【单选题】
which technology cloud be used on top of an MPLS VPN to add confidentiality ?___
A. IPsec
B. 3DES
C. AES
D. SSL
查看试卷,进入试卷练习
微信扫一扫,开始刷题
相关试题
【单选题】
Which term is most closely aligned with the basic purpose of a SIEM solution? ___
A. Non-Repudiation
B. Accountability
C. Causality
D. Repudiation
【单选题】
You have just deployed SNMPv3 in your environment, Your manager asks you to make sure that our SNMP agents can only talk to the SNMP Manager. What would you configure on your SNMI agents to satisfy this request?___
A. A SNMP View containing the SNMP managers
B. Routing Filter with the SNMP managers in it applied outbound
C. A standard ACL containing the SNMP managers applied to the SNMP configuration
D. A SNMP Group containing the SNMP managers
【单选题】
Which feature prevents loops by moving a nontrunking port into an errdisable state when a BPDU is received on that port?___
A. BPDU filte
B. DHCP snooping
C. BPDU guard
D. Port Fast
【单选题】
Which command enables port security to use sticky MAC addresses on a switch?___
A. switchport port-security violation restrict
B. switchport port-security mac-address sticky
C. switchport port-security violation protect
D. switchport port-security
【单选题】
When you edit an IPS subsignature, what is the effect on the parent signature and the family of subsignatures?___
A. The change applies to the parent signature and the entire family of subsignatures
B. The change applies to the parent signature and the subsignature that you edit
C. The change applies only to subsignatures that are numbered sequentially after the subsignature that you edit
D. Other signatures are unaffected, the change applies only to the subsignature that you dit
【单选题】
Which type of mechanism does Cisco FirePOWER de ploy to protect ag detected moving across other networks?___
A. antivirus scanning
B. policy-based
C. reputation-based
D. signature-based
【单选题】
What action must you take on the ise to blacklist a wired device?___
A. Locate the switch through which the device is connected and push an a cl restricting all access by the device
B. Issue a CoA request for the de vice's mac address to each access switch in the network
C. Revoke the device's certificate so it is unable to authenticate to the network
D. Add the device's MAc address to a list of black listed devices
【单选题】
Which type of firewall can perform deep packet inspection?___
A. packet-filtering firewall
B. stateless firewall
C. application firewall
D. personal firewall
【单选题】
What is the main purpose of Control Plane Policing?___
A. to prevent exhaustion of route-proce ssor resources
B. to organize the egress packet queues
C. to define traffic classes
D. to maintain the policy map
【单选题】
Which attack can be prevented by OSPF authentication?___
A. smurf attack
B. IP spoofing attack
C. denial of service attack
D. buffer overflow attack
【单选题】
What is the best definition of hairpinning?___
A. ingress traffic that traverses the outbound interface on a device
B. traffic that enters one interface on a device and that exits through another interface
C. traffic that enters and exits a device through the same interface
D. traffic that tunnels through a device interface
【单选题】
Which SNMPv3 security level provides authentication using HMAC with MD5, but does not use encryption?___
A. authPriv
B. authNo Priv
C. noAuthNoPriv
D. NoauthPriv
【单选题】
You have implemented a dynamic blacklist, using security intelligence to block illicit network activity. However, the blacklist contains several approved connections that users must access for usiness pur poses. Which action can you take to retain the blacklist while allowing users to access the approve d sites?___
A. Create a whitelist and manually add the approved addresses.
B. Disable the dynamic blacklist and deny the specif ic address on a whitelist while permitting the others
C. Edit the dynamic blacklist to remove the approved addresses
D. Disable the dynamic blacklist and create a static blacklist in its place
【单选题】
When connecting to an external resource,you must change a source IP address to use one IP address from a range of 207.165.201.1 to 207.165.1.30. Which option do you implement ?___
A. dynamic source NAT that uses an IP ad dress as a mapped source
B. static destination NAT that uses a subnet as a real de stination
C. dynamic source NAT that uses a range as a mapped source
D. static destination NAT that uses a subnet as a real source
【单选题】
Refer to the exhibit. 【nat(ins,any)dynamic interface】Which ty pe of NaT is configured on a Cisco ASA?___
A. dynamic NAT
B. source identity NAT
C. dynamic PAT
D. identity twice NAT
【单选题】
Which mitigation technology for web-based threats prevents the removal of confidential data from the network?___
