【单选题】
You have been tasked with blocking user access to websites that violate company policy, but the sites use dynamic IP addresses. What is the best practice for URl filtering to solve the problem?___
A. Enable URL filtering and use URL categorization to block the we bsites that violate company
B. Enable URL filtering and create a blacklist to block the websites that violate company policy
C. Enable URL filtering and create a whitelist to block the websites that violate company policy
D.
E. nable URL filtering and use URL categorization to allow only the websites that company policy allows users to access.
查看试卷,进入试卷练习
微信扫一扫,开始刷题
相关试题
【单选题】
Within an 802. 1x-enabled network with the auth Fail feature configured, when does a switch port get placed into a restricted VLAN?___
A. When a conected client fails to authenticate after a certain number of attempts.
B. if a connected client does not support 802. 1x
C. when AAA new-model is ena bled
D. after a connected client exceeds a specified idle time
E. when 802. 1x is not globally enabled on the Cisco Catalyst switch
【单选题】
Which type of attack does a proxy firewall protect against ?___
A. cross-site scripting attack
B. worm traffic
C. port scanning
D. DDoS attacks
【单选题】
When an administrator initiates a device wipe command from the ISE, what is the immediate effect?___
A. It requests the administrator to choose between erasing all device data or only managed corporate data.
B. It requests the administrator to enter the device pin or password before proceeding with the operation
C. It notifies the device user and proceeds with the erase operation
D. It immediately erases all data on the device
【单选题】
What is a valid implicit permit rule for traffic that is traversing the ASa firewall?___
A. ARPs in both directions are permitted in transparent mode only
B. Unicast IPv4 traffic from a higher security interface to a lower security interface is permittee in routed mode only.
C. Unicast IPv6 traffic from a higher security interface to a lower security interface is permitted in transparent mode only.
D. Only BPDUs from a higher security interface to a lower secur ity interface are permitted in transparent mode.
E. Only BPDUs from a higher security interface to a lower secur ity interface are permitted in routed mode
【单选题】
A specific URL has been identified as containing malware. What action can you take to block users from accidentally visiting the URl and becoming infected with malware ?___
A. Enable URL filtering on the perimeter router and add the URls you want to block to the router's local URL list
B. Enable URL filtering on the perimeter firewall and add the URls you want to allow to the router's local URL list.
C. Enable URL filtering on the perimeter router and add the URls you want to allow to the firewall's local URL list
D. Create a blacklist that contains the URl you want to block and activate the blacklist on the perimeter rout
E. Create a whitelist that contains the URLs you want to allow and activate the whitelist on the perimeter router.
【单选题】
How does PEAP protect the EAP exchange ?___
A. It encrypts the exchange using the server certificate
B. It encrypts the exchange using the client certificate
C. It validates the server-supplied certificate,and then encrypts the exchange using the client certificate
D. It validates the client-supplied certificate,and then encrypts the excha nge using the server certificate
【单选题】
Which feature of the Cisco Email Security Appliance can mitigate the impact of snowshoe spam and sophisticated phishing attacks?___
A. contextual analysis
B. holistic understanding of threats
C. graymail management and filtering
D. signature-based IPS
【单选题】
Refer to the exhibit【nat (inside,outside)dunamic interface】 Which translation technique does this configuration result in?___
A. DynamIc PAT
B. Dynamic NAT
C. Twice NAT
D. Static NAT
【单选题】
Refer to the exhibit which are repre sents the data center?___
【单选题】
While trouble shooting site-to-site VPN, you issued the show crypto isakmp sa command. What does the given output show?___
