試験合格保証付きのCyber Technician (CCT) 212-82日本語試験問題集
ECCouncil 212-82日本語日常練習試験は2025年最新のに更新された168問あります
質問 # 79
多国籍企業のセキュリティ専門家である Lorenzo は、リモート アクセス サーバー用の集中認証、承認、アカウンティングを確立するように指示されました。この目的のために、彼はクライアント サーバー モデルに基づき、OSI モデルのトランスポート層で動作するプロトコルを実装しました。
上記のシナリオで Lorenzo が採用したリモート認証プロトコルを特定します。
- A. SNMPv3
- B. IMAPS
- C. POP3S
- D. RADIUS
正解:D
解説:
The correct answer is B, as it identifies the remote authentication protocol employed by Lorenzo in the above scenario. RADIUS (Remote Authentication Dial-In User Service) is a protocol that provides centralized authentication, authorization, and accounting (AAA) for remote-access servers such as VPNs (Virtual Private Networks), wireless networks, or dial-up connections. RADIUS is based on the client-server model and works at the transport layer of the OSI model. RADIUS uses UDP (User Datagram Protocol) as its transport protocol and encrypts only user passwords in its messages. In the above scenario, Lorenzo implemented RADIUS to provide centralized AAA for remote-access servers. Option A is incorrect, as it does not identify the remote authentication protocol employed by Lorenzo in the above scenario. SNMPv3 (Simple Network Management Protocol version 3) is a protocol that provides network management and monitoring for network devices such as routers, switches, servers, or printers. SNMPv3 is basedon the manager-agent model and works at the application layer of the OSI model. SNMPv3 uses UDP as its transport protocol and encrypts all its messages with AES (Advanced Encryption Standard) or DES (Data Encryption Standard). In the above scenario, Lorenzo did not implement SNMPv3 to provide network management and monitoring for network devices.
Option C is incorrect, as it does not identify the remote authentication protocol employed by Lorenzo in the above scenario. POP3S (Post Office Protocol version 3 Secure) is a protocol that provides secure email access and retrieval for email clients from email servers. POP3S is based on the client-server model and works at the application layer of the OSI model. POP3S uses TCP (Transmission Control Protocol) as its transport protocol and encrypts all its messages with SSL (Secure Sockets Layer) or TLS (Transport Layer Security). In the above scenario, Lorenzo did not implement POP3S to provide secure email access and retrieval for email clients from email servers. Option D is incorrect, as it does not identify the remote authentication protocol employed by Lorenzo in the above scenario. IMAPS (Internet Message Access Protocol Secure) is a protocol that provides secure email access and management for email clients from email servers. IMAPS is based on the client-server model and works at the application layer of the OSI model. IMAPS uses TCP as its transport protocol and encrypts all its messages with SSL or TLS. In the above scenario, Lorenzo did not implement IMAPS to provide secure email access and management for email clients from email servers.
References: , Section 8.2
質問 # 80
ヘンリーは、BlackEye - Cyber security solutions に雇われたサイバー セキュリティの専門家です。彼は、ホストのオペレーティング システム (OS) を検出する任務を負っていました。彼は、Unkornscan ツールを使用して、ターゲット システムの OS を検出しました。その結果、彼は、ターゲット システムで Windows OS が実行されていることを示す TTL 値を取得しました。ヘンリーが取得した、ターゲット OS が Windows であることを示す TTL 値を特定します。
- A. 0
- B. 1
- C. 2
- D. 3
正解:C
解説:
128 is the TTL value that Henry obtained, which indicates that the target OS is Windows. TTL (Time to Live) is a field in the IP (Internet Protocol) header that specifies how long a packet can remain in a network before it is discarded or dropped. TTL is usually expressed in seconds or hops (the number of routers or gateways that a packet passes through). TTL is used to prevent packets from looping endlessly in a network or consuming network resources . Different operating systems have different default TTL values for their packets. By observing the TTL value of a packet from a target system or network, one can infer the operating system of the target . Some common TTL values and their corresponding operating systems are:
64: Linux, Unix, Android
128: Windows
255: Cisco IOS
60: Mac OS
In the scenario, Henry used Nmap tool to discover the OS of the target system. Nmap (Network Mapper) is a tool that can perform various network scanning and enumeration tasks, such as port scanning, OS detection, service identification, etc . Nmap can use various techniques to detect the OS of a target system, such as TCP/IP fingerprinting, which involves analyzing various TCP/IP characteristics of packets from the target system, such as TTL value. In the scenario, Henry obtained a TTL value of 128 , which indicates that the target OS is Windows.
