刷题
导入试题
【单选题】
Which statement about NaT table evaluation in the asa is true?___
A. After-auto NAT polices are appl d first
B. Manual NAT policies are applied first
C. the asa uses the most specific match
D. Auto NAT policies are applied first
查看试卷,进入试卷练习
微信扫一扫,开始刷题
答案
B
解析
暂无解析
相关试题
【单选题】
Which information can you display by executing the show crypto ipsec sa command?___
A. ISAKMP SAs that are established between two peers
B. recent changes to the IP address of a peer router
C. proxy infor mation for the connection between two peers
D. IPsec SAs established between two peers
【单选题】
How can you prevent NAT rules from sending traffic to incorrect interfaces?___
A. Assign the output interface in the NAT statement
B. Add the no-proxy-arp command to the nat line.
C. Configure twice NAT instead o bject NAT. 5
D. Use packet-tracer rules to reroute misrouted NAT entries.
【单选题】
What term can be defined as the securing, control, and identification of digital data?___
A. cryptography
B. crypto key
C. cryptoanalysis
D. cryptology
【单选题】
Which feature in the dNS security module provide on and off network DNS protection?___
A. Data Loss Prevention
B. Umbrella
C. Real-time sandboxing
D. Layer-4 monitoring
【单选题】
Which a dverse consequence can occur on a network without BPDu guard ?___
A. The olde st switch can be elected as the root bridge
B. Unauthorized switches that are connected to the network can cause spanning-tree loops
C.
D. ouble tagging can cause the switches to experience CAM table overload.
【单选题】
What configuration is required for multitenancy ?___
A. shared infrastructure
B. multiple carriers
C. co-located resources
D. multiple separate zones
【单选题】
Why does ISE require its own certificate issued by a trusted CA?___
A. ISEs certificate allows guest devices to validate it as a trusted network device
B. It generates certificates for guest devices ba sed on its own certificate
C. It requests certificates for guest devices from the Ca server based on its own certificate.
D. ISE's certificate allows it to join the network security framework
【单选题】
which attack involves large numbers of ICMP packets with a spoofed source IP address?___
A. smurf attack
B. Teardrop attack
C. Nuke attack
D. SYN Flood attack
【单选题】
Which statement about interface and global access rules is true?___
A. Interface access rules are processed before global access rules.
B. Global access rules apply only to outbound traffic, but interface access rules can be applied in either direction
C. The implicit allow is proce ssed after both the global and interface access rules
D. If an interface access rule is applied, the global access rule is ignored
【单选题】
Which type of malicious software can create a back-door into a device or network?___
A. bot
B. worm
C. virus
D. Trojan
【单选题】
Which security term refers to the like lihood that a weakness will be exploited to cause damage to an asset?___
A. threat
B. risk
C. countermeasure
D. vulnerability
【单选题】
Which IPS detection method examines network traffic for preconfigured patterns?___
A. signature-based detection
B. honey-pot detection
C. anomaly-based detection
D. policy-based detection
【单选题】
What is an advantage of split tunneling ?___
A. It allows users with a VpN connection to a corporate network to access the internet with sending traffic across the cor porate network.
