思い立ったらすぐ始めたい、そんな方にぴったりなのがCertShikenのCAS-001対策です。お支払い完了後すぐにダウンロードでき、CompTIA Advanced Security Practitionerの学習を今日からスタートできます。
CompTIA CAS-001 試験概要:
| 認定ベンダー: | CompTIA |
|---|---|
| 試験名: | CompTIA Advanced Security Practitioner (CASP) CAS-001 |
| 試験番号: | CAS-001 |
| 認定の有効期間: | 3年間 |
| 試験形式: | 多肢選択式問題, 実技形式問題(PBQ) |
| 出題数: | 約80問(多肢選択式および実技形式の問題) |
| 関連資格: | CompTIA CySA+ CompTIA Security+ CompTIA PenTest+ |
| 合格点: | 750点(100点~900点のスケールに基づく) |
| 受験料: | 349米ドル(過去の料金であり、地域や時期によって変動する場合があります) |
| 対応言語: | 英語 |
| 試験時間: | 165 分 |
| 推奨トレーニング: | CompTIA 学習用リソース CompTIA公式 CASP対策トレーニング |
| 受験申し込み: | CompTIA認定試験の申込み Pearson VUE CompTIA試験関連情報 |
| サンプル問題: | ![]() |
| 受験方法: | Pearson VUEの試験会場または遠隔監督付きのオンライン形式で実施されます(受験方式の可否は地域や試験バージョンの状況によって異なります)。 |
| 前提条件: | 受験に必須の資格要件はありません。推奨条件:IT業界での実務経験10年以上、うち技術的なセキュリティ関連の実務経験5年以上。 |
| 公式シラバスのURL: | https://www.comptia.org/certifications |
CompTIA CAS-001 試験シラバストピック:
| セクション | 目標 |
|---|---|
| 調査・開発および連携 | - 新興技術とそれに伴うセキュリティ上の影響 - セキュリティ調査および脅威情報の分析 |
| エンタープライズセキュリティ | - エンタープライズ向けセキュリティ制御策の実装 - ID管理およびアクセス制御の戦略 - セキュリティアーキテクチャおよび設計原則 |
| リスク管理およびインシデント対応 | - インシデント対応の手順とライフサイクル - 事業継続および災害復旧計画の策定 - リスク評価および低減戦略 |
| 情報処理、通信技術、業務分野の統合 | - 安全なエンタープライズシステム統合の戦略 - セキュリティに関するガバナンスとコンプライアンスの整合化 - 領域を横断したセキュリティアーキテクチャの計画立案 |
CAS-001試験の疑問を解決するFAQ
CAS-001は、CompTIAが実施する「CompTIA Advanced Security Practitioner (CASP) CAS-001」の認定試験です。この試験に合格すると、「CompTIA Advanced Security Practitioner (CASP)」の認定を取得できます。認定レベルはエキスパートに位置づけられています。関連する認定にはCompTIA Security+、CompTIA CySA+、CompTIA PenTest+などがあります。公式の出題範囲に沿って基礎から応用まで問われるため、CertShikenの495問の練習問題で出題傾向をつかんでおくと、効率的に対策を進められます。
CAS-001の出題数は約80問(多肢選択式および実技形式の問題)、試験時間は165 分です。試験時間を問題数で割ったペースをあらかじめ計算しておき、1問にかけられる時間を意識しながら解くことが大切です。難問に時間を使いすぎて後半が間に合わなくならないよう、本番前にCertShikenの模擬試験で制限時間付きの演習を重ね、時間配分の感覚を身につけておくと安心です。
CAS-001の合格点は750点(100点~900点のスケールに基づく)、受験料は349米ドル(過去の料金であり、地域や時期によって変動する場合があります)です。不合格になった場合、再受験には再度全額の受験料がかかるため、本番の前にCertShikenの495問の練習問題で自己採点を行い、合格点を安定して上回れる状態にしておくことをおすすめします。
CAS-001の受験条件について、公式には次のように案内されています。受験に必須の資格要件はありません。推奨条件:IT業界での実務経験10年以上、うち技術的なセキュリティ関連の実務経験5年以上。最新かつ正確な条件は、必ず公式の試験概要ページでご確認ください。
CAS-001の受験申し込みは、以下の公式窓口から行えます。
なお、受験方式はPearson VUEの試験会場または遠隔監督付きのオンライン形式で実施されます(受験方式の可否は地域や試験バージョンの状況によって異なります)。となっています。
公式では、以下のトレーニングが推奨されています。
公式トレーニングで知識を整理したうえで、CertShikenの495問の練習問題でアウトプットを重ねれば、試験対策の完成度をさらに高められます。
はい。CertShikenではCAS-001問題集の無料サンプルをご用意しており、収録問題の質や構成を購入前にお確かめいただけます。ご購入後は365日間の無料更新が付き、更新期間の終了後も50%割引で更新を継続できるため、長期的な学習にも安心してご利用いただけます。
万が一、ご購入後60日以内にCAS-001試験を受験して不合格となった場合には「返金保証」が適用され、全額をご返金いたします。受験票(受験申込証明)のコピーと公式スコアレポート(Score Report)のPDFを試験実施後2日以内にご提出いただければ、提出後7日以内に手続きが完了します。なお、ご購入後3日以内の受験は対象外(準備期間が短すぎるため)、ダウンロードのみで実際に受験されなかった場合、無料資料や期限切れのご注文も対象外となり、受験者名とお支払い者名が一致している必要があります。返金の代わりに、同等価値の試験対策資料2つを無料でお受け取りいただく選択肢もあり、この場合は元の製品の更新サービスもそのまま継続してご利用いただけます。商品のお届けは、お支払い完了後すぐにダウンロードいただけるほか、1分以内にご登録のメールアドレスへもお送りします。2時間経っても届かない場合はカスタマーサポートまでご連絡ください。インストール可能なパソコンの台数に制限はありません。
CAS-001の出題範囲は、全部で4の分野で構成されています。主な分野としては、「情報処理、通信技術、業務分野の統合」、「エンタープライズセキュリティ」、「リスク管理およびインシデント対応」などが挙げられます。各分野の詳細なトピックと配点は、このページ上部に掲載している試験概要(出題範囲)にまとめていますので、学習計画を立てる際の参考にしてください。
CompTIA Advanced Security Practitioner 認定 CAS-001 試験問題:
A developer is coding the crypto routine of an application that will be installed on a standard headless and diskless server connected to a NAS housed in the datacenter. The developer has written the following six lines of code to add entropy to the routine:
