験 |
| 前提条件: | 推奨: CompTIA Network+ および、セキュリティを重視した IT 管理経験 2年 |
| 公式シラバスのURL: | https://www.comptia.org/certifications/security |
CompTIA CY0-001 試験シラバストピック:
| セクション | 比重 | 目標 |
|---|---|---|
| トピック 1: アーキテクチャと設計 | 21% | - 組み込みシステムおよび特殊用途システムのセキュリティ上の影響を説明する - シナリオに基づき、サイバーセキュリティのレジリエンスを実装する - 物理セキュリティ制御の重要性を説明する - 安全なアプリケーション開発、展開、および自動化の概念を説明する - 暗号概念の基礎を要約する - エンタープライズ環境におけるセキュリティ概念の重要性を説明する - 仮想化およびクラウドセキュリティの概念を要約する - 認証および認可の設計概念を要約する |
| トピック 2: 攻撃、脅威、および脆弱性 | 24% | - シナリオに基づき、アプリケーション攻撃に関連する潜在的な指標を分析する - シナリオに基づき、攻撃の種類を特定するための潜在的な指標を分析する - ソーシャルエンジニアリング攻撃の種類を比較対照する - 脆弱性スキャンの概念を説明する - ペネトレーションテストの概念を説明する - シナリオに基づき、ネットワーク攻撃に関連する潜在的な指標を分析する - 脅威アクターの種類と属性を説明する |
| トピック 3: 運用とインシデント対応 | 16% | - デジタルフォレンジックの主要な側面を説明する - シナリオに基づき、適切なツールを使用して組織のセキュリティを評価する - シナリオに基づき、環境を保護するための緩和技術または制御を適用する - シナリオに基づき、調査を支援するためにデータソースを使用する - インシデント対応におけるポリシー、プロセス、および手順の重要性を要約する |
| トピック 4: 実装 | 25% | - シナリオに基づき、安全なシステム設計を実装する - シナリオに基づき、IDおよびアカウント管理の制御を実装する - シナリオに基づき、クラウドにサイバーセキュリティソリューションを適用する - シナリオに基づき、安全なモバイルデバイスポリシーを実装する - シナリオに基づき、安全なネットワークアーキテクチャの概念を実装する - シナリオに基づき、安全なホスト設定を実装する - シナリオに基づき、認証および認可のソリューションを実装する - シナリオに基づき、公開鍵基盤(PKI)を実装する |
| トピック 5: ガバナンス、リスク、およびコンプライアンス | 14% | - リスク管理のプロセスと概念を説明する - さまざまな種類のセキュリティ制御を比較対照する - 組織に影響を与える規制、標準、およびフレームワークを要約する - セキュリティとの関連におけるプライバシーおよび機微データの概念を説明する - シナリオに基づき、組織のセキュリティポリシーおよび手順に従う |
CompTIA SecAI+ Certification 認定 CY0-001 試験問題:
1. Which of the following roles best supports the implementation of AI governance, risk, and compliance (GRC)? (Choose two.)
A) Security operations center (SOC) analyst
B) Data scientist
C) Network engineer
D) Security architect
E) Software developer
F) Desktop specialist
2. Which of the following helps in managing potential security issues related to model training?
A) National Institute of Standards and Technology (NIST) AI Risk Management Framework (RMF)
B) Organization for Economic Co-operation and Development (OECD)
C) International Organization for Standardization (ISO) 27001
D) General Data Protection Regulation (GDPR)
3. An administrator must conduct generative AI cost monitoring for use in the healthcare industry.
Which of the following criteria is the best way to calculate this cost?
A) Catalog servicing and exchange processing
B) Connection access and exchange gateway
C) Encryption and decryption processing
D) Storage retrieval and prompt processing
4. An organization deploys an application programming interface (API) to allow external customers to perform tasks supported by internally developed AI models. Some customers require limited use of sensitive data.
After the API is deployed, customers report that the API returns sensitive data to all customers. Which of the following is the best action to take with the API?
A) Relocate the model to a virtual private cloud (VPC).
B) Retrain the models on the correct data.
C) Implement role-based access control.
D) Reconfigure the API to use different models.
5. Security analysts want to track potential user behavior anomalies over time. Which of the following is the most comprehensive approach?
A) Using an agentic large language model (LLM) to search for multiple instances of a username in logs
B) Running automated playbooks that monitor standard deviations from a user baseline
C) Using an AI-enabled scanner to compare user permissions to other users in the department
D) Leveraging browser plug-ins that monitor for uncommon sites visited by a user
質問と回答:
| 質問 # 1 正解: B、D | 質問 # 2 正解: A | 質問 # 3 正解: D | 質問 # 4 正解: C | 質問 # 5 正解: B |














1499 お客様のコメント
品質保証JPexamはIT認定試験のシラバスに従って、試験問題の範囲を正確に絞って、的中率が99%の最新問題集を捧げます。
1年間の無料更新サービスJPexamは1年以内に問題集の無料更新サービスを提供し、お客様がいつでも最新版の問題集を持つことを保証いたします。もし試験の内容が変更されたら、弊社は直ちにお客様にお知らせします。それに、弊社の問題集が更新されたら、早速メールで最新バージョンを送付いたします。
全額返金JPexamの問題集を利用すると、短時間で勉強しても試験に合格できるのを保証いたします。試験に不合格になってしまった場合、弊社は全額返金いたします。(
ご購入前のお試しJPexamは問題集のサンプルを無料で提供いたします。ご購入前にサンプルを試用して製品の品質を確認することができます。ご遠慮なく利用してください。