B. It allows users with a vpn connection to a corporate network to access the internet by using the vPN for security.
C. It protects traffic on the private network from users on the public network
D. It enables the VPN server to filter traffic more efficiently
【单选题】
Which IDS/IPS state misidentifies acceptable behavior as an attack ?___
A. false negative
B. true positive NEKA G
C. true negative
D. false positive
【单选题】
What is the maximum num ber of methods that a single method list can contain?___
A. 4
B. 3
C. 2
D. 5
【单选题】
Which command enables authentication at the oSPFv2 routing process level?___
A. ip ospf authentication message-digest
B. area 0 authentication message-digest
C. ip ospf message-digest-key 1 mds Cisco
D. area 0 authentication ipsec spi 500 md5 1234567890ABCDEF1234567890ABCDEF
【单选题】
Which type of firewall monitors a nd protects a specific system?___
A. firewall
B. application firewall
C. stateless firewall wvp
D. personal firewall
【单选题】
On an ASA, which maps are used to identify traffic?___
A. Route maps
B. Policy maps
C. Class maps
D. Service maps
【单选题】
Which type of social engineering attack targets top executives?___
A. whaling
B. vishin
C. spear phishing ng
D. baiting
【单选题】
What is the minimum Cisco lOS version that supports zone-based firewalls?___
A. 12.1T
B. 15.1
C. 15.0
D. 124
【单选题】
In which type of attack does an attacker overwrite an entry in the CAM table to divert traffic destined to a legitimate host?___
A. DHCP spoofing
B. ARP spoofing
C. CAM table overflow
D. MAC spoofing
【多选题】
Which two attack types can be prevented with the impleme ntation of a Cisco IPS solution?___
A. DDos
B. man-in-the-middle
C. worms
D. ARP spoofing
E. VLAN hopping
【多选题】
choose four___
A. DHCP snooping ——————————blocks DHCP messages
B. Dynamic ARP inspection——————verifies IP-to-MAC traffic on untrusted ports
C. IP sources guard ——————————provides layer 2 interface security with ports ACLs
D. Port security————————————mitigates MAC-address spoofing at the access interface
【多选题】
choose four___
A. Step1————————run the system setup wizard
B. Step2————————add an authentication realm
C. Step3————————configure identity management
D. Step4————————configure directory group
【多选题】
What are two advanced features of the Cisco AMp solution for endpoints ___
A. contemplation
B. foresight
C. sandboxing
D. reputation
E. reflection
【多选题】
Which two characteristics of RADIUS are true?___
A. It encrypts only the password between user and server.
B. It uses TCP ports 1812/1813
C. It uses UDP ports 1812/1813.
D. It uses UDP port 49
E. It uses TCP port 49
【多选题】
What are two challenges of using a network-based IPS? ___
A. It is unable to determine whether a detected attack was successful
B. It requires additional storage and proce ssor capacity on syslog servers
C. As the network expands, it requires you to add more sensors.
D. It is unable to detect attacks across the entire network
E. It must support multiple operating systems.
【多选题】
What are two default be haviors of the traffic on a zone-based firewall?___
A. Traffic within the self -zone uses an im plicit deny all.
B. All traffic between zones is implicitly blocked
C. Communication is allowed between interfadAss that are members of the same zone
D. Communication is blocked between interfaces that are members of the same zone
E. The CBAC rules that are configured on router interfaces apply to zone interfaces
【多选题】
Which two advantages does the on-premise model for MDM deployment have over the cloud-based model?___
A. The on-premise model is easier and faster to de ploy than the cloud-based model
B. The on-premise model is more scalable than the cloud-based model
C. The on-premise model is generally less expensive than the cloud-based model
D. The on-premise model generally has less latency than the cloud- based model.
E. The on-premise model provides more control of the MDM solution than the cloud
【多选题】
Which two actions can an end usts take to manage a lost or stolen device in Cisco ISE? ___
A. Activate Cisco ISE End point Protection Services to quarantine the device.
B. Add the mac address of the device to a list of blacklisted devices
C. Force the device to be locked with a PIN
D. Request revocation of the digital certificate of the device.
E. Reinstate a device that the user previously marked as lost or stolen
【多选题】
Which two problems can arise when a proxy firewall serves as the gateway between networks?___
A. It can prevent content caching
B. It can limit application support
C. It is unable to prevent direct connections to other networks
D. It can cause reduced throughput.
E. It is unable to provide antivirus protection
【多选题】
When using the Adaptive Security Device Manager(ASDM), which two methods are available to add a new root certificate?___
