【单选题】
Which statement represents a difference between an access list on an aSa versus an access list on a router?___
A. The asa does not support number access lists
B. The aSa does not support standard access list
C. The asa does not ever use a wildcard mask
D. The asa does not support extended access lists
查看试卷,进入试卷练习
微信扫一扫,开始刷题

答案
C
解析
暂无解析
相关试题
【单选题】
Which command do you enter to verify the status and settings of an iKE Phase 1 tunnel?___
A. show crypto ipsec as output
B. show crypto isakmp
C. show crypto isakmp policy
D. show crypto ipsec transform
【单选题】
Which feature can help a router or switch maintain packet forwarding and protocol states despite an attack or heavy traffic load on the router or switch?___
A. service Policy
B. Control Plane Policing
C. Policy Map
D. Cisco
E. xpress
F. orwarding
【单选题】
Which STP feature can prevent an attacker from becoming the root bridge by immediately shutting down the interface when it receives a BPDU?___
A. root guard
B. Port Fast
C. BPDU guard
D. BPDU filtering
【单选题】
Which technology can best protect data at rest on a user system?___
A. full-disk encryption
B. IPsec tunnel
C. router ACL
D. network IPS
【多选题】
Which two primary security concerns can you mitigate with a BYOD solution ?___
A. schedule for patching the device
B. securing access to a trusted corporate network
C. compliance with applicable policies
D. connections to public Wi-Fi networks
E. device tagging and invento
【多选题】
choose five___
A. MD5————————inserure
B. DES————————insercure
C. SDES———————legacy
D. SHA-1———————legacy
E. HMAC-MD5—————legacy
【多选题】
Which two characteristics of symmetric encryption are true?___
A. It uses digital certificates
B. It requires more resources than asymmetric ancryption
C. It uses the same key to enctypt and decrupt traffic
D. It uses a public key and a pricate key to encrypt and decrypt traffic.
E. It is faster than asymmetric encryption
【多选题】
which two characteristics of PVLAN are true?___
A. Promiscuous porta can communicate with PVLAN ports.
B. Isolated ports cannot communicate with other ports on the same VLAN
C. Community ports have to be a part of the trunk.
D. They require VTP to be enabled in server mode
E. PVLAN ports can be configured as Ether Channel ports
【多选题】
What are two options for running Cisco SDM?___
A. Running SDM from a mobile device
B. Running SDM from within CiscoWorks
C. Running SDM from a router's flash
D. Running SDM from the Cisco web porta
E. Running SDM from a PC
【多选题】
Which two options are the primary deployment modeles for mobile device management?___
A. multisite
B. cloud-based
C. on premises
D. hybrid cloud basedo
E. single site
【多选题】
Drag the recommendation on the left to the Cryptographic algorithms on the right, Options will be used more than once.___
A. Avoid——————————————DES,MD5
B. Legacy——————————————SDES,SHA1,HMAC-MD5
【多选题】
Which two are valid types of vLans using PVLANS ?___
A. Community VLAN
B. Backup VLAN
C. Secondary VLAN
D. Isolated VLAN
E. Isolated VLAN
【多选题】
Which two commands are used to implement Resilient lOS Configuration ___
A. Secure boot-config
B. copy running-config tftp
C. copy flash:ios bin tftp
D. copy running-config startup-config
E. secure boot-image
【多选题】
Which two types of firewalls work at layer 4 and above ?___
A. Stateful inspection
B. Network Address Translation
C. Circuit-Level gateway
D. Static packet filter
E. Application Level firewall
【多选题】
Which two default settings for port security are true ?___
A. Violation is Protect
B. Violation is Restrict
C. Violation is Shutdown
D. Maximum number of MAC addresses is 2
E. Maximum number of MAC addresses is 1
【多选题】
Which two are characteristics of RADIUS?___
A. Uses UDP ports 1812 /1813
B. Uses TCP port 49
C. Uses UDP port 49
D.
