ISO-IEC-27001-Lead-Implementer試験の対策に必要なものを、CertJukenなら一か所でそろえられます。PECB Certified ISO/IEC 27001 Lead Implementerの350問の練習問題から無料サンプル、更新サービスまで、受験準備のすべてをまとめて提供します。
PECB ISO-IEC-27001-Lead-Implementer 試験概要:
| 認定ベンダー: | PECB |
|---|---|
| 試験名: | PECB Certified ISO/IEC 27001 Lead Implementer Exam |
| 試験番号: | ISO-IEC-27001-Lead-Implementer |
| 関連資格: | PECB Certified ISO/IEC 27001 Foundation PECB Certified ISO/IEC 27001 Lead Auditor PECB Certified ISO/IEC 27005 Risk Manager |
| 認定の有効期間: | 3年間 |
| 受験料: | 地域やトレーニングプロバイダーによって異なります(通常、受験バウチャーまたはトレーニングパッケージを含めて500〜1000米ドルの範囲です) |
| 試験時間: | 180 分 |
| 試験形式: | 監視付き試験(オンラインまたはオンサイト), 選択式問題, クローズドブック(資料持ち込み不可) |
| 合格点: | 70% |
| 対応言語: | フランス語, ポルトガル語, スペイン語, アラビア語, 英語, ドイツ語 |
| 出題数: | 80 |
| 推奨トレーニング: | ISO/IEC 27001 情報セキュリティマネジメントシステムコース PECB ISO/IEC 27001 Lead Implementer研修 |
| 受験申し込み: | PECB認定プロセス PECB公式認定試験 |
| サンプル問題: | ![]() |
| 受験方法: | PECB認定パートナーを通じたオンライン監視付き試験またはオンサイト試験 |
| 前提条件: | 情報セキュリティ概念の基本的な理解が推奨されます。ISO/IEC 27001 Foundationの知識があると有益ですが、必須ではありません。 |
| 公式シラバスのURL: | https://pecb.com |
PECB ISO-IEC-27001-Lead-Implementer 試験シラバストピック:
| セクション | 目標 |
|---|---|
| トピック 1: 認証審査の準備とISMSの維持 | - 認証準備
|
| トピック 2: 監視、測定、および継続的改善 | - パフォーマンス評価
|
| トピック 3: ISMSの導入と運用 | - ISMS管理策の導入
|
| トピック 4: ISMS導入の計画と開始 | - リスクマネジメント計画
|
| トピック 5: 情報セキュリティマネジメントシステム(ISMS)の基礎 | - ISO/IEC 27001の原則と構成
|
PECB Certified ISO/IEC 27001 Lead Implementerに関するよくある質問
ISO-IEC-27001-Lead-Implementerは、PECBが実施する「PECB Certified ISO/IEC 27001 Lead Implementer」を取得するための認定試験です。認定レベルはProfessionalで、実務に即した知識とスキルが問われます。PECB Certified ISO/IEC 27001 Lead Auditor、PECB Certified ISO/IEC 27001 Foundation、PECB Certified ISO/IEC 27005 Risk Managerなどの関連認定へのステップとしても位置づけられており、キャリアアップを目指す方に広く選ばれています。CertJukenの練習問題を活用すれば、試験の全体像を把握しながら計画的に対策を進められます。
ISO-IEC-27001-Lead-Implementer試験の問題数は80、制限時間は180 分です。1問あたりに使える時間を意識すると、序盤で時間を使いすぎないペース配分が重要になります。見直しの時間を確保するためにも、CertJukenの模擬試験で時間を計りながら解く練習を重ね、本番と同じ時間感覚を身につけておくと安心です。
ISO-IEC-27001-Lead-Implementer試験の合格基準点は70%で、受験料は地域やトレーニングプロバイダーによって異なります(通常、受験バウチャーまたはトレーニングパッケージを含めて500〜1000米ドルの範囲です)です。万が一不合格になった場合、再受験には再度全額の受験料が必要になります。そのため、本番の前にCertJukenの練習問題で安定して合格点を超えられるかを確認してから受験することをおすすめします。
はい。CertJukenではISO-IEC-27001-Lead-Implementer練習問題の無料サンプル(PDFデモ)を用意しており、内容や使い勝手を確かめてから購入を判断できます。購入後は365日間の無料更新が付き、更新期間の終了後は50%割引で継続更新を利用できます。
CertJukenでは「返金保証」を用意しています。購入後60日以内にISO-IEC-27001-Lead-Implementer試験を受験して不合格だった場合、受験票の写しと公式のスコアレポート(Score Report)のPDFを試験後2日以内に提出すれば、7日以内に全額返金の手続きが完了します。なお、受験者名と購入時の支払者名が一致している必要があり、購入から3日以内の受験や、実際に受験しなかった場合は対象外です。返金の代わりに、同等の試験対策教材2つを無料で受け取り、購入済み製品の更新サービスを継続する選択も可能です。商品は購入後すぐにダウンロードでき、メールでも1分以内にお届けします。2時間経っても届かない場合はカスタマーサポートまでご連絡ください。インストールできるパソコンの台数に制限はありません。
ISO-IEC-27001-Lead-Implementer試験の出題範囲は5の分野に分かれています。主な分野は監視、測定、および継続的改善、情報セキュリティマネジメントシステム(ISMS)の基礎、ISMSの導入と運用です。各分野の詳細な出題項目は、このページ上部の出題範囲一覧で確認できます。
PECB Certified ISO/IEC 27001 Lead Implementer 認定 ISO-IEC-27001-Lead-Implementer 試験問題:
問題 #1
Scenario 3: Socket Inc. is a dynamic telecommunications company specializing in wireless products and services, committed to delivering high-quality and secure communication solutions. Socket Inc. leverages innovative technology, including the MongoDB database, renowned for its high availability, scalability, and flexibility, to provide reliable, accessible, efficient, and well-organized services to its customers. Recently, the company faced a security breach where external hackers exploited the default settings of its MongoDB database due to an oversight in the configuration settings, which had not been properly addressed.
