【单选题】
Which statement about the communication between interfaces on the same security level is true?___
A. Interfaces on the same security level require additional configuration to permit interinterface communication
B. Configuring interfaces on the same security level can cause asymmetric routing
C. All traffic is allowed by default between interfaces on the same security level
D. You can configure only one interface on a n individual security level
查看试卷,进入试卷练习
微信扫一扫,开始刷题
答案
A
解析
暂无解析
相关试题
【单选题】
Which product can be used to provide application layer protection for tcp port 25 traffic?___
A. ESA
B. CWS
C. WSA
D. ASA
【单选题】
which iPS mode is less secure than other options but allows optimal network through put ?___
A. inline mode
B. inline-bypass mode
C. transparent mode
D. Promiscuous mode
【单选题】
Which feature of the Cisco Email security Appliance can mitigate the impact of snowshoe spam and sophisticated phishing attack?___
A. reputation based filtering
B. signature based IPS
C. contextual analysis
D. graymail management and filtering
【单选题】
Which type of social-engineering attack uses normal tele phone service as the attack vector?___
A. smishing
B. dialing
C. phishing
D. vishing
【单选题】
Which quantifiable item should you consider when you organization adopts new technologies?___
A. exploits
B. vulnerability
C. threat
D. Risk
【单选题】
Referencing the ClA model, in which scenario is a hash- only function most appropriate ?___
A. securing data at rest
B. securing real-time traffic
C. securing data in files
D. securing wireless transmissions
【单选题】
Which ports must be open between a aaa server and a microsoft server to permit Active Directory authentications?___
A. 445 and 389
B. 888 and 3389
C. 636 and 4445
D. 363 and 983
【单选题】
Refer to the exhibit for which reason is the tunnel unable to pass traffic___
A. the tunnel is failing to receive traffic from the remote peer
B. the local peer is unable to encrypt the traffic
C. the ip address of the remote peer is incorrect
D. UDP port 500 is blocked
【单选题】
Which type of attack can exploit design flaws in the implementation of an application without___
A. DHCP starvation attacks
B. low-rate dos attacks
C. application DDos flood attacks
D. application DDoS flood attacks
E. volume-based DDoS attacks
【单选题】
How can you protect CDP from reconnaissance attacks?___
A. Enable dynamic ARP inspection on all untrusted ports.
B. Enable dot1x on all ports that are connected to other switches.
C.
D. isable CDP on ports connected to endpoints.
【单选题】
Which type of attack can exploit design flaws in the implementation of an application without ?___
A. DHCP starvation attacks
B. low-rate dos attacks
C. application DDos flood attacks
D. application DDoS flood attacks
E. volume-based DDoS attacks
【单选题】
Which option is a key security compone nt of and MDM deployment ?___
A. using network-specific installer packages
B. using an application tunnel by default
C. using self-signed certificates to validate the server
D. using MS-CHAPv2 as the primary
E. AP method
【单选题】
Which Firepower Management Center feature detects and block exploits and hack attempts?___
A. Content blocker
B. file control
C. intrusion prevention
D. advanced malware protection
【单选题】
hich description of the nonsecret numbers that are used to start a Diffie- Hellman exchange is ture?___
A. They are preconfigured prime integers.
B. They are large pseudorandom numbers.
C. They are very small numbers chosen from a table of known valuses
D. They are numeric values extracted from ha shed system hostnames
【多选题】
Which two characteristics of an application layer firewall are true?___
A. provides stateful firewal functionality
B. has low processor usage
C. provides protection for multiple applications
D. provides rever se proxy services
E. is immune to URL manipulation
【多选题】
Which two devices are components of the BYOD architectural framework?___
A. Nexus 7010 switch
B. Cisco 3945 Router
C. Identify Services Engine
D. Wireless Access oints
E. Prime Infrastructure
【多选题】
Which two actions can a zone based firewall take when looking at traffic? ___
A. forward
B. inspect
C. drop
D. broadcast
E. filter
【多选题】
n which two situations should you use in-band management?___
A. when management applications need concurrent access to the device
B. when you require administrator access from multiple locations
C. when a network device fails to forward packets
D. when you require ROMMON access
E. when the control plane fails to respond
【多选题】
What are two ways to prevent eavesdropping when you perform device management tasks?___
