刷题
导入试题
【多选题】
Which two default settings for port security are true ?___
A. Violation is Protect
B. Violation is Restrict
C. Violation is Shutdown
D. Maximum number of MAC addresses is 2
E. Maximum number of MAC addresses is 1
查看试卷,进入试卷练习
微信扫一扫,开始刷题
答案
CE
解析
暂无解析
相关试题
【多选题】
Which two are characteristics of RADIUS?___
A. Uses UDP ports 1812 /1813
B. Uses TCP port 49
C. Uses UDP port 49
D.
E. ncrypts only the password between user and server
【多选题】
When setting up a site-to-site VPN with PSK authentication on a Cisco router, which two elements must be configured under crypto map?___
A. pfs
B. nat
C. reverse route
D. peer
E. transform-set
【多选题】
When using the Adaptive Security Device Manager(ASDM), which two options are available to add a new root certificate?___
A. Install from SFTP server
B. Usehttps
C. Install from a file
D. Use LDAP
E. Use SCEP
【多选题】
Which two SNMPv3 services support its capabilities as a secure networ k manage protocol? ___
A. access control
B. the shared secret key
C. authentication
D. authorization
E. accounting
【多选题】
Which two statements about routed firewall mode are true ?___
A. The firewall acts as a routed hop in the network
B. This mode conceals the presence of the firewall
C. The firewall requires a unique iP address for each interface
D. This mode allows the firewall to be added to an existing networ k with minimal additional configuration By default, this mode permits most traffic to pass throug
【多选题】
Which two statements describe DHCP spoofing attacks?___
A. They are used to perform man-in- the-middle attacks
B. They can access most network devices
C. They can modify the flow of traffic in transit. LNGKAIG
D. They protect the identity of ti attacker by masking the DHCP address
E. They can physically modify the network gateway
【多选题】
Which two types of VLANs using PVLANs are valid?___
A. isolated
B. promiscuous
C. backup
D. secondary
E. community
【多选题】
What are two limitations of the self-zone policies on a zone-based firewall?___
A. They are unable to block Https traffic
B. They restrict SNMP traffic.
C. They are unable to support Https traffic
D. They are unable to implement application inspection
E. They are unable to perform rate limiting
【多选题】
Which two descriptions of TACACS+ are true? ___
A. The TACACS+ header is unencrypted
B. It combines a uthentication and authorization
C. It uses TCP as its transport protocol
D. Only the password is encrypted.
E. It uses UDP as its transport protocol.
【多选题】
Which two actions does an IPS perform? ___
A. it spans the traffic
B. it reflects the traffic back to the sender
C. it encrypts the traffic
D. it terminates the user session or connection of the attacker
E. it reconfigures a device to block the traffic
【多选题】
In which form of fraud does an attacker try to learn information such as login credenti account information by ma squerading as a reputable entity or person in email, IM or communication channels ?___
A. phishing
B. Smurfit
C. Hacking
D. Identity Spoofing
【多选题】
Which two ESA services are available for incoming and outgoing mails ?___
A. anti-DoS
B. reputation filter
C. antispam
D. content filter
E. DLP
【多选题】
What are two reasons to recommend SNMPv 3 over SNMPv2?___
A. SNMPv3 is secure because you can configure authe ntication and privacy
B. SNMPv3 is insecure because it send in formation in clear text
C. SNMPv2 is insecure because it send information in clear text
D. SNMPv3 is a Cisco proprietary protocol
E. SNMPv2 is secure because you can configure authentication and privacy
【多选题】
Which two actions can a zone- based firewall apply to a packet as it transits a zone pair?___
A. drop
B. inspect
C. queue
D. quarantine
【单选题】
Which security principle has been violated if data is altered in an unauthorized manner?___
A. accountability
B. confidentiality
C. availability
D. integrity
【单选题】
Which IKE Phase 1 parameter can you use to require the site-to-site VPN to use a pre-shared ?___
A. encryption
B. authentication
C. group
【单选题】
Which command successfully creates an administrative user with a password of "cisco"on a Cisco router?___
A. username Operator privilege 7 password cisco
B. username Operator privilege 1 password cisco
C. username Operator privilege 15 password cisco
D. username Operator password cisco privilege 15
【单选题】
Which EAP method authenticates a client against Active Directory without the use of client-side 802.1X certificates?___
A. EAP-TLS
B. EAP-MSCHAPv2
C. EAP-PEAP
D.
