【单选题】
While trouble shooting site-to-site VPN, you issued the show crypto isakmp sa command. What does the given output show?___
A. IKE Phase 1 main mode was created on 10.1.1.5, but it failed to negotiate with 10.10 10.2
B. IKE Phase 1 main mode has successfully negotiated between 10.1.1.5 and 10.10..
C. IKE Phase 1 aggressive mode was created on 10.1.1.5, but it failed to negotiate with
查看试卷,进入试卷练习
微信扫一扫,开始刷题
相关试题
【单选题】
Refer to the exhibit All ports on switch 1 have a primary vLan of 300 Which devices can host 1 reach?___
A. host 2
B. server
C. host 4
D. other devices within VLAN303
【单选题】
Which option is the cloud-based security service from Cisco the provides URL filtering, web browsing content security, and roaming user protection?___
A. Cloud Web service
B. Cloud Advanced Malware Protection
C. Cloud We b Security
D. Cloud Web Protection
【单选题】
How can you detect a false negative on an IPS?___
A. View the alert on the ips
B. Review the ips log
C. Review the is console
D. Use a third- party system to perform penetration testing.
E. Use a third- party to audit the next generation firewall rules
【单选题】
If a switch port goes directly into a blocked state only when a superior BPDU is received, what mechanism must be in use?___
A. STP BPDU guard
B. Loop guard
C. EtherChannel guard
D. STP Root guard
【单选题】
what improvement does EAP-FASTv2 provide over EAP-FAST? ___
A. It allows multiple credentials to be passed in a single EAP exchange.
B. It supports more secure encryption protocols
C. It allows faster authentication by using fewer packets.
D. It addresses security vulnerabilities found in the original protocol
【单选题】
When users login to the Client less Ssl Vpn using https://209.165.201.2/test ,which group policy will be applied?___
A. test
B. clientless
C. sales
D. DfitGrp Policy
E. Default RAGroup
F. Default WEB VPN
G. roup
【单选题】
Which user authentication method is used when users login to the Clientless SSLVPN portal using https://209.165.201.2/test?___
A. AAA with LOCAL database
B. AAA with RADIUS server
C. Certificate
D. :Both Certificate and aaa with LoCAL database
E. Both Certificate and AAA with RADIUS server
【单选题】
What' s the technology that you can use to prevent non malicious program to runin the computer that is disconnected from the network?___
A. Firewall
B. Sofware Antivirus
C. Network IPS
D. Host IPS
【单选题】
Which statement about the communication between interfaces on the same security level is true?___
A. Interfaces on the same security level require additional configuration to permit interinterface communication
B. Configuring interfaces on the same security level can cause asymmetric routing
C. All traffic is allowed by default between interfaces on the same security level
D. You can configure only one interface on a n individual security level
【单选题】
Which product can be used to provide application layer protection for tcp port 25 traffic?___
A. ESA
B. CWS
C. WSA
D. ASA
【单选题】
which iPS mode is less secure than other options but allows optimal network through put ?___
A. inline mode
B. inline-bypass mode
C. transparent mode
D. Promiscuous mode
【单选题】
Which feature of the Cisco Email security Appliance can mitigate the impact of snowshoe spam and sophisticated phishing attack?___
A. reputation based filtering
B. signature based IPS
C. contextual analysis
D. graymail management and filtering
【单选题】
Which type of social-engineering attack uses normal tele phone service as the attack vector?___
A. smishing
B. dialing
C. phishing
D. vishing
【单选题】
Which quantifiable item should you consider when you organization adopts new technologies?___
A. exploits
B. vulnerability
C. threat
D. Risk
【单选题】
Referencing the ClA model, in which scenario is a hash- only function most appropriate ?___
A. securing data at rest
B. securing real-time traffic
C. securing data in files
D. securing wireless transmissions
【单选题】
Which ports must be open between a aaa server and a microsoft server to permit Active Directory authentications?___
A. 445 and 389
B. 888 and 3389
C. 636 and 4445
D. 363 and 983
【单选题】
Refer to the exhibit for which reason is the tunnel unable to pass traffic___
A. the tunnel is failing to receive traffic from the remote peer
B. the local peer is unable to encrypt the traffic
C. the ip address of the remote peer is incorrect
D. UDP port 500 is blocked
【单选题】
Which type of attack can exploit design flaws in the implementation of an application without___