質問 # 81
組織のセキュリティ スペシャリストである Wilson は、クラウド ネットワークのセキュリティを強化するよう指示を受けました。これを実現するために、Wilson は、オンプレミスの消費者ネットワークと VPC 間の通信を集中ユニット経由で確立および管理するネットワーク ルーティング ソリューションを導入しました。このシナリオでクラウド ネットワークのセキュリティを実現するために Wilson が使用した方法を特定します。
- A. トランジットゲートウェイ
- B. パブリックサブネットとプライベートサブネット
- C. VPCエンドポイント
- D. 仮想プライベートクラウド (VPC)
正解:A
解説:
Transit gateways are the method used by Wilson to achieve cloud network security in this scenario. Cloud network security is a branch of cybersecurity that focuses on protecting and securing the network infrastructure and traffic in a cloud environment. Cloud network security can involve various methods or techniques, such as encryption, firewall, VPN, IDS/IPS, etc. Transit gateways are a method of cloud network security that provide a network routing solution that establishes and manages communication between on-premises consumer networks and VPCs (Virtual Private Clouds) via a centralized unit . Transit gateways can be used to simplify and secure the connectivity between different networks or VPCs in a cloud environment . In the scenario, Wilson was instructed to enhance its cloud network security. To achieve this, Wilson deployed a network routing solution that established and managed communication between the on-premises consumer network and VPCs via a centralized unit. This means that he used transit gateways for this purpose. A virtual private cloud (VPC) is not a method of cloud network security, but a term that describes an isolated and private section of a public cloud that provides exclusive access to cloud resources to a single organization or entity . A VPC can be used to create and configure virtual networks in a cloud environment . Public and private subnets are not methods of cloud network security, but terms that describe segments of a VPC that have different levels of accessibility or visibility . A public subnet is a segment of a VPC that can be accessed from the internet or other networks . A private subnet is a segment of a VPC that cannot be accessed from the internet or other networks . A VPC endpoint is not a method of cloud network security, but a term that describes an interface that allows private connectivity between a VPC and other AWS (Amazon Web Services) services or resources .
質問 # 82
アシュトンは、SoftEight Tech でセキュリティ スペシャリストとして働いています。彼は、経営陣からインターネット アクセス ポリシーを強化するよう指示されました。この目的のために、システムやネットワークの使用にかかわらず、すべてを禁止し、会社のすべてのコンピューターに厳しい制限を課すタイプのインターネット アクセス ポリシーを実装しました。
上記のシナリオで Ashton によって実装されたインターネット アクセス ポリシーの種類を特定します。
- A. 偏執的な政策
- B. 許容ポリシー
- C. 乱交ポリシー
- D. 慎重な方針
正解:A
解説:
It identifies the type of Internet access policy implemented by Ashton in the above scenario. An Internet access policy is a set of rules and guidelines that defines how an organization's employees or members can use the Internet and what types of websites or services they can access. There are different types of Internet access policies, such as:
Paranoid policy: This type of policy forbids everything and imposes strict restrictions on all company computers, whether it is system or network usage. This policy is suitable for organizations that deal with highly sensitive or classified information and have a high level of security and compliance requirements.
Prudent policy: This type of policy allows some things and blocks others and imposes moderate restrictions on company computers, depending on the role and responsibility of the user. This policy is suitable for organizations that deal with confidential or proprietary information and have a medium level of security and compliance requirements.
Permissive policy: This type of policy allows most things and blocks few and imposes minimal restrictions on company computers, as long as the user does not violate any laws or regulations.
This policy is suitable for organizations that deal with public or general information and have a low level of security and compliance requirements.
Promiscuous policy: This type of policy allows everything and blocks nothing and imposes no restrictions on company computers, regardless of the user's role or responsibility. This policy is suitable for organizations that have no security or compliance requirements and trust their employees or members to use the Internet responsibly.
In the above scenario, Ashton implemented a paranoid policy that forbids everything and imposes strict restrictions on all company computers, whether it is system or network usage.
質問 # 83
アシュトンは、SoftEight Tech でセキュリティ スペシャリストとして働いています。彼は、経営陣からインターネット アクセス ポリシーを強化するよう指示されました。この目的のために、システムやネットワークの使用にかかわらず、すべてを禁止し、会社のすべてのコンピューターに厳しい制限を課すタイプのインターネット アクセス ポリシーを実装しました。
上記のシナリオで Ashton によって実装されたインターネット アクセス ポリシーの種類を特定します。
- A. 偏執的な政策
- B. 許容ポリシー
- C. 乱交ポリシー
- D. 慎重な方針
正解:A
解説:
The correct answer is A, as it identifies the type of Internet access policy implemented by Ashton in the above scenario. An Internet access policy is a set of rules and guidelines that defines how an organization's employees or members can use the Internet and what types of websites or services they can access. There are different types of Internet access policies, such as:
Paranoid policy: This type of policy forbids everything and imposes strict restrictions on all company computers, whether it is system or network usage. This policy is suitable for organizations that deal with highly sensitive or classified information and have a high level of security and compliance requirements.
