【单选题】
What is an advantage of split tunneling ?___
A. It allows users with a VpN connection to a corporate network to access the internet with sending traffic across the cor porate network.
B. It allows users with a vpn connection to a corporate network to access the internet by using the vPN for security.
C. It protects traffic on the private network from users on the public network
D. It enables the VPN server to filter traffic more efficiently
查看试卷,进入试卷练习
微信扫一扫,开始刷题
答案
A
解析
暂无解析
相关试题
【单选题】
Which IDS/IPS state misidentifies acceptable behavior as an attack ?___
A. false negative
B. true positive NEKA G
C. true negative
D. false positive
【单选题】
What is the maximum num ber of methods that a single method list can contain?___
A. 4
B. 3
C. 2
D. 5
【单选题】
Which command enables authentication at the oSPFv2 routing process level?___
A. ip ospf authentication message-digest
B. area 0 authentication message-digest
C. ip ospf message-digest-key 1 mds Cisco
D. area 0 authentication ipsec spi 500 md5 1234567890ABCDEF1234567890ABCDEF
【单选题】
Which type of firewall monitors a nd protects a specific system?___
A. firewall
B. application firewall
C. stateless firewall wvp
D. personal firewall
【单选题】
On an ASA, which maps are used to identify traffic?___
A. Route maps
B. Policy maps
C. Class maps
D. Service maps
【单选题】
Which type of social engineering attack targets top executives?___
A. whaling
B. vishin
C. spear phishing ng
D. baiting
【单选题】
What is the minimum Cisco lOS version that supports zone-based firewalls?___
A. 12.1T
B. 15.1
C. 15.0
D. 124
【单选题】
In which type of attack does an attacker overwrite an entry in the CAM table to divert traffic destined to a legitimate host?___
A. DHCP spoofing
B. ARP spoofing
C. CAM table overflow
D. MAC spoofing
【多选题】
Which two attack types can be prevented with the impleme ntation of a Cisco IPS solution?___
A. DDos
B. man-in-the-middle
C. worms
D. ARP spoofing
E. VLAN hopping
【多选题】
choose four___
A. DHCP snooping ——————————blocks DHCP messages
B. Dynamic ARP inspection——————verifies IP-to-MAC traffic on untrusted ports
C. IP sources guard ——————————provides layer 2 interface security with ports ACLs
D. Port security————————————mitigates MAC-address spoofing at the access interface
【多选题】
choose four___
A. Step1————————run the system setup wizard
B. Step2————————add an authentication realm
C. Step3————————configure identity management
D. Step4————————configure directory group
【多选题】
What are two advanced features of the Cisco AMp solution for endpoints ___
A. contemplation
B. foresight
C. sandboxing
D. reputation
E. reflection
【多选题】
Which two characteristics of RADIUS are true?___
A. It encrypts only the password between user and server.
B. It uses TCP ports 1812/1813
C. It uses UDP ports 1812/1813.
D. It uses UDP port 49
E. It uses TCP port 49
【多选题】
What are two challenges of using a network-based IPS? ___
A. It is unable to determine whether a detected attack was successful
B. It requires additional storage and proce ssor capacity on syslog servers
C. As the network expands, it requires you to add more sensors.
D. It is unable to detect attacks across the entire network
E. It must support multiple operating systems.
【多选题】
What are two default be haviors of the traffic on a zone-based firewall?___
A. Traffic within the self -zone uses an im plicit deny all.
B. All traffic between zones is implicitly blocked
C. Communication is allowed between interfadAss that are members of the same zone
D. Communication is blocked between interfaces that are members of the same zone
E. The CBAC rules that are configured on router interfaces apply to zone interfaces
【多选题】
Which two advantages does the on-premise model for MDM deployment have over the cloud-based model?___
A. The on-premise model is easier and faster to de ploy than the cloud-based model
B. The on-premise model is more scalable than the cloud-based model
C. The on-premise model is generally less expensive than the cloud-based model
D. The on-premise model generally has less latency than the cloud- based model.
E. The on-premise model provides more control of the MDM solution than the cloud
【多选题】
Which two actions can an end usts take to manage a lost or stolen device in Cisco ISE? ___
