刷题
导入试题
【多选题】
Which two default settings for port security are true ?___
A. Violation is Protect
B. Violation is Restrict
C. Violation is Shutdown
D. Maximum number of MAC addresses is 2
E. Maximum number of MAC addresses is 1
查看试卷,进入试卷练习
微信扫一扫,开始刷题
答案
CE
解析
暂无解析
相关试题
【多选题】
Which two are characteristics of RADIUS?___
A. Uses UDP ports 1812 /1813
B. Uses TCP port 49
C. Uses UDP port 49
D.
E. ncrypts only the password between user and server
【多选题】
When setting up a site-to-site VPN with PSK authentication on a Cisco router, which two elements must be configured under crypto map?___
A. pfs
B. nat
C. reverse route
D. peer
E. transform-set
【多选题】
When using the Adaptive Security Device Manager(ASDM), which two options are available to add a new root certificate?___
A. Install from SFTP server
B. Usehttps
C. Install from a file
D. Use LDAP
E. Use SCEP
【多选题】
Which two SNMPv3 services support its capabilities as a secure networ k manage protocol? ___
A. access control
B. the shared secret key
C. authentication
D. authorization
E. accounting
【多选题】
Which two statements about routed firewall mode are true ?___
A. The firewall acts as a routed hop in the network
B. This mode conceals the presence of the firewall
C. The firewall requires a unique iP address for each interface
D. This mode allows the firewall to be added to an existing networ k with minimal additional configuration By default, this mode permits most traffic to pass throug
【多选题】
Which two statements describe DHCP spoofing attacks?___
A. They are used to perform man-in- the-middle attacks
B. They can access most network devices
C. They can modify the flow of traffic in transit. LNGKAIG
D. They protect the identity of ti attacker by masking the DHCP address
E. They can physically modify the network gateway
【多选题】
Which two types of VLANs using PVLANs are valid?___
A. isolated
B. promiscuous
C. backup
D. secondary
E. community
【多选题】
What are two limitations of the self-zone policies on a zone-based firewall?___
A. They are unable to block Https traffic
B. They restrict SNMP traffic.
C. They are unable to support Https traffic
D. They are unable to implement application inspection
E. They are unable to perform rate limiting
【多选题】
Which two descriptions of TACACS+ are true? ___
A. The TACACS+ header is unencrypted
B. It combines a uthentication and authorization
C. It uses TCP as its transport protocol
D. Only the password is encrypted.
E. It uses UDP as its transport protocol.
【多选题】
Which two actions does an IPS perform? ___
A. it spans the traffic
B. it reflects the traffic back to the sender
C. it encrypts the traffic
D. it terminates the user session or connection of the attacker
E. it reconfigures a device to block the traffic
【多选题】
In which form of fraud does an attacker try to learn information such as login credenti account information by ma squerading as a reputable entity or person in email, IM or communication channels ?___
A. phishing
B. Smurfit
C. Hacking
D. Identity Spoofing
【多选题】
Which two ESA services are available for incoming and outgoing mails ?___
A. anti-DoS
B. reputation filter
C. antispam
D. content filter
E. DLP
【多选题】
What are two reasons to recommend SNMPv 3 over SNMPv2?___
A. SNMPv3 is secure because you can configure authe ntication and privacy
B. SNMPv3 is insecure because it send in formation in clear text
C. SNMPv2 is insecure because it send information in clear text
D. SNMPv3 is a Cisco proprietary protocol
E. SNMPv2 is secure because you can configure authentication and privacy
【多选题】
Which two actions can a zone- based firewall apply to a packet as it transits a zone pair?___
A. drop
B. inspect
C. queue
D. quarantine
【单选题】
Which security principle has been violated if data is altered in an unauthorized manner?___
A. accountability
B. confidentiality
C. availability
D. integrity
【单选题】
Which IKE Phase 1 parameter can you use to require the site-to-site VPN to use a pre-shared ?___
A. encryption
B. authentication
C. group
【单选题】
Which command successfully creates an administrative user with a password of "cisco"on a Cisco router?___
A. username Operator privilege 7 password cisco
B. username Operator privilege 1 password cisco
C. username Operator privilege 15 password cisco
D. username Operator password cisco privilege 15
【单选题】
Which EAP method authenticates a client against Active Directory without the use of client-side 802.1X certificates?___
A. EAP-TLS
B. EAP-MSCHAPv2
C. EAP-PEAP
D.
E. AP-GTC
【单选题】
What is a limitation of network-based IPS?___
A. It must be in dividually configured to support every operating system on the network.
B. It is most effective at the in dividual host level
C. It is unable to monitor attacks across the entire netw ork
D. Large installations require numerous sensors to fully protect the network
【单选题】
When would you configure the ip dhcp snooping trust command on a sw itch?___
A. when the switch is connected to a DHCP server
B. when the switch is working in an edge capacit
C. when the switch is connected to a client system
D. when the switch is serving as an aggregator
【单选题】
How does the 802. 1x supplicant communicate with the authentication server?___
A. The supplicant creates EAP packets and sends them to the authenticator, which encapsulates them into RADIUS and forwards them to the authentication server.
