首页
外语
计算机
考研
公务员
职业资格
财经
工程
司法
医学
专升本
自考
实用职业技能
登录
计算机
Bob is a new security administrator at a financial institution. The organization has experienced some suspicious activity on one
Bob is a new security administrator at a financial institution. The organization has experienced some suspicious activity on one
admin
2013-12-19
73
问题
Bob is a new security administrator at a financial institution. The organization has experienced some suspicious activity on one of the critical servers that contain customer data. When reviewing how the systems are administered, he uncovers some concerning issues pertaining to remote administration. Which of the following should not be put into place to reduce these concerns?
i. Commands and data should not be sent in cleartext.
ii. SSH should be used, not Telnet.
iii. Truly critical systems should be administered locally instead of remotely.
iv. Only a small number of administrators should be able to carry out remote functionality.
v. Strong authentication should be in place for any administration activities.
选项
A、i, ii
B、None of them
C、ii, iv
D、All of them
答案
B
解析
B正确。为了正确地进行远程管理活动,所有这些对策都应该付诸实施。
A不正确。因为敏感命令和敏感数据不应该以明文的形式(即它们需要加密)发送到关键系统。例如,应该使用SSH,而不是Telnet。SSH是一个安全数据通信的网络协议。它允许两个网络相连的系统间的远程shell服务和命令执行,以及其他安全网络服务。它是为了取代使用明文发送信息和明显的密码的Telnet和其他不安全的远程shell协议(比如Berkeley rsh和rexec协议)而设计的,因为这些不安全的协议会导致信息容易受到拦截和泄露。
C不正确。因为敏感命令和敏感数据不应该以明文(即它们需要加密)的形式发送。例如,应该使用SSH,而不是Telnet。真正关键的系统应该通过本地管理,而不是通过远程管理。应该只有一小部分管理可以通过远程执行。
D不正确。因为为了正确地进行远程管理活动,所有这些对策都应该付诸实施。
转载请注明原文地址:https://www.kaotiyun.com/show/cAhZ777K
0
CISSP认证
相关试题推荐
AsformercolonistsofGreatBritain,theFoundingFathersoftheUnitedStatesadoptedmuchofthelegalsystemofGreatBritai
Theterme-commercereferstoallcommercialtransactionsconductedovertheInternet,includingtransactionsbyconsumersandb
Chinaplanstospendbillionsofdollarsinthenextfewyearstodevelopmediaandentertainmentcompaniesthatithopescanco
Menandwomendothinkdifferently,atleastwheretheanatomyofthebrainisconcerned,accordingtoanewstudy.Thebrainis
IntheSecondWorldWara"blockbuster"wasabombthatcouldeliminatewholestreets.Todayitisthekindofhitcreationthat
Writeanessayof160-200wordsbasedonthefollowingdrawing.Inyouressay,youshould1)describethedrawingbriefly,
Writeanessayof160-200wordsbasedonthefollowingpictures.Inyouressay,youshould1)describethepicturesbriefly,
CompanyIsMoreImportantthanGiftsWriteanessayof160-200wordsbasedonthedrawing.Inyouressay,youshould1)
DespiteincreasedairportsecuritysinceSeptember11th,2001,thetechnologytoscanbothpassengersandbaggageforweaponsan
随机试题
敏感性训练
有些疾病仅靠X线检查即能确诊,除了( )
新生儿硬肿症发病的内因是
施工单位负责人在开工会议上宣布了拟参加或不参加安全生产教育培训人员的名单见下表,根据我国《建设工程安全生产管理条例》的规定,你认为所有不正确的安排是()。
在《个人所得税法实施条例》中,规定附加减除费用的适用范围包括()。
下列各项,应计入增值税应税销售额的是()。
From:WayneThomas[wayne@e-solutions.com]To:terry.giblert@monavale.comCc:KarenRussell[Karen.russell@e-solutions.com]S
教师的专业素养是当代教育质量的集中体现,它主要表现在教师的()。
Themainideaofthesebusiness--schoolacademicsisappealing.Inawordwherecompaniesmustadapttonewtechnologiesandsou
CluestoHelpExplaintheFrequencyofInjuriesThethreewomenareallseriousathletes,andtheyworktogetheratasmall
最新回复
(
0
)