【单选题】
How can you prevent NAT rules from sending traffic to incorrect interfaces?___
A. Assign the output interface in the NAT statement
B. Add the no-proxy-arp command to the nat line.
C. Configure twice NAT instead o bject NAT. 5
D. Use packet-tracer rules to reroute misrouted NAT entries.
查看试卷,进入试卷练习
微信扫一扫,开始刷题
答案
A
解析
暂无解析
相关试题
【单选题】
What term can be defined as the securing, control, and identification of digital data?___
A. cryptography
B. crypto key
C. cryptoanalysis
D. cryptology
【单选题】
Which feature in the dNS security module provide on and off network DNS protection?___
A. Data Loss Prevention
B. Umbrella
C. Real-time sandboxing
D. Layer-4 monitoring
【单选题】
Which a dverse consequence can occur on a network without BPDu guard ?___
A. The olde st switch can be elected as the root bridge
B. Unauthorized switches that are connected to the network can cause spanning-tree loops
C.
D. ouble tagging can cause the switches to experience CAM table overload.
【单选题】
What configuration is required for multitenancy ?___
A. shared infrastructure
B. multiple carriers
C. co-located resources
D. multiple separate zones
【单选题】
Why does ISE require its own certificate issued by a trusted CA?___
A. ISEs certificate allows guest devices to validate it as a trusted network device
B. It generates certificates for guest devices ba sed on its own certificate
C. It requests certificates for guest devices from the Ca server based on its own certificate.
D. ISE's certificate allows it to join the network security framework
【单选题】
which attack involves large numbers of ICMP packets with a spoofed source IP address?___
A. smurf attack
B. Teardrop attack
C. Nuke attack
D. SYN Flood attack
【单选题】
Which statement about interface and global access rules is true?___
A. Interface access rules are processed before global access rules.
B. Global access rules apply only to outbound traffic, but interface access rules can be applied in either direction
C. The implicit allow is proce ssed after both the global and interface access rules
D. If an interface access rule is applied, the global access rule is ignored
【单选题】
Which type of malicious software can create a back-door into a device or network?___
A. bot
B. worm
C. virus
D. Trojan
【单选题】
Which security term refers to the like lihood that a weakness will be exploited to cause damage to an asset?___
A. threat
B. risk
C. countermeasure
D. vulnerability
【单选题】
Which IPS detection method examines network traffic for preconfigured patterns?___
A. signature-based detection
B. honey-pot detection
C. anomaly-based detection
D. policy-based detection
【单选题】
What is an advantage of split tunneling ?___
A. It allows users with a VpN connection to a corporate network to access the internet with sending traffic across the cor porate network.
B. It allows users with a vpn connection to a corporate network to access the internet by using the vPN for security.
C. It protects traffic on the private network from users on the public network
D. It enables the VPN server to filter traffic more efficiently
【单选题】
Which IDS/IPS state misidentifies acceptable behavior as an attack ?___
A. false negative
B. true positive NEKA G
C. true negative
D. false positive
【单选题】
What is the maximum num ber of methods that a single method list can contain?___
A. 4
B. 3
C. 2
D. 5
【单选题】
Which command enables authentication at the oSPFv2 routing process level?___
A. ip ospf authentication message-digest
B. area 0 authentication message-digest
C. ip ospf message-digest-key 1 mds Cisco
D. area 0 authentication ipsec spi 500 md5 1234567890ABCDEF1234567890ABCDEF
【单选题】
Which type of firewall monitors a nd protects a specific system?___
A. firewall
B. application firewall
C. stateless firewall wvp
D. personal firewall
【单选题】
On an ASA, which maps are used to identify traffic?___
A. Route maps
B. Policy maps
C. Class maps
D. Service maps
【单选题】
Which type of social engineering attack targets top executives?___
A. whaling
B. vishin
C. spear phishing ng
D. baiting
【单选题】
What is the minimum Cisco lOS version that supports zone-based firewalls?___
A. 12.1T
B. 15.1
C. 15.0
D. 124
【单选题】
In which type of attack does an attacker overwrite an entry in the CAM table to divert traffic destined to a legitimate host?___
A. DHCP spoofing
B. ARP spoofing
C. CAM table overflow
D. MAC spoofing
【多选题】
Which two attack types can be prevented with the impleme ntation of a Cisco IPS solution?___
