【单选题】
What information does the key length provide in an encryption algorithm?___
A. the cipher block size
B. the hash bloc k size
C. the number of permutations
D. the packet size
查看试卷,进入试卷练习
微信扫一扫,开始刷题
相关试题
【单选题】
How do you verify TaCACS+ connectivity to a device?___
A. You successfully log in to the device by using the local credentials
B. You connect via console port and receive the login prompt.
C. You connect to the device using SSH and receive the login prompt.
D. You successfully log in to the device by using ACS credentials
【单选题】
Which term best describes the concept of preventing the modification of data in transit and in storage?___
A. availability
B. confidentially
C. fidelity
D. integrity
【单选题】
Which loS command is used to define the authentication key for ntp?___
A. switch(config )#ntp authentication-key 1 mds Clcs
B. switch(config )#ntp authenticate
C. switch(config)#ntp trusted-key 1
D. switch(config)#ntp source 192.168.0.1
【单选题】
What is true about the cisco lOS Resilient Configuration feature ?___
A. The feature can be disabled through a remote session
B. There is additional space required to secure the primary cisco lOS image file.
C. The feature automatically detects image or configuration version mismatch.
D. Remote storage is used for securing files
【单选题】
When is the default deny all policy an exception in zone-based firewalls?___
A. when traffic terminates on the router via the self zone
B. when traffic traverses two interfaces in different zones
C. when traffic traverses two interfaces in the same zone
D. when traffic sources from the router via the self zone
【单选题】
.If an access port is assigned as an isolated port in a PVLAN, which network ports can it communicate with?___
A. promiscuous ports in the same PLVAN
B. isolated ports in the same PVLAN
C. all ports in the same PAVLAN at ILAR
D. all ports in the adjacent PVLAN
【单选题】
Which IPSEC mode is used to encypt traffic directly between a client and a server VPN endpoint?___
A. quick mode
B. transport mode
C. aggressive mode
D. tunnel mode
【单选题】
Which command do you enter to verify that a vpn connection is established between two endpoints and that the connection is passing traffic? ___
A. Firewall#sh crypto session
B. Firewall#debug crypto isakmp
C. Firewall#tsh crypto ipsec sa
D. Firewall#sh crypto isakmp sa
【单选题】
which type of Pvlan port allows communication from all port types?___
A. isolated
B. in -line
C. community
D. promiscuous
【单选题】
Which command do you enter to configure your firewall to conceal internal addresses?___
A. no ip directed-broadcast
B. no ip logging facility
C. no proxy-arp
D. no ip inspect audit-trial
E. no ip inspect
F. route
【单选题】
Which feature defines a campus area network? ___
A. It has a limited number of segments.
B. It has limited or restricted Internet access
C. It lacks ex1ternal connectivity.
D. It has a single geographic location
【单选题】
What technology can you use to provide data confidentiality data integrity and data origin authentication on your network?___
A. IPSec
B. Certificate Authority
C. IKE
D. Data
E. ncryption Standards
【单选题】
which standard is a hybrid protocol that uses oakley and skerne ke y exchanges is an ISAKMP framework?___
【单选题】
What is the actual los privilege level of User Exec mode?___
【单选题】
What is the effect of the asa command crypto isakmp nat-traversal?___
A. It opens port 500 only on the out side interface
B. It opens port 500 only on the inside interface
C. It opens port 4500 on all interfaces that are IPSec enabled
D. It opens port 4500 only on the out side interfac
【单选题】
Which Fire POWER preproce ssor engine is used to prevent SYN attacks?___
A. Inline normalization
B. IP Defragmentation
C. Ports can
D. etection
【单选题】
Which NAT type allows objects or groups to reference an IP address ?___
A. identity NAt
B. static NAT
C. dynamic
D. dynamic NAT
【单选题】
Which Auto NAT policies are processed first?___
A. Dynamic NAT with longest prefix
B. Dynamic NAT with shortest prefix
C. static NAT with longest prefix
D. static NAT with shortest prefix
【单选题】
Which feature allows a dynamic Pat pool to se lect the next address in the pat pool instead of the next port of an existing address?___
A. next IP
B. round robin
C. dynamic rotation
D. NAT address rotation
【单选题】
Which IPS detection method can you use to detect attacks that are based on the attackers IP address?___
