CAS-003日本語問題集には練習試験問題解答
CAS-003日本語はCASP Recertification実際の無料試験練習テスト
質問 169 
- A. Option A
- B. Option B
- C. Option C
- D. Option E
- E. Option D
正解: C
質問 170
XYZ社は、よりクラウドベースのビジネスツールを使用していることに気付き、パスワード管理は面倒になっています。セキュリティは会社にとって重要です。その結果、パスワードの複製と共有アカウントは受け入れられません。次の実装のうちどれが集中認証による分散型ログインに対応しており、SaaSベンダー間で幅広い互換性がありますか?
- A. SAMLをサポートするクラウドベースの認証サービスを確立します。
- B. 読み取り専用の認証を使用して新しいDiameter認証サーバーを実装します。
- C. フェデレーション用に読み取り専用のActive Directoryサーバーを企業のDMZにインストールします。
- D. 既存の社内RADIUSサーバーへの外部接続を許可します。
正解: A
解説:
There is widespread adoption of SAML standards by SaaS vendors for single sign-on identity management, in response to customer demands for fast, simple and secure employee, customer and partner access to applications in their environments.
By eliminating all passwords and instead using digital signatures for authentication and authorization of data access, SAML has become the Gold Standard for single sign-on into cloud applications. SAML-enabled SaaS applications are easier and quicker to user provision in complex enterprise environments, are more secure and help simplify identity management across large and diverse user communities.
Security Assertion Markup Language (SAML) is an XML-based, open-standard data format for exchanging authentication and authorization data between parties, in particular, between an identity provider and a service provider.
The SAML specification defines three roles: the principal (typically a user), the Identity provider (IdP), and the service provider (SP). In the use case addressed by SAML, the principal requests a service from the service provider. The service provider requests and obtains an identity assertion from the identity provider. On the basis of this assertion, the service provider can make an access control decision - in other words it can decide whether to perform some service for the connected principal.
Incorrect Answers:
B: Diameter authentication server with read-only attestation is not a solution that has wide compatibility among SaaS vendors.
C: The question states that password replication is not acceptable. A read-only Active Directory server in the corporate DMZ would involve password replication.
D: Allowing external connections to the existing corporate RADIUS server is not a secure solution. It is also not a solution that has wide compatibility among SaaS vendors.
References:
https://www.onelogin.com/company/press/press-releases/97-percent-of-saas-vendors-backing-saml-based-single-sign-on
https://en.wikipedia.org/wiki/Security_Assertion_Markup_Language
質問 171 
- A. Option A
- B. Option B
- C. Option C
- D. Option D
正解: C
解説:
Explanation
Mitigation means that a control is used to reduce the risk. In this case, the control is training.
質問 172 
- A. Option A
- B. Option B
- C. Option C
- D. Option E
- E. Option D
正解: C
解説:
質問 173
発電施設の最高情報セキュリティ責任者(CISO)は、施設で使用されている重要なインフラストラクチャで欠落しているセキュリティ更新を検出できることを懸念しています。この重要なインフラストラクチャのほとんどは、ベンダーによって維持されているICSおよびSCADAシステムで構成されています。ベンダーは、ネットワークトラフィックのプロキシがDoS状態を引き起こす可能性があることをCISOに警告しています。重要なシステムを機能させながら、CISOの懸念に対処するのに最適なのは次のうちどれですか?
- A. 最小特権の概念を使用するようにMeアクセスルールを調整する
- B. パッシブ脆弱性スキャンソリューションの実装
- C. 内部Webサイト用のデータダイオードの展開
- D. すべてのログファイルプロパティを取り込むように既存のSIEMを構成する
- E. より頻繁なウイルス対策およびマルウェア対策シグネチャの更新を追加する
正解: C
質問 174
大企業が中小企業との合併を準備しています。中小企業は非常に有益でしたが、中小企業の主なアプリケーションは社内で作成されました。合併の準備として、大企業のセキュリティ管理者は次のどのアクションを実行する必要がありますか?
- A. 統合または共存のリスクを確立するために、セキュリティ評価を実行する必要があります。
- B. ROI計算を実行して、使用する会社のアプリケーションを決定する必要があります。
- C. 社内ソフトウェアで回帰テストを実行して、ソフトウェアに関連するセキュリティリスクを特定する必要があります。
- D. 中小企業の最新の監査結果から実装された緩和策のレビューを実行する必要があります。
正解: A
解説:
With any merger regardless of the monetary benefit there is always security risks and prior to the merger the security administrator should assess the security risks to as to mitigate these.