A. Activate Cisco ISE End point Protection Services to quarantine the device.
B. Add the mac address of the device to a list of blacklisted devices
C. Force the device to be locked with a PIN
D. Request revocation of the digital certificate of the device.
E. Reinstate a device that the user previously marked as lost or stolen
【多选题】
Which two problems can arise when a proxy firewall serves as the gateway between networks?___
A. It can prevent content caching
B. It can limit application support
C. It is unable to prevent direct connections to other networks
D. It can cause reduced throughput.
E. It is unable to provide antivirus protection
【多选题】
When using the Adaptive Security Device Manager(ASDM), which two methods are available to add a new root certificate?___
A. Use sCep
B. Install from SFTP server
C. Install from a file
D. Use Https
E. Use LDAP
【多选题】
Which two are considered basic security principles?___
A. Accountability
B. Redundancy
C. High Availabilit
D. Integrity
E. Confidentiality
【多选题】
Which two roles of the Cisco WSA are true?___
A. IPS
B. firewall
C. antispam
D. web proxy
E. URL filter
【单选题】
Which next-generation encryption algorithm supports four variants?___
A. SHA-2
B. SHA-1
C. MD5
D. HMAC
【单选题】
What aims to remove the abil ity to deny an action?___
A. Non-Repudiation
B. Accountability
C. Integrity
D. Deniability
【单选题】
Which statements about the native VLAN is true ?___
A. It is susceptible to VLAN hopping attacks.
B. It is the Cisco recommended VLAN for switch-management traffic
C. It is most secure when it is a ssigned to vLAn 1.
D. It is the cisco-recomme nded vlan for user traffic
【单选题】
There are two versions of IKE:IKEv1 and IKEv2. Both IKEv1 and IKEv2 protocols operate in phases IKEv1 operates in two phases. IKEv2 operates in how many phases?___
A. 2
B. 3
C. 4
D. 5
【单选题】
What does the dh group refer to?___
A. length of key for hashing C
B. length of key for encryption
C. tunnel lifetime key
D. length of key for key exchange
E. length of key for authentication
【单选题】
Which path do you follow to enable aaa through the SDM ?___
A. Configure Tasks > AAA
B. Configure > Addition Authentication > AAA
C. Configure > AAA
D. Configure > Additional Tasks > AAA
E. Configure Authentication > AAA
【单选题】
which technology cloud be used on top of an MPLS VPN to add confidentiality ?___
A. IPsec
B. 3DES
C. AES
D. SSL
【单选题】
Which term is most closely aligned with the basic purpose of a SIEM solution? ___
A. Non-Repudiation
B. Accountability
C. Causality
D. Repudiation
【单选题】
You have just deployed SNMPv3 in your environment, Your manager asks you to make sure that our SNMP agents can only talk to the SNMP Manager. What would you configure on your SNMI agents to satisfy this request?___
A. A SNMP View containing the SNMP managers
B. Routing Filter with the SNMP managers in it applied outbound
C. A standard ACL containing the SNMP managers applied to the SNMP configuration
