PT0-002日本語 PDF問題集リアル2024最近更新された問題 [Q212-Q236]

Share

PT0-002日本語 PDF問題集リアル2024最近更新された問題

リリースCompTIA PT0-002日本語更新された問題PDF

質問 # 212
クライアントのクラウドおよびオンプレミス環境の評価中に、ペネトレーション テスターは....プレミスの資格情報を使用してクラウド環境内のストレージ オブジェクトの所有権を取得できました。テスターがアクセスできた理由を最もよく説明しているものは次のうちどれですか?

  • A. 環境間のキーの管理ミス
  • B. コンテナのフェデレーション設定ミス
  • C. パブリックドメインにリストされているコンテナ
  • D. プロバイダーでの LaaS 障害

正解:B

解説:
Explanation
The best explanation for why the tester was able to gain access to the storage object within the cloud environment using the on-premises credentials is federation misconfiguration of the container. Federation is a process that allows users to access multiple systems or services with a single set of credentials, by using a trusted third-party service that authenticates and authorizes the users. Federation can enable seamless integration between cloud and on-premises environments, but it can also introduce security risks if not configured properly. Federation misconfiguration of the container can allow an attacker to access the storage object with the on-premises credentials, if the container trusts the on-premises identity provider without verifying its identity or scope. The other options are not valid explanations for why the tester was able to gain access to the storage object within the cloud environment using the on-premises credentials. Key mismanagement between the environments is not relevant to this issue, as it refers to a different scenario involving encryption keys or access keys that are used to protect or access data or resources in cloud or on-premises environments. IaaS failure at the provider is not relevant to this issue, as it refers to a different scenario involving infrastructure as a service (IaaS), which is a cloud service model that provides virtualized computing resources over the internet. Container listed in the public domain is not relevant to this issue, as it refers to a different scenario involving container visibility or accessibility from public networks or users.


質問 # 213
侵入テスターは、サンドボックス環境でモバイル アプリケーションの新しいバージョンをテストしています。アプリケーションと外部 API 間のトラフィックを傍受して暗号化解除するために、テスターはプライベート ルート CA を作成し、そこから証明書を発行しました。テスト担当者は、テストに使用したスマートフォンのトラステッド ストーンにルート CA をインストールしましたが、アプリケーションは証明書の不一致を示すエラーを表示し、サーバーに接続しません。エラーの理由として最も可能性が高いのは次のうちどれですか?

  • A. API サーバーが TLS ではなく SSL を使用している
  • B. アプリケーションにはピン留めされた API 証明書があります。
  • C. ファイアウォールで TCP ポート 443 が開いていません
  • D. テスターが古いバージョンのアプリケーションを使用しています

正解:B


質問 # 214
侵入テスターはシステムへのアクセスを取得し、ユーザー プロセスに移行できます。

上記の出力から、ペネトレーション テスターが行っているアクションは次のうちどれですか? (2つ選んでください。)

  • A. ファイルからリモート システムへの出力のリダイレクト
  • B. すべてのドメイン システムでの新しいプロセスの作成
  • C. リモートシステムでファイルを実行
  • D. リモート システムへの共有のマッピング
  • E. 侵害されたシステムに追加の IP アドレスを追加する
  • F. 実行するスケジュールされたタスクの構築
  • G. リモート システムからのリバース シェルのセットアップ

正解:C、D

解説:
Explanation
WMIC.exe is a built-in Microsoft program that allows command-line access to the Windows Management Instrumentation. Using this tool, administrators can query the operating system for detailed information about installed hardware and Windows settings, run management tasks, and even execute other programs or commands.


質問 # 215
ペネトレーション テスターは、Windows ホストへのシェル アクセスを取得し、wmic.exe プロセス呼び出し create 関数を使用して後で実行するために、特別に細工されたバイナリを実行したいと考えています。次の OS またはファイルシステムのメカニズムのうち、この目的をサポートする可能性が最も高いのはどれですか?