A. Use sCep
B. Install from SFTP server
C. Install from a file
D. Use Https
E. Use LDAP
【多选题】
Which two are considered basic security principles?___
A. Accountability
B. Redundancy
C. High Availabilit
D. Integrity
E. Confidentiality
【多选题】
Which two roles of the Cisco WSA are true?___
A. IPS
B. firewall
C. antispam
D. web proxy
E. URL filter
【单选题】
Which next-generation encryption algorithm supports four variants?___
A. SHA-2
B. SHA-1
C. MD5
D. HMAC
【单选题】
What aims to remove the abil ity to deny an action?___
A. Non-Repudiation
B. Accountability
C. Integrity
D. Deniability
【单选题】
Which statements about the native VLAN is true ?___
A. It is susceptible to VLAN hopping attacks.
B. It is the Cisco recommended VLAN for switch-management traffic
C. It is most secure when it is a ssigned to vLAn 1.
D. It is the cisco-recomme nded vlan for user traffic
【单选题】
There are two versions of IKE:IKEv1 and IKEv2. Both IKEv1 and IKEv2 protocols operate in phases IKEv1 operates in two phases. IKEv2 operates in how many phases?___
A. 2
B. 3
C. 4
D. 5
【单选题】
What does the dh group refer to?___
A. length of key for hashing C
B. length of key for encryption
C. tunnel lifetime key
D. length of key for key exchange
E. length of key for authentication
【单选题】
Which path do you follow to enable aaa through the SDM ?___
A. Configure Tasks > AAA
B. Configure > Addition Authentication > AAA
C. Configure > AAA
D. Configure > Additional Tasks > AAA
E. Configure Authentication > AAA
推荐试题
【单选题】
列车在区间被迫停车后,对于邻线上妨碍行车地点,应从两方面___处防护,如确知列车开来方向时,仅对来车方面防护。
A. 不小于300m
B. 不小于800m
C. 按线路最大速度等级规定的列车紧急制动距离位置
【单选题】
列车运行途中司机发现客车车辆轮轴故障、车体下沉(倾斜)、车辆剧烈振动等危及行车安全的情况时,须立即采取停车措施,停车后由___负责检查处理。
A. 机车乘务员
B. 车辆乘务员
C. 车站(助理)值班员
【单选题】
遇有施工引导接车并正线通过时,准许列车司机凭特定引导手信号的显示,以不超过___ km/h速度进站。
A. 20
B. 30
C. 60
【单选题】
进站预告信号机以显示___信号为定位。
A. 进行
B. 注意
C. 停车
【单选题】
进站信号机均以显示___信号为定位。
A. 进行
B. 注意
C. 停车
【单选题】
引导信号应在列车___越过信号机后及时关闭。
A. 第一轮对
B. 头部
C. 全部
【单选题】
出站信号机的灯光熄灭、显示不明或显示不正确时,均视为___信号。
A. 停车
B. 进行
C. 注意
【单选题】
进站预告信号机灯光熄灭时,视为进站信号机显示为___信号。
A. 停车
B. 进行
C. 注意
【单选题】
三显示自动闭塞区段的进站色灯信号机显示一个绿色灯光时,表示出站及进路信号机在___,进路上的道岔均开通直向位置。
A. 开放状态
B. 关闭状态
C. 无显示状态
【单选题】
四显示自动闭塞区段的进站色灯信号机显示一个黄色闪光和一个黄色灯光,准许列车经过18号及以上道岔___位置,进入站内越过次一架已经开放的信号机。
A. 侧向
B. 直向
C. 正向
【单选题】