A. CTA
B. DCA
C. AMP
D. DLP
【单选题】
Refer to the exhibit. What is the effect of the given configuration?___
A. It establishes the preshared key for the switch
B. It establishes the preshared key for the firewall.
C. It establishes the preshared key for the Cisco ISE appliance
D. It establishes the preshared key for the router.
【多选题】
What are two major considerations when choosing between a SPAN and a TAP when plementing IPS?___
A. the type of analysis the iS will perform
B. the amount of bandwidth available
C. whether RX and TX signals will use separate ports
D. the way in which media errors will be handled
E. the way in which dropped packets will be handled
【多选题】
What are two direct-to-tower methods for redirecting web traffic to Cisco Cloud Web Security?___
A. third-party proxies
B. Cisco Catalyst platforms
C. Cisco NAC Agent
D. hosted PAC files
E. CiSco ISE
【多选题】
Which three descriptions of RADIUS are true? ___
A. It uses TCP as its transport protocol.
B. Only the password is encrypted
C. It supports multiple transport protocols
D. It uses UDP as its transport protocol
E. It combines authentication and authorization
F. It separates authentication,authorization,and accounting
【多选题】
Which two configurations can prevent VLAN hopping attack from attackers at VLAN 10?___
A. using switchport trunk native vlan 10 command on trunk ports
B. enabling BPDU guard on all access ports
C. creating VLAN 99 and using switchport trunk native vlan 99 command on trunk ports
D. applying ACl between VLAN
E. using switchport mode access command on all host ports
F. using switchport nonegotiate command on dynamic desirable ports
【多选题】
What are two features of transparent firewall mode ___
A. It conceals the presence of the firewall from attackers
B. It allows some traffic that is blocked in routed mode
C. It enables the aSA to perform as a router.
D. It acts as a routed hop in the network.
E. It is configured by default
【多选题】
Which two models of A sa tend to be used in a data center?___
A. 5555X
B. 5585X
C. ASA service module
D. 5512X
E. 5540
F. 5520
【多选题】
Which two statements about hardware-based encrption are true?___
A. It is widely accessible
B. It is potentially easier to compromise than software-based encryption. It requires minimal configuration
C. It requires minimal configuration
D. It can be implemented without impacting performance
E. It is highly cost-effective
【多选题】