A. DDos
B. man-in-the-middle
C. worms
D. ARP spoofing
E. VLAN hopping
【多选题】
choose four___
A. DHCP snooping ——————————blocks DHCP messages
B. Dynamic ARP inspection——————verifies IP-to-MAC traffic on untrusted ports
C. IP sources guard ——————————provides layer 2 interface security with ports ACLs
D. Port security————————————mitigates MAC-address spoofing at the access interface
【多选题】
choose four___
A. Step1————————run the system setup wizard
B. Step2————————add an authentication realm
C. Step3————————configure identity management
D. Step4————————configure directory group
【多选题】
What are two advanced features of the Cisco AMp solution for endpoints ___
A. contemplation
B. foresight
C. sandboxing
D. reputation
E. reflection
【多选题】
Which two characteristics of RADIUS are true?___
A. It encrypts only the password between user and server.
B. It uses TCP ports 1812/1813
C. It uses UDP ports 1812/1813.
D. It uses UDP port 49
E. It uses TCP port 49
【多选题】
What are two challenges of using a network-based IPS? ___
A. It is unable to determine whether a detected attack was successful
B. It requires additional storage and proce ssor capacity on syslog servers
C. As the network expands, it requires you to add more sensors.
D. It is unable to detect attacks across the entire network
E. It must support multiple operating systems.
【多选题】
What are two default be haviors of the traffic on a zone-based firewall?___
A. Traffic within the self -zone uses an im plicit deny all.
B. All traffic between zones is implicitly blocked
C. Communication is allowed between interfadAss that are members of the same zone
D. Communication is blocked between interfaces that are members of the same zone
E. The CBAC rules that are configured on router interfaces apply to zone interfaces
【多选题】
Which two advantages does the on-premise model for MDM deployment have over the cloud-based model?___
A. The on-premise model is easier and faster to de ploy than the cloud-based model
B. The on-premise model is more scalable than the cloud-based model
C. The on-premise model is generally less expensive than the cloud-based model
D. The on-premise model generally has less latency than the cloud- based model.
E. The on-premise model provides more control of the MDM solution than the cloud
【多选题】
Which two actions can an end usts take to manage a lost or stolen device in Cisco ISE? ___
A. Activate Cisco ISE End point Protection Services to quarantine the device.
B. Add the mac address of the device to a list of blacklisted devices
C. Force the device to be locked with a PIN
D. Request revocation of the digital certificate of the device.
E. Reinstate a device that the user previously marked as lost or stolen
【多选题】
Which two problems can arise when a proxy firewall serves as the gateway between networks?___
A. It can prevent content caching
B. It can limit application support
C. It is unable to prevent direct connections to other networks
D. It can cause reduced throughput.
E. It is unable to provide antivirus protection
【多选题】
When using the Adaptive Security Device Manager(ASDM), which two methods are available to add a new root certificate?___