进站信号机的引导信号显示一个红色灯光和一个月白色灯光时,列车进站的速度不超过___km/h,并须准备随时停车。
A. 10
B. 15
C. 20
【单选题】
半自动闭塞区段,出站色灯信号机显示___灯光,准许列车由车站出发,开往次要线路。
A. 一个绿色
B. 两个绿色
C. 一个月白色
【单选题】
三显示自动闭塞区段,出站色灯信号机显示一个___灯光,准许列车由车站出发,表示运行前方有一个闭塞分区空闲。
A. 绿色
B. 黄色
C. 月白色
【单选题】
三显示自动闭塞区段的发车进路色灯信号机显示一个___灯光,准许列车运行到次一架信号机之前准备停车。
A. 月白色
B. 黄色
C. 绿色
【单选题】
三显示自动闭塞区段通过色灯信号机显示一个绿色灯光,准许列车按规定速度运行,表示运行前方至少有___闭塞分区空闲。
A. 一个
B. 两个
C. 三个
【单选题】
四显示自动闭塞区段的通过色灯信号机比三显示自动闭塞区段的通过色灯信号机多了___灯光的显示方式。
A. 两个绿色
B. 两个黄色
C. 一个绿色和一个黄色
【单选题】
四显示自动闭塞区段,通过色灯信号机显示一个___灯光,要求列车减速运行,按规定限速要求越过该信号机,表示运行前方有一个闭塞分区空闲。
A. 红色
B. 黄色
C. 绿色
【单选题】
四显示自动闭塞区段,通过色灯信号机显示一个绿色灯光和一个黄色灯光,准许列车按规定速度运行,要求注意准备减速,表示运行前方有___个闭塞分区空闲。
A. 一
B. 两
C. 三
【单选题】
容许信号显示一个___灯光——准许列车在通过色灯信号机显示红色灯光的情况下不停车,以不超过20 km/h的速度通过,运行到次一架通过信号机,并随时准备停车。
A. 绿色
B. 黄色
C. 蓝色
【单选题】
预告色灯信号机(不含遮断信号机的预告信号机)显示一个___灯光, 表示主体信号机在关闭状态。
A. 绿色
B. 黄色
C. 红色
【单选题】
当进站信号机开放一个绿色灯光和一个黄色灯光时,其接近信号机将会显示___灯光。
A. 一个绿色
B. 一个黄色灯光
C. 一个绿色灯光和一个黄色灯光
【单选题】
调车色灯信号机显示一个___灯光时,准许越过该信号机调车。
A. 月白色
B. 红色
C. 蓝色
【单选题】
驼峰色灯信号机显示一个红色闪光灯光,指示机车车辆自驼峰___。
A. 下峰
B. 退回
C. 停车
【单选题】
驼峰色灯信号机显示___——指示机车车辆加速向驼峰推进。
A. 一个绿色
B. 一个绿色闪光灯光
C. 一个绿色灯光和一个黄色灯光
【单选题】
驼峰色灯辅助信号机及其复示信号机显示一个黄色灯光,指示机车车辆向驼峰___推送。
A. 缓慢
B. 准备
C. 预先
【单选题】
进站信号机的色灯复示信号机无显示表示主体信号机在___状态。
A. 开放
B. 关闭
C. 灭灯
【单选题】
发车进路信号机的色灯复示信号机显示一个绿色灯光——表示主体信号机在___状态。
A. 开放
B. 关闭
C. 无显示
【单选题】
在自动闭塞区段,当列车接近的通过信号机显示容许信号时,机车信号机显示一个___灯光。
A. 半黄半红色闪光
B. 红色
C. 蓝色
【单选题】
三显示自动闭塞区段机车信号机显示一个黄色灯光,要求列车注意运行,表示列车接近的地面信号机显示一个___灯光。
A. 红色
B. 蓝色
C. 黄色
【单选题】
无线调车灯显信号显示绿灯闪数次后熄灭,表示___信号。
A. 推进
B. 起动
C. 连结
【单选题】
无线调车灯显信号显示绿、黄灯交替后绿灯长亮,表示___信号。
A. 连接
B. 溜放
C. 减速
【单选题】
列车运行中,遇昼间两臂高举头上向两侧急剧摇动,夜间白色灯光上下急剧摇动,司机应立即___。
A. 减速
B. 降弓
C. 停车
【单选题】
列车运行中,遇昼间展开的___信号旗,司机需将列车降低到要求的速度。
A. 红色
B. 黄色
C. 绿色
【单选题】
调车手信号指挥机车向显示人反方向去的信号,昼间用展开的绿色信号旗、夜间用绿色灯光___。
A. 在下部左右摇动
B. 上下摇动
C. 上下小动
【单选题】
调车手信号指挥机车向显示人方向稍行移动的信号,昼间为拢起的红色信号旗直立平举,再用展开的绿色信号旗___。
A. 上下摇动
B. 左右小动
C. 上下小动
【单选题】
联系用手信号显示股道号码时,夜间白色灯光左右摇动后,从左下方向右上方高举,表示股道开通___道。
A. 一
B. 二
C. 三
【单选题】
联系用手信号显示股道号码时,夜间白色灯光作圆形转动,表示股道开通___道。
A. 二
B. 五
C. 八
【单选题】
联系用手信号显示股道号码时,昼间右臂向右平伸,左臂向右下斜45°角,表示股道开通___道。
A. 四
B. 六
C. 九
【单选题】
联系用手信号显示股道号码时,夜间白色灯光作圆形转动后,再高举头上左右小动,表示股道开通___道。
A. 八
B. 九
C. 十
【单选题】
联系用手信号显示十、五、三车距离信号中的“十车”(约110米)信号时,昼间的显示方式为展开的绿色信号旗单臂平伸连续下压 ___次。
A. 一
B. 两
C. 三
欢迎使用我爱刷题
×
微信搜索我爱刷题小程序
温馨提示
×
请在电脑上登陆“www.woaishuati.com”使用