刷题
导入试题
【单选题】
You have been tasked with blocking user access to websites that violate company policy, but the sites use dynamic IP addresses. What is the best practice for URl filtering to solve the problem?___
A. Enable URL filtering and use URL categorization to block the we bsites that violate company
B. Enable URL filtering and create a blacklist to block the websites that violate company policy
C. Enable URL filtering and create a whitelist to block the websites that violate company policy
D.
E. nable URL filtering and use URL categorization to allow only the websites that company policy allows users to access.
查看试卷,进入试卷练习
微信扫一扫,开始刷题
答案
A
解析
暂无解析
相关试题
【单选题】
Within an 802. 1x-enabled network with the auth Fail feature configured, when does a switch port get placed into a restricted VLAN?___
A. When a conected client fails to authenticate after a certain number of attempts.
B. if a connected client does not support 802. 1x
C. when AAA new-model is ena bled
D. after a connected client exceeds a specified idle time
E. when 802. 1x is not globally enabled on the Cisco Catalyst switch
【单选题】
Which type of attack does a proxy firewall protect against ?___
A. cross-site scripting attack
B. worm traffic
C. port scanning
D. DDoS attacks
【单选题】
When an administrator initiates a device wipe command from the ISE, what is the immediate effect?___
A. It requests the administrator to choose between erasing all device data or only managed corporate data.
B. It requests the administrator to enter the device pin or password before proceeding with the operation
C. It notifies the device user and proceeds with the erase operation
D. It immediately erases all data on the device
【单选题】
What is a valid implicit permit rule for traffic that is traversing the ASa firewall?___
A. ARPs in both directions are permitted in transparent mode only
B. Unicast IPv4 traffic from a higher security interface to a lower security interface is permittee in routed mode only.
C. Unicast IPv6 traffic from a higher security interface to a lower security interface is permitted in transparent mode only.
D. Only BPDUs from a higher security interface to a lower secur ity interface are permitted in transparent mode.
E. Only BPDUs from a higher security interface to a lower secur ity interface are permitted in routed mode
【单选题】
A specific URL has been identified as containing malware. What action can you take to block users from accidentally visiting the URl and becoming infected with malware ?___
A. Enable URL filtering on the perimeter router and add the URls you want to block to the router's local URL list
B. Enable URL filtering on the perimeter firewall and add the URls you want to allow to the router's local URL list.
C. Enable URL filtering on the perimeter router and add the URls you want to allow to the firewall's local URL list
D. Create a blacklist that contains the URl you want to block and activate the blacklist on the perimeter rout
E. Create a whitelist that contains the URLs you want to allow and activate the whitelist on the perimeter router.
【单选题】
How does PEAP protect the EAP exchange ?___
A. It encrypts the exchange using the server certificate
B. It encrypts the exchange using the client certificate
C. It validates the server-supplied certificate,and then encrypts the exchange using the client certificate
D. It validates the client-supplied certificate,and then encrypts the excha nge using the server certificate
【单选题】
Which feature of the Cisco Email Security Appliance can mitigate the impact of snowshoe spam and sophisticated phishing attacks?___
A. contextual analysis
B. holistic understanding of threats
C. graymail management and filtering
D. signature-based IPS
【单选题】
Refer to the exhibit【nat (inside,outside)dunamic interface】 Which translation technique does this configuration result in?___
A. DynamIc PAT
B. Dynamic NAT
C. Twice NAT
D. Static NAT
【单选题】
Refer to the exhibit which are repre sents the data center?___
A. A
B. B
C. C
D. D
【单选题】
While trouble shooting site-to-site VPN, you issued the show crypto isakmp sa command. What does the given output show?___
A. IKE Phase 1 main mode was created on 10.1.1.5, but it failed to negotiate with 10.10 10.2
B. IKE Phase 1 main mode has successfully negotiated between 10.1.1.5 and 10.10..
C. IKE Phase 1 aggressive mode was created on 10.1.1.5, but it failed to negotiate with
【单选题】
Refer to the exhibit All ports on switch 1 have a primary vLan of 300 Which devices can host 1 reach?___
A. host 2
B. server
C. host 4
D. other devices within VLAN303
【单选题】
Which option is the cloud-based security service from Cisco the provides URL filtering, web browsing content security, and roaming user protection?___
