SC0-451 Tactical Perimeter Defense Certified Practice Exam

所在平台: Udemy

课程主页: https://www.udemy.com/course/sc0-451-tactical-perimeter-defense-certified-practice-exam-f/

课程评论:没有评论

第一个写评论        关注课程

课程简介

以下是中国关于Coursera“SC0-451 战术边界防御认证实践考试”课程的内容摘要: 本课程提供一系列模拟试题,旨在帮助学员准备“SC0-451 战术边界防御”相关的认证考试。课程内容涵盖了网络安全中的多个关键领域,包括: * **防火墙策略配置:** 学习如何组织和构建防火墙策略,了解策略中包含的各种部分,例如可接受使用声明、网络连接声明、事件处理声明和升级程序声明等。 * **入侵检测系统(IDS)的功能与限制:** 探讨IDS在管理硬件故障方面的局限性,例如IDS通常只能通知事件发生,而无法主动管理硬件故障或响应SNMP陷阱信息。 * **防火墙策略的两种基本立场:** 掌握在创建防火墙策略时可以采取的两种核心策略:“拒绝所有流量,只允许必需的流量”和“允许所有流量,只拒绝必需的流量”。 * **购买与构建防火墙的权衡:** 分析购买现成防火墙相对于自行构建防火墙的优势,包括良好的管理图形用户界面(GUI)、完善的日志记录和告警功能,以及通常具备的实时监控能力。 * **IP Tables 防火墙规则解析:** 通过分析具体的iptables命令,理解防火墙规则的功能,例如如何配置出站流量规则,限制或允许特定协议(如TCP)和目标IP地址(如172.168.35.40)的访问,特别是针对www服务(端口80)的流量。 通过这些模拟试题,学员可以检验和加强自己在网络边界防御策略、IDS运作原理以及防火墙配置方面的知识和实践能力。

课程评论(0条)

课程详情

Sample Questions:You are in the process of configuring your network firewall policy. As you begin building the content of the policy you start to organize the document into sections. Which of the following are sections found in the firewall policy?The Acceptable Use StatementThe Firewall Administrator StatementThe Network Connection StatementThe Incident Handling StatementThe Escalation Procedures StatementYou have just installed a new Intrusion Detection System in your network. You are concerned that there are functions this system will not be able to perform. What is a reason an IDS cannot manage hardware failures?The IDS can only manage RAID 5 failures.The IDS cannot be programmed to receive SNMP alert messages.The IDS cannot be programmed to receive SNMP trap messages.The IDS cannot be programmed to respond to hardware failures.The IDS can only inform you that an event happened.At a policy meeting you have been given the task of creating the firewall policy. What are the two basic positions you can take when creating the policy?To deny all traffic and permit only that which is required.To permit only IP traffic and filter TCP trafficTo permit only TCP traffic and filter IP trafficTo permit all traffic and deny that which is required.To include your internal IP address as blocked from incoming to prevent spoofing.Your company has created it's security policy and it's time to get the firewall in place. Your group is trying to decide whether to build a firewall or buy one. What are some of the benefits to purchasing a firewall rather than building one?They usually have a good management GUI.They offer good logging and alerting.You do not need to configure them.The OS doesn't need to be hardened before installing the vendor's firewall on it.They often do real time monitoring.You have recently taken over the security of a mid-sized network. You are reviewing the current configuration of the IP Tables firewall, and notice the following rule: ip chains -A output -p TCP -d! 172.168.35.40 www What is the function of this rule?This rule for the output chain states that all www traffic on 172.168.35.40 from any IP address is allowed.This rule for the input chain states that all TCP packets are able to get to the www service on any IP address except for 172.168.35.40.This rule for the input chain states that all TCP packets are allowed to the 172.168.35.40 IP address to any port other than 80.This rule for the output chain states that all TCP packets are able to get to the www service on any IP address except for 172.168.35.40.This rule for the output chain states that all TCP packets are allowed to the 172.168.35.40 IP address to any port other than 80.You have recently taken over the security of a mid-sized network. You are reviewing the current configuration of the IP Tables firewall, and notice the following rule: ip chains -A output -p TCP -d! 172.168.35.40 www What is the function of this rule?This rule for the output chain states that all www traffic on 172.168.35.40 from any IP address is allowed.This rule for the input chain states that all TCP packets are able to get to the www service on any IP address except for 172.168.35.40.This rule for the input chain states that all TCP packets are allowed to the 172.168.35.40 IP address to any port other than 80.This rule for the output chain states that all TCP packets are able to get to the www service on any IP address except for 172.168.35.40.This rule for the output chain states that all TCP packets are allowed to the 172.168.35.40 IP address to any port other than 80.

课程标签

0人关注该课程

主题相关的课程