A. Use an SSH connection.
B. Use SNMPv3
C. Use out-of-band management
D. Use SNMP
E. Use in-band management
【多选题】
Which two features are commonly used CoPP and CPPr to protect the control plane? ___
A. QoS
B. traffic classification
C. access lists
D. policy maps
E. class maps
F. Cisco Express Forwarding
【多选题】
Which four tunne ling prot ocols are enabled in the Dfit GrpPolicy group policy ?___
A. Clientless SSL VPN
B. SSL VPN Client
C. PPTP
D. L2TP/IPsec
E. IPsec IKEv1
F. IPsec IKEv2
【多选题】
Which two statements regarding the aSA VPN configurations are correct?___
A. The asa has a certificate issued by an external certificate authority associated to the ASDM TrustPoint1
B. The Default WEBVPNGroup Connection Profile is using the aaa with RADIUS server method
C. The Inside-srvbook mark references the https://192.168.1.2url
D. Only Clientless SSL VPN access is allowed with the Sales group policy
E. Any Connect, IPSec IKEv1, and IPSec IKEv2 VPN access is enabled on the outside interface
F. The Inside -SRV bookmark has not been applied to the Sales group policy
【多选题】
Which three ESP fields can be encrypted during transmission?___
A. Security Parameter Index
B. Sequence Number
C. MAC Address
D. Padding
E. Pad length
F. Next Header
【多选题】
.Which three statements de scribe DHCP spoofing attacks?___
A. They can modify traffic in transit.
B. They are used to perform man- in-the-middle attacks
C. They use ARP poisoning
D. They can access most network devices
E. They protect the ide ntity of the attacker by masking the DHCP address.
F. They are can physically modify the network gateway.
【多选题】
Which statement about the communication between interfaces on the same security level is true?___
A. Interfaces on the same security level require additional configuration to permit interinterface communication
B. Configuring interfaces on the same security level can cause asymmetric routing
C. All traffic is allowed by default between interfaces on the same security level
D. You can configure only one interface on a n individual security level
【多选题】
In which two situations should you use in band management? ___
A. when the control plane fails to respond
B. when you require administrator access from multiple locations
C. when you require ROMMON access.
D. where a network device fails to forward packets
E. when multiple ma nagement applications need concument access to the device.
【多选题】
Which two features are supported in a VRF-aware softwar infrastructure before VRF-lite?___
A. multicast
B. fair queuing
C. WCCP
D.
E. IGRP
【多选题】
.Which loS command do you enter to test authentication again a AAA server?___
A. dialer aaa suffix <suffix> password <password>
B. ppp authentication chap pap test
C. test aaa-server authentication dialer group user name <user> password <password>
D. aaa authentication enable default test group tacases
【多选题】
Which two statements about the self zone on a cisco Xone based policy firewall are true?___
A. Multiple interfaces can be assigned to the self zone
B. it supports stateful inspections for multicast traffic
C. zone pairs that include the self zone apply to traffic transiting the device.
D. it can be either the source zone or the destination zone
E. traffic entering the self zone must match a rule
【多选题】
Which type of attack can exploit design flaws in the implementation of an application without ?___
A. DHCP starvation attacks
B. low-rate dos attacks
C. application DDos flood attacks
D. application DDoS flood attacks
E. volume-based DDoS attacks
【单选题】
Which type of firewall can server as the interme diary between a client and a server ?___
A. Stateless firewall
B. application firewall
C. proxy firewall
D. personal firewall
【单选题】
What is the highest security level that can be configured for an interface on an ASA?___
A. 0
B. 50
C. 10
D. 200
【单选题】
Which term refers to the electromagnetic interference that can radiate from network cables?___
A. Gaussian distributions
B. Doppler waves
C. emanations
D. multimode distortion
【单选题】
How does a zone pair handle traffic if the policy de fination of the zone pair is missing?___