A. Cloud Web service
B. Cloud Advanced Malware Protection
C. Cloud We b Security
D. Cloud Web Protection
【单选题】
How can you detect a false negative on an IPS?___
A. View the alert on the ips
B. Review the ips log
C. Review the is console
D. Use a third- party system to perform penetration testing.
E. Use a third- party to audit the next generation firewall rules
【单选题】
If a switch port goes directly into a blocked state only when a superior BPDU is received, what mechanism must be in use?___
A. STP BPDU guard
B. Loop guard
C. EtherChannel guard
D. STP Root guard
【单选题】
what improvement does EAP-FASTv2 provide over EAP-FAST? ___
A. It allows multiple credentials to be passed in a single EAP exchange.
B. It supports more secure encryption protocols
C. It allows faster authentication by using fewer packets.
D. It addresses security vulnerabilities found in the original protocol
【单选题】
When users login to the Client less Ssl Vpn using https://209.165.201.2/test ,which group policy will be applied?___
A. test
B. clientless
C. sales
D. DfitGrp Policy
E. Default RAGroup
F. Default WEB VPN
G. roup
【单选题】
Which user authentication method is used when users login to the Clientless SSLVPN portal using https://209.165.201.2/test?___
A. AAA with LOCAL database
B. AAA with RADIUS server
C. Certificate
D. :Both Certificate and aaa with LoCAL database
E. Both Certificate and AAA with RADIUS server
【单选题】
What' s the technology that you can use to prevent non malicious program to runin the computer that is disconnected from the network?___
A. Firewall
B. Sofware Antivirus
C. Network IPS
D. Host IPS
【单选题】
Which statement about the communication between interfaces on the same security level is true?___
A. Interfaces on the same security level require additional configuration to permit interinterface communication
B. Configuring interfaces on the same security level can cause asymmetric routing
C. All traffic is allowed by default between interfaces on the same security level
D. You can configure only one interface on a n individual security level
【单选题】
Which product can be used to provide application layer protection for tcp port 25 traffic?___
A. ESA
B. CWS
C. WSA
D. ASA
【单选题】
which iPS mode is less secure than other options but allows optimal network through put ?___
A. inline mode
B. inline-bypass mode
C. transparent mode
D. Promiscuous mode
【单选题】
Which feature of the Cisco Email security Appliance can mitigate the impact of snowshoe spam and sophisticated phishing attack?___
A. reputation based filtering
B. signature based IPS
C. contextual analysis
D. graymail management and filtering
【单选题】
Which type of social-engineering attack uses normal tele phone service as the attack vector?___
A. smishing
B. dialing
C. phishing
D. vishing
【单选题】
Which quantifiable item should you consider when you organization adopts new technologies?___
A. exploits
B. vulnerability
C. threat
D. Risk
【单选题】
Referencing the ClA model, in which scenario is a hash- only function most appropriate ?___
A. securing data at rest
B. securing real-time traffic
C. securing data in files
D. securing wireless transmissions
【单选题】
Which ports must be open between a aaa server and a microsoft server to permit Active Directory authentications?___
A. 445 and 389
B. 888 and 3389
C. 636 and 4445
D. 363 and 983
【单选题】
Refer to the exhibit for which reason is the tunnel unable to pass traffic___
A. the tunnel is failing to receive traffic from the remote peer
B. the local peer is unable to encrypt the traffic
C. the ip address of the remote peer is incorrect
D. UDP port 500 is blocked
【单选题】
Which type of attack can exploit design flaws in the implementation of an application without___
A. DHCP starvation attacks
B. low-rate dos attacks
C. application DDos flood attacks
D. application DDoS flood attacks
E. volume-based DDoS attacks
【单选题】
How can you protect CDP from reconnaissance attacks?___
A. Enable dynamic ARP inspection on all untrusted ports.
B. Enable dot1x on all ports that are connected to other switches.
C.
