CS0-003 試験問題 156

AXSS vulnerability was reported on one of the non-sensitive/non-mission-critical public websites of a company. The security department confirmed the finding and needs to provide a recommendation to the application owner. Which of the following recommendations will best prevent this vulnerability from being exploited? (Select two).
  • CS0-003 試験問題 157

    A security analyst is developing a script to filter firewall vulnerabilities. The script will impact the integrity of data hosted on devices connected to networks. Which of the following is a CVSS v4.0 that the analyst can use to test a true positive for the script?
  • CS0-003 試験問題 158

    脆弱性管理チームは、毎週のスキャンで発見されたすべての脆弱性にパッチを適用することはできません。そこで、以下に示すサードパーティのスコアリングシステムを使用し、最も緊急性の高い脆弱性にパッチを適用します。

    さらに、脆弱性管理チームは、SmearとChanningの指標は他の指標よりも重要度が低いと考えているため、優先度を下げます。上記のサードパーティスコアリングシステムを考慮すると、以下の脆弱性のうちどれを最初にパッチ適用すべきでしょうか?
  • CS0-003 試験問題 159

    A company patches its servers using automation software. Remote SSH or RDP connections are allowed to the servers only from the service account used by the automation software. All servers are in an internal subnet without direct access to or from the internet. An analyst reviews the following vulnerability summary:

    Which of the following vulnerability IDs should the analyst address first?
  • CS0-003 試験問題 160

    A vulnerability scan shows the following issues:
    Asset Type
    CVSS Score
    Exploit Vector
    Workstations
    6.5
    RDP vulnerability
    Storage Server
    9.0
    Unauthorized access due to server application vulnerability
    Firewall
    8.9
    Default password vulnerability
    Web Server
    10.0
    Zero-day vulnerability (vendor working on patch)
    Which of the following actions should the security analyst take first?