JPNTest 350-701日本語問題集630問でCCNP Securityを確実実践 [Q200-Q216]

Share

JPNTest 350-701日本語問題集630問でCCNP Securityを確実実践

リアル最新350-701日本語試験問題350-701日本語問題集

質問 # 200
組織は、CiscoUmbrellaを使用してURLブロッキングを実装しています。ユーザーは一部のサイトにアクセスできますが、エラーのために他のサイトにアクセスできません。エラーが発生するのはなぜですか?

  • A. クライアントコンピュータにCisco Umbrella RootCA証明書がインストールされていません。
  • B. インテリジェントプロキシとSSL復号化がポリシーで無効になっています。
  • C. クライアントコンピューターには、内部CAサーバーから展開されたSSL証明書がありません。
  • D. IP層の強制が構成されていません。

正解:B

解説:
Explanation
https://support.umbrella.com/hc/en-us/articles/115004564126-SSL-Decryption-in-the-Intelligent-Proxy


質問 # 201
電子メールおよびWebトラフィックのIPアドレスのレピュテーションを追跡できるTalosレピュテーションセンターはどれですか?

  • A. AMPレピュテーションセンター
  • B. IPおよびドメインレピュテーションセンター
  • C. ファイルレピュテーションセンター
  • D. IPブラックリストセンター

正解:B


質問 # 202
ネットワーク上で現在発生していることに対する可視性と認識を提供するものは何ですか?

  • A. CMX
  • B. テレメトリ
  • C. プライムインフラストラクチャ
  • D. WMI

正解:B

解説:
Telemetry - Information and/or data that provides awareness and visibility into what is occurring on the network at any given time from networking devices, appliances, applications or servers in which the core function of the device is not to generate security alerts designed to detect unwanted or malicious activity from computer networks. Reference: https://www.cisco.com/c/dam/en_us/about/doing_business/legal/service_descriptions/docs/activethreat-analytics-premier.pdf at any given time from networking devices, appliances, applications or servers in which the core function of the device is not to generate security alerts designed to detect unwanted or malicious activity from computer networks.
Telemetry - Information and/or data that provides awareness and visibility into what is occurring on the network at any given time from networking devices, appliances, applications or servers in which the core function of the device is not to generate security alerts designed to detect unwanted or malicious activity from computer networks. Reference: https://www.cisco.com/c/dam/en_us/about/doing_business/legal/service_descriptions/docs/activethreat-analytics-premier.pdf


質問 # 203
展示を参照してください、

iPsec VPN 接続のトラブルシューティングを試行すると、次のメッセージが表示されるコマンドはどれですか?

  • A. crypto isakmp 接続のデバッグ
  • B. 暗号化 ipsec エンドポイントのデバッグ
  • C. デバッグ暗号 isakmp
  • D. 暗号化 Ipsec のデバッグ

正解:C

解説:
The command that results in these messages when attempting to troubleshoot an iPsec VPN connection is debug crypto isakmp. This command displays debug information about the Internet Key Exchange (IKE) protocol, which is used to establish security associations (SAs) for IPsec VPNs. The messages in the exhibit show various steps and statuses of the IKE negotiation process, such as creating and deleting peer structures, receiving and sending packets, and checking the compatibility of the security policies and proposals. The other commands are either invalid (debug crypto ipsec endpoint and debug crypto isakmp connection) or display different information (debug crypto ipsec shows the details of the IPsec encryption and decryption operations). References:
https://www.cisco.com/c/en/us/training-events/training-certifications/training/training-services/courses/implemen
https://www.cisco.com/c/en/us/support/docs/security-vpn/ipsec-negotiation-ike-protocols/5409-ipsec-debug-00.h


質問 # 204
エンドポイントがネットワークに接続することを許可する前に、どのCiscoISEサービスがエンドポイントのコンプライアンスをチェックしますか。

  • A. Threat Centric NAC
  • B. Cisco TrustSec
  • C. profiler
  • D. posture

正解:D


質問 # 205
組織にポリシーが設定されたCiscoESAがあり、違反に割り当てられたアクションをカスタマイズしたいと考えています。組織は、メッセージのコピーを配信し、メッセージを追加してDLP違反としてフラグを立てることを望んでいます。この機能を提供するには、どのアクションを実行する必要がありますか?