D. A SNMP Group containing the SNMP managers
【单选题】
Which feature prevents loops by moving a nontrunking port into an errdisable state when a BPDU is received on that port?___
A. BPDU filte
B. DHCP snooping
C. BPDU guard
D. Port Fast
【单选题】
Which command enables port security to use sticky MAC addresses on a switch?___
A. switchport port-security violation restrict
B. switchport port-security mac-address sticky
C. switchport port-security violation protect
D. switchport port-security
【单选题】
When you edit an IPS subsignature, what is the effect on the parent signature and the family of subsignatures?___
A. The change applies to the parent signature and the entire family of subsignatures
B. The change applies to the parent signature and the subsignature that you edit
C. The change applies only to subsignatures that are numbered sequentially after the subsignature that you edit
D. Other signatures are unaffected, the change applies only to the subsignature that you dit
【单选题】
Which type of mechanism does Cisco FirePOWER de ploy to protect ag detected moving across other networks?___
A. antivirus scanning
B. policy-based
C. reputation-based
D. signature-based
【单选题】
What action must you take on the ise to blacklist a wired device?___
A. Locate the switch through which the device is connected and push an a cl restricting all access by the device
B. Issue a CoA request for the de vice's mac address to each access switch in the network
C. Revoke the device's certificate so it is unable to authenticate to the network
D. Add the device's MAc address to a list of black listed devices
【单选题】
Which type of firewall can perform deep packet inspection?___
A. packet-filtering firewall
B. stateless firewall
C. application firewall
D. personal firewall
【单选题】
What is the main purpose of Control Plane Policing?___
A. to prevent exhaustion of route-proce ssor resources
B. to organize the egress packet queues
C. to define traffic classes
D. to maintain the policy map
【单选题】
Which attack can be prevented by OSPF authentication?___
A. smurf attack
B. IP spoofing attack
C. denial of service attack
D. buffer overflow attack
【单选题】
What is the best definition of hairpinning?___
A. ingress traffic that traverses the outbound interface on a device
B. traffic that enters one interface on a device and that exits through another interface
C. traffic that enters and exits a device through the same interface
D. traffic that tunnels through a device interface
【单选题】
Which SNMPv3 security level provides authentication using HMAC with MD5, but does not use encryption?___
A. authPriv
B. authNo Priv
C. noAuthNoPriv
D. NoauthPriv
推荐试题
【单选题】
列车长在___与车站指定高铁快件交接人员按集装件交接单和装载清单办理交接。
A. 车门处
B. 车厢内
C. 立岗位置
D. 大件行李处
【单选题】
动车组列车开车前,列车长提示___播放广播、监听音量及内容。
A. 乘务员
B. 兼职广播员
C. 随车机械师
D. 司机
【单选题】
动车组列车未配备乘警的,由___兼职行使列车安全员职责。
A. 乘务员
B. 列车长
C. 随车机械师
D. 餐车人员
【单选题】
动车组列车未配备乘警时,列车长要及时掌握车内治安动态,积极调解旅客矛盾纠纷,对调解和处理不了的,要立即报告___,并先行固定提取相关证据。