Prudent policy: This type of policy allows some things and blocks others and imposes moderate restrictions on company computers, depending on the role and responsibility of the user. This policy is suitable for organizations that deal with confidential or proprietary information and have a medium level of security and compliance requirements.
Permissive policy: This type of policy allows most things and blocks few and imposes minimal restrictions on company computers, as long as the user does not violate any laws or regulations. This policy is suitable for organizations that deal with public or general information and have a low level of security and compliance requirements.
Promiscuous policy: This type of policy allows everything and blocks nothing and imposes no restrictions on company computers, regardless of the user's role or responsibility. This policy is suitable for organizations that have no security or compliance requirements and trust their employees or members to use the Internet responsibly.
In the above scenario, Ashton implemented a paranoid policy that forbids everything and imposes strict restrictions on all company computers, whether it is system or network usage. Option B is incorrect, as it does not identify the type of Internet access policy implemented by Ashton in the above scenario. A prudent policy allows some things and blocks others and imposes moderate restrictions on company computers, depending on the role and responsibility of the user. In the above scenario, Ashton did not implement a prudent policy, but a paranoid policy. Option C is incorrect, as it does not identify the type of Internet access policy implemented by Ashton in the above scenario. A permissive policy allows most things and blocks few and imposes minimal restrictions on company computers, as long as the user does not violate any laws or regulations. In the above scenario, Ashton did not implement a permissive policy, but a paranoid policy. Option D is incorrect, as it does not identify the type of Internet access policy implemented by Ashton in the above scenario. A promiscuous policy allows everything and blocks nothing and imposes no restrictions on company computers, regardless of the user's role or responsibility. In the above scenario, Ashton did not implement a promiscuous policy, but a paranoid policy.
質問 # 84
大手ヘルスケア プロバイダーの NovusCorp は、あらゆる潜在的なリスクを確実にカバーできるよう、BC および DR 計画を綿密に設計していました。最近、プライマリ データ センターで壊滅的な洪水が発生しました。同社は迅速に DR 計画を発動し、セカンダリ データ センターに業務を移行しました。しかし、24 時間以内に、プロバイダーは予期せぬ課題に直面しました。セカンダリ データ センターが、これまでにないほど大量のデータ要求を受信し始め、システムの過負荷と中断を引き起こしたのです。この状況は、プロバイダーの初期リスク評価には含まれていませんでした。この苦境に直面して、NovusCorp は、事業継続性を確保するために、直ちにどのような行動を取るべきでしょうか。
- A. システムの安定性を維持するために、重要でないデータ要求を減らし、データ アクセスに一時的な制限を課します。
- B. 増加したデータ要求負荷を処理するために、セカンダリ データ センターのインフラストラクチャをアップグレードするためのリソースを割り当てます。
- C. 潜在的なリスクにもかかわらず、プライマリ データ センターへのテールバックを即時に開始します。
- D. プライマリ センターが復旧するまで、一時的なオーバーフローのためにクラウド ベースのデータ ストレージ プロバイダーを利用します。
正解:D
解説:
* Engaging a cloud-based data storage provider allows NovusCorp to manage the sudden influx of data requests without overloading the secondary data center. Cloud providers can quickly scale resources to meet demand.
質問 # 85
サイバーセキュリティ技術者として、最近攻撃を受けたデバイスからキャプチャされた Linux イメージのファイル システムを分析する任務を負っています。「Attacker Machine-1」のドキュメント フォルダーにあるフォレンジック イメージ「Evidenced.img」を調べ、イメージ ファイルからユーザーを特定します。(実践的な質問)
- A. ジョン
- B. 攻撃者
- C. 了解
- D. スミス
正解:B
解説:
The attacker is a user from the image file in the above scenario. A file system is a method or structure that organizes and stores files and data on a storage device, such as a hard disk, a flash drive, etc. A file system can have different types based on its format or features, such as FAT, NTFS, ext4, etc. A file system can be analyzed to extract various information, such as file names, sizes, dates, contents, etc. A Linux image is an image file that contains a copy or a snapshot of a Linux-based file system.A Linux image can be analyzed to extract various information about a Linux-based system or device.To analyze the file system of a Linux image captured from a device that has been attacked recently and identify a user from the image file, one has to follow these steps:
Navigate to Documents folder of Attacker Machine-1.
Right-click on Evidenced.img file and select Mount option. Wait for the image file to be mounted and assigned a drive letter.
Open File Explorer and navigate to the mounted drive.
Open etc folder and open passwd file with a text editor.
Observe the user accounts listed in the file.
