
[2024年10月最新リリース]SY0-701日本語問題集でCompTIA Security+認証
最新の完璧なSY0-701日本語問題集問題と解答で100%パスさせます
質問 # 86
許容使用ポリシーは、次のセキュリティ制御タイプのうちどれを最もよく表していますか?
- A. 探偵
- B. 修正
- C. 補償
- D. 予防的
正解:D
解説:
An acceptable use policy (AUP) is a set of rules that govern how users can access and use a corporate network or the internet. The AUP helps companies minimize their exposure to cyber security threats and limit other risks. The AUP also serves as a notice to users about what they are not allowed to do and protects the company against misuse of their network. Users usually have to acknowledge that they understand and agree to the rules before accessing the network1.
An AUP best represents a preventive security control type, because it aims to deter or stop potential security incidents from occurring in the first place. A preventive control is proactive and anticipates possible threats and vulnerabilities, and implements measures to prevent them from exploiting or harming the system or the data. A preventive control can be physical, technical, or administrative in nature2.
Some examples of preventive controls are:
Locks, fences, or guards that prevent unauthorized physical access to a facility or a device Firewalls, antivirus software, or encryption that prevent unauthorized logical access to a network or a system Policies, procedures, or training that prevent unauthorized or inappropriate actions or behaviors by users or employees An AUP is an example of an administrative preventive control, because it defines the policies and procedures that users must follow to ensure the security and proper use of the network and the IT resources. An AUP can prevent users from engaging in activities that could compromise the security, performance, or availability of the network or the system, such as:
Downloading or installing unauthorized or malicious software
Accessing or sharing sensitive or confidential information without authorization or encryption Using the network or the system for personal, illegal, or unethical purposes Bypassing or disabling security controls or mechanisms Connecting unsecured or unapproved devices to the network By enforcing an AUP, a company can prevent or reduce the likelihood of security breaches, data loss, legal liability, or reputational damage caused by user actions or inactions3.
Reference = 1: How to Create an Acceptable Use Policy - CoreTech, 2: [Security Control Types: Preventive, Detective, Corrective, and Compensating], 3: Why You Need A Corporate Acceptable Use Policy - CompTIA
質問 # 87
レガシー IoT デバイスの OS に、新たに特定されたネットワーク アクセスの脆弱性が見つかりました。この脆弱性を迅速に軽減するには、次のうちどれが最適ですか?
- A. 保険
- B. 置き換え
- C. パッチ適用
- D. セグメンテーション
正解:D
解説:
Segmentation is a technique that divides a network into smaller subnetworks or segments, each with its own security policies and controls. Segmentation can help mitigate network access vulnerabilities in legacy loT devices by isolating them from other devices and systems, reducing their attack surface and limiting the potential impact of a breach. Segmentation can also improve network performance and efficiency by reducing congestion and traffic. Patching, insurance, and replacement are other possible strategies to deal with network access vulnerabilities, but they may not be feasible or effective in the short term. Patching may not be available or compatible for legacy loT devices, insurance may not cover the costs or damages of a cyberattack, and replacement may be expensive and time-consuming. References: CompTIA Security+ Study Guide: Exam SY0-701, 9th Edition, page 142-143
質問 # 88
ある企業が機密ストレージ アレイを廃棄し、廃棄を完了するために外部ベンダーを雇います。企業がベンダーに要求する必要があるのは次のうちどれですか。
- A. 分類
- B. 所有権の証明
- C. 在庫リスト
- D. 認定
正解:D
解説:
The company should request a certification from the vendor that confirms the storage array has been disposed of securely and in compliance with the company's policies and standards. A certification provides evidence that the vendor has followed the proper procedures and methods to destroy the classified data and prevent unauthorized access or recovery. A certification may also include details such as the date, time, location, and method of disposal, as well as the names and signatures of the personnel involved. References: CompTIA Security+ Study Guide: Exam SY0-701, 9th Edition, Chapter 3, page 1441
質問 # 89
ある企業は、脅威サーフェス プログラムを拡張し、個人が同社のインターネット向けアプリケーションのセキュリティ テストを行えるようにしています。同社は、発見された脆弱性に基づいて研究者に報酬を支払う予定です。同社が設定しているプログラムについて最もよく説明されているのは次のうちどれですか。
- A. レッドチーム
- B. オープンソースインテリジェンス
- C. バグバウンティ
- D. 侵入テスト
正解:C
解説:
A bug bounty is a program that rewards security researchers for finding and reporting vulnerabilities in an application or system. Bug bounties are often used by companies to improve their security posture and incentivize ethical hacking. A bug bounty program typically defines the scope, rules, and compensation for the researchers.
