2024年最新の実際のSY0-701日本語問題集PDFで100%合格率を保証します [Q132-Q157]

Share

2024年最新の実際のPassTest SY0-701日本語問題集PDFで100%合格率を保証します

無料CompTIA SY0-701日本語試験問題と解答

質問 # 132
従業員が退職したときに権限を迅速に更新することで組織のセキュリティ体制を最も強化できる自動化ユースケースは次のどれですか?

  • A. 権限要求のエスカレーション
  • B. 変更承認の確認
  • C. アクセスを無効にする
  • D. リソースのプロビジョニング

正解:C

解説:
Disabling access is an automation use case that would best enhance the security posture of an organization by rapidly updating permissions when employees leave a company. Disabling access is the process of revoking or suspending the access rights of a user account, such as login credentials, email, VPN, cloud services, etc. Disabling access can prevent unauthorized or malicious use of the account by former employees or attackers who may have compromised the account. Disabling access can also reduce the attack surface and the risk of data breaches or leaks. Disabling access can be automated by using scripts, tools, or workflows that can trigger the action based on predefined events, such as employee termination, resignation, or transfer.
Automation can ensure that the access is disabled in a timely, consistent, and efficient manner, without relying on manual intervention or human error.


質問 # 133
企業は、ネットワークを構築するときに認定ハードウェアを使用する必要があります。偽造ハードウェアの調達に伴うリスクに最もよく対処しているのは、次のどれですか。

  • A. サプライチェーンの徹底的な分析
  • B. ベンダー契約およびSOWにおける監査権条項
  • C. すべてのサプライヤーとベンダーに対する徹底的な侵入テスト
  • D. 法的に強制力のある企業買収ポリシー

正解:A

解説:
Counterfeit hardware is hardware that is built or modified without the authorization of the original equipment manufacturer (OEM). It can pose serious risks to network quality, performance, safety, and reliability. Counterfeit hardware can also contain malicious components that can compromise the security of the network and the data that flows through it. To address the risks associated with procuring counterfeit hardware, a company should conduct a thorough analysis of the supply chain, which is the network of entities involved in the production, distribution, and delivery of the hardware. By analyzing the supply chain, the company can verify the origin, authenticity, and integrity of the hardware, and identify any potential sources of counterfeit or tampered products.


質問 # 134
次のどれが VoIP 関連の一般的な脆弱性ですか? (2 つ選択してください)。

  • A. DHCPスヌーピング
  • B. VLANホッピング
  • C. 追い越し
  • D. ヴィッシング
  • E. フィッシング
  • F. スピム

正解:D、F

解説:
SPIM (Spam over Internet Messaging) poses a threat to VoIP systems by consuming bandwidth, diverting resources, and potentially causing denial of service attacks. The influx of SPIM messages can degrade the quality of VoIP calls, overload servers, and serve as a platform for social engineering attacks, jeopardizing the security of VoIP users. To mitigate these risks, organizations should implement spam filters, intrusion detection systems, and regular software updates while also educating users to recognize and avoid potential threats associated with SPIM.


質問 # 135
ある銀行が顧客の個人情報を格納する新しいサーバーを設置しました。機密データが変更されないようにするために、銀行は次のどれを使用する必要がありますか?

  • A. ネットワークアクセス制御
  • B. ユーザー行動分析
  • C. フルディスク暗号化
  • D. ファイルの整合性監視

正解:D


質問 # 136
脆弱性スキャンを実行した後、システム管理者は、特定された脆弱性の 1 つがスキャンされたシステムに存在しないことに気付きました。この例を説明するのは次のどれですか。

  • A. 偽陰性
  • B. 誤検知
  • C. 真陽性
  • D. 真陰性

正解:B

解説:
A false positive occurs when a vulnerability scan identifies a vulnerability that is not actually present on the systems that were scanned. This means that the scan has incorrectly flagged a system as vulnerable.
False positive: Incorrectly identifies a vulnerability that does not exist on the scanned systems.
False negative: Fails to identify an existing vulnerability on the system.
True positive: Correctly identifies an existing vulnerability.
True negative: Correctly identifies that there is no vulnerability.