The user accounts listed in the file are:
root:x:0:0:root:/root:/bin/bash daemon:x:1:1:daemon:/usr/sbin:/usr/sbin/nologin bin:x:2:2:bin:/bin:/usr/sbin/nologin sys:x:3:3:sys:/dev:/usr/sbin/nologin sync:x:4:65534:sync:/bin:/bin/sync games:x:5:60:games:/usr/games:/usr/sbin/nologin man:x:6:12:man:/var/cache/man:/usr/sbin/nologin lp:x:7:7:lp:/var/spool/lpd:/usr/sbin/nologin mail:x:8:8:mail:/var/mail:/usr/sbin/nologin news:x:9:9:news:/var/spool/news:/usr/sbin/nologin uucp:x:10:10:uucp:/var/spool/uucp:/usr/sbin/nologin proxy:x:13:13:proxy:/bin:/usr/sbin/nologin www-data:x:33:33:www-data:/var/www:/usr/sbin/nologin backup:x:34:34:backup:/var/backups:/usr/sbin/nologin list:x:38:38:Mailing List Manager:/var/list:/usr/sbin/nologin irc:x:39:39:ircd:/var/run/ircd:/usr/sbin/nologin gnats:x:41:41:Gnats Bug-Reporting System (admin):/var/lib/gnats:/usr/sbin/nologin nobody:x:65534:65534:nobody:/nonexistent:/usr/sbin/nologin systemd-timesync:x:100: systemd- network:x: systemd-resolve:x: systemd-bus-proxy:x: syslog:x: _apt:x: messagebus:x: uuidd:x:
lightdm:x: whoopsie:x: avahi-autoipd:x: avahi:x: dnsmasq:x: colord:x: speech-dispatcher:x:
hplip:x:
kernoops:x: saned:x: nm-openvpn:x: nm-openconnect:x: pulse:x: rtkit:x: sshd:x: attacker::1000 The user account that is not a system or service account is attacker, which is a user from the image file.
質問 # 86
pfSense ファイアウォールは、Web アプリケーション www.abchacker.com をブロックするように設定されています。管理者が設定したルールを分析し、ルールを適用するために使用されたプロトコルを選択します。
ヒント: ファイアウォールのログイン資格情報は以下の通りです。
ユーザー名: admin
パスワード: admin@l23
- A. FTP
- B. TCP/UDP
- C. POP3
- D. ARP
正解:B
解説:
TCP/UDP is the protocol that has been used to apply the rule to block the web application www.abchacker.com in the above scenario. pfSense is a firewall and router software that can be installed on a computer or a device to protect a network from various threats and attacks. pfSense can be configured to block or allow traffic based on various criteria, such as source, destination, port, protocol, etc. pfSense rules are applied to traffic in the order they appear in the firewall configuration . To perform an analysis on the rules set by the admin, one has to follow these steps:
Open a web browser and type 20.20.10.26
Press Enter key to access the pfSense web interface.
Enter admin as username and admin@l23 as password.
Click on Login button.
Click on Firewall menu and select Rules option.
Click on LAN tab and observe the rules applied to LAN interface.
The rules applied to LAN interface are:
The first rule blocks any traffic from LAN interface to www.abchacker.com website using TCP/UDP protocol. The second rule allows any traffic from LAN interface to any destination using any protocol. Since the first rule appears before the second rule, it has higher priority and will be applied first. Therefore, TCP/UDP is the protocol that has been used to apply the rule to block the web application www.abchacker.com. POP3 (Post Office Protocol 3) is a protocol that allows downloading emails from a mail server to a client device. FTP (File Transfer Protocol) is a protocol that allows transferring files between a client and a server over a network. ARP (Address Resolution Protocol) is a protocol that resolves IP addresses to MAC (Media Access Control) addresses on a network.