D. isable CDP on ports connected to endpoints.
【单选题】
Which type of attack can exploit design flaws in the implementation of an application without ?___
A. DHCP starvation attacks
B. low-rate dos attacks
C. application DDos flood attacks
D. application DDoS flood attacks
E. volume-based DDoS attacks
【单选题】
Which option is a key security compone nt of and MDM deployment ?___
A. using network-specific installer packages
B. using an application tunnel by default
C. using self-signed certificates to validate the server
D. using MS-CHAPv2 as the primary
E. AP method
【单选题】
Which Firepower Management Center feature detects and block exploits and hack attempts?___
A. Content blocker
B. file control
C. intrusion prevention
D. advanced malware protection
【单选题】
hich description of the nonsecret numbers that are used to start a Diffie- Hellman exchange is ture?___
A. They are preconfigured prime integers.
B. They are large pseudorandom numbers.
C. They are very small numbers chosen from a table of known valuses
D. They are numeric values extracted from ha shed system hostnames
【多选题】
Which two characteristics of an application layer firewall are true?___
A. provides stateful firewal functionality
B. has low processor usage
C. provides protection for multiple applications
D. provides rever se proxy services
E. is immune to URL manipulation
【多选题】
Which two devices are components of the BYOD architectural framework?___
A. Nexus 7010 switch
B. Cisco 3945 Router
C. Identify Services Engine
D. Wireless Access oints
E. Prime Infrastructure
【多选题】
Which two actions can a zone based firewall take when looking at traffic? ___
A. forward
B. inspect
C. drop
D. broadcast
E. filter
【多选题】
n which two situations should you use in-band management?___
A. when management applications need concurrent access to the device
B. when you require administrator access from multiple locations
C. when a network device fails to forward packets
D. when you require ROMMON access
E. when the control plane fails to respond
【多选题】
What are two ways to prevent eavesdropping when you perform device management tasks?___
A. Use an SSH connection.
B. Use SNMPv3
C. Use out-of-band management
D. Use SNMP
E. Use in-band management
【多选题】
Which two features are commonly used CoPP and CPPr to protect the control plane? ___