E. ncrypts only the password between user and server
【多选题】
When setting up a site-to-site VPN with PSK authentication on a Cisco router, which two elements must be configured under crypto map?___
A. pfs
B. nat
C. reverse route
D. peer
E. transform-set
【多选题】
When using the Adaptive Security Device Manager(ASDM), which two options are available to add a new root certificate?___
A. Install from SFTP server
B. Usehttps
C. Install from a file
D. Use LDAP
E. Use SCEP
【多选题】
Which two SNMPv3 services support its capabilities as a secure networ k manage protocol? ___
A. access control
B. the shared secret key
C. authentication
D. authorization
E. accounting
【多选题】
Which two statements about routed firewall mode are true ?___
A. The firewall acts as a routed hop in the network
B. This mode conceals the presence of the firewall
C. The firewall requires a unique iP address for each interface
D. This mode allows the firewall to be added to an existing networ k with minimal additional configuration By default, this mode permits most traffic to pass throug
【多选题】
Which two statements describe DHCP spoofing attacks?___
A. They are used to perform man-in- the-middle attacks
B. They can access most network devices
C. They can modify the flow of traffic in transit. LNGKAIG
D. They protect the identity of ti attacker by masking the DHCP address
E. They can physically modify the network gateway
【多选题】
Which two types of VLANs using PVLANs are valid?___
A. isolated
B. promiscuous
C. backup
D. secondary
E. community
【多选题】
What are two limitations of the self-zone policies on a zone-based firewall?___
A. They are unable to block Https traffic
B. They restrict SNMP traffic.
C. They are unable to support Https traffic
D. They are unable to implement application inspection
E. They are unable to perform rate limiting
【多选题】
Which two descriptions of TACACS+ are true? ___
A. The TACACS+ header is unencrypted
B. It combines a uthentication and authorization
C. It uses TCP as its transport protocol
D. Only the password is encrypted.
E. It uses UDP as its transport protocol.
【多选题】
Which two actions does an IPS perform? ___
A. it spans the traffic
B. it reflects the traffic back to the sender
C. it encrypts the traffic
D. it terminates the user session or connection of the attacker
E. it reconfigures a device to block the traffic
【多选题】
In which form of fraud does an attacker try to learn information such as login credenti account information by ma squerading as a reputable entity or person in email, IM or communication channels ?___
A. phishing
B. Smurfit
C. Hacking
D. Identity Spoofing
【多选题】
Which two ESA services are available for incoming and outgoing mails ?___
A. anti-DoS
B. reputation filter
C. antispam
D. content filter
E. DLP
【多选题】
What are two reasons to recommend SNMPv 3 over SNMPv2?___
A. SNMPv3 is secure because you can configure authe ntication and privacy
B. SNMPv3 is insecure because it send in formation in clear text
C. SNMPv2 is insecure because it send information in clear text
D. SNMPv3 is a Cisco proprietary protocol
E. SNMPv2 is secure because you can configure authentication and privacy
【多选题】
Which two actions can a zone- based firewall apply to a packet as it transits a zone pair?___
A. drop
B. inspect
C. queue
D. quarantine
【单选题】
Which security principle has been violated if data is altered in an unauthorized manner?___
A. accountability
B. confidentiality
C. availability
D. integrity
【单选题】
Which IKE Phase 1 parameter can you use to require the site-to-site VPN to use a pre-shared ?___
A. encryption
B. authentication
C. group
【单选题】
Which command successfully creates an administrative user with a password of "cisco"on a Cisco router?___
A. username Operator privilege 7 password cisco
B. username Operator privilege 1 password cisco
C. username Operator privilege 15 password cisco
D. username Operator password cisco privilege 15
【单选题】
Which EAP method authenticates a client against Active Directory without the use of client-side 802.1X certificates?___
A. EAP-TLS
B. EAP-MSCHAPv2
C. EAP-PEAP
D.