  • A. PowerShell モジュール
  • B. 代替データ ストリーム
  • C. PsExec
  • D. MP4 ステガノグラフィ

正解:B

解説:
Explanation
Alternate data streams (ADS) are a feature of the NTFS file system that allows storing additional data in a file without affecting its size, name, or functionality. ADS can be used to hide or embed data or executable code in a file, such as a specially crafted binary for later execution. ADS can be created or accessed using various tools or commands, such as the command prompt, PowerShell, or Sysinternals12. For example, the following command can create an ADS named secret.exe in a file named test.txt and run it using wmic.exe process call create function: type secret.exe > test.txt:secret.exe & wmic process call create "cmd.exe /c test.txt:secret.exe"


質問 # 216
ペネトレーション テスターが Web サーバーに対する脆弱性スキャンを完了し、1 つの重大な脆弱性を特定しました。
これが真の陽性であることを確認するための最良の方法は次のうちどれですか?

  • A. 別のスキャナーを実行して比較します。
  • B. サーバーで手動テストを実行します。
  • C. オンラインで脆弱性を探します。
  • D. スキャナーで結果を確認します。

正解:B


質問 # 217
侵入テスト チームは、建物に侵入するための物理的な侵入テストを実施しています。侵入テスト担当者がエンゲージメント ドキュメントのコピーを携帯する必要がある理由は次のうちどれですか?

  • A. 建物の入り口を案内する
  • B. クライアントとの請求情報を検証するため
  • C. 発見された場合の証拠として
  • D. 原稿紛失時のバックアップとして

正解:C


質問 # 218
ある企業は、自社のクラウド サービス プロバイダーが自社のソフトウェア開発を格納する VM を適切に保護していないことを懸念しています。VM は、他の企業が物理リソースを共有しているデータセンターに収容されています。
次の攻撃の種類のうち、会社にとって最も懸念されるのはどれですか?

  • A. サイドチャンネル
  • B. サイバースクワッティング
  • C. セッションライディング
  • D. データフラッディング

正解:A

解説:
https://www.techtarget.com/searchsecurity/definition/side-channel-attack#:~:text=Side%2Dchannel%20attacks%20can%20even,share%20the%20same%20physical%20hardware


質問 # 219
システム管理者と技術スタッフが閲覧できる侵入テストレポートの修復セクションを作成する際に、次のどのタイプの情報を含める必要がありますか?

  • A. 評価からのエンゲージメントのルール
  • B. エグゼクティブ サマリーと試験会社に関する情報
  • C. 侵害された場合のビジネスへの影響に関する情報
  • D. 脆弱性の簡単な説明とそれを修正するための高度なコントロール

正解:D

解説:
Explanation
The systems administrator and the technical stuff would be more interested in the technical aspect of the findings


質問 # 220
侵入テスターは、エンゲージメントで使用する次のスクリプトを作成しました。

ただし、スクリプトを実行しようとすると、テスターは次のエラーを受け取ります。

エラーの理由は次のうちどれですか?

  • A. sys 変数が定義されていません。
  • B. argv モジュールはインポートされませんでした。
  • C. argv 変数が定義されていません。
  • D. sys モジュールがインポートされませんでした。

正解:D

解説:
The sys module is a built-in module in Python that provides access to system-specific parameters and functions, such as command-line arguments, standard input/output, and exit status. The sys module must be imported before it can be used in a script, otherwise an error will occur. The script uses the sys.argv variable, which is a list that contains the command-line arguments passed to the script. However, the script does not import the sys module at the beginning, which causes the error "NameError: name 'sys' is not defined". To fix this error, the script should include the statement "import sys" at the top. The other options are not valid reasons for the error.


質問 # 221
侵入テスト中に、限られたユーザー インターフェイスでシステムにアクセスできます。このマシンは、ポート スキャンが必要な隔離されたネットワークにアクセスできるようです。
手順
コード セグメントを分析して、ポート スキャン スクリプトを完了するために必要なセクションを特定します。
適切な要素を正しい場所にドラッグして、スクリプトを完成させます。
いつでもシミュレーションを初期状態に戻したい場合は、[すべてリセット] ボタンをクリックしてください。

正解:

解説:

Explanation:
A picture containing shape Description automatically generated

A picture containing treemap chart Description automatically generated

Text Description automatically generated

Graphical user interface Description automatically generated


質問 # 222
OWASP Top 10 v2017 に含まれる Web アプリケーションのセキュリティ リスクは次のうちどれですか? (2つ選んでください。)