A. It inspects all traffic.
B. It drops all traffic.
C. It permits all traffic wihtout logging
D. It permits and logs all traffic
【单选题】
default how does a zone based firewall handle traffic to add from the self zone?___
A. It permits all traffic without inspection
B. It inspects all traffic to determine how it is handled
C. It permits all traffic after inspection
D. It frops all traffic
【单选题】
Which command should beused to ena ble AAA Authentication to determine if a user can access the privilege command level?___
A. aaa authentication enable local
B. aaa authentication enable level=
C. aaa authentication enable method de fault
D. aaa authentication enable defa ult local
【单选题】
On an ASA, the policy indicates that traffic should not be translated is often referred to as which of the following?___
A. NAT zero
B. NAT forward
C. NAT nul
D. NAT allow
【单选题】
Which protocol offers data Integrity encryption, authentication, and anti-replay functions for IPSec VPN?___
A. ESP protocol
B. IKEv3 Protocol
C. AH protoco
D. IKEv1 Protocol
【单选题】
Which component offers a variety of security Solution, including firwall, IF Antivirus and antiphishing features?___
A. Cisco loS router
B. Cisco ASA 5500 Ser ies security appliance
C. Cisco ASA 5500 X series Next Gen Security appliance
D. Cisco 4200 series IPS appliance
【单选题】
Refer to the exhibit, A Network Secur ity administrator check the ASa firewall NAT policy table rith show nat command, which statement is fails?___
A. There are only reverse translation matches for the REAL SERvER object
B. First policy in the Section 1 is a dynamic nat entry defined in the object configuration
C. NAT policy in section 2 is static entry de fined in the object configuration
D. Translation in Section 3 used when a connection does not matches any entries in first two sections