A. DHCP starvation attacks
B. low-rate dos attacks
C. application DDos flood attacks
D. application DDoS flood attacks
E. volume-based DDoS attacks
【单选题】
How can you protect CDP from reconnaissance attacks?___
A. Enable dynamic ARP inspection on all untrusted ports.
B. Enable dot1x on all ports that are connected to other switches.
C.
D. isable CDP on ports connected to endpoints.
【单选题】
Which type of attack can exploit design flaws in the implementation of an application without ?___
A. DHCP starvation attacks
B. low-rate dos attacks
C. application DDos flood attacks
D. application DDoS flood attacks
E. volume-based DDoS attacks
【单选题】
Which option is a key security compone nt of and MDM deployment ?___
A. using network-specific installer packages
B. using an application tunnel by default
C. using self-signed certificates to validate the server
D. using MS-CHAPv2 as the primary
E. AP method
【单选题】
Which Firepower Management Center feature detects and block exploits and hack attempts?___
A. Content blocker
B. file control
C. intrusion prevention
D. advanced malware protection
【单选题】
hich description of the nonsecret numbers that are used to start a Diffie- Hellman exchange is ture?___
A. They are preconfigured prime integers.
B. They are large pseudorandom numbers.
C. They are very small numbers chosen from a table of known valuses
D. They are numeric values extracted from ha shed system hostnames
【多选题】
Which two characteristics of an application layer firewall are true?___
A. provides stateful firewal functionality
B. has low processor usage
C. provides protection for multiple applications
D. provides rever se proxy services
E. is immune to URL manipulation
【多选题】
Which two devices are components of the BYOD architectural framework?___
A. Nexus 7010 switch
B. Cisco 3945 Router
C. Identify Services Engine
D. Wireless Access oints
E. Prime Infrastructure
【多选题】
Which two actions can a zone based firewall take when looking at traffic? ___
A. forward
B. inspect
C. drop
D. broadcast
E. filter
【多选题】
n which two situations should you use in-band management?___
A. when management applications need concurrent access to the device
B. when you require administrator access from multiple locations
C. when a network device fails to forward packets
D. when you require ROMMON access
E. when the control plane fails to respond
【多选题】
What are two ways to prevent eavesdropping when you perform device management tasks?___
A. Use an SSH connection.
B. Use SNMPv3
C. Use out-of-band management
D. Use SNMP
E. Use in-band management
【多选题】
Which two features are commonly used CoPP and CPPr to protect the control plane? ___
A. QoS
B. traffic classification
C. access lists
D. policy maps
E. class maps
F. Cisco Express Forwarding
【多选题】
Which four tunne ling prot ocols are enabled in the Dfit GrpPolicy group policy ?___
