
あなたを合格させる試験には100%確認済み1D0-671試験問題
1D0-671問題集PDFで1D0-671リアル試験問題解答
質問 # 32
Which term is used to describe the activity of a hacker who enters a computer network and begins mapping the contents of the system?
- A. System snooping
- B. Trojan
- C. Spoofing
- D. Virus planting
正解:A
質問 # 33
Which of the following can help reduce the likelihood of a successful dictionary attack?
- A. A security policy
- B. The use of Microsoft Active Directory
- C. An IPSEC-based VPN
- D. A strong password policy
正解:D
質問 # 34
You purchased a network scanner six months ago. In spite of regularly conducting scans using this software, you have noticed that attackers have been able to compromise your servers over the last month.
Which of the following is the most likely explanation for this problem?
- A. The network scanner is no substitute for scans conducted by an individual.
- B. The network scanner needs an update.
- C. The network scanner needs to be replaced.
- D. The network scanner has a trojan.
正解:B
質問 # 35
How do activity logs help to implement and maintain a security plan?
- A. Activity logs remind users to log on with strong passwords, because the logs can be analyzed to see if users are complying with policy.
- B. Activity logs allow you to determine if and how an unauthorized activity occurred.
- C. Activity logs provide advice on firewall installation, because they enable network baseline creation.
- D. Activity logs dissuade would-be hackers from breaching your security.
正解:B
質問 # 36
You are creating an information security policy for your company.
Which of the following activities will help you focus on creating policies for the most important resources?
- A. Implementing non-repudiation
- B. Classifying systems
- C. Auditing the firewall
- D. Logging users
正解:B
質問 # 37
Consider the following image of a packet capture:
Which of the following best describes the protocol used, along with its primary benefit?
- A. It is an active FTP session, which is supported by all FTP clients.
- B. It is an active FTP session, which is necessary in order to support IPv6.
- C. It is an extended passive FTP session, which is necessary to support IPv6.
- D. It is a passive FTP session, which is easier for firewalls to process.
正解:D
質問 # 38
What is the most common attack method against TCP?
- A. Trojan
- B. Illicit server
- C. SYN flood attack
- D. IP address spoofing
正解:C
質問 # 39
You are using a PKI solution that is based on Secure Sockets Layer (SSL).
Which of the following describes the function of the asymmetric-key-encryption algorithm used?
- A. It encrypts the symmetric key.
- B. It encrypts all of the data.
- C. It encrypts the X.509 key.
- D. It encrypts the hash code used for data integrity.
正解:A
質問 # 40
Consider the following diagram:
Which of the following best describes the protocol activity shown in the diagram, along with the most likely potential threat that accompanies this protocol?
- A. The TCP three-way handshake, with the threat of a man-in-the-middle attack
- B. The ICMP Time Exceeded message, with the threat of a denial-of-service attack
- C. The SIP three-way handshake, with the threat of a buffer overflow
- D. The DNS name query, with the threat of cache poisoning
正解:A
質問 # 41
The best way to thwart a dictionary attack is by enforcing a:
- A. firewall configuration policy.
- B. proxy server policy.
- C. restricted access policy.
- D. strong password policy.
正解:D
質問 # 42
Which ICMP message type is sent whenever the destination cannot handle the amount of traffic being received?
- A. Echo Reply
- B. Redirect Message
- C. Source Quench
- D. Source Quench
正解:D
質問 # 43
Which of the following is the primary weakness of symmetric-key encryption?
- A. Symmetric-key encryption operates slower than asymmetric-key encryption.
- B. Symmetric-key encryption does not provide the service of data confidentiality.
- C. Keys created using symmetric-key encryption are difficult to distribute securely.
- D. Data encrypted using symmetric-key encryption is subject to corruption during transport.
正解:C
質問 # 44
Your organization has made a particularly unpopular policy decision. Your supervisor fears that a series of attacks may occur as a result. You have been assigned to increase automated auditing on a server.
When fulfilling this request, which of the following resources should you audit the most aggressively?
- A. Intrusion detection systems, especially those placed on sensitive networks
- B. Log files on firewall systems
- C. Firewall settings for desktop systems
- D. Authentication databases, including directory servers
正解:D
質問 # 45
Which of the following errors most commonly occurs when responding to a security breach?
