【单选题】
How does PEAP protect the EAP exchange ?___
A. It encrypts the exchange using the server certificate
B. It encrypts the exchange using the client certificate
C. It validates the server-supplied certificate,and then encrypts the exchange using the client certificate
D. It validates the client-supplied certificate,and then encrypts the excha nge using the server certificate
查看试卷,进入试卷练习
微信扫一扫,开始刷题

答案
A
解析
暂无解析
相关试题
【单选题】
Which feature of the Cisco Email Security Appliance can mitigate the impact of snowshoe spam and sophisticated phishing attacks?___
A. contextual analysis
B. holistic understanding of threats
C. graymail management and filtering
D. signature-based IPS
【单选题】
Refer to the exhibit【nat (inside,outside)dunamic interface】 Which translation technique does this configuration result in?___
A. DynamIc PAT
B. Dynamic NAT
C. Twice NAT
D. Static NAT
【单选题】
While trouble shooting site-to-site VPN, you issued the show crypto isakmp sa command. What does the given output show?___
A. IKE Phase 1 main mode was created on 10.1.1.5, but it failed to negotiate with 10.10 10.2
B. IKE Phase 1 main mode has successfully negotiated between 10.1.1.5 and 10.10..
C. IKE Phase 1 aggressive mode was created on 10.1.1.5, but it failed to negotiate with
【单选题】
Refer to the exhibit All ports on switch 1 have a primary vLan of 300 Which devices can host 1 reach?___
A. host 2
B. server
C. host 4
D. other devices within VLAN303
【单选题】
Which option is the cloud-based security service from Cisco the provides URL filtering, web browsing content security, and roaming user protection?___
A. Cloud Web service
B. Cloud Advanced Malware Protection
C. Cloud We b Security
D. Cloud Web Protection
【单选题】
How can you detect a false negative on an IPS?___
A. View the alert on the ips
B. Review the ips log
C. Review the is console
D. Use a third- party system to perform penetration testing.
E. Use a third- party to audit the next generation firewall rules
【单选题】
If a switch port goes directly into a blocked state only when a superior BPDU is received, what mechanism must be in use?___
A. STP BPDU guard
B. Loop guard
C. EtherChannel guard
D. STP Root guard
【单选题】
what improvement does EAP-FASTv2 provide over EAP-FAST? ___
A. It allows multiple credentials to be passed in a single EAP exchange.
B. It supports more secure encryption protocols
C. It allows faster authentication by using fewer packets.
D. It addresses security vulnerabilities found in the original protocol
【单选题】
When users login to the Client less Ssl Vpn using https://209.165.201.2/test ,which group policy will be applied?___
A. test
B. clientless
C. sales
D. DfitGrp Policy
E. Default RAGroup
F. Default WEB VPN
G. roup
【单选题】
Which user authentication method is used when users login to the Clientless SSLVPN portal using https://209.165.201.2/test?___
A. AAA with LOCAL database
B. AAA with RADIUS server
C. Certificate
D. :Both Certificate and aaa with LoCAL database
E. Both Certificate and AAA with RADIUS server
【单选题】
What' s the technology that you can use to prevent non malicious program to runin the computer that is disconnected from the network?___
A. Firewall
B. Sofware Antivirus
C. Network IPS
D. Host IPS
【单选题】
Which statement about the communication between interfaces on the same security level is true?___
A. Interfaces on the same security level require additional configuration to permit interinterface communication
B. Configuring interfaces on the same security level can cause asymmetric routing
C. All traffic is allowed by default between interfaces on the same security level
D. You can configure only one interface on a n individual security level
【单选题】
Which product can be used to provide application layer protection for tcp port 25 traffic?___
A. ESA
B. CWS
C. WSA
D. ASA
【单选题】
which iPS mode is less secure than other options but allows optimal network through put ?___
A. inline mode
B. inline-bypass mode
C. transparent mode
D. Promiscuous mode
【单选题】
Which feature of the Cisco Email security Appliance can mitigate the impact of snowshoe spam and sophisticated phishing attack?___
A. reputation based filtering
B. signature based IPS
C. contextual analysis
D. graymail management and filtering
【单选题】
Which type of social-engineering attack uses normal tele phone service as the attack vector?___
A. smishing
B. dialing
C. phishing
D. vishing
【单选题】
Which quantifiable item should you consider when you organization adopts new technologies?___
A. exploits
B. vulnerability
C. threat
D. Risk
【单选题】
Referencing the ClA model, in which scenario is a hash- only function most appropriate ?___
A. securing data at rest
B. securing real-time traffic
C. securing data in files
D. securing wireless transmissions
【单选题】
Which ports must be open between a aaa server and a microsoft server to permit Active Directory authentications?___
A. 445 and 389
B. 888 and 3389
C. 636 and 4445
D. 363 and 983
【单选题】
Refer to the exhibit for which reason is the tunnel unable to pass traffic___
A. the tunnel is failing to receive traffic from the remote peer
B. the local peer is unable to encrypt the traffic
C. the ip address of the remote peer is incorrect
D. UDP port 500 is blocked
【单选题】
Which type of attack can exploit design flaws in the implementation of an application without___
A. DHCP starvation attacks
B. low-rate dos attacks
C. application DDos flood attacks
D. application DDoS flood attacks
E. volume-based DDoS attacks
【单选题】
How can you protect CDP from reconnaissance attacks?___
A. Enable dynamic ARP inspection on all untrusted ports.
B. Enable dot1x on all ports that are connected to other switches.
C.