A. Clientless SSL VPN
B. SSL VPN Client
C. PPTP
D. L2TP/IPsec
E. IPsec IKEv1
F. IPsec IKEv2
【多选题】
Which two statements regarding the aSA VPN configurations are correct?___
A. The asa has a certificate issued by an external certificate authority associated to the ASDM TrustPoint1
B. The Default WEBVPNGroup Connection Profile is using the aaa with RADIUS server method
C. The Inside-srvbook mark references the https://192.168.1.2url
D. Only Clientless SSL VPN access is allowed with the Sales group policy
E. Any Connect, IPSec IKEv1, and IPSec IKEv2 VPN access is enabled on the outside interface
F. The Inside -SRV bookmark has not been applied to the Sales group policy
【多选题】
Which three ESP fields can be encrypted during transmission?___
A. Security Parameter Index
B. Sequence Number
C. MAC Address
D. Padding
E. Pad length
F. Next Header
【多选题】
.Which three statements de scribe DHCP spoofing attacks?___
A. They can modify traffic in transit.
B. They are used to perform man- in-the-middle attacks
C. They use ARP poisoning
D. They can access most network devices
E. They protect the ide ntity of the attacker by masking the DHCP address.
F. They are can physically modify the network gateway.
【多选题】
Which statement about the communication between interfaces on the same security level is true?___
A. Interfaces on the same security level require additional configuration to permit interinterface communication
B. Configuring interfaces on the same security level can cause asymmetric routing
C. All traffic is allowed by default between interfaces on the same security level
D. You can configure only one interface on a n individual security level
【多选题】
In which two situations should you use in band management? ___
A. when the control plane fails to respond
B. when you require administrator access from multiple locations
C. when you require ROMMON access.
D. where a network device fails to forward packets
E. when multiple ma nagement applications need concument access to the device.
【多选题】
Which two features are supported in a VRF-aware softwar infrastructure before VRF-lite?___
A. multicast
B. fair queuing
C. WCCP
D.
E. IGRP
【多选题】
.Which loS command do you enter to test authentication again a AAA server?___
A. dialer aaa suffix <suffix> password <password>
B. ppp authentication chap pap test
C. test aaa-server authentication dialer group user name <user> password <password>