A. IKE Phase 1 main mode was created on 10.1.1.5, but it failed to negotiate with 10.10 10.2
B. IKE Phase 1 main mode has successfully negotiated between 10.1.1.5 and 10.10..
C. IKE Phase 1 aggressive mode was created on 10.1.1.5, but it failed to negotiate with
【单选题】
Refer to the exhibit All ports on switch 1 have a primary vLan of 300 Which devices can host 1 reach?___
A. host 2
B. server
C. host 4
D. other devices within VLAN303
【单选题】
Which option is the cloud-based security service from Cisco the provides URL filtering, web browsing content security, and roaming user protection?___
A. Cloud Web service
B. Cloud Advanced Malware Protection
C. Cloud We b Security
D. Cloud Web Protection
【单选题】
How can you detect a false negative on an IPS?___
A. View the alert on the ips
B. Review the ips log
C. Review the is console
D. Use a third- party system to perform penetration testing.
E. Use a third- party to audit the next generation firewall rules
【单选题】
If a switch port goes directly into a blocked state only when a superior BPDU is received, what mechanism must be in use?___
A. STP BPDU guard
B. Loop guard
C. EtherChannel guard
D. STP Root guard
【单选题】
what improvement does EAP-FASTv2 provide over EAP-FAST? ___
A. It allows multiple credentials to be passed in a single EAP exchange.
B. It supports more secure encryption protocols
C. It allows faster authentication by using fewer packets.
D. It addresses security vulnerabilities found in the original protocol
【单选题】
When users login to the Client less Ssl Vpn using https://209.165.201.2/test ,which group policy will be applied?___
A. test
B. clientless
C. sales
D. DfitGrp Policy
E. Default RAGroup
F. Default WEB VPN
G. roup
【单选题】
Which user authentication method is used when users login to the Clientless SSLVPN portal using https://209.165.201.2/test?___
A. AAA with LOCAL database
B. AAA with RADIUS server
C. Certificate
D. :Both Certificate and aaa with LoCAL database
E. Both Certificate and AAA with RADIUS server
【单选题】
What' s the technology that you can use to prevent non malicious program to runin the computer that is disconnected from the network?___
A. Firewall
B. Sofware Antivirus
C. Network IPS
D. Host IPS
【单选题】
Which statement about the communication between interfaces on the same security level is true?___
A. Interfaces on the same security level require additional configuration to permit interinterface communication
B. Configuring interfaces on the same security level can cause asymmetric routing
C. All traffic is allowed by default between interfaces on the same security level
D. You can configure only one interface on a n individual security level
【单选题】
Which product can be used to provide application layer protection for tcp port 25 traffic?___
A. ESA
B. CWS
C. WSA
D. ASA
【单选题】
which iPS mode is less secure than other options but allows optimal network through put ?___
A. inline mode
B. inline-bypass mode
C. transparent mode
D. Promiscuous mode
【单选题】
Which feature of the Cisco Email security Appliance can mitigate the impact of snowshoe spam and sophisticated phishing attack?___
A. reputation based filtering
B. signature based IPS
C. contextual analysis
D. graymail management and filtering
【单选题】
Which type of social-engineering attack uses normal tele phone service as the attack vector?___
A. smishing
B. dialing
C. phishing
D. vishing
【单选题】
Which quantifiable item should you consider when you organization adopts new technologies?___
A. exploits
B. vulnerability
C. threat
D. Risk
【单选题】
Referencing the ClA model, in which scenario is a hash- only function most appropriate ?___
A. securing data at rest
B. securing real-time traffic
C. securing data in files
D. securing wireless transmissions
【单选题】
Which ports must be open between a aaa server and a microsoft server to permit Active Directory authentications?___
A. 445 and 389
B. 888 and 3389
C. 636 and 4445
D. 363 and 983
【单选题】
Refer to the exhibit for which reason is the tunnel unable to pass traffic___
A. the tunnel is failing to receive traffic from the remote peer
B. the local peer is unable to encrypt the traffic
C. the ip address of the remote peer is incorrect
D. UDP port 500 is blocked
【单选题】
Which type of attack can exploit design flaws in the implementation of an application without___
A. DHCP starvation attacks
B. low-rate dos attacks
C. application DDos flood attacks
D. application DDoS flood attacks
E. volume-based DDoS attacks
【单选题】
How can you protect CDP from reconnaissance attacks?___
A. Enable dynamic ARP inspection on all untrusted ports.
B. Enable dot1x on all ports that are connected to other switches.
C.
