刷题
导入试题
【单选题】
How can you detect a false negative on an IPS?___
A. View the alert on the ips
B. Review the ips log
C. Review the is console
D. Use a third- party system to perform penetration testing.
E. Use a third- party to audit the next generation firewall rules
查看试卷,进入试卷练习
微信扫一扫,开始刷题
答案
D
解析
暂无解析
相关试题
【单选题】
If a switch port goes directly into a blocked state only when a superior BPDU is received, what mechanism must be in use?___
A. STP BPDU guard
B. Loop guard
C. EtherChannel guard
D. STP Root guard
【单选题】
what improvement does EAP-FASTv2 provide over EAP-FAST? ___
A. It allows multiple credentials to be passed in a single EAP exchange.
B. It supports more secure encryption protocols
C. It allows faster authentication by using fewer packets.
D. It addresses security vulnerabilities found in the original protocol
【单选题】
When users login to the Client less Ssl Vpn using https://209.165.201.2/test ,which group policy will be applied?___
A. test
B. clientless
C. sales
D. DfitGrp Policy
E. Default RAGroup
F. Default WEB VPN
G. roup
【单选题】
Which user authentication method is used when users login to the Clientless SSLVPN portal using https://209.165.201.2/test?___
A. AAA with LOCAL database
B. AAA with RADIUS server
C. Certificate
D. :Both Certificate and aaa with LoCAL database
E. Both Certificate and AAA with RADIUS server
【单选题】
What' s the technology that you can use to prevent non malicious program to runin the computer that is disconnected from the network?___
A. Firewall
B. Sofware Antivirus
C. Network IPS
D. Host IPS
【单选题】
Which statement about the communication between interfaces on the same security level is true?___
A. Interfaces on the same security level require additional configuration to permit interinterface communication
B. Configuring interfaces on the same security level can cause asymmetric routing
C. All traffic is allowed by default between interfaces on the same security level
D. You can configure only one interface on a n individual security level
【单选题】
Which product can be used to provide application layer protection for tcp port 25 traffic?___
A. ESA
B. CWS
C. WSA
D. ASA
【单选题】
which iPS mode is less secure than other options but allows optimal network through put ?___
A. inline mode
B. inline-bypass mode
C. transparent mode
D. Promiscuous mode
【单选题】
Which feature of the Cisco Email security Appliance can mitigate the impact of snowshoe spam and sophisticated phishing attack?___
A. reputation based filtering
B. signature based IPS
C. contextual analysis
D. graymail management and filtering
【单选题】
Which type of social-engineering attack uses normal tele phone service as the attack vector?___
A. smishing
B. dialing
C. phishing
D. vishing
【单选题】
Which quantifiable item should you consider when you organization adopts new technologies?___
A. exploits
B. vulnerability
C. threat
D. Risk
【单选题】
Referencing the ClA model, in which scenario is a hash- only function most appropriate ?___
A. securing data at rest
B. securing real-time traffic
C. securing data in files
D. securing wireless transmissions
【单选题】
Which ports must be open between a aaa server and a microsoft server to permit Active Directory authentications?___
A. 445 and 389
B. 888 and 3389
C. 636 and 4445
D. 363 and 983
【单选题】
Refer to the exhibit for which reason is the tunnel unable to pass traffic___
A. the tunnel is failing to receive traffic from the remote peer
B. the local peer is unable to encrypt the traffic
C. the ip address of the remote peer is incorrect
D. UDP port 500 is blocked
【单选题】
Which type of attack can exploit design flaws in the implementation of an application without___
A. DHCP starvation attacks
B. low-rate dos attacks
C. application DDos flood attacks
D. application DDoS flood attacks
E. volume-based DDoS attacks
【单选题】
How can you protect CDP from reconnaissance attacks?___
A. Enable dynamic ARP inspection on all untrusted ports.
B. Enable dot1x on all ports that are connected to other switches.
C.
