【多选题】
choose four___
A. DHCP snooping ——————————blocks DHCP messages
B. Dynamic ARP inspection——————verifies IP-to-MAC traffic on untrusted ports
C. IP sources guard ——————————provides layer 2 interface security with ports ACLs
D. Port security————————————mitigates MAC-address spoofing at the access interface
查看试卷,进入试卷练习
微信扫一扫,开始刷题
答案
ABCD
解析
暂无解析
相关试题
【多选题】
choose four___
A. Step1————————run the system setup wizard
B. Step2————————add an authentication realm
C. Step3————————configure identity management
D. Step4————————configure directory group
【多选题】
What are two advanced features of the Cisco AMp solution for endpoints ___
A. contemplation
B. foresight
C. sandboxing
D. reputation
E. reflection
【多选题】
Which two characteristics of RADIUS are true?___
A. It encrypts only the password between user and server.
B. It uses TCP ports 1812/1813
C. It uses UDP ports 1812/1813.
D. It uses UDP port 49
E. It uses TCP port 49
【多选题】
What are two challenges of using a network-based IPS? ___
A. It is unable to determine whether a detected attack was successful
B. It requires additional storage and proce ssor capacity on syslog servers
C. As the network expands, it requires you to add more sensors.
D. It is unable to detect attacks across the entire network
E. It must support multiple operating systems.
【多选题】
What are two default be haviors of the traffic on a zone-based firewall?___
A. Traffic within the self -zone uses an im plicit deny all.
B. All traffic between zones is implicitly blocked
C. Communication is allowed between interfadAss that are members of the same zone
D. Communication is blocked between interfaces that are members of the same zone
E. The CBAC rules that are configured on router interfaces apply to zone interfaces
【多选题】
Which two advantages does the on-premise model for MDM deployment have over the cloud-based model?___
A. The on-premise model is easier and faster to de ploy than the cloud-based model
B. The on-premise model is more scalable than the cloud-based model
C. The on-premise model is generally less expensive than the cloud-based model
D. The on-premise model generally has less latency than the cloud- based model.
E. The on-premise model provides more control of the MDM solution than the cloud
【多选题】
Which two actions can an end usts take to manage a lost or stolen device in Cisco ISE? ___
A. Activate Cisco ISE End point Protection Services to quarantine the device.
B. Add the mac address of the device to a list of blacklisted devices
C. Force the device to be locked with a PIN
D. Request revocation of the digital certificate of the device.
E. Reinstate a device that the user previously marked as lost or stolen
【多选题】
Which two problems can arise when a proxy firewall serves as the gateway between networks?___
A. It can prevent content caching
B. It can limit application support
C. It is unable to prevent direct connections to other networks
D. It can cause reduced throughput.
E. It is unable to provide antivirus protection
【多选题】
When using the Adaptive Security Device Manager(ASDM), which two methods are available to add a new root certificate?___
