刷题
导入试题
【单选题】
Which statement about the communication between interfaces on the same security level is true?___
A. Interfaces on the same security level require additional configuration to permit interinterface communication
B. Configuring interfaces on the same security level can cause asymmetric routing
C. All traffic is allowed by default between interfaces on the same security level
D. You can configure only one interface on a n individual security level
查看试卷,进入试卷练习
微信扫一扫,开始刷题
答案
A
解析
暂无解析
相关试题
【单选题】
Which product can be used to provide application layer protection for tcp port 25 traffic?___
A. ESA
B. CWS
C. WSA
D. ASA
【单选题】
which iPS mode is less secure than other options but allows optimal network through put ?___
A. inline mode
B. inline-bypass mode
C. transparent mode
D. Promiscuous mode
【单选题】
Which feature of the Cisco Email security Appliance can mitigate the impact of snowshoe spam and sophisticated phishing attack?___
A. reputation based filtering
B. signature based IPS
C. contextual analysis
D. graymail management and filtering
【单选题】
Which type of social-engineering attack uses normal tele phone service as the attack vector?___
A. smishing
B. dialing
C. phishing
D. vishing
【单选题】
Which quantifiable item should you consider when you organization adopts new technologies?___
A. exploits
B. vulnerability
C. threat
D. Risk
【单选题】
Referencing the ClA model, in which scenario is a hash- only function most appropriate ?___
A. securing data at rest
B. securing real-time traffic
C. securing data in files
D. securing wireless transmissions
【单选题】
Which ports must be open between a aaa server and a microsoft server to permit Active Directory authentications?___
A. 445 and 389
B. 888 and 3389
C. 636 and 4445
D. 363 and 983
【单选题】
Refer to the exhibit for which reason is the tunnel unable to pass traffic___
A. the tunnel is failing to receive traffic from the remote peer
B. the local peer is unable to encrypt the traffic
C. the ip address of the remote peer is incorrect
D. UDP port 500 is blocked
【单选题】
Which type of attack can exploit design flaws in the implementation of an application without___
A. DHCP starvation attacks
B. low-rate dos attacks
C. application DDos flood attacks
D. application DDoS flood attacks
E. volume-based DDoS attacks
【单选题】
How can you protect CDP from reconnaissance attacks?___
A. Enable dynamic ARP inspection on all untrusted ports.
B. Enable dot1x on all ports that are connected to other switches.
C.
D. isable CDP on ports connected to endpoints.
【单选题】
Which type of attack can exploit design flaws in the implementation of an application without ?___
A. DHCP starvation attacks
B. low-rate dos attacks
C. application DDos flood attacks
D. application DDoS flood attacks
E. volume-based DDoS attacks
【单选题】
Which option is a key security compone nt of and MDM deployment ?___
A. using network-specific installer packages
B. using an application tunnel by default
C. using self-signed certificates to validate the server
D. using MS-CHAPv2 as the primary
E. AP method
【单选题】
Which Firepower Management Center feature detects and block exploits and hack attempts?___
A. Content blocker
B. file control
C. intrusion prevention
D. advanced malware protection
【单选题】
hich description of the nonsecret numbers that are used to start a Diffie- Hellman exchange is ture?___
A. They are preconfigured prime integers.
B. They are large pseudorandom numbers.
C. They are very small numbers chosen from a table of known valuses
D. They are numeric values extracted from ha shed system hostnames
【多选题】
Which two characteristics of an application layer firewall are true?___
A. provides stateful firewal functionality
B. has low processor usage
C. provides protection for multiple applications
D. provides rever se proxy services
E. is immune to URL manipulation
【多选题】
Which two devices are components of the BYOD architectural framework?___
A. Nexus 7010 switch
B. Cisco 3945 Router
C. Identify Services Engine
D. Wireless Access oints
E. Prime Infrastructure
【多选题】
Which two actions can a zone based firewall take when looking at traffic? ___
A. forward
B. inspect
C. drop
D. broadcast
E. filter
【多选题】
n which two situations should you use in-band management?___
A. when management applications need concurrent access to the device
B. when you require administrator access from multiple locations
C. when a network device fails to forward packets
D. when you require ROMMON access
E. when the control plane fails to respond
【多选题】
What are two ways to prevent eavesdropping when you perform device management tasks?___
