無料セールまもなく終了!100%有効350-701日本語試験問題集に727問題と解答が待ってます
検証済み350-701日本語問題集と解答であなたを合格確定させるCCNP Security試験解答!
質問 # 75
VPN関数を左から右の説明にドラッグアンドドロップします。
正解:
解説:
Explanation
質問 # 76
Cisco ASA5500シリーズファイアウォールでNetFlowを許可する2つのタスクはどれですか。 (2つ選択してください)
- A. NetFlowバージョン9を有効にします。
- B. flow-exportコマンドを使用してNetFlowコレクターを定義します
- C. ポート9996でUDPトラフィックを許可するACLを作成します。
- D. NetFlowExporterをインバウンド方向の外部インターフェイスに適用します。
- E. 興味深いトラフィックに一致するクラスマップを作成します。
正解:B、D
質問 # 77
展示を参照してください。
ネットワーク管理者は、admin5ユーザーのコマンド認証を構成します。この設定後、admin5ユーザーはHQ_Routerで何ができますか?
- A. すべての構成を完了します
- B. インターフェースのIPアドレスを設定します
- C. サブインターフェースを追加
- D. 構成を完了しない
正解:D
解説:
Explanation The user "admin5" was configured with privilege level 5. In order to allow configuration (enter global configuration mode), we must type this command: (config)#privilege exec level 5 configure terminal Without this command, this user cannot do any configuration. Note: Cisco IOS supports privilege levels from 0 to 15, but the privilege levels which are used by default are privilege level 1 (user EXEC) and level privilege 15 (privilege EXEC)
質問 # 78
CiscoFirepowerのセキュリティインテリジェンスポリシーを使用して、Firepowerブロックベースの2つの基準はどれですか。
(2つ選択してください)
- A. プロトコルID
- B. ポート番号
- C. MACアドレス
- D. URL
- E. IPアドレス
正解:D、E
解説:
Security Intelligence Sources
...
Custom Block lists or feeds (or objects or groups)
Block specific IP addresses, URLs, or domain names using a manually-created list or feed (for IP addresses, you can also use network objects or groups.) For example, if you become aware of malicious sites or addresses that are not yet blocked by a feed, add these sites to a custom Security Intelligence list and add this custom list to the Block list in the Security Intelligence tab of your access control policy.
Security Intelligence Sources
...
Custom Block lists or feeds (or objects or groups)
Block specific IP addresses, URLs, or domain names using a manually-created list or feed (for IP addresses, you can also use network objects or groups.) For example, if you become aware of malicious sites or addresses that are not yet blocked by a feed, add these sites to a custom Security Intelligence list and add this custom list to the Block list in the Security Intelligence tab of your access control policy.
Reference:
Security Intelligence Sources
...
Custom Block lists or feeds (or objects or groups)
Block specific IP addresses, URLs, or domain names using a manually-created list or feed (for IP addresses, you can also use network objects or groups.) For example, if you become aware of malicious sites or addresses that are not yet blocked by a feed, add these sites to a custom Security Intelligence list and add this custom list to the Block list in the Security Intelligence tab of your access control policy.
質問 # 79
Cisco ESAネットワーク管理者は、新しくインストールされたサービスを使用して、レピュテーション判定に基づいたポリシーの作成を支援するように任命されています。テスト中に、CiscoESAが判定が確定していないファイルをドロップしていないことが判明しました。この問題の原因は何ですか?
- A. ファイルのレピュテーションスコアがしきい値を超えています
- B. ポリシーは、ドロップではなく検疫にメッセージを送信するために作成されました
- C. ポリシーはファイル分析を無効にするために作成されました
- D. ファイルのレピュテーションスコアがしきい値を下回っています
正解:C
解説:
Maybe the "newly installed service" in this question mentions about Advanced Malware Protection (AMP) which can be used along with ESA. AMP allows superior protection across the attack continuum.
+ File Reputation - captures a fingerprint of each file as it traverses the ESA and sends it to AMP's cloudbased intelligence network for a reputation verdict. Given these results, you can automatically block malicious files and apply administrator-defined policy.