A. Use sCep
B. Install from SFTP server
C. Install from a file
D. Use Https
E. Use LDAP
【多选题】
Which two are considered basic security principles?___
A. Accountability
B. Redundancy
C. High Availabilit
D. Integrity
E. Confidentiality
【多选题】
Which two roles of the Cisco WSA are true?___
A. IPS
B. firewall
C. antispam
D. web proxy
E. URL filter
【单选题】
Which next-generation encryption algorithm supports four variants?___
A. SHA-2
B. SHA-1
C. MD5
D. HMAC
【单选题】
What aims to remove the abil ity to deny an action?___
A. Non-Repudiation
B. Accountability
C. Integrity
D. Deniability
【单选题】
Which statements about the native VLAN is true ?___
A. It is susceptible to VLAN hopping attacks.
B. It is the Cisco recommended VLAN for switch-management traffic
C. It is most secure when it is a ssigned to vLAn 1.
D. It is the cisco-recomme nded vlan for user traffic
【单选题】
There are two versions of IKE:IKEv1 and IKEv2. Both IKEv1 and IKEv2 protocols operate in phases IKEv1 operates in two phases. IKEv2 operates in how many phases?___
A. 2
B. 3
C. 4
D. 5
【单选题】
What does the dh group refer to?___
A. length of key for hashing C
B. length of key for encryption
C. tunnel lifetime key
D. length of key for key exchange
E. length of key for authentication
【单选题】
Which path do you follow to enable aaa through the SDM ?___
A. Configure Tasks > AAA
B. Configure > Addition Authentication > AAA
C. Configure > AAA
D. Configure > Additional Tasks > AAA
E. Configure Authentication > AAA
【单选题】
which technology cloud be used on top of an MPLS VPN to add confidentiality ?___
A. IPsec
B. 3DES
C. AES
D. SSL
【单选题】
Which term is most closely aligned with the basic purpose of a SIEM solution? ___
A. Non-Repudiation
B. Accountability
C. Causality
D. Repudiation
【单选题】
You have just deployed SNMPv3 in your environment, Your manager asks you to make sure that our SNMP agents can only talk to the SNMP Manager. What would you configure on your SNMI agents to satisfy this request?___
A. A SNMP View containing the SNMP managers
B. Routing Filter with the SNMP managers in it applied outbound
C. A standard ACL containing the SNMP managers applied to the SNMP configuration
D. A SNMP Group containing the SNMP managers
【单选题】
Which feature prevents loops by moving a nontrunking port into an errdisable state when a BPDU is received on that port?___
A. BPDU filte
B. DHCP snooping
C. BPDU guard
D. Port Fast
【单选题】
Which command enables port security to use sticky MAC addresses on a switch?___
A. switchport port-security violation restrict
B. switchport port-security mac-address sticky
C. switchport port-security violation protect
D. switchport port-security
【单选题】
When you edit an IPS subsignature, what is the effect on the parent signature and the family of subsignatures?___
A. The change applies to the parent signature and the entire family of subsignatures
B. The change applies to the parent signature and the subsignature that you edit
C. The change applies only to subsignatures that are numbered sequentially after the subsignature that you edit
D. Other signatures are unaffected, the change applies only to the subsignature that you dit
【单选题】
Which type of mechanism does Cisco FirePOWER de ploy to protect ag detected moving across other networks?___
A. antivirus scanning
B. policy-based
C. reputation-based
D. signature-based
【单选题】
What action must you take on the ise to blacklist a wired device?___
A. Locate the switch through which the device is connected and push an a cl restricting all access by the device
B. Issue a CoA request for the de vice's mac address to each access switch in the network
C. Revoke the device's certificate so it is unable to authenticate to the network
D. Add the device's MAc address to a list of black listed devices
【单选题】
Which type of firewall can perform deep packet inspection?___
A. packet-filtering firewall
B. stateless firewall
C. application firewall
D. personal firewall
【单选题】
What is the main purpose of Control Plane Policing?___
A. to prevent exhaustion of route-proce ssor resources
B. to organize the egress packet queues
C. to define traffic classes
D. to maintain the policy map
【单选题】
Which attack can be prevented by OSPF authentication?___
A. smurf attack
B. IP spoofing attack
C. denial of service attack
D. buffer overflow attack
【单选题】
What is the best definition of hairpinning?___
A. ingress traffic that traverses the outbound interface on a device
B. traffic that enters one interface on a device and that exits through another interface
C. traffic that enters and exits a device through the same interface
D. traffic that tunnels through a device interface
【单选题】
Which SNMPv3 security level provides authentication using HMAC with MD5, but does not use encryption?___
A. authPriv
B. authNo Priv
C. noAuthNoPriv
D. NoauthPriv
【单选题】
You have implemented a dynamic blacklist, using security intelligence to block illicit network activity. However, the blacklist contains several approved connections that users must access for usiness pur poses. Which action can you take to retain the blacklist while allowing users to access the approve d sites?___
A. Create a whitelist and manually add the approved addresses.
B. Disable the dynamic blacklist and deny the specif ic address on a whitelist while permitting the others
C. Edit the dynamic blacklist to remove the approved addresses
D. Disable the dynamic blacklist and create a static blacklist in its place
【单选题】
When connecting to an external resource,you must change a source IP address to use one IP address from a range of 207.165.201.1 to 207.165.1.30. Which option do you implement ?___
A. dynamic source NAT that uses an IP ad dress as a mapped source
B. static destination NAT that uses a subnet as a real de stination
C. dynamic source NAT that uses a range as a mapped source
D. static destination NAT that uses a subnet as a real source
【单选题】
Refer to the exhibit. 【nat(ins,any)dynamic interface】Which ty pe of NaT is configured on a Cisco ASA?___
A. dynamic NAT
B. source identity NAT
C. dynamic PAT
D. identity twice NAT
【单选题】
Which mitigation technology for web-based threats prevents the removal of confidential data from the network?___
A. CTA
B. DCA
C. AMP
D. DLP
【单选题】
Refer to the exhibit. What is the effect of the given configuration?___
A. It establishes the preshared key for the switch
B. It establishes the preshared key for the firewall.
C. It establishes the preshared key for the Cisco ISE appliance
D. It establishes the preshared key for the router.
【多选题】
What are two major considerations when choosing between a SPAN and a TAP when plementing IPS?___
A. the type of analysis the iS will perform
B. the amount of bandwidth available
C. whether RX and TX signals will use separate ports
D. the way in which media errors will be handled
E. the way in which dropped packets will be handled
【多选题】
What are two direct-to-tower methods for redirecting web traffic to Cisco Cloud Web Security?___
