刷题
导入试题
【多选题】
Which two types of firewalls work at layer 4 and above ?___
A. Stateful inspection
B. Network Address Translation
C. Circuit-Level gateway
D. Static packet filter
E. Application Level firewall
查看试卷,进入试卷练习
微信扫一扫,开始刷题
答案
AE
解析
暂无解析
相关试题
【多选题】
Which two default settings for port security are true ?___
A. Violation is Protect
B. Violation is Restrict
C. Violation is Shutdown
D. Maximum number of MAC addresses is 2
E. Maximum number of MAC addresses is 1
【多选题】
Which two are characteristics of RADIUS?___
A. Uses UDP ports 1812 /1813
B. Uses TCP port 49
C. Uses UDP port 49
D.
E. ncrypts only the password between user and server
【多选题】
When setting up a site-to-site VPN with PSK authentication on a Cisco router, which two elements must be configured under crypto map?___
A. pfs
B. nat
C. reverse route
D. peer
E. transform-set
【多选题】
When using the Adaptive Security Device Manager(ASDM), which two options are available to add a new root certificate?___
A. Install from SFTP server
B. Usehttps
C. Install from a file
D. Use LDAP
E. Use SCEP
【多选题】
Which two SNMPv3 services support its capabilities as a secure networ k manage protocol? ___
A. access control
B. the shared secret key
C. authentication
D. authorization
E. accounting
【多选题】
Which two statements about routed firewall mode are true ?___
A. The firewall acts as a routed hop in the network
B. This mode conceals the presence of the firewall
C. The firewall requires a unique iP address for each interface
D. This mode allows the firewall to be added to an existing networ k with minimal additional configuration By default, this mode permits most traffic to pass throug
【多选题】
Which two statements describe DHCP spoofing attacks?___
A. They are used to perform man-in- the-middle attacks
B. They can access most network devices
C. They can modify the flow of traffic in transit. LNGKAIG
D. They protect the identity of ti attacker by masking the DHCP address
E. They can physically modify the network gateway
【多选题】
Which two types of VLANs using PVLANs are valid?___
A. isolated
B. promiscuous
C. backup
D. secondary
E. community
【多选题】
What are two limitations of the self-zone policies on a zone-based firewall?___
A. They are unable to block Https traffic
B. They restrict SNMP traffic.
C. They are unable to support Https traffic
D. They are unable to implement application inspection
E. They are unable to perform rate limiting
【多选题】
Which two descriptions of TACACS+ are true? ___
A. The TACACS+ header is unencrypted
B. It combines a uthentication and authorization
C. It uses TCP as its transport protocol
D. Only the password is encrypted.
E. It uses UDP as its transport protocol.
【多选题】
Which two actions does an IPS perform? ___
A. it spans the traffic
B. it reflects the traffic back to the sender
C. it encrypts the traffic
D. it terminates the user session or connection of the attacker
E. it reconfigures a device to block the traffic
【多选题】
In which form of fraud does an attacker try to learn information such as login credenti account information by ma squerading as a reputable entity or person in email, IM or communication channels ?___
A. phishing
B. Smurfit
C. Hacking
D. Identity Spoofing
【多选题】
Which two ESA services are available for incoming and outgoing mails ?___
A. anti-DoS
B. reputation filter
C. antispam
D. content filter
E. DLP
【多选题】
What are two reasons to recommend SNMPv 3 over SNMPv2?___
A. SNMPv3 is secure because you can configure authe ntication and privacy
B. SNMPv3 is insecure because it send in formation in clear text
C. SNMPv2 is insecure because it send information in clear text
D. SNMPv3 is a Cisco proprietary protocol
E. SNMPv2 is secure because you can configure authentication and privacy
【多选题】
Which two actions can a zone- based firewall apply to a packet as it transits a zone pair?___
A. drop
B. inspect
C. queue
D. quarantine
【单选题】
Which security principle has been violated if data is altered in an unauthorized manner?___
A. accountability
B. confidentiality
C. availability
D. integrity
【单选题】
Which IKE Phase 1 parameter can you use to require the site-to-site VPN to use a pre-shared ?___
A. encryption
B. authentication
C. group
【单选题】
Which command successfully creates an administrative user with a password of "cisco"on a Cisco router?___
A. username Operator privilege 7 password cisco
B. username Operator privilege 1 password cisco
C. username Operator privilege 15 password cisco
D. username Operator password cisco privilege 15
【单选题】
Which EAP method authenticates a client against Active Directory without the use of client-side 802.1X certificates?___
A. EAP-TLS
B. EAP-MSCHAPv2
C. EAP-PEAP
D.
