[2026年更新]無料200-201日本語試験問題集は試験を合格するには超簡単 [Q240-Q265]

Share

[2026年更新]無料200-201日本語試験問題集はパス試験は超簡単

200-201日本語試験問題集で200-201日本語練習テスト問題

質問 # 240
ネットワーク エンジニアは NetFlow レポートで、内部ホストが外部 DNS サーバーに多数の DNS リクエストを送信していることに気付きました。 SOC アナリストがエンドポイントをチェックしたところ、エンドポイントが感染し、ボットネットの一部になっていることが判明しました。 エンドポイントは複数の DNS リクエストを送信していますが、その IP アドレスは偽装されていました。有効な外部ソース 感染したエンドポイントはどのような攻撃に関与していますか?1?

  • A. DNS ハイジャック
  • B. DNS フラッディング
  • C. DNS 増幅
  • D. DNS トンネリング

正解:C


質問 # 241
展示を参照してください。

アナリストはCiscoASAデバイスからこのアラートを受信し、多数のアクティビティログが生成されました。このタイプの証拠はどのように分類されるべきですか?

  • A. 状況
  • B. 最高
  • C. 間接
  • D. 裏付け

正解:D

解説:
Indirect=circumstantail so there is no posibility to match A or B (only one answer is needed in this question).
For suer it's not a BEST evidence - this FW data inform only of DROPPED traffic. If smth happend inside network, presented evidence could be used to support other evidences or make our narreation stronger but alone it's mean nothing.


質問 # 242
ユーザーtom0411976943とdan1968754032の間の公開鍵の信頼できる交換を支援するためにエンジニアは何を使用する必要がありますか?

  • A. 中央鍵管理サーバー
  • B. 信頼の網
  • C. 信頼できる認証局
  • D. 登録局データ

正解:C

解説:
In the context of public key infrastructure (PKI), a trusted certificate authority (CA) is responsible for issuing digital certificates that verify a digital entity's identity on the internet. The CA acts as a trusted third party between the user (in this case, tom0411976943) and the recipient (dan1968754032), ensuring that the public keys are indeed who they claim to be. The CA verifies the identity of the users and then issues a certificate containing the public key and a variety of other identification information. The trusted CA can then vouch for the authenticity of each user to the other.
Understanding Cisco Cybersecurity Operations Fundamentals (CBROPS)


質問 # 243
暗号化がセキュリティ監視にとって難しいのはなぜですか?

  • A. 暗号化により、分析および保存するパケット サイズが大きくなります。
  • B. 暗号化は、回避および難読化の手段として脅威アクターによって使用されます。
  • C. 暗号化分析は、攻撃者が VPN トンネルを監視するために使用します。
  • D. 暗号化により、CPU による追加の処理要件が導入されます。

正解:B

解説:
Encryption is challenging to security monitoring because it can be used by threat actors as a method of evasion and obfuscation. Encryption can prevent security devices from inspecting the content or payload of the network traffic, making it difficult to detect malicious activity or signatures. Encryption can also hide the source and destination of the traffic, making it hard to trace the origin or destination of the attack. References:
https://learningnetworkstore.cisco.com/on-demand-e-learning/understanding-cisco-cybersecurity-operations- fundamentals-cbrops-v1-0/CSCU-LP-CBROPS-V1-028093.html (Module 4, Lesson 4.1.1)


質問 # 244
スライディング ウィンドウの異常検出とは何ですか?

  • A. 最も低い特権/許可レベルをソフトウェアに適用します
  • B. 所有するアプリケーションのリクエストの応答時間を定義します。
  • C. 通常の動作に合わない珍しいパターンを特定します。
  • D. 運用および管理プロセスの変化を検出します。

正解:C


質問 # 245
認証局はセキュリティにどのように影響しますか?

  • A. サーバーと通信するときにクライアントIDを検証します。
  • B. SSL証明書を要求するときにドメインIDを認証します。
  • C. SSL証明書を要求するときにクライアントIDを認証します。
  • D. SSL証明書のドメインIDを検証します。

正解:D

解説:
Explanation
A certificate authority is a computer or entity that creates and issues digital certificates. CA do not
"authenticate" it validates. "D" is wrong because The digital certificate validate a user. CA --> DC --> user, server or whatever.