質問 # 137
セキュリティ アナリストは、ネットワークに接続されている現在のエンドポイント資産の月次監査中に不正なデバイスを発見しました。企業ネットワークは、アクセス制御に 002.1X を使用しています。デバイスがネットワークにアクセスするには、既知のハードウェア アドレスを持ち、有効なユーザー名とパスワードをキャプティブ ポータルに入力する必要があります。監査レポートは次のとおりです。

不正なデバイスの接続が許可される可能性が最も高い方法はどれですか?

  • A. ユーザーが個人のデバイスを使用して MAC クローン攻撃を実行しました。
  • B. 管理者がテストのためにセキュリティ制御をバイパスしました。
  • C. DMCP障害により誤ったIPアドレスが配布されました
  • D. DNS ハイジャックにより、攻撃者はキャプティブ ポータルのトラフィックを傍受できます。

正解:A

解説:
The most likely way a rogue device was able to connect to the network is through a MAC cloning attack. In this attack, a personal device copies the MAC address of an authorized device, bypassing the 802.1X access control that relies on known hardware addresses for network access. The matching MAC addresses in the audit report suggest that this technique was used to gain unauthorized network access.
References =
* CompTIA Security+ SY0-701 Course Content: Domain 03 Security Architecture.
* CompTIA Security+ SY0-601 Study Guide: Chapter on Network Security and MAC Address Spoofing.


質問 # 138
レガシー サーバーで実行されている重要なビジネス アプリケーションを処理するための最適な方法はどれですか?

  • A. セグメンテーション
  • B. 廃止
  • C. 強化
  • D. 孤立

正解:A

解説:
The device is STILL running a critical application. therefore it needs to be connected to the network. a compensating mechanism for this scenario would be segmentation as this would limit the ability of an attacker to pivot from the vulnerable server to the rest of the network.as possible.


質問 # 139
会社の Web フィルターは、URL をスキャンして文字列を検索し、一致するものが見つかった場合はアクセスを拒否するように設定されています。暗号化されていない Web サイトへのアクセスを禁止するには、アナリストは次のどの検索文字列を使用する必要がありますか。

  • A. :443
  • B. http://
  • C. encryption=off\
  • D. www.*.com

正解:B

解説:
A web filter is a device or software that can monitor, block, or allow web traffic based on predefined rules or policies. One of the common methods of web filtering is to scan the URL for strings and deny access when matches are found. For example, a web filter can block access to websites that contain the words "gambling", "porn", or "malware" in their URLs. A URL is a uniform resource locator that identifies the location and protocol of a web resource. A URL typically consists of the following components: protocol://domain:port/path?query#fragment. The protocol specifies the communication method used to access the web resource, such as HTTP, HTTPS, FTP, or SMTP. The domain is the name of the web server that hosts the web resource, such as www.google.com or www.bing.com. The port is an optional number that identifies the specific service or application running on the web server, such as 80 for HTTP or 443 for HTTPS. The path is the specific folder or file name of the web resource, such as /index.html or /images/logo.png. The query is an optional string that contains additional information or parameters for the web resource, such as ?q=security or ?lang=en. The fragment is an optional string that identifies a specific part or section of the web resource, such as #introduction or #summary.
To prohibit access to non-encrypted websites, an analyst should employ a search string that matches the protocol of non-encrypted web traffic, which is HTTP. HTTP stands for hypertext transfer protocol, and it is a standard protocol for transferring data between web servers and web browsers. However, HTTP does not provide any encryption or security for the data, which means that anyone who intercepts the web traffic can read or modify the data. Therefore, non-encrypted websites are vulnerable to eavesdropping, tampering, or spoofing attacks. To access a non-encrypted website, the URL usually starts with http://, followed by the domain name and optionally the port number. For example, http://www.example.com or http://www.example.com:80. By scanning the URL for the string http://, the web filter can identify and block non-encrypted websites.
The other options are not correct because they do not match the protocol of non-encrypted web traffic. Encryption=off is a possible query string that indicates the encryption status of the web resource, but it is not a standard or mandatory parameter. Https:// is the protocol of encrypted web traffic, which uses hypertext transfer protocol secure (HTTPS) to provide encryption and security for the data. Www.*.com is a possible domain name that matches any website that starts with www and ends with .com, but it does not specify the protocol. :443 is the port number of HTTPS, which is the protocol of encrypted web traffic. Reference = CompTIA Security+ Study Guide (SY0-701), Chapter 2: Securing Networks, page 69. Professor Messer's CompTIA SY0-701 Security+ Training Course, Section 2.1: Network Devices and Technologies, video: Web Filter (5:16).


