A security analyst needs to harden access to a network. One of the requirements is to authenticate users with smart cards. Which of the following should the analyst enable to best meet this requirement?
A. MS-CHAPv2
B. CHAP
C. PEAP
D. EAP-TLS
正解:D
質問 2:
A company owns a public-facing e-commerce website. The company outsources credit card transactions to a payment company. Which of the following BEST describes the role of the payment company?
A. Data controller
B. Data owners
C. Data processor
D. Data custodian
正解:C
解説: (Pass4Test メンバーにのみ表示されます)
質問 3:
A company needs to provide administrative access to internal resources while minimizing the traffic allowed through the security boundary. Which of the following methods is most secure?
A. Deploying a perimeter network
B. Installing a WAF
C. Implementing a bastion host
D. Utilizing single sign-on
正解:C
質問 4:
A systems analyst is responsible for generating a new digital forensics chain -of- custody form Which of the following should the analyst include in this documentation? (Select two).
A. The order of volatility
B. The provenance of the artifacts
C. A warning banner
D. The date and time
E. A forensics NDA
F. The vendor's name
正解:B,D
解説: (Pass4Test メンバーにのみ表示されます)
質問 5:
A cyber security administrator is using iptables as an enterprise firewall. The administrator created some rules, but the network now seems to be unresponsive. All connections are being dropped by the firewall Which of the following would be the best option to remove the rules?
A. # iptables -P INPUT -j DROP
B. # iptables -t mangle -X
C. # iptables -2
D. # iptables -F
正解:D
解説: (Pass4Test メンバーにのみ表示されます)
質問 6:
An external vendor recently visited a company's headquarters for a presentation. Following the visit, a member of the hosting team found a file that the external vendor left behind on a server. The file contained detailed architecture information and code snippets. Which of the following data types best describes this file?
A. Proprietary
B. Critical
C. Public
D. Government
正解:A
質問 7:
Which of the following best practices gives administrators a set period to perform changes to an operational system to ensure availability and minimize business impacts?
A. Change management boards
B. Blackout plan
C. Impact analysis
D. Scheduled downtime
正解:D
質問 8:
A third-party vendor is moving a particular application to the end-of-life stage at the end of the current year. Which of the following is the most critical risk if the company chooses to continue running the application?
A. Lack of support
B. Lack of source code access
C. Lack of new features
D. Lack of security updates
正解:D
Tazaki -
Pass4Testのこの一つも問題集で合格に必須な基本的知識を 習得できる構成となっていて、SY0-601試験対策には最高に使いやすいと思います。