刷题
导入试题
【多选题】
Which two default settings for port security are true ?___
A. Violation is Protect
B. Violation is Restrict
C. Violation is Shutdown
D. Maximum number of MAC addresses is 2
E. Maximum number of MAC addresses is 1
查看试卷,进入试卷练习
微信扫一扫,开始刷题
答案
CE
解析
暂无解析
相关试题
【多选题】
Which two are characteristics of RADIUS?___
A. Uses UDP ports 1812 /1813
B. Uses TCP port 49
C. Uses UDP port 49
D.
E. ncrypts only the password between user and server
【多选题】
When setting up a site-to-site VPN with PSK authentication on a Cisco router, which two elements must be configured under crypto map?___
A. pfs
B. nat
C. reverse route
D. peer
E. transform-set
【多选题】
When using the Adaptive Security Device Manager(ASDM), which two options are available to add a new root certificate?___
A. Install from SFTP server
B. Usehttps
C. Install from a file
D. Use LDAP
E. Use SCEP
【多选题】
Which two SNMPv3 services support its capabilities as a secure networ k manage protocol? ___
A. access control
B. the shared secret key
C. authentication
D. authorization
E. accounting
【多选题】
Which two statements about routed firewall mode are true ?___
A. The firewall acts as a routed hop in the network
B. This mode conceals the presence of the firewall
C. The firewall requires a unique iP address for each interface
D. This mode allows the firewall to be added to an existing networ k with minimal additional configuration By default, this mode permits most traffic to pass throug
【多选题】
Which two statements describe DHCP spoofing attacks?___
A. They are used to perform man-in- the-middle attacks
B. They can access most network devices
C. They can modify the flow of traffic in transit. LNGKAIG
D. They protect the identity of ti attacker by masking the DHCP address
E. They can physically modify the network gateway
【多选题】
Which two types of VLANs using PVLANs are valid?___
A. isolated
B. promiscuous
C. backup
D. secondary
E. community
【多选题】
What are two limitations of the self-zone policies on a zone-based firewall?___
A. They are unable to block Https traffic
B. They restrict SNMP traffic.
C. They are unable to support Https traffic
D. They are unable to implement application inspection
E. They are unable to perform rate limiting
【多选题】
Which two descriptions of TACACS+ are true? ___
A. The TACACS+ header is unencrypted
B. It combines a uthentication and authorization
C. It uses TCP as its transport protocol
D. Only the password is encrypted.
E. It uses UDP as its transport protocol.
【多选题】
Which two actions does an IPS perform? ___
A. it spans the traffic
B. it reflects the traffic back to the sender
C. it encrypts the traffic
D. it terminates the user session or connection of the attacker
E. it reconfigures a device to block the traffic
【多选题】
In which form of fraud does an attacker try to learn information such as login credenti account information by ma squerading as a reputable entity or person in email, IM or communication channels ?___
A. phishing
B. Smurfit
C. Hacking
D. Identity Spoofing
【多选题】
Which two ESA services are available for incoming and outgoing mails ?___
A. anti-DoS
B. reputation filter
C. antispam
D. content filter
E. DLP
【多选题】
What are two reasons to recommend SNMPv 3 over SNMPv2?___
A. SNMPv3 is secure because you can configure authe ntication and privacy
B. SNMPv3 is insecure because it send in formation in clear text
C. SNMPv2 is insecure because it send information in clear text
D. SNMPv3 is a Cisco proprietary protocol
E. SNMPv2 is secure because you can configure authentication and privacy
【多选题】
Which two actions can a zone- based firewall apply to a packet as it transits a zone pair?___
A. drop
B. inspect
C. queue
D. quarantine
【单选题】
Which security principle has been violated if data is altered in an unauthorized manner?___
A. accountability
B. confidentiality
C. availability
D. integrity
【单选题】
Which IKE Phase 1 parameter can you use to require the site-to-site VPN to use a pre-shared ?___
A. encryption
B. authentication
C. group
【单选题】
Which command successfully creates an administrative user with a password of "cisco"on a Cisco router?___
A. username Operator privilege 7 password cisco
B. username Operator privilege 1 password cisco
C. username Operator privilege 15 password cisco
D. username Operator password cisco privilege 15
【单选题】
Which EAP method authenticates a client against Active Directory without the use of client-side 802.1X certificates?___
A. EAP-TLS
B. EAP-MSCHAPv2
C. EAP-PEAP
D.