A. QoS
B. traffic classification
C. access lists
D. policy maps
E. class maps
F. Cisco Express Forwarding
【多选题】
Which four tunne ling prot ocols are enabled in the Dfit GrpPolicy group policy ?___
A. Clientless SSL VPN
B. SSL VPN Client
C. PPTP
D. L2TP/IPsec
E. IPsec IKEv1
F. IPsec IKEv2
推荐试题
【多选题】
协定存款合同期满,甲方需要销户,必须于距合同到期日___天前向乙方提出书面销户通知,并于到期日办理销户手续。
A. 5天
B. 10天
C. 15天
D. 20天
【多选题】
对协定存款账户销户的,如果在结息日销户,超过基本存款额度部分的存款按___挂牌公布的协定存款利率计息;如果不在结息日销户,超过基本存款额度部分的存款从上一结息日起到销户日止,不再按协定存款利率计息,而按( )挂牌公布的活期存款利率计息。
A. 结息日、销户日
B. 开户日、销户日
C. 结息日、开户日
D. 开户日,开户日
【多选题】
原则上在绍兴银行开立单位结算账户,且开户期限已满一个___的单位才能申请办理协定存款。
A. 月
B. 季度
C. 会计年度
【多选题】
合同期内,存款单位原则上不得要求销户,如遇特殊情况,须向经办行提交书面销户申请(见附件3),经办行在收到销户申请后___内答复。
A. 3天
B. 5天
C. 3个工作日
D. 5个工作日
【多选题】
下面关于单位协定存款说法正确的有___。
A. 开户单位要与银行签订《绍兴银行人民币单位协定存款合同》;
B. 开立单位结算账户的中华人民共和国境内的法人及其他组织;
C. 具有结算和协定存款双重功能;
D. 并约定基本存款额度,约定期限,由银行将协定存款账户中超过该额度的部分按协定存款利率单独计息的一种存款方式。
【多选题】
下列关于单位协定存款说法正确的有___。
A. 单位开立协定存款基本存款额度不得低于10万元;
B. 协定存款按日计息,按季结息;
C. 协定存款最长不超过1年(含1年);
D. 《单位协定存款合同》与开户申请书一起专夹保管。
【多选题】
定期保证金进行置款的交易码___。
A. 2401
B. 2410
C. 2402
D. 2411
【多选题】
二十、非银承保证金的销户和提前置换销户的银承保证金,需要客户经理提供___通知书。
A. 开户
B. 变动
C. 调整
D. 销户
【多选题】
处理保证金追加追减锁定时,如果业务类型选择___ ,需要选择输入签发标识本行签发/他行代签,其他类型置灰,不需要输入。
A. 国际结算
B. 保函
C. 国内信用证
D. 远期结售汇
【多选题】
保证金通过相关交易、国结系统及前台追加锁定金额进行管理,锁定金额不得___可用余额。
A. 小于
B. 小于等于
C. 大于
D. 大于等于
【多选题】
三十一、对于银承保证金,追加减是通过票据系统的银承开立销户时关联保证金时___加减的。
A. 自动
B. 操作存取
C. 操作转账
【多选题】
受理审核保证金业务。柜员应审核:___
A. 客户提交的付款凭证转帐支票
B. 转账支票,绍兴银行保证金开户告知书
C. 现金支票,绍兴银行保证金开户告知书
D. 现金支票,绍兴银行保证金开户通知书
【多选题】
保证金业务下设立___产品。
A. 银承保证金
B. 保函保证金
C. 开证项下保证金
D. 其它保证金
【多选题】
办理下列哪些业务需要客户经理提供保证金变动通知书。___
A. 非银承保证金的销户
B. 银承保证金的销户
C. 提前置换销户的银承保证金,
D. 以上都是
【多选题】
下列说法哪些是正确的 ___。
A. 活期类保证金在季度结息时将利息计入保证金本身活期账户。
B. 定期类账户可通过柜面进行单独结息或结息销户;定期未到期前只能进行结息销户,不能进行单独结息。
C. 保证金被部分或全部锁定时,不能进行结息销户。
D. 活期保证金账户对应的锁定业务到期后,相应的锁定金额不再计算利息。
E. 定期保证金账户到期后,计活期利息。定期保证金到期前支取的,支取部份的积数将从定期积数转入活期积数。
【多选题】
以下哪些签发开立时,需要存一部分资金在银行作为保证金。 ___
A. 银行承兑汇票
B. 开立保函
C. 开立信用证
D. 三省一市汇票
【多选题】
以下关于保证金参数定义的说法正确的有___。
A. 到期日:用于记录定期保证金到期日,定期保证金在开户时可以自行设置到期日,但不能小于原存期的对日到期日。
B. 锁定金额:通过相关交易、国结系统及前台追加锁定金额进行管理,锁定金额不得大于可用余额。
C. 可支取余额:账户余额减去锁定金额,即可用于追加锁定或支取的金额。
D. 票据流水号:信贷系统的借据号、电子商业汇票系统的汇票号码、国结系统的业务序号,用于对应每笔具体业务。
【多选题】
集中核算账户分为父账户(集团账户)与子账户(各核算单位账户),父账户账号使用原有实体账号,各子账户虚拟账号组成为___
A. 父账号+三位子账号编号
B. 父账号+四位子账号编号
C. 父账号+五位子账号编号
D. 父账号+六位子账号编号
【多选题】
对公集中核算账户是为方便集团实现下属各单位账户集中管理、分户核算而设立的人民币___。
