CompTIA CS0-001最新問題集[2022]高得点を掴み取れ [Q207-Q230]

Share

CompTIA CS0-001最新問題集[2022]高得点を掴み取れ

CS0-001問題集GoShiken100%合格率保証


CompTIA CS0-001 認定試験の出題範囲:

トピック出題範囲
トピック 1
  • シナリオを前提として、一般的な症状を分析して、インシデント対応をサポートするための最善の行動方針を選択します
トピック 2
  • シナリオを前提として、脅威データまたは動作を区別して、インシデントの影響を判断します
トピック 3
  • さまざまなサイバーセキュリティツールとテクノロジーを使用する一般的な目的と理由を比較対照する
トピック 4
  • 企業環境を確保するために使用される慣行の目的を説明する
トピック 5
  • シナリオが与えられたら、ツールキットを準備し、調査中に適切なフォレンジックツールを使用します
トピック 6
  • シナリオを前提として、データを使用してIDおよびアクセス管理に関連するセキュリティ問題の修正を推奨します
トピック 7
  • シナリオを前提として、情報セキュリティの脆弱性管理プロセスを実装する
トピック 8
  • 組織内の次のターゲットに見られる一般的な脆弱性を比較対照する
トピック 9
  • インシデントの復旧とインシデント後の対応プロセスを要約する
トピック 10
  • フレームワーク、共通のポリシー、コントロール、および手順の間の関係を説明する
トピック 11
  • シナリオを前提として、脆弱性スキャンの結果の出力を分析します
トピック 12
  • シナリオを前提として、ネットワーク偵察の結果を分析します

 

質問 207
While a threat intelligence analyst was researching an indicator of compromise on a search engine, the
web proxy generated an alert regarding the same indicator. The threat intelligence analyst states that
related sites were not visited but were searched for in a search engine. Which of the following MOST likely
happened in this situation?

  • A. The analyst is not using the standard approved browser.
  • B. The alert in unrelated to the analyst's search.
  • C. The analyst has prefetch enabled on the browser in use.
  • D. The analyst accidently clicked a link related to the indicator.

正解: C

解説:
Explanation/Reference:
Explanation:

 

質問 208
A medical organization recently started accepting payments over the phone. The manager is concerned
about the impact of the storage of different types of data. Which of the following types of data incurs the
highest regulatory constraints?

  • A. IP
  • B. PHI
  • C. PII
  • D. PCI

正解: D

 

質問 209
A penetration tester is preparing for an audit of critical systems that may impact the security of the environment. This includes the external perimeter and the internal perimeter of the environment. During which of the following processes is this type of information normally gathered?

  • A. Scoping
  • B. Enumeration
  • C. Timing
  • D. Authorization

正解: A

 

質問 210
A security analyst is reviewing packet captures to determine the extent of success during an attacker's reconnaissance phase following a recent incident.
The following is a hex and ASCII dump of one such packet:

Which of the following BEST describes this packet?

  • A. DNS over UDP standard query
  • B. DNS BIND version request
  • C. DNS over TCP server status query
  • D. DNS zone transfer request

正解: B

 

質問 211
After reviewing the following packet, a cybersecurity analyst has discovered an unauthorized service is running on a company's computer.

Which of the following ACLs, if implemented, will prevent further access ONLY to the unauthorized service and will not impact other services?

  • A. DENY TCP ANY HOST 10.38.219.20 EQ 3389
  • B. DENY TCP ANY HOST 192.168.1.10 EQ 25
  • C. DENY IP HOST192.168.1.10 HOST 10.38.219.20 EQ 3389
  • D. DENY IP HOST 10.38.219.20 ANY EQ 25

正解: A

 

質問 212
Alerts have been received from the SIEM, indicating infections on multiple computers. Based on threat characteristic, these files were quarantined by the host-based antivirus program. At the same time, additional alerts in the SIEM show multiple blocked URLs from the address of the infected computers; the URLs were clashed as uncategorized. The domain location of the IP address of the URLs that were blocked is checked, and it is registered to an ISP in Russia. Which of the following steps should be taken NEXT?