  • A. コピーを他の受信者に配信および送信する
  • B. DLP違反通知を隔離して送信する
  • C. DLP違反でサブジェクトヘッダーを隔離および変更する
  • D. 免責事項のテキストを配信して追加する

正解:D


質問 # 206
Cisco WSAがWeb要求をチェックするとき、ユーザー定義のポリシーに一致できない場合はどうなりますか。

  • A. リクエストをブロックします。
  • B. グローバルポリシーを適用します。
  • C. 高度なポリシーを適用します。
  • D. 次の識別プロファイルポリシーを適用します。

正解:B

解説:
When a Cisco WSA receives a web request, it evaluates it against the policies in the policy table. Each policy type has a predefined, global policy, which maintains default actions for that policy type. If the web request does not match any user-defined policy, the WSA applies the global policy. The global policy can be configured to allow, block, or redirect the web request based on various criteria. The global policy acts as a catch-all policy for any web request that is not explicitly handled by a user-defined policy. References :=
* User Guide for AsyncOS 11.0 for Cisco Web Security Appliances - Create Policies to Control Internet Requests
* User Guide for AsyncOS 12.7 for Cisco Web Security Appliances - LD (Limited Deployment) - Acquire End-User Credentials


質問 # 207
悪意のあるユーザーは、4つの異なるスイッチポートで同時にMABを使用して許可されたプリンター接続をスプーフィングすることにより、ネットワークアクセスを取得しました。それ以上の違反を防ぐ2つの触媒スイッチセキュリティ機能はどれですか? (2つ選択してください)

  • A. DHCPスヌーピング
  • B. IPデバイスの追跡
  • C. プライベートVLAN
  • D. ポートセキュリティ
  • E. 802.1AE MacSec
  • F. 動的ARP検査

正解:A、F


質問 # 208
Firepower Next Generation Intrustion Prevention System検出器を左側から右側の正しい定義にドラッグアンドドロップします。

正解:

解説:

Explanation

Reference:
https://www.cisco.com/c/en/us/td/docs/security/firepower/640/configuration/guide/fpmc-configguide-v64/detecti


質問 # 209
エンジニアは、プロトコルフィールドを分析し、産業用システムからのトラフィックの異常を検出するようにCisco FTDを設定する必要があります。これらの要件を満たすには、何をする必要がありますか。

  • A. DNP3プリプロセッサの侵入ルールを設定します
  • B. CiscoFTDでトラフィック分析を有効にします
  • C. アクセス制御ポリシーを変更して産業用トラフィックを信頼する
  • D. CIPプリプロセッサのプレフィルタポリシーを実装する