質問 # 90
企業は、ネットワークを構築するときに認定ハードウェアを使用する必要があります。偽造ハードウェアの調達に伴うリスクに最もよく対処しているのは、次のどれですか。
- A. ベンダー契約およびSOWにおける監査権条項
- B. サプライチェーンの徹底的な分析
- C. すべてのサプライヤーとベンダーに対する徹底的な侵入テスト
- D. 法的に強制力のある企業買収ポリシー
正解:B
解説:
Counterfeit hardware is hardware that is built or modified without the authorization of the original equipment manufacturer (OEM). It can pose serious risks to network quality, performance, safety, and reliability. Counterfeit hardware can also contain malicious components that can compromise the security of the network and the data that flows through it. To address the risks associated with procuring counterfeit hardware, a company should conduct a thorough analysis of the supply chain, which is the network of entities involved in the production, distribution, and delivery of the hardware. By analyzing the supply chain, the company can verify the origin, authenticity, and integrity of the hardware, and identify any potential sources of counterfeit or tampered products.
質問 # 91
ある企業が、リスク登録簿に記載されている項目に対処するためにサイバー保険を購入しました。これは次のどの戦略を表していますか?
- A. 転送
- B. 軽減
- C. 避ける
- D. 受け入れる
正解:A
質問 # 92
ある企業が、インフラストラクチャをオフプレミス ソリューションに移行するための小額の助成金を受け取りました。最初に検討すべきは次のうちどれですか。
- A. クラウドプロバイダーのセキュリティ
- B. エンジニアの能力
- C. アーキテクチャのセキュリティ
- D. 実装コスト
正解:C
解説:
Security of architecture is the process of designing and implementing a secure infrastructure that meets the business objectives and requirements. Security of architecture should be considered first when migrating to an off-premises solution, such as cloud computing, because it can help to identify and mitigate the potential risks and challenges associated with the migration, such as data security, compliance, availability, scalability, and performance. Security of architecture is different from security of cloud providers, which is the process of evaluating and selecting a trustworthy and reliable cloud service provider that can meet the security and operational needs of the business. Security of architecture is also different from cost of implementation, which is the amount of money required to migrate and maintain the infrastructure in the cloud. Security of architecture is also different from ability of engineers, which is the level of skill and knowledge of the IT staff who are responsible for the migration and management of the cloud infrastructure. Reference: CompTIA Security+ Study Guide: Exam SY0-701, 9th Edition, page 3491
質問 # 93
ある組織が本社と支社の間で VPN を活用しています。VPN が保護しているのは次のどれですか?
- A. データ主権
- B. 転送中のデータ
- C. 地理的制限
- D. 使用中のデータ
正解:B
解説:
Data in transit is data that is moving from one location to another, such as over a network or through the air. Data in transit is vulnerable to interception, modification, or theft by malicious actors. A VPN (virtual private network) is a technology that protects data in transit by creating a secure tunnel between two endpoints and encrypting the data that passes through it2.
