[2024年09月03日] 完全版には更新されたのはCertified Cybersecurity Associate(PCCET)認定サンプル問題 [Q69-Q91]

Share

[2024年09月03日] 完全版には更新されたのはCertified Cybersecurity Associate(PCCET)認定サンプル問題

最新のPalo Alto Networks PCCETリアル試験問題集PDF


Palo Alto Networks PCCET(Palo Alto Networks Certified Cybersecurity Entry-level Technician)認定試験は、Palo Alto Networksが提供する高く評価され、広く認知されている認定試験です。この認定は、サイバーセキュリティの分野に初めて参入し、キャリアを開始するための知識とスキルの基礎を築きたい個人を対象としています。PCCET認定試験は、ネットワークセキュリティ、クラウドセキュリティ、暗号化、サイバー脅威インテリジェンスを含む、基礎的なサイバーセキュリティの概念、原則、用語に対する個人の理解を検証します。


PCCET認定に加えて、Palo Alto Networksは、より経験豊富なプロフェッショナルを対象とした高度なサイバーセキュリティのトピックをカバーする、PCNSA(Palo Alto Networks Certified Network Security Administrator)およびPCNSE(Palo Alto Networks Certified Network Security Engineer)などの他のサイバーセキュリティ認定を提供しています。

 

質問 # 69
In the attached network diagram, which device is the switch?

  • A. D
  • B. B
  • C. A
  • D. C

正解:A


質問 # 70
On which security principle does virtualization have positive effects?

  • A. non-repudiation
  • B. confidentiality
  • C. availability
  • D. integrity

正解:C


質問 # 71
In which phase of the cyberattack lifecycle do attackers establish encrypted communication channels back to servers across the internet so that they can modify their attack objectives and methods?

  • A. actions on the objective
  • B. command and control
  • C. installation
  • D. exploitation

正解:B

解説:
Command and Control: Attackers establish encrypted communication channels back to command-and-control (C2) servers across the internet so that they can modify their attack objectives and methods as additional targets of opportunity are identified within the victim network, or to evade any new security countermeasures that the organization may attempt to deploy if attack artifacts are discovered.


質問 # 72
What should a security operations engineer do if they are presented with an encoded string during an incident investigation?

  • A. Run it against VirusTotal.
  • B. Append it to the investigation notes but do not alter it.
  • C. Save it to a new file and run it in a sandbox.
  • D. Decode the string and continue the investigation.

正解:D


質問 # 73
When signature-based antivirus software detects malware, what three things does it do to provide protection? (Choose three.)

  • A. decrypt the infected file using base64
  • B. remove the infected file's extension
  • C. quarantine the infected file
  • D. delete the infected file
  • E. alert system administrators

正解:B、C、D


質問 # 74
In which step of the cyber-attack lifecycle do hackers embed intruder code within seemingly innocuous files?

  • A. reconnaissance
  • B. delivery
  • C. exploitation
  • D. weaponization

正解:D

解説:
"Weaponization: Next, attackers determine which methods to use to compromise a target endpoint. They may choose to embed intruder code within seemingly innocuous files such as a PDF or Microsoft Word document or email message."


質問 # 75
On an endpoint, which method should you use to secure applications against exploits?

  • A. strong user passwords
  • B. software patches
  • C. endpoint-based firewall
  • D. full-disk encryption

正解:C


質問 # 76
Which characteristic of serverless computing enables developers to quickly deploy application code?

  • A. Uploading cloud service autoscaling services to deploy more virtual machines to run their application code based on user demand
  • B. Uploading the application code itself, without having to provision a full container image or any OS virtual machine components
  • C. Using Container as a Service (CaaS) to deploy application containers to run their code.
  • D. Using cloud service spot pricing to reduce the cost of using virtual machines to run their application code

正解:B

解説:
Explanation
"In serverless apps, the developer uploads only the app package itself, without a full container image or any OS components. The platform dynamically packages it into an image, runs the image in a container, and (if needed) instantiates the underlying host OS and VM and the hardware required to run them."


質問 # 77
Which security component should you configure to block viruses not seen and blocked by the perimeter firewall?