D. isable CDP on ports connected to endpoints.
【单选题】
Which type of attack can exploit design flaws in the implementation of an application without ?___
A. DHCP starvation attacks
B. low-rate dos attacks
C. application DDos flood attacks
D. application DDoS flood attacks
E. volume-based DDoS attacks
【单选题】
Which option is a key security compone nt of and MDM deployment ?___
A. using network-specific installer packages
B. using an application tunnel by default
C. using self-signed certificates to validate the server
D. using MS-CHAPv2 as the primary
E. AP method
【单选题】
Which Firepower Management Center feature detects and block exploits and hack attempts?___
A. Content blocker
B. file control
C. intrusion prevention
D. advanced malware protection
【单选题】
hich description of the nonsecret numbers that are used to start a Diffie- Hellman exchange is ture?___
A. They are preconfigured prime integers.
B. They are large pseudorandom numbers.
C. They are very small numbers chosen from a table of known valuses
D. They are numeric values extracted from ha shed system hostnames
【多选题】
Which two characteristics of an application layer firewall are true?___
A. provides stateful firewal functionality
B. has low processor usage
C. provides protection for multiple applications
D. provides rever se proxy services
E. is immune to URL manipulation
【多选题】
Which two devices are components of the BYOD architectural framework?___
A. Nexus 7010 switch
B. Cisco 3945 Router
C. Identify Services Engine
D. Wireless Access oints
E. Prime Infrastructure
【多选题】
Which two actions can a zone based firewall take when looking at traffic? ___
A. forward
B. inspect
C. drop
D. broadcast
E. filter
【多选题】
n which two situations should you use in-band management?___
A. when management applications need concurrent access to the device
B. when you require administrator access from multiple locations
C. when a network device fails to forward packets
D. when you require ROMMON access
E. when the control plane fails to respond
【多选题】
What are two ways to prevent eavesdropping when you perform device management tasks?___