質問 # 94
ソフトウェア開発マネージャーは、会社が作成したコードの信頼性を確保したいと考えています。次のオプションのうち、最も適切なものはどれですか。
- A. ユーザー入力フィールドの入力検証をテストする
- B. 安全なCookieが使用されていることを確認する
- C. 自社開発ソフトウェアのコード署名の実行
- D. ソフトウェアの静的コード解析を実行する
正解:C
解説:
Code signing is a technique that uses cryptography to verify the authenticity and integrity of the code created by the company. Code signing involves applying a digital signature to the code using a private key that only the company possesses. The digital signature can be verified by anyone who has the corresponding public key, which can be distributed through a trusted certificate authority. Code signing can prevent unauthorized modifications, tampering, or malware injection into the code, and it can also assure the users that the code is from a legitimate source. Reference = CompTIA Security+ Study Guide with over 500 Practice Test Questions: Exam SY0-701, 9th Edition, Chapter 2, page 74. CompTIA Security+ (SY0-701) Certification Exam Objectives, Domain 3.2, page 11. Application Security - SY0-601 CompTIA Security+ : 3.2
質問 # 95
セキュリティ アナリストは、ネットワークへのアクセスを強化する必要があります。要件の 1 つは、スマート カードを使用してユーザーを認証することです。この要件を最もよく満たすために、アナリストは次のどれを有効にする必要がありますか。
- A. MS-CHAPv2
- B. チャップ
- C. PEAP
- D. EAP-TLS
正解:D
解説:
EAP-TLS is a strong and secure authentication method that involves the use of digital certificates, typically stored on smart cards, for user authentication. It requires the user to present a valid certificate, which is verified by the authentication server, providing a high level of security.
質問 # 96
ある企業は、他社が自社について調査や偵察を行っているときにアラートを受け取りたいと考えています。1 つの方法は、会社の資産と思われる既知の脆弱性を持つインフラストラクチャの一部をオンラインでホストすることです。このアプローチを説明するのは次のどれですか。
- A. バグバウンティ
- B. ハニーポット
- C. 水飲み場
- D. DNS シンクホール
正解:B
解説:
A honeypot is a security mechanism set up to attract and detect potential attackers by simulating vulnerable assets. By hosting a part of the infrastructure online with known vulnerabilities that appear to be company assets, the company can observe and analyze the behavior of attackers conducting reconnaissance. This approach allows the company to get alerts and gather intelligence on potential threats.
References = CompTIA Security+ SY0-701 study materials, particularly on threat detection techniques such as honeypots.
質問 # 97
ある企業は、SIEM システムを導入し、アナリストを任命して毎週ログを確認することを計画しています。企業が導入しようとしている制御の種類は次のどれですか。
- A. 予防的
- B. 修正
- C. 抑止力
- D. 探偵
正解:D
解説:
A detective control is a type of control that monitors and analyzes the events and activities in a system or a network, and alerts or reports when an incident or a violation occurs. A SIEM (Security Information and Event Management) system is a tool that collects, correlates, and analyzes the logs from various sources, such as firewalls, routers, servers, or applications, and provides a centralized view of the security status and incidents. An analyst who reviews the logs on a weekly basis can identify and investigate any anomalies, trends, or patterns that indicate a potential threat or a breach. A detective control can help the company to respond quickly and effectively to the incidents, and to improve its security posture and resilience. Reference = CompTIA Security+ Study Guide with over 500 Practice Test Questions: Exam SY0-701, 9th Edition, Chapter 1, page 23. CompTIA Security+ SY0-701 Exam Objectives, Domain 4.3, page 14.
質問 # 98
ある企業は、脅威サーフェス プログラムを拡張し、個人が同社のインターネット向けアプリケーションのセキュリティ テストを行えるようにしています。同社は、発見された脆弱性に基づいて研究者に報酬を支払う予定です。同社が設定しているプログラムについて最もよく説明されているのは次のうちどれですか。
- A. レッドチーム
- B. オープンソースインテリジェンス
- C. バグバウンティ
- D. 侵入テスト
正解:C
解説:
A bug bounty is a program that rewards security researchers for finding and reporting vulnerabilities in an application or system. Bug bounties are often used by companies to improve their security posture and incentivize ethical hacking. A bug bounty program typically defines the scope, rules, and compensation for the researchers. References = CompTIA Security+ Study Guide with over 500 Practice Test Questions: Exam SY0-701, 9th Edition, Chapter 1, page 10. CompTIA Security+ (SY0-701) Certification Exam Objectives, Domain 1.1, page 2.
