更新済みの2024年03月 350-701日本語試験練習テスト問題
検証済み350-701日本語問題集と解答100%一発合格保証で更新された問題集
質問 # 98
展示を参照してください。
https://api.amp.cisco.com/v1/computersでの作業中にAPIキーは何をしますか?
- A. クライアントIDを表示します
- B. HTTP認証
- C. リクエストをインポートします
- D. HTTP認証
正解:C
質問 # 99
右上の正しい定義に左から火力と次世代侵入防止システム検出器をドロップします。
正解:
解説:
質問 # 100
透過モードで実行されているCiscoWSAと明示モードで実行されているCiscoWSAの2つの違いは何ですか。 (2つ選択してください。)
- A. Cisco WSAは、明示モードで実行されている場合にのみ、独自のIPアドレスで応答します。
- B. Cisco WSAは、透過モードで実行されている場合にのみ、レイヤ3デバイスを使用してトラフィックをリダイレクトします。
- C. Cisco WSAは、透過モードで実行されている場合にのみ、独自のIPアドレスで応答します。
- D. Cisco WSAが透過モードで実行されている場合、HTTP要求の宛先としてWSA自身のIPアドレスを使用します。
- E. Cisco WSAは、透過モードで実行されている場合にのみWebブラウザで設定されます。
正解:C、D
質問 # 101
ASAファイアウォール透過モードのブリッジグループの特徴は何ですか。
- A. 複数のインターフェースが含まれており、インターフェース間のアクセスルールはカスタマイズ可能です
- B. これはレイヤー3セグメントであり、1つのポートとカスタマイズ可能なアクセスルールが含まれています
- C. 単一のアクセスルールでARPトラフィックを許可します
- D. BVIインターフェースにIPアドレスがあり、トラフィックの管理に使用されます
正解:A
解説:
A bridge group is a group of interfaces that the ASA bridges instead of routes. Bridge groups are only supported in Transparent Firewall Mode. Like any other firewall interfaces, access control between interfaces is controlled, and all of the usual firewall checks are in place.
Each bridge group includes a Bridge Virtual Interface (BVI). The ASA uses the BVI IP address as the source address for packets originating from the bridge group. The BVI IP address must be on the same subnet as the bridge group member interfaces. The BVI does not support traffic on secondary networks; only traffic on the same network as the BVI IP address is supported.
You can include multiple interfaces per bridge group. If you use more than 2 interfaces per bridge group, you can control communication between multiple segments on the same network, and not just between inside and outside. For example, if you have three inside segments that you do not want to communicate with each other, you can put each segment on a separate interface, and only allow them to communicate with the outside interface. Or you can customize the access rules between interfaces to allow only as much access as desired.
A bridge group is a group of interfaces that the ASA bridges instead of routes. Bridge groups are only supported in Transparent Firewall Mode. Like any other firewall interfaces, access control between interfaces is controlled, and all of the usual firewall checks are in place.
Each bridge group includes a Bridge Virtual Interface (BVI). The ASA uses the BVI IP address as the source address for packets originating from the bridge group. The BVI IP address must be on the same subnet as the bridge group member interfaces. The BVI does not support traffic on secondary networks; only traffic on the same network as the BVI IP address is supported.
You can include multiple interfaces per bridge group. If you use more than 2 interfaces per bridge group, you can control communication between multiple segments on the same network, and not just between inside and outside. For example, if you have three inside segments that you do not want to communicate with each other, you can put each segment on a separate interface, and only allow them to communicate with the outside interface. Or you can customize the access rules between interfaces to allow only as much access as desired.
A bridge group is a group of interfaces that the ASA bridges instead of routes. Bridge groups are only supported in Transparent Firewall Mode. Like any other firewall interfaces, access control between interfaces is controlled, and all of the usual firewall checks are in place.
Each bridge group includes a Bridge Virtual Interface (BVI). The ASA uses the BVI IP address as the source address for packets originating from the bridge group. The BVI IP address must be on the same subnet as the bridge group member interfaces. The BVI does not support traffic on secondary networks; only traffic on the same network as the BVI IP address is supported.
You can include multiple interfaces per bridge group. If you use more than 2 interfaces per bridge group, you can control communication between multiple segments on the same network, and not just between inside and outside. For example, if you have three inside segments that you do not want to communicate with each other, you can put each segment on a separate interface, and only allow them to communicate with the outside interface. Or you can customize the access rules between interfaces to allow only as much access as desired.
Reference:
Note: BVI interface is not used for management purpose. But we can add a separate Management slot/port interface that is not part of any bridge group, and that allows only management traffic to the ASA.