E. AP-GTC
【单选题】
What is a limitation of network-based IPS?___
A. It must be in dividually configured to support every operating system on the network.
B. It is most effective at the in dividual host level
C. It is unable to monitor attacks across the entire netw ork
D. Large installations require numerous sensors to fully protect the network
【单选题】
When would you configure the ip dhcp snooping trust command on a sw itch?___
A. when the switch is connected to a DHCP server
B. when the switch is working in an edge capacit
C. when the switch is connected to a client system
D. when the switch is serving as an aggregator
【单选题】
How does the 802. 1x supplicant communicate with the authentication server?___
A. The supplicant creates EAP packets and sends them to the authenticator, which encapsulates them into RADIUS and forwards them to the authentication server.
B. The supplicant creates RADIUS packets and sends them to the authe nticator, which encapsulates the m into EAP and forwards them to the a uthentication server.
C. The supplicant creates RADIUS packets and sends them to the authenticator, which translates them into eap and forwards them to the a ut hentication server
D. The supplicant creates
E. AP packets and sends them to the authe nticator, which translates them into radius and forwards them to the authentication server.
【单选题】
Which command do you enter to verify the phase I status of a VPN connection?___
A. sh crypto se ssion
B. debug crypto isakmp
C. sh crypto isakmp sa
D. sh crypto ipsec sa
【单选题】
Refer to the exhibit. what is the e ffect of the given configuration?___
A. It enables authentication,
B. It prevents keychain authentication.
C. The two routers receive normal updates from one another.
D. The two device s are able to pass the message digest to one another.
【单选题】
Which command can you enter to configure OSPF to use hashing to authenticate routing updates?___
A. ip ospf aut hentication message-digest
B. neighbor 192 168.0 112 cost md5
C. ip ospf priority 1
D. ip ospf aut hentication-key
【单选题】
Which command can you enter to verify the status of Cisco lOS Resilient Configuration on a Cisco router?___
A. show secure bootset
B. secure boot-image
C. show binary file
D. ure boot-config
【单选题】
A user on your network inadvertently activates a botnet program that was received as an emai attachment. Which type of mechanism does Cisco Firepower use to detect and block only the botnet attack?___
A. network-based access control rule
B. reputation-based
C. user-ba sed access control rule
D. botnet traffic filter
【单选题】
What does the policy map do in CoPP?___
A. defines service parameters
B. defines packet selection parameters
C. defines the packet filter
D. define s the action to be performed
【单选题】
How is management traffic isolated on a Cisco ASR 1002?___
A. Traffic isolation is done on the vlan level
B. There is no management traffic isolation on a Cisco ASR 1002
C. Traffic is isolated based upon how you configure routing on the device
D. The management interface is configured in a special vRF that provides traffic isolation from the default routing table
【单选题】
Which statement about NaT table evaluation in the asa is true?___
A. After-auto NAT polices are appl d first
B. Manual NAT policies are applied first
C. the asa uses the most specific match
D. Auto NAT policies are applied first
【单选题】
Which information can you display by executing the show crypto ipsec sa command?___
