申し込みから学習開始まで待たされることはありません。CertJukenでCCZT問題集を購入すると、決済完了後すぐに62問の練習問題をダウンロードして、その日のうちにCloud Security Alliance Certificate of Competence in Zero Trust (CCZT)対策を始められます。
Cloud Security Alliance CCZT 試験概要:
| 認定ベンダー: | Cloud Security Alliance (CSA) |
|---|---|
| 試験名: | Certificate of Competence in Zero Trust (CCZT) |
| 試験番号: | CCZT |
| 受験料: | 175米ドル |
| 対応言語: | 英語 |
| 関連資格: | Certificate of Cloud Security Knowledge (CCSK) |
| 出題数: | 60 |
| 合格点: | 80% |
| 試験時間: | 120 分 |
| 認定の有効期間: | 2年間 |
| 試験形式: | 参照可, 多肢選択式, オンライン遠隔実施 |
| 推奨トレーニング: | CSA公式 CCZTトレーニングおよび学習キット |
| 受験申し込み: | CSA公式 CCZT試験申込み |
| サンプル問題: | ![]() |
| 受験方法: | 遠隔監督付きオンライン方式、参照可、受験権1つにつき2回の受験が可能で有効期間は2年間 |
| 前提条件: | 受験に必須の前提条件はなし。クラウドセキュリティに関する基礎知識またはCCSK資格の保有が推奨される |
| 公式シラバスのURL: | https://cloudsecurityalliance.org/education/cczt/ |
Cloud Security Alliance CCZT 試験シラバストピック:
| セクション | 比重 | 目標 |
|---|---|---|
| トピック 1: Zero Trustの戦略立案と計画 | 20% | - 導入ロードマップと段階的な展開計画 - ポリシーの枠組みとガバナンス体制 - 現状評価と成熟度モデリング |
| トピック 2: Zero Trustの基礎概念 | 15% | - 原則と基本理念 - 導入の背景とリスク低減効果 - 準拠規格:NIST SP 800-207、CISAガイダンス |
| トピック 3: Zero Trustの導入と運用 | 20% | - 監視、ログ管理、継続的な改善 - 継続的な認証と最小権限アクセスの適用 - IDおよびデバイスの信頼性検証 |
| トピック 4: Zero Trustアーキテクチャ | 25% | - ワークロード、ネットワーク、ユーザーのセグメンテーション - 制御プレーンとデータプレーン - 論理構成要素とデータフロー |
| トピック 5: Software Defined Perimeter (SDP) | 20% | - クライアント-ゲートウェイモデルおよびクライアント間モデル - SDPのアーキテクチャと構成要素 - Zero Trustとの統合 |
CCZT試験で受験者がよく抱く疑問
CCZTは、Cloud Security Allianceが実施する「Certificate of Competence in Zero Trust」を取得するための認定試験です。認定レベルは中級/専門レベルで、実務に即した知識とスキルが問われます。Certificate of Cloud Security Knowledge (CCSK)などの関連認定へのステップとしても位置づけられており、キャリアアップを目指す方に広く選ばれています。CertJukenの練習問題を活用すれば、試験の全体像を把握しながら計画的に対策を進められます。
CCZT試験の問題数は60、制限時間は120 分です。1問あたりに使える時間を意識すると、序盤で時間を使いすぎないペース配分が重要になります。見直しの時間を確保するためにも、CertJukenの模擬試験で時間を計りながら解く練習を重ね、本番と同じ時間感覚を身につけておくと安心です。
CCZT試験の合格基準点は80%で、受験料は175米ドルです。万が一不合格になった場合、再受験には再度全額の受験料が必要になります。そのため、本番の前にCertJukenの練習問題で安定して合格点を超えられるかを確認してから受験することをおすすめします。
はい。CertJukenではCCZT練習問題の無料サンプル(PDFデモ)を用意しており、内容や使い勝手を確かめてから購入を判断できます。購入後は365日間の無料更新が付き、更新期間の終了後は50%割引で継続更新を利用できます。
CertJukenでは「返金保証」を用意しています。購入後60日以内にCCZT試験を受験して不合格だった場合、受験票の写しと公式のスコアレポート(Score Report)のPDFを試験後2日以内に提出すれば、7日以内に全額返金の手続きが完了します。なお、受験者名と購入時の支払者名が一致している必要があり、購入から3日以内の受験や、実際に受験しなかった場合は対象外です。返金の代わりに、同等の試験対策教材2つを無料で受け取り、購入済み製品の更新サービスを継続する選択も可能です。商品は購入後すぐにダウンロードでき、メールでも1分以内にお届けします。2時間経っても届かない場合はカスタマーサポートまでご連絡ください。インストールできるパソコンの台数に制限はありません。
CCZT試験の出題範囲は5の分野に分かれています。主な分野はSoftware Defined Perimeter (SDP)(20%)、Zero Trustアーキテクチャ(25%)、Zero Trustの戦略立案と計画(20%)です。各分野の詳細な出題項目は、このページ上部の出題範囲一覧で確認できます。
Cloud Security Alliance Certificate of Competence in Zero Trust (CCZT) 認定 CCZT 試験問題:
問題 #1
What is a server exploitation threat that SDP features (server isolation, single packet authorization [SPA], and dynamic drop-all firewalls) protect against?
A. Denial of service (DoS)/distributed denial of service (DDoS) attacks
B. Domain name system (DNS) poisoning attacks
C. Phishing attacks
D. Certificate forgery attacks
問題 #2
When kicking off ZT planning, what is the first step for an
organization in defining priorities?
A. Identifying the data and assets
B. Define a business case
C. Define the scope
D. Determine current state
問題 #3
To ensure an acceptable user experience when implementing SDP, a
security architect should collaborate with IT to do what?
A. Advise IT stakeholders that the security team will fully manage all aspects of the SDP rollout.
B. Model and plan the user experience, client software distribution,
and device onboarding processes.
C. Build the business case for SDP, based on cost modeling and
business value.
D. Plan to release SDP as part of a single major change or a "big-bang" implementation.
問題 #4
What does device validation help establish in a ZT deployment?
A. Connection based on user
B. Unrestricted public access
C. High-speed network connectivity
D. Trusted connection based on certificate-based keys
問題 #5
Optimal compliance posture is mainly achieved through two key ZT
features:_____ and_____
A. (1) Authentication (2) Authorization of all networked assets
B. (1) Never trusting (2) Reducing the attack surface
C. (1) Principle of least privilege (2) Verifying remote access
connections
D. (1) Discovery (2) Mapping access controls and network assets
解説:
| 問題 #1 正解: A | 問題 #2 正解: C | 問題 #3 正解: B | 問題 #4 正解: D | 問題 #5 正解: A |




寺岛**
Sumida
原日**
Tachibana