質問 # 99
数人の従業員が、最高経営責任者(CEO)を名乗る人物から詐欺のテキスト メッセージを受け取りました。メッセージには次のように書かれていました。
「私は今、空港にいて、メールにアクセスできません。従業員表彰賞用のギフト カードを購入していただく必要があります。ギフト カードを次のメール アドレスに送ってください。」この状況に対する最適な対応は次のうちどれですか。(2 つ選択してください)。
- A. 会社全体に電子メールによる警告を発行します。
- B. CEO の電話のフォレンジック調査を実施します。
- C. 現在の従業員表彰ギフトカードをキャンセルします。
- D. 毎年の社内研修にスミッシング演習を追加します。
- E. モバイル デバイス管理を実装します。
- F. CEO に電話番号を変更してもらいます。
正解:A、D
解説:
This situation is an example of smishing, which is a type of phishing that uses text messages (SMS) to entice individuals into providing personal or sensitive information to cybercriminals. The best responses to this situation are to add a smishing exercise to the annual company training and to issue a general email warning to the company. A smishing exercise can help raise awareness and educate employees on how to recognize and avoid smishing attacks. An email warning can alert employees to the fraudulent text message and remind them to verify the identity and legitimacy of any requests for information or money. Reference = What Is Phishing | Cybersecurity | CompTIA, Phishing - SY0-601 CompTIA Security+ : 1.1 - Professor Messer IT Certification Training Courses
質問 # 100
経理担当者は、新しい口座を使用するようにという不正な指示を受け、攻撃者の銀行口座に送金しました。今後この行為を防ぐには、次のうちどれが最も効果的でしょうか。
- A. 電信送金の送信プロセスの更新
- B. 内部脅威検出対策の実施
- C. セキュリティインシデント報告の標準化
- D. 定期的なフィッシングキャンペーンの実行
正解:A
解説:
To prevent an accounting clerk from sending money to an attacker's bank account due to fraudulent instructions, the most effective measure would be updating the processes for sending wire transfers. This can include implementing verification steps, such as requiring multiple approvals for changes in payment instructions and directly confirming new account details with trusted sources.
Updating processes for sending wire transfers: Involves adding verification and approval steps to prevent fraudulent transfers.
Standardizing security incident reporting: Important for handling incidents but not specifically focused on preventing fraudulent wire transfers.
Executing regular phishing campaigns: Helps raise awareness but may not directly address the process vulnerability.
Implementing insider threat detection measures: Useful for detecting malicious activities but does not directly prevent fraudulent transfer instructions.
質問 # 101
高可用性ネットワークを設計する際に考慮する必要があるのは次のうちどれですか? (2 つ選択してください)。
- A. 物理的な分離
- B. パッチを当てる機能
- C. 応答性
- D. 回復の容易さ
- E. 拡張認証
- F. 攻撃対象領域
正解:D、F
解説:
A high-availability network is a network that is designed to minimize downtime and ensure continuous operation of critical services and applications. To achieve this goal, a high-availability network must consider two important factors: ease of recovery and attack surface.
Ease of recovery refers to the ability of a network to quickly restore normal functionality after a failure, disruption, or disaster. A high-availability network should have mechanisms such as redundancy, failover, backup, and restore to ensure that any single point of failure does not cause a complete network outage. A high-availability network should also have procedures and policies for incident response, disaster recovery, and business continuity to minimize the impact of any network issue on the organization's operations and reputation.
Attack surface refers to the exposure of a network to potential threats and vulnerabilities. A high-availability network should have measures such as encryption, authentication, authorization, firewall, intrusion detection and prevention, and patch management to protect the network from unauthorized access, data breaches, malware, denial-of-service attacks, and other cyberattacks. A high-availability network should also have processes and tools for risk assessment, threat intelligence, vulnerability scanning, and penetration testing to identify and mitigate any weaknesses or gaps in the network security.