質問 # 246
攻撃者が 4 桁の数字のパスワードのみを使用し、ユーザー名を使用しない認証システムを使用してネットワークを侵害しようとする場合、どのような攻撃方法が使用されますか?

  • A. リプレイ
  • B. クロスサイト スクリプティング
  • C. 辞書
  • D. SQL インジェクション

正解:C

解説:
A dictionary attack is a method used to break into a password-protected computer or server by systematically entering every word in a dictionary as a password. In the context of an authentication system that uses only
4-digit numeric passwords, a dictionary attack would involve trying all possible combinations of 4-digit numbers until the correct one is found.
References: Understanding Cisco Cybersecurity Operations Fundamentals (CBROPS) course materials discuss various attack methods, including dictionary attacks, and how they can be used to compromise networks


質問 # 247
従業員に、仕事を遂行するために必要なリソースのみへのアクセスを許可する慣行は何ですか?

  • A. 職務の分離
  • B. 最小権限の原則
  • C. 組織の分離
  • D. 原理を知る必要がある

正解:B


質問 # 248
展示を参照してください。

この要求は、データベースによって駆動される Web アプリケーション サーバーに送信されました。どのタイプの Web サーバー攻撃が表されますか?

  • A. ヒープメモリの破損
  • B. ブラインド SQL インジェクション
  • C. コマンドインジェクション
  • D. パラメータ操作

正解:B


質問 # 249
セキュリティの専門家が、CDFS 形式で保存された ISO ファイルである証拠のコピーに取り組んでいます。このファイルはどのタイプの証拠ですか?

  • A. Windows で作成した CD データのコピー
  • B. Mac ベースのシステムで作成された CD データのコピー
  • C. Android ベースのシステムで作成された CD データのコピー
  • D. Linux システムで作成された CD データのコピー

正解:A

解説:
The CDFS (Compact Disc File System) format is associated with the ISO 9660 standard, which is a file system for optical disc media. It is commonly used in Windows systems for CDs. When a security expert works on an ISO file saved in CDFS format, it typically indicates that the data was prepared or copied using a Windows-based system. This is because CDFS is the file system that Windows uses to read and write CDs, and the ISO file is an image of that CD data1.
Reference:
Understanding CDFS (Compact Disc File System): A Comprehensive Guide2.
What type of evidence is this file? - VCEguide.com


質問 # 250
TapポートとSPANポートから取得したデータの違いは何ですか?

  • A. Tapは指定されたポートからの既存のトラフィックをミラーリングしますが、SPANはより詳細な分析のためにより構造化されたデータを提示します。
  • B. SPANはメディアエラーの検出を改善し、Tapはデータの可視性を低下させたトラフィックへの直接アクセスを提供します。
  • C. Tapは物理層から監視デバイスにトラフィックを送信し、SPANはスイッチから宛先へのネットワークトラフィックのコピーを提供します
  • D. SPANは、ネットワークデバイスとネットワークの間でトラフィックを変更せずに受動的に分割しますが、Tapは応答時間を変更します。

正解:A


質問 # 251
疑わしいユーザーが、組織内の侵害されたホストから接続を開きました。トラフィックはルーターを通過しており、ネットワーク管理者はこのフローを特定できました。管理者は、必要なデータを収集するために 5 タプルに従っていました。このアプローチに基づいて収集された情報はどれですか?

  • A. プロトコル
  • B. 直接パス
  • C. NAT
  • D. ユーザー名

正解:C


質問 # 252
展示を参照してください。

このパケット キャプチャから特定されるアラートはどれですか?

  • A. 中間者攻撃
  • B. ブルートフォース攻撃
  • C. ARP ポイズニング
  • D. SQL インジェクション

正解:B

解説:
The screenshot shows multiple POP requests with the command PASS, which is typically used for password entry. The rapid succession and variation of these requests suggest an attempt to guess the password, characteristic of a brute-force attack. Remember, always verify with additional data or context when possible, as packet captures can contain vast amounts of information and may require thorough analysis for accurate interpretation.


