【多选题】
When setting up a site-to-site VPN with PSK authentication on a Cisco router, which two elements must be configured under crypto map?___
A. pfs
B. nat
C. reverse route
D. peer
E. transform-set
查看试卷,进入试卷练习
微信扫一扫,开始刷题
相关试题
【多选题】
When using the Adaptive Security Device Manager(ASDM), which two options are available to add a new root certificate?___
A. Install from SFTP server
B. Usehttps
C. Install from a file
D. Use LDAP
E. Use SCEP
【多选题】
Which two SNMPv3 services support its capabilities as a secure networ k manage protocol? ___
A. access control
B. the shared secret key
C. authentication
D. authorization
E. accounting
【多选题】
Which two statements about routed firewall mode are true ?___
A. The firewall acts as a routed hop in the network
B. This mode conceals the presence of the firewall
C. The firewall requires a unique iP address for each interface
D. This mode allows the firewall to be added to an existing networ k with minimal additional configuration By default, this mode permits most traffic to pass throug
【多选题】
Which two statements describe DHCP spoofing attacks?___
A. They are used to perform man-in- the-middle attacks
B. They can access most network devices
C. They can modify the flow of traffic in transit. LNGKAIG
D. They protect the identity of ti attacker by masking the DHCP address
E. They can physically modify the network gateway
【多选题】
Which two types of VLANs using PVLANs are valid?___
A. isolated
B. promiscuous
C. backup
D. secondary
E. community
【多选题】
What are two limitations of the self-zone policies on a zone-based firewall?___
A. They are unable to block Https traffic
B. They restrict SNMP traffic.
C. They are unable to support Https traffic
D. They are unable to implement application inspection
E. They are unable to perform rate limiting
【多选题】
Which two descriptions of TACACS+ are true? ___
A. The TACACS+ header is unencrypted
B. It combines a uthentication and authorization
C. It uses TCP as its transport protocol
D. Only the password is encrypted.
E. It uses UDP as its transport protocol.
【多选题】
Which two actions does an IPS perform? ___
A. it spans the traffic
B. it reflects the traffic back to the sender
C. it encrypts the traffic
D. it terminates the user session or connection of the attacker
E. it reconfigures a device to block the traffic
【多选题】
In which form of fraud does an attacker try to learn information such as login credenti account information by ma squerading as a reputable entity or person in email, IM or communication channels ?___
A. phishing
B. Smurfit
C. Hacking
D. Identity Spoofing
【多选题】
Which two ESA services are available for incoming and outgoing mails ?___
A. anti-DoS
B. reputation filter
C. antispam
D. content filter
E. DLP
【多选题】
What are two reasons to recommend SNMPv 3 over SNMPv2?___
A. SNMPv3 is secure because you can configure authe ntication and privacy
B. SNMPv3 is insecure because it send in formation in clear text
C. SNMPv2 is insecure because it send information in clear text
D. SNMPv3 is a Cisco proprietary protocol
E. SNMPv2 is secure because you can configure authentication and privacy
【多选题】
Which two actions can a zone- based firewall apply to a packet as it transits a zone pair?___
A. drop
B. inspect
C. queue
D. quarantine
【单选题】
Which security principle has been violated if data is altered in an unauthorized manner?___
A. accountability
B. confidentiality
C. availability
D. integrity
【单选题】
Which IKE Phase 1 parameter can you use to require the site-to-site VPN to use a pre-shared ?___
A. encryption
B. authentication
C. group
【单选题】
Which command successfully creates an administrative user with a password of "cisco"on a Cisco router?___
A. username Operator privilege 7 password cisco
B. username Operator privilege 1 password cisco
C. username Operator privilege 15 password cisco
D. username Operator password cisco privilege 15
【单选题】
Which EAP method authenticates a client against Active Directory without the use of client-side 802.1X certificates?___
A. EAP-TLS
B. EAP-MSCHAPv2
C. EAP-PEAP
D.
E. AP-GTC
【单选题】
What is a limitation of network-based IPS?___
A. It must be in dividually configured to support every operating system on the network.
B. It is most effective at the in dividual host level
C. It is unable to monitor attacks across the entire netw ork
D. Large installations require numerous sensors to fully protect the network
【单选题】
When would you configure the ip dhcp snooping trust command on a sw itch?___
A. when the switch is connected to a DHCP server
B. when the switch is working in an edge capacit
C. when the switch is connected to a client system
D. when the switch is serving as an aggregator
【单选题】
How does the 802. 1x supplicant communicate with the authentication server?___
A. The supplicant creates EAP packets and sends them to the authenticator, which encapsulates them into RADIUS and forwards them to the authentication server.