質問 # 140
最近のアップグレード (WLAN インフラストラクチャ) 以来、複数のモバイル ユーザーがロビーからインターネットにアクセスできなくなっています。ネットワーク チームは建物のヒート マップ調査を実施し、そのエリアに複数の WAP があることを発見しました。これらの WAP は、高出力設定で同様の周波数を使用しています。セキュリティ チームが次に評価する必要があるインストールに関する考慮事項は次のどれですか。

  • A. 暗号化の種類
  • B. 新しいWLANの展開
  • C. WAP 配置
  • D. チャネルの重複

正解:D

解説:
When multiple Wireless Access Points (WAPs) are using similar frequencies with high power settings, it can cause channel overlap, leading to interference and connectivity issues. This is likely the reason why mobile users are unable to access the internet in the lobby. Evaluating and adjusting the channel settings on the WAPs to avoid overlap is crucial to resolving the connectivity problems.
References = CompTIA Security+ SY0-701 study materials, particularly the domain on Wireless and Mobile Security, which covers WLAN deployment considerations.


質問 # 141
脆弱性の重大性を定量的に測定するために使用されるのは次のどれですか?

  • A. CERT
  • B. CIA
  • C. CVSS
  • D. CVE

正解:C

解説:
CVSS stands for Common Vulnerability Scoring System, which is a framework that provides a standardized way to assess and communicate the severity and risk of vulnerabilities. CVSS uses a set of metrics and formulas to calculate a numerical score ranging from 0 to 10, where higher scores indicate higher criticality. CVSS can help organizations prioritize remediation efforts and compare vulnerabilities across different systems and vendors. The other options are not used to measure the criticality of a vulnerability, but rather to identify, classify, or report them. Reference: CompTIA Security+ Study Guide: Exam SY0-701, 9th Edition, page 39


質問 # 142
レガシー サーバーで実行されている重要なビジネス アプリケーションを処理するための最適な方法はどれですか?

  • A. 強化
  • B. 廃止
  • C. セグメンテーション
  • D. 孤立

正解:A

解説:
A legacy server is a server that is running outdated or unsupported software or hardware, which may pose security risks and compatibility issues. A critical business application is an application that is essential for the operation and continuity of the business, such as accounting, payroll, or inventory management. A legacy server running a critical business application may be difficult to replace or upgrade, but it should not be left unsecured or exposed to potential threats.
One of the best ways to handle a legacy server running a critical business application is to harden it. Hardening is the process of applying security measures and configurations to a system to reduce its attack surface and vulnerability. Hardening a legacy server may involve steps such as:
Applying patches and updates to the operating system and the application, if available Removing or disabling unnecessary services, features, or accounts Configuring firewall rules and network access control lists to restrict inbound and outbound traffic Enabling encryption and authentication for data transmission and storage Implementing logging and monitoring tools to detect and respond to anomalous or malicious activity Performing regular backups and testing of the system and the application Hardening a legacy server can help protect the critical business application from unauthorized access, modification, or disruption, while maintaining its functionality and availability. However, hardening a legacy server is not a permanent solution, and it may not be sufficient to address all the security issues and challenges posed by the outdated or unsupported system. Therefore, it is advisable to plan for the eventual decommissioning or migration of the legacy server to a more secure and modern platform, as soon as possible.


質問 # 143
管理者は、複数のユーザーが疑わしい IP アドレスからログインしていることに気付きました。ユーザーと話し合った後、管理者は従業員がそれらの IP アドレスからログインしていないことを確認し、影響を受けたユーザーのパスワードをリセットしました。管理者は、この種の攻撃が今後成功しないようにするために、次のどれを実施する必要がありますか?