+ File Analysis - provides the ability to analyze unknown files that are traversing the ESA. A highly secure sandbox environment enables AMP to glean precise details about the file's behavior and to combine that data with detailed human and machine analysis to determine the file's threat level. This disposition is then fed into AMP cloud-based intelligence network and used to dynamically update and expand the AMP cloud data set for enhanced protection
質問 # 80
脅威を左側から右側の脅威の例にドラッグアンドドロップします
正解:
解説:
質問 # 81
クラウドPaaSモデルのどの2つの側面が、プロバイダーではなく顧客によって管理されていますか? (2つ選択してください。)
- A. ミドルウェア
- B. オペレーティングシステム
- C. データ
- D. アプリケーション
- E. 仮想化
正解:C、D
解説:
Explanation
https://apprenda.com/library/paas/iaas-paas-saas-explained-compared/
質問 # 82
CiscoASDMよりもCiscoFMCを使用する利点は何ですか。
- A. Cisco FMCはすべてのファイアウォール製品をサポートしますが、CiscoASDMはCiscoASAデバイスのみをサポートします
- B. Cisco FMCはJavaを使用し、CiscoASDMはHTML5を使用します。
- C. Cisco FMCはデバイスへの設定のプッシュをサポートしていますが、CiscoASDMはサポートしていません。
- D. Cisco FMCは集中管理を提供しますが、CiscoASDMは提供しません。
正解:D
解説:
https://www.cisco.com/c/en/us/td/docs/security/firepower/compatibility/firepower-compatibility.html
質問 # 83
コンテキストディレクトリエージェントの機能は何ですか?
- A. Active Directoryログを読み取り、IPアドレスをユーザー名にマップします
- B. WebセキュリティアプライアンスからActiveDirectoryにユーザー認証要求を中継します
- C. ユーザーのグループメンバーシップを維持します
- D. ユーザー識別のためにWebセキュリティアプライアンスに代わってユーザー認証要求を受け入れます
正解:A
解説:
Explanation Cisco Context Directory Agent (CDA) is a mechanism that maps IP Addresses to usernames in order to allow security gateways to understand which user is using which IP Address in the network, so those security gateways can now make decisions based on those users (or the groups to which the users belong to). CDA runs on a Cisco Linux machine; monitors in real time a collection of Active Directory domain controller (DC) machines for authentication-related events that generally indicate user logins; learns, analyzes, and caches mappings of IP Addresses and user identities in its database; and makes the latest mappings available to its consumer devices. Reference: https://www.cisco.com/c/en/us/td/docs/security/ibf/cda_10/Install_Config_guide/cda10/ cda_oveviw.html Cisco Context Directory Agent (CDA) is a mechanism that maps IP Addresses to usernames in order to allow security gateways to understand which user is using which IP Address in the network, so those security gateways can now make decisions based on those users (or the groups to which the users belong to).
CDA runs on a Cisco Linux machine; monitors in real time a collection of Active Directory domain controller (DC) machines for authentication-related events that generally indicate user logins; learns, analyzes, and caches mappings of IP Addresses and user identities in its database; and makes the latest mappings available to its consumer devices.
Reference:
Explanation Cisco Context Directory Agent (CDA) is a mechanism that maps IP Addresses to usernames in order to allow security gateways to understand which user is using which IP Address in the network, so those security gateways can now make decisions based on those users (or the groups to which the users belong to). CDA runs on a Cisco Linux machine; monitors in real time a collection of Active Directory domain controller (DC) machines for authentication-related events that generally indicate user logins; learns, analyzes, and caches mappings of IP Addresses and user identities in its database; and makes the latest mappings available to its consumer devices. Reference: https://www.cisco.com/c/en/us/td/docs/security/ibf/cda_10/Install_Config_guide/cda10/ cda_oveviw.html
質問 # 84
Cisco Umbrellaを使用する利点は何ですか?
- A. アプリケーション接続が発生する前に攻撃を軽減できます。
- B. ファイルは、実行が許可される前にウイルスがスキャンされます。
- C. 悪意のあるインバウンドトラフィックを防ぎます。
- D. DNSクエリはより速く解決されます。
正解:A
質問 # 85
脅威を左側から右側の脅威の例にドラッグアンドドロップします
正解:
解説:
質問 # 86
展示を参照してください。
ドメイン名からの長さやサブドメインの数など、DNS要求の任意の機能を使用して、観測値を比較できる予想される動作のモデルを構築できることを考慮してください。これらの値はどのタイプの悪意のある攻撃に関連付けられていますか?
- A. W32/AutoRunワーム
- B. 永遠の青い窓
- C. ハートブリードSSLバグ
- D. スペクターワーム
正解:A
質問 # 87
最近の違反の後、組織は、永続性を取り戻す前に、フィッシングを使用してネットワークへの最初のアクセスを取得したと判断しました。フィッシング攻撃から得られた情報は、ユーザーが既知の悪意のあるWebサイトにアクセスした結果です。これが将来起こるのを防ぐために何をしなければなりませんか?