A. ISAKMP SAs that are established between two peers
B. recent changes to the IP address of a peer router
C. proxy infor mation for the connection between two peers
D. IPsec SAs established between two peers
【单选题】
How can you prevent NAT rules from sending traffic to incorrect interfaces?___
A. Assign the output interface in the NAT statement
B. Add the no-proxy-arp command to the nat line.
C. Configure twice NAT instead o bject NAT. 5
D. Use packet-tracer rules to reroute misrouted NAT entries.
【单选题】
What term can be defined as the securing, control, and identification of digital data?___
A. cryptography
B. crypto key
C. cryptoanalysis
D. cryptology
【单选题】
Which feature in the dNS security module provide on and off network DNS protection?___
A. Data Loss Prevention
B. Umbrella
C. Real-time sandboxing
D. Layer-4 monitoring
【单选题】
Which a dverse consequence can occur on a network without BPDu guard ?___
A. The olde st switch can be elected as the root bridge
B. Unauthorized switches that are connected to the network can cause spanning-tree loops
C.
D. ouble tagging can cause the switches to experience CAM table overload.
【单选题】
What configuration is required for multitenancy ?___
A. shared infrastructure
B. multiple carriers
C. co-located resources
D. multiple separate zones
【单选题】
Why does ISE require its own certificate issued by a trusted CA?___
A. ISEs certificate allows guest devices to validate it as a trusted network device
B. It generates certificates for guest devices ba sed on its own certificate
C. It requests certificates for guest devices from the Ca server based on its own certificate.
D. ISE's certificate allows it to join the network security framework
【单选题】
which attack involves large numbers of ICMP packets with a spoofed source IP address?___
A. smurf attack
B. Teardrop attack
C. Nuke attack
D. SYN Flood attack
【单选题】
Which statement about interface and global access rules is true?___
A. Interface access rules are processed before global access rules.
B. Global access rules apply only to outbound traffic, but interface access rules can be applied in either direction
C. The implicit allow is proce ssed after both the global and interface access rules
D. If an interface access rule is applied, the global access rule is ignored
【单选题】