A. anomally-based
B. policy-based
C. signature-based
D. reputation-based
【单选题】
Which type of encryption technology has the broadest platform support?___
A. software
B. middleware
C. file-level
D. hardware
【单选题】
Which type of address translation supports the initiation of comm unications bidirectionally ?___
A. multi-session PAT
B. dynamic NAT
C. dynamic PAT
D. static NAT
【单选题】
Which label is given to a person who uses existing computer scripts to hack into computers while lacking the expertise to write the own?___
A. script kiddy
B. white hat hacker
C. hacktivist
D. phreaker
【单选题】
What is the primary purpose of a defined rule in an IPS?___
A. to configure an event action that takes place when a signature is triggered
B. to define a set of actions that occur when a specific user logs in to the system
C. to configure an event action that is pre-defined by the system administrator
D. to detect internal attacks
【单选题】
Which option is the default valuce for the Diffie- Hell man group when configuring a site-to-site VPn on an asa device ?___
A. Group 1
B. Group 2
C. Group 5
D. Group 7
【单选题】
Which feature filters CoPP packets?___
A. access control lists
B. class maps
C. policy maps
D. route maps
【单选题】
Which command is used in global configuration mode to enable AAA?___
A. configure-model aaa
B. configure aaa-modelA
C. aaa new-model
D. aaa
E. XEC
【单选题】
Which statement about the given configuration is true?___
A. The single-connection command causes the device to establish one connection for all TACACS
B. The single-connection command causes the device to process one TacAcs request and then move to the next server
C. The timeout com mand causes the device to move to the next server after 20 seconds of TACACS inactive
【多选题】
What are two well-known security terms?___
A. phishing//网络钓鱼
B. ransomware //勒索软件
C. BPDU guard
D. LACP
E. hair-pinning
【多选题】
Which two commands must you enter to securely archive the primary bootset of a device___
A. router(config )#secure boot-config
B. router(config)#auto secure
C. router(config)#secure boot-image
D. router(config)#service passw ord-encryption
【多选题】
Which two functions can SIEM provide ?___
A. correlation between logs and events from multiple systems
B. event aggregation that allows for reduced log storage requirements
C. proactive malware analysis to block malicious traffic
D. dual-factor authentication
E. centralized firewall management
【多选题】
Which two features of Cisco Web Reputation tracking can mitigate web-based threats?___
A. buffer overflow filterin dhsuowip
B. Bayesian filters
C. web reputation filters
D. outbreak filtering
E. exploit filtering
【多选题】
What are two challenges when deploying host- level IPS? ___
A. The deployment must support multiple operating systems.
B. It is unable to provide a complete networ k picture of an attack.
C. It is unable to determine the outcome of e very attack that it detects
D. It does not provide protection for offsite computers
E. It is unable to detect fragmentation attacks
【多选题】
Which technology can be used to rate data fidelity and to provide an authenticated hash for data?___
A. file reputation
B. file analysis
C. signature updates
D. network blocking
【多选题】
Which two statements about host-based iPS solutions are true?___
A. It uses only signature-based polices
B. It can be deployed at the perimeter.
C. It can be have more restrictive policies than network-based IPS
D. it works with deployed firewall
E. It can generate alerts based on be havior at the de sto
【多选题】
When two events would cause the state table of a stateful firewall to be updated? ___
A. when a packet is evaluated against the outbound access list and is denied
B. when a con nection is created
C. when rate-limiting is applied
D. when a connection s timer has expired within the state table.
E. when an outbound packet is forwarded to the outbound interface
【多选题】
Which two characteristics apply to an intrusion Prevention System(IPS)?___
A. Cannot drop the packet on its own
B. Cabled directly inline with the flow of the network traffic
C. Runs in promiscuous mode wat
D. Does not add delay to the original traffic
E. Can drop traffic based on a set of rules
【多选题】
crypto ipsec trans form-set myset esp-md5-hmac esp-aes-256,What are two effects of the given command?___