推荐试题
【单选题】
戴手套能代替手卫生。___
A. 对
B. 错
【多选题】
新型冠状病毒易感染人群有哪些?___
A. 老人
B. 儿童
C. 孕产妇
D. 免疫功能较差人群
【多选题】
穿防护服的步骤有哪些?___
A. 打开防护服,检查是否破损、拉链是否完好,将拉链拉至下方。
B. 握住防护服联体帽、衣袖的同时,抓住防护服腰部拉链开口处,避免与地面接触。
C. 脱鞋后由下至上穿防护服,并用联体帽包住头部。
D. 穿好后,将拉链拉至最上方,再由上至下密封拉链扣,保证防护服的密闭性。
【多选题】
以下属于保电人员进入疫区开展工作,个人防护用品的有___
A. N95 口罩
B. 一次性帽子
C. 防护服
D. 安全帽
【多选题】
使用什么消毒剂对新型冠状病毒有效?___
A. 75%的酒精
B. 碘伏
C. 含氯消毒剂
D. 过氧乙酸和氯仿等脂溶剂
【多选题】
日常生活中哪些时刻需要洗手?___
A. 外出回家时
B. 接触公共物品后
C. 饭前饭后
D. 打电话前后
【多选题】
传染病能够传播和流行,必须具备的三个基本环节是什么?___
A. 传播源
B. 传播途径
C. 病原体
D. 易感人群
【多选题】
传染病的水平传播范畴有那些?___
A. 呼吸道传播
B. 消化道传播
C. 接触传播
D. 血液体液传播
【多选题】
传染病的垂直传播范畴包含哪些?___
A. 传播源
B. 母婴传播
C. 病原体
D. 父婴传播
【多选题】
病原体离开“源头”,通过空气作为媒介来感染新的易感个体,它是呼吸道传染病主要的传播方式,包括那些?___
A. 飞沫传播
B. 飞沫核传播
C. 尘埃传播
D. 接触传播
【多选题】
什么是呼吸道飞沫传播?___
A. 远程打招呼
B. 日常谈话
C. 咳嗽
D. 打喷嚏
【多选题】
人成为冠状病毒的“超级传播者“”的因素有哪些?___
A. 机体免疫状态:对于一些免疫力低下的人群,如合并其他基础疾病的患者尤其是老年人,病毒在体内的复制能力较强,在咳嗽和打喷嚏时释放的病原体则更多,而有些感染者体质较好,免疫系统对于“高度耐受“,自身没有特殊症状,日常照旧,
B. 行为特点:我们处在交通便捷的时代,很多时候,喜欢旅游出行的患者还没有出现不适,病原体就搭载着飞机高铁到处跑了
C. 环境因素:相对封闭和人口密集的场所容易出现“超级传播者“
D. 医务人员因工作原因接触大量易感人员
【多选题】
新型冠状病毒感染一般多久会发病?___
A. 1-2天
B. 3-7天
C. 8-14天
D. 15天以上
【多选题】
可能处于潜伏期内的人员需要做好那些方面?___
A. 做好自我隔离,避免与人密切接触
B. 戴好口罩,严格遵守咳嗽礼仪,在咳嗽时用纸巾掩饰口鼻并迅速将纸巾仍至垃圾通内
C. 避免用手去触摸自己的口鼻眼及公共物品
D. 不要外出去人口较多的公共场合
【多选题】
新型冠状病毒在空气、衣物、水体等环境中能存活多久?___
A. 一般来说在空气中是无法存活的
B. 衣服上存活几分钟到几小时
C. 土壤、滤纸片、棉布片上存活4-6小时,不锈钢、光滑玻璃片、塑料片存活至少2天
D. 污染的自来水中2天后仍能保持较强的感染性
【多选题】
去过疫情高发区或接触过疫区人员的人群如何做好防护?___
A. 直接隔离
B. 尽快电话练习所在社区或村委会登记,积极配合问询和随访
C. 不与他人密切接触,包括家人
D. 不要随意走动,勿乘坐交通工具
【多选题】
普通人群如何做好个人防护?___
A. 少出行,不聚会
B. 戴口罩
C. 多洗手
D. 少熬夜
【多选题】
返岗上班人群如何做好防护?___
A. 确认自己1周内没有和患病人员接触
B. 全程佩戴好口罩,电梯、办公室、会议室餐厅(最后吃饭时刻取下)等高危场所都需戴口罩
C. 办公室通风,做好平面消毒工作
D. 勤洗手
【多选题】
新型冠状病毒感染的治疗原则是什么?___
A. 卧床休息
B. 吃抗生素
C. 抗病毒治疗
D. 抗菌药物治疗
【多选题】
哪些人在感染新型冠状病毒后容易出现危重症?___
A. 老年人群
B. 本身已有基础疾病的患者
C. 孕妇
