【单选题】
Why does ISE require its own certificate issued by a trusted CA?___
A. ISEs certificate allows guest devices to validate it as a trusted network device
B. It generates certificates for guest devices ba sed on its own certificate
C. It requests certificates for guest devices from the Ca server based on its own certificate.
D. ISE's certificate allows it to join the network security framework
查看试卷,进入试卷练习
微信扫一扫,开始刷题
相关试题
【单选题】
which attack involves large numbers of ICMP packets with a spoofed source IP address?___
A. smurf attack
B. Teardrop attack
C. Nuke attack
D. SYN Flood attack
【单选题】
Which statement about interface and global access rules is true?___
A. Interface access rules are processed before global access rules.
B. Global access rules apply only to outbound traffic, but interface access rules can be applied in either direction
C. The implicit allow is proce ssed after both the global and interface access rules
D. If an interface access rule is applied, the global access rule is ignored
【单选题】
Which type of malicious software can create a back-door into a device or network?___
A. bot
B. worm
C. virus
D. Trojan
【单选题】
Which security term refers to the like lihood that a weakness will be exploited to cause damage to an asset?___
A. threat
B. risk
C. countermeasure
D. vulnerability
【单选题】
Which IPS detection method examines network traffic for preconfigured patterns?___
A. signature-based detection
B. honey-pot detection
C. anomaly-based detection
D. policy-based detection
【单选题】
What is an advantage of split tunneling ?___
A. It allows users with a VpN connection to a corporate network to access the internet with sending traffic across the cor porate network.
B. It allows users with a vpn connection to a corporate network to access the internet by using the vPN for security.
C. It protects traffic on the private network from users on the public network
D. It enables the VPN server to filter traffic more efficiently
【单选题】
Which IDS/IPS state misidentifies acceptable behavior as an attack ?___
A. false negative
B. true positive NEKA G
C. true negative
D. false positive
【单选题】
What is the maximum num ber of methods that a single method list can contain?___
【单选题】
Which command enables authentication at the oSPFv2 routing process level?___
A. ip ospf authentication message-digest
B. area 0 authentication message-digest
C. ip ospf message-digest-key 1 mds Cisco
D. area 0 authentication ipsec spi 500 md5 1234567890ABCDEF1234567890ABCDEF
【单选题】
Which type of firewall monitors a nd protects a specific system?___
A. firewall
B. application firewall
C. stateless firewall wvp
D. personal firewall
【单选题】
On an ASA, which maps are used to identify traffic?___
A. Route maps
B. Policy maps
C. Class maps
D. Service maps
【单选题】
Which type of social engineering attack targets top executives?___
A. whaling
B. vishin
C. spear phishing ng
D. baiting
【单选题】
What is the minimum Cisco lOS version that supports zone-based firewalls?___
A. 12.1T
B. 15.1
C. 15.0
D. 124
【单选题】
In which type of attack does an attacker overwrite an entry in the CAM table to divert traffic destined to a legitimate host?___
A. DHCP spoofing
B. ARP spoofing
C. CAM table overflow
D. MAC spoofing
【多选题】
Which two attack types can be prevented with the impleme ntation of a Cisco IPS solution?___