質問 # 253
NIST SP 800-61 r2には、インシデント対応プロセスのどの2つの要素が記載されていますか?(2つ選択してください。)

  • A. インシデント後の活動
  • B. 脆弱性管理
  • C. リスク評価
  • D. 検出と分析
  • E. 脆弱性スコアリング

正解:A、D

解説:
NIST SP 800-61 r2 outlines a structured incident handling lifecycle composed of four phases: Preparation, Detection and Analysis, Containment, Eradication, and Recovery, and Post-Incident Activity. Detection and Analysis involve identifying and investigating incidents, while Post-Incident Activity focuses on lessons learned and evidence retention for future reference.
References: SP 800-61 Rev. 2, Computer Security Incident Handling Guide | CSRC, Computer Security Incident Handling Guide - NIST, We Read NIST SP 800-61 so You Don't Have to.


質問 # 254
展示品を参照してください。

会社の従業員がエンドポイント デバイスから mail google.com に接続しています。Web サイトは読み込まれますが、エラーが発生します。何が起きているのでしょうか?

  • A. 証明書は信頼されたルートにありません。
  • B. DNSハイジャック攻撃
  • C. エンドポイントのローカル時刻が無効です。
  • D. 中間者攻撃

正解:D

解説:
A man-in-the-middle attack is a type of cyberattack where an attacker intercepts and alters the communication between two parties who believe they are directly communicating with each other. In this case, the attacker is impersonating mail.google.com and presenting a fake certificate to the endpoint device. The endpoint device detects that the certificate is not issued by a trusted authority and displays an error message. The attacker can then monitor or modify the traffic between the endpoint device and mail.google.com. References:
* Understanding Cisco Cybersecurity Operations Fundamentals (CBROPS) - Cisco, Module 3: Host- Based Analysis, Lesson 3.2: Endpoint Security Technologies
* 200-201 CBROPS - Cisco, Exam Topics, 3.0 Host-Based Analysis, 3.2 Compare and contrast the functionality of these endpoint security technologies
* Cisco Certified CyberOps Associate Overview - Cisco Learning Network, Videos, 3.2 Compare and contrast the functionality of these endpoint security technologies


質問 # 255
展示品を参照してください。

エンジニアは侵入を調査し、pcap ファイルを分析しています。エンジニアが考慮すべき 2 つの重要な要素はどれですか? (2つお選びください。)

  • A. 長さ 120 とウィンドウ サイズ (64) が同じ
  • B. 可変の「情報」フィールドと不変のシーケンス番号
  • C. 宛先ポート 80 を持つ同じ送信元 IP アドレス
  • D. 変動がほとんどない大量の oi SYN パケット
  • E. 複数の送信元IPアドレスから確認応答されたSYNパケット

正解:D、E

解説:
* The exhibit shows a pcap file capturing multiple TCP SYN packets directed at the same destination IP address.
* High volume of SYN packets with very little variance in time: This pattern is indicative of a SYN flood attack, a type of Denial of Service(DoS) attack where numerous SYN requests are sent to overwhelm the target system.
* SYN packets acknowledged from several source IP addresses: This can be indicative of a Distributed Denial of Service (DDoS) attack where multiple compromised hosts (botnet) are used to generate traffic.
* These characteristics suggest that the network is under a SYN flood or DDoS attack, aiming to exhaust the target's resources and disrupt service availability.
References
* Understanding SYN Flood Attacks
* Analysis of DDoS Attack Patterns
* Wireshark Analysis Techniques for Intrusion Detection


質問 # 256

図を参照してください。エンジニアは、ログのグループ化されたセットから侵害されたホストを分離するために、5タプルアプローチを使用する必要があります。
エンジニアはどのデータを使用する必要がありますか?