Fortunately, diligent data backups and centralized logging through a server ensured no loss of information. In response to this incident, Socket Inc. undertook a thorough evaluation of its security measures. The company recognized the urgent need to improve its information security and decided to implement an information security management system (ISMS) based on ISO/IEC 27001.
To improve its data security and protect its resources, Socket Inc. implemented entry controls and secure access points. These measures were designed to prevent unauthorized access to critical areas housing sensitive data and essential assets. In compliance with relevant laws, regulations, and ethical standards, Socket Inc.
implemented pre-employment background checks tailored to business needs, information classification, and associated risks. A formalized disciplinary procedure was also established to address policy violations.
Additionally, security measures were implemented for personnel working remotely to safeguard information accessed, processed, or stored outside the organization ' s premises.
Socket Inc. safeguarded its information processing facilities against power failures and other disruptions.
Unauthorized access to critical records from external sources led to the implementation of data flow control services to prevent unauthorized access between departments and external networks. In addition, Socket Inc.
used data masking based on the organization's topic-level general policy on access control and other related topic-level general policies and business requirements, considering applicable legislation. It also updated and documented all operating procedures for information processing facilities and ensured that they were accessible to top management exclusively.
The company also implemented a control to define and implement rules for the effective use of cryptography, including cryptographic key management, to protect the database from unauthorized access. The implementation was based on all relevant agreements, legislation, regulations, and the information classification scheme. Network segregation using VPNs was proposed to improve security and reduce administrative efforts.
Regarding the design and description of its security controls, Socket Inc. has categorized them into groups, consolidating all controls within a single document. Lastly, Socket Inc. implemented a new system to maintain, collect, and analyze information about information security threats and integrate information security into project management.
Based on the scenario above, answer the following question:
Which of the following physical controls was NOT included in Socket Inc. ' s strategy?
A. Annex A 7.11 Supporting utilities
B. Annex A 7.2 Physical entry
C. Annex A 7.9 Security of assets off-premises
問題 #2
Scenario 5: Bytes iS a dynamic and innovative Company specializing in the design, manufacturing. and distribution Of hardware and software, with a focus On providing comprehensive network and supporting services. It is headquartered in the vibrant tech hub of Lagos, Nigeria. It has a diverse and dedicated team, boasting a workforce of over 800 employees who are passionate about delivering cutting-edge solutions to their Clients. Given the nati-jte Of its business. Bytes frequently handles sensitive data both internally and When collaborating With Clients and partners.
Recognizing the Challenges inherent in securely sharing data with clients. partners, and within its own internal operations. Bytes has implemented robust information security measures, They utilize a defined risk assessment process, which enables them to assess and address potential threats and information security risks.
This process ensures compliance with ISOflEC 27001 requirements, a critical aspect of Bytes ' operations.
Initially. Bytes identified both external and internal issues that are relevant to its purpose and that impact its ability to achieve the intended information security management System Outcomes, External issues beyond the company ' S control include factors Such as social and Cultural dynamics, political. legal.
normative, and regulatory environments, financial and macroeconomic conditions. technological developments, natural factors, and competitive pressures. Internal issues, which are within the organization ' s control, encompass aspects like the company ' s culture. its policies, objectives, and strategies; govetnance structures.
roles, and responsibilities: adopted standards and guidelines; contractual relationships that influence processes within the ISMS scope: processes and procedures resources and knowledge capabilities; physical infrastructure information systems. information flows. and decisiorwnaking processes; as well as the results of previous audits and risk assessments. Bytes also focused on identifying the interested parties relevant to the ISMS understanding their requirements, and determining which Of those requirements will be addressed by the ISMS In pursuing a secure digital environment, Bytes leverages the latest technology, utilizing automated vulnerability scanning tools to identify known vulnerable services in their ICT systems. This proactive approach ensures that potential weaknesses are swiftly addressed. bolstering their overall information security posture.