  • A. strong endpoint passwords
  • B. endpoint NIC ACLs
  • C. endpoint disk encryption
  • D. endpoint antivirus software

正解:D

解説:
Endpoint antivirus software is a type of software designed to help detect, prevent, and eliminate malware on devices, such as laptops, desktops, smartphones, and tablets. Endpoint antivirus software can block viruses that are not seen and blocked by the perimeter firewall, which is a network security device that monitors and controls incoming and outgoing network traffic based on predefined security rules. Perimeter firewall can block some known viruses, but it may not be able to detect and stop new or unknown viruses that use advanced techniques to evade detection. Endpoint antivirus software can provide an additional layer of protection by scanning the files and processes on the devices and using various methods, such as signatures, heuristics, behavior analysis, and cloud-based analysis, to identify and remove malicious code123. Reference:
What Is Endpoint Antivirus? Key Features & Solutions Explained - Trellix Microsoft Defender for Endpoint | Microsoft Security Download ESET Endpoint Antivirus | ESET


質問 # 78
What type of address translation does a NAT perform?

  • A. Physical Io logical
  • B. Private to public
  • C. Logical to physical
  • D. Public to private

正解:B

解説:
NAT stands for Network Address Translation, which is a process that allows devices on a private network to communicate with devices on a public network, such as the Internet. NAT translates the private IP addresses of the devices on the private network to public IP addresses that can be routed on the public network. This way, multiple devices on the private network can share a single public IP address and access the Internet. NAT also provides security benefits, as it hides the internal network structure and IP addresses from the outside world. Reference: Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET), Fundamentals of Network Security, Network Address Translation (NAT)


質問 # 79
Which three services are part of Prisma SaaS? (Choose three.)

  • A. Data Exposure Control
  • B. Data Loss Prevention
  • C. Denial of Service
  • D. DevOps
  • E. Threat Prevention

正解:A、B、E


質問 # 80
During the OSI layer 3 step of the encapsulation process, what is the Protocol Data Unit (PDU) called when the IP stack adds source (sender) and destination (receiver) IP addresses?

  • A. Data
  • B. Packet
  • C. Frame
  • D. Segment

正解:B


質問 # 81
Which type of LAN technology is being displayed in the diagram?

  • A. Mesh Topology
  • B. Star Topology
  • C. Bus Topology
  • D. Spine Leaf Topology

正解:B


質問 # 82
Which term describes data packets that move in and out of the virtualized environment from the host network or a corresponding traditional data center?

  • A. Intrazone traffic
  • B. North-South traffic
  • C. East-West traffic
  • D. Interzone traffic

正解:B

解説:
North-South traffic refers to the data packets that move between the virtualized environment and the external network, such as the internet or a traditional data center. This traffic typically involves requests from clients to access applications or services hosted on virtual machines (VMs) or containers, or responses from those VMs or containers to the clients. North-South traffic can also include management or monitoring traffic from external devices to the virtualized environment. Reference: Fundamentals of Cloud Security, East-West and North-South Traffic Security, What is the meaning / origin of the terms north-south and east-west traffic?


質問 # 83
Which endpoint product from Palo Alto Networks can help with SOC visibility?

  • A. WildFire
  • B. Cortex XDR
  • C. AutoFocus
  • D. STIX

正解:B

解説:
Cortex XDR is an endpoint product from Palo Alto Networks that can help with SOC visibility by allowing you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view all the alerts from all Palo Alto Networks products in one place, and to perform root cause analysis and automated response actions. Cortex XDR also integrates with other Palo Alto Networks products, such as WildFire, AutoFocus, and Cortex Data Lake, to provide comprehensive threat intelligence and data enrichment12. Reference:
SOC Services - Palo Alto Networks
Endpoint Protection - Palo Alto Networks
Security Operations | Palo Alto Networks
Cortex - Palo Alto Networks


質問 # 84
Which endpoint tool or agent can enact behavior-based protection?

  • A. DNS Security
  • B. Cortex XDR
  • C. AutoFocus
  • D. MineMeld

正解:B

解説:
Explanation


質問 # 85
Which option describes the "selective network security virtualization" phase of incrementally transforming data centers?

  • A. during the selective network security virtualization phase, all intra-host traffic is forwarded to a Web proxy server
  • B. during the selective network security virtualization phase, all intra-host communication paths are strictly controlled
  • C. during the selective network security virtualization phase, all intra-host traffic is load balanced
  • D. during the selective network security virtualization phase, all intra-host traffic is encapsulated and encrypted using the IPSEC protocol

正解:B

解説:
Selective network security virtualization: Intra-host communications and live migrations are architected at this phase. All intra-host communication paths are strictly controlled to ensure that traffic between VMs at different trust levels is intermediated either by an on-box, virtual security appliance or by an off-box, physical security appliance.


質問 # 86
Which security component can detect command-and-control traffic sent from multiple endpoints within a corporate data center?

