最新の[2023年12月09日]350-701日本語試験問題集で有効で更新された問題集
無料お試しまもなく終了!100%有効な350-701日本語試験問題集には607問があります
質問 # 124
NetFlowエクスポート形式を左から右の説明にドラッグアンドドロップします。
正解:
解説:
質問 # 125
マルチベンダー環境をサポートし、サイト間のトラフィックを保護できるVPNテクノロジーはどれですか?
- A. SSL VPN
- B. VPNを取得
- C. FlexVPN
- D. DMVPN
正解:C
解説:
FlexVPN is an IKEv2-based VPN technology that provides several benefits beyond traditional site-to-site VPN implementations. FlexVPN is a standards-based solution that can interoperate with non-Cisco IKEv2 implementations. Therefore FlexVPN can support a multivendor environment. All of the three VPN technologies support traffic between sites (site-to-site or spoke-to-spoke).
質問 # 126
セキュリティソリューションを左側から右側に提供するメリットにドラッグアンドドロップします。
正解:
解説:
質問 # 127
Encrypted Traffic Analytics を統合して、可視性の向上、コンプライアンスの促進、応答時間の短縮、環境を保護するための教育的および自動化された決定を提供するために必要な情報を管理者に提供するシスコのソリューションはどれですか?
- A. Cisco SDN
- B. シスコ セキュリティ コンプライアンス ソリューション
- C. Cisco DNA センター
- D. Cisco ISE
正解:B
質問 # 128
ネットワーク管理者は、アクセス制御ポリシーで特定のURLをブロックするルールを構成し、「チャットとインスタントメッセージング」カテゴリを選択しています。この目標を達成するには、どのレピュテーションスコアを選択する必要がありますか?
- A. 0
- B. 1
- C. 2
- D. 3
正解:D
解説:
We choose "Chat and Instant Messaging" category in "URL Category":
To block certain URLs we need to choose URL Reputation from 6 to 10.
質問 # 129
Cisco ASAプラットフォームで有効なREST APIのリクエストはどれですか。 (2つ選択してください。)
- A. connect
- B. push
- C. put
- D. options
- E. get
正解:C、E
質問 # 130
Firepower Next Generation Intrustion Prevention System検出器を左側から右側の正しい定義にドラッグアンドドロップします。
正解:
解説:
Explanation
Reference:
https://www.cisco.com/c/en/us/td/docs/security/firepower/640/configuration/guide/fpmc-configguide-v64/detecti
質問 # 131
VPNに接続していないリモートユーザーをフィッシング攻撃から保護するシスコのセキュリティソリューションはどれですか。
- A. Cisco Firepower
- B. Cisco Stealthwatch
- C. Cisco Umbrella
- D. NGIPS
正解:C
質問 # 132
説明を左側から右側の正しいプロトコルバージョンにドラッグアンドドロップします。
正解:
解説:
Explanation
質問 # 133
ある組織では、LAN 上のクライアントに IP アドレスを割り当てるように DHCP サーバーをセットアップしています。LAN スイッチが悪意のある DHCP トラフィックを防止し、同時に IP アドレスを正しいエンドポイントに配布するには、何を行う必要がありますか?