B. The supplicant creates RADIUS packets and sends them to the authe nticator, which encapsulates the m into EAP and forwards them to the a uthentication server.
C. The supplicant creates RADIUS packets and sends them to the authenticator, which translates them into eap and forwards them to the a ut hentication server
D. The supplicant creates
E. AP packets and sends them to the authe nticator, which translates them into radius and forwards them to the authentication server.
【单选题】
Which command do you enter to verify the phase I status of a VPN connection?___
A. sh crypto se ssion
B. debug crypto isakmp
C. sh crypto isakmp sa
D. sh crypto ipsec sa
【单选题】
Refer to the exhibit. what is the e ffect of the given configuration?___
A. It enables authentication,
B. It prevents keychain authentication.
C. The two routers receive normal updates from one another.
D. The two device s are able to pass the message digest to one another.
【单选题】
Which command can you enter to configure OSPF to use hashing to authenticate routing updates?___
A. ip ospf aut hentication message-digest
B. neighbor 192 168.0 112 cost md5
C. ip ospf priority 1
D. ip ospf aut hentication-key
【单选题】
Which command can you enter to verify the status of Cisco lOS Resilient Configuration on a Cisco router?___
A. show secure bootset
B. secure boot-image
C. show binary file
D. ure boot-config
【单选题】
A user on your network inadvertently activates a botnet program that was received as an emai attachment. Which type of mechanism does Cisco Firepower use to detect and block only the botnet attack?___
A. network-based access control rule
B. reputation-based
C. user-ba sed access control rule
D. botnet traffic filter
【单选题】
What does the policy map do in CoPP?___
A. defines service parameters
B. defines packet selection parameters
C. defines the packet filter
D. define s the action to be performed
【单选题】
How is management traffic isolated on a Cisco ASR 1002?___
A. Traffic isolation is done on the vlan level
B. There is no management traffic isolation on a Cisco ASR 1002
C. Traffic is isolated based upon how you configure routing on the device
D. The management interface is configured in a special vRF that provides traffic isolation from the default routing table
【单选题】
Which statement about NaT table evaluation in the asa is true?___
A. After-auto NAT polices are appl d first
B. Manual NAT policies are applied first
C. the asa uses the most specific match
D. Auto NAT policies are applied first
【单选题】
Which information can you display by executing the show crypto ipsec sa command?___
A. ISAKMP SAs that are established between two peers
B. recent changes to the IP address of a peer router
C. proxy infor mation for the connection between two peers
D. IPsec SAs established between two peers
【单选题】
How can you prevent NAT rules from sending traffic to incorrect interfaces?___
A. Assign the output interface in the NAT statement
B. Add the no-proxy-arp command to the nat line.
C. Configure twice NAT instead o bject NAT. 5
D. Use packet-tracer rules to reroute misrouted NAT entries.
【单选题】
What term can be defined as the securing, control, and identification of digital data?___
A. cryptography
B. crypto key
C. cryptoanalysis
D. cryptology
【单选题】
Which feature in the dNS security module provide on and off network DNS protection?___
A. Data Loss Prevention
B. Umbrella
C. Real-time sandboxing
D. Layer-4 monitoring
【单选题】
Which a dverse consequence can occur on a network without BPDu guard ?___
A. The olde st switch can be elected as the root bridge
B. Unauthorized switches that are connected to the network can cause spanning-tree loops
C.
D. ouble tagging can cause the switches to experience CAM table overload.
【单选题】
What configuration is required for multitenancy ?___
A. shared infrastructure
B. multiple carriers
C. co-located resources
D. multiple separate zones
【单选题】
Why does ISE require its own certificate issued by a trusted CA?___
A. ISEs certificate allows guest devices to validate it as a trusted network device
B. It generates certificates for guest devices ba sed on its own certificate
C. It requests certificates for guest devices from the Ca server based on its own certificate.
D. ISE's certificate allows it to join the network security framework
【单选题】
which attack involves large numbers of ICMP packets with a spoofed source IP address?___
