SY0-701 無料問題集「CompTIA Security+ Certification」

A Chief Information Security Officer (CISO) has developed information security policies that relate to the software development methodology. Which of the following would the CISO most likely include in the organization's documentation?

As part of new compliance audit requirements, multiple servers need to be segmented on different networks and should be reachable only from authorized internal systems. Which of the following would meet the requirements?

解説: (JPNTest メンバーにのみ表示されます)
While conducting a business continuity tabletop exercise, the security team becomes concerned by potential impacts if a generator fails during failover. Which of the following is the team most likely to consider in regard to risk management activities?

解説: (JPNTest メンバーにのみ表示されます)
Which of the following exercises should an organization use to improve its incident response process?

解説: (JPNTest メンバーにのみ表示されます)
The Chief Information Security Officer wants to put security measures in place to protect PlI. The organization needs to use its existing labeling and classification system to accomplish this goal. Which of the following would most likely be configured to meet the requirements?

解説: (JPNTest メンバーにのみ表示されます)
An organization needs to monitor its users' activities to prevent insider threats. Which of the following solutions would help the organization achieve this goal?

解説: (JPNTest メンバーにのみ表示されます)
A systems administrator is auditing all company servers to ensure. They meet the minimum security baseline While auditing a Linux server, the systems administrator observes the /etc/shadow file has permissions beyond the baseline recommendation. Which of the following commands should the systems administrator use to resolve this issue?

解説: (JPNTest メンバーにのみ表示されます)
A bank insists all of its vendors must prevent data loss on stolen laptops. Which of the following strategies is the bank requiring?

解説: (JPNTest メンバーにのみ表示されます)
A client asked a security company to provide a document outlining the project, the cost, and the completion time frame. Which of the following documents should the company provide to the client?

解説: (JPNTest メンバーにのみ表示されます)
A certificate authority needs to post information about expired certificates. Which of the following would accomplish this task?

解説: (JPNTest メンバーにのみ表示されます)
The physical security team at a company receives reports that employees are not displaying their badges. The team also observes employees tailgating at controlled entrances. Which of the following topics will the security team most likely emphasize in upcoming security training?

解説: (JPNTest メンバーにのみ表示されます)
A company relies on open-source software libraries to build the software used by its customers. Which of the following vulnerability types would be the most difficult to remediate due to the company's reliance on open- source libraries?

解説: (JPNTest メンバーにのみ表示されます)
Which of the following best represents an application that does not have an on-premises requirement and is accessible from anywhere?

解説: (JPNTest メンバーにのみ表示されます)
After reviewing the following vulnerability scanning report:
Server:192.168.14.6
Service: Telnet
Port: 23 Protocol: TCP
Status: Open Severity: High
Vulnerability: Use of an insecure network protocol
A security analyst performs the following test:
nmap -p 23 192.168.14.6 -script telnet-encryption
PORT STATE SERVICE REASON
23/tcp open telnet syn-ack
I telnet encryption:
| _ Telnet server supports encryption
Which of the following would the security analyst conclude for this reported vulnerability?

解説: (JPNTest メンバーにのみ表示されます)
Which of the following is the best way to validate the integrity and availability of a disaster recovery site?

解説: (JPNTest メンバーにのみ表示されます)

弊社を連絡する

我々は12時間以内ですべてのお問い合わせを答えます。

オンラインサポート時間:( UTC+9 ) 9:00-24:00
月曜日から土曜日まで

サポート:現在連絡