CheckPoint Check Point Accredited Sandblast Administrator 認定 156-730 試験問題:
1. A Threat Extraction license is always bundled with Threat Emulation.
A) False - Threat extraction is part of the basic NGFW license.
B) True - it is part of the NGTP and EBP license.
C) True - it is part of the NGTX license.
D) False - they can be purchased separately.
2. Anti-Bot uses the following detection/prevention features:
1 . Reputation lookup of DNS/IP/URL access
2 . Dynamic analysis for Bots
3. Outbound SPAM
4. Bot behavior signatures
A) 2 and 3
B) 1 and 3
C) 1, 3 and 4
D) 1, 2, and 3
3. At which layer in the Attack Infection Flow can CPU Level Emulation detect a malicious file?
A) The malware binary
B) The vulnerability
C) The Exploit stage
D) The shell code
4. What kind of approach or approaches will Check Point SandBlast apply to prevent malicious EXE-files?
A) Exploit
B) Machine learning algorithm
C) Whitelist and Exploit
D) Signature
質問と回答:
質問 # 1 正解: D | 質問 # 2 正解: C | 質問 # 3 正解: C | 質問 # 4 正解: A |