- A. アクセスポリシーを変更します。
- B. 識別プロファイルを変更します。
- C. アウトバウンドマルウェアスキャンポリシーを変更する
- D. Webプロキシ設定を変更する
正解:D
解説:
Reference:
https://www.cisco.com/c/en/us/td/docs/security/firepower/60/configuration/guide/fpmc-config-guidev60/Access_
質問 # 88
Cisco Tetrationプラットフォームがユーザーの通常の動作を学習できるようにする疑わしいパターンはどれですか?
- A. 別のユーザーからのファイルアクセス
- B. 特権の昇格
- C. 興味深いファイルアクセス
- D. ユーザーログインの疑わしい動作
正解:D
解説:
Explanation Explanation The various suspicious patterns for which the Cisco Tetration platform looks in the current release are: + Shell code execution: Looks for the patterns used by shell code. + Privilege escalation: Watches for privilege changes from a lower privilege to a higher privilege in the process lineage tree. + Side channel attacks: Cisco Tetration platform watches for cache-timing attacks and page table fault bursts. Using these, it can detect Meltdown, Spectre, and other cache-timing attacks. + Raw socket creation: Creation of a raw socket by a nonstandard process (for example, ping). + User login suspicious behavior: Cisco Tetration platform watches user login failures and user login methods. + Interesting file access: Cisco Tetration platform can be armed to look at sensitive files. + File access from a different user: Cisco Tetration platform learns the normal behavior of which file is accessed by which user. + Unseen command: Cisco Tetration platform learns the behavior and set of commands as well as the lineage of each command over time. Any new command or command with a different lineage triggers the interest of the Tetration Analytics platform. Reference: https://www.cisco.com/c/en/us/products/collateral/data-center-analytics/tetration-analytics/whitepaper-c11-740380.html Explanation The various suspicious patterns for which the Cisco Tetration platform looks in the current release are:
+ Shell code execution: Looks for the patterns used by shell code.
+ Privilege escalation: Watches for privilege changes from a lower privilege to a higher privilege in the process lineage tree.
+ Side channel attacks: Cisco Tetration platform watches for cache-timing attacks and page table fault bursts.
Using these, it can detect Meltdown, Spectre, and other cache-timing attacks.
+ Raw socket creation: Creation of a raw socket by a nonstandard process (for example, ping).
+ User login suspicious behavior: Cisco Tetration platform watches user login failures and user login methods.
+ Interesting file access: Cisco Tetration platform can be armed to look at sensitive files.
+ File access from a different user: Cisco Tetration platform learns the normal behavior of which file is accessed by which user.
+ Unseen command: Cisco Tetration platform learns the behavior and set of commands as well as the lineage of each command over time. Any new command or command with a different lineage triggers the interest of the Tetration Analytics platform.
Explanation Explanation The various suspicious patterns for which the Cisco Tetration platform looks in the current release are: + Shell code execution: Looks for the patterns used by shell code. + Privilege escalation: Watches for privilege changes from a lower privilege to a higher privilege in the process lineage tree. + Side channel attacks: Cisco Tetration platform watches for cache-timing attacks and page table fault bursts. Using these, it can detect Meltdown, Spectre, and other cache-timing attacks. + Raw socket creation: Creation of a raw socket by a nonstandard process (for example, ping). + User login suspicious behavior: Cisco Tetration platform watches user login failures and user login methods. + Interesting file access: Cisco Tetration platform can be armed to look at sensitive files. + File access from a different user: Cisco Tetration platform learns the normal behavior of which file is accessed by which user. + Unseen command: Cisco Tetration platform learns the behavior and set of commands as well as the lineage of each command over time. Any new command or command with a different lineage triggers the interest of the Tetration Analytics platform. Reference: https://www.cisco.com/c/en/us/products/collateral/data-center-analytics/tetration-analytics/whitepaper-c11-740380.html
質問 # 89
CiscoASDMよりもCiscoFMCを使用する利点は何ですか。
- A. Cisco FMCはすべてのファイアウォール製品をサポートしますが、CiscoASDMはCiscoASAデバイスのみをサポートします
- B. Cisco FMCはJavaを使用し、CiscoASDMはHTML5を使用します。
- C. Cisco FMCはデバイスへの設定のプッシュをサポートしていますが、CiscoASDMはサポートしていません。
- D. Cisco FMCは集中管理を提供しますが、CiscoASDMは提供しません。
正解:D
解説:
Cisco FTD devices, Cisco Firepower devices, and the Cisco ASA FirePOWER modules can be managed by the Firepower Management Center (FMC), formerly known as the FireSIGHT Management Center -> Answer D is not correct Cisco FTD devices, Cisco Firepower devices, and the Cisco ASA FirePOWER modules can be managed by the Firepower Management Center (FMC), formerly known as the FireSIGHT Management Center -> Answer D is not correct Reference:
Note: The ASA FirePOWER module runs on the separately upgraded ASA operating system
"You cannot use an FMC to manage ASA firewall functions."