Which type of malicious software can create a back-door into a device or network?___
A. bot
B. worm
C. virus
D. Trojan
推荐试题
【判断题】
【判断】 高压熔断器的熔丝一相或多相熔断后,在熔断器撞击器的作用下使负荷开关跳闸,可防止由于缺相运行而造成的电气设备损坏。()
A. 对
B. 错
【判断题】
【判断】 真空断路器每次分合闸时 ,波纹管都会有一次伸缩变形 ,它的寿命通常决定了断路器的寿命。 ()
A. 对
B. 错
【判断题】
【判断】 高分断能力高压熔断器具有开断短路电流能力强的优点。 ()
A. 对
B. 错
【判断题】
【判断】 由于检修工作需要 ,可将六氟化硫 (SF6)断路器打开后 ,将六氟化硫 (SF6) 气体排入大气中。 ()
A. 对
B. 错
【判断题】
【判断】 组合式 (美式) 箱变因变压器与箱变外壳为一个整体,所以调整变压器容量(增容或减容) 比较困难。
A. 对
B. 错
【判断题】
【判断】 新装电容器组投运前 ,应对与电容器连接的电气元件进行试验并合格。 ()
A. 对
B. 错
【判断题】
【判断】 如果高压电容器刚断电即又合闸 ,有可能使熔断器熔断或断路器跳闸。 ()
A. 对
B. 错
【判断题】
【判断】 额定电压和标定容量均相同的单相高压电容器 ,接入同一电压等级的电网时 ,电容器组的结线方式接成三角形和接成星形的补偿效果相同。 ()
A. 对
B. 错
【判断题】
【判断】 对运行中断路器一般要求 ,断路器金属外壳应有明显的接地标志。 ()
A. 对
B. 错
【判断题】
【判断】 新装电容器组投运前 ,应检查放电电阻的阻值和容量是否符合规程要求。 ()
A. 对
B. 错
【判断题】
【判断】 高压电容器组断电后 ,若需再次合闸 ,应在其断电 3 分钟后进行。 ()
A. 对
B. 错
【判断题】
【判断】 在断路器异常运行及处理中 ,值班人员发现当断路器发生分闸脱扣器拒动时 ,应申请立即处理。
A. 对
B. 错
【判断题】
10kV/0.4kV 配电变压器一、二次绕组的匝数比 k 等于( 25)
A. 对
B. 错
【判断题】
电力电缆敷设到位后 , 首次绑扎可采用铁丝等材料将电缆定型 , 在进行二次整理时将绑扎材料更换为并定尺绑扎。
A. 对
B. 错
【判断题】
二次设备之间的连接按(等电位)的原则进行。
A. 对
B. 错
【判断题】
电力电容器接入线路对电力系统进行补偿的目的是(提高功率因数)
A. 对
B. 错
【判断题】
35kV 架空铜导线的最小允许截面应选( 35) mm2
A. 对
B. 错
【判断题】
在爆炸危险场所,应尽量少安装(插座)
A. 对
B. 错
【判断题】
额定电压为 1000V 及以上的设备,测量绝缘电阻时应选用( 2500) V 的摇表
A. 对
B. 错
【判断题】
额定电压为 220V 的灯泡接在 110V 电源上,灯泡的功率是原来的( 1/4 )
A. 对
B. 错
【判断题】
设备的断路器,隔离开关都在合闸位置,说明设备处在(运行)状态
A. 对
B. 错
【判断题】
电流互感器的一次电流由(线路负荷电流)决定
A. 对
B. 错
【判断题】
按照能量守恒定律,变压器绕组电压高的一侧,电流(小)
A. 对
B. 错
【判断题】
架空电力线路在同一档距中 , 各相导线的弧垂应力求一致 , 允许误差不应大于 (0.2)m
A. 对
B. 错
【判断题】
接地装置是防雷装置的主要组成部分, 作用是(泄放雷电电流) ,限制防雷装置的对地电压, 使之不至过高。
A. 对
B. 错
【判断题】
AN代表变压器的冷却方式是(干式自冷)
A. 对
B. 错
【判断题】
纯净的变压器油具有优良的(冷却)性能
A. 对
B. 错
【判断题】
由于倒闸操作而引起的过电压,称为(操作)过电压
A. 对
B. 错
【判断题】
电缆线路中有中间接头时,压接接头最高允许温度为( 150)℃
A. 对
B. 错
【判断题】
在人体触电过程中, (室颤)电流在较短时间内,能引起心室障碍而造成血液循环停止,这是电击致死的主要原因。
A. 对
B. 错
【判断题】
当设备发生碰壳漏电时,人体接触设备金属外壳造成的电击称作(间接接触)电击
A. 对
B. 错
【判断题】
氧气,乙炔管道以及其他会产生静电的管道必须(接成一个整体再接地),以防止静电事故发生
A. 对
B. 错
【判断题】
固定式成套配电装置中断路器和隔离开关之间一般设有机械联锁装置,以防止(带负荷操作隔离开关),保证人身和设备的安全
A. 对
B. 错
【判断题】
被测量交流电流如大于( 5) A 时,一般需要配合电流互感器进行测量
A. 对
B. 错
【判断题】
所有断路器,隔离开关均断开,在有可能来电端挂好接地线,说明设备处于(检修)状态
A. 对
B. 错
【判断题】
变压器防爆管的作用是(防止油箱破裂)
A. 对
B. 错
【判断题】
主网是电力系统的最高级电网,电压在( 35) kV 以上
A. 对
B. 错
【判断题】
在变配电所中 B 相的颜色是(绿)
A. 对
B. 错
【判断题】
生产生活中,静电时时出现,其中,最大的危害是引发爆炸或(引发火灾)
A. 对
B. 错
【判断题】
当不知道被测电流的大致数值时,应该先使用(较大)量程的电流表试测
A. 对
B. 错
欢迎使用我爱刷题
×
微信搜索我爱刷题小程序
温馨提示
×
请在电脑上登陆“www.woaishuati.com”使用