  • A. ゼロデイ攻撃
  • B. クロスサイト スクリプティング
  • C. 注入欠陥
  • D. 競合状態の攻撃
  • E. バッファ オーバーフロー
  • F. ランサムウェア攻撃

正解:B、C

解説:
Explanation
A01-Injection
A02-Broken Authentication
A03-Sensitive Data Exposure
A04-XXE
A05-Broken Access Control
A06-Security Misconfiguration
A07-XSS
A08-Insecure Deserialization
A09-Using Components with Known Vulnerabilities
A10-Insufficient Logging & Monitoring


質問 # 223
enum4linux.pl コマンドを実行した後、侵入テスターは次の出力を受け取りました。

侵入テスターが次に実行するコマンドは次のうちどれですか?

  • A. smbspool //192.160.100.56/print$
  • B. smbclient //192.168.100.56/web -U '' -N
  • C. smbget //192.168.100.56/web -U ''
  • D. net rpc share -S 192.168.100.56 -U ''

正解:B

解説:
A vulnerability scan is a type of assessment that helps to identify vulnerabilities in a network or system. It scans systems for potential vulnerabilities, misconfigurations, and outdated software. Based on the output from a vulnerability scan, a penetration tester can identify vulnerabilities that may be exploited to gain access to a system. In this scenario, the output from the penetration testing tool shows that 100 hosts contained findings due to improper patch management. This indicates that the vulnerability scan detected vulnerabilities that could have been prevented through proper patch management. Therefore, the most likely test performed by the penetration tester is a vulnerability scan.


質問 # 224
クライアントのクラウドおよびオンプレミス環境の評価中に、ペネトレーション テスターは....プレミスの資格情報を使用してクラウド環境内のストレージ オブジェクトの所有権を取得できました。テスターがアクセスできた理由を最もよく説明しているものは次のうちどれですか?

  • A. 環境間のキーの管理ミス
  • B. パブリック ドメインにリストされているコンテナ
  • C. プロバイダーでの LaaS 障害
  • D. コンテナのフェデレーション構成が間違っています

正解:D

解説:
The best explanation for why the tester was able to gain access to the storage object within the cloud environment using the on-premises credentials is federation misconfiguration of the container. Federation is a process that allows users to access multiple systems or services with a single set of credentials, by using a trusted third-party service that authenticates and authorizes the users. Federation can enable seamless integration between cloud and on-premises environments, but it can also introduce security risks if not configured properly. Federation misconfiguration of the container can allow an attacker to access the storage object with the on-premises credentials, if the container trusts the on-premises identity provider without verifying its identity or scope. The other options are not valid explanations for why the tester was able to gain access to the storage object within the cloud environment using the on-premises credentials. Key mismanagement between the environments is not relevant to this issue, as it refers to a different scenario involving encryption keys or access keys that are used to protect or access data or resources in cloud or on-premises environments. IaaS failure at the provider is not relevant to this issue, as it refers to a different scenario involving infrastructure as a service (IaaS), which is a cloud service model that provides virtualized computing resources over the internet. Container listed in the public domain is not relevant to this issue, as it refers to a different scenario involving container visibility or accessibility from public networks or users.


質問 # 225
侵入テストを実行しているテスターは、リモート攻撃に対して重大な脆弱性があることが知られている古いファイアウォールを発見しましたが、エンゲージメントの IP アドレスの元のリストには含まれていません。テスターが取るのに最適なオプションは次のうちどれですか?

  • A. ファイアウォールにパッチを適用します。
  • B. ファイアウォールについてクライアントに通知します。
  • C. ファイアウォールの脆弱性をスキャンします。
  • D. ファイアウォールをクラウドからセグメント化します。

正解:B

解説:
The best option for the tester to take is to notify the client about the firewall. The firewall is not part of the original list of IP addresses for the engagement, which means it is out of scope and should not be tested without permission. The tester should inform the client about the existence and potential risks of the firewall, and ask if they want to include it in the scope or not.


質問 # 226
あるソフトウェア会社は、会社のソフトウェア開発プラクティスのセキュリティを評価するために、セキュリティ コンサルタントを雇いました。コンサルタントは、ソフトウェア バイナリでファジングを実行して偵察を開始することを選択します。次の脆弱性のうち、セキュリティ コンサルタントが特定する可能性が最も高いのはどれですか?