質問 175
顧客は悪意のあるソフトウェアへのリンクを含むEメールを受信しています。これらの電子メールはスパムフィルタを破壊しています。電子メールは次のようになります。
配信先:[email protected]
受信日:10.14.120.205まで
月、2010年11月1日11:15:24 -0700(PDT)
受信日:10.231.31.193まで
月、2010年11月1日11:15:23 -0700(PDT)
リターンパス:<[email protected]>
受信:<[email protected]>の127.0.0.1から。月、2010年11月1日13:15:14 -0500(封筒から<[email protected]>)受信:smtpex.example.com(SMTP READY)によるESMTP(AIO);月、2010年11月1日13時15分14秒-0500受信:172.18.45.122から192.168.2.55まで。月、2010年11月1日13:15:14 -0500から:会社<[email protected]>に: "[email protected]" <[email protected]>日付:月、2010年11月1日13:15:11 -0500主題:新しい保険申請スレッドトピック:新しい保険申請あなたのアカウントへのフルアクセスを維持するために以下のサイトからソフトウェアをダウンロードしてインストールしてください。
www.examplesite.com
________________________________
追加情報:許可メールサーバーのIPアドレスは192.168.2.10と192.168.2.11です。
ネットワークのサブネットは192.168.2.0 / 25です。
次のうちどれがセキュリティ管理者がこのリスクを排除するために取ることができるであろう最も適切な行動方針ですか? (2を選択)
- A. 許可されていないメールサーバー上の悪意のある活動の起点を特定します。
- B. スパムフィルタでSTARTTLSを有効にします。
- C. オープンリレー機能を無効にします。
- D. 不正メールサーバーのSMTPサービスをシャットダウンします。
- E. すべての不正なメールサーバーに対してファイアウォールのポート25をブロックします。
正解: D,E
解説:
In this question, we have an unauthorized mail server using the IP: 192.168.2.55.
Blocking port 25 on the firewall for all unauthorized mail servers is a common and recommended security step. Port 25 should be open on the firewall to the IP addresses of the authorized email servers only (192.168.2.10 and 192.168.2.11). This will prevent unauthorized email servers sending email or receiving and relaying email.
Email servers use SMTP (Simple Mail Transfer Protocol) to send email to other email servers. Shutting down the SMTP service on the unauthorized mail server is effectively disabling the mail server functionality of the unauthorized server.
Incorrect Answers:
A: You shouldn't worry about identifying the origination point for the malicious activity on the unauthorized mail server. There isn't much you could do about the remote origination point even if you did identify it. You have an 'unauthorized' mail server. That is what you should be dealing with.
C: In this question, the email was received by the unauthorized email server (192.168.2.55) ready to be collected by the recipient. The email was not relayed (forwarded) to other email servers. Disabling open relay functionality will not stop the emails. You need to disable all email (SMTP) functionality of the unauthorized server, not just relaying.
E: STARTTLS enables TLS encryption on communications with the spam filter. It will do nothing to prevent the usage of the unauthorized email server.
References:
https://en.wikipedia.org/wiki/Simple_Mail_Transfer_Protocol
https://www.arclab.com/en/kb/email/how-to-read-and-analyze-the-email-header-fields-spf-dkim.html
質問 176
ファイアウォールチームのマネージャーは、ファイアウォールの変更が問題を引き起こしているという不満をさまざまなITチームから得ています。
これらの問題に最もよく対処するためにマネージャーが推奨するのは次のどれですか?
- A. ファイアウォールポリシーをプッシュする前に、すべての新しいファイアウォールルールがセカンダリファイアウォールの管理者に確認するよう要求する。
- B. 広範な影響を与える可能性が高い今後の変更について議論するために、関連チームの週次レビューを設定します。
- C. 変更リクエストフォームを更新して、リクエストチームがリクエストされた変更に関する追加の詳細を提供できるようにします。
- D. 更新されたファイアウォールポリシーをプッシュする前に、ファイアウォールチームに要求側チームとの変更を確認するように要求します。
正解: B
質問 177
DLPソリューションは、FTPを使用してリモートサーバーに送信されている未確認の暗号化データをいくつか示しています。脆弱性スキャンにより、OSレベルのパッチが適用されていないLinuxサーバーのコレクションが見つかりました。さらに調査すると、技術者は、いくつかのサーバーで実行されている未確認のプロセスがいくつかあることに気付きました。この時点でデータセキュリティチームが着手する最初の重要なステップは何でしょうか。
- A. Linuxサーバを再起動し、実行中のプロセスを確認して、必要なパッチをインストールします。
- B. 1つ以上のLinuxサーバーの、RAMを含むビットレベルのイメージを実行します。
- C. プロセスIDデータをキャプチャして、確認のためにウイルス対策ベンダーに送信します。
- D. 本番環境から単一のLinuxサーバーを削除し、隔離します。
- E. セキュリティ違反について上級管理職に通知します。
正解: B
解説:
Incident management (IM) is a necessary part of a security program. When effective, it mitigates business impact, identifies weaknesses in controls, and helps fine-tune response processes.