  • A. 多要素認証
  • B. パスワードの複雑さ
  • C. アクセス管理
  • D. 権限の割り当て

正解:A

解説:
The correct answer is A because multifactor authentication (MFA) is a method of verifying a user's identity by requiring more than one factor, such as something the user knows (e.g., password), something the user has (e.g., token), or something the user is (e.g., biometric). MFA can prevent unauthorized access even if the user's password is compromised, as the attacker would need to provide another factor to log in. The other options are incorrect because they do not address the root cause of the attack, which is weak authentication. Permissions assignment (B) is the process of granting or denying access to resources based on the user's role or identity.
Access management is the process of controlling who can access what and under what conditions. Password complexity (D) is the requirement of using strong passwords that are hard to guess or crack, but it does not prevent an attacker from using a stolen password.


質問 # 144
セキュリティ アナリストがドメイン アクティビティ ログを確認し、次の点に気付きました。

セキュリティアナリストが発見した内容について、最も適切な説明は次のどれですか?

  • A. 攻撃者が jsmith のアカウントをブルートフォース攻撃しようとしています。
  • B. ユーザー jsmith のアカウントがロックアウトされました。
  • C. ドメインにランサムウェアが展開されました。
  • D. jsmithのワークステーションにキーロガーがインストールされています

正解:A

解説:
Brute force is a type of attack that tries to guess the password or other credentials of a user account by using a large number of possible combinations. An attacker can use automated tools or scripts to perform a brute force attack and gain unauthorized access to the account. The domain activity logs show that the user ismith has failed to log in 10 times in a row within a short period of time, which is a strong indicator of a brute force attack. The logs also show that the source IP address of the failed logins is different from the usual IP address of ismith, which suggests that the attacker is using a different device or location to launch the attack. The security analyst should take immediate action to block the attacker's IP address, reset ismith's password, and notify ismith of the incident.


質問 # 145
セキュリティ管理者は、機密性の高い顧客データの流出を防ぐために DLP ソリューションを導入しています。管理者が最初に行うべきことは何ですか?

  • A. クラウド ストレージ Web サイトへのアクセスをブロックします。
  • B. 送信メールの添付ファイルをブロックするルールを作成します。
  • C. ファイル サーバー上の共有からすべてのユーザー権限を削除します。
  • D. データに分類を適用します。

正解:D

解説:
Data classification is the process of assigning labels or tags to data based on its sensitivity, value, and risk. Data classification is the first step in a data loss prevention (DLP) solution, as it helps to identify what data needs to be protected and how. By applying classifications to the data, the security administrator can define appropriate policies and rules for the DLP solution to prevent the exfiltration of sensitive customer data.


質問 # 146
管理者が単一サーバーのセキュリティ ログを確認して、次のことを発見しました。このログ ファイルに記録されたアクションを最もよく表すのは次のどれですか。

  • A. ユーザーがパスワードを忘れた
  • B. 権限昇格
  • C. ブルートフォース攻撃
  • D. パスワード監査に失敗しました

正解:C

解説:
A brute-force attack is a type of attack that involves systematically trying all possible combinations of passwords or keys until the correct one is found. The log file shows multiple failed login attempts in a short amount of time, which is a characteristic of a brute-force attack. The attacker is trying to guess the password of the Administrator account on the server. The log file also shows the event ID 4625, which indicates a failed logon attempt, and the status code 0xC000006A, which means the user name is correct but the password is wrong. These are indicators of compromise (IoC) that suggest a brute-force attack is taking place. References: CompTIA Security+ Study Guide: Exam SY0-701, 9th Edition, page 215-216 and 223 1


質問 # 147
セキュリティ管理者は、何らかのチェックを含む環境でデータを保護する方法を必要とします。これにより、管理者は変更を追跡できます。この目標を達成するために、管理者は次のどれを設定する必要がありますか?