A. Use sCep
B. Install from SFTP server
C. Install from a file
D. Use Https
E. Use LDAP
【多选题】
Which two are considered basic security principles?___
A. Accountability
B. Redundancy
C. High Availabilit
D. Integrity
E. Confidentiality
【多选题】
Which two roles of the Cisco WSA are true?___
A. IPS
B. firewall
C. antispam
D. web proxy
E. URL filter
【单选题】
Which next-generation encryption algorithm supports four variants?___
A. SHA-2
B. SHA-1
C. MD5
D. HMAC
【单选题】
What aims to remove the abil ity to deny an action?___
A. Non-Repudiation
B. Accountability
C. Integrity
D. Deniability
【单选题】
Which statements about the native VLAN is true ?___
A. It is susceptible to VLAN hopping attacks.
B. It is the Cisco recommended VLAN for switch-management traffic
C. It is most secure when it is a ssigned to vLAn 1.
D. It is the cisco-recomme nded vlan for user traffic
【单选题】
There are two versions of IKE:IKEv1 and IKEv2. Both IKEv1 and IKEv2 protocols operate in phases IKEv1 operates in two phases. IKEv2 operates in how many phases?___
A. 2
B. 3
C. 4
D. 5
【单选题】
What does the dh group refer to?___
A. length of key for hashing C
B. length of key for encryption
C. tunnel lifetime key
D. length of key for key exchange
E. length of key for authentication
【单选题】
Which path do you follow to enable aaa through the SDM ?___
A. Configure Tasks > AAA
B. Configure > Addition Authentication > AAA
C. Configure > AAA
D. Configure > Additional Tasks > AAA
E. Configure Authentication > AAA
【单选题】
which technology cloud be used on top of an MPLS VPN to add confidentiality ?___
A. IPsec
B. 3DES
C. AES
D. SSL
【单选题】
Which term is most closely aligned with the basic purpose of a SIEM solution? ___
A. Non-Repudiation
B. Accountability
C. Causality
D. Repudiation
推荐试题
【判断题】
按照《银行业金融机构全面风险管理指引》规定,风险限额临近监管指标限额时,银行业金融机构应当启动相应的纠正措施和报告程序,采取必要的风险分散措施,并向银行业监督管理机构报告
A. 对
B. 错
【判断题】
按照《银行业金融机构全面风险管理指引》规定,银行业金融机构应当制定每项业务对应的风险管理政策和程序。未制定的,不得开展该项业务
A. 对
B. 错
【判断题】
当前,部分银行业金融机构业务外包管控不严,责任约束机制缺失,委托代理开展过程中,未能有效管控外包机构、人员非法获取、接触、处理客户个人信息数据行为,存在第三方泄露客户个人信息风险隐患
A. 对
B. 错
【判断题】
银行业金融机构要牢固树立全员合规意识,进一步加强员工教育与外包行为管理,强化信息安全建设,强化内部监督,建立完善客户个人信息保护长效机制。严肃处理发现的违规问题,对涉嫌犯罪的,及时向检察机关报案
A. 对
B. 错
【判断题】
根据中国银监会办公厅关于银行业金融机构客户个人信息泄露案件风险提示的通知(银监办发〔2016〕156号)规定,银行业金融机构要在有效防范客户个人信息案件风险基础上,完善法律风险应对预案,降低因客户个人信息保护不到位诱发案件风险对银行业造成的不良影响
A. 对
B. 错
【判断题】
银行业金融要充分认识保护客户个人信息安全工作的重要意义,切实落实主体责任,完善客户个人信息保护制度建设,强化执行管理
A. 对
B. 错
【判断题】
应行业金融机构可视具体情况决定是否将同业客户纳入实施统一授信的客户范围
A. 对
B. 错
【判断题】
在计算大额风险暴露时,对具有经济关联关系的客户应参照集团客户进行授信和集中度管理
A. 对
B. 错
【判断题】
原则上,不需要对非信贷资产进行风险分类
A. 对
B. 错
【判断题】
特定目的载体投资应按照穿透性原则对应至最终债务人
A. 对
B. 错
【判断题】
