[2024年07月31日] 最新版を今すぐ試そうCS0-003日本語練習テスト問題解答 [Q66-Q91]

Share

[2024年07月31日] 最新版を今すぐ試そうCS0-003日本語練習テスト問題解答

CS0-003日本語問題集と試験テストエンジン

質問 # 66
アナリストは、次のエンドポイント ログ エントリを確認します。

次のうちどれが発生しましたか?

  • A. 権限昇格
  • B. レジストリの変更
  • C. コンピュータの名前を変更します
  • D. 新しいアカウントが導入されました

正解:D

解説:
The endpoint log entry shows that a new account named "admin" has been created on a Windows system with a local group membership of "Administrators". This indicates that a new account has been introduced on the system with administrative privileges. This could be a sign of malicious activity, such as privilege escalation or backdoor creation, by an attacker who has compromised the system.


質問 # 67
高度に悪用された 2 つの脆弱性に対するパッチが、同じ金曜日の午後にリリースされました。システムと脆弱性に関する情報を以下の表に示します。

セキュリティ アナリストは修復のために次のどれを優先する必要がありますか?

  • A. 人員配置
  • B. ブリーズ
  • C. ロジャー
  • D. ブレイディ

正解:D

解説:
Brady should be prioritized for remediation, as it has the highest risk score and the highest number of affected users. The risk score is calculated by multiplying the CVSS score by the exposure factor, which is the percentage of systems that are vulnerable to the exploit. Brady has a risk score of 9 x 0.8 = 7.2, which is higher than any other system. Brady also has 500 affected users, which is more than any other system. Therefore, patching brady would reduce the most risk and impact for the organization. The other systems have lower risk scores and lower numbers of affected users, so they can be remediated later.


質問 # 68
サイバーセキュリティ チームのリーダーは、毎週のエグゼクティブ ブリーフで提示する指標を作成しています。経営陣は、ネットワークに侵入するマルウェアの拡散を阻止するのにどれくらいの時間がかかるかを知りたいと考えています。
チームリーダーがブリーフに含めるべき指標は次のうちどれですか?

  • A. 平均故障間隔
  • B. 平均修復時間
  • C. 平均検出時間
  • D. 平均収容時間

正解:D


質問 # 69
教訓を見直した後、更新する必要があるのは次のうちどれですか?

  • A. 災害復旧計画
  • B. 事業継続計画
  • C. 机上演習
  • D. インシデント対応計画

正解:D

解説:
A lessons-learned review is a process of evaluating the effectiveness and efficiency of the incident response plan after an incident or an exercise. The purpose of the review is to identify the strengths and weaknesses of the incident response plan, and to update it accordingly to improve the future performance and resilience of the organization. Therefore, the incident response plan should be updated after a lessons-learned review.
References: The answer was based on the NCSC CAF guidance from the National Cyber Security Centre, which states: "You should use post-incident and post-exercise reviews to actively reduce the risks associated with the same, or similar, incidents happening in future. Lessons learned can inform any aspect of your cyber security, including: System configuration Security monitoring and reporting Investigation procedures Containment/recovery strategies"


質問 # 70
境界ネットワーク内の Web サーバーのスキャン中に、ポート 3389 経由で悪用される可能性のある脆弱性が特定されました。Web サーバーは WAF によって保護されています。この脆弱性に関連する全体的なリスクの変化を最もよく表しているのは次のうちどれですか?

  • A. Web アプリケーション ファイアウォールが設置されているため、リスクは減少します。
  • B. ネットワーク ファイアウォールが使用されているため、リスクは変わりません。
  • C. RDP がファイアウォールによってブロックされるため、リスクは減少します。
  • D. ホストが外部に面しているため、リスクが増加します。

正解:C

解説:
Port 3389 is commonly used by Remote Desktop Protocol (RDP), which is a service that allows remote access to a system. A vulnerability on this port could allow an attacker to compromise the web server or use it as a pivot point to access other systems. However, if the firewall blocks this port, the risk of exploitation is reduced.


質問 # 71
最高情報セキュリティ責任者 (CISO) は、企業の業種をターゲットにすることが知られている特定の攻撃者がネットワークに侵入し、ネットワーク内に長期間留まる可能性があることを懸念しています。
CISO の目標を達成するには、次のどの手法を実行する必要がありますか?