D. isable CDP on ports connected to endpoints.
【单选题】
Which type of attack can exploit design flaws in the implementation of an application without ?___
A. DHCP starvation attacks
B. low-rate dos attacks
C. application DDos flood attacks
D. application DDoS flood attacks
E. volume-based DDoS attacks
【单选题】
Which option is a key security compone nt of and MDM deployment ?___
A. using network-specific installer packages
B. using an application tunnel by default
C. using self-signed certificates to validate the server
D. using MS-CHAPv2 as the primary
E. AP method
【单选题】
Which Firepower Management Center feature detects and block exploits and hack attempts?___
A. Content blocker
B. file control
C. intrusion prevention
D. advanced malware protection
【单选题】
hich description of the nonsecret numbers that are used to start a Diffie- Hellman exchange is ture?___
A. They are preconfigured prime integers.
B. They are large pseudorandom numbers.
C. They are very small numbers chosen from a table of known valuses
D. They are numeric values extracted from ha shed system hostnames
【多选题】
Which two characteristics of an application layer firewall are true?___
A. provides stateful firewal functionality
B. has low processor usage
C. provides protection for multiple applications
D. provides rever se proxy services
E. is immune to URL manipulation
【多选题】
Which two devices are components of the BYOD architectural framework?___
A. Nexus 7010 switch
B. Cisco 3945 Router
C. Identify Services Engine
D. Wireless Access oints
E. Prime Infrastructure
【多选题】
Which two actions can a zone based firewall take when looking at traffic? ___
A. forward
B. inspect
C. drop
D. broadcast
E. filter
【多选题】
n which two situations should you use in-band management?___
A. when management applications need concurrent access to the device
B. when you require administrator access from multiple locations
C. when a network device fails to forward packets
D. when you require ROMMON access
E. when the control plane fails to respond
【多选题】
What are two ways to prevent eavesdropping when you perform device management tasks?___
A. Use an SSH connection.
B. Use SNMPv3
C. Use out-of-band management
D. Use SNMP
E. Use in-band management
【多选题】
Which two features are commonly used CoPP and CPPr to protect the control plane? ___
A. QoS
B. traffic classification
C. access lists
D. policy maps
E. class maps
F. Cisco Express Forwarding
【多选题】
Which four tunne ling prot ocols are enabled in the Dfit GrpPolicy group policy ?___
A. Clientless SSL VPN
B. SSL VPN Client
C. PPTP
D. L2TP/IPsec
E. IPsec IKEv1
F. IPsec IKEv2
【多选题】
Which two statements regarding the aSA VPN configurations are correct?___
A. The asa has a certificate issued by an external certificate authority associated to the ASDM TrustPoint1
B. The Default WEBVPNGroup Connection Profile is using the aaa with RADIUS server method
C. The Inside-srvbook mark references the https://192.168.1.2url
D. Only Clientless SSL VPN access is allowed with the Sales group policy
E. Any Connect, IPSec IKEv1, and IPSec IKEv2 VPN access is enabled on the outside interface
F. The Inside -SRV bookmark has not been applied to the Sales group policy
【多选题】
Which three ESP fields can be encrypted during transmission?___
A. Security Parameter Index
B. Sequence Number
C. MAC Address
D. Padding
E. Pad length
F. Next Header
【多选题】
.Which three statements de scribe DHCP spoofing attacks?___
A. They can modify traffic in transit.
B. They are used to perform man- in-the-middle attacks
C. They use ARP poisoning
D. They can access most network devices
E. They protect the ide ntity of the attacker by masking the DHCP address.
F. They are can physically modify the network gateway.
【多选题】
Which statement about the communication between interfaces on the same security level is true?___
A. Interfaces on the same security level require additional configuration to permit interinterface communication
B. Configuring interfaces on the same security level can cause asymmetric routing
C. All traffic is allowed by default between interfaces on the same security level
D. You can configure only one interface on a n individual security level
【多选题】
In which two situations should you use in band management? ___
A. when the control plane fails to respond
B. when you require administrator access from multiple locations
C. when you require ROMMON access.
D. where a network device fails to forward packets
E. when multiple ma nagement applications need concument access to the device.
【多选题】
Which two features are supported in a VRF-aware softwar infrastructure before VRF-lite?___
A. multicast
B. fair queuing
C. WCCP
D.