E. AP-GTC
【单选题】
What is a limitation of network-based IPS?___
A. It must be in dividually configured to support every operating system on the network.
B. It is most effective at the in dividual host level
C. It is unable to monitor attacks across the entire netw ork
D. Large installations require numerous sensors to fully protect the network
【单选题】
When would you configure the ip dhcp snooping trust command on a sw itch?___
A. when the switch is connected to a DHCP server
B. when the switch is working in an edge capacit
C. when the switch is connected to a client system
D. when the switch is serving as an aggregator
【单选题】
How does the 802. 1x supplicant communicate with the authentication server?___
A. The supplicant creates EAP packets and sends them to the authenticator, which encapsulates them into RADIUS and forwards them to the authentication server.
B. The supplicant creates RADIUS packets and sends them to the authe nticator, which encapsulates the m into EAP and forwards them to the a uthentication server.
C. The supplicant creates RADIUS packets and sends them to the authenticator, which translates them into eap and forwards them to the a ut hentication server
D. The supplicant creates
E. AP packets and sends them to the authe nticator, which translates them into radius and forwards them to the authentication server.
【单选题】
Which command do you enter to verify the phase I status of a VPN connection?___
A. sh crypto se ssion
B. debug crypto isakmp
C. sh crypto isakmp sa
D. sh crypto ipsec sa
【单选题】
Refer to the exhibit. what is the e ffect of the given configuration?___
A. It enables authentication,
B. It prevents keychain authentication.
C. The two routers receive normal updates from one another.
D. The two device s are able to pass the message digest to one another.
【单选题】
Which command can you enter to configure OSPF to use hashing to authenticate routing updates?___
A. ip ospf aut hentication message-digest
B. neighbor 192 168.0 112 cost md5
C. ip ospf priority 1
D. ip ospf aut hentication-key
【单选题】
Which command can you enter to verify the status of Cisco lOS Resilient Configuration on a Cisco router?___
A. show secure bootset
B. secure boot-image
C. show binary file
D. ure boot-config
推荐试题
【单选题】