Note: BVI interface is not used for management purpose. But we can add a separate Management slot/port interface that is not part of any bridge group, and that allows only management traffic to the ASA.
質問 # 102
エンジニアは、プロトコルフィールドを分析し、産業用システムからのトラフィックの異常を検出するようにCisco FTDを設定する必要があります。これらの要件を満たすには、何をする必要がありますか。
- A. CiscoFTDでトラフィック分析を有効にします
- B. アクセス制御ポリシーを変更して産業用トラフィックを信頼する
- C. DNP3プリプロセッサの侵入ルールを設定します
- D. CIPプリプロセッサのプレフィルタポリシーを実装する
正解:D
解説:
Explanation The Modbus, DNP3, and CIP SCADA preprocessors detect traffic anomalies and provide data to intrusion rules. Therefore in this question only answer A or answer C is correct. The DNP3 preprocessor detects anomalies in DNP3 traffic and decodes the DNP3 protocol for processing by the rules engine, which uses DNP3 keywords to access certain protocol fields. The Common Industrial Protocol (CIP) is a widely used application protocol that supports industrial automation applications. EtherNet/IP is an implementation of CIP that is used on Ethernet-based networks.The CIP preprocessor detects CIP and ENIP traffic running on TCP or UDP and sends it to the intrusion rules engine. You can use CIP and ENIP keywords in custom intrusion rules to detect attacks in CIP and ENIP traffic. Reference: https://www.cisco.com/c/en/us/td/docs/security/firepower/630/configuration/guide/fpmc-configguide-v63/scada_preprocessors.html Both DNP3 and CIP preprocessors can be used to detect traffic anomalies but we choose CIP as it is widely used in industrial applications. Note: + An intrusion rule is a specified set of keywords and arguments that the system uses to detect attempts to exploit vulnerabilities in your network. As the system analyzes network traffic, it compares packets against the conditions specified in each rule, and triggers the rule if the data packet meets all the conditions specified in the rule. + Preprocessor rules, which are rules associated with preprocessors and packet decoder detection options in the network analysis policy. Most preprocessor rules are disabled by default.
The Modbus, DNP3, and CIP SCADA preprocessors detect traffic anomalies and provide data to intrusion rules. Therefore in this question only answer A or answer C is correct.
The DNP3 preprocessor detects anomalies in DNP3 traffic and decodes the DNP3 protocol for processing by the rules engine, which uses DNP3 keywords to access certain protocol fields.
The Common Industrial Protocol (CIP) is a widely used application protocol that supports industrial automation applications. EtherNet/IP is an implementation of CIP that is used on Ethernet-based networks.The CIP preprocessor detects CIP and ENIP traffic running on TCP or UDP and sends it to the intrusion rules engine.
You can use CIP and ENIP keywords in custom intrusion rules to detect attacks in CIP and ENIP traffic.
Reference:
Both DNP3 and CIP preprocessors can be used to detect traffic anomalies but we choose CIP as it is widely used in industrial applications.
Note:
Explanation The Modbus, DNP3, and CIP SCADA preprocessors detect traffic anomalies and provide data to intrusion rules. Therefore in this question only answer A or answer C is correct. The DNP3 preprocessor detects anomalies in DNP3 traffic and decodes the DNP3 protocol for processing by the rules engine, which uses DNP3 keywords to access certain protocol fields. The Common Industrial Protocol (CIP) is a widely used application protocol that supports industrial automation applications. EtherNet/IP is an implementation of CIP that is used on Ethernet-based networks.The CIP preprocessor detects CIP and ENIP traffic running on TCP or UDP and sends it to the intrusion rules engine. You can use CIP and ENIP keywords in custom intrusion rules to detect attacks in CIP and ENIP traffic. Reference: https://www.cisco.com/c/en/us/td/docs/security/firepower/630/configuration/guide/fpmc-configguide-v63/scada_preprocessors.html Both DNP3 and CIP preprocessors can be used to detect traffic anomalies but we choose CIP as it is widely used in industrial applications. Note: + An intrusion rule is a specified set of keywords and arguments that the system uses to detect attempts to exploit vulnerabilities in your network. As the system analyzes network traffic, it compares packets against the conditions specified in each rule, and triggers the rule if the data packet meets all the conditions specified in the rule. + Preprocessor rules, which are rules associated with preprocessors and packet decoder detection options in the network analysis policy. Most preprocessor rules are disabled by default.
質問 # 103
管理者はCiscoISE内で新しい許可ポリシーを設定し、デバイスのプロファイリングに問題があります。 RADIUS認証に基づいてプロファイリングされた新しいCiscoIP Phoneの属性は表示されますが、CDPまたはDHCPの属性は表示されません。この問題に対処するには、管理者は何をする必要がありますか?
