フリー問題

Palo Alto Networks Certified Cybersecurity Practitioner のフリー問題 13 / 20 問目

問題文

A repository was made public by mistake for two hours. Within a day, a database credential that had been written directly into the source of one service was being used from an unfamiliar address. What was missing?

選択肢

  1. A shorter interval between planned replacements of the credential, so that a copy taken from the source stops working before it can be used.
  2. Encryption of the repository at rest, because a repository whose contents are unreadable exposes nothing even during the two hours it was public.
  3. Examination of the source and the build for embedded secrets, so a credential written into the code never reaches a released artifact.
  4. Protection for the running workload, because a component that observes what a service does would have recognized the use of the credential from an unfamiliar address and refused it, which removes the need to examine the source for what it happens to contain.

解答・解説を確認するには

正解と解説の確認、回答の記録には無料登録が必要です。登録すると演習モードでフリー問題に回答し、正誤と解説をその場で確認できます。