A. 定期存款账户
B. 活期存款账户
C. 结算账户
D. 储蓄账户
【多选题】
集团子账户户名的修改及子账户的删除,只有___的子账户才能作删除操作。
A. 余额为0
B. 余额大于0
C. 余额小于1
D. 余额大于1
【多选题】
对公集中核算账户是为方便集团实现下属各单位账户集中管理、分户核算而设立的人民币活期存款账户;由集团统一开设账户,集团账户为使用实体账号___集团下各核算单位为使用虚拟账号的( ) 。
A. 虚拟账户; 实体账户
B. 主账户 ; 子账户
C. 总账户 ;分账户
【多选题】
子户账号=父账号+四位子账号编号,子户账号可以在常规的对公活期交易里操作,比如___。
A. 存取款
B. 转账
C. 销户
D. 以上都对
【多选题】
下列说法错误的是___
A. 当集中核算账户设定时,需要先对活期账户临时结息;
B. 开立子户时,主户的余额必须全部分配给子户;
C. 一经开立了子户,主户不能再有业务进出;
D. 子户账号=父账号+五位子账号编号。
【多选题】
关于集中核算账户设定及取消,以下正确的是哪些 ___
A. 当集中核算账户设定时,由于集团父账户余额分配至各集团子户,不需要先对活期账户临时结息。
B. 主账户设定为集团账户后,原账户的通存通兑标志失效,以设定时指定的通存通兑标志进行交易限制;所开设的所有子户都遵循该通兑规则。
C. 作集团主户的取消交易时,控制其主户下只剩下一个子户才可取消(子户结清交易,见后),且该子户系集团账户的利息入账子户。
【多选题】
集中核算账户的父账户可打印全体子户汇总的账单信息,各子账户可分别查询到交易明细,交易码有___
A. 2612
B. 2611
C. 2436
D. 2435
【多选题】
下列关于集中核算账户说法正确的有___
A. 集中核算账户的父账户余额为各子账户余额的总和,但其可用余额为零,无法进行结算;
B. 开立子户时,主户的余额必须全部分配给子户,一经开立了子户,主户可以有业务进出;
C. 当子户绑定主户利息时,不允许结清,要做利息入账维护;
D. 当子户为最后一个子户时,不允许结清,只能取消主户设定来实现。
【多选题】
关于集团账户描述正确的是___
A. 当集团主户的取消时,控制其主户下只剩下一个子户才可取消(子户结清交易,见后),且该子户系集团账户的利息入账子户。当取消集团主户时,系统自动会把剩下的子户本息转入集团主户,且取消其集团主户的功能;
B. 当子户绑定主户利息时,不允许结清,要做利息入账维护;
C. 当子户为最后一个子户时,不允许结清,只能取消主户设定来实现;
D. 集团子账户查询维护主要用于子账户户名的修改及子账户的删除,只有余额为0的子账户才能作删除操作。
【多选题】
类多级账簿分为___户和( )户。
A. 大 小
B. 多 少
C. 主 子
D. 主 散
【多选题】
___交易主要用于主户签约、主户解约、主户查询、子户签约、子户解约、子户修改、子户查询功能
A. 2421
B. 2422
C. 2423
D. 2424
【多选题】
R、类多级账簿分为主户和子户两个概念,其中主户是___,子户使用( )。子户是在主户下开设的分类明细核算账户,并能核算并记载各个子户资金收付明细信息及交易对手信息。
A. 实体结算账号 虚拟账号
B. 虚拟卡号 实体结算账号
C. 实体结算账号 虚拟账号
D. 实体结算账号 虚拟账号或虚拟卡
【多选题】
“2421类多级账簿协议管理”交易主要用于___功能。
A. 主户签约
B. 主户解约
C. 主户查询
D. 子户签约
E. 子户解约
F. 子户修改
G. 子户查询
【多选题】
类多级账簿具有哪些特点___
A. 核算精准
B. 设置灵活
C. 操作方便
【多选题】
类多级账簿主要适用于___企事业单位。
A. 财政
B. 学校
C. 资金集中管理
D. 分级核算
【多选题】
假设某公司于2016年8月3日签约类多级账簿业务,其中,签约生效日可以输入为___,签约到期日默认( )。
A. 2016-08-03 2017-08-03
B. 2016-08-03 2099-12-31
C. 2016-08-04 2017-08-03
D. 2016-08-04 2099-12-31
【多选题】
子账户修改可以修改___
A. 子户户名
B. 期末余额
C. 期初余额
D. 子户余额
【多选题】
十七、公存溢是指面向公司类客户发行的,单笔金额在___万(含)人民币以上的定期存款产品。
A. 100
B. 200
C. 500
D. 1000
【多选题】
办理公存溢业务的公司类客户是指在中华人民共和国境内依法成立的企业客户、党政机关、事业及社会团体客户,其利率按人民银行同档次基准利率上浮___%执行。
A. 10
B. 20
C. 30
D. 40
【多选题】
客户办理“公存溢”存款开户时,需要提供___。
A. 开户资料
B. 付款凭证
C. “公存溢”存款开户审批表。
【多选题】
公存溢单位定期存款(中长期)——人民币,产品存期为:___
A. 1年
B. 2年
C. 3年
D. 5年
【多选题】
公存溢单位定期存款的产品存期有___。
A. 1个月
B. 3个月
C. 6个月
D. 1年
E. 2年
F. 3年
G. 5年。
欢迎使用我爱刷题
×
微信搜索我爱刷题小程序
温馨提示
×
请在电脑上登陆“www.woaishuati.com”使用