- A. Taking too much time to document the attack
- B. Making snap judgments based on emotions, as opposed to company policy
- C. Shutting down network access using the firewall, rather than the network router
- D. Adhering to the company policy rather than determining actions based on the IT manager's input
正解:B
質問 # 46
A Web site that contains malicious content designed to harm your computer is known as:
- A. an ad-hoc Web site.
- B. a poisoned Web site.
- C. a wiki.
- D. a greynet Web site.
正解:B
質問 # 47
Danielle was informed by her network administrator that an audit may be conducted during the night to determine the hosts that exist on the network and document any open ports. The next day, Danielle was unable to access any network services.
What may have occurred instead of the anticipated audit?
- A. A brute-force attack
- B. A scanning attack
- C. A zero-day attack
- D. A social engineering attack
正解:B
質問 # 48
Which of the following activities is the most effective at keeping the actions of nae end users from putting the company's physical and logical resources at risk?
- A. Conducting a training session at the time of hire
- B. Configuring network intrusion-detection software to monitor end user activity
- C. Assembling a team of security professionals to monitor the network
- D. Reconfiguring the network firewall
正解:A
質問 # 49
Which of the following is a security principle that allows you to protect your network resources?
- A. Avoid being suspicious of legitimate activity.
- B. Provide training for end users and IT workers.
- C. Deploy security enforcement only in the largest departments.
- D. Realize that some high-end systems should stand alone.
正解:B
質問 # 50
Which task should you perform first when considering where to place equipment?
- A. Consult with management to determine specific needs.
- B. Conduct a needs assessment audit.
- C. Secure funding.
- D. Conduct research to determine the appropriate products for your organization.
正解:B
質問 # 51
Which of the following applications can help determine whether a denial-ofservice attack is occurring against a network host?
- A. The netstat command and a packet sniffer
- B. The ping command and User Manager
- C. The ps command and a network scanner
- D. The iptables command and Windows desktop firewall
正解:A
質問 # 52
Which of the following is a primary auditing activity?
- A. Encrypting data files
- B. Changing login accounts
- C. Checking log files
- D. Configuring the firewall
正解:C
質問 # 53
A security breach has occurred involving the company e-commerce server. Customer credit card data has been released to unauthorized third parties.
Which of the following lists the appropriate parties to inform?
- A. Shareholders, law enforcement agencies and company employees
- B. Affected customers, credit card companies and law enforcement agencies
- C. The Internet Service Provider, ICANN and company shareholders
- D. External security consultants, company board members and affected customers
正解:B
質問 # 54
Which of the following accurately describes an aspect of an access control list (ACL)?
- A. The ACL defines the database roles that users have on a database server.
- B. The ACL defines users that have access to a resource on a database server.
- C. The ACL lists entities that can access a database server, but does not provide access levels.
- D. The ACL cannot determine whether a user has access to an object, but can define exactly what the user can do with that object.
正解:A
質問 # 55
Which of the following commands would you use to create a simple personal firewall that blocks all incoming ICMP traffic?
- A. iptables -A INPUT -p icmp -s 10.100.100.0/24 -d 0/0 -j DROP
- B. iptables -A INPUT -p icmp -s 10.100.100.0/255.255.255 -d 0/0 -j KILL
- C. iptables - INPUT -p icmp -s 0/0 -d 0/0 -j KILL
- D. iptables -A INPUT -p icmp -s 0/0 -d 0/0 -j DROP
正解:D
質問 # 56
Which algorithm can use a 128-bit key, and has been adopted as a standard by various governments and corporations?
- A. RC2
- B. Advanced Encryption Standard (AES)
- C. International Data Encryption Algorithm (IDEA)
- D. MARS
正解:B
質問 # 57
......
1D0-671問題集100合保証には最新のサンプル:https://www.goshiken.com/CIW/1D0-671-mondaishu.html
準備1D0-671問題解答無料更新には100%試験合格保証 [2024年更新]:https://drive.google.com/open?id=1jUhyLmiDCOB6Le_FLSygISb4e1y-irRv