建筑工程勘察、设计、施工的质量必须符合国家有关建筑工程安全标准的要求,具体管理办法由___规定。
A. 国务院建设行政主管部门
B. 国务院
C. 中国建筑业协会
D. 全国人民代表大会
【单选题】
建筑施工企业转让、出借资质证书或者以其他方式允许他人以本企业的名义承揽工程的,对因该项承揽工程不符合规定的质量标准造成的损失,___。
A. 由建筑施工企业独自负责
B. 承包单位与接受转包或者分包的单位各自独立承担相应责任
C. 由建筑施工企业与使用本企业名义的单位或者个人各自独立承担赔偿责任
D. 由建筑施工企业与使用本企业名义的单位或者个人承担连带赔偿责任
【单选题】
《建筑法》关于施工许可、建筑施工企业资质审查和建筑工程发包、承包、禁止转包,以及建筑工程监理、建筑工程安全和质量管理的规定,适用于其他专业建筑工程的建筑活动,具体办法由___规定。
A. 国务院
B. 国务院建设行政主管部门
C. 中国建筑业协会
D. 全国人民代表大会
【单选题】
《建筑法》规定,大型建筑工程或者结构复杂的建筑工程,可以由两个以上的承包单位联合共同承包。共同承包的各方对承包合同的履行___。
A. 独立承担各自的责任
B. 承担连带责任
C. 不承担责任
D. 承担适当的责任
【单选题】
实施建筑工程监理前,建设单位应当将委托的工程监理单位、监理的内容及监理权限,___被监理的建筑施工企业。
A. 口头通知
B. 书面通知
C. 以任何形式通知
D. 不必通知
【单选题】
工程监理单位不按照委托监理合同的约定履行监理义务,对应当监督检查的项目不检查或者不按照规定检查,给建设单位造成损失的,应当承担___。
A. 全部的赔偿责任
B. 大部分的赔偿责任
C. 相应的赔偿责任
D. 相应的补偿责任
【单选题】
工程监理单位与承包单位串通,为承包单位谋取非法利益,给建设单位造成损失的,应当___。
A. 独自承担赔偿责任
B. 与承包单位承担连带赔偿责任
C. 不必承担赔偿责任
D. 由承包单位承担赔偿责任
【单选题】
___应当向建筑施工企业提供与施工现场相关的地下管线资料,建筑施工企业应当采取措施加以保护。
A. 设计单位
B. 监理单位
C. 建设单位
D. 各级地方人民政府建设行政主管部门
【单选题】
___应当建立健全劳动安全生产教育培训制度,加强对职工安全生产的教育培训;未经安全生产教育培训的人员,不得上岗作业。
A. 建筑施工企业
B. 监理单位
C. 设计单位
D. 建设单位
【单选题】
建筑设计单位和建筑施工企业对建设单位违反法律、行政法规和建筑工程质量、安全标准,提出的降低工程质量的要求,___。
A. 可以予以拒绝
B. 应当予以拒绝
C. 不得予以拒绝
D. 视情况决定拒绝与否
【单选题】
建筑工程监理应当依照法律、行政法规及有关的技术标准、设计文件和建筑工程承包合同,对承包单位在施工质量、建设工期和建设资金使用等方面,代表___实施监督。
A. 施工单位
B. 建设单位
C. 主管部门
D. 上级机关
【单选题】
建筑施工企业在编制施工组织设计时,对专业性较强的工程项目,___。
A. 不必编制专项安全施工组织设计
B. 视情况决定是否编制专项安全施工组织设计
C. 视情况决定是否采取安全技术措施
D. 应当编制专项安全施工组织设计,并采取安全技术措施
【单选题】
___应当遵守有关环境保护和安全生产的法律、法规的规定,采取控制和处理施工现场的各种粉尘、废气、废水、固体废物以及噪声、振动对环境的污染和危害的措施。
A. 各级人民政府
B. 监理单位
C. 建筑施工企业
D. 建设单位
【单选题】
___对建设工程的质量、安全事故、质量缺陷、安全隐患等都有权向建设行政主管部门或者其他有关部门进行检举、控告、投诉。
A. 任何单位和个人
B. 建设单位
C. 监理单位
D. 项目经理
【单选题】
建设行政主管部门和其他有关部门在对建筑活动实施监督管理过程中,___。
A. 可以收取相关费用
B. 不得收取任何费用
C. 除按照国务院有关规定收取费用外,不得收取其他费用
D. 除按照国务院有关规定收取费用外,还可收取其他费用
【单选题】
从事建筑活动的专业技术人员,应当___从事建筑活动。
A. 依法取得相应的执业资格证书,但可在执业资格证书许可的范围外
B. 依法取得相应的执业资格证书,并在执业资格证书许可的范围内
C. 不必取得执业资格证书
D. 依法取得相应的职业资格证书,但可在执业资格证书许可的范围外
【单选题】
从事建设工程活动,必须严格执行基本建设程序,坚持___的原则。
A. 先勘察、后设计、再施工
B. 先计划,后设计,再预算
C. 先预算,后勘察,再设计
D. 先设计,后勘察,再施工
【单选题】
关于建设项目设计文件的修改,下列表述正确的是___。
A. 建设文件是工程建设的主要依据,经批准后,不得任意变更和修改
B. 建设单位和监理单位可以修改工程建设勘察设计文件
C. 确需修改的,应由新的勘察设计单位修改
D. 修改单位对修改的勘察设计文件不承担相应的法律责任
【单选题】
涉及建筑主体和承重结构变动的装修工程,建设单位应当在施工前委托原设计单位或者具有相应资质等级的设计单位提出设计方案;没有设计方案的___。
A. 不得施工
B. 在某些部门许可下可以施工
C. 在质量监督部门监督下可以施工
D. 不确定