  • A. 最適化されていないリソース管理
  • B. バッファ オーバーフロー
  • C. 文字列に格納された認証情報
  • D. 弱い認証スキーム

正解:B

解説:
Explanation
fuzzing introduces unexpected inputs into a system and watches to see if the system has any negative reactions to the inputs that indicate security, performance, or quality gaps or issues


質問 # 227
ペネトレーションテスターは未知の環境テストを実施し、後の評価段階で使用できる追加情報を収集します。追加のテストに役立つ情報を生成する可能性が最も高いのは次のうちどれですか?

  • A. 企業組織を対象としたコードリポジトリの検索
  • B. 対象会社に以前勤務していた開発者に関連付けられたコード リポジトリの検索
  • C. に関連付けられたターゲット企業のコード リポジトリで以前に働いていた開発者に関連付けられたコード リポジトリを検索します。
  • D. 対象企業の組織に関連付けられたコードリポジトリの検索

正解:A

解説:
Code repositories are online platforms that store and manage source code and other files related to software development projects. Code repositories can contain useful information for additional testing, such as application names, versions, features, functions, vulnerabilities, dependencies, credentials, comments, or documentation. Searching for code repositories associated with the target company's organization would most likely produce useful information for additional testing, as it would reveal the software projects that the target company is working on or using, and potentially expose some weaknesses or flaws that can be exploited. Code repositories can be searched by using tools such as GitHub, GitLab, Bitbucket, or SourceForge1. The other options are not as likely to produce useful information for additional testing, as they are not directly related to the target company's software development activities. Searching for code repositories associated with a developer who previously worked for the target company may not yield any relevant or current information, as the developer may have deleted, moved, or updated their code repositories after leaving the company. Searching for code repositories associated with the target company's competitors or customers may not yield any useful or accessible information, as they may have different or unrelated software projects, or they may have restricted or protected their code repositories from public view.


質問 # 228
評価者は、ステートフル ファイアウォール ルール セットの計画を立てるために Nmap を使用したいと考えています。評価者が実行する可能性が最も高いのは次のスキャンのうちどれですか?

  • A. nmap -sS 192.168.0.1/24
  • B. nmap -oG 192.168.0.1/24
  • C. nmap 192.168.0.1/24
  • D. nmap -sA 192.168.0.1/24

正解:D

解説:
https://nmap.org/book/scan-methods-ack-scan.html


質問 # 229
脆弱性評価を実施しているペネトレーション テスターが、ネットワーク セグメントで ICMP が無効になっていることを発見しました。次のうち、ネットワーク セグメントに対するサービス拒否攻撃に使用できるものはどれですか?

  • A. フラグル
  • B. ピンフラッド
  • C. スマーフ
  • D. 死のピン

正解:A

解説:
Fraggle attack is same as a Smurf attack but rather than ICMP, UDP protocol is used. The prevention of these attacks is almost identical to Fraggle attack.
Ref: https://www.okta.com/identity-101/fraggle-attack/


質問 # 230
侵入テスト ツールからの出力は、不適切なパッチ管理による検出結果が 100 個のホストに含まれていることを示しています。侵入テスターが実行したのは次のうちどれですか?

  • A. Nmap スキャン
  • B. WHOIS ルックアップ
  • C. パケットキャプチャ
  • D. 脆弱性スキャン

正解:D

解説:
A vulnerability scan is a type of penetration testing tool that is used to scan a network for vulnerabilities. A vulnerability scan can detect misconfigurations, missing patches, and other security issues that could be exploited by attackers. In this case, the output shows that 100 hosts had findings due to improper patch management, which means that the tester performed a vulnerability scan.


質問 # 231
侵入テスターは、ネットワーク スイッチの脆弱性を特定するために使用できる次の Perl スクリプトをダウンロードしました。ただし、スクリプトが正しく機能していません。
テスターがスクリプトを意図したとおりに動作させるために適用する必要がある変更は、次のうちどれですか?