1 - If VIDEO input exists, use video data for entropy 2 - If AUDIO input exists, use audio data for entropy 3 - If MOUSE input exists, use mouse data for entropy 4 - IF KEYBOARD input exists, use keyboard data for entropy 5 - IF IDE input exists, use IDE data for entropy 6 - IF NETWORK input exists, use network data for entropy
Which of the following lines of code will result in the STRONGEST seed when combined?
- A. 3 and 5
- B. 6 and 4
- C. 5 and 2
- D. 2 and 1
正解:B 🗳️
A large financial company has a team of security-focused architects and designers that contribute into broader IT architecture and design solutions. Concerns have been raised due to the security contributions having varying levels of quality and consistency. It has been agreed that a more formalized methodology is needed that can take business drivers, capabilities, baselines, and re-usable patterns into account. Which of the following would BEST help to achieve these objectives?
- A. Introduce an ESA framework
- B. Construct a security control library
- C. Construct a library of re-usable security patterns
- D. Include SRTM in the SDLC
正解:A 🗳️
Company ABC has a 100Mbps fiber connection from headquarters to a remote office 200km (123 miles) away. This connection is provided by the local cable television company. ABC would like to extend a secure VLAN to the remote office, but the cable company says this is impossible since they already use VLANs on their internal network. Which of the following protocols should the cable company be using to allow their customers to establish VLANs to other sites?
- A. EIGRP
- B. IS-IS
- C. 802.1q
- D. MPLS
正解:D 🗳️
A business owner has raised concerns with the Chief Information Security Officer (CISO) because money has been spent on IT security infrastructure, but corporate assets are still found to be vulnerable. The business recently implemented a patch management product and SOE hardening initiative. A third party auditor reported findings against the business because some systems were missing patches. Which of the following statements BEST describes this situation?
- A. Security controls are generally never 100% effective and gaps should be explained to stakeholders and managed accordingly.
- B. The audit findings are invalid because remedial steps have already been applied to patch servers and the remediation takes time to complete.
- C. The business owner is at fault because they are responsible for patching the systems and have already been given patch management and SOE hardening products.
- D. The CISO has not selected the correct controls and the audit findings should be assigned to them instead of the business owner.
正解:A 🗳️
New zero-day attacks are announced on a regular basis against a broad range of technology systems. Which of the following best practices should a security manager do to manage the risks of these attack vectors? (Select TWO).
- A. Establish an emergency response call tree.
- B. Maintain a list of critical systems.
- C. Backup the router and firewall configurations.
- D. Create an inventory of applications.
- E. Update all network diagrams.
正解:B、D 🗳️
ヘルプがないなら、全額返金
CertShikenはヘルプがないなら、全額返金という承諾を通して、自分の商品に自信があります。我々が開発してから、我々の商品を利用して試験に失敗することを見たことがありません。このフィードバックで、我々はあなたの我々の商品から得る利益と試験に合格する高い可能性を確保できます。
我々は、あなたのCAS-001 - CompTIA Advanced Security Practitioner 認証試験を準備するとき、あなたの投資する努力、時間とお金はあなたの失敗に悲しくて失望することを理解しています。我々はあなたの痛さと失望を減少することができなく、でも、我々はあなたの金融損失を担うことができます。
これは、ある原因のため、あなたは我々の商品を利用して試験に失敗したら、我々は我々の商品での支出をあなたに戻り返すことを表明します。あなたは試験に失敗してからの7日以内であなたの失敗した報告書を我々にメールを送るだけです。




Hirai
堀江**
Osaka
川田**
并松**
Ohtani