The Cisco Secure Firewall Threat Defense Manager (Firepower Management Center) increases the effectiveness of your Cisco network security solutions by providing centralized, integrated, and streamlined management.
Cisco FTD devices, Cisco Firepower devices, and the Cisco ASA FirePOWER modules can be managed by the Firepower Management Center (FMC), formerly known as the FireSIGHT Management Center -> Answer D is not correct Note: The ASA FirePOWER module runs on the separately upgraded ASA operating system
"You cannot use an FMC to manage ASA firewall functions."
The Cisco Secure Firewall Threat Defense Manager (Firepower Management Center) increases the effectiveness of your Cisco network security solutions by providing centralized, integrated, and streamlined management.
Note: The ASA FirePOWER module runs on the separately upgraded ASA operating system
"You cannot use an FMC to manage ASA firewall functions."
The Cisco Secure Firewall Threat Defense Manager (Firepower Management Center) increases the effectiveness of your Cisco network security solutions by providing centralized, integrated, and streamlined management.
質問 # 90
Jenkins、Octopus Deploy、Azure DevOpsなどのツールは、アプリケーションとインフラストラクチャの自動化に関して何を提供しますか?
- A. コンパイル時のインストルメンテーション
- B. 継続的インテグレーションと継続的デプロイ
- C. クラウドアプリケーションセキュリティブローカー
- D. コンテナオーケストレーション
正解:B
解説:
Tools like Jenkins, Octopus Deploy, and Azure DevOps provide continuous integration and continuous deployment (CI/CD) capabilities for application and infrastructure automation. CI/CD is a process that enables developers to deliver code changes more frequently and reliably by automating the building, testing, and deployment stages. CI/CD tools help to integrate various components of the software delivery pipeline, such as source control, testing frameworks, configuration management, security scanning, and deployment platforms. By using CI/CD tools, developers can achieve faster feedback loops, improved quality, reduced errors, and increased efficiency123.
According to the Cisco course on Implementing and Operating Cisco Security Core Technologies (SCOR), CI
/CD is one of the key concepts of DevSecOps, which is a culture and practice that aims to embed security into every stage of the software development lifecycle. DevSecOps requires collaboration and communication between development, security, and operations teams, as well as the use of automation tools and techniques to ensure security is integrated throughout the process45. References: 1: Configuring Jenkins in Azure and deploying with Octopus 2: Octopus Deploy vs. Azure DevOps (VSTS/TFS) 3: Building .NET Core Apps in Azure DevOps and integrating Octopus Deploy 4: Implementing and Operating Cisco Security Core Technologies (SCOR) v1.0 5: 350-701 SCOR - Cisco
質問 # 91
IPsecで使用される2つの暗号化アルゴリズムはどれですか? {2つ選択してください。)
- A. AES-CBC
- B. AES-ABC
- C. トリプルAMC-CBC
- D. AES-BAC
- E. HMAC-SHA1 / SHA2
正解:A、E
解説:
Reference:
https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_conn_vpnips/configuration/15-mt/sec-sec-for-vpns-w-ipsec-15-mt-book/sec-cfg-vpn-ipsec.html
質問 # 92
DMVPNテクノロジーとFlexVPNテクノロジーの共通点は何ですか?
- A. IOSルーターはDMVPNとFlexVPNに対して同じNHRPコードを実行します
- B. FlexVPNとDMVPNは、IS-ISルーティングプロトコルを使用してスポークと通信します
- C. FlexVPNとDMVPNは新しいキー管理プロトコルを使用します
- D. FlexVPNとDMVPNは同じハッシュアルゴリズムを使用します
正解:A
解説:
Reference: https://packetpushers.net/cisco-flexvpn-dmvpn-high-level-design/
質問 # 93
右上の正しい定義に左から火力と次世代侵入防止システム検出器をドロップします。
正解:
解説:
Explanation:
A picture containing table Description automatically generated
質問 # 94
......
350-701日本語試験問題集で100%合格率350-701日本語試験:https://www.jpntest.com/shiken/350-701J-mondaishu