質問 # 87
組織のセキュリティ チーム メンバーである Jase は、危険な状況下で業務が中断されないよう保証する任務を負っていました。そこで Jase は、脅威の発生を最小限に抑え、重要なビジネス領域を保護し、脅威の影響を軽減するための抑止制御戦略を実施しました。このシナリオで Jase が実行したビジネス継続性と災害復旧活動は次のどれですか。
- A. 応答
- B. 修復
- C. 回復
- D. 予防
正解:D
解説:
Prevention is the business continuity and disaster recovery activity performed by Jase in this scenario. Prevention is an activity that involves implementing a deterrent control strategy to minimize the occurrence of threats, protect critical business areas, and mitigate the impact of threats. Prevention can include measures such as backup systems, firewalls, antivirus software, or physical security1. Reference: Prevention Activity in BCDR
質問 # 88
インシデント対応者の Cairo は、組織のネットワークで発生したインシデントに対応していました。すべての IH&R 手順を実行した後、Cairo はインシデント後の活動を開始しました。彼は、影響を受けたすべてのデバイス、ネットワーク、アプリケーション、およびソフトウェアを特定して評価することにより、インシデントによって発生したすべての種類の損失を判定しました。このシナリオで Cairo が実行したインシデント後の活動を特定します。
- A. 調査を終了する
- B. ポリシーの確認と改訂
- C. インシデントの影響評価
- D. インシデントの開示
正解:C
解説:
Incident impact assessment is the post-incident activity performed by Cairo in this scenario. Incident impact assessment is a post-incident activity that involves determining all types of losses caused by the incident by identifying and evaluating all affected devices, networks, applications, and software. Incident impact assessment can include measuring financial losses, reputational damages, operational disruptions, legal liabilities, or regulatory penalties1. Reference: Incident Impact Assessment
質問 # 89
大手 IT コンサルタント会社である TechSolutions は、市の公共図書館のワイヤレス ネットワーク インフラストラクチャの全面改修を請け負っています。毎日何千人ものユーザーがネットワークにアクセスするため、潜在的な脅威を阻止できる強力な暗号化が不可欠です。また、TechSolutions は、図書館利用者が使用するさまざまなデバイスを考慮し、下位互換性を確保する必要があります。このシナリオに最適な暗号化メカニズムはどれでしょうか。
- A. TKIP (一時鍵整合性プロトコル)
- B. WPA3 (Wi-Fi 保護アクセス 3)
- C. WEP (有線同等プライバシー)
- D. AES-CCMP (カウンターモード暗号ブロック連鎖メッセージ認証コードプロトコルを備えた高度暗号化標準)
正解:B
解説:
For TechSolutions to overhaul the wireless network infrastructure for the city's public libraries, WPA3 is the best choice due to the following reasons:
* Security: WPA3 provides enhanced security over previous protocols like WPA2, offering stronger encryption mechanisms and protection against brute-force attacks.
* Backward Compatibility: WPA3 ensures compatibility with devices supporting WPA2, making it suitable for diverse devices used by library-goers.
* Features:
* Simultaneous Authentication of Equals (SAE): Enhances security during the handshake process.
* Forward Secrecy: Protects past communications even if the current encryption key is compromised.
* Improved Encryption: Uses AES-256 in Galois/Counter Mode (AES-GCM) for secure encryption.
References:
* Wi-Fi Alliance WPA3 Overview: Wi-Fi Alliance
* Analysis of WPA3 features: ACM Digital Library
質問 # 90
組織のネットワーク管理者である Jordan は、ネットワーク関連の問題を特定し、ネットワーク パフォーマンスを改善するように指示されました。ネットワークのトラブルシューティング中に、ターゲット ホストで IP 関連サービス (FTP や Web サービスなど) が利用できないためにデータグラムを転送できないことを示すメッセージを受け取りました。このシナリオで Jordan が見つけたネットワークの問題は次のどれですか。
- A. 時間超過メッセージ
- B. 宛先に到達できないメッセージ
- C. 到達不可能なネットワーク
- D. ネットワークケーブルが接続されていません
正解:B
解説:
Destination unreachable message is the network issue that Jordan found in this scenario. Destination unreachable message is a type of ICMP message that indicates that the datagram could not be forwarded owing to the unavailability of IP-related services (such as FTP or web services) on the target host. Destination unreachable message can be caused by various reasons, such as incorrect routing, firewall blocking, or host configuration problems1.
References: Destination Unreachable Message
質問 # 91
あなたは、航空宇宙および防衛分野における先進的な技術ソリューションで有名な多国籍テクノロジー複合企業 GlobalTech の主任サイバーセキュリティ スペシャリストです。この組織の評判は、同社が開拓する革新的なテクノロジーによって築かれており、その多くは国家の最高機密です。
日曜の深夜、画期的なミサイル防衛システムの設計図とプロジェクトの詳細が保存されているサーバーで不審な活動が行われているという警告を受け取りました。兆候は、従来のセキュリティ対策を回避した複雑で多段階のサイバー攻撃を示唆しています。予備調査により、サイバー犯罪者が内部者の認証情報を使用した可能性があり、侵入がさらに複雑になっていることが判明しました。関係するデータの機密性が非常に高いため、漏洩は国家安全保障に深刻な影響を及ぼし、会社の評判を回復不能なほど傷つける可能性があります。このセキュリティ インシデントの潜在的な重大性と複雑さを考慮して、この状況を効果的に処理し、重要なデータを保護し、潜在的な影響を最小限に抑えるために、どのような即時の措置を講じるべきでしょうか。
- A. 外部の専門サイバーセキュリティ会社と連携して並行調査を実施し、その専門知識を活用して犯人を特定し、侵害の手口を理解します。
- B. 国家安全保障の潜在的な侵害について連邦政府機関に通知します。連邦政府機関と連携して、さらなるデータ流出を防ぎ、国家の利益を保護するために必要なすべての措置が講じられるようにします。
- C. インシデント対応プロトコルを開始し、影響を受けたサーバーを隔離して即時封じ込めることに重点を置きます。同時に、ネットワーク ログと影響を受けたシステムを調べて、侵害の範囲と深刻度を評価します。
- D. 最高経営責任者と法務チームに違反について報告します。株主と顧客に事件と講じられている対策について常に最新情報が伝わるように、公開声明を準備します。
正解:C
質問 # 92
プロのハッカーであるリチャードは、位置情報からユーザーのオフライン活動に関する機密データと情報を収集するために、マーケティング担当者に雇われました。リチャードは、CPS 機能を使用して、ユーザーのモバイル デバイスが正確な位置に近いかどうかを判断する手法を採用しました。この手法を使用して、リチャードは、静的な場所に仮想バリアを配置し、バリアを越えるモバイル ユーザーと対話しました。このシナリオでリチャードが使用した手法を特定してください。
- A. セオフェンシング
- B. 無線(OTA)アップデート
- C. コンテナ化
- D. 完全なデバイス暗号化
正解:A
解説:
Geofencing is a technique that uses GPS features to determine the proximity of a user's mobile device to an exact location. Geofencing can be used to create a virtual barrier positioned at a static location to interact with mobile users crossing the barrier. Geofencing can be used for marketing, security, and tracking purposes2.
