刷题
导入试题
【单选题】
Which protocol offers data Integrity encryption, authentication, and anti-replay functions for IPSec VPN?___
A. ESP protocol
B. IKEv3 Protocol
C. AH protoco
D. IKEv1 Protocol
查看试卷,进入试卷练习
微信扫一扫,开始刷题
答案
A
解析
暂无解析
相关试题
【单选题】
Which component offers a variety of security Solution, including firwall, IF Antivirus and antiphishing features?___
A. Cisco loS router
B. Cisco ASA 5500 Ser ies security appliance
C. Cisco ASA 5500 X series Next Gen Security appliance
D. Cisco 4200 series IPS appliance
【单选题】
Refer to the exhibit, A Network Secur ity administrator check the ASa firewall NAT policy table rith show nat command, which statement is fails?___
A. There are only reverse translation matches for the REAL SERvER object
B. First policy in the Section 1 is a dynamic nat entry defined in the object configuration
C. NAT policy in section 2 is static entry de fined in the object configuration
D. Translation in Section 3 used when a connection does not matches any entries in first two sections
【单选题】
What is true of an aSa in transparent mode ?___
A. It supports OSPF
B. It requires an IP address for each interface
C. It requires a management IP address
D. It allows the use of dynamic NaT
【单选题】
What is the effect of the ip scp server enable command?___
A. It references an access list that allows specific SCP servers
B. It allows the router to initiate requests to an SCP server
C. It allows the router to become an SCP server
D. It adds SCP to the list of allowed copy functions
【单选题】
How can you mitigate attacks in which the attacker attaches more than one vLan tag to a packet?___
A. Assign an access VLAN to every active port on the switch
B. Disable Ether Channel on the switch
C. Explicitly identity each VLAN allowed across the trunk
D.
E. nable transparent VTP on the switch
【单选题】
Which technology can you implement to centrally mitigate potential threats when users on your network download files that might be malicious?___
A. Enable file-reputation services to inspect all files that traverse the company network and block files with low reputation scores
B. Verify that the compa ny IpS blocks all known malicious website
C. Verity that antivirus software is installed and up to date for all users on your network
D. Implement URL filtering on the perimeter firewall
【单选题】
What is the most common implementation of PaT in a standard networked environment?___
A. configuring multiple external hosts to join the self zo ne and to communicate with one another
B. configuring multiple internal hosts to communicate outside of the network using the outside interface IP address
C. configuring multiple internal hosts to communicate outside of the network by using the inside interface IP address
D. configuring an any any rule to enable external hosts to communicate inside the network
【单选题】
Which component of a bYod architecture provides aAa services for endpoint access ?___
A. Integrated Services Router
B. access point
C. ASA
D. Identity Services
E. ngine
【单选题】
You are configuring a NAT rule on a Cisco ASA ,Which description of a mapped interface is true?___
A. It is mandatory for all firewall modes
B. It is optional in routed mode
C. It is optional in transparent mode
D. It is mandatory for ide ntity NAT only
【单选题】
Which description of the use of a private key is true ?___
A. The sender signs a message using the receivers private key
B. The sender signs a message using their private key
C. The sender encrypts a message using the receivers private key
D. The receiver decrypts a n15ssage using the sender's private key
【单选题】
Which mechanism does the FireAMP Connector use to avoid conflicts with other security applications such as antivirus products ?___
A. Virtualization
B. Containers
C. Sandboxing
D.
E. xclusions
【单选题】
Which network to pology de scribes multiple LANS in a gec? ___
A. SOHO
B. MAN
C. pan
D. CAN
【单选题】
Which statement represents a difference between an access list on an aSa versus an access list on a router?___
A. The asa does not support number access lists
B. The aSa does not support standard access list
C. The asa does not ever use a wildcard mask
D. The asa does not support extended access lists
【单选题】
Which command do you enter to verify the status and settings of an iKE Phase 1 tunnel?___
A. show crypto ipsec as output
B. show crypto isakmp
C. show crypto isakmp policy
D. show crypto ipsec transform
【单选题】
Which feature can help a router or switch maintain packet forwarding and protocol states despite an attack or heavy traffic load on the router or switch?___
A. service Policy
B. Control Plane Policing
C. Policy Map
D. Cisco
E. xpress
F. orwarding
【单选题】
Which STP feature can prevent an attacker from becoming the root bridge by immediately shutting down the interface when it receives a BPDU?___