A. It configures authentication use AES 256.
B. It configures authentication to use MD5 HMAC
C. It configures authentication use AES 256.
D. It configures encryption to ase MD5 HMAC.
E. It configures encryption to use AES 256
【多选题】
your security team has discovered a malicious program that has been harvesting the CEos email messages and the com pany 's user database for the last 6 months. What are two possible types of attacks your team discovered?___
A. social activism
B. EPolymorphic Virus
C. advanced persistent threat
D. drive-by spyware
E. targeted malware
【单选题】
以下关于数据处理的叙述中,不正确的足___。
A. :数据处理不仅能预测不久的未来,自时还能影响未
B. :数据处理和数据分析可以为决策提供真知灼见
C. :数据处理的重点应从技术角度去发现和解释数据蕴涵的意义
D. :数据处理足从现实世界到数据,冉从数据到现实世界的过程
推荐试题
【判断题】
尚未制定法律、行政法规的,国务院部、委员会制定的规章对违反行政管理秩序的行为,可以设定警告或者一定数量罚款的行政处罚
【判断题】
地方性法规可以设定除吊销企业营业执照以外的各种行政处罚
【判断题】
公民、法人或者其他组织对行政机关作出的行政处罚,有权申诉或检举
【判断题】
宁波市人民政府制定的规章对违反行政管理秩序的行为,只能设定一定数量罚款的行政处罚
【判断题】
当场作出行政处罚决定时,执法人员对于依法给予五十元以下的罚款可以当场收缴
【判断题】
对情节复杂或者重大违法行为给予较重的行政处罚,应当由办案人员集体讨论决定
【判断题】
行政机关执法人员在询问或者检查时应当制作笔录
【判断题】
在可以当场作出行政处罚决定的情况下,行政执法人员可以不表明身份
【判断题】
公民、法人或者其他组织对行政机关所给予的行政处罚,享有陈述权、申辩权
【判断题】
当事人对限制人身自由的行政处罚有异议的,依照《治安管理处罚法》有关规定执行
【判断题】
听证结束后,行政处罚听证笔录是行政机关作出决定的依据
【判断题】
作出行政处罚决定的行政机关对逾期缴纳罚款的,可以直接从当事人的账户上划拨
【判断题】
行政机关应当认真审查,发现行政处罚有错误,应当主动改正
【判断题】
上级行政机关或者有关部门对使用的非法单据应予以收缴销毁,对直接负责的主管人员和其他直接责任人员依法给予行政处分
【判断题】
省、自治区、直辖市人民政府可以决定一个行政机关行使有关行政机关的行政处罚权
【判断题】
当事人对当场作出的行政处罚决定不服的,可以依法申请行政复议
【判断题】
对管辖发生争议的,报请共同的上一级行政机关指定管辖
【判断题】
行政处罚听证会的相关费用应由行政机关承担
【判断题】
当事人要求听证的,应当在行政机关告知后三日内提出
【判断题】
行政机关对当事人进行处罚使用非法定部门制发的罚款、没收财物单据的,当事人无权拒绝处罚,但可以事后检举
【判断题】
行政机关为牟取本单位私利,对应当依法移交司法机关追究刑事责任的不移交,以行政处罚代替刑罚,由上级行政机关或者有关部门责令纠正;拒不纠正的,对直接负责的主管人员可直接追究刑事责任
【判断题】
宁波市人民政府制定的规章对违反行政管理秩序的行为,可以设定警告或一定数量罚款的行政处罚
【判断题】
宁波市人民政府制定的规章对违反行政管理秩序的行为,可以设定警告或一定数量罚款的行政处罚。罚款限额由宁波市人大常委会规定
【判断题】
甲因扰乱法庭秩序而被依法处以拘留15天的处罚,对此甲可以依法申请行政复议
【判断题】
在行政复议中,申请行政复议的公民、法人或者其他组织是申请人
【判断题】
申请行政机关履行保护人身权利、财产权利、受教育权利的法定职责,行政机关没有依法履行的,公民、法人或者其他组织可以依法申请行政复议
【判断题】
甲为刑满释放人员,出狱后自己开办了一家饭店。由于其曾有犯罪前科,当地县工商局要求其每年额外交纳一万元的“诚信保证金”,否则将吊销其营业执照。对此,甲可以向上一级工商管理部门申请行政复议
【判断题】
行政复议机关决定撤销或者确认某具体行政行为违法的,可以责令被申请人在一定期限内重新作出具体行政行为
【判断题】
对地方各级人民政府的具体行政行为不服的,可以向本级人民政府申请行政复议,也可以向上一级地方人民政府申请行政复议
【判断题】
公民、法人或者其他组织自具体行政行为发生之日起六十日内未提出行政复议申请的,将不能再申请行政复议
【判断题】
行政复议期间有关“五日”、“七日”等的规定是指工作日,不含节假日
【判断题】
对本县公安局的具体行政行为不服的,申请人只能向本县人民政府申请行政复议
【判断题】
行政复议机关在复议过程中发现被申请人对申请人作出的处罚决定过轻,应当决定撤销原处罚决定,作出较原处罚更重的处罚决定
【判断题】
被申请人因不可抗力,不能参加行政复议的,行政复议不中止审理
【判断题】
申请人在行政复议决定作出前自愿撤回行政复议申请的,需经行政复议机构同意方可撤回
【判断题】
案件涉及法律适用问题,需要有权机关作出解释或者确认的,行政复议中止,满60日该情形仍持续的,行政复议终止
【判断题】
申请人S公司在复议期间与D公司合并为Y公司,若Y公司声称放弃行政复议,该行政复议终止
【判断题】
案件审理需要以其他案件的审理结果为依据,而其他案件尚未审结的,行政复议中止审理