D. 儿童
【多选题】
防护口罩应选用哪一种?___
A. 医用外科口罩
B. 普通棉纱口罩
C. 保暖/装饰口罩
D. 医用防护口罩(N95.FFP2及以上)
【多选题】
新型冠状病毒感染后会出现那些表现___
A. 发热、咳嗽、乏力、不同程度的呼吸困难等临床症状
B. 头疼、轻度肌肉酸痛、流涕、咽痛等感冒样症状
C. 紧张性呼吸困难、淤毒性休克、多器官功能衰竭
D. 毫无症状
【多选题】
出现那些症状时需要及时就医___
A. 没有相关流行病史,也未接触来自疫情高发地的,出现轻微发热症状
B. 有明确相关流行病史或接触过患者或疑似患者
C. 出现小范围聚集性发病(如家中几个人同时发病)
D. 孕妇、老年人或有心、肺、肾等基础疾病的发热病人·
【多选题】
关于“新型冠状病毒感染的肺炎”的临床表现,下述说法正确的是 ___
A. 发热,乏力,呼吸道症状以干咳为主,并逐渐出现呼吸困难,严重者急性呼吸窘迫综合征、脓毒症休克、难以纠正的代谢性酸中毒和出凝血功能障碍。
B. 早期呈现多发小斑片影及间质改变,以肺外带明显。进而发展为双肺多发磨玻璃影、浸润影,严重者可出现肺实变,胸腔积液少见。
C. 发病早期白细胞总数正常或减低,淋巴细胞计数减少。
D. 经规范抗菌药物治疗3天病情无明显改善或进行性加重。
E. 新型冠状病毒病原学监测为阳性。
【多选题】
“新型冠状病毒感染的肺炎”可以感染的动物物种为:___
A. 蝙蝠
B. 家畜(如:猪、狗、牛)
C. 野生动物(如:猴子、山羊)
D. 家禽(如:鸡、鸭、鹅)
E. 鸟类
【多选题】
怀疑自己有新型冠状病毒感染的症状怎么办?___
A. 佩戴口罩,与对方保持距离
B. 不闻不问,假装自己不知道
C. 建议与自己接触过的人佩戴口罩并前往就近的定点救治医院发热门诊就诊
D. 帮与自己接触过的人到网上找治疗偏方
【多选题】
新型冠状病毒感染引起的症状与SARS、流感、普通感冒有什么区别?___
A. 新型冠状病毒感染以发热、乏力、干咳为主要表现,并会出现肺炎
B. 新型冠状病毒感染的患者早期可能不发热,仅有畏寒和呼吸道感染症状,但CT会显示有肺炎现象
C. 新型冠状病毒感染引起的重症病例与SARS类似
D. 新型冠状病毒感染的临床表现有时可能会引起肺炎
【多选题】
2020年1月25日,中共中央政治局常务委员会召开会议,会议强调,要全力以赴救治感染患者。要按照的“()、()、()、()”原则,将重症病例集中到综合力量强的定点医疗机构进行救治,及时收治所有确诊病人。___
A. 集中患者;
B. 集中专家
C. 集中资源;
D. 集中救治
【多选题】
什么是“密切接触者”?___
A. 与患者乘坐同一交通工具,但又未做任何防护措施的人员
B. 与患者共用一个教室,但又未做任何防护措施的人员
C. 与患者在同一所房屋中生活,但又未做任何防护措施的人员
D. 是否属于密切接触者,最终需要疾病预防控制中心的专业人员做出专业判定
【多选题】
在什么情况下N95口罩需要更换? ___
A. 呼吸阻抗明显增加时
B. 口罩有破损.损坏或与面部无法密合时
C. 口罩受污染(如染有血渍或飞沫等异物时)
D. 曾使用于个例病房或病患接触(因为该口罩已被污染)
【判断题】
宠物会传播新型冠状病毒。
A. 对
B. 错
【判断题】
口罩戴的层数越多,防病毒效果越好。
A. 对
B. 错
【判断题】
全身喷洒酒精可起到消毒效果。
A. 对
B. 错
【判断题】
熏醋不能直接杀灭新型冠状病毒。
A. 对
B. 错
【判断题】
晒太阳不能杀死冠状病毒。
A. 对
B. 错
【判断题】
乳铁蛋白能预防新型冠状病毒感染的肺炎。
A. 对
B. 错
【判断题】
服抗生素能预防新型冠状病毒感染。
A. 对
B. 错
【判断题】
吃维生素C不可以预防新型冠状病毒感染。
A. 对
B. 错
【判断题】
洗手全过程要认真揉搓双手 15 秒以上,特别要注意彻底清洗戴戒指、手表和其他装饰品的部位,(有条件的也应清洗戒指、手表等饰品),应先摘下手上的饰物再彻底清洁。
A. 对
B. 错
【判断题】
保电工作人员,离开疫区的时候用 84 消毒液对现场使用的安全工器具及服装进行喷洒消毒即可。
A. 对
B. 错