  • A. 脆弱性スキャン
  • B. 敵対的なエミュレーション
  • C. バグ報奨金
  • D. パッシブディスカバリ

正解:B

解説:
The correct answer is B. Adversary emulation.
Adversary emulation is a technique that involves mimicking the tactics, techniques, and procedures (TTPs) of a specific threat actor or group to test the effectiveness of the security controls and incident response capabilities of an organization1. Adversary emulation can help identify and address the gaps and weaknesses in the security posture of an organization, as well as improve the readiness and skills of the security team.
Adversary emulation can also help measure the dwell time, which is the duration that a threat actor remains undetected inside the network2.
The other options are not the best techniques to meet the CISO's goals. Vulnerability scanning (A) is a technique that involves scanning the network and systems for known vulnerabilities, but it does not simulate a real attack or test the incident response capabilities. Passive discovery is a technique that involves collecting information about the network and systems without sending any packets or probes, but it does not identify or exploit any vulnerabilities or test the security controls. Bug bounty (D) is a program that involves rewarding external researchers or hackers for finding and reporting vulnerabilities in an organization's systems or applications, but it does not focus on a specific threat actor or group.


質問 # 72
セキュリティ アナリストは Web サーバーのログを確認しており、攻撃者が SQL インジェクションの脆弱性を悪用しようとしていることに気付きました。アナリストが攻撃を分析し、今後の攻撃を防ぐために使用できるツールは次のうちどれですか?

  • A. Web アプリケーション ファイアウォール
  • B. ネットワーク侵入検知システム
  • C. Web プロキシ
  • D. 脆弱性スキャナー

正解:A


質問 # 73
アナリストのチームは、さまざまなソースからの情報を相関させる新しい内部システムを開発しています。その情報を分析し、企業ポリシーに従って通知をトリガーします。導入されたテクノロジーは次のどれですか?

  • A. IPS
  • B. 急上昇
  • C. SIEM
  • D. 証明書

正解:C

解説:
SIEM (Security Information and Event Management) technology aggregates and analyzes activity from many different resources across your IT infrastructure. The description of correlating information from various sources and triggering notifications aligns with the capabilities of a SIEM system.


質問 # 74
組織は、次の表にリストされているいくつかのインシデントを追跡しています。
組織のMTTDは次のうちどれですか?

  • A. 0
  • B. 1
  • C. 2
  • D. 3

正解:D

解説:
The MTTD (Mean Time To Detect) is calculated by averaging the time elapsed in detecting incidents. From the given data: (180+150+170+140)/4 = 160 minutes. This is the correct answer according to the CompTIA CySA+ CS0-003 Certification Study Guide1, Chapter 4, page 161. References: CompTIA CySA+ Study Guide: Exam CS0-003, 3rd Edition, Chapter 4, page 153; CompTIA CySA+ CS0-003 Certification Study Guide, Chapter 4, page 161.


質問 # 75
サイバーセキュリティ アナリストは SIEM ログを調査し、内部ホストからブロックリストに登録された外部サーバーへの一貫したリクエストを観察しています。アクティビティを最もよく説明しているものは次のうちどれですか?
起こっていますか?

  • A. データの引き出し
  • B. スキャン中
  • C. ビーコン
  • D. 不正なデバイス

正解:C

解説:
Beaconing is the best term to describe the activity that is taking place, as it refers to the periodic communication between an infected host and a blocklisted external server. Beaconing is a common technique used by malware to establish a connection with a command-and-control (C2) server, which can provide instructions, updates, or exfiltration capabilities to the malware. Beaconing can vary in frequency, duration, and payload, depending on the type and sophistication of the malware. The other terms are not as accurate as beaconing, as they describe different aspects of malicious activity. Data exfiltration is the unauthorized transfer of data from a compromised system to an external destination, such as a C2 server or a cloud storage service. Data exfiltration can be a goal or a consequence of malware infection, but it does not necessarily involve blocklisted servers or consistent requests. Rogue device is a device that is connected to a network without authorization or proper security controls. Rogue devices can pose a security risk, as they can introduce malware, bypass firewalls, or access sensitive data. However, rogue devices are not necessarily infected with malware or communicating with blocklisted servers. Scanning is the process of probing a network or a system for vulnerabilities, open ports, services, or other information. Scanning can be performed by legitimate administrators or malicious actors, depending on the intent and authorization. Scanning does not imply consistent requests or blocklisted servers, as it can target any network or system.