D. aaa authentication enable default test group tacases
【多选题】
Which two statements about the self zone on a cisco Xone based policy firewall are true?___
A. Multiple interfaces can be assigned to the self zone
B. it supports stateful inspections for multicast traffic
C. zone pairs that include the self zone apply to traffic transiting the device.
D. it can be either the source zone or the destination zone
E. traffic entering the self zone must match a rule
【多选题】
Which type of attack can exploit design flaws in the implementation of an application without ?___
A. DHCP starvation attacks
B. low-rate dos attacks
C. application DDos flood attacks
D. application DDoS flood attacks
E. volume-based DDoS attacks
【单选题】
Which type of firewall can server as the interme diary between a client and a server ?___
A. Stateless firewall
B. application firewall
C. proxy firewall
D. personal firewall
推荐试题
【单选题】
检疫处理单位应妥善保存检疫处理工作记录、检疫处理结果报告单、检疫处理方案及效果评价等相关资料,保存期为________。___
【单选题】
《出入境检疫处理单位和人员管理办法》规定,《出入境检疫处理人员从业资格证》有效期为________。___
【单选题】
作出出入境检疫处理单位核准决定的,应当自作出决定之日起________颁发并送达《出入境检疫处理单位核准证书》___
A. 5日内
B. 7日内
C. 10日内
D. 15日内
【单选题】
海关在现场查验过程中发现符合检疫处理指征的,应向交通工具负责人、货主或者代理人出具________。___
A. 卫生处理结果报告单
B. 检验检疫处理通知书
C. 卫生处理原始记录单
D. 卫生处理通知书
【单选题】
________不属于出入境检疫处理高风险业务。___
A. 交通工具的熏蒸处理
B. 突发公共卫生事件检疫处理
C. 发现检疫性有害生物并需要检疫处理的
D. 废旧物品的消毒处理
【单选题】
________不属于卫生处理监管工作检查重点。___
A. 检验检疫处理通知书
B. 检疫处理结果报告单
C. 检疫处理原始记录单
D. 报关单
【单选题】
《检疫处理结果报告单》中,________不是必填内容。___
A. 处理药剂
B. 处理时间
C. 散毒时间
D. 处理方法
【单选题】
当发现病媒生物应当实施卫生处理时,应开具________告知当事人。___
A. 《检疫处理工作记录》
B. 《检疫处理业务联系单》
C. 《检疫处理结果报告单》
D. 《检验检疫处理通知书》
【单选题】
检疫处理单位应当根据不同类型的卫生处理任务制定相应的________,明确检疫处理人员、药品、器械以及防护用品等配置要求,报当地检验检疫机构备案。___
A. 检疫处理计划
B. 检疫处理方案
C. 检疫处理规范
D. 检疫处理作业指导书
【单选题】
《检验检疫处理通知书》上注明,要对一艘国际航行船舶进行喷洒除虫处理,资质类别为________的检疫处理单位符合上述卫生处理作业要求。___
A. A类-船舶熏蒸
B. B类-普通熏蒸
C. C类-消毒处理(除熏蒸外)
D. D类-除虫灭鼠(药物和器械)
【单选题】
出入境检疫处理按照实施方式和技术要求分为________。___
【单选题】
检疫处理单位法人变更,应当于变更之日起________,到颁发《核准证书》的直属海关申请办理变更手续。___
A. 10日内
B. 20日内
C. 30日内
D. 40日内
【单选题】
检疫处理人员未按照技术要求和操作规程进行操作的,由海关给予警告或者处以________罚款。___
A. 1000元以下
B. 2000元以下
C. 5000元以下
D. 10000元以下
【单选题】
下列关于卫生处理药品储存管理的表述,错误的是:___
A. 保管人员应为健康成年人,经过专业培训,持证上岗
B. 贮存卫生处理药物的仓库,应建立严格的出入库管理制度
C. 药品入库验收应在库房外安全地点进行
D. 药品出库,应按生产日期选用最新的药品出库
【单选题】
出入境口岸除虫效果快速评价方法中的虫样法,在除虫开始前,将效果检测虫样放入虫样笼中,每笼中的效果检测虫样与虫样笼不得少于___________
A. 5头、5笼
B. 8头、5笼
C. 10头、5笼