- A. DHCPインターフェイスでip dhcp snooping trustコマンドを設定して、CiscoISEに情報を取得します。
- B. 適切なプロトコル情報を送信するようにスイッチ内のデバイスセンサー機能を構成します
- C. スイッチ内でサービステンプレートを設定して、ポート設定を標準化し、正しい情報がCiscoISEに送信されるようにします。
- D. Cisco ISE内で認証ポート制御自動機能を設定して、接続しようとしているデバイスを識別します
正解:B
解説:
Reference:
https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/200292-ConfigureDevice-Sensor-f
質問 # 104
ユーザーが認証アクションと登録アクションを分離でき、サーバーからのファイル取得を実行するためのHTTP / TFTPコマンドを指定するオプションを提供するPKI登録方法はどれですか?
- A. 自己署名
- B. ターミナル
- C. プロファイル
- D. url
正解:C
解説:
A trustpoint enrollment mode, which also defines the trustpoint authentication mode, can be performed via 3 main methods: 1. Terminal Enrollment - manual method of performing trustpoint authentication and certificate enrolment using copy-paste in the CLI terminal. 2. SCEP Enrollment - Trustpoint authentication and enrollment using SCEP over HTTP. 3. Enrollment Profile - Here, authentication and enrollment methods are defined separately. Along with terminal and SCEP enrollment methods, enrollment profiles provide an option to specify HTTP/TFTP commands to perform file retrieval from the Server, which is defined using an authentication or enrollment url under the profile. Reference: https://www.cisco.com/c/en/us/support/docs/security-vpn/public-key-infrastructure-pki/211333-IOSPKI-Deployment-Guide-Initial-Design.html
1. Terminal Enrollment - manual method of performing trustpoint authentication and certificate enrolment using copy-paste in the CLI terminal.
2. SCEP Enrollment - Trustpoint authentication and enrollment using SCEP over HTTP.
3. Enrollment Profile - Here, authentication and enrollment methods are defined separately. Along with terminal and SCEP enrollment methods, enrollment profiles provide an option to specify HTTP/TFTP commands to perform file retrieval from the Server, which is defined using an authentication or enrollment url under the profile.
A trustpoint enrollment mode, which also defines the trustpoint authentication mode, can be performed via 3 main methods: 1. Terminal Enrollment - manual method of performing trustpoint authentication and certificate enrolment using copy-paste in the CLI terminal. 2. SCEP Enrollment - Trustpoint authentication and enrollment using SCEP over HTTP. 3. Enrollment Profile - Here, authentication and enrollment methods are defined separately. Along with terminal and SCEP enrollment methods, enrollment profiles provide an option to specify HTTP/TFTP commands to perform file retrieval from the Server, which is defined using an authentication or enrollment url under the profile. Reference: https://www.cisco.com/c/en/us/support/docs/security-vpn/public-key-infrastructure-pki/211333-IOSPKI-Deployment-Guide-Initial-Design.html
質問 # 105
Cisco Security Managerは何を管理していますか?
- A. ASA
- B. ESA
- C. アクセスポイント
- D. WSA
正解:A
解説:
Cisco Security Manager provides a comprehensive management solution for: - Cisco ASA 5500 Series Adaptive Security Appliances - Cisco intrusion prevention systems 4200 and 4500 Series Sensors - Cisco AnyConnect Secure Mobility Client Reference: https://www.cisco.com/c/en/us/products/security/security-manager/index.html
- Cisco ASA 5500 Series Adaptive Security Appliances
- Cisco intrusion prevention systems 4200 and 4500 Series Sensors
- Cisco AnyConnect Secure Mobility Client
Cisco Security Manager provides a comprehensive management solution for: - Cisco ASA 5500 Series Adaptive Security Appliances - Cisco intrusion prevention systems 4200 and 4500 Series Sensors - Cisco AnyConnect Secure Mobility Client Reference: https://www.cisco.com/c/en/us/products/security/security-manager/index.html
質問 # 106
テナントが仮想マシンのOSパッチを担当するクラウドサービスモデルはどれですか?
- A. IaaS
- B. UCaaS
- C. PaaS
- D. SaaS
正解:A
解説:
Only in On-site (on-premises) and IaaS we (tenant) manage O/S (Operating System).
質問 # 107
管理者は、ネットワーク管理システムがSNMPv3を使用してホストをアクティブに監視できるように、ASDMを介してCiscoASAを設定する必要があります。この構成で実行する必要がある2つのタスクはどれですか?