B. The supplicant creates RADIUS packets and sends them to the authe nticator, which encapsulates the m into EAP and forwards them to the a uthentication server.
C. The supplicant creates RADIUS packets and sends them to the authenticator, which translates them into eap and forwards them to the a ut hentication server
D. The supplicant creates
E. AP packets and sends them to the authe nticator, which translates them into radius and forwards them to the authentication server.
【单选题】
Which command do you enter to verify the phase I status of a VPN connection?___
A. sh crypto se ssion
B. debug crypto isakmp
C. sh crypto isakmp sa
D. sh crypto ipsec sa
【单选题】
Refer to the exhibit. what is the e ffect of the given configuration?___
A. It enables authentication,
B. It prevents keychain authentication.
C. The two routers receive normal updates from one another.
D. The two device s are able to pass the message digest to one another.
【单选题】
Which command can you enter to configure OSPF to use hashing to authenticate routing updates?___
A. ip ospf aut hentication message-digest
B. neighbor 192 168.0 112 cost md5
C. ip ospf priority 1
D. ip ospf aut hentication-key
【单选题】
Which command can you enter to verify the status of Cisco lOS Resilient Configuration on a Cisco router?___
A. show secure bootset
B. secure boot-image
C. show binary file
D. ure boot-config
【单选题】
A user on your network inadvertently activates a botnet program that was received as an emai attachment. Which type of mechanism does Cisco Firepower use to detect and block only the botnet attack?___
A. network-based access control rule
B. reputation-based
C. user-ba sed access control rule
D. botnet traffic filter
【单选题】
What does the policy map do in CoPP?___
A. defines service parameters
B. defines packet selection parameters
C. defines the packet filter
D. define s the action to be performed
【单选题】
How is management traffic isolated on a Cisco ASR 1002?___
A. Traffic isolation is done on the vlan level
B. There is no management traffic isolation on a Cisco ASR 1002
C. Traffic is isolated based upon how you configure routing on the device
D. The management interface is configured in a special vRF that provides traffic isolation from the default routing table
【单选题】
Which statement about NaT table evaluation in the asa is true?___
A. After-auto NAT polices are appl d first
B. Manual NAT policies are applied first
C. the asa uses the most specific match
D. Auto NAT policies are applied first
【单选题】
Which information can you display by executing the show crypto ipsec sa command?___
A. ISAKMP SAs that are established between two peers
B. recent changes to the IP address of a peer router
C. proxy infor mation for the connection between two peers
D. IPsec SAs established between two peers
【单选题】
How can you prevent NAT rules from sending traffic to incorrect interfaces?___
A. Assign the output interface in the NAT statement
B. Add the no-proxy-arp command to the nat line.
C. Configure twice NAT instead o bject NAT. 5
D. Use packet-tracer rules to reroute misrouted NAT entries.
【单选题】
What term can be defined as the securing, control, and identification of digital data?___
A. cryptography
B. crypto key
C. cryptoanalysis
D. cryptology
【单选题】
Which feature in the dNS security module provide on and off network DNS protection?___
A. Data Loss Prevention
B. Umbrella
C. Real-time sandboxing
D. Layer-4 monitoring
【单选题】
Which a dverse consequence can occur on a network without BPDu guard ?___
A. The olde st switch can be elected as the root bridge
B. Unauthorized switches that are connected to the network can cause spanning-tree loops
C.
D. ouble tagging can cause the switches to experience CAM table overload.
【单选题】
What configuration is required for multitenancy ?___
A. shared infrastructure
B. multiple carriers
C. co-located resources
D. multiple separate zones
【单选题】
Why does ISE require its own certificate issued by a trusted CA?___
A. ISEs certificate allows guest devices to validate it as a trusted network device
B. It generates certificates for guest devices ba sed on its own certificate
C. It requests certificates for guest devices from the Ca server based on its own certificate.
D. ISE's certificate allows it to join the network security framework
【单选题】
which attack involves large numbers of ICMP packets with a spoofed source IP address?___
A. smurf attack
B. Teardrop attack
C. Nuke attack
D. SYN Flood attack
【单选题】
Which statement about interface and global access rules is true?___
A. Interface access rules are processed before global access rules.
B. Global access rules apply only to outbound traffic, but interface access rules can be applied in either direction
C. The implicit allow is proce ssed after both the global and interface access rules
D. If an interface access rule is applied, the global access rule is ignored
【单选题】
Which type of malicious software can create a back-door into a device or network?___
A. bot
B. worm
C. virus
D. Trojan
【单选题】
Which security term refers to the like lihood that a weakness will be exploited to cause damage to an asset?___
A. threat
B. risk
C. countermeasure
D. vulnerability
【单选题】
Which IPS detection method examines network traffic for preconfigured patterns?___
A. signature-based detection
B. honey-pot detection
C. anomaly-based detection
D. policy-based detection
【单选题】
What is an advantage of split tunneling ?___
A. It allows users with a VpN connection to a corporate network to access the internet with sending traffic across the cor porate network.