質問 # 102
企業は、セキュリティ境界を通過するトラフィックを最小限に抑えながら、内部リソースへの管理アクセスを提供する必要があります。次の方法のうち、最も安全なのはどれですか。
- A. WAFのインストール
- B. 境界ネットワークの展開
- C. シングルサインオンの活用
- D. 要塞ホストの実装
正解:D
解説:
A bastion host is a special-purpose server that is designed to withstand attacks and provide secure access to internal resources. A bastion host is usually placed on the edge of a network, acting as a gateway or proxy to the internal network. A bastion host can be configured to allow only certain types of traffic, such as SSH or HTTP, and block all other traffic. A bastion host can also run security software such as firewalls, intrusion detection systems, and antivirus programs to monitor and filter incoming and outgoing traffic. A bastion host can provide administrative access to internal resources by requiring strong authentication and encryption, and by logging all activities for auditing purposes12.
A bastion host is the most secure method among the given options because it minimizes the traffic allowed through the security boundary and provides a single point of control and defense. A bastion host can also isolate the internal network from direct exposure to the internet or other untrusted networks, reducing the attack surface and the risk of compromise3.
Deploying a perimeter network is not the correct answer, because a perimeter network is a network segment that separates the internal network from the external network. A perimeter network usually hosts public- facing services such as web servers, email servers, or DNS servers that need to be accessible from the internet. A perimeter network does not provide administrative access to internal resources, but rather protects them from unauthorized access. A perimeter network can also increase the complexity and cost of network management and security4.
Installing a WAF is not the correct answer, because a WAF is a security tool that protects web applications from common web-based attacks by monitoring, filtering, and blocking HTTP traffic. A WAF can prevent attacks such as cross-site scripting, SQL injection, or file inclusion, among others. A WAF does not provide administrative access to internal resources, but rather protects them from web application vulnerabilities. A WAF is also not a comprehensive solution for network security, as it only operates at the application layer and does not protect against other types of attacks or threats5.
Utilizing single sign-on is not the correct answer, because single sign-on is a method of authentication that allows users to access multiple sites, services, or applications with one username and password. Single sign- on can simplify the sign-in process for users and reduce the number of passwords they have to remember and manage. Single sign-on does not provide administrative access to internal resources, but rather enables access to various resources that the user is authorized to use. Single sign-on can also introduce security risks if the user's credentials are compromised or if the single sign-on provider is breached6. References = 1: Bastion host - Wikipedia, 2: 14 Best Practices to Secure SSH Bastion Host - goteleport.com, 3: The Importance Of Bastion Hosts In Network Security, 4: What is the network perimeter? | Cloudflare, 5: What is a WAF? | Web Application Firewall explained, 6: [What is single sign-on (SSO)? - Definition from WhatIs.com]
質問 # 103
セキュリティ アナリストが会社のパブリック ネットワークをスキャンし、実稼働ネットワークへのアクセスに使用できるリモート デスクトップがホストで実行されていることを発見しました。セキュリティ アナリストは次のどの変更を推奨すべきでしょうか。
- A. リモートサーバーをドメインに接続し、パスワードの長さを増やす
- B. VPNを設定し、ジャンプサーバーをファイアウォール内に配置する
- C. リモートデスクトップポートを非標準の番号に変更する
- D. リモート デスクトップ サーバーからの Web 接続にプロキシを使用する
正解:B
解説:
A VPN is a virtual private network that creates a secure tunnel between two or more devices over a public network. A VPN can encrypt and authenticate the data, as well as hide the IP addresses and locations of the devices. A jump server is a server that acts as an intermediary between a user and a target server, such as a production server. A jump server can provide an additional layer of security and access control, as well as logging and auditing capabilities. A firewall is a device or software that filters and blocks unwanted network traffic based on predefined rules. A firewall can protect the internal network from external threats and limit the exposure of sensitive services and ports. A security analyst should recommend setting up a VPN and placing the jump server inside the firewall to improve the security of the remote desktop access to the production network. This way, the remote desktop service will not be exposed to the public network, and only authorized users with VPN credentials can access the jump server and then the production server. Reference: CompTIA Security+ Study Guide: Exam SY0-701, 9th Edition, Chapter 8: Secure Protocols and Services, page 382-383 1; Chapter 9: Network Security, page 441-442 1
質問 # 104
......
最新のSY0-701日本語試験問題集でCompTIA試験トレーニング:https://www.passtest.jp/CompTIA/SY0-701-JPN-shiken.html