  • A. SPF
  • B. 完璧
  • C. NAC
  • D. GPO

正解:B

解説:
FIM stands for File Integrity Monitoring, which is a method to secure data by detecting any changes or modifications to files, directories, or registry keys. FIM can help a security administrator track any unauthorized or malicious changes to the data, as well as verify the integrity and compliance of the data. FIM can also alert the administrator of any potential breaches or incidents involving the data.
Some of the benefits of FIM are:
* It can prevent data tampering and corruption by verifying the checksums or hashes of the files.
* It can identify the source and time of the changes by logging the user and system actions.
* It can enforce security policies and standards by comparing the current state of the data with the baseline or expected state.
* It can support forensic analysis and incident response by providing evidence and audit trails of the changes.
References:
* CompTIA Security+ SY0-701 Certification Study Guide, Chapter 5: Technologies and Tools, Section
5.3: Security Tools, p. 209-210
* CompTIA Security+ SY0-701 Certification Exam Objectives, Domain 2: Technologies and Tools, Objective 2.4: Given a scenario, analyze and interpret output from security technologies, Sub-objective:
File integrity monitor, p. 12


質問 # 148
IT マネージャーは、データ分類イニシアチブによって機密データが環境から流出する可能性があることが判明した後、組織のセキュリティ機能を強化しています。次のソリューションのどれがリスクを軽減しますか?

  • A. SPF
  • B. DLP
  • C. XDR
  • D. DMARC

正解:B

解説:
To mitigate the risk of sensitive data being exfiltrated from the environment, the IT manager should implement a Data Loss Prevention (DLP) solution. DLP monitors and controls the movement of sensitive data, ensuring that unauthorized transfers are blocked and potential data breaches are prevented.
* XDR (Extended Detection and Response) is useful for threat detection across multiple environments but doesn't specifically address data exfiltration.
* SPF (Sender Policy Framework) helps prevent email spoofing, not data exfiltration.
* DMARC (Domain-based Message Authentication, Reporting & Conformance) also addresses email security and spoofing, not data exfiltration.


質問 # 149
管理チームは、手動で設定された新しいアカウントに必ずしも正しいアクセス権や権限が付与されていないことに気付きました。
システム管理者がアカウント作成を効率化するために使用すべき自動化手法は次のどれですか?

  • A. ユーザープロビジョニングスクリプト
  • B. エスカレーションスクリプト
  • C. チケット発行ワークフロー
  • D. ガードレールスクリプト

正解:A

解説:
A user provisioning script is an automation technique that uses a predefined set of instructions or commands to create, modify, or delete user accounts and assign appropriate access or permissions. A user provisioning script can help to streamline account creation by reducing manual errors, ensuring consistency and compliance, and saving time and resources. The other options are not automation techniques that can streamline account creation:
Guard rail script: This is a script that monitors and enforces the security policies and rules on a system or a network. A guard rail script can help to prevent unauthorized or malicious actions, such as changing security settings, accessing restricted resources, or installing unwanted software. Ticketing workflow: This is a process that tracks and manages the requests, issues, or incidents that are reported by users or customers. A ticketing workflow can help to improve the communication, collaboration, and resolution of problems, but it does not automate the account creation process. Escalation script: This is a script that triggers an alert or a notification when a certain condition or threshold is met or exceeded. An escalation script can help to inform the relevant parties or authorities of a critical situation, such as a security breach, a performance degradation, or a service outage.


質問 # 150
IT マネージャーは、ヘルプ デスク ソフトウェアの管理者コンソールにアクセスできるのは IT マネージャーとヘルプ デスク リーダーのみであることをヘルプ デスク スタッフ全体に通知します。IT マネージャーが設定しているセキュリティ手法は次のどれですか。

  • A. 構成の強制
  • B. 従業員の監視
  • C. 強化
  • D. 最小権限

正解:D

解説:
The principle of least privilege is a security concept that limits access to resources to the minimum level needed for a user, a program, or a device to perform a legitimate function. It is a cybersecurity best practice that protects high-value data and assets from compromise or insider threat. Least privilege can be applied to different abstraction layers of a computing environment, such as processes, systems, or connected devices.
However, it is rarely implemented in practice.
In this scenario, the IT manager is setting up the principle of least privilege by restricting access to the administrator console of the help desk software to only two authorized users: the IT manager and the help desk lead. This way, the IT manager can prevent unauthorized or accidental changes to the software configuration, data, or functionality by other help desk staff. The other help desk staff will only have access to the normal user interface of the software, which is sufficient for them to perform their job functions.
The other options are not correct. Hardening is the process of securing a system by reducing its surface of vulnerability, such as by removing unnecessary software, changing default passwords, or disabling unnecessary services. Employee monitoring is the surveillance of workers' activity, such as by tracking web browsing, application use, keystrokes, or screenshots. Configuration enforcement is the process of ensuring that a system adheres to a predefined set of security settings, such as by applying a patch, a policy, or a template.
References =
https://en.wikipedia.org/wiki/Principle_of_least_privilege
https://en.wikipedia.org/wiki/Principle_of_least_privilege