質問 # 76
次のセキュリティ運用タスクのうち、自動化に最適なものはどれですか?

  • A. 不審なファイルの分析:
    フォルダー内で疑わしいグラフィックを探します。

    見つかったグラフィックスのカテゴリに基づいて、元のフォルダーにサブフォルダーを作成します。

    疑わしいグラフィックを適切なサブフォルダーに移動します
  • B. ファイアウォール IoC ブロック アクション:
    最近公開されたゼロデイ エクスプロイトからの IoC のファイアウォール ログを調べます。 ログで見つかった動作をブロックするためにファイアウォールで緩和策を講じます。 ブロック ルールによって引き起こされた誤検知を追跡します。
  • C. セキュリティ アプリケーション ユーザー エラー:
    セキュリティ アプリケーションでユーザーが問題を抱えている兆候をエラー ログで検索します。 ユーザーの電話番号を調べます。 アプリケーションの使用に関する質問がある場合は、ユーザーに電話してください。
  • D. 電子メールヘッダー分析:
    電子メールのヘッダーでフィッシング信頼度指標が 5 以上であるかどうかを確認します。 送信者のドメインをブロック リストに追加します。 電子メールを隔離に移動します。

正解:D

解説:
Email header analysis is one of the security operations tasks that are ideal for automation. Email header analysis involves checking the email header for various indicators of phishing or spamming attempts, such as sender address spoofing, mismatched domains, suspicious subject lines, or phishing confidence metrics. Email header analysis can be automated using tools or scripts that can parse and analyze email headers and take appropriate actions based on predefined rules or thresholds


質問 # 77
セキュリティ管理者は、テストの目的で、実稼働環境からテスト環境に Pll データ レコードをインポートする必要があります。データの機密性を最もよく保護するのは次のうちどれですか?

  • A. ハッシュ化
  • B. 透かし
  • C. データマスキング
  • D. エンコーディング

正解:C

解説:
Data masking is a technique that replaces sensitive data with fictitious or anonymized data, while preserving the original format and structure of the data. This way, the data can be used for testing purposes without revealing the actual Pll information. Data masking is one of the best practices for data analysis of confidential data1. References: CompTIA CySA+ CS0-003 Certification Study Guide, page 343; Best Practices for Data Analysis of Confidential Data


質問 # 78
組織は、次の表にリストされているいくつかのインシデントを追跡しています。

  • A. 0
  • B. 1
  • C. 2
  • D. 3

正解:D

解説:
The MTTD (Mean Time To Detect) is calculated by averaging the time elapsed in detecting incidents. From the given data: (180+150+170+140)/4 = 160 minutes. This is the correct answer according to the CompTIA CySA+ CS0-003 Certification Study Guide1, Chapter 4, page 161. Reference: CompTIA CySA+ Study Guide: Exam CS0-003, 3rd Edition, Chapter 4, page 153; CompTIA CySA+ CS0-003 Certification Study Guide, Chapter 4, page 161.


質問 # 79
脆弱性アナリストはシステムの脆弱性のリストを受け取り、エクスプロイトがビジネスに与える関連する影響を評価する必要があります。現在のスプリントの制約を考慮すると、修正できるのは 3 つだけです。CVSS3.1 の基本スコアを考慮した場合、最も影響が少ないリスクを表すのは次のうちどれですか?

  • A. AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L - 基本スコア 6.5
  • B. AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:L/A:L - 基本スコア 7.2
  • C. AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:L - 基本スコア 6.0
  • D. AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H - 基本スコア 6.4

正解:C

解説:
This option represents the least impactful risk because it has the lowest base score among the four options, and it also requires high privileges, user interaction, and high attack complexity to exploit, which reduces the likelihood of a successful attack.


質問 # 80
セキュリティ アナリストは、修復のために脆弱性の優先順位を付ける任務を負っています。関連する企業のセキュリティ ポリシーを以下に示します。
セキュリティ ポリシー 1006: 脆弱性管理
1. 当社は、セキュリティ脆弱性の修復に優先順位を付けるために、CVSSv3.1 基本スコア メトリック (悪用可能性と影響) を使用するものとします。
2. 機密性と可用性のどちらかを選択しなければならない状況では、当社はシステムとデータの可用性よりもデータの機密性を優先するものとします。
3. 当社は、社内で利用可能なシステムへのパッチ適用よりも、公開されているシステムおよびサービスへのパッチ適用を優先します。
セキュリティ ポリシーによれば、次の脆弱性のうち、最も優先してパッチを適用する必要があるのはどれですか?

