CV0-003日本語練習テスト問題解答には更新された376問があります
CV0-003日本語問題集はCompTIA Cloud+合格確定させる練習で376問があります
質問 # 25
クラウド管理者は、カスタム VM 展開スクリプトを使用しています。3 か月使用した後、スクリプトは LDAP ドメインに参加しなくなりました。クラウド管理者は、アカウントに正しいアクセス許可があることを確認します。失敗の原因として最も可能性が高いのは次のうちどれですか?
- A. 壊れた信頼関係
- B. 期限切れのパスワード
- C. 無効な証明書
- D. 暗号化方式が正しくありません
正解:B
質問 # 26
管理者の Joe は、新しい仮想化アプリケーション サーバーのクローンを作成しました。新しいアプリケーション サーバーは数か月間動作し、期待されるパフォーマンスを満たしています。クローンから 2 番目のアプリケーション サーバーを構築した後、Joe は 2 番目のサーバーが遅すぎるという報告をいくつか受け取ります。Joe が予想されるサーバー パフォーマンスを判断するために最初に使用する必要があるのは、次のうちどれですか?
- A. 変更管理データベース
- B. ベースライン ドキュメント
- C. NIC スループット監視ツール
- D. HBA スループット監視ツール
正解:B
質問 # 27
クラウド セキュリティ エンジニアは、クラウド プロバイダー コンソールへの認証が安全であることを確認する必要があります。この目的を最もよく達成できるのは次のうちどれですか?
- A. パスワードと物理トークンの使用が必要です。
- B. ユーザーの送信元 IP が RFC1918 アドレスである必要があります。
- C. パスワードの長さは 10 文字である必要があります。
- D. パスワードに大文字、小文字、数字、記号を含める必要があります。
正解:A
解説:
Explanation
A password and a physical token are two factors of authentication that can provide a higher level of security than a password alone. A physical token is a device that generates a one-time code or password that the user must enter along with their password to access the cloud provider console. This is an example of multi-factor authentication (MFA), which requires the user to present two or more pieces of evidence to prove their identity. MFA can prevent unauthorized access even if the password is compromised, as the attacker would also need to have the physical token to log in.
質問 # 28
システム管理者は、ハイブリッド クラウド環境で SSO 認証を構成する必要があります。
次のうち、使用するのに最適なテクニックはどれですか?
- A. 証明書認証
- B. 多要素認証
- C. アクセス制御
- D. 連邦
正解:B
解説:
Section: (none)
Explanation
質問 # 29
VDI 管理者は、製図部門から、レンダリングが通常より遅いという報告を受けました。VDI インフラストラクチャのパフォーマンスを最適化するために管理者が最初にチェックする必要があるのは、次のうちどれですか?
- A. GPU
- B. ストレージ
- C. メモリ
- D. CPU
正解:C
解説:
https://www.computer.org/publications/tech-news/trends/7-tips-for-faster-3d-rendering
質問 # 30
クラウド管理者は、金融アプリケーションのセキュリティ レビューの一環として、Web サーバーのグループとデータベース サーバー間の接続を制御する必要があります。この目的を達成するための最良の方法は次のうちどれですか?
- A. ネットワークセキュリティグループを作成します。
- B. 個別の VLAN を作成します。
- C. ディレクトリセキュリティグループを作成します。
- D. リソースグループを作成します。
正解:A
解説:
A network security group is a service that allows the cloud administrator to filter and control the network traffic between different resources in a cloud environment. A network security group contains security rules that specify the source, destination, protocol, port, and direction of the traffic, and whether to allow or deny it. A network security group can be associated with a subnet or a network interface in a virtual machine, and it can apply to inbound or outbound traffic. A network security group would be the best way to achieve the objective of controlling the connections between a group of web servers and database servers as part of the financial application security review, as it can provide granular and flexible control over the network access and security of the servers.
質問 # 31
通常、ネットワーク ストレージ実装で高速なアクセス速度を提供するのは次のうちどれですか?