質問 # 151
会議室で会議を行い、会社のインシデント対応計画をテストしている経営陣を説明するのは次のどれですか。

  • A. 業務の継続
  • B. キャパシティプランニング
  • C. テーブルトップ演習
  • D. 並列処理

正解:C

解説:
A tabletop exercise involves the executive team or key stakeholders discussing and testing the company's incident response plan in a simulated environment. These exercises are low-stress, discussion-based, and help to validate the plan's effectiveness by walking through different scenarios without disrupting actual operations. It is an essential part of testing business continuity and incident response strategies.
* Continuity of operations refers to the ability of an organization to continue functioning during and after a disaster but doesn't specifically involve simulations like tabletop exercises.
* Capacity planning is related to ensuring the infrastructure can handle growth, not incident response testing.
* Parallel processing refers to running multiple processes simultaneously, which is unrelated to testing an incident response plan.


質問 # 152
ベンダーは、コマンド ラインを使用して、あるサーバーから別のサーバーにファイルをリモートかつ安全に転送する必要があります。
このタイプのアクセスを可能にするために実装する必要があるプロトコルは次のどれですか? (2 つ選択してください)。

  • A. SNMP
  • B. SFTP
  • C. RDP
  • D. SSH
  • E. SMTP
  • F. S/MIME

正解:B、D

解説:
Secure Shell (SSH) is a protocol used for secure command-line access to remote systems, while Secure File Transfer Protocol (SFTP) is an extension of SSH used specifically for securely transferring files. Both SSH and SFTP ensure that data is encrypted during transmission, protecting it from interception or tampering.
References =
* CompTIA Security+ SY0-701 Course Content: Domain 03 Security Architecture.
* CompTIA Security+ SY0-601 Study Guide: Chapter on Secure Protocols and Encryption.


質問 # 153
ファイアウォール構成のトラブルシューティング中に、技術者は ACL の一番下に「すべて拒否」ポリシーを追加する必要があると判断しました。技術者はポリシーを更新しましたが、新しいポリシーによって会社の複数のサーバーがアクセス不能になりました。
この問題を防ぐには、次のどのアクションを実行すればよいでしょうか?

  • A. 運用ネットワークでポリシーを有効にする前に、非運用環境でポリシーをテストする
  • B. 新しいポリシーを有効にする前に、「すべて拒否」ポリシーの侵入防止シグネチャを無効にする
  • C. 「すべてを拒否」ポリシーの上に「すべて1を許可」ポリシーを含める
  • D. 変更要求に新しいポリシーを文書化し、変更管理に要求を送信する

正解:A

解説:
A firewall policy is a set of rules that defines what traffic is allowed or denied on a network. A firewall policy should be carefully designed and tested before being implemented, as a misconfigured policy can cause network disruptions or security breaches. A common best practice is to test the policy in a non-production environment, such as a lab or a simulation, before enabling the policy in the production network. This way, the technician can verify the functionality and performance of the policy, and identify and resolve any issues or conflicts, without affecting the live network. Testing the policy in a non-production environment would prevent the issue of the 'deny any' policy causing several company servers to become unreachable, as the technician would be able to detect and correct the problem before applying the policy to the production network.
Documenting the new policy in a change request and submitting the request to change management is a good practice, but it would not prevent the issue by itself. Change management is a process that ensures that any changes to the network are authorized, documented, and communicated, but it does not guarantee that the changes are error-free or functional. The technician still needs to test the policy before implementing it.
Disabling any intrusion prevention signatures on the 'deny any' policy prior to enabling the new policy would not prevent the issue, and it could reduce the security of the network. Intrusion prevention signatures are patterns that identify malicious or unwanted traffic, and allow the firewall to block or alert on such traffic.
Disabling these signatures would make the firewall less effective in detecting and preventing attacks, and it would not affect the reachability of the company servers.
Including an 'allow any' policy above the 'deny any' policy would not prevent the issue, and it would render the 'deny any' policy useless. A firewall policy is processed from top to bottom, and the first matching rule is applied. An 'allow any' policy would match any traffic and allow it to pass through the firewall, regardless of the source, destination, or protocol. This would negate the purpose of the 'deny any' policy, which is to block any traffic that does not match any of the previous rules. Moreover, an 'allow any' policy would create a security risk, as it would allow any unauthorized or malicious traffic to enter or exit the network. References = CompTIA Security+ SY0-701 Certification Study Guide, page 204-205; Professor Messer's CompTIA SY0-701 Security+ Training Course, video 2.1 - Network Security Devices, 8:00 - 10:00.