E. AP-GTC
【单选题】
What is a limitation of network-based IPS?___
A. It must be in dividually configured to support every operating system on the network.
B. It is most effective at the in dividual host level
C. It is unable to monitor attacks across the entire netw ork
D. Large installations require numerous sensors to fully protect the network
【单选题】
When would you configure the ip dhcp snooping trust command on a sw itch?___
A. when the switch is connected to a DHCP server
B. when the switch is working in an edge capacit
C. when the switch is connected to a client system
D. when the switch is serving as an aggregator
【单选题】
How does the 802. 1x supplicant communicate with the authentication server?___
A. The supplicant creates EAP packets and sends them to the authenticator, which encapsulates them into RADIUS and forwards them to the authentication server.
B. The supplicant creates RADIUS packets and sends them to the authe nticator, which encapsulates the m into EAP and forwards them to the a uthentication server.
C. The supplicant creates RADIUS packets and sends them to the authenticator, which translates them into eap and forwards them to the a ut hentication server
D. The supplicant creates
E. AP packets and sends them to the authe nticator, which translates them into radius and forwards them to the authentication server.
【单选题】
Which command do you enter to verify the phase I status of a VPN connection?___
A. sh crypto se ssion
B. debug crypto isakmp
C. sh crypto isakmp sa
D. sh crypto ipsec sa
【单选题】
Refer to the exhibit. what is the e ffect of the given configuration?___
A. It enables authentication,
B. It prevents keychain authentication.
C. The two routers receive normal updates from one another.
D. The two device s are able to pass the message digest to one another.
【单选题】
Which command can you enter to configure OSPF to use hashing to authenticate routing updates?___
A. ip ospf aut hentication message-digest
B. neighbor 192 168.0 112 cost md5
C. ip ospf priority 1
D. ip ospf aut hentication-key
【单选题】
Which command can you enter to verify the status of Cisco lOS Resilient Configuration on a Cisco router?___
A. show secure bootset
B. secure boot-image
C. show binary file
D. ure boot-config
【单选题】
A user on your network inadvertently activates a botnet program that was received as an emai attachment. Which type of mechanism does Cisco Firepower use to detect and block only the botnet attack?___
A. network-based access control rule
B. reputation-based
C. user-ba sed access control rule
D. botnet traffic filter
【单选题】
What does the policy map do in CoPP?___
A. defines service parameters
B. defines packet selection parameters
C. defines the packet filter
D. define s the action to be performed
【单选题】
How is management traffic isolated on a Cisco ASR 1002?___
A. Traffic isolation is done on the vlan level
B. There is no management traffic isolation on a Cisco ASR 1002
C. Traffic is isolated based upon how you configure routing on the device
D. The management interface is configured in a special vRF that provides traffic isolation from the default routing table
【单选题】
Which statement about NaT table evaluation in the asa is true?___
A. After-auto NAT polices are appl d first
B. Manual NAT policies are applied first
C. the asa uses the most specific match
D. Auto NAT policies are applied first
【单选题】
Which information can you display by executing the show crypto ipsec sa command?___