E. AP-GTC
【单选题】
What is a limitation of network-based IPS?___
A. It must be in dividually configured to support every operating system on the network.
B. It is most effective at the in dividual host level
C. It is unable to monitor attacks across the entire netw ork
D. Large installations require numerous sensors to fully protect the network
【单选题】
When would you configure the ip dhcp snooping trust command on a sw itch?___
A. when the switch is connected to a DHCP server
B. when the switch is working in an edge capacit
C. when the switch is connected to a client system
D. when the switch is serving as an aggregator
【单选题】
How does the 802. 1x supplicant communicate with the authentication server?___
A. The supplicant creates EAP packets and sends them to the authenticator, which encapsulates them into RADIUS and forwards them to the authentication server.
B. The supplicant creates RADIUS packets and sends them to the authe nticator, which encapsulates the m into EAP and forwards them to the a uthentication server.
C. The supplicant creates RADIUS packets and sends them to the authenticator, which translates them into eap and forwards them to the a ut hentication server
D. The supplicant creates
E. AP packets and sends them to the authe nticator, which translates them into radius and forwards them to the authentication server.
【单选题】
Which command do you enter to verify the phase I status of a VPN connection?___
A. sh crypto se ssion
B. debug crypto isakmp
C. sh crypto isakmp sa
D. sh crypto ipsec sa
【单选题】
Refer to the exhibit. what is the e ffect of the given configuration?___
A. It enables authentication,
B. It prevents keychain authentication.
C. The two routers receive normal updates from one another.
D. The two device s are able to pass the message digest to one another.
【单选题】
Which command can you enter to configure OSPF to use hashing to authenticate routing updates?___
A. ip ospf aut hentication message-digest
B. neighbor 192 168.0 112 cost md5
C. ip ospf priority 1
D. ip ospf aut hentication-key
【单选题】
Which command can you enter to verify the status of Cisco lOS Resilient Configuration on a Cisco router?___
A. show secure bootset
B. secure boot-image
C. show binary file
D. ure boot-config
【单选题】
A user on your network inadvertently activates a botnet program that was received as an emai attachment. Which type of mechanism does Cisco Firepower use to detect and block only the botnet attack?___
A. network-based access control rule
B. reputation-based
C. user-ba sed access control rule
D. botnet traffic filter
【单选题】
What does the policy map do in CoPP?___
A. defines service parameters
B. defines packet selection parameters
C. defines the packet filter
D. define s the action to be performed
【单选题】
How is management traffic isolated on a Cisco ASR 1002?___
A. Traffic isolation is done on the vlan level
B. There is no management traffic isolation on a Cisco ASR 1002
C. Traffic is isolated based upon how you configure routing on the device
D. The management interface is configured in a special vRF that provides traffic isolation from the default routing table
【单选题】
Which statement about NaT table evaluation in the asa is true?___
A. After-auto NAT polices are appl d first
B. Manual NAT policies are applied first
C. the asa uses the most specific match
D. Auto NAT policies are applied first
【单选题】
Which information can you display by executing the show crypto ipsec sa command?___
A. ISAKMP SAs that are established between two peers
B. recent changes to the IP address of a peer router
C. proxy infor mation for the connection between two peers
D. IPsec SAs established between two peers
【单选题】
How can you prevent NAT rules from sending traffic to incorrect interfaces?___
A. Assign the output interface in the NAT statement
B. Add the no-proxy-arp command to the nat line.
C. Configure twice NAT instead o bject NAT. 5
D. Use packet-tracer rules to reroute misrouted NAT entries.
【单选题】
What term can be defined as the securing, control, and identification of digital data?___
A. cryptography
B. crypto key
C. cryptoanalysis
D. cryptology
【单选题】
Which feature in the dNS security module provide on and off network DNS protection?___
A. Data Loss Prevention
B. Umbrella
C. Real-time sandboxing
D. Layer-4 monitoring
【单选题】
Which a dverse consequence can occur on a network without BPDu guard ?___
A. The olde st switch can be elected as the root bridge
B. Unauthorized switches that are connected to the network can cause spanning-tree loops
C.