In this question, an attack has been identified and confirmed. When a server is compromised or used to commit a crime, it is often necessary to seize it for forensics analysis. Security teams often face two challenges when trying to remove a physical server from service: retention of potential evidence in volatile storage or removal of a device from a critical business process.
Evidence retention is a problem when the investigator wants to retain RAM content. For example, removing power from a server starts the process of mitigating business impact, but it also denies forensic analysis of data, processes, keys, and possible footprints left by an attacker.
A full a bit level image, including RAM should be taken of one or more of the Linux servers. In many cases, if your environment has been deliberately attacked, you may want to take legal action against the perpetrators. In order to preserve this option, you should gather evidence that can be used against them, even if a decision is ultimately made not to pursue such action. It is extremely important to back up the compromised systems as soon as possible. Back up the systems prior to performing any actions that could affect data integrity on the original media.
Incorrect Answers:
A: Capturing process ID data and submitting it to anti-virus vendor for review would not be the first step. Furthermore, it is unlikely that a virus is the cause of the problem on the LINUX servers. It is much more likely that the missing OS level patches left the systems vulnerable.
B: Rebooting the Linux servers would lose the contents of the running RAM. This may be needed for litigation so a full backup including RAM should be taken first. Then the servers can be cleaned and patched.
C: Removing a single Linux server from production and placing it in quarantine would probably involve powering off the server. Powering off the server would lose the contents of the running RAM. This may be needed for litigation so a full backup including RAM should be taken first.
D: Notifying upper management of a security breach probably should be done after the security breach is contained. You should follow standard incident management procedures first. Reporting on the incident is one of the later steps in the process.
References:
http://whatis.techtarget.com/reference/Five-Steps-to-Incident-Management-in-a-Virtualized-Environment
https://technet.microsoft.com/en-us/library/cc700825.aspx
質問 178 
- A. Option A
- B. Option C
- C. Option B
- D. Option E
- E. Option D
正解: A
解説:
Explanation
Using likelihood and consequence to determine risk is known as qualitative risk analysis.
With qualitative risk analysis, the risk would be evaluated forits probability and impact using a numbered ranking system such as low, medium, and high or perhaps using a 1 to 10 scoring system.
After qualitative analysis has been performed, you can then perform quantitative risk analysis. A Quantitative risk analysisis a further analysis of the highest priority risks during which a numerical or quantitative rating is assigned to the risk.
Qualitative risk analysis is usually quick to perform and no special tools or software is required. However, qualitative risk analysis is subjective and based on the user's experience.
質問 179
セキュリティエンジニアは、セキュリティ評価中にアプリケーションを分析して、一般的な脅威から保護するように設定されていることを確認します。 以下の出力があるとします。
セキュリティエンジニアMOSTがこの出力を生成するために使用した可能性のあるツールはどれですか?
- A. Fuzzer
- B. HTTP interceptor
- C. Application fingerprinter
- D. Vulnerability scanner
正解: B
質問 180
侵入テスト担当者がComptia.orgで評価を実施しており、公衆インターネットに接続している間にコーヒーショップから次のコマンドを実行します。
侵入テスト担当者は、コマンド出力について次のうちどれを結論付ける必要がありますか?
- A. Comptia.org DNSサーバーのパブリックビューとプライベートビューが正しく設定されていません
- B. Comptia.orgは古いメールサーバを実行しています。これはエクスプロイトに対して脆弱です。
- C. 192.168.102.67はバックアップメールサーバーで、攻撃に対して脆弱な場合があります。
- D. Comptia.orgのDNS SPFレコードは更新されていません
正解: A
解説:
Answer B is incorrect, there's no information about the server version
Answer C is incorrect, there's no SPF records here
Answer D is incorrect. Usually the secondary MX record is simply a different route to the same server.
Answer A is correct, 192.168.x.x is a private IP address and should not be displayed publicly.