- A. DHCP スヌーピングを構成し、すべてのクライアント接続に対して信頼できるインターフェイスを設定します。
- B. DHCP スヌーピング データベースでダイナミック ARP インスペクションとアンチスプーフィング ACL を構成します。
- C. 動的 ARP インスペクションを構成し、DHCP スヌーピング データベースにエントリを追加します。
- D. DHCP スヌーピングを構成し、DHCP サーバーの信頼できるインターフェイスを設定します。
正解:A
質問 # 134
CiscoFirepowerがCiscoTalosから脅威インテリジェンスアップデートをダウンロードするタイミングを表す用語はどれですか。
- A. 分析
- B. 消費
- C. 共有
- D. オーサリング
正解:B
解説:
... we will showcase Cisco Threat Intelligence Director (CTID) an exciting feature on Cisco's Firepower Management Center (FMC) product offering that automates the operationalization of threat intelligence. TID has the ability to consume threat intelligence via STIX over TAXII and allows uploads/downloads of STIX and simple blacklists. Reference: https://blogs.cisco.com/developer/automate-threat-intelligence-using-cisco-threat-intelligencedirector
... we will showcase Cisco Threat Intelligence Director (CTID) an exciting feature on Cisco's Firepower Management Center (FMC) product offering that automates the operationalization of threat intelligence. TID has the ability to consume threat intelligence via STIX over TAXII and allows uploads/downloads of STIX and simple blacklists. Reference: https://blogs.cisco.com/developer/automate-threat-intelligence-using-cisco-threat-intelligencedirector
質問 # 135
CiscoASDMよりもCiscoFMCを使用する利点は何ですか。
- A. Cisco FMCはすべてのファイアウォール製品をサポートしますが、CiscoASDMはCiscoASAデバイスのみをサポートします
- B. Cisco FMCは集中管理を提供しますが、CiscoASDMは提供しません。
- C. Cisco FMCはデバイスへの設定のプッシュをサポートしていますが、CiscoASDMはサポートしていません。
- D. Cisco FMCはJavaを使用し、CiscoASDMはHTML5を使用します。
正解:B
解説:
Cisco FTD devices, Cisco Firepower devices, and the Cisco ASA FirePOWER modules can be managed by the Firepower Management Center (FMC), formerly known as the FireSIGHT Management Center -> Answer D is not correct Cisco FTD devices, Cisco Firepower devices, and the Cisco ASA FirePOWER modules can be managed by the Firepower Management Center (FMC), formerly known as the FireSIGHT Management Center -> Answer D is not correct Reference:
Note: The ASA FirePOWER module runs on the separately upgraded ASA operating system
"You cannot use an FMC to manage ASA firewall functions."
The Cisco Secure Firewall Threat Defense Manager (Firepower Management Center) increases the effectiveness of your Cisco network security solutions by providing centralized, integrated, and streamlined management.
Cisco FTD devices, Cisco Firepower devices, and the Cisco ASA FirePOWER modules can be managed by the Firepower Management Center (FMC), formerly known as the FireSIGHT Management Center -> Answer D is not correct Note: The ASA FirePOWER module runs on the separately upgraded ASA operating system
"You cannot use an FMC to manage ASA firewall functions."
The Cisco Secure Firewall Threat Defense Manager (Firepower Management Center) increases the effectiveness of your Cisco network security solutions by providing centralized, integrated, and streamlined management.
Note: The ASA FirePOWER module runs on the separately upgraded ASA operating system
"You cannot use an FMC to manage ASA firewall functions."
The Cisco Secure Firewall Threat Defense Manager (Firepower Management Center) increases the effectiveness of your Cisco network security solutions by providing centralized, integrated, and streamlined management.
質問 # 136
ASAブリッジグループの導入は、ブリッジグループごとにいくつのインターフェイスをサポートしますか?
- A. 最大8
- B. 最大2
- C. 最大4
- D. 最大16
正解:C
質問 # 137
展示を参照してください。
組織は、ネットワーク内でDHCPスヌーピングを使用しています。新しいスイッチのVLAN41のユーザーが、IPアドレスが取得されていないと不満を言っています。ユーザーにネットワーク接続を提供するには、スイッチインターフェイスでどのコマンドを構成する必要がありますか?
- A. ip dhcp snooping verify mac-address
- B. ip dhcp snooping limit 41
- C. ip dhcp snooping trust
- D. ip dhcp snooping vlan 41
正解:C
解説:
Explanation
https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst6500/ios/12-2SX/configuration/guide/book/snoodhcp
質問 # 138
クライアント ワークステーションの応答時間が極端に遅くなります。エンジニアは、攻撃者が傍受して独立した接続を作成し、被害者間でメッセージを中継して、プライベート接続を介して互いに話していると思わせるのではないかと疑っています。このタイプの攻撃から解放するには、どの機能を有効にして構成する必要がありますか?