D. 12头、8笼
【单选题】
入出境霍乱染疫列车卫生处理范围不包括:___
A. 载有染疫人的车厢
B. 载有染疫人车厢的相邻车厢
C. 染疫列车停靠周围50米
D. 本口岸同时段所有入出境列车
【单选题】
对集装箱实施熏蒸处理,投药2小时进行浓度测定,平均熏蒸剂浓度不应低于投药量的________。___
A. 78%
B. 65%
C. 50%
D. 30%
【单选题】
使用含氯消毒剂对入出境船舶废弃物进行直接投药消毒,1000mL消毒物中需加入50mL含有效氯________的含氯消毒溶液,搅拌均匀,放置________。___
A. 10000mL;30分钟
B. 10000 mL;60分钟
C. 20000 mL;60分钟
D. 20000 mL;120分钟
【单选题】
________的主要成分为季铵盐类。___
A. 优莱洁环境消毒液
B. 泰胜消毒片
C. 漂白粉
D. 84消毒液
【单选题】
评价氯化消毒剂的简便指标是________。___
A. 加氯总量
B. 含氯总量
C. 余氯量
D. 有效氯
【单选题】
携带活蚊的入出境航空器,应当实施________。___
【单选题】
航空器除鼠进行效果评价时粉剂法布设规格为________。___
A. 10厘米×10厘米
B. 15厘米×15厘米
C. 20厘米×20厘米
D. 30厘米×30厘米
【单选题】
航空器除鼠的效果评价,除鼠时间不应少于________。___
A. 6小时
B. 12小时
C. 18小时
D. 24小时
【单选题】
船舶硫酰氟熏蒸除鼠投放药物时,投药分组进行,每组两人,在现场负责人的组织指挥下,按顺序自________而________,由里往外,由________风向到________风向依次投药。___
A. 上;下;下;上
B. 下;上;下;上
C. 上;下;上;下
D. 下;上;上;下
【单选题】
国际航行船舶硫酰氟除鼠中发生硫酰氟钢瓶泄漏时,应穿上防护服,戴上________,进行处理。___
A. N95口罩
B. 普通口罩
C. 全面罩
D. 自给式呼吸器
【单选题】
入出境霍乱染疫航空器到达后,应先处理________。___
A. 航空器入口处及通道
B. 染疫人的呕吐物、排泄物
C. 被污染的食物、餐具、用具
D. 染疫人使用过的厕所
【单选题】
实施蒸熏除鼠的列车要远离正常生产、作业区域或者使现场人员远离蒸熏列车,列车应调到安全的轨道,离开其他列车________以上。___
A. 50 m
B. 100 m
C. 200 m
D. 400 m
【单选题】
列车熏蒸除鼠应安排好人员巡逻,密封和散毒时注意警戒,上风向________,下风向________内禁止列车、人员靠近。___
A. 20 m;50 m
B. 40 m;80 m
C. 50 m;100 m
D. 80 m;200 m
【单选题】
入出境国际航行船舶熏蒸除鼠,采取靠泊熏蒸的,应安排人员在码头上巡逻,上风向________,下风向________内禁止船舶、人员靠近,以保证船舶熏蒸期间的安全。___
A. 20 m;50 m
B. 50 m;80 m
C. 50 m;100 m
D. 80 m;200 m
【单选题】
发生硫酰氟药液沾入眼睛时,应立即用大量清洁流水冲洗眼睛至少____,并送医院检查治疗。___
A. 2 min
B. 3 min
C. 4 min
D. 5 min
【单选题】
发生硫酰氟钢瓶泄漏时,应穿上防护服,戴上自给式呼吸器进行处理;不能立即解决时,应尽快将钢瓶移至空旷安全处或将其排空于________和熟石灰的混合物中。___
【单选题】
船舶硫酰氟熏蒸除鼠投药、散毒时的个人防护措施是________。___
A. 配戴医用口罩
B. 配戴自给多呼吸器、面罩
C. 配戴滤毒罐、面罩
D. 配戴N95口罩
【单选题】
霍乱染疫船舶的压舱水余氯量不低于________,且不应检出霍乱弧菌。___
A. 0.1 mg/L
B. 0.5 mg/L
C. 1 mg/L
D. 5 mg/L
【单选题】
废旧船舶熏蒸散毒时,夜间应在船舶明显处所垂直悬挂________三盏灯号,表示本船正在散毒。___
A. 红、红、红
B. 绿、红、绿
C. 绿、红、红
D. 红、绿、红
【单选题】
________不是国境口岸常用的熏蒸消毒药品。___
A. 环氧乙烷
B. 溴甲烷
C. 过氧乙酸
D. 甲醛
【单选题】
为保证足够的消毒时间,消毒时间应从________开始计算。___
A. 配药完成时
B. 开始施药时
C. 施药结束时
D. 开始配药时
【单选题】
________适用于虫患严重的出入境交通工具、集培箱、货物等可密闭的环境。___
A. 超低容量喷雾
B. 施放胃毒剂
C. 熏蒸
D. 施放触杀剂
【单选题】
有机磷类杀虫剂中毒要及时应用________进行解毒。___
A. 阿司匹林
B. 强的松
C. 安定
D. 阿托品
【单选题】
下列关于不同种类的中毒患者佩戴标志的表述,错误的是:___
A. 出现影响生命的损害,需要紧急处理的,佩戴红色标志
B. 伤害或中毒不严重,可随后处理或转运的,佩戴黄色标志
C. 未中毒、无伤害或轻微中毒,不需要处理或转运的,佩戴绿色标志
D. 无呼吸,甲床黑、无脉搏,重度昏迷的,佩戴红色标志
【单选题】
入境霍乱染疫航空器,卫生处理合格的,签发________。___
A. 运输工具检疫处理通知书
B. 运输工具检疫处理报告
C. 运输工具检疫处理证书
D. 运输工具检疫合格证明