A. 调度
B. 客运段
C. 客运处
D. 公安指挥中心
【单选题】
加强“三品”查堵,落实动车组列车禁烟制度,及时检查卫生间、通过台等重点部位,发现吸烟行为的旅客及时制止,按规定移交___依法处理。
A. 公安部门
B. 停车站
C. 到站
D. 终点站
【单选题】
掌握车内旅客动态,积极做好服务工作, 耐心解答问询,落实“首问首诉”负责制, 积极响应旅客诉求,遇有___主动提供帮助。
A. 特殊旅客
B. 重点旅客
C. 首长
D. 外宾
【单选题】
微波炉、电烤箱内油垢“___”。
A. 一用一清
B. 一客一清
C. 一餐一清
D. 一人一清
【单选题】
在有上水、吸污作业的车站到站前,组织列车员对车厢用水情况进行统计,有严重缺水或污物箱满溢的,提前与___联系。
A. 上水站
B. 中途站
C. 停车站
D. 前方站
【单选题】
遇有动车组列车晚点时,向___了解晚点原因,及时上报晚点情况。
A. 客调
B. 动调
C. 司机
D. 上级
【单选题】
遇有动车组列车晚点时,统一口径向旅客做好解释和安抚工作,掌握___旅客情况。
A. 重点
B. 特殊
C. 中转换乘
D. 换乘飞机
【单选题】
运行中遇有突发情况时,涉及有关行车问题时,及时向___报告,听从(C )的统一指挥。
A. 客调
B. 动调
C. 司机
D. 上级
【单选题】
客运班组交接班时,对《动车组固定服务设施状态检查记录》中记载的问题与___做好交接。
A. 接班列车长
B. 质检员
C. 随车机械师
D. 列车员
【单选题】
公寓保休时,按照规定线路统一列队行走,遵守待乘纪律,外出执行请假制度,坚持___以上同去同归。
A. 两人
B. 三人
C. 四人
D. 所有人
【单选题】
动车组列车员始发开车前___min,到指定车门处立岗。
A. 5
B. 10
C. 20
D. 30
【单选题】
动车组列车员要加强运行途中的安全宣传,及时劝阻___在车厢内跑动、坐在小桌板上或运行中在座席上站立。
A. 旅客
B. 无座旅客
C. 学生
D. 儿童
【单选题】
动车组列车餐车人员始发后列车长min、终到前___min和途中到站前、开车后(A )min内不进入车厢内流动售货。
A. 10、20、5
B. 5、20、10
C. 10、10、5
D. 20、20、5
【单选题】
动车组列车餐车人员要随时清理餐车卫生,物品定置摆放,餐台、吧台做到“___”。
A. 一用一清
B. 一客一清
C. 一餐一清
D. 一人一清
【单选题】
动车组列车餐车人员车底终到前___min清点货物整理装箱, 码放整齐,大不压小,重不压轻,定位摆放,不堵通道; 保持展示柜、售货车售货状态,不间断售货服务;终到前(D )min整理展示柜、售货车商品。
A. 30、15
B. 30、10
C. 40、20
D. 40、10
【单选题】
动车组客运质检员列车终到前___min到达指定位置接车。
A. 5
B. 10
C. 15
D. 20
【单选题】
对商务座及以上旅客的人均服务费用标准原则上为本线商务座及以上全程票价的___。
A. 5-8%
B. 2-3%
C. 1-3%
D. 2-5%
【单选题】
对特、一等座旅客的人均服务费用标准原则上为本线一等座全程票价的___。
A. 5-8%
B. 2-3%
C. 1-3%
D. 2-5%
【单选题】
站车广播员每年培训时间不得少于___课时。
A. 14
B. 15
C. 16
D. 17
【单选题】
动车组列车开车前___min,播报“开车前音乐”,手动播报。
A. 5
B. 10
C. 15
D. 20
【单选题】
动车组列车开车前___min,播报“开车前预告”,手动播报。
A. 5
B. 10
C. 15
D. 20
【单选题】
到站前___km,播报“到站前二报”,自动播报。
A. 5
B. 10
C. 15
D. 20
【单选题】
自2014年___起,各局为商务座旅客免费提供耳塞;根据旅客需求,免费提供给一等座旅客。
A. 5月10日
B. 43617
C. 43586
D. 43626
【单选题】
动车组因停电或故障造成长时间停车,车内温度低于___或重点旅客需要时,可为旅客发放防寒备品。
A. 零上5度
B. 零下5度
C. 零上10度
D. 零下10度
【单选题】
动车组列车给水原则:单程运行时间在___以上的,途中(D运行7小时前后)安排1次全列满水。
A. 10小时
B. 11小时
C. 13小时
D. 14小时
【单选题】
动车组列车给水原则:车底连续套跑___以上的,中间(A运行6小时前后)安排1次折返站全列满水。
A. 10小时
B. 11小时
C. 13小时
D. 14小时
【单选题】
动车组列车给水原则:停时___分钟及以下的,不安排给水作业。
A. 3
B. 5
C. 7
D. 8
【单选题】
库内保洁人员在列车到站前___,统一着装、持证在站台指定位置立岗接车,在动车组列车始发前(B )完成。
A. 15min、2h
B. 15min、1h
C. 20min、1h
D. 25min、1h
【单选题】
折返保洁人员在列车到站前___,统一着装在站台指定位置立岗接车,在开车前(A )完成保洁工作。
A. 15min、5min
B. 10min、5min
C. 15min、2min
D. 20min、5min
【单选题】
CRH5A型动车组:允许配置额定功率___微波炉1台、额定功率(D )微波炉2台。
A. 2.7 kW、1.7 kW
B. 2.9 kW、1.9 kW
C. 2.7 kW、1.9 kW
D. 2.9 kW、1.7 kW
【单选题】
动车组列车客运值班员和列车长站车交接位置。短编组动车组列车:___之间。
A. 3、4车
B. 4、5车
C. 7、8车
D. 8、9车
【单选题】
客运值班员和列车长站车交接位置。重联动车组列车:到达列车运行前组第___之间。
A. 3、4车
B. 4、5车
C. 7、8车
D. 8、9车
【单选题】
客运值班员和列车长站车交接位置。长编组动车组列车:___之间。
A. 3、4车
B. 4、5车
C. 7、8车
D. 8、9车
【单选题】
车站与公寓之间距离超过___的需安排汽车接送。
A. 2Km
B. 3Km
C. 4Km
D. 5Km
【单选题】
登乘动车组司机室时需交验《动车组司机室登乘证》及___,经值乘民警(D有乘警值乘的)验证同意后方可登乘。
A. 身份证
B. 驾驶证
C. 乘车证
D. 工作证
【单选题】
动车组司机室的登乘人数,除特殊情况外,不得超过___人。同一系统每次只准许1人登乘。
A. 1
B. 2
C. 3
D. 4
【单选题】
登乘人员须在动车组始发站提前___分钟C或随值乘司机进入动车组司机室(C司机室有侧门的,必须通过侧门进入司机室)。
A. 5
B. 10
C. 15
D. 20