- A. リバース ARP
- B. リンクアグリゲーション
- C. プライベート VLAN
- D. ダイナミック ARP インスペクション
正解:D
質問 # 139
展示を参照してください。
この出力を表示するために使用されたコマンドはどれですか?
- A. dot1xすべての要約を表示
- B. dot1xを表示
- C. dot1xインターフェースgi1 / 0/12を表示
- D. dot1xすべてを表示
正解:D
質問 # 140
展示を参照してください。
この構成では、15という数字は何を表していますか?
- A. ルーターにアクセスできるSNMPデバイスを識別するアクセスリスト
- B. SNMPv3認証試行間の秒単位の間隔
- C. このルーターに対する許可されたユーザーの特権レベル
- D. SNMPv3ユーザーがロックアウトされるまでに失敗した可能性のある試行の数
正解:A
解説:
The syntax of this command is shown below:
snmp-server group [group-name {v1 | v2c | v3 [auth | noauth | priv]}] [read read-view] [write write-view] [notify notify-view] [access access-list] The command above restricts which IP source addresses are allowed to access SNMP functions on the router. You could restrict SNMP access by simply applying an interface ACL to block incoming SNMP packets that don't come from trusted servers. However, this would not be as effective as using the global SNMP commands shown in this recipe. Because you can apply this method once for the whole router, it is much simpler than applying ACLs to block SNMP on all interfaces separately. Also, using interface ACLs would block not only SNMP packets intended for this router, but also may stop SNMP packets that just happened to be passing through on their way to some other destination device.
質問 # 141
crypto isakmp key ciscXXXXXXXX address 172.16.0.0コマンドを実行した結果はどうなりますか?
- A. キーciscXXXXXXXXを使用して、172.16.0.0 / 32ピアのIPアドレスを認証します
- B. キーciscXXXXXXXXを使用して、IKEExchange内のすべての証明書を保護します
- C. キーciscXXXXXXXXを使用して、172.16.0.0 / 16の範囲のIKEv1ピアを認証します
- D. キーciscXXXXXXXXを使用して、172.16.0.0 / 16の範囲のIKEv2ピアを認証します
正解:C
解説:
Configure a Crypto ISAKMP Key
In order to configure a preshared authentication key, enter the crypto isakmp key command in global configuration mode:
crypto isakmp key cisco123 address 172.16.1.1
https://community.cisco.com/t5/vpn/isakmp-with-0-0-0-0-dmvpn/td-p/4312380 It is a bad practice but it is valid. 172.16.0.0/16 the full range will be accepted as possible PEER
https://www.examtopics.com/discussions/cisco/view/46191-exam-350-701-topic-1-question-71-discussion/#:~:text=Command%20reference%20is%20not%20decisive,172.16.1.128%20cisco123%0ACSR%2D1(config)%23 Testing without a netmask shows that command interpretation has a preference for /16 and /24. CSR-1(config)#crypto isakmp key cisco123 address 172.16.0.0 CSR-1(config)#do show crypto isakmp key | i cisco default 172.16.0.0 [255.255.0.0] cisco123 CSR-1(config)#no crypto isakmp key cisco123 address 172.16.0.0 CSR-1(config)#crypto isakmp key cisco123 address 172.16.1.0 CSR-1(config)#do show crypto isakmp key | i cisco default 172.16.1.0 [255.255.255.0] cisco123 CSR-1(config)#no crypto isakmp key cisco123 address 172.16.1.0 CSR-1(config)#crypto isakmp key cisco123 address 172.16.1.128 CSR-1(config)#do show crypto isakmp key | i cisco default 172.16.1.128 cisco123 CSR-1(config)#
質問 # 142
フィッシング攻撃やソーシャルエンジニアリング攻撃の犠牲になる可能性を最小限に抑えるために使用されている2つのエンドポイント対策はどれですか。 (2つ選択してください。)
- A. クロスサイトスクリプティング用のパッチ。
- B. エンドポイントでの入力検証と文字エスケープから保護します。
- C. スパムおよびウイルスメールフィルターをインストールします。
- D. 最新のマルウェア対策プログラムでシステムを保護します。
- E. プライベートクラウドへのバックアップを実行します。
正解:B、D
質問 # 143
欺瞞的なフィッシングとスピアフィッシングの違いは何ですか?