A. root guard
B. Port Fast
C. BPDU guard
D. BPDU filtering
【单选题】
Which technology can best protect data at rest on a user system?___
A. full-disk encryption
B. IPsec tunnel
C. router ACL
D. network IPS
【多选题】
Which two primary security concerns can you mitigate with a BYOD solution ?___
A. schedule for patching the device
B. securing access to a trusted corporate network
C. compliance with applicable policies
D. connections to public Wi-Fi networks
E. device tagging and invento
【多选题】
choose five___
A. MD5————————inserure
B. DES————————insercure
C. SDES———————legacy
D. SHA-1———————legacy
E. HMAC-MD5—————legacy
【多选题】
Which two characteristics of symmetric encryption are true?___
A. It uses digital certificates
B. It requires more resources than asymmetric ancryption
C. It uses the same key to enctypt and decrupt traffic
D. It uses a public key and a pricate key to encrypt and decrypt traffic.
E. It is faster than asymmetric encryption
【多选题】
which two characteristics of PVLAN are true?___
A. Promiscuous porta can communicate with PVLAN ports.
B. Isolated ports cannot communicate with other ports on the same VLAN
C. Community ports have to be a part of the trunk.
D. They require VTP to be enabled in server mode
E. PVLAN ports can be configured as Ether Channel ports
【多选题】
What are two options for running Cisco SDM?___
A. Running SDM from a mobile device
B. Running SDM from within CiscoWorks
C. Running SDM from a router's flash
D. Running SDM from the Cisco web porta
E. Running SDM from a PC
【多选题】
Which two options are the primary deployment modeles for mobile device management?___
A. multisite
B. cloud-based
C. on premises
D. hybrid cloud basedo
E. single site
【多选题】
Drag the recommendation on the left to the Cryptographic algorithms on the right, Options will be used more than once.___
A. Avoid——————————————DES,MD5
B. Legacy——————————————SDES,SHA1,HMAC-MD5
【多选题】
Which two are valid types of vLans using PVLANS ?___
A. Community VLAN
B. Backup VLAN
C. Secondary VLAN
D. Isolated VLAN
E. Isolated VLAN
【多选题】
Which two commands are used to implement Resilient lOS Configuration ___
A. Secure boot-config
B. copy running-config tftp
C. copy flash:ios bin tftp
D. copy running-config startup-config
E. secure boot-image
【多选题】
Which two types of firewalls work at layer 4 and above ?___
A. Stateful inspection
B. Network Address Translation
C. Circuit-Level gateway
D. Static packet filter
E. Application Level firewall
【多选题】
Which two default settings for port security are true ?___
A. Violation is Protect
B. Violation is Restrict
C. Violation is Shutdown
D. Maximum number of MAC addresses is 2
E. Maximum number of MAC addresses is 1
【多选题】
Which two are characteristics of RADIUS?___
A. Uses UDP ports 1812 /1813
B. Uses TCP port 49
C. Uses UDP port 49
D.
E. ncrypts only the password between user and server
【多选题】
When setting up a site-to-site VPN with PSK authentication on a Cisco router, which two elements must be configured under crypto map?___
A. pfs
B. nat
C. reverse route
D. peer
E. transform-set
【多选题】
When using the Adaptive Security Device Manager(ASDM), which two options are available to add a new root certificate?___
A. Install from SFTP server
B. Usehttps
C. Install from a file
D. Use LDAP
E. Use SCEP
【多选题】
Which two SNMPv3 services support its capabilities as a secure networ k manage protocol? ___
A. access control
B. the shared secret key
C. authentication
D. authorization
E. accounting
【多选题】
Which two statements about routed firewall mode are true ?___
A. The firewall acts as a routed hop in the network
B. This mode conceals the presence of the firewall
C. The firewall requires a unique iP address for each interface
D. This mode allows the firewall to be added to an existing networ k with minimal additional configuration By default, this mode permits most traffic to pass throug