References: What is Geofencing?
質問 # 93
ライリーはルイに秘密のメッセージを送信しました。メッセージを送信する前に、ライリーは自分の秘密鍵を使用してメッセージにデジタル署名しました。ルイはメッセージを受信し、対応する鍵を使用してデジタル署名を検証し、メッセージが送信中に改ざんされていないことを確認しました。
上記のシナリオでルイがデジタル署名を検証するために使用したキーは次のどれですか?
- A. ライリーの公開鍵
- B. ルイの秘密鍵
- C. ルイの公開鍵
- D. ライリーの秘密鍵
正解:A
解説:
Riley's public key is the key that Louis used to verify the digital signature in the above scenario. A digital signature is a cryptographic technique that verifies the authenticity and integrity of a message or document. A digital signature is created by applying a hash function to the message or document and then encrypting the hash value with the sender's private key. A digital signature can be verified by decrypting the hash value with the sender's public key and comparing it with the hash value of the original message or document.Riley's public key is the key that corresponds to Riley's private key, which he used to sign the message. Louis's public key is the key that corresponds to Louis's private key, which he may use to encrypt or decrypt messages with Riley.
Louis's private key is the key that only Louis knows and can use to sign or decrypt messages.
Riley's private key is the key that only Riley knows and can use to sign or encrypt messages.
質問 # 94
組織のセキュリティ専門家である Finley は、SIEM ダッシュボードを通じて組織のネットワーク動作を監視する任務を負っていました。監視中に、Finley はネットワーク内で疑わしいアクティビティに気付きました。そこで、1 つのネットワーク パケットをキャプチャして分析し、シグネチャに悪意のあるパターンが含まれているかどうかを判断しました。このシナリオで Finley が使用した攻撃シグネチャ分析手法を特定します。
- A. アトミック署名ベースの分析
- B. 複合シグネチャベースの分析
- C. コンテンツベースの署名分析
- D. コンテキストベースのシグネチャ分析
正解:C
解説:
Content-based signature analysis is the attack signature analysis technique employed by Finley in this scenario. Content-based signature analysis is a technique that captures and analyzes a single network packet to determine whether the signature included malicious patterns. Content- based signature analysis can be used to detect known attacks, such as buffer overflows, SQL injections, or cross-site scripting.
質問 # 95
集中ログ管理のために、最近買収した子会社の Linux マシンと会社の Windows 環境の統合を担当するシステム管理者として、最も大きな課題は何でしょうか?
- A. 両方のシステムによって生成される膨大な量のログを処理します。
- B. Windows と Linux の両方のログ管理ツールに精通した熟練した人材を見つける。
- C. 組み込みログ ビューアーのさまざまなユーザー インターフェイス (イベント ビューアーと Syslog) をナビゲートします。
- D. Windows システムと Linux システムで使用されるログ形式の非互換性を管理します。
正解:D
解説:
Integrating Linux machines with a Windows environment for centralized log management poses significant challenges, primarily due to the incompatibility of log formats:
* Log Format Differences:
* Windows: Uses Event Viewer to store logs in a proprietary format.
* Linux: Uses Syslog to store logs in plain text files with a different structure.
* Centralized Management: To achieve effective centralized log management, logs from both systems need to be normalized into a common format.
* Solutions:
* Log Aggregators: Tools like Logstash or Fluentd can collect, parse, and transform logs from different systems into a unified format.
