A. 結果は、攻撃者が会社について知ることができる可能性があることを反映しているはずです。
B. 提供された文書を使って、ペンテスト組織はすぐに注目すべき分野を決定できます。
C. 結果にはネットワークの詳細図が表示され、内部的に弱い部分を特定するのに役立ちます。
D. 計画外のサーバー停止のリスクが軽減されます。
Answer: A
A black box penetration test is usually done when you do not have access to the code, much the same like an outsider/attacker. This is then the best way to run a penetration test that will also reflect what an attacker/outsider can learn about the company. A black box test simulates an outsiders attack.
Incorrect Answers:
A: Unplanned server outages are not the advantage of running black box penetration testing.
B: Making use of documentation is actually avoided since black box testing simulates the attack as done by an outsider.
C: An in-depth view of the company's network and internal weak points is not an advantage of black box penetration tests.
Gregg, Michael, and Billy Haines, CASP CompTIA Advanced Security Practitioner Study Guide, John Wiley & Sons, Indianapolis, 2012, p. 168

A company uses Azure to host web apps.
The company plans to deploy a new web app using Kubernetes cluster. You create a new resource group for the cluster.
You need to deploy the application.
Which three actions should you perform?



During project selection, which factor is most important?
A. Internal business needs
B. Budget
C. Schedule
D. Types of constraints
Answer: A

What should you use to set up event correlation? (Select two.)
A. Duplicate Suppression on the management server
B. Duplicate Suppression on the agent
C. Event Deduplication
D. Correlation Composer
E. Event Suppression
Answer: A,D