  • A. Install a computer with the same settings as the infected computers in the DM^ to use as a honeypot Permit the URLs classified as uncategorized to and from that host.
  • B. Run a vulnerability scan and patch discovered vulnerabilities on the next patching cycle Have the users restart their computer Create a use case in the SIEM to monitor farted logins on infected computers.
  • C. Run a full antivirus scan on all computers and use Splunk to search for any suspicious activity that happened just before the alerts were received in the SIEM.
  • D. Remove those computers from the network and replace the hard drives Send the Infected hard drives out lot investigation.

正解: C

 

質問 213
A security analyst received several service tickets reporting that a company storefront website is not accessible by internal domain users. However, external users are accessing the website without issue. Which of the following is the MOST likely reason for this behavior?

  • A. The time synchronization server is corrupted.
  • B. The DNS server is corrupted.
  • C. The certificate is expired.
  • D. The FQDN is incorrect.

正解: B

 

質問 214
A security analyst has noticed that a particular server has consumed over 1TB of bandwidth over the course of the month. It has port 3333 open; however, there have not been any alerts or notices regarding the server or its activities. Which of the following did the analyst discover?

  • A. APT
  • B. DDoS
  • C. Zero day
  • D. False positive

正解: C

 

質問 215
A security analyst is adding input to the incident response communication plan. A company officer has suggested that if a data breach occurs, only affected parties should be notified to keep an incident from becoming a media headline. Which of the following should the analyst recommend to the company officer?

  • A. Guidance from laws and regulations should be considered when deciding who must be notified in order to avoid fines and judgements from non-compliance.
  • B. An externally hosted website should be prepared in advance to ensure that when an incident occurs victims have timely access to notifications from a non-compromised recourse.
  • C. The HR department should have information security personnel who are involved in the investigation of the incident sign non-disclosure agreements so the company cannot be held liable for customer data that might be viewed during an investigation.
  • D. The first responder should contact law enforcement upon confirmation of a security incident in order for a forensics team to preserve chain of custody.

正解: D

 

質問 216
An organization wants to remediate vulnerabilities associated with its web servers. An initial vulnerability scan has been performed, and analysts are reviewing the results. Before starting any remediation, the analysts want to remove false positives to avoid spending time on issues that are not actual vulnerabilities.
Which of the following would be an indicator of a likely false positive?

  • A. The scan result version is different from the automated asset inventory.
  • B. 'HTTPS' entries indicate the web page is encrypted securely.
  • C. Reports show the scanner compliance plug-in is out-of-date.
  • D. Any items labeled 'low' are considered informational only.

正解: D

解説:
Explanation/Reference:
Explanation:

 

質問 217
An alert has been distributed throughout the information security community regarding a critical Apache vulnerability. Which of the following courses of action would ONLY identify the known vulnerability?

  • A. Perform an unauthenticated vulnerability scan on all servers in the environment.
  • B. Perform a scan for the specific vulnerability on all web servers.
  • C. Perform an authenticated scan on all web servers in the environment.
  • D. Perform a web vulnerability scan on all servers in the environment.

正解: B

解説:
Section: (none)
Explanation/Reference:
Explanation:

 

質問 218
A security analyst performs various types of vulnerability scans.
Review the vulnerability scan results to determine the type of scan that was executed and if a false positive occurred for each device.
Instructions:
Select the Results Generated drop-down option to determine if the results were generated from a credentialed scan, non-credentialed scan, or a compliance scan.
For ONLY the credentialed and non-credentialed scans, evaluate the results for false positives and check the findings that display false positives. NOTE: If you would like to uncheck an option that is currently selected, click on the option a second time.
Lastly, based on the vulnerability scan results, identify the type of Server by dragging the Server to the results.
The Linux Web Server, File-Print Server and Directory Server are draggable.
If at any time you would like to bring back the initial state of the simulation, please select the Reset button.
When you have completed the simulation, please select the Done button to submit. Once the simulation is submitted, please select the Next button to continue.

正解:

解説:

Explanation
1. non-credentialed scan- File Print Server: False positive is first bullet point.
2. credentialed scan - Linux Web Server: No False positives.
3. Compliance scan- Directory Server

 

質問 219
A project lead is reviewing the statement of work for an upcoming project that is focused on identifying potential weaknesses in the organization's internal and external network infrastructure. As part of the project, a team of external contractors will attempt to employ various attacks against the organization.
The statement of work specifically addresses the utilization of an automated tool to probe network resources in an attempt to develop logical diagrams indication weaknesses in the infrastructure.
The scope of activity as described in the statement of work is an example of:

  • A. friendly DoS
  • B. penetration testing
  • C. session hijacking
  • D. social engineering
  • E. vulnerability scanning

正解: B

 

質問 220
An organization wants to remediate vulnerabilities associated with its web servers. An initial vulnerability scan has been performed, and analysts are reviewing the results. Before starling any remediation the analysts want to remove false positives to avoid spending time on issues that are not actual vulnerabilities. Which of the following would be an indicator of a likely false positive?

