フリー問題

Designing Cisco Security Infrastructure v1.0 のフリー問題 20 / 20 問目

問題文

An asset review asks what sits on a developer's own machine and what has to be put around it. Which pair of answers does NIST SP 800-204D give?

選択肢

  1. Source code, credentials and access to sensitive material such as signing keys sit there, and the firm has to name its critical assets, then put access control, multi-factor authentication and encryption around them, in that desk-side inventory.
  2. Just the working copy of the code sits there, with the secrets left in the pipeline vault, and the firm has to name its critical assets, then put access control, multi-factor authentication and encryption around them and their backups, in that desk-side inventory.
  3. Source code, credentials and access to sensitive material such as signing keys sit there, and the firm has to move that material onto a hardened build-side server that developers reach through a thin client and nothing else, in that desk-side inventory.
  4. Just the working copy of the code sits there, with the secrets left in the pipeline vault, and the firm has to move that material onto a hardened build-side server and its vault that developers reach through a thin client and nothing else, in that desk-side inventory.

解答・解説を確認するには

正解と解説の確認、回答の記録には無料登録が必要です。登録すると演習モードでフリー問題に回答し、正誤と解説をその場で確認できます。