A. third-party proxies
B. Cisco Catalyst platforms
C. Cisco NAC Agent
D. hosted PAC files
E. CiSco ISE
【多选题】
Which three descriptions of RADIUS are true? ___
A. It uses TCP as its transport protocol.
B. Only the password is encrypted
C. It supports multiple transport protocols
D. It uses UDP as its transport protocol
E. It combines authentication and authorization
F. It separates authentication,authorization,and accounting
【多选题】
Which two configurations can prevent VLAN hopping attack from attackers at VLAN 10?___
A. using switchport trunk native vlan 10 command on trunk ports
B. enabling BPDU guard on all access ports
C. creating VLAN 99 and using switchport trunk native vlan 99 command on trunk ports
D. applying ACl between VLAN
E. using switchport mode access command on all host ports
F. using switchport nonegotiate command on dynamic desirable ports
【多选题】
What are two features of transparent firewall mode ___
A. It conceals the presence of the firewall from attackers
B. It allows some traffic that is blocked in routed mode
C. It enables the aSA to perform as a router.
D. It acts as a routed hop in the network.
E. It is configured by default
推荐试题
【多选题】
用人单位应当优先采用有利于防治职业病和保护劳动者健康的( ),逐步替代职业病危害严重的技术、工艺、设备、材料。[2分] ___
A. 新技术
B. 新工艺
C. 新设备
D. 新材料
【多选题】
作业机具、安全工器具、个人防护用品、应急救援器材等应符合国家或行业标准的规定,并根据产品说明书、有关标准规范或实际情况定期进行( )或试验,对不符合要求的,应及时更换。[2分] ___
A. 检测
B. 检验
C. 检查
D. 核对
【多选题】
下列经施工单位向管道所在地县级人民政府主管管道保护工作的部门提出申请后 ,可进行的 施工作业有 ( )[2分] ___
A. 穿跨越管道的施工作业
B. 在管道线路中心线两侧各五米至五十米和本法第五十八条第一项所列管道附属设施周边一百米地域范围内 ,新建、 改建、 扩建铁路、 公路、河渠 ,架设电力线路 ,埋设地下电缆、光缆 ,设置安全接地体、避雷接地体
C. 在管道线路中心线两侧各二百米和本法第五十八条第一项所列管道附属设施周边五百米地域范围内 ,进行爆破、地震法勘探或者工程挖掘、工程钻探、采矿
D. 以上做法均不正确
【多选题】
《安全生产法》第六十五条规定,安全生产监督检查人员应当将检查的时间、地点、内容、发现的问题及其处理情况( )。[2分] ___
A. 作出书面记录
B. 检查人员签字
C. 被检查单位的负责人签字
D. 安全管理部门负责人签字
【多选题】
《职业病防治法》所称职业病,是指( )和( )组织等用人单位的劳动者在职业活动中,因接触粉尘、放射性物质和其他有毒、有害因素而引起的疾病。[2分] ___
A. 企业
B. 事业单位
C. 个体经济 正确答案:ABC
【多选题】
下列属于禁止危害管道安全的行为有 :( )[2分] ___
A. 擅自开启、关闭管道阀门
B. 采用移动、切割、打孔、砸撬、拆卸等手段损坏管道
C. 移动、毁损、涂改管道标志
D. 在埋地管道上方巡查便道上行驶重型车辆
【多选题】
职业病防治工作坚持预防为主、防治结合的方针,建立( )和社会监督的机制,实行分类管理、综合治理。[2分] ___
A. 用人单位负责
B. 行政机关监管
C. 行业自律
D. 职工参与
【多选题】
《安全生产法》第一条明确了制定《安全生产法》目的是为了加强安全生产工作,杜绝生产安全事故,保障人民群众( )安全,促进经济社会持续健康发展,制定本法。[2分] ___