  • A. Reports indicate that findings are informational.
  • B. The scan result version is different front the automated asset inventory.
  • C. Any item& labeled "low" are considered informational only.
  • D. HTTPS entries indicate the web page is encrypted securely.

正解: A

 

質問 221
A recent audit has uncovered several coding errors and a lack of input validation being used on a public portal. Due to the nature of the portal and the severity of the errors, the portal is unable to be patched. Which of the following tools could be used to reduce the risk of being compromised?

  • A. Web proxy
  • B. Web application firewall
  • C. Network firewall
  • D. Intrusion prevention system

正解: B

 

質問 222
A corporation has implemented an 802.1X wireless network using self-signed certificates. Which of the following represents a risk to wireless users?

  • A. Cross-site scripting attacks
  • B. Man-in-the-middle attacks
  • C. Buffer overflow attacks
  • D. Denial of service attacks

正解: B

 

質問 223
A software patch has been released to remove vulnerabilities from company's software. A security analyst has been tasked with testing the software to ensure the vulnerabilities have been remediated and the application is still functioning properly. Which of the following tests should be performed NEXT?

  • A. Penetration testing
  • B. Regression testing
  • C. User acceptance testing
  • D. Fuzzing

正解: A,B,D

 

質問 224
A cybersecurity analyst is reviewing Apache logs on a web server and finds that some logs are missing. The analyst has identified that the systems administrator accidentally deleted some log files. Which of the following actions or rules should be implemented to prevent this incident from reoccurring?

  • A. Backup server
  • B. Separation of duties
  • C. Personnel training
  • D. Mandatory vacation

正解: A

 

質問 225
The business has been informed of a suspected breach of customer dat
a. The internal audit team, in conjunction with the legal department, has begun working with the cybersecurity team to validate the report. To which of the following response processes should the business adhere during the investigation?

  • A. The security analysts should limit communication to trusted parties conducting the investigation
  • B. The security analysts should interview system operators and report their findings to the internal auditors
  • C. The security analysts should report the suspected breach to regulators when an incident occurs
  • D. The security analysts should not respond to internal audit requests during an active investigation

正解: A

 

質問 226
As part of an upcoming engagement for a client, an analyst is configuring a penetration testing application to ensure the scan complies with information defined in the SOW. Which of the following types of information should be considered based on information traditionally found in the SOW? (Select two.)

  • A. Maintenance windows
  • B. Timing of the scan
  • C. Excluded hosts
  • D. IPS configuration
  • E. Contents of the executive summary report
  • F. Incident response policies

正解: B,C

解説:
Explanation/Reference:
Explanation:

 

質問 227
A cybersecurity analyst is currently investigating a server outage. The analyst has discovered the following value was entered for the username: 0xbfff601a. Which of the following attacks may be occurring?

  • A. Smurf attack
  • B. Man-in-the-middle attack
  • C. Denial of service attack
  • D. Buffer overflow attack
  • E. Format string attack

正解: E

解説:
Explanation/Reference:

 

質問 228
A security analyst has a sample of malicious software and needs to know what the sample does? The analyst runs the sample in a carefully controlled and monitored virtual machine to observe the software behavior.
Which of the following malware analysis approaches is this?

  • A. White box testing
  • B. Static code analysis
  • C. Sandboxing
  • D. Fuzzing

正解: C

 

質問 229
While reviewing web server logs, a security analyst notices the following code:

Which of the following would prevent this code from performing malicious actions?

  • A. Installing a network firewall in front of the application
  • B. Requiring the application to use input validation
  • C. Performing web application penetration testing
  • D. Disabling the use of HTTP and requiring the use of HTTPS

正解: D

 

質問 230
......

100%合格率リアルCS0-001試験成功を掴み取れ:https://www.goshiken.com/CompTIA/CS0-001-mondaishu.html