A. ISAKMP SAs that are established between two peers
B. recent changes to the IP address of a peer router
C. proxy infor mation for the connection between two peers
D. IPsec SAs established between two peers
【单选题】
How can you prevent NAT rules from sending traffic to incorrect interfaces?___
A. Assign the output interface in the NAT statement
B. Add the no-proxy-arp command to the nat line.
C. Configure twice NAT instead o bject NAT. 5
D. Use packet-tracer rules to reroute misrouted NAT entries.
【单选题】
What term can be defined as the securing, control, and identification of digital data?___
A. cryptography
B. crypto key
C. cryptoanalysis
D. cryptology
【单选题】
Which feature in the dNS security module provide on and off network DNS protection?___
A. Data Loss Prevention
B. Umbrella
C. Real-time sandboxing
D. Layer-4 monitoring
【单选题】
Which a dverse consequence can occur on a network without BPDu guard ?___
A. The olde st switch can be elected as the root bridge
B. Unauthorized switches that are connected to the network can cause spanning-tree loops
C.
D. ouble tagging can cause the switches to experience CAM table overload.
【单选题】
What configuration is required for multitenancy ?___
A. shared infrastructure
B. multiple carriers
C. co-located resources
D. multiple separate zones
【单选题】
Why does ISE require its own certificate issued by a trusted CA?___
A. ISEs certificate allows guest devices to validate it as a trusted network device
B. It generates certificates for guest devices ba sed on its own certificate
C. It requests certificates for guest devices from the Ca server based on its own certificate.
D. ISE's certificate allows it to join the network security framework
【单选题】
which attack involves large numbers of ICMP packets with a spoofed source IP address?___
A. smurf attack
B. Teardrop attack
C. Nuke attack
D. SYN Flood attack
【单选题】
Which statement about interface and global access rules is true?___
A. Interface access rules are processed before global access rules.
B. Global access rules apply only to outbound traffic, but interface access rules can be applied in either direction
C. The implicit allow is proce ssed after both the global and interface access rules
D. If an interface access rule is applied, the global access rule is ignored
【单选题】
Which type of malicious software can create a back-door into a device or network?___