E. IGRP
【多选题】
.Which loS command do you enter to test authentication again a AAA server?___
A. dialer aaa suffix <suffix> password <password>
B. ppp authentication chap pap test
C. test aaa-server authentication dialer group user name <user> password <password>
D. aaa authentication enable default test group tacases
【多选题】
Which two statements about the self zone on a cisco Xone based policy firewall are true?___
A. Multiple interfaces can be assigned to the self zone
B. it supports stateful inspections for multicast traffic
C. zone pairs that include the self zone apply to traffic transiting the device.
D. it can be either the source zone or the destination zone
E. traffic entering the self zone must match a rule
【多选题】
Which type of attack can exploit design flaws in the implementation of an application without ?___
A. DHCP starvation attacks
B. low-rate dos attacks
C. application DDos flood attacks
D. application DDoS flood attacks
E. volume-based DDoS attacks
【单选题】
Which type of firewall can server as the interme diary between a client and a server ?___
A. Stateless firewall
B. application firewall
C. proxy firewall
D. personal firewall
【单选题】
What is the highest security level that can be configured for an interface on an ASA?___
A. 0
B. 50
C. 10
D. 200
【单选题】
Which term refers to the electromagnetic interference that can radiate from network cables?___
A. Gaussian distributions
B. Doppler waves
C. emanations
D. multimode distortion
【单选题】
How does a zone pair handle traffic if the policy de fination of the zone pair is missing?___
A. It inspects all traffic.
B. It drops all traffic.
C. It permits all traffic wihtout logging
D. It permits and logs all traffic
推荐试题
【单选题】
BD006 电源电压不完全财称,三相负载对称的无功功率可采用___测量。
A. 一表跨相法
B. 二表跨相法
C. 三表跨相法
D. 两表法
【单选题】
BD006 采用一表跨相法测得的三相无功功率应为功率表测得的数值的___。
A. 倍
B. 倍
C. 1/倍
D. 3倍
【单选题】
BD006 电磁系指示仪表的指针偏转角与仪表线圈安匝数的___成正比,所以其刻度是不均匀的。
A. 三次方
B. 二次方
C. 二次方根
D. 三次方根
【单选题】
BD007 交流电度表属于___式仪表。
A. 整流
B. 感应
C. 热动
D. 热电
【单选题】
BD007 电度表中制动力矩是___产生的。
A. 游丝
B. 永久磁铁
C. 拉簧
D. 可动线圈中的电流
【单选题】
BDO0 7 电度表接线必须在电路 ___情况下进行。
A. 开路
B. 短路
C. 断电
D. 带电
【单选题】
BD008 指针式万用表采用的是___仪表测量机构。
A. 电磁系
B. 感应系
C. 静电系
D. 磁电系
【单选题】
BD008 万用表测量完毕后,应将转换开关转到空挡或___的最高挡。
A. 交流电压
B. 电阻
C. 电流
D. 直流电压
【单选题】
BD008 使用万用表测量晶体管或集成件时,不得使用___量程挡。
A. RXlk、R×10k
B. R×10k、R×100k
C. R×1k、R×100k
D. R×100k、RX1000k
【单选题】
BD009 兆欧表由___、手摇发电机和测量线路组成。