A. DDos
B. man-in-the-middle
C. worms
D. ARP spoofing
E. VLAN hopping
【多选题】
choose four___
A. DHCP snooping ——————————blocks DHCP messages
B. Dynamic ARP inspection——————verifies IP-to-MAC traffic on untrusted ports
C. IP sources guard ——————————provides layer 2 interface security with ports ACLs
D. Port security————————————mitigates MAC-address spoofing at the access interface
【多选题】
choose four___
A. Step1————————run the system setup wizard
B. Step2————————add an authentication realm
C. Step3————————configure identity management
D. Step4————————configure directory group
【多选题】
What are two advanced features of the Cisco AMp solution for endpoints ___
A. contemplation
B. foresight
C. sandboxing
D. reputation
E. reflection
【多选题】
Which two characteristics of RADIUS are true?___
A. It encrypts only the password between user and server.
B. It uses TCP ports 1812/1813
C. It uses UDP ports 1812/1813.
D. It uses UDP port 49
E. It uses TCP port 49
【多选题】
What are two challenges of using a network-based IPS? ___
A. It is unable to determine whether a detected attack was successful
B. It requires additional storage and proce ssor capacity on syslog servers
C. As the network expands, it requires you to add more sensors.
D. It is unable to detect attacks across the entire network
E. It must support multiple operating systems.
【多选题】
What are two default be haviors of the traffic on a zone-based firewall?___
A. Traffic within the self -zone uses an im plicit deny all.
B. All traffic between zones is implicitly blocked
C. Communication is allowed between interfadAss that are members of the same zone
D. Communication is blocked between interfaces that are members of the same zone
E. The CBAC rules that are configured on router interfaces apply to zone interfaces
【多选题】
Which two advantages does the on-premise model for MDM deployment have over the cloud-based model?___
A. The on-premise model is easier and faster to de ploy than the cloud-based model
B. The on-premise model is more scalable than the cloud-based model
C. The on-premise model is generally less expensive than the cloud-based model
D. The on-premise model generally has less latency than the cloud- based model.
E. The on-premise model provides more control of the MDM solution than the cloud
【多选题】
Which two actions can an end usts take to manage a lost or stolen device in Cisco ISE? ___
A. Activate Cisco ISE End point Protection Services to quarantine the device.
B. Add the mac address of the device to a list of blacklisted devices
C. Force the device to be locked with a PIN
D. Request revocation of the digital certificate of the device.
E. Reinstate a device that the user previously marked as lost or stolen
【多选题】
Which two problems can arise when a proxy firewall serves as the gateway between networks?___
A. It can prevent content caching
B. It can limit application support
C. It is unable to prevent direct connections to other networks
D. It can cause reduced throughput.
E. It is unable to provide antivirus protection
【多选题】
When using the Adaptive Security Device Manager(ASDM), which two methods are available to add a new root certificate?___
A. Use sCep
B. Install from SFTP server
C. Install from a file