A. Use an SSH connection.
B. Use SNMPv3
C. Use out-of-band management
D. Use SNMP
E. Use in-band management
【多选题】
Which two features are commonly used CoPP and CPPr to protect the control plane? ___
A. QoS
B. traffic classification
C. access lists
D. policy maps
E. class maps
F. Cisco Express Forwarding
【多选题】
Which four tunne ling prot ocols are enabled in the Dfit GrpPolicy group policy ?___
A. Clientless SSL VPN
B. SSL VPN Client
C. PPTP
D. L2TP/IPsec
E. IPsec IKEv1
F. IPsec IKEv2
【多选题】
Which two statements regarding the aSA VPN configurations are correct?___
A. The asa has a certificate issued by an external certificate authority associated to the ASDM TrustPoint1
B. The Default WEBVPNGroup Connection Profile is using the aaa with RADIUS server method
C. The Inside-srvbook mark references the https://192.168.1.2url
D. Only Clientless SSL VPN access is allowed with the Sales group policy
E. Any Connect, IPSec IKEv1, and IPSec IKEv2 VPN access is enabled on the outside interface
F. The Inside -SRV bookmark has not been applied to the Sales group policy
【多选题】
Which three ESP fields can be encrypted during transmission?___
A. Security Parameter Index
B. Sequence Number
C. MAC Address
D. Padding
E. Pad length
F. Next Header
【多选题】
.Which three statements de scribe DHCP spoofing attacks?___
A. They can modify traffic in transit.
B. They are used to perform man- in-the-middle attacks
C. They use ARP poisoning
D. They can access most network devices
E. They protect the ide ntity of the attacker by masking the DHCP address.
F. They are can physically modify the network gateway.
【多选题】
Which statement about the communication between interfaces on the same security level is true?___
A. Interfaces on the same security level require additional configuration to permit interinterface communication
B. Configuring interfaces on the same security level can cause asymmetric routing
C. All traffic is allowed by default between interfaces on the same security level
D. You can configure only one interface on a n individual security level
【多选题】
In which two situations should you use in band management? ___
A. when the control plane fails to respond
B. when you require administrator access from multiple locations
C. when you require ROMMON access.
D. where a network device fails to forward packets
E. when multiple ma nagement applications need concument access to the device.
【多选题】
Which two features are supported in a VRF-aware softwar infrastructure before VRF-lite?___
A. multicast
B. fair queuing
C. WCCP
D.
E. IGRP
【多选题】
.Which loS command do you enter to test authentication again a AAA server?___
A. dialer aaa suffix <suffix> password <password>
B. ppp authentication chap pap test
C. test aaa-server authentication dialer group user name <user> password <password>
D. aaa authentication enable default test group tacases
【多选题】
Which two statements about the self zone on a cisco Xone based policy firewall are true?___
A. Multiple interfaces can be assigned to the self zone
B. it supports stateful inspections for multicast traffic
C. zone pairs that include the self zone apply to traffic transiting the device.
D. it can be either the source zone or the destination zone
E. traffic entering the self zone must match a rule
【多选题】
Which type of attack can exploit design flaws in the implementation of an application without ?___
A. DHCP starvation attacks
B. low-rate dos attacks
C. application DDos flood attacks
D. application DDoS flood attacks
E. volume-based DDoS attacks
【单选题】
Which type of firewall can server as the interme diary between a client and a server ?___
A. Stateless firewall
B. application firewall
C. proxy firewall
D. personal firewall
【单选题】
What is the highest security level that can be configured for an interface on an ASA?___
A. 0
B. 50
C. 10
D. 200
【单选题】
Which term refers to the electromagnetic interference that can radiate from network cables?___
A. Gaussian distributions
B. Doppler waves
C. emanations
D. multimode distortion
【单选题】
How does a zone pair handle traffic if the policy de fination of the zone pair is missing?___
