CIW 1D0-671 試験概要:
| 認定ベンダー: | CIW (Certification Partners, LLC) |
| 試験名: | CIW Web Security Associate |
| 試験番号: | 1D0-671 |
| 認定の有効期間: | 無期限(有効期限なし、CIWのポリシーに準拠) |
| 試験時間: | 90 minutes |
| 受験料: | $150–$200 USD |
| 出題数: | 50-60 |
| 合格点: | 74% |
| 対応言語: | English |
| 試験形式: | 多肢選択式, 監督付き試験 |
| 推奨トレーニング: | CIW Web Security Associate トレーニング |
| 受験申し込み: | CIW認定ポータル CIW公式試験ページ |
| サンプル問題: | CIW 1D0-671 サンプル問題 |
| 受験方法: | オンライン監督付き試験またはテストセンター(地域に応じて Pearson VUE または Certiport から配信) |
| 前提条件: | ネットワークおよびWeb技術の基礎知識があることが推奨されます |
| 公式シラバスのURL: | https://www.ciwcertified.com |
CIW 1D0-671 試験シラバストピック:
| セクション | 目標 |
|---|---|
| トピック 1: インシデント対応とリスク管理 | - リスクアセスメントの基礎 - インシデント対応ライフサイクル |
| トピック 2: ネットワークとインターネットセキュリティ | - ネットワークセキュリティアーキテクチャ - インターネット経由の安全な通信 |
| トピック 3: アイデンティティとアクセス管理 | - 認証と認可 - アクセス制御方法 |
| トピック 4: 脅威、脆弱性、および攻撃 | - Webアプリケーション攻撃 - マルウェアとエクスプロイトの種類 |
| トピック 5: セキュリティポリシーとコンプライアンス | - セキュリティガバナンス - 規制とコンプライアンスの基礎 |
| トピック 6: セキュリティの基礎 | - セキュリティの基本概念 - セキュリティ原則とモデル |
| トピック 7: 暗号技術 | - 暗号化の基礎 - ハッシュとデジタル署名 |
CIW Web Security Associate 認定 1D0-671 試験問題:
1. Consider the following series of commands from a Linux system:
iptables -A input -p icmp -s 0/0 -d 0/0 -j REJECT
Which explanation best describes the impact of the resulting firewall ruleset?
A) Individuals on remote networks will not be able to use ping to troubleshoot connections.
B) Individuals on remote networks will no longer be able to use SSH to control internal network resources.
C) Stateful multi-layer inspection has been enabled.
D) Internal hosts will not be able to ping each other using ICMP.
2. Requests for Web-based resources have become unacceptably slow. You have been assigned to implement a solution that helps solve this problem.
Which of the following would you recommend?
A) Implement a screening router on the network DMZ
B) Enable stateful multi-layer inspection on the packet filter
C) Implement caching on the network proxy server
D) Enable authentication on the network proxy server
3. Which algorithm can use a 128-bit key, and has been adopted as a standard by various governments and corporations?
A) MARS
B) International Data Encryption Algorithm (IDEA)
C) Advanced Encryption Standard (AES)
D) RC2
4. Consider the following diagram:
Which of the following best describes the protocol activity shown in the diagram, along with the most likely potential threat that accompanies this protocol?
A) The ICMP Time Exceeded message, with the threat of a denial-of-service attack
B) The SIP three-way handshake, with the threat of a buffer overflow
C) The DNS name query, with the threat of cache poisoning
D) The TCP three-way handshake, with the threat of a man-in-the-middle attack
5. Consider the following diagram involving two firewall-protected networks:
Which of the following is necessary for each of the firewalls to allow private IP addresses to be passed on to the Internet?
A) DMZ creation
B) Chargeback
C) Masquerading
D) Stateful multi-layer inspection
質問と回答:
| 質問 # 1 正解: A | 質問 # 2 正解: C | 質問 # 3 正解: C | 質問 # 4 正解: D | 質問 # 5 正解: C |














1046 お客様のコメント
品質保証JPexamはIT認定試験のシラバスに従って、試験問題の範囲を正確に絞って、的中率が99%の最新問題集を捧げます。
1年間の無料更新サービスJPexamは1年以内に問題集の無料更新サービスを提供し、お客様がいつでも最新版の問題集を持つことを保証いたします。もし試験の内容が変更されたら、弊社は直ちにお客様にお知らせします。それに、弊社の問題集が更新されたら、早速メールで最新バージョンを送付いたします。
全額返金JPexamの問題集を利用すると、短時間で勉強しても試験に合格できるのを保証いたします。試験に不合格になってしまった場合、弊社は全額返金いたします。(
ご購入前のお試しJPexamは問題集のサンプルを無料で提供いたします。ご購入前にサンプルを試用して製品の品質を確認することができます。ご遠慮なく利用してください。