A. Use an SSH connection.
B. Use SNMPv3
C. Use out-of-band management
D. Use SNMP
E. Use in-band management
【多选题】
Which two features are commonly used CoPP and CPPr to protect the control plane? ___
A. QoS
B. traffic classification
C. access lists
D. policy maps
E. class maps
F. Cisco Express Forwarding
【多选题】
Which four tunne ling prot ocols are enabled in the Dfit GrpPolicy group policy ?___
A. Clientless SSL VPN
B. SSL VPN Client
C. PPTP
D. L2TP/IPsec
E. IPsec IKEv1
F. IPsec IKEv2
推荐试题
【单选题】
《建筑法》规定,大型建筑工程或者结构复杂的建筑工程,可以由两个以上的承包单位联合共同承包。共同承包的各方对承包合同的履行___。
A. 独立承担各自的责任
B. 承担连带责任
C. 不承担责任
D. 承担适当的责任
【单选题】
总承包单位和分包单位就分包工程对建设单位___。
A. 独立承担各自的责任
B. 不承担责任
C. 承担适当的责任
D. 承担连带责任
【单选题】
禁止总承包单位将工程分包给不具备相应资质条件的单位。___分包单位将其承包的工程再分包。
A. 允许
B. 禁止
C. 原则上禁止
D. 原则上允许
【单选题】
实施建筑工程监理前,建设单位应当将委托的工程监理单位、监理的内容及监理权限,___被监理的建筑施工企业。
A. 口头通知
B. 书面通知
C. 以任何形式通知
D. 不必通知
【单选题】
工程监理单位不按照委托监理合同的约定履行监理义务,对应当监督检查的项目不检查或者不按照规定检查,给建设单位造成损失的,应当承担___。
A. 全部的赔偿责任
B. 大部分的赔偿责任
C. 相应的赔偿责任
D. 相应的补偿责任
【单选题】
工程监理单位与承包单位串通,为承包单位谋取非法利益,给建设单位造成损失的,应当___。
A. 独自承担赔偿责任
B. 与承包单位承担连带赔偿责任
C. 不必承担赔偿责任
D. 由承包单位承担赔偿责任
【单选题】
施工总承包的,建筑工程___的施工必须由总承包单位自行完成。
A. 地基基础工程
B. 主体结构
C. 装修工程
D. 一半以上的工程量
【单选题】
___应当向建筑施工企业提供与施工现场相关的地下管线资料,建筑施工企业应当采取措施加以保护。
A. 设计单位
B. 监理单位
C. 建设单位
D. 各级地方人民政府建设行政主管部门
【单选题】
___应当建立健全劳动安全生产教育培训制度,加强对职工安全生产的教育培训;未经安全生产教育培训的人员,不得上岗作业。
A. 建筑施工企业
B. 监理单位
C. 设计单位
D. 建设单位
【单选题】
建筑施工企业必须为从事危险作业的职工办理意外伤害保险,由___支付保险费。
A. 建筑施工企业
B. 职工
C. 建筑施工企业和职工
D. 保险公司
【单选题】
房屋拆除应当由___承担,由施工单位负责人对安全负责。
A. 具备相应资质等级的施工单位
B. 基本具备保证安全条件的建筑施工单位
C. 一般的建筑施工单位
D. 建设单位
【单选题】
建筑设计单位和建筑施工企业对建设单位违反法律、行政法规和建筑工程质量、安全标准,提出的降低工程质量的要求,___。
A. 可以予以拒绝
B. 应当予以拒绝
C. 不得予以拒绝
D. 视情况决定拒绝与否
【单选题】
建筑活动应当确保___。
A. 经济性
B. 建筑工程质量和安全
C. 技术先进
D. 有利于推动当地经济发展
【单选题】
建筑工程的发包单位___将建筑工程的勘察、设计、施工、设备采购一并发包给一个工程总承包单位。
【单选题】
分包单位___将其承包的工程再分包。
A. 不得
B. 可以
C. 必须
D. 自行决定是否
【单选题】
工程监理单位___转让工程监理业务。
A. 可以
B. 必须
C. 自行决定是否
D. 不得
【单选题】
施工现场对毗邻的建筑物、构筑物和特殊作业环境可能造成损害的,建筑施工企业___采取安全防护措施。
A. 应当
B. 可以
C. 不得
D. 自行决定是否
【单选题】
建筑工程监理应当依照法律、行政法规及有关的技术标准、设计文件和建筑工程承包合同,对承包单位在施工质量、建设工期和建设资金使用等方面,代表___实施监督。
A. 施工单位
B. 建设单位