D. isable CDP on ports connected to endpoints.
【单选题】
Which type of attack can exploit design flaws in the implementation of an application without ?___
A. DHCP starvation attacks
B. low-rate dos attacks
C. application DDos flood attacks
D. application DDoS flood attacks
E. volume-based DDoS attacks
【单选题】
Which option is a key security compone nt of and MDM deployment ?___
A. using network-specific installer packages
B. using an application tunnel by default
C. using self-signed certificates to validate the server
D. using MS-CHAPv2 as the primary
E. AP method
【单选题】
Which Firepower Management Center feature detects and block exploits and hack attempts?___
A. Content blocker
B. file control
C. intrusion prevention
D. advanced malware protection
【单选题】
hich description of the nonsecret numbers that are used to start a Diffie- Hellman exchange is ture?___
A. They are preconfigured prime integers.
B. They are large pseudorandom numbers.
C. They are very small numbers chosen from a table of known valuses
D. They are numeric values extracted from ha shed system hostnames
【多选题】
Which two characteristics of an application layer firewall are true?___
A. provides stateful firewal functionality
B. has low processor usage
C. provides protection for multiple applications
D. provides rever se proxy services
E. is immune to URL manipulation
【多选题】
Which two devices are components of the BYOD architectural framework?___
A. Nexus 7010 switch
B. Cisco 3945 Router
C. Identify Services Engine
D. Wireless Access oints
E. Prime Infrastructure
【多选题】
Which two actions can a zone based firewall take when looking at traffic? ___
A. forward
B. inspect
C. drop
D. broadcast
E. filter
【多选题】
n which two situations should you use in-band management?___
A. when management applications need concurrent access to the device
B. when you require administrator access from multiple locations
C. when a network device fails to forward packets
D. when you require ROMMON access
E. when the control plane fails to respond
【多选题】
What are two ways to prevent eavesdropping when you perform device management tasks?___
A. Use an SSH connection.
B. Use SNMPv3
C. Use out-of-band management
D. Use SNMP
E. Use in-band management
【多选题】
Which two features are commonly used CoPP and CPPr to protect the control plane? ___
A. QoS
B. traffic classification
C. access lists
D. policy maps
E. class maps
F. Cisco Express Forwarding
【多选题】
Which four tunne ling prot ocols are enabled in the Dfit GrpPolicy group policy ?___
A. Clientless SSL VPN
B. SSL VPN Client
C. PPTP
D. L2TP/IPsec
E. IPsec IKEv1
F. IPsec IKEv2
【多选题】
Which two statements regarding the aSA VPN configurations are correct?___
A. The asa has a certificate issued by an external certificate authority associated to the ASDM TrustPoint1
B. The Default WEBVPNGroup Connection Profile is using the aaa with RADIUS server method
C. The Inside-srvbook mark references the https://192.168.1.2url
D. Only Clientless SSL VPN access is allowed with the Sales group policy
E. Any Connect, IPSec IKEv1, and IPSec IKEv2 VPN access is enabled on the outside interface
F. The Inside -SRV bookmark has not been applied to the Sales group policy
【多选题】
Which three ESP fields can be encrypted during transmission?___
A. Security Parameter Index
B. Sequence Number
C. MAC Address
D. Padding
E. Pad length
F. Next Header
【多选题】
.Which three statements de scribe DHCP spoofing attacks?___
A. They can modify traffic in transit.
B. They are used to perform man- in-the-middle attacks
C. They use ARP poisoning
D. They can access most network devices
E. They protect the ide ntity of the attacker by masking the DHCP address.
F. They are can physically modify the network gateway.
【多选题】
Which statement about the communication between interfaces on the same security level is true?___
A. Interfaces on the same security level require additional configuration to permit interinterface communication
B. Configuring interfaces on the same security level can cause asymmetric routing
C. All traffic is allowed by default between interfaces on the same security level
D. You can configure only one interface on a n individual security level
【多选题】
In which two situations should you use in band management? ___
A. when the control plane fails to respond
B. when you require administrator access from multiple locations
C. when you require ROMMON access.
D. where a network device fails to forward packets
E. when multiple ma nagement applications need concument access to the device.
【多选题】
Which two features are supported in a VRF-aware softwar infrastructure before VRF-lite?___
A. multicast
B. fair queuing
C. WCCP
D.