  • A.
  • B.
  • C.
  • D.

正解:B

解説:
According to the security policy, the company shall use the CVSSv3.1 Base Score Metrics to prioritize the remediation of security vulnerabilities. Option C has the highest CVSSv3.1 Base Score of 9.8, which indicates a critical severity level. The company shall also prioritize confidentiality of data over availability of systems and data, and option C has a high impact on confidentiality (C:H). Finally, the company shall prioritize patching of publicly available systems and services over patching of internally available systems, and option C affects a public-facing web server. Official References: https://www.first.org/cvss/


質問 # 81
セキュリティ アナリストが脆弱性スキャンを実行します。スキャン結果のメトリックに基づいて、アナリストはパッチを適用するホストに優先順位を付ける必要があります。アナリストはツールを実行し、次の出力を受け取ります。

メトリックに基づいて、次のホストのどれに最初にパッチを適用する必要がありますか?

  • A. ホスト04
  • B. ホスト03
  • C. ホスト02
  • D. ホスト01

正解:B

解説:
Host03 should be patched first, based on the metrics, as it has the highest risk score and the highest number of critical vulnerabilities. The risk score is calculated by multiplying the CVSS score by the exposure factor, which is the percentage of systems that are vulnerable to the exploit. Host03 has a risk score of 10 x 0.9 = 9, which is higher than any other host. Host03 also has 5 critical vulnerabilities, which are the most severe and urgent to fix, as they can allow remote code execution, privilege escalation, or data loss. The other hosts have lower risk scores and lower numbers of critical vulnerabilities, so they can be patched later.


質問 # 82
特定された脅威と脆弱性を、発生の可能性と影響とともにマッピング、追跡、軽減するのに役立つツールは次のうちどれですか?

  • A. 侵入テスト
  • B. 脆弱性評価
  • C. コンプライアンスレポート
  • D. リスクレジスタ

正解:D

解説:
A risk register is a useful tool for mapping, tracking, and mitigating identified threats and vulnerabilities with the likelihood and impact of occurrence. A risk register is a document that records the details of all the risks identified in a project or an organization, such as their sources, causes, consequences, probabilities, impacts, and mitigation strategies. A risk register can help the security team to prioritize the risks based on their severity and urgency, and to monitor and control them throughout the project or the organization's lifecycle12.
A vulnerability assessment, a penetration test, and a compliance report are all methods or outputs of identifying and evaluating the threats and vulnerabilities, but they are not tools for mapping, tracking, and mitigating them345. References: What is a Risk Register? | Smartsheet, Risk Register: Definition & Example, Vulnerability Assessment vs. Penetration Testing: What's the Difference?, What is a Penetration Test and How Does It Work?, What is a Compliance Report? | Definition, Types, and Examples


質問 # 83
次のセキュリティ運用タスクのうち、自動化に最適なものはどれですか?

  • A. 不審なファイルの分析:
    フォルダー内で疑わしいグラフィックを探します。
    見つかったグラフィックスのカテゴリに基づいて、元のフォルダーにサブフォルダーを作成します。
    疑わしいグラフィックを適切なサブフォルダーに移動します
  • B. 電子メール ヘッダー分析:
    電子メールのヘッダーでフィッシング信頼度指標が 5 以上であるかどうかを確認します。 送信者のドメインをブロック リストに追加します。 電子メールを隔離に移動します。
  • C. ファイアウォール IoC ブロック アクション:
    最近公開されたゼロデイ エクスプロイトからの IoC のファイアウォール ログを調べます。 ログで見つかった動作をブロックするためにファイアウォールで緩和策を講じます。 ブロック ルールによって引き起こされた誤検知を追跡します。
  • D. セキュリティ アプリケーション ユーザー エラー:
    セキュリティ アプリケーションでユーザーが問題を抱えている兆候をエラー ログで検索します。 ユーザーの電話番号を調べます。 アプリケーションの使用に関する質問がある場合は、ユーザーに電話してください。