正解:D

解説:
Explanation The Modbus, DNP3, and CIP SCADA preprocessors detect traffic anomalies and provide data to intrusion rules. Therefore in this question only answer A or answer C is correct. The DNP3 preprocessor detects anomalies in DNP3 traffic and decodes the DNP3 protocol for processing by the rules engine, which uses DNP3 keywords to access certain protocol fields. The Common Industrial Protocol (CIP) is a widely used application protocol that supports industrial automation applications. EtherNet/IP is an implementation of CIP that is used on Ethernet-based networks.The CIP preprocessor detects CIP and ENIP traffic running on TCP or UDP and sends it to the intrusion rules engine. You can use CIP and ENIP keywords in custom intrusion rules to detect attacks in CIP and ENIP traffic. Reference: https://www.cisco.com/c/en/us/td/docs/security/firepower/630/configuration/guide/fpmc-configguide-v63/scada_preprocessors.html Both DNP3 and CIP preprocessors can be used to detect traffic anomalies but we choose CIP as it is widely used in industrial applications. Note: + An intrusion rule is a specified set of keywords and arguments that the system uses to detect attempts to exploit vulnerabilities in your network. As the system analyzes network traffic, it compares packets against the conditions specified in each rule, and triggers the rule if the data packet meets all the conditions specified in the rule. + Preprocessor rules, which are rules associated with preprocessors and packet decoder detection options in the network analysis policy. Most preprocessor rules are disabled by default.
The Modbus, DNP3, and CIP SCADA preprocessors detect traffic anomalies and provide data to intrusion rules. Therefore in this question only answer A or answer C is correct.
The DNP3 preprocessor detects anomalies in DNP3 traffic and decodes the DNP3 protocol for processing by the rules engine, which uses DNP3 keywords to access certain protocol fields.
The Common Industrial Protocol (CIP) is a widely used application protocol that supports industrial automation applications. EtherNet/IP is an implementation of CIP that is used on Ethernet-based networks.The CIP preprocessor detects CIP and ENIP traffic running on TCP or UDP and sends it to the intrusion rules engine.
You can use CIP and ENIP keywords in custom intrusion rules to detect attacks in CIP and ENIP traffic.
Reference:
Both DNP3 and CIP preprocessors can be used to detect traffic anomalies but we choose CIP as it is widely used in industrial applications.
Note:
Explanation The Modbus, DNP3, and CIP SCADA preprocessors detect traffic anomalies and provide data to intrusion rules. Therefore in this question only answer A or answer C is correct. The DNP3 preprocessor detects anomalies in DNP3 traffic and decodes the DNP3 protocol for processing by the rules engine, which uses DNP3 keywords to access certain protocol fields. The Common Industrial Protocol (CIP) is a widely used application protocol that supports industrial automation applications. EtherNet/IP is an implementation of CIP that is used on Ethernet-based networks.The CIP preprocessor detects CIP and ENIP traffic running on TCP or UDP and sends it to the intrusion rules engine. You can use CIP and ENIP keywords in custom intrusion rules to detect attacks in CIP and ENIP traffic. Reference: https://www.cisco.com/c/en/us/td/docs/security/firepower/630/configuration/guide/fpmc-configguide-v63/scada_preprocessors.html Both DNP3 and CIP preprocessors can be used to detect traffic anomalies but we choose CIP as it is widely used in industrial applications. Note: + An intrusion rule is a specified set of keywords and arguments that the system uses to detect attempts to exploit vulnerabilities in your network. As the system analyzes network traffic, it compares packets against the conditions specified in each rule, and triggers the rule if the data packet meets all the conditions specified in the rule. + Preprocessor rules, which are rules associated with preprocessors and packet decoder detection options in the network analysis policy. Most preprocessor rules are disabled by default.


質問 # 210
マネージドIntercloudFabricデプロイメントモデルの2つのタイプは何ですか? (2つ選択してください。)

  • A. エンタープライズ管理
  • B. ユーザー管理
  • C. パブリックマネージド
  • D. サービスプロバイダーが管理
  • E. ハイブリッドマネージド

正解:A、D

解説:
Explanation


質問 # 211
どのアルゴリズムが非対称暗号化を提供しますか?

  • A. RC4
  • B. 3DES
  • C. AES
  • D. RSA

正解:D

解説:
https://securityboulevard.com/2020/05/types-of-encryption-5-encryption-algorithms-how-to-choose-the-right-one/#:~:text=Standard%20asymmetric%20encryption%20algorithms%20include,%2C%20El%20Gamal%2C%20and%20DSA.


質問 # 212
攻撃者が組織内のユーザーのユーザー名とパスワードを盗むのを防ぐために、どのテクノロジーを使用する必要がありますか?