A. smurf attack
B. Teardrop attack
C. Nuke attack
D. SYN Flood attack
【单选题】
Which statement about interface and global access rules is true?___
A. Interface access rules are processed before global access rules.
B. Global access rules apply only to outbound traffic, but interface access rules can be applied in either direction
C. The implicit allow is proce ssed after both the global and interface access rules
D. If an interface access rule is applied, the global access rule is ignored
【单选题】
Which type of malicious software can create a back-door into a device or network?___
A. bot
B. worm
C. virus
D. Trojan
【单选题】
Which security term refers to the like lihood that a weakness will be exploited to cause damage to an asset?___
A. threat
B. risk
C. countermeasure
D. vulnerability
推荐试题
【多选题】
自动转账签约管理包括()。___
A. 自动转账签约
B. 自动转账解约
C. 查询自动转账签约信息
D. 更换自动转账账户
【多选题】
个人客户办理“聪明账”增值账户业务需本人或者代理人到营业网点办理,且提供的资料包括()。___
A. 本人有效身份证件原件
B. 代理人须持代理人和被代理人有效身份证件原件
C. 本人(或被代理人)金穗借记卡
D. 签订《中国农业银行“聪明账”增值账户业务协议》,一式两份
【多选题】
“聪明账”增值账户业务是将客户的个人()和()以系统联系起来,进行科学管理,以增加客户收益的一项理财业务。___
A. 活期存款账户
B. 零存整取定期账户
C. 整存整取存款定期子账户
D. 通知存款账户
【多选题】
个人资金归集入账方式分为()。___
A. 多笔入账
B. 单笔入账
C. 指定笔数入账
D. 汇总入账
【多选题】
“整存整取加息智能转存”业务中合理转存天数的计算由()决定。___
A. 旧定期利率
B. 新定期利率
C. 新活期利率
D. 存期
【多选题】
客户可以通过()签约“整存整取加息智能转存”。___
A. 整存整取存单
B. 定期一本通
C. 金穗借记卡
D. 活期一本通
【多选题】
“整存整取加息智能转存”重新存入的账户()发生相应的改变,存款原账号不改变。___
A. 账户余额
B. 利率
C. 起息日
D. 到期日
【多选题】
“整存整取加息智能转存”业务中转存时重新存入的账户余额为()之和。___
A. 提前支取的存款账户余额
B. 原定期存款账户余额
C. 提前支取的税后活期利息
D. 提前支取的账户本息和
【多选题】
“聪明账”增值账户明细查询可以查询到()等明细。___
A. 自动约转子账户明细
B. 便捷消费子账户冻结明细
C. 便捷消费子账户消费明细
D. 便捷消费子账户销转明细
【多选题】
个人资金归集签约业务办理成功后,需交还客户的相关资料包括()等。___
A. 业务回单第二联
B. 《个人资金归集业务协议书》第二联
C. 收费凭证
D. 身份证件原件
【多选题】
确认资金归集关系交易办理成功后,需专夹保管的相关资料包括()等。___
A. 《个人资金归集子账户扣款授权书》第一联
B. 业务回单第一联
C. 《个人资金归集子账户扣款授权书》第二联
D. 身份证复印件
【多选题】
凡因()或其他目的需要开具资信证明的居民个人和非居民个人,均可向我行开办个人存款证明业务的营业机构申请办理。___
A. 出国留学
B. 探亲
C. 旅游
D. 移民定居
【多选题】
个人存款证明仅作为客户本人在银行个人金融资产的证明,()或作其它用途,也不能作为办理支取的凭据。___
A. 可以质押
B. 不得转让
C. 不得为他人担保或作其他用途
D. 不能挂失
【多选题】
可用于开具个人存款证明的个人金融资产包括:()等。___
A. 本外币定活期储蓄存款
B. 凭证式国债
C. 储蓄国债
D. 中低风险的个人理财产品
【多选题】
周末及法定节假日不办理存金通定投业务的()。___
A. 赎回
B. 签约
C. 修改
D. 终止
【多选题】
存金通非交易过户是指因()等原因进行的贵金属份额的所有权转移。___
A. 遗产继承
B. 转让
C. 出售
D. 赠与
【多选题】
经办人员进入存金通销售交易,录入(),审核无误后提交系统处理。___
A. 账户金代码
B. 销售重量
C. 选择客户级别
D. 销售价格
【多选题】