正解:B

解説:
Email header analysis is one of the security operations tasks that are ideal for automation. Email header analysis involves checking the email header for various indicators of phishing or spamming attempts, such as sender address spoofing, mismatched domains, suspicious subject lines, or phishing confidence metrics. Email header analysis can be automated using tools or scripts that can parse and analyze email headers and take appropriate actions based on predefined rules or thresholds


質問 # 84
最高情報セキュリティ責任者は、企業内のシャドウ IT を排除し、削減したいと考えています。組織へのリスクを増大させる、リスクの高いクラウド アプリケーションがいくつか使用されています。リスクの軽減に役立つ解決策は次のうちどれですか?

  • A. クラウド アプリケーションへの SSO を有効にする
  • B. API ゲートウェイをデプロイする
  • C. CASB を展開し、ポリシーの適用を有効にする
  • D. 厳密なアクセスを使用して MFA を構成する

正解:C

解説:
A cloud access security broker (CASB) is a tool that can help reduce the risk of shadow IT in the enterprise by providing visibility and control over cloud applications and services. A CASB can enable policy enforcement by blocking unauthorized or risky cloud applications, enforcing data loss prevention rules, encrypting sensitive data, and detecting anomalous user behavior.


質問 # 85
セキュリティ アナリストは、USB インターフェイスを介してソフトウェアを組み込む非攻撃ベクトルに関連する、悪用された既知の脆弱性を軽減する必要があります。アナリストは次のうちどれを最初に行うべきですか?

  • A. 構成をチェックして、会社の資産で USB ポートが有効になっているかどうかを判断します。
  • B. ログを確認して、この悪用可能な脆弱性がすでに会社に影響を与えているかどうかを確認します。
  • C. 未知の暗号化されていない USB を使用するリスクについてのセキュリティ意識向上トレーニングを実施します。
  • D. USB を会社の資産に接続できないことを説明するリムーバブル メディア ポリシーを作成します。

正解:A

解説:
USB ports are a common attack vector that can be used to deliver malware, steal data, or compromise systems.
The first step to mitigate this vulnerability is to check the configurations of the company assets and disable or restrict the USB ports if possible. This will prevent unauthorized devices from being connected and reduce the attack surface. The other options are also important, but they are not the first priority in this scenario.
References:
* CompTIA CySA+ CS0-003 Certification Study Guide, page 247
* What are Attack Vectors: Definition & Vulnerabilities, section "How to secure attack vectors"
* Are there any attack vectors for a printer connected through USB in a Windows environment?, answer by user "schroeder"


質問 # 86
セキュリティ アナリストは、侵害の可能性の間に発生したイベントを調査しています。アナリストは次のログを取得します。

ログ内のイベントに基づいて、発生している可能性が最も高いのは次のうちどれですか?

  • A. 攻撃者が脆弱性スキャンを実行しています。
  • B. 敵対者がパスワード スタッフィング攻撃を実行しています。
  • C. 敵対者が権限を昇格させています。
  • D. 敵対者は最短の侵入経路を見つけようとしています。

正解:A

解説:
.
Explanation:
Based on the events in the log, the most likely occurrence is that an adversary is performing a vulnerability scan. The log shows LDAP read operations and EDR enumerating local groups, which are indicative of an adversary scanning the system to find vulnerabilities or sensitive information. The final entry shows SMB connection attempts to multiple hosts from a single host, which could be a sign of network discovery or lateral movement. Reference: CompTIA CySA+ Study Guide: Exam CS0-003, 3rd Edition, Chapter 4: Security Operations and Monitoring, page 161; Monitor logs from vulnerability scanners, Section: Reports on Nessus vulnerability data.


質問 # 87
インシデント対応チームは重要なサーバーで IoC を発​​見しました。チームはさらなる調査のために技術的証拠を分離して収集する必要があります。サーバーを分離する前に機密情報を保存するには、次のデータのうちどれを最初に収集する必要がありますか?

  • A. ハードディスク
  • B. ルーティングテーブル
  • C. 悪意のあるタイル
  • D. 静的 IP アドレス
  • E. プライマリブートパーティション

正解:A

解説:
The hard disk is the piece of data that should be collected first in order to preserve sensitive information before isolating the server. The hard disk contains all the files and data stored on the server, which may include evidence of malicious activity, such as malware installation, data exfiltration, or configuration changes. The hard disk should be collected using proper forensic techniques, such as creating an image or a copy of the disk and maintaining its integrity using hashing algorithms.