B. It allows users with a vpn connection to a corporate network to access the internet by using the vPN for security.
C. It protects traffic on the private network from users on the public network
D. It enables the VPN server to filter traffic more efficiently
推荐试题
【单选题】
在信贷资金总量一定的情况下,信贷资金周转速度、流动性、安全性、效益性的关系是___。
A. 周转速度快,流动性就越强,安全性就越能得保证。但效益性较差
B. 周转速度快,流动性就越强,安全性就差,效益性较差
C. 周转速度慢,流动性就越差,安全性也就越差,效益性较差
D. 周转速度慢,流动性就越差,安全性也就越好,效益性较好
【单选题】
以下措施不能提高商业银行经营流动性和安全性的是___。
A. 存贷款期限结构匹配
B. 提高存货周转速度
C. 提高应收账款的周转速度
D. 提高二级市场股票的换手频率
【单选题】
下列属于直接融资的行为有___。
A. 何某向工商银行借款100000 元专门用于其企业的工程结算
B. A 公司向B 公司投入资金8000000 元,并占有B 公司30%的股份
C. A 公司通过融资机构向B 公司借款600000 元
D. 何某通过金融机构借入资金120000 元
【单选题】
下列不属于借款申请需明确内容的是。___
A. 基本情况
B. 贷款品种
C. 贷款利率
D. 贷款金额
【单选题】
下列关于贷款种类说法,错误的是___
A. 按照贷款币种可分为人民币贷款和外币贷款
B. 按照贷款期限可分为短期贷款和中长期贷款
C. 按照贷款对象可分为生产企业贷款和外商投资企业贷款
D. 按照贷款利率可分为浮动利率贷款和固定利率贷款
【单选题】
下列不属于间接融资的行为有___。
A. 文小姐向银行借款10 万元专门用于其房屋装修
B. A 公司购入B 公司20%的股权,价值80 万元
C. 赵小姐春节期间通过信用卡透支了2 万元购买年货
D. 郑先生通过银行贷款购买了一辆车
【单选题】
调查的基本要求:熟知客户和客户的业务,取得必要的客户信息资料和信贷业务信息资料,并核实资料的___。
A. 真实性
B. 完成性
C. 可操作性
D. 全面性
【单选题】
商业银行在信贷过程中保持贷款种类和期限的多样化是为了保持信贷的___。
A. 效益性
B. 流动性
C. 安全性
D. 自主性
【单选题】
企业向银行借款属于____,发行债券、股票属于____。___
A. 直接融资;间接融资
B. 间接投资;直接投资
C. 间接融资;直接融资
D. 直接投资;间接投资
【单选题】
关于商业银行“安全性、流动性和效益性原则”的说法,不正确的是___。
A. 为了保证贷款的安全性,商业银行需要合理安排贷款的种类和期限
B. 在信贷资金总量一定的情况下,资金的周转速度加快,效益性相应较差
C. 在贷款规模一定的情况下,一般贷款期限越长,收益越大
D. 贷款期限越长,安全性越高
【单选题】
按贷款用途划分,公司信贷的种类不包括___
A. 基本建设贷款
B. 技术改造贷款
C. 流动资金贷款
D. 自营贷款
【单选题】
___是指特定产品要素组合下的信贷服务方式,主要包括贷款、担保、承兑、信用支持、保函、信用证和承诺等。
A. 交易对象
B. 信贷产品
C. 信贷金额
D. 信贷期限
【单选题】
银行市场细分是根据___差异对市场进行的划分。
A. 信贷产品
B. 卖方银行
C. 买方客户
D. 信贷市场
【单选题】
贷放分控是指银行业金融机构将___作为两个独立的业务环节。
A. 贷前申请与贷款审批
B. 贷款审批与贷款发放
C. 贷款发放与贷款清偿
D. 贷款申请与贷款清偿
【单选题】
除贷款外,商业银行的资金一般主要用于___。
A. 结算业务
B. 代理业务
C. 存款业务
D. 资金业务
【单选题】
___是银行在商业汇票上签章承诺按出票人指示到期付款的行为。
A. 承兑
B. 担保
C. 贷款
D. 公司信贷
【单选题】
在银行流动资金贷前调查报告中,借款人财务状况不包括___。
A. 流动资金数额和周转速度
