CISSP-ISSMP試験は出題範囲が広く、独学だけでは不安を感じる方も少なくありません。ShikenPASSのISC CISSP-ISSMP - Information Systems Security Management Professional問題集は447問の練習問題で出題傾向を網羅しており、弱点分野の克服をしっかりサポートします。
ISC CISSP-ISSMP 試験概要:
| 認定ベンダー: | ISC2 |
|---|---|
| 試験名: | Information Systems Security Management Professional (ISSMP) |
| 試験番号: | CISSP-ISSMP |
| 対応言語: | 英語 |
| 合格点: | 1000点中700点 |
| 認定の有効期間: | 3年間(ISC2の継続的専門教育(CPE)および維持要件を通じて更新可能) |
| 試験形式: | コンピュータベース試験 (CBT), 多肢選択式問題 |
| 試験時間: | 180 分 |
| 出題数: | 125 |
| 関連資格: | CISSP ISSEP ISSAP |
| 受験料: | USD 599 |
| サンプル問題: | DOWNLOAD DEMO |
| 受験方法: | ISC2認定テストセンターで実施されるコンピュータベースの試験、または提供されている場合はISC2がサポートする試験配信オプションを通じて受験可能です。 |
| 前提条件: | 受験者は、(1) 有効なCISSP認定を保持し、1つ以上のISSMPドメインにおいて通算2年以上のフルタイムの実務経験を有していること、または (2) 2つ以上のISSMPドメインにおいて通算7年以上のフルタイムの実務経験を有していることのいずれかを満たす必要があります。関連する学位またはISC2が承認した資格により、実務経験要件のうち最大1年分を免除することができます。 |
| 公式シラバスのURL: | https://www.isc2.org/certifications/issmp/issmp-certification-exam-outline |
ISC CISSP-ISSMP 試験シラバストピック:
| セクション | 比重 | 目標 |
|---|---|---|
| トピック 1: セキュリティ運用 | 18% | - 運用のセキュリティ機能の管理
|
| トピック 2: リーダーシップと組織管理 | 21% | - セキュリティ戦略と組織ガバナンスの整合
|
| トピック 3: コンティンジェンシー管理 | 12% | - ビジネス継続性とレジリエンス
|
| トピック 4: システムライフサイクル管理 | 15% | - システムライフサイクル全体におけるセキュリティの統合
|
| トピック 5: 法律、倫理、およびセキュリティコンプライアンス管理 | 14% | - 法務およびコンプライアンスガバナンス
|
| トピック 6: リスクマネジメント | 20% | - リスクの特定、評価、および管理
|
ISC CISSP-ISSMP - Information Systems Security Management Professional(CISSP-ISSMP)受験者からのよくあるご質問
CISSP-ISSMP試験は、ISC2が実施する公式の認定試験で、合格すると「CISSP Concentrations」の認定を取得できます。この認定はプロフェッショナルレベルに位置づけられています。関連する認定資格にはCISSP、ISSAP、ISSEPなどがあります。詳しい試験情報は、このページの試験概要やほかの質問項目でもご紹介しています。
CISSP-ISSMP試験の問題数は125、制限時間は180 分です。限られた時間で全問を解き切るには、1問ごとのペースを意識し、難しい問題に時間を使いすぎない進め方が重要です。ShikenPASSのテストエンジンには時間制限付きの模擬試験モードがあるため、本番と同じ時間配分で447問の練習問題に取り組めます。受験直前には、必ず時間を計った通し演習で時間感覚を確認しておきましょう。
CISSP-ISSMP試験の合格に必要なスコアは1000点中700点、受験料はUSD 599です。万が一不合格になった場合、再受験には受験料を再度全額支払う必要があるため、本番前の仕上がり確認が欠かせません。ShikenPASSの練習問題で模擬試験を繰り返し、安定して合格点を上回る状態になってから受験することをおすすめします。
はい。ShikenPASSではISC CISSP-ISSMP - Information Systems Security Management Professional(CISSP-ISSMP)問題集の無料サンプルをご用意しており、購入前に内容や品質をご確認いただけます。また、ご購入後は365日間無料で最新版にアップデートでき、更新期間終了後の更新も50%割引でご利用いただけます。
ShikenPASSでは「返金保証」をご用意しています。ご購入後60日以内にCISSP-ISSMP試験を受験して不合格だった場合、受験票の写しと公式スコアレポート(Score Report)のPDFを試験後2日以内にご提出いただければ、7日以内に全額返金の手続きが完了します。なお、ご購入後3日以内の受験や、実際に受験されなかった場合、無料資料・期限切れのご注文は対象外となり、受験者名とお支払い者名の一致が必要です。返金の代わりに、同等の試験資料2点を無料でお受け取りいただき、元の製品の更新サービスを継続することも可能です。商品はお支払い完了後すぐにダウンロードでき、1分以内にメールでもお届けします。2時間経っても届かない場合はカスタマーサポートまでご連絡ください。インストールできるパソコンの台数に制限はありません。
CISSP-ISSMP試験の出題範囲は、公式の発表では全部で6の分野に分かれています。主な分野としては、「リーダーシップと組織管理」(21%)、「コンティンジェンシー管理」(12%)、「法律、倫理、およびセキュリティコンプライアンス管理」(14%)などが挙げられます。各分野に含まれる詳細なトピックは、上記の試験範囲一覧でご確認ください。
ISC CISSP-ISSMP - Information Systems Security Management Professional 認定 CISSP-ISSMP 試験問題:
問題 #1
You are the program manager for your project. You are working with the project managers regarding the procurement processes for their projects. You have ruled out one particular contract type because it is considered too risky for the program. Which one of the following contract types is usually considered to be the most dangerous for the buyer?
A. Cost plus percentage of costs
B. Fixed fee
C. Time and materials
D. Cost plus incentive fee
問題 #2
Mark works as a security manager for SoftTech Inc. He is performing a security awareness program. To be successful in performing the awareness program, he should take into account the needs and current levels of training and understanding of the employees and audience.
There are five key ways, which Mark should keep in mind while performing this activity.
Current level of computer usage
What the audience really wants to learn
How receptive the audience is to the security program
How to gain acceptance
Who might be a possible ally
Which of the following activities is performed in this security awareness process?
A. Separation of duties
B. Audience participation
C. Audience segmentation
D. Stunned owl syndrome
問題 #3
Which of the following BEST describes the primary difference between "strategic risk" and
"operational risk" in a security context?
A. Strategic risk relates to long-term organizational objectives; operational risk relates to day-to-day process failures
B. They are identical concepts
C. Operational risk only applies to IT systems
D. Strategic risk is always lower priority than operational risk
問題 #4
The incident response team has turned the evidence over to the forensic team. Now, it is the time to begin looking for the ways to improve the incident response process for next time. What are the typical areas for improvement?
Each correct answer represents a complete solution. Choose all that apply.
A. Information dissemination policy
B. Additional personnel security controls
C. Incident response plan
D. Electronic monitoring statement
問題 #5
Which of the following BEST describes why "insurance proof-of-loss documentation" should be considered during disaster response, not just afterward?
A. Insurance documentation is irrelevant to the response phase
B. Insurance claims require no supporting documentation
C. Proof-of-loss documentation should only be prepared by insurance adjusters
D. Contemporaneous documentation of damage and response costs during the event supports more accurate and expedited insurance claims later
解説:
| 問題 #1 正解: A | 問題 #2 正解: C | 問題 #3 正解: A | 問題 #4 正解: A、B、C、D | 問題 #5 正解: D |

弊社は製品に自信を持っており、面倒な製品を提供していません。


-Nozu