银行也金融机构应严格及时、准确和全面的监测国别风险暴露,严格国别风险限额管理,制定书面的国别风险准备金计提政策,但无需向银监会报送相关报表
A. 对
B. 错
【判断题】
对在贷款分类中弄虚作假掩饰贷款质量的,应视情节严重程度决定是否问责或采取处罚措施
A. 对
B. 错
【判断题】
非信贷资产分类要坚持实质重于形式的原则,实行穿透式管理
A. 对
B. 错
【判断题】
按照《中国银监会关于银行业风险防控工作的指导意见》规定,银行业金融机构要认真落实《预算法》和《国务院关于加强地方政府性债务管理的意见》要求,不得违规新增地方政府融资平台贷款,严禁接受地方政府担保兜底
A. 对
B. 错
【判断题】
按照《中国银监会关于银行业风险防控工作的指导意见》规定,网络借贷信息中介机构应依法合规开展业务,确保出借人资金来源合法,禁止欺诈、虚假宣传
A. 对
B. 错
【判断题】
按照《中国银监会关于银行业风险防控工作的指导意见》规定,银行业金融机构要完善流动性风险治理架构,将同业业务、投资业务、托管业务、理财业务等纳入流动性风险监测范围,制定合理的流动性限额和管理方案
A. 对
B. 错
【判断题】
按照《中国银监会关于银行业风险防控工作的指导意见》规定,银行业金融机构应将房地产企业贷款、个人按揭贷款、以房地产为抵押的贷款、房地产企业债券,以及其他形式的房地产融资纳入监测范围,不定期开展房地产压力测试
A. 对
B. 错
【判断题】
按照《中国银监会关于银行业风险防控工作的指导意见》规定,银行业金融机构要完善押品准入管理机制,建立健全房地产押品动态监测机制,定期发布内部预警信息,采取有效应对措施
A. 对
B. 错
【判断题】
按照《中国银监会关于银行业风险防控工作的指导意见》规定,网络借贷信息中介机构不得将不具备还款能力的借款人纳入营销范围,禁止向未满18岁的在校大学生提供网贷服务,
A. 对
B. 错
【判断题】
按照《中国银监会关于银行业风险防控工作的指导意见》规定,银行业金融机构要完善外包管理体系,降低外包风险,不得将信息科技管理责任外包
A. 对
B. 错
【判断题】
银行业金融机构应严格遵守相关法律法规和境外项目管理规定,可根据本行风险评估,在风险可控的范围内自行向境外项目提供融资
A. 对
B. 错
【判断题】
银行业金融机构应遵循“了解你的客户”原则,全面了解客户的业务经营和财务状况,以及当地经营环境,必要时还应了解“客户的客户”等情况
A. 对
B. 错
【判断题】
高级管理层对经营活动的合规性负最终责任,高级管理层应切实履行合规管理职责,监事会应加强对董事会和高级管理层合规管理职责履行情况的监督
A. 对
B. 错
【判断题】
按照《中国银监会中资商业银行行政许可事项实施办法》规定,中资商业银行设立境内分支机构须经筹建和开业两个阶段
A. 对
B. 错
【判断题】
按照《中国银监会中资商业银行行政许可事项实施办法》规定,中资商业银行设立的境内分支机构包括分行、分行级专营机构、支行、分行级专营机构的分支机构等
A. 对
B. 错
【判断题】
按照《中国银监会中资商业银行行政许可事项实施办法》规定,最近1年无严重违法违规行为和因内部管理问题导致的重大案件,是中资商业银行申请设立分行的条件之一
A. 对
B. 错
【判断题】
按照《中国银监会中资商业银行行政许可事项实施办法》规定,中资商业银行募集次级定期债务、发行次级债券、混合资本债、金融债及其他债务、资本补充工具,由证监会受理、审查并决定
A. 对
B. 错
【判断题】
按照《中国银监会中资商业银行行政许可事项实施办法》规定,国有商业银行、邮政储蓄银行、股份制商业银行申请开办衍生产品交易业务,由所在地银监局受理、审查并决定
A. 对
B. 错
【判断题】
按照《中国银监会中资商业银行行政许可事项实施办法》规定,管理型支行行长属于高级管理人员,须经任职资格许可
A. 对
B. 错
【判断题】
按照《中国银监会中资商业银行行政许可事项实施办法》规定,具有高管任职资格且未连续中断任职1年以上的拟任人在同一法人机构内,同类性质平行调整职务或改任较低职务的,不需要重新申请核准任职资格
A. 对
B. 错
【判断题】
按照《中国银监会中资商业银行行政许可事项实施办法》规定,中资商业银行指定符合相应任职资格条件的人员代为履职的,自指定之日起3日内向负责任职资格审核的机关报告
A. 对
B. 错
【判断题】
按照《中国银监会中资商业银行行政许可事项实施办法》规定,代为履职的时间不得超过3个月
A. 对
B. 错
【判断题】
按照《中国银监会中资商业银行行政许可事项实施办法》规定,二级分行市指不直接接受商业银行法人机构指导或授权开展工作,在机构管理、业务管理、人员管理等日常经营管理中直接或主要接受上级分行的指导或管辖并对其负责的分行
A. 对
B. 错
【判断题】
按照《商业银行杠杆率管理办法(修订)》规定,商业一行在计算调整后的表内外资产余额时,应考虑抵质押品、保证和信用衍生产品等信用风险缓释因素
A. 对
B. 错
【判断题】
按照《商业银行杠杆率管理办法(修订)》规定,商业银行高级管理层承担杠杆率管理的最终责任
A. 对
B. 错
【判断题】
按照《商业银行杠杆率管理办法(修订)》规定,衍生产品资产余额按照现期风险暴露法计算,除符合规定的保证金外,相关抵质押品不应从衍生产品资产余额中扣除
A. 对
B. 错
【判断题】
按照《商业银行杠杆率管理办法(修订)》规定,证券融资交易资产余额应当为证券融资交易的会计资产余额和证券融资交易的交易对手信用风险暴露之和
A. 对
B. 错
【判断题】
按照《商业银行杠杆率管理办法(修订)》规定,商业银行从事证券融资交易,如其根据财务会计准则规定可以将证券出表,但交易实质和承担的风险与买入返售或卖出回购业务相同的,应当将该出表的证券计入证券融资交易资产余额中
A. 对
B. 错
【判断题】
按照《商业银行杠杆率管理办法(修订)》规定,并表杠杆率及未并表杠杆率均应每季度报送一次
A. 对
B. 错
【判断题】
按照《商业银行杠杆率管理办法(修订)》规定,农村信用社、村镇银行等机构不需执行本办法
A. 对
B. 错