客户与我行签订存金通产品定投协议时,应约定()、()、()及()。定投截止日期与首次委托购买日期的时间间隔必须大于或等于12个月。___
A. 定投品种
B. 委托购买日
C. 定投重量
D. 定投截止日期
【多选题】
经办人员办理存金通销售、购回、提货等交易时,若因柜员操作失误、在交易系统中录入错误,在尚未同投资者进行实物黄金交割或资金收付前,报三级主管同意后可以通过柜员撤销交易进行撤销。本交易()进行。___
A. 可跨日
B. 不可跨日
C. 可跨柜员
D. 不可跨柜员
【多选题】
BoEing投资理财业务客户签约时可以选择开通渠道。除系统默认的渠道外,个人可以开通的渠道包括()。___
A. 电话银行
B. 网银渠道
C. 掌上银行
D. 自助机具
【多选题】
签约天天利滚利及半开放式产品做自动理财时,需客户选择()作为申购周期。___
A. 每天
B. 每周
C. 每季
D. 每半年
【多选题】
可以修改的自动理财签约主要信息有()。___
A. 最低留存金额
B. 单笔最高限额
C. 理财产品
D. 申购周期
【多选题】
理财产品购买交易包括()。___
A. 认购
B. 申购
C. 申购预申请
D. 回购
【多选题】
个人客户可在()进行风险承受能力评测。___
A. 网银端
B. 电话银行
C. 掌上银行端
D. 柜面端
【多选题】
目前对公“双利丰”可签约活期账户类型包括()。___
A. 基本户
B. 一般户
C. 临时户
D. 专用户
【多选题】
对公双利丰最低起存金额为等值人民币()万元(含)以上,且原则上要求子账户最低汇总金额不得低于等值人民币()万元。___
A. 10万元
B. 50万元
C. 500万元
D. 5000万元
【多选题】
个人客户持()到开户行所在省内的任一营业机构办理理财产品赎回和实时赎回业务。___
A. 理财产品认购书
B. 本人有效身份证件
C. 存款证明书
D. 原交易介质
【多选题】
理财产品交割单打印,在数据保留期间支持客户补打,补打时显示补打字样。个人客户可到()进行打印及补打,对公客户只能在()进行打印及补打。___
A. 全国任一网点
B. 省内任一网点
C. 辖内任一网点
D. 开户网点
【多选题】
对公客户应持有()到其开户行办理理财产品紧急退出业务。___
A. 加盖公章的企业营业执照正本或副本复印件
B. 加盖公章的组织机构代码证、事业单位法人、社会团体或其他组织提供的民政部门或主管部门颁发的注册登记证书复印件
C. 经办人有效身份证件原件及复印件
D. 非企业法定代表人(单位负责人)办理的,需提供《理财业务授权委托书》
【多选题】
企业网银端实现理财产品()等交易功能。___
A. 购买
B. 自动理财签约
C. 赎回
D. 撤销
【多选题】
结算产品是指以结算账户为基础,为满足交易双方结清债权债务需要所提供的结算服务。主要包括()等产品。___
A. 票据产品
B. 汇兑
C. 委托收款
D. 单位结算卡
【多选题】
票据产品是指《中华人民共和国票据法》所规定的由出票人依法签发的、约定自己或者委托付款人在见票时或指定的日期向收款人或持票人无条件支付一定金额并可转让的有价证券,主要包括()等。___
A. 银行汇票
B. 商业汇票
C. 银行本票
D. 支票
【多选题】
汇兑产品是根据汇款人委托,通过行内网内往来系统或人民银行现代化支付系统将其款项汇给异地收款人的一种资金汇划结算方式,系统设有()和()。___
A. 加急汇兑
B. 普通汇兑
C. 特急汇兑
D. 紧急汇兑
【多选题】
单位结算卡是我行单位结算账户的支付媒介,为对公客户提供多渠道现金存取款、转账、消费和查询等服务。一张单位结算卡关联一个单位结算账户,通过()和()共同控制交易风险。___
A. 卡密码
B. K宝
C. 附加安全认证方式
D. K令
【多选题】
账户管理产品是指农业银行通过营业网点或电子渠道为客户提供的基于其结算账户的个性化服务,以方便客户构建合理的账户体系、及时掌握账户信息、有效控制账户收支,科学进行业务决策。主要包括()等产品。___
A. 账户信息服务
B. 账户支付限额
C. 账户收支对象
D. 账户监管
【多选题】
账户支付限额管理是指客户可申请对结算账户的单笔或一定时期的累计支付金额进行控制,对超过金额的交易予以限制,分为()。___
A. 单笔支付限额
B. 日支付限额
C. 年支付限额
D. 累计支付限额
【多选题】
多级账簿是指客户在同一结算账户下开设的分类明细核算登记簿(也称辅助账簿),主要记载一定时期内资金收付的详细信息。客户通过多级账簿,不但能实现同一结算账户分类明细核算,还可实现()等功能。___
A. 外部监管
B. 额度管理控制
C. 分类查询统计
D. 资金内部计价
【多选题】
结算套餐重点营销目标是中小企业优质客户,中小企业优质客户的标准主要参考其账户的()。___
A. 对公结算量
B. 中间业务收入
C. 月均存款
D. 授信情况
【多选题】
对公人民币结算套餐收费基数包含()。___
A. 按笔收费
B. 按金额收费
C. 按月收费
D. 按年收费
【多选题】
单位存款分为()和人民银行规定的其他存款。___
A. 活期存款
B. 定期存款
C. 通知存款
D. 协定存款
欢迎使用我爱刷题
×
微信搜索我爱刷题小程序
温馨提示
×
请在电脑上登陆“www.woaishuati.com”使用