D. Use Https
E. Use LDAP
【多选题】
Which two are considered basic security principles?___
A. Accountability
B. Redundancy
C. High Availabilit
D. Integrity
E. Confidentiality
【多选题】
Which two roles of the Cisco WSA are true?___
A. IPS
B. firewall
C. antispam
D. web proxy
E. URL filter
【单选题】
Which next-generation encryption algorithm supports four variants?___
A. SHA-2
B. SHA-1
C. MD5
D. HMAC
【单选题】
What aims to remove the abil ity to deny an action?___
A. Non-Repudiation
B. Accountability
C. Integrity
D. Deniability
【单选题】
Which statements about the native VLAN is true ?___
A. It is susceptible to VLAN hopping attacks.
B. It is the Cisco recommended VLAN for switch-management traffic
C. It is most secure when it is a ssigned to vLAn 1.
D. It is the cisco-recomme nded vlan for user traffic
【单选题】
There are two versions of IKE:IKEv1 and IKEv2. Both IKEv1 and IKEv2 protocols operate in phases IKEv1 operates in two phases. IKEv2 operates in how many phases?___
【单选题】
What does the dh group refer to?___
A. length of key for hashing C
B. length of key for encryption
C. tunnel lifetime key
D. length of key for key exchange
E. length of key for authentication
【单选题】
Which path do you follow to enable aaa through the SDM ?___
A. Configure Tasks > AAA
B. Configure > Addition Authentication > AAA
C. Configure > AAA
D. Configure > Additional Tasks > AAA
E. Configure Authentication > AAA
【单选题】
which technology cloud be used on top of an MPLS VPN to add confidentiality ?___
A. IPsec
B. 3DES
C. AES
D. SSL
【单选题】
Which term is most closely aligned with the basic purpose of a SIEM solution? ___
A. Non-Repudiation
B. Accountability
C. Causality
D. Repudiation
【单选题】
You have just deployed SNMPv3 in your environment, Your manager asks you to make sure that our SNMP agents can only talk to the SNMP Manager. What would you configure on your SNMI agents to satisfy this request?___
A. A SNMP View containing the SNMP managers
B. Routing Filter with the SNMP managers in it applied outbound
C. A standard ACL containing the SNMP managers applied to the SNMP configuration
D. A SNMP Group containing the SNMP managers
【单选题】
Which feature prevents loops by moving a nontrunking port into an errdisable state when a BPDU is received on that port?___
A. BPDU filte
B. DHCP snooping
C. BPDU guard
D. Port Fast
【单选题】
Which command enables port security to use sticky MAC addresses on a switch?___
A. switchport port-security violation restrict
B. switchport port-security mac-address sticky
C. switchport port-security violation protect
D. switchport port-security
【单选题】
When you edit an IPS subsignature, what is the effect on the parent signature and the family of subsignatures?___
A. The change applies to the parent signature and the entire family of subsignatures
B. The change applies to the parent signature and the subsignature that you edit
C. The change applies only to subsignatures that are numbered sequentially after the subsignature that you edit
D. Other signatures are unaffected, the change applies only to the subsignature that you dit
【单选题】
Which type of mechanism does Cisco FirePOWER de ploy to protect ag detected moving across other networks?___
A. antivirus scanning
B. policy-based
C. reputation-based