- A. SAN
- B. DAS
- C. SATA
- D. NFS
正解:B
質問 # 32
需要に基づいて、IaaS プロバイダーは顧客のためにセキュリティ アプリケーションをデプロイしたいと考えています。
IaaS プロバイダーがこれをターゲット システムに適用するための最良の手法は次のうちどれですか?
- A. カスタム プログラミング
- B. オーケストレーション
- C. ベンダー アプリケーション
- D. スクリプト
正解:B
質問 # 33
DevOps 管理者は、プライベート クラウドで新しいアプリケーション Slack を構築しています。このアプリケーションは機密情報を保存し、インターネットからアクセスできます。次のうち、機密保持に最も役立つものはどれですか?
- A. EDR
- B. IDS
- C. NAC
- D. DLP
正解:D
解説:
Explanation
The most useful tool in maintaining confidentiality for a new application stack that will store sensitive information and be accessible from the internet is data loss prevention (DLP). DLP is a type of security solution that monitors and controls the flow of data in and out of a system or network. It can detect and prevent unauthorized access, transmission, or leakage of sensitive data, such as personal information, financial records, or intellectual property. DLP can also enforce encryption, masking, or deletion of sensitive data to protect its confidentiality. Reference: CompTIA Cloud+ Certification Exam Objectives, Domain 2.0 Security, Objective 2.5 Given a scenario, apply data security techniques in the cloud.
質問 # 34
システム管理者は、設定されたスケジュールでサーバーに対してタスクを実行するためのプレイブックを作成しています。
システム管理者が Playbook 内で使用する必要がある認証手法は次のうちどれですか?
- A. 管理者の SSO 資格情報を使用します。
- B. サーバー上にサービス アカウントを作成します。
- C. サーバーのルート認証情報を使用します。
- D. Playbook 内にパスワードをハードコーディングします。
正解:A
質問 # 35
新しいプライベート クラウドの展開でのパフォーマンスが期待を満たしていません。エンジニアは、仮想化ホストの準備/待機時間が長いと判断しました。現在、次の構成とメトリックを持つ VM がホストに存在します。
次のトラブルシューティングの選択肢のうち、予想されるベースラインを満たすために準備/待機時間を長くするために使用される可能性が最も高いのはどれですか?
- A. VM2 のメモリ サイズを増やします。
- B. VM1 の CPU 数を減らします。
- C. VM4 の CPU 数を増やします。
- D. VM3 のメモリ サイズを減らします。
正解:A
質問 # 36
クラウド管理者は、パブリック クラウドで組織のインフラストラクチャを管理しています。現在、すべてのサーバーは、すべてのトラフィックが通過する必要がある単一のファイアウォールを備えた単一の仮想ネットワーク内に配置されています。セキュリティ要件により、本番、QA、および開発サーバーは相互に直接通信できないようにする必要があります。セキュリティ要件に準拠するために管理者が実行する必要があるのは、次のうちどれですか?
- A. 本番、QA、および開発サーバー用に個別の仮想ネットワークを作成します。
サーバーを適切な仮想ネットワークに移動します。
ネットワークをピアリングします。 - B. 運用、QA、および開発サーバー用に個別のネットワーク セキュリティ グループを作成します。
適切な運用、QA、および開発サーバーにネットワーク セキュリティ グループを適用します。
ネットワークをピアリングします。 - C. 本番、QA、および開発サーバー用に個別の仮想ネットワークを作成します。
サーバーを適切な仮想ネットワークに移動します。
ファイアウォールを除くすべてのトラフィックを拒否する各仮想ネットワークに、ネットワーク セキュリティ グループを適用します。 - D. 運用、QA、および開発サーバー用に個別のネットワーク セキュリティ グループを作成します。
ネットワークをピアリングします。
ネットワークごとにファイアウォールへの静的ルートを作成します。
正解:C
解説:
These are the actions that the administrator should perform to comply with the security requirement of isolating production, QA, and development servers from each other in a public cloud environment:
Create separate virtual networks for production, QA, and development servers: A virtual network is a logical isolation of network resources or systems within a cloud environment. Creating separate virtual networks for different types of servers can help to segregate them from each other and prevent direct communication or interference.