D. ouble tagging can cause the switches to experience CAM table overload.
【单选题】
What configuration is required for multitenancy ?___
A. shared infrastructure
B. multiple carriers
C. co-located resources
D. multiple separate zones
【单选题】
Why does ISE require its own certificate issued by a trusted CA?___
A. ISEs certificate allows guest devices to validate it as a trusted network device
B. It generates certificates for guest devices ba sed on its own certificate
C. It requests certificates for guest devices from the Ca server based on its own certificate.
D. ISE's certificate allows it to join the network security framework
【单选题】
which attack involves large numbers of ICMP packets with a spoofed source IP address?___
A. smurf attack
B. Teardrop attack
C. Nuke attack
D. SYN Flood attack
【单选题】
Which statement about interface and global access rules is true?___
A. Interface access rules are processed before global access rules.
B. Global access rules apply only to outbound traffic, but interface access rules can be applied in either direction
C. The implicit allow is proce ssed after both the global and interface access rules
D. If an interface access rule is applied, the global access rule is ignored
【单选题】
Which type of malicious software can create a back-door into a device or network?___
A. bot
B. worm
C. virus
D. Trojan
【单选题】
Which security term refers to the like lihood that a weakness will be exploited to cause damage to an asset?___
A. threat
B. risk
C. countermeasure
D. vulnerability
推荐试题
【单选题】
国家标准《安全色》中规定,安全色为___四种颜色。
A. 红、蓝、黑、绿
B. 红、青、黄、绿
C. 红、蓝、黄、绿
【单选题】
安全生产管理的目标是减少、控制危害和事故,尽量避免生产过程中由于___所造成的人身伤害、财产损失及其他损失。
A. 管理不善
B. 危险
C. 事故
【单选题】
生产经营单位为了保证安全资金的有效投入,应编制安全技术措施计划,其核心是___。
A. 安全技术预案
B. 安全技术手册
C. 安全技术措施
【单选题】
根据突发环境事件的发生过程、性质和机理,突发环境事件分为:突发环境污染事件、___事件和辐射环境污染事件。
A. 危险化学品污染
B. 光化学污染
C. 生物物种安全环境
【单选题】
针对应急预案中全部或大部分应急响应功能,检验、评价应急组织应急行动能力的演练活动叫___演习。
A. 全面
B. 桌面
C. 功能
【单选题】
在应急救援过程中,物资供应部门负责抢险和抢救物资的___等工作。
A. 供销
B. 供应
C. 供应和保障
【单选题】
生产经营单位应当及时向有关部门或者单位报告应急预案的___,并按照有关应急预案报备程序重新备案。
A. 修订情况
B. 备案时间
C. 演练情况
【单选题】
《危险化学品安全管理条例》规定,___不得在托运的普通货物中夹带危险化学品,不得将危险化学品匿报或者谎报为普通货物托运。
A. 托运人
B. 运输单位
C. 承运人
【单选题】
《安全生产法》规定,危险物品的生产、经营、储存单位以及矿山、金属冶炼、城市轨道交通运营、建筑施工单位应当建立___组织;生产经营规模较小,可以不建立的,应当指定兼职的应急救援人员。
A. 安全
B. 应急救援
C. 工作
【单选题】