A. It inspects all traffic.
B. It drops all traffic.
C. It permits all traffic wihtout logging
D. It permits and logs all traffic
【单选题】
default how does a zone based firewall handle traffic to add from the self zone?___
A. It permits all traffic without inspection
B. It inspects all traffic to determine how it is handled
C. It permits all traffic after inspection
D. It frops all traffic
【单选题】
Which command should beused to ena ble AAA Authentication to determine if a user can access the privilege command level?___
A. aaa authentication enable local
B. aaa authentication enable level=
C. aaa authentication enable method de fault
D. aaa authentication enable defa ult local
【单选题】
On an ASA, the policy indicates that traffic should not be translated is often referred to as which of the following?___
A. NAT zero
B. NAT forward
C. NAT nul
D. NAT allow
【单选题】
Which protocol offers data Integrity encryption, authentication, and anti-replay functions for IPSec VPN?___
A. ESP protocol
B. IKEv3 Protocol
C. AH protoco
D. IKEv1 Protocol
【单选题】
Which component offers a variety of security Solution, including firwall, IF Antivirus and antiphishing features?___
A. Cisco loS router
B. Cisco ASA 5500 Ser ies security appliance
C. Cisco ASA 5500 X series Next Gen Security appliance
D. Cisco 4200 series IPS appliance
【单选题】
Refer to the exhibit, A Network Secur ity administrator check the ASa firewall NAT policy table rith show nat command, which statement is fails?___
A. There are only reverse translation matches for the REAL SERvER object
B. First policy in the Section 1 is a dynamic nat entry defined in the object configuration
C. NAT policy in section 2 is static entry de fined in the object configuration
D. Translation in Section 3 used when a connection does not matches any entries in first two sections
推荐试题
【判断题】
任何单位和个人不得生产、经营、进口和使用国家明令禁止使用的可能产生职业病危害的设备或者材料
A. 对
B. 错
【判断题】
某些单位可以将产生职业病危害的作业转移给不具备职业病防护条件的单位和个人
A. 对
B. 错
【判断题】
用人单位与劳动者订立劳动合同(含聘用合同)时,应当将工作过程中可能产生的职业病危害及其后果、职业病防护措施和待遇等如实告知劳动者,并在劳动合同中写明,不得隐瞒或者欺骗
A. 对
B. 错
【判断题】