  • A. b4:2a0ef227 83
  • B. 0
  • C. 7c:5c:f8:9f:d1:fc
  • D. 1

正解:D


質問 # 257
エンジニアは、入力および出力の境界トラフィックを復号化し、ネットワークセキュリティデバイスが悪意のあるアウトバウンド通信を検出できるようにすることで、コマンドアンドコントロール通信を検出するようにネットワークシステムを構成する必要があります。タスクを実行するためにどのテクノロジーを使用する必要がありますか?

  • A. 署名
  • B. 静的IPアドレス
  • C. デジタル証明書
  • D. 暗号スイート

正解:C


質問 # 258
攻撃ベクトルと攻撃対象領域の違いは何ですか?

  • A. 攻撃ベクトルはセキュリティ上の弱点をターゲットとし、攻撃対象領域は攻撃者がそれらの弱点を突破して侵入を試みる場所です。
  • B. 攻撃対象領域は、利用可能な既存の脆弱性の数を定義し、攻撃ベクトルは、利用可能なエクスプロイトの難易度を決定します。
  • C. 攻撃対象領域は、脅威の攻撃者が使用する戦術、手法、および手順であり、攻撃ベクトルはシステム ハードウェアです。
  • D. 攻撃ベクトルは構成上の欠陥であり、攻撃対象領域はそのような欠陥を持つシステムまたはソフトウェアです。

正解:C


質問 # 259
エンジニアは、重要なサーバーのパフォーマンスの低下に影響を与えるアラートを受け取りました。分析の結果、CPUとメモリの負荷が高いことがわかりました。このリソース使用量を調査するためにエンジニアが取るべき次のステップは何ですか?

  • A. 「ps-u」を実行して、サーバーに高い負荷をかけた追加のプロセスを誰が実行したかを調べます。
  • B. 「ps-d」を実行して高負荷プロセスの優先度を下げ、リソースの枯渇を回避します。
  • C. 「ps-m」を実行してデーモンの既存の状態をキャプチャし、必要なプロセスをマップしてギャップを見つけます。
  • D. 「ps-ef」を実行して、どのプロセスが大量のリソースを使用しているかを理解します。

正解:D

解説:
The "ps" command is used to display information about the processes running on a system. The "-ef" option shows the full format listing, which includes the process ID, the user, the CPU and memory usage, the command name, and other details. This can help the engineer identify which processes are consuming the most resources and causing the degraded performance of the server. The other options are either invalid or irrelevant, as they do not provide the necessary information or perform the required action. References := Cisco Cybersecurity


質問 # 260
展示を参照してください。

左から要素名を右の PCAP ファイルの正しい部分にドラッグ アンド ドロップします。

正解:

解説:


質問 # 261
攻撃の影響を受けるすべてのホストの特定を含むインシデント対応ステップはどれですか?

  • A. 事後活動
  • B. 封じ込め、根絶、回復
  • C. 検出と分析
  • D. 準備

正解:B

解説:
Explanation
3.3.3 Identifying the Attacking Hosts During incident handling, system owners and others sometimes want to or need to identify the attacking host or hosts. Although this information can be important, incident handlers should generally stay focused on containment, eradication, and recovery.
https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf The response phase, or containment, of incident response, is the point at which the incident response team begins interacting with affected systems and attempts to keep further damage from occurring as a result of the incident.


質問 # 262
さまざまな事業部門間のインシデント対応の調整、損害の最小化、規制当局への報告を担当する NIST IR カテゴリーの利害関係者は?

  • A. CSIRT
  • B. PSIRT
  • C. 広報
  • D. 管理

正解:D


質問 # 263
展示を参照してください。

「サブディセクタに TCP ストリームの再構築を許可」機能を有効にすると、どのような結果が予想されますか?

  • A. TCP ストリームを無効にする
  • B. TCP の断片化を解除
  • C. TCP サブディセクタを挿入
  • D. パケット キャプチャからファイルを抽出します

正解:B


質問 # 264
左の要素を右のインシデント処理の正しい順序にドラッグ アンド ドロップします。

正解:

解説:

Explanation:
A close-up of several blue rectangular boxes Description automatically generated


質問 # 265
......

200-201日本語試験問題集で200-201日本語練習テスト問題:https://www.goshiken.com/Cisco/200-201J-mondaishu.html