E. IGRP
推荐试题
【多选题】
根据《关于进一步深化整治银行业市场乱象的通知》(银监发〔2018〕4 号)的规定,下列选项中属于向关系人员输送利益的是( )。___
A. 直接或变相向关系人发放信用贷款,或员工以优于其他同类客户条件获取本行贷款
B. 以低于同等条件,招收或调入客户的亲属或子女
C. 公款存放主体相关负责人员的配偶、子女及其配偶和其他直接利益相关人员为银行业金融机构员工的,未按规定实行回避
D. 对大客户、大企业、大机构相关负责人进行变相商业贿赂等。
【多选题】
为加强对普惠金融重点领域的支持,根据《关于 2018 年推动银行业小微企业金融服务高质量发展的通知》(银监办发〔2018〕29 号)的规定,对单户授信总额 1000 万元以下(含)的小微企业贷款考核努力实现“两增两控”目标,“两增两控”具体是指:___
A. 小微企业贷款同比增速不低于各项贷款同比增速
B. 小微企业有贷款余额的户数不低于上年同期水平
C. 合理控制小微企业贷款资产质量水平
D. 合理控制小微企业贷款综合成本水平
E. 合理控制小微企业贷款综合管理水平
【多选题】
流动性风险管理体系应当包括以下基本要素()。___
A. 有效的流动性风险管理治理结构
B. 完善的流动性风险管理策略、政策和程序
C. 有效的流动性风险识别、计量、监测和控制
D. 完备的管理信息系统
【多选题】
《关于完善商业银行存款偏离度管理有关事项的通知》银保监办发〔2018〕48 号规定,商业银行应进一步规范吸收存款行为,不得采取以下手段违规吸收和虚假增加存款()。___
A. 违规通过返还现金或有价证券、赠送实物等不正当手段吸收存款。
B. 通过个人或机构等第三方资金中介吸收存款。
C. 通过设定不合理的取款用款限制、关闭网上银行、压票退票等方式拖延、拒绝支付存款本金和利息。
D. 严禁以强制设定条款或协商约定将贷款资金转为存款;以存款作为审批和发放贷款的前提条件;向“空户”虚假放贷、虚假增存。
E. 严禁将贷款资金作为保证金循环开立银行承兑汇票并贴现,虚增存贷款。
【多选题】
以下关于征信监管系统申请用户说法正确的有()。___
A. 申请用户负责系统参数配置、升级维护、批处理操作、网络安全、应急恢复及软硬件技术支持等
B. 申请用户负责收集、查验并上传客户证件信息
C. 申请用户负责审核查询用户提交的资料信息
D. 申请用户负责查询授权书、查看及打印信用报告
E. 申请用户、查询用户均由县级管理员设立
【多选题】
下面关于征信监管系统说法正确的有()。___
A. 系统管理用户及业务管理用户可随时增加或删除用户权限
B. 征信监管系统用户均不能删除,只能对用户进行停用或启用的操作
C. 系统管理用户设在省联社信息科技部,业务管理用户设在征信监管系统业务管理部门,申请用户及查询用户由县级管理员设立
D. 业务管理用户按省、市、县三级设置,并确保与中国人民银行个人和企业征信系统用户管理员保持一致
E. 查询用户应与中国人民银行个人和企业征信系统普通用户保持一致
【多选题】
根据《河南省农村信用社联合社关于进一步严管理贷款的意见》要求,有下列( )情形之一的,对直接责任人一律开除,涉嫌犯罪的,移交司法机关处理。___
A. 与客户串通,使用虚假资料骗取贷款的
B. 发放假冒名贷款的
C. 以贷谋私,索取、收受客户财物的
D. 侵占、截留、挪用客户信贷资金的
E. 在贷款调查、审查、审批等操作环节中未严格履职,存在明显漏洞和严重问题,导致贷款发放扣形成损失的
F. 返反有关管理规定,逆程序、超权限发放贷款的
【多选题】
根据《河南省农村信用社员工违规行为处理办法》规定,办理贷款业务中,有下列( )行为之一的,给予有关责任人员记过至撤职处分;后果或情节严重的,给予开除处分。___
A. 未经审批擅自降低利率以及采用其他正当手段发贷款的
B. 操纵、篡改评审结果或与客户串通,导致存在重大问题的项目得以审批通过的
C. 授意、指使、强令信贷人员违规发放贷款的
D. 未回避关系人贷款审批流程的
E. 向关系人发放信用贷款的
【判断题】
牢固树立政治意识、大局意识、核心意识、看齐意识,坚定维护以习近平同志为核心的党中央权威和集中统一领导,保证全党的团结统一和行动一致,保证党的决定得到迅速有效的贯彻执行
A. 对
B. 错
【判断题】
2018年全国农村中小金融机构监管工作会议,将2017年农村中小金融机构的发展特点总结为“三稳两进两回归”,其中“两回归”是指经营发展向主业回归和资产质量向真实回归
A. 对
B. 错
【判断题】
“三稳三进”指的是确保薄弱领域金融支持业务总量稳定、普惠领域政策框架和基调稳定、普惠金融体制机制稳定、在优化结构上求进、在监管考核上求进、在提高质量上求进
A. 对
B. 错