C. 主管部门
D. 上级机关
【单选题】
实施建筑工程监理前,___应当将委托的工程监理单位、监理的内容及监理权限,书面通知被监理的建筑施工企业。
A. 施工单位
B. 主管部门
C. 建设单位
D. 上级机关
【单选题】
建筑工程安全生产管理必须坚持___的方针。
A. 安全第一、预防为主
B. 事中控制与事后控制相结合
C. 经济效益第一
D. 技术先进
【单选题】
建筑施工企业在编制施工组织设计时,对专业性较强的工程项目,___。
A. 不必编制专项安全施工组织设计
B. 视情况决定是否编制专项安全施工组织设计
C. 视情况决定是否采取安全技术措施
D. 应当编制专项安全施工组织设计,并采取安全技术措施
【单选题】
___应当在施工现场采取维护安全、防范危险、预防火灾等措施;有条件的,应当对施工现场实行封闭管理。
A. 各级人民政府
B. 监理单位
C. 建筑施工企业
D. 建设单位
【单选题】
___应当遵守有关环境保护和安全生产的法律、法规的规定,采取控制和处理施工现场的各种粉尘、废气、废水、固体废物以及噪声、振动对环境的污染和危害的措施。
A. 各级人民政府
B. 监理单位
C. 建筑施工企业
D. 建设单位
【单选题】
___对建设工程的质量、安全事故、质量缺陷、安全隐患等都有权向建设行政主管部门或者其他有关部门进行检举、控告、投诉。
A. 任何单位和个人
B. 建设单位
C. 监理单位
D. 项目经理
【单选题】
建设行政主管部门和其他有关部门在对建筑活动实施监督管理过程中,___。
A. 可以收取相关费用
B. 不得收取任何费用
C. 除按照国务院有关规定收取费用外,不得收取其他费用
D. 除按照国务院有关规定收取费用外,还可收取其他费用
【单选题】
从事建筑活动的专业技术人员,应当___从事建筑活动。
A. 依法取得相应的执业资格证书,但可在执业资格证书许可的范围外
B. 依法取得相应的执业资格证书,并在执业资格证书许可的范围内
C. 不必取得执业资格证书
D. 依法取得相应的职业资格证书,但可在执业资格证书许可的范围外
【单选题】
___不得滥用行政权力,限定发包单位将招标发包的建筑工程发包给指定的承包单位。
A. 建设单位
B. 监理单位
C. 主管部门
D. 政府及其所属部门
【单选题】
从事建设工程活动,必须严格执行基本建设程序,坚持___的原则。
A. 先勘察、后设计、再施工
B. 先计划,后设计,再预算
C. 先预算,后勘察,再设计
D. 先设计,后勘察,再施工
【单选题】
关于建设项目设计文件的修改,下列表述正确的是___。
A. 建设文件是工程建设的主要依据,经批准后,不得任意变更和修改
B. 建设单位和监理单位可以修改工程建设勘察设计文件
C. 确需修改的,应由新的勘察设计单位修改
D. 修改单位对修改的勘察设计文件不承担相应的法律责任
【单选题】
涉及建筑主体和承重结构变动的装修工程,建设单位应当在施工前委托原设计单位或者具有相应资质等级的设计单位提出设计方案;没有设计方案的___。
A. 不得施工
B. 在某些部门许可下可以施工
C. 在质量监督部门监督下可以施工
D. 不确定
【单选题】
房屋建筑使用者在装修过程中,不得擅自变动房屋建筑主体和___。
A. 全部结构
B. 承重结构
C. 部分结构
D. 重要结构
【单选题】
注册建筑师、注册结构工程师等注册执业人员应当在设计文件上___,对设计文件负责。
A. 盖章
B. 签字
C. 盖有关部门的公章
D. 审批
【单选题】
___提供的地质、测量、水文等勘察成果必须真实、准确。
A. 勘察单位
B. 设计单位
C. 建设主管部门
D. 其他单位
【单选题】
___应当根据勘察成果文件进行建设工程设计。
A. 设计单位
B. 监理单位
C. 建设单位
D. 其他部门
【单选题】
设计单位应当就审查合格的施工图设计文件向___作出详细说明。
A. 施工单位
B. 建筑部门
C. 国家
D. 其他部门
【单选题】
下列哪个单位应当依法取得相应等级的资质证书,并在其资质等级许可的范围内承揽工程___。
A. 建设单位
B. 房地产公司
C. 施工单位
D. 工程单位
【单选题】
___施工单位超越本单位资质等级许可的业务范围或者以其他施工单位的名义承揽工程。
A. 许可
B. 禁止
C. 在某些特殊情况下许可
D. 在建设主管部门许可下可以
【单选题】
___施工单位允许其他单位或者个人以本单位的名义承揽工程。
A. 许可
B. 禁止
C. 在某些特殊情况下可以
D. 在建设主管部门许可下可以
【单选题】
___不得转包或者违法分包工程。
A. 施工单位
B. 建设单位
C. 房地产公司
D. 所有建筑相关部门
【单选题】
施工单位在施工过程中发现设计文件和图纸有差错的,应当___。
A. 按照常规做法来做
B. 按照相关规定来做
C. 及时提出意见和建议
D. 及时向有关部门报告