
1D0-671 PDF問題集リアル2024最近更新された問題
リリースCIW 1D0-671更新された問題PDF
質問 # 40
Which type of attack exploits routed IP datagrams and is often found at the network layer?
- A. SYN flooding
- B. Route mangling
- C. IP spoofing
- D. Source routing
正解:D
質問 # 41
Irina has contracted with a company to provide Web design consulting services. The company has asked her to use several large files available via an HTTP server.
The IT department has provided Irina with user name and password, as well as the DNS name of the HTTP server. She then used this information to obtain the files she needs to complete her task using Mozilla Firefox.
Which of the following is a primary risk factor when authenticating with a standard HTTP server?
- A. Irina has used the wrong application for this protocol, thus increasing the likelihood of a man-in- the- middle attack.
- B. Irina has accessed the Web server using a non-standard Web browser.
- C. HTTP uses cleartext transmission during authentication, which can lead to a man-in-the- middle attack.
- D. A standard HTTP connection uses public-key encryption that is not sufficiently strong, inviting the possibility of a man-in-the-middle attack.
正解:C
質問 # 42
A disgruntled employee has discovered that the company Web server is not protected against particular buffer overflow vulnerability.
The disgruntled employee has created an application to take advantage of this vulnerability and secretly obtain sensitive data from the Web server's hard disk. This application sends a set of packets to the Web server that causes it to present an unauthenticated terminal with root privileges.
What is the name for this particular type of attack?
- A. Trojan
- B. Man-in-the-middle attack
- C. Zero-day attack
- D. Denial of service
正解:C
質問 # 43
Consider the following image:
From the information in this image, what type of attack is occurring?
- A. A man-in-the-middle attack
- B. A spoofing attackD.A spoofing attack
- C. A connection-hijacking attackC.A connection-hijacking attack
- D. A brute-force attack
正解:D
質問 # 44
A CGI application on the company's Web server has a bug written into it. This particular bug allows the application to write data into an area of memory that has not been properly allocated to the application. An attacker has created an application that takes advantage of this bug to obtain credit card information.
Which of the following security threats is the attacker exploiting, and what can be done to solve the problem?
- A. - Buffer overflow
- Work with the Web developer to solve the problem - B. - Man-in-the-middle attack
- Contact the company auditor - C. - Denial of service
- Contact the organization that wrote the code for the Web server - D. - SQL injection
- Work with a database administrator to solve the problem
正解:A
質問 # 45
Which of the following is most likely to address a problem with an operating system's ability to withstand an attack that attempts to exploit a buffer overflow?
- A. Firewall
- B. Software update
- C. Network scanner
- D. Intrusion detection system
正解:B
質問 # 46
Which of the following organizations provides regular updates concerning security breaches and issues?
- A. ICANN
- B. CERT
- C. ISO
- D. IETF
正解:B
質問 # 47
What is the primary advantage of using a circuit-level proxy?
- A. It allows applications to provide connection information to the SOCKS server.
- B. It allows masquerading.
- C. It can discriminate between good and malicious data.
- D. It provides Network Address Translation (NAT).
正解:D
質問 # 48
Which of the following can help you authoritatively trace a network flooding attack?
- A. Ping
- B. Router logs
- C. Your ISP
- D. Firewall logs
正解:C
質問 # 49
Which term describes a dedicated system meant only to house firewall software?
- A. Proxy server
- B. Kernel firewall
- C. Virtual Private Network (VPN)
- D. Firewall appliance
正解:D
質問 # 50
Which of the following can specify the route by which a packet of information has traveled?
- A. A packet trace
- B. A reverse scan
- C. A physical line trace
- D. A phone line trace
正解:A
質問 # 51
At the beginning of an IPsec session, which activity occurs during the Internet Key Exchange (IKE)?
- A. Negotiating the authentication method
- B. Negotiating the version of IP to be used
- C. Determining the network identification number
- D. Determining the number of security associations
正解:A
質問 # 52
Which of the following is a primary weakness of asymmetric-key encryption?
- A. It can lead to the corruption of encrypted data during network transfer.
- B. It is difficult to transfer any portion of an asymmetric key securely.
- C. It is reliant on the Secure Sockets Layer (SSL) standard, which has been compromised.
- D. It is slow because it requires extensive calculations by the computer.
正解:D
質問 # 53
Which of the following is considered to be the most secure default firewall policy, yet usually causes the most work from an administrative perspective?
- A. Configuring the firewall to coordinate with the intrusion-detection system
- B. Blocking all access by default, then allowing only necessary connections
- C. Allowing all access by default, then blocking only suspect network connections
- D. Configuring the firewall to respond automatically to threats
正解:B
質問 # 54
Which of the following describes the practice of stateful multi-layer inspection?
- A. Inspecting packets in all layers of the OSI/RM with a packet filter
- B. Using Quality of Service (QoS) on a proxy-oriented firewall
- C. Prioritizing voice and video data to reduce congestion
- D. Using a VLAN on a firewall to enable masquerading of private IP addresses
正解:A
質問 # 55
You have implemented a service on a Linux system that allows a user to read and edit resources.
What is the function of this service?
- A. Intrusion detection
- B. Access control
- C. Authentication
- D. Data integrity
正解:B
質問 # 56
Your organization has made a particularly unpopular policy decision. Your supervisor fears that a series of attacks may occur as a result. You have been assigned to increase automated auditing on a server.
When fulfilling this request, which of the following resources should you audit the most aggressively?
- A. Intrusion detection systems, especially those placed on sensitive networks
- B. Firewall settings for desktop systems
- C. Authentication databases, including directory servers
- D. Log files on firewall systems
正解:C
質問 # 57
You are creating an information security policy for your company.
Which of the following activities will help you focus on creating policies for the most important resources?
- A. Logging users
- B. Auditing the firewall
- C. Implementing non-repudiation
- D. Classifying systems
正解:D
質問 # 58
......
1D0-671問題集と練習テスト(126試験問題):https://www.passtest.jp/CIW/1D0-671-shiken.html
ガイド(2024年最新)実際のCIW 1D0-671試験問題:https://drive.google.com/open?id=1517bhdICeeUDDpXgRo5YTh4b9XbIJcOj