* SIEM Systems: Security Information and Event Management (SIEM) systems like Splunk or ELK Stack can handle log ingestion from multiple sources, normalizing data for analysis.
References:
* SIEM Implementation Guides: Splunk Documentation
* Log Management Best Practices: Syslog-ng Documentation
質問 # 96
犯罪捜査官のルーベンは、元のファイルに影響を与えずに、疑わしいメディア内の削除されたファイルとフォルダーをすべて取得したいと考えています。この目的のために、彼はメディア全体のクローン コピーを作成し、元のメディアの汚染を防ぐ方法を使用します。
上記のシナリオで Ruben が使用した方法を特定します。
- A. スパース獲得
- B. 論理的獲得
- C. ドライブの復号化
- D. ビットストリームイメージング
正解:D
解説:
Bit-stream imaging is the method utilized by Ruben in the above scenario. Bit-stream imaging is a method that involves creating a cloned copy of the entire media and prevents the contamination of the original media. Bit-stream imaging copies all the data on the media, including deleted files and folders, hidden partitions, slack space, etc., at a bit level. Bit-stream imaging preserves the integrity and authenticity of the digital evidence and allows further analysis without affecting the original media. Sparse acquisition is a method that involves creating a partial copy of the media by skipping empty sectors or blocks. Drive decryption is a method that involves decrypting an encrypted drive or partition using a password or a key. Logical acquisition is a method that involves creating a copy of the logical files and folders on the media using file system commands.
質問 # 97
ザイオンは、施設の周囲に設置された物理的なセキュリティ機器の実装と管理を担当する従業員のカテゴリに属しています。彼は、経営陣から、物理的なセキュリティに関連する機器の機能を確認するように指示されました。ザイオンの指定を特定します。
- A. ガード
- B. 安全担当者
- C. 監督者
- D. 最高情報セキュリティ責任者
正解:A
解説:
The correct answer is C, as it identifies the designation of Zion. A guard is a person who is responsible for implementing and managing the physical security equipment installed around the facility. A guard typically performs tasks such as:
Checking the functionality of equipment related to physical security
Monitoring the surveillance cameras and alarms
Controlling the access to restricted areas
Responding to emergencies or incidents
In the above scenario, Zion belongs to this category of employees who are responsible for implementing and managing the physical security equipment installed around the facility. Option A is incorrect, as it does not identify the designation of Zion. A supervisor is a person who is responsible for overseeing and directing the work of other employees. A supervisor typically performs tasks such as:
Assigning tasks and responsibilities to employees
Evaluating the performance and productivity of employees
Providing feedback and guidance to employees
Resolving conflicts or issues among employees
In the above scenario, Zion does not belong to this category of employees who are responsible for overseeing and directing the work of other employees. Option B is incorrect, as it does not identify the designation of Zion. A chief information security officer (CISO) is a person who is responsible for establishing and maintaining the security vision, strategy, and program for an organization. A CISO typically performs tasks such as:
Developing and implementing security policies and standards
Managing security risks and compliance
Leading security teams and projects
Communicating with senior management and stakeholders
In the above scenario, Zion does not belong to this category of employees who are responsible for establishing and maintaining the security vision, strategy, and program for an organization. Option D is incorrect, as it does not identify the designation of Zion. A safety officer is a person who is responsible for ensuring that health and safety regulations are followed in an organization. A safety officer typically performs tasks such as:
Conducting safety inspections and audits
Identifying and eliminating hazards and risks
Providing safety training and awareness
Reporting and investigating accidents or incidents
In the above scenario, Zion does not belong to this category of employees who are responsible for ensuring that health and safety regulations are followed in an organization. Reference: Section 7.1
質問 # 98
認定セキュリティ専門家のアレックスは、攻撃側チームと防御側チームの両方で働いています。彼のチームの主な責任は、保護を強化し、組織のセキュリティ基準を高めることです。このシナリオでアレックスのチームを特定します。
- A. レッドチーム
- B. 白チーム
- C. 紫色の学習
- D. 青チーム
正解:C
解説:
Purple team is the team that Alex works for in this scenario. A team is a group of people that work together to achieve a common goal or objective. A team can have different types based on its role or function in an organization or a project. A purple team is a type of team that works for both aggressor and defender teams. A purple team can be used to enhance protection and boost the security standards of an organization by performing various tasks, such as testing, evaluating, improving, or integrating the security measures implemented by the defender team or exploited by the aggressor team. In the scenario, Alex is a certified security professional who works for both aggressor and defender teams. His team's main responsibility involves enhancing protection and boosting the security standards of the organization. This means that he works for a purple team. A white team is a type of team that acts as an observer or an arbitrator between the aggressor and defender teams. A white team can be used to monitor, evaluate, or adjudicate the performance or outcome of the aggressor and defender teams by providing feedback, guidance, or rules. A blue team is a type of team that acts as a defender or a protector of an organization's network or system. A blue team can be used to prevent, detect, or respond to attacks from external or internal threats by implementing various security measures, such as firewalls, antivirus, encryption, etc. A red team is a type of team that acts as an attacker or an adversary of an organization's network or system. A red team can be used to simulate realistic attacks from external or internal threats by exploiting various vulnerabilities, weaknesses, or gaps in the organization's security posture.