【多选题】
Which two statements describe DHCP spoofing attacks?___
A. They are used to perform man-in- the-middle attacks
B. They can access most network devices
C. They can modify the flow of traffic in transit. LNGKAIG
D. They protect the identity of ti attacker by masking the DHCP address
E. They can physically modify the network gateway
【多选题】
Which two types of VLANs using PVLANs are valid?___
A. isolated
B. promiscuous
C. backup
D. secondary
E. community
【多选题】
What are two limitations of the self-zone policies on a zone-based firewall?___
A. They are unable to block Https traffic
B. They restrict SNMP traffic.
C. They are unable to support Https traffic
D. They are unable to implement application inspection
E. They are unable to perform rate limiting
【多选题】
Which two descriptions of TACACS+ are true? ___
A. The TACACS+ header is unencrypted
B. It combines a uthentication and authorization
C. It uses TCP as its transport protocol
D. Only the password is encrypted.
E. It uses UDP as its transport protocol.
【多选题】
Which two actions does an IPS perform? ___
A. it spans the traffic
B. it reflects the traffic back to the sender
C. it encrypts the traffic
D. it terminates the user session or connection of the attacker
E. it reconfigures a device to block the traffic
【多选题】
In which form of fraud does an attacker try to learn information such as login credenti account information by ma squerading as a reputable entity or person in email, IM or communication channels ?___
A. phishing
B. Smurfit
C. Hacking
D. Identity Spoofing
【多选题】
Which two ESA services are available for incoming and outgoing mails ?___
A. anti-DoS
B. reputation filter
C. antispam
D. content filter
E. DLP
推荐试题
【单选题】
《中华人民共和国职业病防治法》自___起施行。
A. 2002年5月1日
B. 2000年5月1日
C. 2001年10月27日
【单选题】
钎焊时,钎料和母材___
A. 都熔化
B. 都不熔化
C. 钎料熔化但母材不熔化
【单选题】
焊接电缆一般要求用___紫铜软线制成。
A. 单股
B. 双股
C. 多股
【单选题】
水下焊接时为防止高温熔滴落进潜水服的折迭处或供气管,烧坏潜水服或供气管,尽量避免___
A. 横焊
B. 平焊
C. 仰焊和仰割
【单选题】
电弧焊时采用的焊机等电气设备及___均是带电体
A. 焊钳
B. 焊件
C. 焊钳、焊件
【单选题】
用过高的电弧电压堆焊时,工件的熔深___。
A. 急剧减小
B. 略有减小
C. 不变
【单选题】
下列不属于一级动火范围的是___
A. 大型油罐
B. 密闭室
C. 酒精炉
【单选题】
焊接时对人体产生的___一方面可以出现局部振动病症状.另一方面还可能出现头眩晕、呕吐、恶心、耳聋、胃下垂、焦虑等症状
A. 局部振动
B. 全身振动
C. 强烈振动
【单选题】
焊机接地回线乱接乱搭,由于接触不良使___,容易造成火灾:
A. 电压升高
B. 电压减小
C. 电阻热增大
【单选题】
下列选项中不属于IS014000涵盖内容的是___
A. 环境管理体系。
B. 焊接质量管理体系
C. 环境管理体系审核
【单选题】
登高焊接与热切割作业是指焊工在坠落高度基准面___m以上
A. 1
B. 2
C. 4
【单选题】
埋弧焊时,电弧的磁偏吹最小的电源是___
A. 脉冲电流
B. 直流
C. 交流
【单选题】
弧焊发电机出现电动机反转的原因是___电动机与电网接线错误。
A. 单相
B. 两相
C. 三相
【单选题】
弧焊机着火首先应___,然后再用灭火器灭火。
A. 拉闸断电
B. 灭火
C. 打“121”
【判断题】
《安全生产法》规定,生产经营单位对重大危险源应当告知从业员和相关人员在紧急情况下应当采取的应急措施。
A. 对
B. 错
【判断题】
一般在动火前应采用一嗅、二看、三测爆的检查方法。
A. 对
B. 错
【判断题】
电弧辐射主要有紫外线、红外线和可见光三种射线,不会产生对人体危害较大的X射线等。
A. 对
B. 错
【判断题】
碳孤气刨时,应使用专用碳棒,以免产生过多有害气体。
A. 对
B. 错
【判断题】
为了确保氧气瓶的使用安全,出厂前要经受1.15倍瓶装压力的水压试验。
A. 对
B. 错
【判断题】
焊接电缆的绝缘一般每半年检查一次。
A. 对
B. 错
【判断题】
可燃性液体的闪点越低,其火灾危险性越小。
A. 对
B. 错
【判断题】
可燃气体钢瓶不许与氧气瓶同车装运或存放于同一库房。
A. 对
B. 错
【判断题】
氩弧焊时,电弧的辐射强度比焊条电弧焊强得多,因此,要加强防护措施。
A. 对
B. 错
【判断题】
直流反接适合于焊薄件。
A. 对
B. 错
【判断题】
如果需动火的设备处于禁火区内,必须按禁火区的动火管理规定申请动火证。
A. 对
B. 错
【判断题】
发生触电事故后,应立即切断事故发生场所电源开关或插头。
A. 对
B. 错
【判断题】
焊机长期超负荷运行或短路发热会使绝缘损坏而造成焊机漏电。
A. 对
B. 错
【判断题】
对于烧伤部位,可以将牙膏、油膏等油性物质涂于烧伤创面以减少创面污染的机会和减轻就医时处理的难度。
A. 对
B. 错
【判断题】
纯He气仅用于熔透法焊接,比如焊接铜。
A. 对
B. 错
【判断题】
等离子电弧是一种气流。
A. 对
B. 错
【判断题】
凡与大地有可靠接触的金属导体,均可作为自然接地体。
A. 对
B. 错
【判断题】
MAG焊适用于碳钢、合金钢和不锈钢等黑色金属材料的全位置焊接。
A. 对
B. 错
【判断题】
铝热焊设备简单、投资少,焊接操作简便,无需电源。
A. 对
B. 错
【判断题】
电石属于遇水燃烧危险品。
A. 对
B. 错
【判断题】
二氧化碳焊可用于汽车、船舶、机车车辆、集装箱、矿山及工程 机械等。
A. 对
B. 错
【判断题】
氩弧焊是采用工业纯氢作为保护气体的
A. 对
B. 错
【判断题】
脱离低压电源的方法可用"拉、切、挑、拽"四个字概括。
A. 对
B. 错
【判断题】
焊接不带电的金属外壳时,可以不采用安全防护措施。
A. 对
B. 错
【判断题】
埋弧焊焊丝数目仅有单丝。
A. 对
B. 错
【判断题】
气焊黄铜时既产生烟尘又产生有毒气体。
A. 对
B. 错
欢迎使用我爱刷题
×
微信搜索我爱刷题小程序
温馨提示
×
请在电脑上登陆“www.woaishuati.com”使用