(2つ選択してください。)
- A. コミュニティ文字列を指定します。
- B. SNMPマネージャーとUDPポートを指定します。
- C. SNMPユーザーグループを指定します
- D. SNMPUSMエントリを追加します
- E. SNMPホストアクセスエントリを追加します
正解:C、E
質問 # 108
安全なアプリケーションを構築するために開発者が従わなければならない安全な開発慣行とガイドラインのコレクションから作成されたソリューションはどれですか?
- A. OWASP
- B. Radamsa
- C. AFL
- D. Fuzzing Framework
正解:A
質問 # 109
ACME-Router(config)#loginブロックの結果は何ですか-Cisco IOSルータでの60コマンド内での100回の試行4の場合?
- A. 60秒間に4つの障害が発生した場合、ルータは100秒間クワイエットモードになります。
- B. ログインに4回失敗すると、回線は60秒間ブロックされ、ACL1では許可IPアドレスのみが許可されます。
- C. ログインに4回失敗すると、回線は100秒間ブロックされ、ACLで許可されるIPアドレスのみが許可されます。
- D. 4回のログイン試行が100秒以内に失敗した場合、次のログインプロンプトまで60秒待ちます。
正解:A
質問 # 110
AMP for Endpoints Outbreak Control内の2つのリストタイプは何ですか? (2つ選択してください。)
- A. URL
- B. ブロックされたポート
- C. 許可されたアプリケーション
- D. 単純なカスタム検出
- E. コマンドと制御
正解:C、D
解説:
Advanced Malware Protection (AMP) for Endpoints offers a variety of lists, referred to as Outbreak Control, that allow you to customize it to your needs. The main lists are: Simple Custom Detections, Blocked Applications, Allowed Applications, Advanced Custom Detections, and IP Blocked and Allowed Lists.
A Simple Custom Detection list is similar to a blocked list. These are files that you want to detect and quarantine.
Allowed applications lists are for files you never want to convict. Some examples are a custom application that is detected by a generic engine or a standard image that you use throughout the company Reference: https://docs.amp.cisco.com/AMP%20for%20Endpoints%20User%20Guide.pdf Advanced Malware Protection (AMP) for Endpoints offers a variety of lists, referred to as Outbreak Control, that allow you to customize it to your needs. The main lists are: Simple Custom Detections, Blocked Applications, Allowed Applications, Advanced Custom Detections, and IP Blocked and Allowed Lists.
A Simple Custom Detection list is similar to a blocked list. These are files that you want to detect and quarantine.
Advanced Malware Protection (AMP) for Endpoints offers a variety of lists, referred to as Outbreak Control, that allow you to customize it to your needs. The main lists are: Simple Custom Detections, Blocked Applications, Allowed Applications, Advanced Custom Detections, and IP Blocked and Allowed Lists.
A Simple Custom Detection list is similar to a blocked list. These are files that you want to detect and quarantine.
Allowed applications lists are for files you never want to convict. Some examples are a custom application that is detected by a generic engine or a standard image that you use throughout the company Reference: https://docs.amp.cisco.com/AMP%20for%20Endpoints%20User%20Guide.pdf
質問 # 111
プロファイリングで使用されるエンドポイント属性を収集するために、Cisco ISE は何を使用しますか?
- A. Cisco AnyConnect セキュア モビリティ クライアント
- B. プローブ
- C. 姿勢評価
- D. Cisco pxGrid
正解:B
質問 # 112
エンジニアは、ネットワーク内のCiscoスイッチで802.1X認証を設定し、メカニズムとしてCoAを使用しています。 CoAトラフィックがネットワークを通過できるようにするには、ファイアウォールのどのポートを開く必要がありますか?
- A. UDP 1812
- B. TCP 49
- C. UDP 1700
- D. TCP 6514
正解:C
解説:
質問 # 113
つのDDoS攻撃のカテゴリは何ですか? (2つ選択してください)
- A. sequential
- B. protocol
- C. database
- D. volume-based
- E. screen-based
正解:B、D
解説:
There are three basic categories of attack:
+ volume-based attacks, which use high traffic to inundate the network bandwidth
+ protocol attacks, which focus on exploiting server resources
+ application attacks, which focus on web applications and are considered the most sophisticated and serious type of attacks Reference: https://www.esecurityplanet.com/networks/types-of-ddos-attacks/
質問 # 114
ネットワークエンジニアは、ネットワークに新しい医療機器を追加する任務を負っています。 CiscoISEはSheNACサーバとして使用されており、新しいデバイスには使用可能なサプリカントがありません。このデバイスをネットワークに安全に接続するには、何をする必要がありますか?