質問 # 99
プロのハッカーであるリチャードは、位置情報からユーザーのオフライン活動に関する機密データと情報を収集するために、マーケティング担当者に雇われました。リチャードは、CPS 機能を使用して、ユーザーのモバイル デバイスが正確な位置に近いかどうかを判断する手法を採用しました。この手法を使用して、リチャードは、静的な場所に仮想バリアを配置し、バリアを越えるモバイル ユーザーと対話しました。このシナリオでリチャードが使用した手法を特定してください。
- A. セオフェンシング
- B. 無線(OTA)アップデート
- C. コンテナ化
- D. 完全なデバイス暗号化
正解:A
解説:
Geofencing is a technique that uses GPS features to determine the proximity of a user's mobile device to an exact location. Geofencing can be used to create a virtual barrier positioned at a static location to interact with mobile users crossing the barrier. Geofencing can be used for marketing, security, and tracking purposes.
質問 # 100
ある組織のインシデント処理および対応 (IH&R) チームは、組織の Web サーバーに対する最近のサイバー攻撃に対処していました。IH&P チームのメンバーである Fernando は、インシデントの根本原因を排除し、すべての攻撃ベクトルを遮断して、将来同様のインシデントが発生しないようにする任務を負っていました。この目的のために、Fernando は Web サーバーに最新のパッチを適用し、最新のセキュリティ メカニズムをインストールしました。このシナリオで Fernando が実行した IH&R ステップを特定します。
- A. 根絶
- B. 通知
- C. 封じ込め
- D. 回復
正解:A
解説:
Eradication is the IH&R step performed by Fernando in this scenario. Eradication is a step in IH&R that involves eliminating the root cause of the incident and closing all attack vectors to prevent similar incidents in future. Eradication can include applying patches, installing security mechanisms, removing malware, restoring backups, or reformatting systems.
質問 # 101
ネットワーク内で5SHサービスが有効になっているマシンを特定します。そのマシンへのSSH接続を開始し、マシン内のファイルttag.txtを探し、その内容を回答として入力します。SSHログインの認証情報はsam/admin@123です。
- A. sam2@bob
- B. sam@bob
- C. bob2@sam
- D. bobt@sam
正解:D
解説:
bob1@sam is the file's content as the answer. To find the machine with SSH service enabled, one can use a network scanning tool such as Nmap to scan the network for port 22, which is the default port for SSH. For example, the command nmap -p 22 192.168.0.0/24 will scan the network range 192.168.0.0/24 for port 22 and display the results. To initiate an SSH connection to the machine, one can use a command-line tool such as ssh or an SSH client such as PuTTY to connect to the machine using the credentials sam/admin@123. For example, the command ssh [email protected] will connect to the machine with IP address 192.168.0.10 using the username sam and prompt for the password admin@123. To find the file flag.txt in the machine, one can use a file searching tool such as find or locate to search for the file name in the machine's file system. For example, the command find / -name flag.txt will search for the file flag.txt from the root directory (/) and display its location. To enter the file's content as the answer, one can use a file viewing tool such as cat or less to display the content of the file flag.txt. For example, the command cat /home/sam/flag.txt will display the content of the file flag.txt located in
/home/sam/ directory.
質問 # 102
インシデント対応者の Cairo は、組織のネットワークで発生したインシデントに対応していました。すべての IH&R 手順を実行した後、Cairo はインシデント後の活動を開始しました。彼は、影響を受けたすべてのデバイス、ネットワーク、アプリケーション、およびソフトウェアを特定して評価することにより、インシデントによって発生したすべての種類の損失を判定しました。このシナリオで Cairo が実行したインシデント後の活動を特定します。
- A. 調査を終了する
- B. ポリシーの確認と改訂
- C. インシデントの影響評価
- D. インシデントの開示
正解:C
解説:
Incident impact assessment is the post-incident activity performed by Cairo in this scenario. Incident impact assessment is a post-incident activity that involves determining all types of losses caused by the incident by identifying and evaluating all affected devices, networks, applications, and software. Incident impact assessment can include measuring financial losses, reputational damages, operational disruptions, legal liabilities, or regulatory penalties1. References: Incident Impact Assessment
質問 # 103
......
テストエンジン練習212-82日本語テスト問題:https://www.passtest.jp/ECCouncil/212-82-JPN-shiken.html