A. bot
B. worm
C. virus
D. Trojan
【单选题】
Which security term refers to the like lihood that a weakness will be exploited to cause damage to an asset?___
A. threat
B. risk
C. countermeasure
D. vulnerability
推荐试题
【判断题】
更换道岔尖轨作业目的确保线路稳定,保证地铁列车安全运行
A. 对
B. 错
【判断题】
尖轨非工作边与基本轨工作边的最小距离为65mm,容许误差为-2mm
A. 对
B. 错
【判断题】
使用撬棍翻动钢轨时,要有经验人员操作,其他人要远离撬棍和钢轨翻动的方向,禁止用手翻动钢轨
A. 对
B. 错
【判断题】
钢轨拨进拨出时,要统一指挥,动作一致,注意前后、左右人员安全,以防伤人
A. 对
B. 错
【判断题】
上道时要执行“眼看、手比、口呼”制度,确保人身安全
A. 对
B. 错
【判断题】
铁路支距尺用于测量标准轨距铁路道岔导曲线的支距
A. 对
B. 错
【判断题】
支距测量范围为100~1390mm
A. 对
B. 错
【判断题】
液压起道器应定期检查液压油是否清洁,并及时更换新油
A. 对
B. 错
【判断题】
液压起道器更换液压油前,用汽油或柴油将油箱内洗干净
A. 对
B. 错
【判断题】
液压起道器不工作时,油缸柱塞应全部回缩,防止表面锈蚀
A. 对
B. 错
【判断题】
液压拨道器,是适用于铁道线路日常保养和维修的专用工具,具有起道拔道两种功能
A. 对
B. 错
【判断题】
液压起拨道器由底盘、底盘两端销轴、拨杆、起道轮液压传动系统组成
A. 对
B. 错
【判断题】
液压起拨道器油箱渗油的原因为油箱紧固螺栓松动
A. 对
B. 错
【判断题】
捣固机器操作时,应避开防爬器、轨距杆、支撑等障碍物
A. 对
B. 错
【判断题】
捣固机器作业中,操作手应密切注意机器运转情况和线路状态
A. 对
B. 错
【判断题】
捣固作业发生故障时,应立即停机,用手压泵急速提镐下道进行处理,严禁在线路上停机处理故障
A. 对
B. 错
【判断题】
使用燃油发动机,加油时不用停机
A. 对
B. 错
【判断题】
进行绝缘接头拆卸作业时,需通号人员配合,长柄工具应有绝缘套,作业中不得将两股钢轨搭接
A. 对
B. 错
【判断题】
进行锯轨和打磨时,非操作人员应离开作业区至少1m以上
A. 对
B. 错
【判断题】
翻动钢轨或拨钢轨时,要指派业务熟悉、体力较好的人员进行,同时应喊号使动作一致
A. 对
B. 错
【判断题】
更换钢轨时,如需动用道岔,需通号部门联系进行配合
A. 对
B. 错
【判断题】
上道作业前应对磨轨机进行全面细致的检查,若机器工作性能不良,砂轮片受潮,禁止使用
A. 对
B. 错
【判断题】
上道作业前应对磨轨机进行全面细致的检查,以电动机为动力的,若发现电气开关状态不良,电缆线绝缘不良,单边绝缘性能不良,禁止上道作业
A. 对
B. 错
【判断题】
安放工料具及卸、运钢轨时,不得损坏轨旁设备
A. 对
B. 错
【判断题】
检查、改正尖轨部分轨距,调整好尖轨开程、动程,以及轮缘槽尺寸、竖切部分密贴状况,配合通号人员调试尖轨密贴
A. 对
B. 错
【判断题】
运送备用钢轨及工具材料至施工现场,放在轨枕头时,距线路上的钢轨净距不少于150㎜
A. 对
B. 错
【判断题】
运送备用钢轨及工具材料至施工现场,放在道心时,距线路的钢轨净距不少于300㎜
A. 对
B. 错
【判断题】
运送备用钢轨及工具材料至施工现场,新轨高度不得超过线路上的钢轨面25㎜
A. 对
B. 错
【判断题】
起道捣固作业看道:起道人俯身距起道机20~30m处的标准股上往回看,以起好的地段为准,看钢轨下腭水平线的高低情况,指挥压机手起道
A. 对
B. 错
【判断题】
起道捣固作业根据车流密度和线路状态,接头应适当抬高,考虑沉落量
A. 对
B. 错
【判断题】
在坡道上起道,从上坡往下坡看时,每点都不能低,从下坡往上坡看时每点都不能高
A. 对
B. 错
【判断题】
正线路轨距变化率不大于1/1000,其他线路不大于2/1000
A. 对
B. 错
【判断题】
据轨作业时,锯后钢轨长度误差不超过±2mm
A. 对
B. 错
【判断题】
钻孔作业时,螺孔允许误差:孔径±1mm,位置±lmm
A. 对
B. 错
【判断题】
钻孔作业时,钢轨孔两边应到棱,边缘不得有毛刺;倒棱倒角45°~60°,顺长0.5~1.0mm
A. 对
B. 错
【判断题】
安装接头鱼尾板时,曲线线路接头的紧固顺序为:先紧1、6位,再2、5位,最后紧3、4位
A. 对
B. 错
【判断题】
安装接头鱼尾板时,直线线路的接头螺栓紧固顺序为:先紧1、6位,再紧3、4位,最后拧紧2、5位
A. 对
B. 错
【判断题】
安装接头鱼尾板时,初步紧固后,要用扭矩扳手按顺序扭紧螺帽,调校至所需的扭矩
A. 对
B. 错
【判断题】
接头鱼尾板安装完成后的1至2个星期内,工班长应安排人员对该接头螺栓进行复紧
A. 对
B. 错
【判断题】
更换铁垫板时,铁垫板应安放在木枕中间,位置正确平整,垫板外肩要与轨底密靠,空隙不超过2mm,滑床板与基本轨落槽,滑床板与基本轨及尖轨底部密贴
A. 对
B. 错
欢迎使用我爱刷题
×
微信搜索我爱刷题小程序
温馨提示
×
请在电脑上登陆“www.woaishuati.com”使用