  • A. RADIUSベースのREAP
  • B. 動的ARP検査
  • C. 多要素認証
  • D. フィンガープリント

正解:C

解説:
Multifactor authentication (MFA) is an authentication method that requires the user to provide two or more verification factors to gain access to a resource such as an application, online account, or a VPN1. MFA is a core component of a strong identity and access management (IAM) policy. MFA can help prevent an attacker from stealing usernames and passwords of users within an organization by adding an extra layer of security beyond the traditional username and password. For example, a user may need to enter a one-time code sent to their phone or email, scan their fingerprint, or use a hardware token to prove their identity. This way, even if an attacker obtains the user's credentials, they cannot access the resource without the second factor2.
The other options are not technologies that can help prevent an attacker from stealing usernames and passwords of users within an organization. RADIUS-based REAP is a protocol that allows wireless clients to authenticate with a RADIUS server, but it does not provide MFA3. Fingerprinting is a technique that identifies the operating system or application of a device based on its network characteristics, but it does not provide MFA4. Dynamic ARP Inspection is a security feature that prevents ARP spoofing attacks by validating ARP packets, but it does not provide MFA5.
References := 1: What is Multi-Factor Authentication (MFA)? |
OneLogin(https://www.onelogin.com/learn/what-is-mfa) 2: What is: Multifactor Authentication - Microsoft Support(https://support.microsoft.com/en-us/topic/what-is-multifactor-authentication-e5e39437-121c-be60-d123 Implementing and Operating Cisco Security Core Technologies (SCOR) v1.0, Module 3: Securing the Network, Lesson 3.3: Secure Wireless Connectivity, Topic 3.3.1: Wireless Security Protocols, page 3-40. 4:
Implementing and Operating Cisco Security Core Technologies (SCOR) v1.0, Module 2: Securing the Cloud, Lesson 2.2: Cloud Security Assessment, Topic 2.2.1: Cloud Security Concepts, page 2-13. 5: Implementing and Operating Cisco Security Core Technologies (SCOR) v1.0, Module 3: Securing the Network, Lesson 3.2:
Secure Network Access, Topic 3.2.2: Layer 2 Security Features, page 3-19.


質問 # 213
展示を参照してください。

Cisco ASAで終端するリモートアクセスVPNソリューションを設定する場合、管理者は、マシン証明書を使用したAAA認証と組み合わせて外部トークン認証メカニズムを利用したいと考えています。これを可能にするには、どの構成アイテムを変更する必要がありますか?

  • A. グループポリシー
  • B. DHCPサーバー
  • C. SAMLサーバー
  • D. メソッド

正解:D

解説:
In order to use AAA along with an external token authentication mechanism, set the "Method" as "Both" in the Authentication.


質問 # 214
CiscoASDMよりもCiscoFMCを使用する利点は何ですか。

  • A. Cisco FMCはデバイスへの設定のプッシュをサポートしていますが、CiscoASDMはサポートしていません。
  • B. Cisco FMCは集中管理を提供しますが、CiscoASDMは提供しません。
  • C. Cisco FMCはすべてのファイアウォール製品をサポートしますが、CiscoASDMはCiscoASAデバイスのみをサポートします
  • D. Cisco FMCはJavaを使用し、CiscoASDMはHTML5を使用します。

正解:B

解説:
Reference:
https://www.cisco.com/c/en/us/products/collateral/security/firesight-management-center/datasheetc78-736775.ht


質問 # 215
Cisco Security Managerは何を管理していますか?

  • A. WSA
  • B. アクセスポイントO
  • C. ESA
  • D. ASA

正解:D

解説:
https://www.cisco.com/c/en/us/products/collateral/security/security-manager/datasheet-C78-737182.html


質問 # 216
......

350-701日本語別格な問題集で最上級の成績にさせる350-701日本語問題:https://www.jpntest.com/shiken/350-701J-mondaishu

弊社を連絡する

我々は12時間以内ですべてのお問い合わせを答えます。

オンラインサポート時間:( UTC+9 ) 9:00-24:00
月曜日から土曜日まで

サポート:現在連絡