In their comprehensive approach to information security, Bytes has identified and assessed various risks. During this process, despite implementing the security controls, Bytes ' expert team identified unacceptable residual risks, and the team Currently faces uncertainty regarding which specific options to for addressing these identified and unacceptable residual risks.
According to Scenario 5, which type of policy did Bytes formulate?
A. High-level general policies
B. Topic-specific policies
C. High-level specific policies
問題 #3
Infralink is a medium-sized IT consultancy firm headquartered in Dublin, Ireland. It specializes in secure cloud infrastructure, software integration, and data analytics, serving a diverse client base in the healthcare, financial services, and legal sectors, including hospitals, insurance providers, and law firms. To safeguard sensitive client data and support business continuity, Infralink has implemented an information security management system (ISMS) aligned with the requirements of ISO/IEC 27001.
In developing its security architecture, the company adopted services to support centralized user identification and shared authentication mechanisms across its departments. These services also governed the creation and management of credentials within the company. Additionally, Infralink deployed solutions to protect sensitive data in transit and at rest, maintaining confidentiality and integrity across its systems.
In preparation for implementing information security controls, the company ensured the availability of necessary resources, personnel competence, and structured planning. It conducted a cost-benefit analysis, scheduled implementation phases, and prepared documentation and activity checklists for each phase. The intended outcomes were clearly defined to align security controls with business objectives.
Infralink started by implementing several controls from Annex A of ISO/IEC 27001. These included regulating physical and logical access to information and assets in accordance with business and information security requirements, managing the identity life cycle, and establishing procedures for providing, reviewing, modifying, and revoking access rights. However, controls related to the secure allocation and management of authentication information, as well as the establishment of rules or agreements for secure information transfer, have not yet been implemented. During the documentation process, the company ensured that all ISMS- related documents supported traceability by including titles, creation or update dates, author names, and unique reference numbers. Based on the scenario above, answer the following question.
Which security services did infralink implement as part of its security architecture?
A. Boundary control and audit monitoring services
B. Access control and cryptographic services
C. Integrity services
問題 #4
Scenario 10: NetworkFuse develops, manufactures, and sells network hardware. The company has had an operational information security management system (ISMS) based on ISO/IEC 27001 requirements and a quality management system (QMS) based on ISO 9001 for approximately two years. Recently, it has applied for a j^ombined certification audit in order to obtain certification against ISO/IEC 27001 and ISO 9001.
After selecting the certification body, NetworkFuse prepared the employees for the audit The company decided to not conduct a self-evaluation before the audit since, according to the top management, it was not necessary. In addition, it ensured the availability of documented information, including internal audit reports and management reviews, technologies in place, and the general operations of the ISMS and the QMS.
However, the company requested from the certification body that the documentation could not be carried off- site However, the audit was not performed within the scheduled days because NetworkFuse rejected the audit team leader assigned and requested their replacement The company asserted that the same audit team leader issued a recommendation for certification to its main competitor, which, for the company ' s top management, was a potential conflict of interest. The request was not accepted by the certification body NetworkFuse should_________________to ensure that employees are prepared for the audit. Refer to scenario 10.
A. Observe the technologies used
B. Select a certification body that provides combined audits
C. Conduct practice interviews
問題 #5
BioLooVitalis is a biopharmaceutical firm headquartered in Singapore Renowned for its pioneering work in the fie d of human therapeutics. BioLooVitalis places a strong emphasis on addressing critical healthcare concerns particularly in the domains of cardiovascular diseases, oncology bone health, and inflammation BioLooVitalis has demonstrated its commitment to data security and integrity by maintaining an effective information security management system (ISMS) based on ISO/IEC 77001 for the past two years. After noticing an increase m failed login attempts over several weeks. bioLooVitalis IT security learn reviewed log data, correlated it with user behavior patterns, and mapped it against known attach vectors to determine potential causes. Based on their findings, they prepared a technical report detailing the nature of the anomalies and submitted it to the compliance function. The compliance team then summarized the findings and presented them to the executive management during the quarterly ISMS performance review. To proactively track system behavior following the spike n failed login attempts. BioLooVitalis ' s IT security team configured a dashboard showing real time login activity. system response times, and end point availability across departments. This helped the team quickly detect abnormal behavior without waiting formal reporting cycles. Following The implementation of the real time access control dashboard BioLooVitalis internal audit team assessed whether the new processes and tools effectively reduced unauthorized access attempts and met both technical and policy-based requirements. Lastly, the internal auditors collected system-generated access logs, reviewed user access reports, and conducted interviews with IT personnel. These data sources helped them verify whether the new controls were functioning as intended and aligned with internal ISMS objectives.
Based on The scenario above, answer the following question.
According to scenario 8 what did the internal auditors collect during the evaluation of the new access control measures?
A. Audit conclusions
B. Audit evidence
C. Findings as nonconformities
解説:
| 問題 #1 正解: A | 問題 #2 正解: A | 問題 #3 正解: B | 問題 #4 正解: C | 問題 #5 正解: B |




Fujimatsu
山口**
Shiraishi
武田**