- A. プロファイリングでMABを使用する
- B. 姿勢評価でMABを使用します。
- C. プロファイリングで802.1Xを使用します。
- D. 姿勢評価で802.1Xを使用します。
正解:A
解説:
Explanation
As the new device does not have a supplicant, we cannot use 802.1X.
MAC Authentication Bypass (MAB) is a fallback option for devices that don't support 802.1x. It is virtually always used in deployments in some way shape or form. MAB works by having the authenticator take the connecting device's MAC address and send it to the authentication server as its username and password. The authentication server will check its policies and send back an Access-Accept or Access-Reject just like it would with 802.1x.
Cisco ISE Profiling Services provides dynamic detection and classification of endpoints connected to the network. Using MAC addresses as the unique identifier, ISE collects various attributes for each network endpoint to build an internal endpoint database. The classification process matches the collected attributes to prebuilt or user-defined conditions, which are then correlated to an extensive library of profiles. These profiles include a wide range of device types, including mobile clients (iPads, Android tablets, Chromebooks, and so on), desktop operating systems (for example, Windows, Mac OS X, Linux, and others), and numerous non-user systems such as printers, phones, cameras, and game consoles.
Once classified, endpoints can be authorized to the network and granted access based on their profile. For example, endpoints that match the IP phone profile can be placed into a voice VLAN using MAC Authentication Bypass (MAB) as the authentication method. Another example is to provide differentiated network access to users based on the device used. For example, employees can get full access when accessing the network from their corporate workstation but be granted limited network access when accessing the network from their personal iPhone.
質問 # 115
VPNのセキュアハッシュアルゴリズムによって何が提供されますか?
- A. 認証
- B. 鍵交換
- C. 整合性
- D. 暗号化
正解:C
解説:
Reference: https://www.ciscopress.com/articles/article.asp?p=24833&seqNum=4
質問 # 116
どの姿勢評価要件がクライアントに修復のオプションを提供し、特定の時間枠内の修復を必要としますか?
- A. 監査
- B. 可視性
- C. オプション
- D. 必須
正解:D
解説:
https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/admin_guide/b_ISE_admin_guide_24/m_client_posture_ Mandatory Requirements During policy evaluation, the agent provides remediation options to clients who fail to meet the mandatory requirements defined in the posture policy. End users must remediate to meet the requirements within the time specified in the remediation timer settings
質問 # 117
FlexVPNとDMVPNの違いは何ですか?
- A. FlexVPNはIKEv1またはIKEv2を使用し、DMVPNはIKEv2のみを使用します
- B. DMVPNはIKEv1またはIKEv2を使用し、FlexVPNはIKEv1のみを使用します
- C. DMVPNはIKEv1のみを使用しますFlexVPNはIKEv2のみを使用します
- D. FlexVPNはIKEv2を使用し、DMVPNはIKEv1またはIKEv2を使用します
正解:D
質問 # 118
Cisco AMP for Endpointsは、組織がマルウェアのさまざまなファミリを検出するのを支援するために何を使用しますか?
- A. ファジーフィンガープリントを実行するEthos Engine
- B. 電子メールスキャンを実行するためのClam AV Engine
- C. 動的分析を実行するための機械学習を備えたSpero Engine
- D. エンドポイントがクラウドに接続されているときにマルウェアを検出するTetra Engine
正解:A
解説:
ETHOS is the Cisco file grouping engine. It allows us to group families of files together so if we see variants of a malware, we mark the ETHOS hash as malicious and whole families of malware are instantly detected.
ETHOS is the Cisco file grouping engine. It allows us to group families of files together so if we see variants of a malware, we mark the ETHOS hash as malicious and whole families of malware are instantly detected.
ETHOS is the Cisco file grouping engine. It allows us to group families of files together so if we see variants of a malware, we mark the ETHOS hash as malicious and whole families of malware are instantly detected.
Reference:
ETHOS = Fuzzy Fingerprinting using static/passive heuristics
ETHOS = Fuzzy Fingerprinting using static/passive heuristics
質問 # 119
組織のネットワークに接続するマシンに、組織のマルウェアの発生を防ぐために推奨されるウイルス対策の定義とパッチがあることを保証するシスコのプラットフォームはどれですか。
- A. Cisco ISE
- B. Cisco ESA
- C. Cisco WiSM
- D. Cisco Prime Infrastructure
正解:A
解説:
Reference:
https://www.cisco.com/c/en/us/support/docs/security/email-security-appliance/118188-qanda-esa-00.html
質問 # 120
......
合格できるCCNP Security 350-701日本語試験問題集には633問があります:https://www.jpntest.com/shiken/350-701J-mondaishu