質問 181
会社は最近、会社に脅威を与えるさまざまな種類のトラフィックを検出するために、さまざまなセキュリティサービスを実装しました。ネットワーク内で次のサービスが有効になりました。
*脆弱性の特定のサブセットのスキャン
*ウェブサイトトラフィックの分類とログ
*アプリケーショントラフィックに基づいて特定のACLを有効にする
*疑わしいファイルを検証のためにサードパーティのサイトに送信する
社内サーバーからパブリックサイトに大量のデータを共有するユーザーの複数のインシデントを特定したレポートがセキュリティチームに送信されました。そのデータのごく一部にはマルウェアとスパイウェアも含まれていました。次のサービスのうち、MOSTが動作を特定してレポートを送信した可能性が高いサービスはどれですか。
- A. アプリケーションサンドボックス
- B. クラウドセキュリティブローカー
- C. ユーザー行動分析
- D. エンドポイント保護
- E. コンテンツフィルター
- F. Webアプリケーションファイアウォール
正解: C
質問 182
セキュリティ設計者が新しいプロジェクトに最適なソリューションを決定しています。このプロジェクトは、高度な認証機能、ユーザー用のSSO、およびシステムへの1日目のアクセスを合理化するための自動プロビジョニングを備えた新しいイントラネットを開発しています。セキュリティ設計者は次の要件を確認しました。
1.情報は信頼できるマスターデータソースから供給されるべきです。
2.デバイスとユーザーの身元証明のための将来の要件がなければなりません。
3.再利用できる汎用IDコネクタを開発する必要があります。
4.現在のプロジェクト範囲は、内部でホストされているアプリケーションのみです。
以下のソリューション構成要素のうち、セキュリティ設計者が要件を最もよく満たすために使用すべきものはどれですか。
- A. SAML、コンテキストアウェア認証、oAuth、WAYF
- B. NAC、radius、802.1x、集中型Active Directory
- C. AD、証明書ベースの認証、Kerberos、SPML
- D. LDAP、多要素認証、oAuth、XACML
正解: D
質問 183
セキュリティエンジニアが、会社に対して再度評価を実行しています。セキュリティエンジニアは、レビューからの次の出力を調べます。
エンジニアがこの評価を実行するために利用しているツールはどれですか。
- A. SCAPスキャナー
- B. ポートスキャナ
- C. 脆弱性スキャナー
- D. 代行受信プロキシ
正解: A
質問 184 


- A. sqlmap -w
- B. arp -s
- C. netstat -a
- D. ifconfig -arp
正解: C
質問 185
セキュリティエンジニアは、管理者からの依頼により、設定ボードの新しいメンバーになりました。同社は今年から2つの新しい主要なITプロジェクトを開始しており、アプリケーション展開のセキュリティを計画したいと考えています。理事会は主に、アプリケーションが連邦政府の査定および承認基準に準拠しているかどうかを懸念します。セキュリティエンジニアは、両方のアプリケーションのセキュリティ評価をいつ行うべきかを決定するためのタイムラインを求め、その後のコンフィギュレーションボード会議には出席しません。セキュリティエンジニアがセキュリティアセスメントを実行するだけの場合は、システム承認の次の手順のうちセキュリティエンジニアを省略したのはどれですか。
- A. ユーザー受け入れテストの結果を確認します
- B. 利害関係者と相談して、どの基準を省略できるかを判断します。
- C. セキュリティ管理基準を確立します
- D. ソフトウェア開発セキュリティ標準に従ってアプリケーションをビルドします
正解: C
解説:
A security baseline is the minimum level of security that a system, network, or device must adhere to. It is the initial point of reference for security and the document against which assessments would be done.
Incorrect Answers:
B: Building the application with secure coding is the programmers' duty.
C: User acceptance testing is part of the development process
D: Standards are not security concerns.
References:
Gregg, Michael, and Billy Haines, CASP CompTIA Advanced Security Practitioner Study Guide, John Wiley & Sons, Indianapolis, 2012, pp. 272-273
質問 186
セキュリティアセスメントの間、組織はネットワークセグメンテーションに対する不適切な管理について助言されます。査定者は、トラフィックをセグメント化するために組織がVLANに依存しているだけでは、規制基準に基づくセグメント化を提供するには不十分であると説明しています。
次のうちどれがより高いレベルのセグメンテーションを提供するためにVLANと共に実装することを検討すべきですか?
- A. エアギャップ
- B. アクセス制御リスト
- C. ネットワーク仮想化
- D. 弾性負荷分散
- E. スパニングツリープロトコル
正解: B
解説:
While the VLANs segment the networks the ACLs provide authority over the actual traffic passing between.
質問 187
ビジネスは成長し、他の場所に分岐し始めています。別の国にオフィスを開くことを見越して、最高情報セキュリティ責任者(CISO)と法務チームは、新しいオフィスを開くためのデータに関して次の基準を満たす必要があることに同意します。
* 5年間の店舗課税関連文書
* 顧客の住所を暗号化形式で保存する
* 1年後に顧客情報を破棄する
* 顧客の本国のみでデータを保管する
CISOは、これらの要件を最もよく満たすために次のうちどれを実装すべきですか。
(3つ選んでください。)
- A. バックアップポリシー
- B. 暗号化規格
- C. 利用規定
- D. データ保持方針
- E. キャパシティプランニング方針
- F. 法令順守ポリシー
- G. データ分類基準
- H. データ主権政策
正解: B,D,H
質問 188 
- A. Option A
- B. Option C
- C. Option B
- D. Option E
- E. Option D
正解: C
質問 189 
- A. Option A
- B. Option B
- C. Option C
- D. Option E
- E. Option D
正解: C
質問 190
......
無料CASP Recertification CAS-003日本語試験問題:https://www.goshiken.com/CompTIA/CAS-003J-mondaishu.html