質問 # 154
システム管理者は、企業環境内でパスワード ポリシーを変更しており、この更新をできるだけ早くすべてのシステムに実装したいと考えています。管理者は、次のオペレーティング システムのセキュリティ対策のうちどれを使用する可能性が最も高いでしょうか。

  • A. EDR プロファイルの更新
  • B. GPO 更新をプッシュしています
  • C. PAP を有効にする
  • D. PowerShell スクリプトのデプロイ

正解:B

解説:
A group policy object (GPO) is a mechanism for applying configuration settings to computers and users in an Active Directory domain. By pushing a GPO update, the systems administrator can quickly and uniformly enforce the new password policy across all systems in the domain.
Deploying PowerShell scripts, enabling PAP, and updating EDR profiles are not the most efficient or effective ways to change the password policy within an enterprise environment.


質問 # 155
セキュリティ エンジニアがワークステーションとサーバー上で不正な変更やソフトウェアが適切に監視されていることを確認するために実行できるアクションは次のどれですか。

  • A. すべてのシステムにエンドポイント管理ソフトウェアをインストールします。
  • B. スケジュールされたタスクをログに記録するようにすべてのシステムを構成します。
  • C. 既知の悪意のあるシグネチャに基づいてトラフィックをブロックします。
  • D. ネットワークから出るすべてのトラフィックを収集して監視します。

正解:A

解説:
Endpoint management software is a tool that allows security engineers to monitor and control the configuration, security, and performance of workstations and servers from a central console. Endpoint management software can help detect and prevent unauthorized changes and software installations, enforce policies and compliance, and provide reports and alerts on the status of the endpoints. The other options are not as effective or comprehensive as endpoint management software for this purpose. Reference: CompTIA Security+ Study Guide: Exam SY0-701, 9th Edition, page 137 1


質問 # 156
セキュリティ アナリストがドメイン アクティビティ ログを確認し、次の点に気付きました。

セキュリティアナリストが発見した内容について、最も適切な説明は次のどれですか?

  • A. [smithのワークステーションにキーロガーがインストールされています
  • B. 攻撃者が ismith のアカウントをブルートフォース攻撃しようとしています。
  • C. ユーザー jsmith のアカウントがロックアウトされました。
  • D. ドメインにランサムウェアが展開されました。

正解:B

解説:
Brute force is a type of attack that tries to guess the password or other credentials of a user account by using a large number of possible combinations. An attacker can use automated tools or scripts to perform a brute force attack and gain unauthorized access to the account. The domain activity logs show that the user ismith has failed to log in 10 times in a row within a short period of time, which is a strong indicator of a brute force attack. The logs also show that the source IP address of the failed logins is different from the usual IP address of ismith, which suggests that the attacker is using a different device or location to launch the attack. The security analyst should take immediate action to block the attacker's IP address, reset ismith's password, and notify ismith of the incident. Reference = CompTIA Security+ Study Guide with over 500 Practice Test Questions: Exam SY0-701, 9th Edition, Chapter 1, page 14. CompTIA Security+ (SY0-701) Certification Exam Objectives, Domain 1.1, page 2. Threat Actors and Attributes - SY0-601 CompTIA Security+ : 1.1


質問 # 157
......

検証済みSY0-701日本語問題集と解答で最新SY0-701日本語をダウンロード:https://www.passtest.jp/CompTIA/SY0-701-JPN-shiken.html