フリー問題

Palo Alto Networks Certified Cybersecurity Practitioner のフリー問題 17 / 20 問目

問題文

An organization already runs endpoint detection. Why are disk encryption and patch management still listed as endpoint protections?

選択肢

  1. Because detection products require that the disk be encrypted and that the system be fully patched before their agent will start, so these two measures are prerequisites for the detection layer rather than protections in their own right.
  2. Because they are the only two controls on the endpoint that can be automated, so they are listed apart from the measures that depend on an analyst reviewing an alert first.
  3. Because they address exposures that detection does not touch: data read from a lost device, and weaknesses that an attacker can use before any malicious file is involved.
  4. Because encryption and patching replace the need for detection on endpoints that are kept up to date, so the detection agent can be removed from any machine that is fully patched and encrypted.

解答・解説を確認するには

正解と解説の確認、回答の記録には無料登録が必要です。登録すると演習モードでフリー問題に回答し、正誤と解説をその場で確認できます。