D. signature-based
推荐试题
【单选题】
以下关于静脉血栓形成的病因叙述不正确的是___
A. 静脉壁损伤
B. 血流缓慢
C. 血液高凝状态
D. 多发生于手术后或制动患者
E. 静脉闭塞
【单选题】
对不稳定的股骨颈骨折治疗是___
A. 手法复位,外固定
B. 手法复位,内外固定
C. 手法复位,内固定
D. 牵引治疗
E. 以上都不对
【单选题】
骨关节结核的表现除哪项外均是___
A. 夜间盗汗
B. 局部肿胀疼
C. 消瘦
D. 关节僵直
E. 高热
【单选题】
全胃肠外营养支持患者可能发生的最严重的代谢并发症是___
A. 高钾血症
B. 低钾血症
C. 高渗性非酮性昏迷
D. 肝功能异常
E. 高血糖
【单选题】
胃-十二指肠溃疡急性穿孔最重要的诊断依据是___
A. X线检查可见膈下游离气体
B. 肝浊音界缩小
C. 上腹部刀割样剧痛
D. 腹式呼吸音减弱
E. 板状腹
【单选题】
指出断肢再植术后护理中错误的一项___
A. 专人护理,禁止探视
B. 室温应恒定在20~25℃为宜
C. 术后1周开始患肢功能锻炼
D. 患肢斜坡放置于比心脏略高5~8cm
E. 禁用血管收缩药物
【单选题】
肩关节脱位特有的体征是___
A. 肩部肿胀
B. 肩部外展障碍
C. 方肩畸形
D. 肩部内收障碍
E. 肩部压痛
【单选题】
胆道T管引流与腹腔引流管的护理措施不同的是___
A. 拔管前夹管观察1~2天
B. 妥善固定引流管
C. 观察引流量和性状
D. 保持引流管通畅
E. 引流袋不得高于引流出口
【单选题】
可确定骨关节脱位的是___
A. 功能障碍
B. 疼痛
C. 弹性固定
D. 骨擦音
E. 肿胀
【单选题】
胃癌按组织病理学分类,临床最常见的是___
A. 鳞癌
B. 腺癌
C. 黏液癌
D. 低分化癌
E. 未分化癌
【单选题】
患者,女性,35岁,左肾结核无功能,右肾轻度积水,功能尚可,膀胱容量正常,上肺浸润性肺结核。目前最首选的治疗应是___
A. 左肾切除
B. 左肾部分切除
C. 左肾造瘘
D. 右肾造瘘
E. 抗结核治疗
【单选题】
下列关于颅中窝骨折患者的护理错误的是___
A. 禁止腰椎穿刺
B. 枕部垫无菌巾
C. 禁忌堵塞鼻腔
D. 床头抬高15~30cm
E. 用抗菌药溶液冲洗鼻腔
【单选题】
烧伤后休克期的最主要原因是___
A. 精神刺激
B. 创面剧烈疼痛
C. 大量水分蒸发
D. 大量组织坏死,分解产物吸收
E. 大量血浆自创面外渗和渗向组织间隙
【单选题】
膀胱癌早期最主要的症状是___
A. 疼痛
B. 尿频
C. 尿急
D. 尿痛
E. 血尿
【单选题】
反常呼吸常发生于___
A. 单根肋骨骨折
B. 多根肋骨单处骨折
C. 多根肋骨多处骨折
D. 单根肋骨单处骨折
E. 胸壁软组织损伤
【单选题】
软组织急性化脓性感染,在出现波动前需早期切开引流的是___
A. 转移性脓肿
B. 痈
C. 脓性指头炎侧面纵切开
D. 急性蜂窝织炎
E. 面部疖肿
【单选题】
膀胱全切除术后的饮食是___
A. 流食
B. 半流食
C. 无渣软食
D. 禁食
E. 以上都不对
【单选题】
预防创伤性坏疽发病最可靠的方法是___
A. 应用青霉素
B. 彻底清创
C. 应用甲硝唑
D. 应用抗毒素
E. 高压氧治疗
【单选题】
预防全麻患者发生误吸的主要措施是___
A. 术前禁食禁水
B. 术前放置胃管
C. 选择静脉麻醉
D. 术前用阿托品
E. 术前用止吐药
【单选题】
护理疑有腹腔内脏器损伤的患者,错误的是___
A. 尽量少搬动患者
B. 注射广谱抗生素
C. 安置半卧位
D. 禁食、输液
E. 注射镇痛剂
【单选题】
极低出生体重儿是指___
A. 出生1小时内体重不足1000g
B. 出生1小时内体重不足1250g
C. 出生1小时内体重不足1500g
D. 出生1小时内体重不足2000g
E. 出生1小时内体重不足2500g
【单选题】
异位妊娠时,受精卵最易着床的部位是___
A. 宫颈
B. 卵巢
C. 输卵管
D. 腹腔
E. 以上都不是
【单选题】
下述哪项属子宫附件___
A. 阴道口
B. 大阴唇
C. 小阴唇
D. 阴唇韧带
E. 输卵管
【单选题】
出生时导致脑性瘫痪常见的原因是___
A. 缺氧
B. 外伤
C. 核黄疸
D. 羊水栓塞
E. 胎儿期感染
【单选题】
在女方不孕因素中,最常见的病因是___
A. 子宫黏膜下肌瘤
B. 输卵管因素
C. 外阴、阴道炎症
D. 宫颈细长,宫颈炎
E. 子宫内膜异位症
【单选题】
上消化道出血病因诊断的首选检查措施为___
A. X线钡餐造影检查
B. 选择性动脉造影
C. 内镜检查
D. 化验检查
E. 吞线试验
【单选题】
属于脑血病患者智能损害早期的主要表现是___
A. 逆行性遗忘
B. 病理性赘述
C. 记忆错误
D. 近事遗忘
E. 远事遗忘
【单选题】
赵女士在妇科检查中发现宫颈重度糜烂,宫颈刮片细胞学检查为巴氏Ⅲ级,提示为___
A. 正常
B. 炎症
C. 可疑癌
D. 高度可疑癌
E. 癌
【单选题】
发生急性左心衰竭时,病人应采取的体位是___
A. 平卧位
B. 头高脚低位
C. 头低脚高位
D. 侧卧位
E. 坐位,两腿下垂
【单选题】
下列不属于流行性出血热的传播途径的是___
A. 血液传播
B. 呼吸道传播
C. 接触传播
D. 母婴传播
E. 消化道传播
【单选题】
青年人最常见的恶性骨瘤是___
A. 骨软骨瘤
B. 骨肉瘤
C. 骨髓瘤
D. Ewing瘤
E. 骨巨细胞瘤
【单选题】
对于小儿体液特点的表述,正确的是___
A. 年龄愈小,体液占体重的百分比愈高
B. 年龄愈小,细胞内液量相对为多
C. 年龄愈小,每日水的交换量相对为少
D. 血清钠含量高于成人
E. 需水量同于成人
【单选题】
下列关于肺血管的描述错误的是___
A. 肺有双重血流供应,即肺循环和支气管循环
B. 肺循环是一个高压、高阻力循环系统
C. 各级支气管和肺的营养主要由支气管循环供应
D. 肺气体交换功能主要由肺循环执行
E. 肺动脉携带静脉血,肺静脉输送动脉血
【单选题】
急性白血病和慢性白血病的分类依据是___
A. 发病原因
B. 首发症状
C. 贫血程度的不同
D. 出血症状的不同
E. 白血病细胞的成熟程度
【单选题】
杜加试验阳性可见于___
A. 肩关节脱位
B. 肘关节脱位
C. Colles骨折
D. 肱骨髁上骨折
E. 锁骨骨折
【单选题】
导致产褥病率最主要的原因是___
A. 乳腺感染
B. 上呼吸道感染
C. 泌尿系统感染
D. 手术切口感染
E. 产褥感染
【单选题】
小儿先能抬头后能坐、之后能走是遵循了下列哪项发育顺序___
A. 由上到下的顺序
B. 由近到远的顺序
C. 由粗到细的顺序
D. 由低级到高级的顺序
E. 由简单到复杂的顺序
【单选题】
男性,19岁,1天前出现脐周疼痛,呈阵发性,约5小时后疼痛转移并固定于右下腹部,诊断为急性阑尾炎。该患者在发病开始时表现为脐周疼痛的机制为___
A. 阑尾尖端指向脐周或上腹部
B. 胃肠功能紊乱
C. 内脏神经反射
D. 体神经反射
E. 阑尾位置
【单选题】
小儿各系统中最迟发育的是___
A. 神经系统
B. 生殖系统
C. 脂肪组织
D. 淋巴系统
E. 肌肉组织
【单选题】
以下治疗会导致水中毒的是___
A. 补给钾盐过少
B. 补给钠盐过多
C. 补给电解质先后次序不当
D. 单纯输入5%的葡萄糖液过多
E. 补液中加入电解质浓度过高