In which two modes can the Cisco We b Security appliance be de ployed?___
A. as a transparent proxy using the Secure Sockets Layer protocol
B. as a transparent proxy using the Web Cache Communication Protocol
C. explicit proxy mode
D. as a transparent proxy using the Hyper Text Transfer Protocol
E. explicit active mode
【单选题】
1.三相刀开关的图形符号与交流接触器的主触点符号是___。
A. 一样的
B. 可以互换
C. 有区别的
D. 没有区别
【单选题】
5.熔断器的作用是___。
A. 短路保护
B. 过载保护
C. 失压保护
D. 零压保护
【单选题】
6.热继电器的作用是___。
A. 短路保护
B. 过载保护
C. 失压保护
D. 零压保护
【单选题】
7.交流接触器的作用是可以___接通和断开负载。
【单选题】
8.三相异步电动机的启停控制线路由电源开关、熔断器、___、热继电器、按钮等组成。
A. 时间继电器
B. 速度继电器
C. 交流接触器
D. 漏电保护器
【单选题】
9.三相异步电动机的启停控制线路中需要有___、过载保护和失压保护功能。
A. 短路保护
B. 超速保护
C. 失磁保护
D. 零速保护
【单选题】
10维修电工以___、安装接线图和平面布置图最为重要。
A. 电气原理图
B. 电气设备图
C. 电气安装图
D. 电气组装图
【单选题】
11.熔断器的额定电压应___线路的工作电压。
A. 远大于
B. 不等于
C. 小于等于
D. 大于等于
【单选题】
12.对于电阻性负载,熔断器熔体的额定电流___线路的工作电流。
A. 远大于
B. 不等于
C. 等于或略大于
D. 等于或略小于
【单选题】
13.对于电动机负载,熔断器熔体的额定电流应选电动机额定电流的___倍。
A. 1~1.5
B. 1.5-2.5
C. 2.0~3.0
D. 2.5~3.5
【单选题】
14.使用快速熔断器时,一般按___来选择。
A. IN=1.03IF
B. IN=1.57IF
C. IN=2.57IF
D. IN=3IF
【单选题】
15.断路器中过电流脱扣器的额定电流应该大于等于线路的___。
A. 最大允许电流
B. 最大过载电流
C. 最大负载电流
D. 最大短路电流
推荐试题
【判断题】
诚实守信不仅是人们私人交往中必须遵守的一条社会公共生活道德准则,也是职业道德的一条重要规范
【判断题】
“爱护货物、尊重货主”不是检车员的职业道德规范
【判断题】
“顾全大局,联劳协作”是车辆钳工的职业道德规范
【判断题】
良好的职业道德的养成,只有靠“他律”,即来自社会的培养和组织的灌输教育
【判断题】
职业道德修养是一个长期、曲折、渐进的过程
【判断题】
职业道德修养对个人的进步和成长没有帮助
【判断题】
职业理想,是个人对职业的向往和追求,具有强烈的可能性
【判断题】
一个人的职业道德水平不体现在对本职工作的态度上
【判断题】
职业技能是做好本职工作的手段,是胜任本职工作的重要条件
【判断题】
本职工作的实践是表现职工职业道德的重要领域,也是锻炼职工职业道德品质的主要场所
【判断题】
职业道德不是企业形象的一个重要组成部分
【判断题】
任何一种社会舆论,都是在一定道德观念的长期熏陶和支配下形成的
【判断题】
客车电器装置中的发电机、蓄电池、轴温报警器等中(段)修周期应与客车段修周期基本一致,可提前或延期六个月(装在不常用车上的可根据状态再延期)
【判断题】
KP-2A型控制箱三相交流输出线电压为46伏,直流输出电压为59土1伏
【判断题】
J5型电机的额定转速为700-3500转/分
【判断题】
背向二位车端面向一位车端的右手侧为一位侧,左手侧为二位侧
【判断题】
一般情况下,室内充电的蓄电池或运用中充电的蓄电池,遇到明火都有可能发生爆炸
【判断题】
客车电器装置的修程分大修,中修和辅修三种
【判断题】
变压器是一种将某一等级的交流电压变换成另一等级电压的装置
【判断题】
运用客车入库后,都必须按规定进行车体绝缘测试
【判断题】
使用钳流表测量电流时,如被测电流无法估计时,应把钳流表的量程置于最大挡位
【判断题】
耐压300V的电容器能在有效值220V的交流电压下安全工作
【判断题】
在不断开导线的情况下测量电流的大小,应使用钳形电流表
【判断题】
用万用表欧姆挡测二极管极性时,应记住其“+”插孔是接自附电池的负极,而“-”插孔是接自正极
【判断题】
焊接电子电路时,为防止虚焊现象出现,应使用300W的电烙铁
【判断题】
蒸发器是制冷系统中产生和输入冷量的设备
【判断题】
热继电器的整定电流若只稍大于电动机的额定电流,则电动机不能正常起动
【判断题】
热继电器的保护动作在过载后必须经过一定时间才能执行
【判断题】
电路中所需的各种直流电压,可以通过变压器变换获得
【判断题】
免维护密封铅酸电池存放后开路电压每节在12V以下,必须及时恢复充电,充足后方可使用
【判断题】
客车配线对导线绝缘层材料的要求是不仅其电气绝缘及热传导性能良好,而且还应具有耐酸、碱、油性和不延燃性
【判断题】
KP-2A型控制箱中设有限流充电环节,以限制发电机对蓄电池组充电的电流
【判断题】
98型应急电源整流器输入电源电压为220V、50Hz
【判断题】
电动机起动时发出嗡嗡声,是由于电动机缺相运转以致电流过大而引起的
【判断题】
客车空调装置中电动机回路接有熔断器,主要用来作过载保护