A. 电磁系比率表
B. 磁电系比率表
C. 电流表
D. 电流互感器 。
【单选题】
BD009使用兆欧表测量绝缘电阻时。被测设备应接在___端口使用兆欧表
A. L、E
B. L、G
C. G、E
D. E和地
【单选题】
BD009 用兆欧表测量时,摇动摇表手柄的速度要保持在___为宜。
A. 60r/min
B. 80 r/min
C. 100 r/min
D. 120r/min
【单选题】
BD010 用来测量交流电流的钳形电流表是由电流互感器和___组成的。
A. 电压表
B. 电流表
C. 比率表
D. 电能表
【单选题】
BD010 使用钳形电流表测量绕线式异步电动机的转子电流时,必须选用具有___量机构的钳形电流表。
A. 电磁式
B. 磁电式
C. 电动式
D. 静电式
【单选题】
BD010 测量高压电缆各相电流时,电缆头线间距离应在___以上,且绝缘良好。
A. 100 mm
B. 200 mm
C. 300 mm
D. 400 mm
【单选题】
BEO01 高压绝缘杆的检验周期是___。
A. 3个月
B. 6个月
C. 1年
D. 3年
【单选题】
BEO01 35 kV绝缘杆交流耐压试验标准是___。
A. 40 kV
B. 60 kV
C. 95 kV
D. 5倍线电压
【单选题】
BEO01 6--10 kV纶缘杆交流耐压试验标准是___。
A. 45 kV
B. 50 kV
C. 3倍线电压
D. 5倍线电压
【单选题】
BE002 绝缘手套的试验周期为___。
A. 3个月
B. 6个月
C. 9个月
D. 1年
【单选题】
BE002 高压绝缘手套工频交流耐压标准为___。
A. 2.5 kV
B. 5 kV
C. 8 kV
D. 22 kV
【单选题】
BE002 低压绝缘手套工频交流耐压标准为___。
A. 2.5 kV
B. 5 kV
C. 8 kV
D. 22 kV
【单选题】
BE003 高压绝缘靴的检验周期为___
A. 3个月
B. 6个月
C. 1年
D. 3年
【单选题】
BE003 高压橡胶绝缘靴的交流耐压时间标准为___。
A. 1 min
B. 2 min
C. 3 min
D. 8 min
【单选题】
BE003 高压橡胶绝缘靴试验泄漏电流___。
A. >2.0 mA
B. >2.5 mA
C. ≤7.5 mA
D. ≤2.5 mA
【单选题】
BE004 高压验电器一般要求___做1次绝缘试验。
A. 3个月
B. 6个月
C. 9个月
D. 2个月
【单选题】
BE004 6 kV验电器的工频交流耐压标准为___。
A. 40 kV
B. 30 kV
C. 10 kV
D. 6kV
【单选题】
BE004 20一35 kV验电器的工频交流耐压标准为___。
A. 80 kV
B. 90 kV
C. 100 kV
D. 105 kV
【单选题】
互感器瓷件有严重损伤的是___
A. 名牌设备
B. 一类设备
C. 优良设备
D. 三类设备
【单选题】
BB035 变电所采用双主机监控系统与二次设备分散布置,大大提高了信息传输回路的___。
A. 传输速度
B. 正确性
C. 抗电磁干扰能力
D. 可靠性
【单选题】
BB034晶体管保护电路比较回路的作用是根据___对多个量进行电气量的比较。
A. 设计值
B. 给定的条件
C. 制定的条件
D. 规定的条件
【单选题】
BB032 当灵敏度允许时,速断保护可采用两相电流___的接线方式。
A. 差
B. 和
C. 差动
D. 零序
【单选题】
BB028 电容器组的相横联差动保护用于反映___连接电容器组的内部故障。
A. 三角形
B. 双三角形
C. 星形
D. 双星形
【单选题】
BB024 在中性点不接地系统中发生单相接地故障时,流过故障线路始端的零序___。
A. 超前零序电压90
B. 滞后零序电压90
C. 与零序电压同相位
D. 与零序电压反相
【单选题】
BB024 在小电流接地系统中发生单相接地故障时,因___,所以一般允许短时间运行。
A. 不破坏系统电压的对称
B. 接地电流较小,造不成危害
C. 相电压低,对系统不会造成危害
D. 无零序电压
【单选题】
BB019 为了防止变压器外部短路引起的过电流,并作为变压器主保护的后备,变压器应装设___。
A. 过电流保护
B. 过压保护
C. 零序保护
D. 熔断器保护
【单选题】
BA024 FCZ1系列磁吹避雷器由限流型磁吹间隙和高温阀片组成,它的保护特性比同级电压的普通阀式避雷器___。
A. 差
B. 不能比较
C. 一样好
D. 好
【单选题】
BA024 磁吹避雷器因利用了___,间隙的去游离作用增强,提高了灭弧能力。
A. 并联间隙
B. 串联间隙
C. 磁吹式火花间隙
D. 保护间隙
【单选题】
BA008 变压器并列运行的基本条件是一、二次电压相等,___,连接组别相同,容量比不超过1/3 。
A. 阻抗电压相等
B. 阻抗相等
C. 组别相同
D. 组别相等
【单选题】
BA007 在变压器中性点装设消弧线圈的目的是___。
A. 提高电网电压水平
B. 限制变压器故障电流
C. 补偿电网接地时的电容电流
D. 补偿电网接地时的电感电流
【单选题】
AB010 正弦矢量在纵坐标轴上的投影表示该正弦量的___。
A. 有效值
B. 最大值
C. 瞬时值
D. 最小值
欢迎使用我爱刷题
×
微信搜索我爱刷题小程序
温馨提示
×
请在电脑上登陆“www.woaishuati.com”使用