Move the servers to the appropriate virtual network: Moving the servers to the appropriate virtual network can help to assign them to their respective roles and functions, as well as ensure that they follow the network policies and rules of their virtual network.
Apply a network security group to each virtual network that denies all traffic except for the firewall: A network security group is a set of rules or policies that control and filter inbound and outbound network traffic for a virtual network or system. Applying a network security group to each virtual network that denies all traffic except for the firewall can help to enforce security and compliance by blocking any unauthorized or unwanted traffic between different types of servers, while allowing only necessary traffic through the firewall.
質問 # 37
次のクラウド サービスのうち、完全に管理されているのはどれですか?
- A. サーバーレス コンピューティング
- B. IoT
- C. クラウド内の GPU
- D. IaaS
- E. SaaS
正解:E
解説:
SaaS (Software as a Service) is a cloud service model that provides fully managed applications to the end users. The users do not have to worry about installing, updating, or maintaining the software, as the cloud provider handles all these tasks. Examples of SaaS are Gmail, Office 365, Salesforce, etc.
質問 # 38
管理者がアーキテクトに昇格した場合、いずれかのサーバーにアクセスしようとすると、アーキテクトは「認証失敗: アカウントは許可されていません」というエラーを受け取ります。アクセスが拒否された理由を説明しているのは次のうちどれですか?
- A. 任意の ACL が有効です
- B. フェデレーション情報が完全に入力されていません
- C. ロールベースの ACL が有効になっています
- D. 多要素認証が部分的に機能しています
正解:A
質問 # 39
システム管理者は、GPU で高速化された VDI ソリューションを展開しています。複数のユーザーからの要求に応じて、管理者は古いバージョンの OS を仮想ワークステーションにインストールします。
VM の大部分は、OS の最新の LTS バージョンを実行します。
次のタイプのドライバーのうち、すべての仮想ワークステーションとの互換性を確保する可能性が最も高いのはどれですか?
- A. レガシ ドライバー
- B. ベンダーの Web サイトから入手した最新のドライバー
- C. OS リポジトリからのドライバー
- D. 代替コミュニティ ドライバー
正解:B
質問 # 40
ある会社は、セキュリティ会社を雇って、その環境の脆弱性評価を実行しました。最初のフェーズでは、エンジニアはホストによって公開されているネットワーク サービスをスキャンする必要があります。LEAST権限でこれを達成するのに役立つのは、次のうちどれですか?
- A. アプリケーションスキャン
- B. エージェントベースのスキャン
- C. 認証済みスキャン
- D. ネットワークベースのスキャン
正解:D
解説:
A network-based scan is a type of vulnerability assessment that scans the network services exposed by the hosts without requiring any credentials or agents. This type of scan will help achieve the objective of scanning the network services with the least privileges, as it does not need any access to the hosts or their internal configurations. A network-based scan can identify open ports, running services, and potential vulnerabilities on the hosts. Reference: CompTIA Cloud+ Certification Exam Objectives, Domain 2.0 Security, Objective 2.4 Given a scenario, implement security automation and orchestration in a cloud environment.
質問 # 41
管理者は、地理的に分散したコミュニティにサービスを提供する Web ファームを構築しました。セッション状態の永続性が有効になっています。LAN の転送速度を最適化するために実装できるのは、次のうちどれですか?
- A. コンテンツ切り替え
- B. ゾーニング
- C. マルチパス
- D. HTTP 圧縮
正解:C
質問 # 42
いくつかの SaaS アプリケーションがユーザーによって使用されていることが発見され、InfoSec チームはすべてのクライアント マシンの構成ファイルを更新する必要があります。
Web プロキシ経由でユーザーをリダイレクトするために使用されるファイルの種類は次のうちどれですか?
- A. .tmp
- B. .log
- C. .dat
- D. .pac
正解:D
質問 # 43
......
最新CV0-003日本語試験問題にはリアルなCV0-003日本語問題集があります:https://www.passtest.jp/CompTIA/CV0-003J-shiken.html