- A. スピアフィッシングとは、攻撃が組織の経営幹部を狙ったものです。
- B. 詐欺的なフィッシングは、被害者のDNSサーバーを乗っ取って操作し、ユーザーを偽のWebページにリダイレクトします。
- C. 詐欺的なフィッシングは、経営幹部レベルの役割を持つ組織内の特定のユーザーを狙った攻撃です。
- D. スピアフィッシングキャンペーンは、特定の個人とグループの人々を対象としています。
正解:D
解説:
Explanation
In deceptive phishing, fraudsters impersonate a legitimate company in an attempt to steal people's personal data or login credentials. Those emails frequently use threats and a sense of urgency to scare users into doing what the attackers want.
Spear phishing is carefully designed to get a single recipient to respond. Criminals select an individual target within an organization, using social media and other public information - and craft a fake email tailored for that person.
質問 # 144
管理者がプライベートクラウド管理のためにスイッチをDCNMに追加する方法を制御できるように、ファブリックにスイッチを追加するために使用する必要がある2つの方法はどれですか。(2つ選択してください。)
- A. PowerOn自動プロビジョニング
- B. シードIP
- C. CDP AutoDiscovery
- D. Cisco Cloud Director
- E. CiscoPrimeインフラストラクチャ
正解:A、B
質問 # 145
組織はネットワークセキュリティにCiscoFirepowerとCiscoMeraki MXを使用しており、これらのプラットフォーム全体でクラウドポリシーを一元管理する必要があります。この目標を達成するには、どのソフトウェアを使用する必要がありますか?
- A. Cisco DNA Center
- B. Cisco Secureworks
- C. Cisco Configuration Professional
- D. Cisco Defense Orchestrator
正解:D
解説:
Explanation Explanation Cisco Defense Orchestrator is a cloud-based management solution that allows you to manage security policies and device configurations with ease across multiple Cisco and cloud-native security platforms. Cisco Defense Orchestrator features: .... Management of hybrid environments: Managing a mix of firewalls running the ASA, FTD, and Meraki MX software is now easy, with the ability to share policy elements across platforms. Reference: https://www.cisco.com/c/en/us/products/collateral/security/defense-orchestrator/datasheet-c78- 736847.html Explanation Cisco Defense Orchestrator is a cloud-based management solution that allows you to manage security policies and device configurations with ease across multiple Cisco and cloud-native security platforms.
Cisco Defense Orchestrator features:
....
Management of hybrid environments: Managing a mix of firewalls running the ASA, FTD, and Meraki MX software is now easy, with the ability to share policy elements across platforms.
Reference:
Explanation Explanation Cisco Defense Orchestrator is a cloud-based management solution that allows you to manage security policies and device configurations with ease across multiple Cisco and cloud-native security platforms. Cisco Defense Orchestrator features: .... Management of hybrid environments: Managing a mix of firewalls running the ASA, FTD, and Meraki MX software is now easy, with the ability to share policy elements across platforms. Reference: https://www.cisco.com/c/en/us/products/collateral/security/defense-orchestrator/datasheet-c78- 736847.html
質問 # 146
......
350-701日本語試験問題集で100%高得点させる350-701日本語試験解答がこちら:https://www.jpntest.com/shiken/350-701J-mondaishu