B. 主要客户、供应商和分销渠道
C. 资产负债比率
D. 存货净值和周转速度
【单选题】
公司信贷的借款人指___
A. 经工商行政管理机关(或主管机关)核准登记的自然人
B. 经行政机关核准登记的企(事)业法人
C. 经行政机关核准登记的自然人
D. 经工商行政管理机关(或主管机关)核准登记的企(事)业法人
【单选题】
贷前调查中最常用、最重要的方法,同时也是在一般情况下必须采用的方法是___。
A. 现场调研
B. 搜寻调查
C. 委托调查
D. 突击检查
【单选题】
影响行业的外部因素不包括___
A. 国民经济
B. 外部经济
C. 国家政策
D. 企业自身规模效益
【单选题】
银行在对客户进行借款需求分析时,不需要关注的是___。
A. 企业的借款需求原因,即所借款项的用途
B. 企业的还款来源
C. 企业还款的可靠程度
D. 公司的治理结构
【单选题】
以下导致企业流动资产增加的因素不包括___。
A. 季节性销售增长
B. 长期销售增长
C. 资产效率下降
D. 债务重构
【单选题】
主营业务指标通常指主营业务收入占___的比重。
A. 营业额
B. 总资本
C. 全部利润
D. 销售收入总额
【单选题】
以下关于流动比率和企业资产的变现能力关系的说法中,正确的是___
A. 流动比率越高,说明企业资产的变现能力越强
B. 流动比率越高,说明企业资产的变现能力越弱
C. 流动比率越低,说明企业资产的变现能力越强
D. 流动比率与企业资产的变现能力没有关系
【单选题】
以下各项中不能反映应收账款的营运能力的是___。
A. 应收账款周转率
B. 应收账款回收期
C. 应收账款账龄
D. 应收账款余额
【单选题】
以下不属于所有者权益项目的是___
A. 未分配利润
B. 资本公积
C. 盈余公积
D. 流动资产
【单选题】
法人贷款业务,申请信贷业务的客户应当是经___核准登记的企业(事业)法人其他经济组织。
A. 工商行政管理机关(或主管机关)
B. 国税局
C. 人民银行
D. 农村信用社
【单选题】
下列因素与借款人的偿债能力无关的是___。
A. 盈利能力
B. 营运能力
C. 资本结构
D. 产品竞争力
【单选题】
下列关于资产负债率的论述中,错误的是___
A. 资产负债率=负债合计÷资产合计×100%
B. 资产负债率=资产合计÷负债合计×100%
C. 资产负债率反映项目各年负债水平、财务风险及偿债能力
D. 银行从债权安全的角度考虑,总希望借款人的负债水平低一点
【单选题】
下列公式中,不能反映存货周转速度的是___
A. 销货成本/平均存货余额×100%
B. 存货平均余额×计算期天数/销货成本
C. 计算期天数/存货周转次数
D. (期初存货余额+期末存货余额)/2
【单选题】
下列不属于资产负债表的基本内容的是___
A. 资产
B. 负债
C. 资本结构
D. 所有者权益
【单选题】
下列不属于企业财务状况风险的是___
A. 借款人在银行的存款有较大幅度下降
B. 应收账款异常增加
C. 流动资产占总资产比重下降
D. 短期负债增加适当,长期负债大量增加
【单选题】
所有者权益代表投资者对企业___所有权。
A. 全部资产
B. 全部负债
C. 净资产
D. 流动资产
【单选题】
商业银行对借款人最关心的就是其现在和未来的___。
A. 技术水平
B. 销售业绩
C. 偿债能力
D. 信息披露
【单选题】
一般企业贷款操作流程:___
A. 建立正式客户-评级-授信-申请贷款-发放贷款
B. 建立正式客户-授信-评级-申请贷款-发放贷款
C. 建立正式客户-申请贷款-评级-授信-发放贷款
D. 建立正式客户-申请贷款-授信-评级-发放贷款
【单选题】
借款人盈利能力的比率通过___反映。
A. 效率比率
B. 杠杆比率
C. 流动比率
D. 营业利润率
【单选题】
借款人还款能力的主要标志就是___。
A. 借款人的现金流量是否充足
B. 借款人的资产负债比率是否足够低
C. 借款人的管理水平是否很高
D. 借款人的销售收入和利润是否足够高
【单选题】
到的比率。___
A. 平均存货余额,销货收入
B. 销货收入,平均存货余额
C. 销货成本,平均存货余额
D. 平均存货余额,销货成本
【单选题】
反映客户长期偿债能力的比率是___
A. 流动比率
B. 资产负债率
C. 净利润率
D. 速动比率