  • A. 6 行目を削除します。
  • B. 行 3、5、および 6 を削除します。
  • C. 2 行目を $ip= 10.192.168.254; に変更します。
  • D. 7 行目以下のすべての行をスクリプトの先頭に移動します。

正解:B

解説:
Explanation
https://www.asc.ohio-state.edu/lewis.239/Class/Perl/perl.html
Example script:
#!/usr/bin/perl
$ip=$argv[1];
attack($ip);
sub attack {
print("x");
}


質問 # 232
侵入テスターは、特定のドメインの Web 上で入手可能なドキュメントに隠された情報を見つけたいと考えています。侵入テスターは次のうちどれを使用する必要がありますか?

  • A. CentralOps
  • B. シール
  • C. ネットクラフト
  • D. レスポンダ

正解:B

解説:
Explanation
https://kalilinuxtutorials.com/foca-metadata-hidden-documents/


質問 # 233
コード レビュー評価中に、ペネトレーション テスターは、Web アプリケーション ファイルの 1 つ内に次の脆弱なコードを発見しました。
<% String id = request.getParameter("id"); %>
従業員 ID: <%= id %>
このコードに基づいて、脆弱性の悪用を防ぐための最良の修復策は次のうちどれですか?

  • A. パラメータ化されたクエリ
  • B. 出力エンコーディング
  • C. パッチ適用

正解:B

解説:
Output encoding is a technique that prevents cross-site scripting (XSS) attacks by encoding the user input before displaying it on the web page. This way, any malicious scripts or HTML tags are rendered harmless and cannot execute on the browser. Output encoding is recommended by the OWASP Top 10 as a defense against XSS1. In this case, the vulnerable code is using a scriptlet to display the employee ID without any validation or encoding, which could allow an attacker to inject malicious code through the id parameter. Output encoding would prevent this by escaping any special characters in the id parameter. Reference: The Official CompTIA PenTest+ Student Guide (Exam PT0-002) eBook, Chapter 4, Section 4.2.1: Cross-site Scripting; Best PenTest+ certification study resources and training materials, Section 1: Cross-site Scripting (XSS) Attack; OWASP Top 10 2021, A7: Cross-site Scripting (XSS).


質問 # 234
システムに侵入した後、ペネトレーションテスターは、次にどのようなアクションを実行するかを決定するために、より多くの情報を必要とします。テスターは次のコマンドを実行します。

ペネトレーションテスターが実行しようとしている可能性が最も高い攻撃は次のうちどれですか?

  • A. コンテナ脱出テクニック
  • B. リソース枯渇
  • C. メタデータ サービス攻撃
  • D. 資格情報の収集

正解:C

解説:
The penetration tester is most likely trying to perform a metadata service attack, which is an attack that exploits a vulnerability in the metadata service of a cloud provider. The metadata service is a service that provides information about the cloud instance, such as its IP address, hostname, credentials, user data, or role permissions. The metadata service can be accessed from within the cloud instance by using a special IP address, such as 169.254.169.254 for AWS, Azure, and GCP. The commands that the penetration tester runs are curl commands, which are used to transfer data from or to a server. The curl commands are requesting data from the metadata service IP address with different paths, such as /latest/meta-data/iam/security-credentials/ and /latest/user-data/. These paths can reveal sensitive information about the cloud instance, such as its IAM role credentials or user data scripts. The penetration tester may use this information to escalate privileges, access other resources, or perform other actions on the cloud environment. The other options are not likely attacks that the penetration tester is trying to perform.


質問 # 235
侵入テスターは、dirb ユーティリティを使用して Web サーバーをスキャンした後、次の結果を得ました。
...
生成された単語: 4612
----
スキャン URL: http://10.2.10.13/ ----
+
http://10.2.10.13/about (コード:200|サイズ:1520)
+
http://10.2.10.13/home.html (コード:200|サイズ:214)
+
http://10.2.10.13/index.html (コード:200|サイズ:214)
+
http://10.2.10.13/info (コード:200|サイズ:214)
...
ダウンロード済み: 4612 - 見つかった: 4
次の要素のうち、侵入テスト担当者にとって有用な情報が含まれている可能性が最も高いのはどれですか?

  • A. home.html
  • B. 情報
  • C. について
  • D. index.html

正解:C


質問 # 236
......

PT0-002日本語問題集と練習テスト(360試験問題):https://www.goshiken.com/CompTIA/PT0-002J-mondaishu.html