《危险化学品安全管理条例》规定,化学品安全技术说明书和化学品安全标签所载明的内容应当符合___标准的要求。
A. 国家
B. 行业
C. 企业
【单选题】
人体直接接触或过分接近正常带电体而发生的触电现象称为___触电。
A. 直接接触
B. 间接接触
C. 跨步电压
【单选题】
发生汽水共腾的主要原因是___。
A. 炉水pH值太低
B. 炉水含盐量太低
C. 炉水含盐量太高
【单选题】
依照卫生部公布的职业病目录,法定尘肺不包括___。
A. 铝尘肺
B. 石墨尘肺
C. 木工尘肺
【单选题】
爆炸现象的最主要特征是___。
A. 压力急剧升高
B. 温度升高
C. 发热发光
【单选题】
可燃粉尘的粒径越小,发生爆炸的危险性___。
A. 越小
B. 越大
C. 无关
【单选题】
零售业务的店面与存放危险化学品的库房(或罩棚)应有实墙相隔。单一品种存放量不能超过()kg,总质量不能超过___t。
A. 500、2
B. 300、1
C. 500、3
【单选题】
下列可以露天堆放的物品是___。
A. 剧毒物品
B. 遇湿燃烧物品
C. 腐蚀物品
【单选题】
当受热、撞击或强烈震动时,容器内压力急剧增大,致使容器破裂爆炸,或导致气瓶阀门松动漏气,酿成火灾或中毒事故的危险化学品为___。
A. 爆炸品
B. 易燃液体
C. 压缩气体和液化气体
【单选题】
按照《化学品安全标签编写规定》的要求,化学品的名称应用___标明。
A. 中文
B. 英文
C. 中文和英文分别
【单选题】
海因里希对5000多起伤害事故案例进行了详细调查研究后得出海因里希法则,事故后果为严重伤害、轻微伤害和无伤害的事故件数之比为___。
A. 1:10:300
B. 1:29:300
C. 1:10:100
【单选题】
《生产安全事故报告和调查处理条例》中要求,事故报告应当及时、准确、___。
A. 完整
B. 详细
C. 全面
【单选题】
锅炉上的易熔塞、电路中的熔断器都是减少事故损失的措施,其具体作用可概括为___。
A. 救援
B. 隔离
C. 设置薄弱环节
【单选题】
特种设备使用单位对在用特种设备应当至少每___进行一次自行检查,并作出记录。
A. 月
B. 两个月
C. 三个月
【单选题】
化学品安全技术说明书中所写化学品名称___。
A. 必须用中、英文两种形式填写
B. 只写中文名称,不用写英文名称
C. 只写英文名称,不写中文名称
【单选题】
在同一房间或同一区域内,不同的物料之间分开一定的距离,非禁忌物料间用通道保持空间的储存方式叫___储存。
A. 隔离
B. 隔开
C. 分离
【单选题】
运输危险化学品的车船及其它运输工具___搭乘无关人员。
A. 禁止
B. 可搭乘1人
C. 允许搭乘多名
【单选题】
下列___是事故隐患排查治理和防控的责任主体。
A. 安全监管监察部门
B. 生产经营单位
C. 政府有关部门
【单选题】
企业应急预案的编制要做到___,使预案的制定过程成为隐患排查治理的过程和全员应急知识培训教育的过程。
A. 领导参与
B. 专家参与
C. 全员参与
【单选题】
《危险化学品安全管理条例》规定,___级以上人民政府应当建立危险化学品安全监督管理工作协调机制,支持、督促负有危险化学品安全监督管理职责的部门依法履行职责,协调、解决危险化学品安全监督管理工作中的重大问题。
A. 省
B. 市
C. 县
【单选题】
《危险化学品经营企业开业条件和技术要求》规定,零售业务的店面内危险化学品的摆放应布局合理,___不能混放。综合性商场(含建材市场)所经营的危险化学品应有专柜存放。
A. 不同商品
B. 所有物料
C. 禁忌物料
【单选题】
《安全生产法》规定,矿山、金属冶炼、建筑施工、道路运输单位和危险物品的生产、经营、储存单位,应当设置___机构或者配备专职安全生产管理人员。
A. 办事
B. 安全生产管理
C. 专门
【单选题】
带电灭火时,若用水枪灭火,宜采用___水枪。
A. 喷淋
B. 水柱
C. 喷雾
【单选题】
《气瓶安全监察规程》规定,采用车辆运输时,气瓶要妥善固定。卧放时,瓶阀端应朝向一方,垛高不得超过___层且不得超过车箱高度。
A. 4
B. 5
C. 6
【单选题】
下列属于职业危害中物理危害的是___。
A. 电离辐射
B. 细菌
C. 有机粉尘
【单选题】
不属于燃烧三要素的是___。
A. 点火源
B. 可燃性物质
C. 阻燃性物质
【单选题】
在《常用危险化学品的分类及标志》中规定,每种常用危险化学品最多可选用___个安全标志。
A. 2
B. 3
C. 4
【单选题】
苯急性中毒主要表现为对中枢神经系统的麻醉作用,而慢性中毒主要为___系统的损害。
A. 消化?
B. 呼吸
C. 造血
【单选题】
受日光照射能发生化学反应引起燃烧、爆炸、分解、化合或能产生有毒气体的危险品包装应采取___措施。
A. 避光
B. 防潮湿
C. 防火
【单选题】
爆炸品禁止使用的灭火剂___。
A. 泡沫
B. 水
C. 沙土盖压
【单选题】
危险化学品的托运人不得___。
A. 在普通货物中夹带危险化学品
B. 向承运人说明运输的危险化学品的危害
C. 向承运人说明运输的危险化学品的应急措施
欢迎使用我爱刷题
×
微信搜索我爱刷题小程序
温馨提示
×
请在电脑上登陆“www.woaishuati.com”使用