用人单位不可以隐瞒本单位职业卫生真实情况
A. 对
B. 错
【判断题】
向用人单位提供可能产生职业病危害的化学品的,不用提供中文说明书
A. 对
B. 错
【判断题】
任何单位和个人不得将产生职业病危害的作业转移给不具备职业病防护条件的个人
A. 对
B. 错
【判断题】
用人单位对需要复查和医学观察的劳动者应按照体检机构的要求安排其复查和医学观察
A. 对
B. 错
【判断题】
用人单位不用对从事使用有毒物品作业的劳动者进行离岗时的职业健康检查
A. 对
B. 错
【判断题】
用人单位不可以建立职业病危害事故应急救援预案
A. 对
B. 错
【判断题】
用人单位主要负责人、职业卫生管理人员的职业卫生培训,其内容不包括职业病危害预防和控制的基本知识
A. 对
B. 错
【判断题】
用人单位应当建立职业健康监护档案,其内容不包括职业病诊疗等劳动者健康资料
A. 对
B. 错
【判断题】
国家鼓励研制、开发、推广、应用有利于预防、控制、消除职业中毒危害和保护劳动者健康的新技术、新工艺、新材料
A. 对
B. 错
【判断题】
用人单位必须依法参加工伤保险
A. 对
B. 错
【判断题】
任何单位或者个人不得将工伤保险基金用于投资运营、兴建或者改建办公场所、发放奖金,或者挪作其他用途
A. 对
B. 错
【判断题】
自残或者自杀的不得认定为工伤或者视同工伤
A. 对
B. 错
【判断题】
职工因工作遭受事故伤害或者患职业病进行治疗,享受工伤医疗待遇
A. 对
B. 错
【判断题】
特种设备在出租期间的使用管理和维护保养义务由特种设备出租单位承担,法律另有规定或者当事人另有约定的除外
A. 对
B. 错
【判断题】
任何单位和个人有权向负责特种设备安全监督管理的部门和有关部门举报涉及特种设备安全的违法行为
A. 对
B. 错
【判断题】
特种设备安全管理人员不需要取得相应资格,就可从事相关工作
A. 对
B. 错
【判断题】
公共交通工具、公共场所和其他人员密集场所的经营单位或者管理单位应当制定具体应急预案,为交通工具和有关场所配备报警装置和必要的应急救援设备、设施
A. 对
B. 错
【判断题】
特种设备使用单位应当建立健全特种设备安全、节能管理制度和岗位安全、节能责任制度
A. 对
B. 错
【判断题】
任何单位和个人对违反《特种设备安全监察条例》规定的行为,有权向特种设备安全监督管理部门和行政监察等有关部门举报
A. 对
B. 错
【判断题】
电梯的安装、改造、维修,只能由电梯制造单位进行
A. 对
B. 错
【判断题】
特种设备安装、改造、维修的施工单位应当在施工前将拟进行的特种设备安装、改造、维修情况书面告知直辖市或设区的市的特种设备安全监督管理部门
A. 对
B. 错
【判断题】
移动式压力容器、气瓶充装单位应当经省、自治区、直辖市的特种设备安全监督管理部门许可,方可从事充装活动
A. 对
B. 错
【判断题】
特种设备使用单位应当使用符合安全技术规范要求的特种设备
A. 对
B. 错
【判断题】
特种设备在投入使用前或者投入使用后的登记标志应当置于或者附着于该特种设备的显著位置
A. 对
B. 错
【判断题】
未经不定期检验的特种设备,不得继续使用
A. 对
B. 错
【判断题】
电梯投入使用后,电梯制造单位应当对其制造的电梯的安全运行情况进行跟踪调查和了解,并作出记录
A. 对
B. 错
【判断题】
特种设备使用单位应当对特种设备作业人员进行特种设备安全、节能教育和培训
A. 对
B. 错
【判断题】
两个以上不同资质等级的单位实行联合共同承包的,应当按照资质等级高的单位的业务许可范围承揽工程
A. 对
B. 错
【判断题】
禁止总承包单位将工程分包给不具备相应资质条件的单位
A. 对
B. 错
【判断题】
禁止分包单位将其承包的工程再分包
A. 对
B. 错
【判断题】
建筑施工企业在编制施工组织设计时,应当根据建筑工程的特点制定相应的安全技术措施
A. 对
B. 错
【判断题】
施工现场对毗邻的建筑物、构筑物和特殊作业环境可能造成损害的,建筑施工企业应当采取安全防护措施
A. 对
B. 错
【判断题】
建设单位应当向建筑施工企业提供与施工现场相关的地下管线资料,建设单位应当采取措施加以保护
A. 对
B. 错
【判断题】
施工现场安全由建筑施工企业负责
A. 对
B. 错
【判断题】
建筑施工企业应当建立健全劳动安全生产教育培训制度,加强对职工安全生产的教育培训
A. 对
B. 错
【判断题】
建筑工程施工的质量必须符合国家有关建筑工程安全标准的要求
A. 对
B. 错
【判断题】
施工作业单位应当在经批准的路段和时间内施工作业,并在距离施工作业地点来车方向安全距离处设置明显的安全警示标志,采取防护措施
A. 对
B. 错
欢迎使用我爱刷题
×
微信搜索我爱刷题小程序
温馨提示
×
请在电脑上登陆“www.woaishuati.com”使用