  • A. Port-based firewall
  • B. Stateless firewall
  • C. Personal endpoint firewall
  • D. Next-generation firewall

正解:D

解説:
A next-generation firewall (NGFW) is a security component that can detect command-and-control (C2) traffic sent from multiple endpoints within a corporate data center. A NGFW is a network device that combines traditional firewall capabilities with advanced features such as application awareness, intrusion prevention, threat intelligence, and cloud-based analysis. A NGFW can identify and block C2 traffic by inspecting the application layer protocols, signatures, and behaviors of the network traffic, as well as correlating the traffic with external sources of threat intelligence. A NGFW can also leverage inline cloud analysis to detect and prevent zero-day C2 threats in real-time. A NGFW can provide granular visibility and control over the network traffic, as well as generate alerts and reports on the C2 activity. Reference:
Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET) Command and Control, Tactic TA0011 - Enterprise | MITRE ATT&CK Advanced Threat Prevention: Inline Cloud Analysis - Palo Alto Networks


質問 # 87
In which two cloud computing service models are the vendors responsible for vulnerability and patch management of the underlying operating system? (Choose two.)

  • A. SaaS
  • B. PaaS
  • C. On-premises
  • D. IaaS

正解:A、B


質問 # 88
The customer is responsible only for which type of security when using a SaaS application?

  • A. physical
  • B. data
  • C. infrastructure
  • D. platform

正解:B

解説:
Data security is the only type of security that the customer is fully responsible for when using a SaaS application. Data security refers to the protection of data from unauthorized access, use, modification, deletion, or disclosure. Data security includes aspects such as encryption, backup, recovery, access control, and compliance12. The customer is responsible for ensuring that their data is secure in transit and at rest, and that they comply with any applicable regulations or policies regarding their data.
The other types of security - physical, platform, and infrastructure - are the responsibility of the SaaS provider. Physical security refers to the protection of the hardware and facilities that host the SaaS application. Platform security refers to the protection of the software and services that run the SaaS application. Infrastructure security refers to the protection of the network and systems that support the SaaS application. The SaaS provider is responsible for ensuring that these layers of security are maintained and updated, and that they meet the required standards and certifications34. Reference:
SaaS and the Shared Security Model
A Guide to SaaS Shared Responsibility Model
The Shared Responsibility Model for Security in The Cloud (IaaS, PaaS & SaaS) Shared responsibility in the cloud


質問 # 89
In addition to integrating the network and endpoint components, what other component does Cortex integrate to speed up IoC investigations?

  • A. Cloud
  • B. Computer
  • C. Infrastructure
  • D. Switch

正解:A

解説:
Explanation
Cortex XDR breaks the silos of traditional detection and response by natively integrating network, endpoint, and cloud data to stop sophisticated attacks


質問 # 90
Which network firewall operates up to Layer 4 (Transport layer) of the OSI model and maintains information about the communication sessions which have been established between hosts on trusted and untrusted networks?

  • A. Group policy
  • B. Stateless
  • C. Static packet-filter
  • D. Stateful

正解:D

解説:
Explanation
Stateful packet inspection firewalls Second-generation stateful packet inspection (also known as dynamic packet filtering) firewalls have the following characteristics:
They operate up to Layer 4 (Transport layer) of the OSI model and maintain state information about the communication sessions that have been established between hosts on the trusted and untrusted networks.
They inspect individual packet headers to determine source and destination IP address, protocol (TCP, UDP, and ICMP), and port number (during session establishment only) to determine whether the session should be allowed, blocked, or dropped based on configured firewall rules.
After a permitted connection is established between two hosts, the firewall creates and deletes firewall rules for individual connections as needed, thus effectively creating a tunnel that allows traffic to flow between the two hosts without further inspection of individual packets during the session.
This type of firewall is very fast, but it is port-based and it is highly dependent on the trustworthiness of the two hosts because individual packets aren't inspected after the connection is established.


質問 # 91
......

Palo Alto Networks PCCET問題集で一発合格を目指すならこれ!:https://jp.fast2test.com/PCCET-premium-file.html

PCCET練習テスト問題更新されたのは160問があります:https://drive.google.com/open?id=1ixY0jr0qmxvJdWBoU5auZhPthfVcWJwf


弊社を連絡する

我々は12時間以内ですべてのお問い合わせを答えます。

我々の働いている時間: ( GMT 0:00-15:00 )
月曜日から土曜日まで

サポート: 現在連絡 

English Deutsch 繁体中文 한국어