質問 # 88
ACME Commercial という会社のセキュリティ アナリストは、https://offce365password.acme.co に解決されるホスト IP へのアウトバウンド トラフィックがあることに気付きました。サイトの標準 VPN ログオン ページは次のとおりです。
www.acme.com/logon。次のうち、真実である可能性が最も高いのはどれですか?

  • A. ソーシャル エンジニアリング攻撃が進行中です
  • B. セキュリティ オペレーション センターは定期的なパスワード監査を実行しています。
  • C. 新しい VPN ゲートウェイが導入されました
  • D. 通常のパスワード変更用URLです。

正解:A

解説:
A social engineering attack is underway is the most likely explanation for the outbound traffic to a host IP that resolves to https://offce365password.acme.co, while the site's standard VPN logon page is www.acme.com/logon. A social engineering attack is a technique that exploits human psychology and behavior to manipulate people into performing actions or divulging information that benefit the attackers. A common type of social engineering attack is phishing, which involves sending fraudulent emails or other messages that appear to come from a legitimate source, such as a company or a colleague, and lure the recipients into clicking on malicious links or attachments, or entering their credentials or other sensitive information on fake websites. In this case, the attackers may have registered a domain name that looks similar to the company's domain name, but with a typo (offce365 instead of office365), and set up a fake website that mimics the company's VPN logon page. The attackers may have also sent phishing emails to the company's employees, asking them to reset their passwords or log in to their VPN accounts using the malicious link. The security analyst should investigate the source and content of the phishing emails, and alert the employees not to click on any suspicious links or enter their credentials on any untrusted websites. Official References:
https://partners.comptia.org/docs/default-source/resources/comptia-cysa-cs0-002-exam-objectives
https://www.comptia.org/certifications/cybersecurity-analyst
https://www.comptia.org/blog/the-new-comptia-cybersecurity-analyst-your-questions-answered


質問 # 89
インシデント後の教訓を学ぶステップに含めるべき重要な側面は次のうちどれですか?

  • A. 収集したすべての法的証拠を提示し、警察に引き渡します。
  • B. 内部ミスがあったかどうか、またミスを繰り返さないように誰がミスをしたかを判断します。
  • C. インシデント対応計画または手順の改善または変更を特定します。
  • D. インシデントの財務的影響について話し合い、セキュリティ管理が適切に行われているかどうかを判断します。

正解:C

解説:
An important aspect that should be included in the lessons-learned step after an incident is to identify any improvements or changes in the incident response plan or procedures. The lessons-learned step is a process that involves reviewing and evaluating the incident response activities and outcomes, as well as identifying and documenting any strengths, weaknesses, gaps, or best practices. Identifying any improvements or changes in the incident response plan or procedures can help enhance the security posture, readiness, or capability of the organization for future incidents


質問 # 90
セキュリティ アナリストは、侵害された可能性のあるマシンからの FTP セッションを含む Wireshark のパケット キャプチャを調査しています。アナリストは、表示フィルター ftp を設定します。アナリストは、226 転送完了応答を含む RETR リクエストがいくつかあることを確認できますが、パケット リスト ペインにはファイル転送自体を含むパケットが表示されません。アナリストがダウンロードしたファイルの内容全体を確認するには、次のどれを実行できますか?

  • A. [ファイル] メニューに移動し、[オブジェクトのエクスポート] オプションから [FTP] を選択します。
  • B. 表示フィルターを f cp-daca に変更し、TCP ストリームに従います。
  • C. 表示フィルターを tcg.port=20 に変更します。
  • D. 表示フィルタを f cp に変更します。積極的。細孔

正解:B

解説:
The best way to see the entire contents of the downloaded files in Wireshark is to change the display filter to ftp-data and follow the TCP streams. FTP-data is a protocol that is used to transfer files between an FTP client and server using TCP port 20. By filtering for ftp-data packets and following the TCP streams, the analyst can see the actual file data that was transferred during the FTP session


質問 # 91
......

2024年最新のGoShiken CS0-003日本語のPDFで最近更新された問題です:https://www.goshiken.com/CompTIA/CS0-003J-mondaishu.html