A. 生命
B. 财产
C. 健康 正确答案:AB
【判断题】
《安全生产法》第八十二条规定,参与事故抢救的部门和单位应当听从本部门和单位领导的指示,各个击破采取有效的应急救援措施,减少人员伤亡和财产损失。[1分]
A. 对
B. 错
【判断题】
《安全生产法》第二十七条规定,生产经营单位的特种作业人员必须按照国家有关规定经专门的安全作业培训,取得相应资格,方可上岗作业。[1分]
A. 对
B. 错
【判断题】
《安全生产法》第二十三条规定,生产经营单位不得因安全生产管理人员依法履行职责而降低其工资、福利等待遇或者解除与其订立的劳动合同。[1分]
A. 对
B. 错
【判断题】
《安全生产法》第二十三条规定,生产经营单位作出涉及安全生产的经营决策,应当听取安全生产管理机构以及安全生产管理人员的意见。[1分]
A. 对
B. 错
【判断题】
《安全生产法》第二十五条规定,劳务派遣单位应当对被派遣劳动者进行必要的安全生产教育和培训。生产经营单位使用被派遣劳动者的,不必对被派遣劳动者进行岗位安全操作规程和安全操作技能的教育和培训。[1分]
A. 对
B. 错
【判断题】
《安全生产法》第九条规定,国务院安全生产监督管理部门对全国安全生产工作实施管理。[1分]
A. 对
B. 错
【判断题】
《安全生产法》第六十二条规定,安全生产监督管理部门对检查中发现重大事故隐患排除前或者排除过程中无法保证安全的,应当提醒作业人员从危险区域内撤出。[1分]
A. 对
B. 错
【判断题】
《安全生产法》第七十一条规定,任何单位和个人对事故隐患或者安全生产违法行为,均有权向负有安全生产监督管理职责的部门报告或者举报。[1分]
A. 对
B. 错
【判断题】
《安全生产法》第三十一条规定,生产、使用、储存危险物品的建设项目竣工投入生产或者使用前,应当由建设单位负责组织对安全设施进行验收;验收合格后,方可投入生产和使用。[1分]
A. 对
B. 错
【判断题】
《安全生产法》第三条规定, 安全生产工作应当以人为本,坚持科学发展,坚持安全第一、预防为主的方针,强化和落实生产经营单位的主体责任,建立生产经营单位负责、职工参与、政府监管、行业自律和社会监督的机制。[1分]
A. 对
B. 错
【判断题】
《安全生产法》第十九条规定,生产经营单位应当建立相应的机制,加强对安全生产责任制落实情况的监督管理,保证安全生产责任制的落实。[1分]
A. 对
B. 错
【判断题】
《安全生产法》第四十八条规定,目前国家不强制要求生产经营单位投保安全生产责任保险。[1分]
A. 对
B. 错
【判断题】
《安全生产法》第四十八条规定,生产经营单位必须依法参加工伤保险,为从业人员缴纳保险费。[1分]
A. 对
B. 错
【判断题】
《安全生产法》第四十五条规定,两个以上生产经营单位在同一作业区域内进行生产经营活动,可能危及对方生产安全的,应当签订安全生产管理协议,明确各自的安全生产管理职责和应当采取的安全措施,并指定专职安全生产管理人员进行安全检查与协调。[1分]
A. 对
B. 错
【判断题】
《安全生产法》第五条规定, 生产经营单位的主要负责人对本单位的安全生产工作全面负责。[1分]
A. 对
B. 错
【判断题】
《安全生产法》规定,从业人员有权对本单位安全生产工作中存在的问题提出整改。[1分]
A. 对
B. 错
【判断题】
《临时/应急抢修单》可由现场监护人签发。[1分]
A. 对
B. 错
【判断题】
《侵权责任法》第 66 条规定因污染环境发生纠纷 ,污染者应当就法律规定的不承担责任或者 减轻责任的情形及其行为与损害之间不存在因果关系承担赔偿责任。 ( )[1分]
A. 对
B. 错
【判断题】
《石油天然气管道保护法》中所称的管道附属设施中不包括管道穿越铁路、公路的检漏装置。 ( )[1分]
A. 对
B. 错
【判断题】
《职业病防治法》第二十条规定,用人单位应当采取下列职业病防治管理措施:设置或者指定职业卫生管理机构或者组织,配备专职或者兼职的职业卫生管理人员,负责本单位的职业病防治工作。[1分]
A. 对
B. 错
【判断题】
《职业病防治法》第六十一条规定,用人单位已经不存在或者无法确认劳动关系的职业病病人,可以向地方人民政府医疗保障、民政部门申请医疗救助和生活等方面的救助。[1分]
A. 对
B. 错
【判断题】
《职业病防治法》第七条规定,用人单位必须依法参加工伤保险。[1分]
A. 对
B. 错
【判断题】
《职业病防治法》第三十四条规定,用人单位应当对劳动者进行上岗前的职业卫生培训和离岗期间的定期职业卫生培训,普及职业卫生知识,督促劳动者遵守职业病防治法律、法规、规章和操作规程,指导劳动者正确使用职业病防护设备和个人使用的职业病防护用品。[1分]
A. 对
B. 错
【判断题】
安规所称工作是指从事浙能集团所属输气管道调度、运行、维(检、抢)修、检测、检验、试验、技术改造和改(扩)建工程施工等职务行为。[1分]
A. 对
B. 错
【判断题】
安规所称特殊作业是指涉及输气管道安全运行并具有较大作业风险的动火作业、受限空间作业、货梯升降作业、高处作业、起重作业、管线打开作业、临时用电作业。[1分]
A. 对
B. 错
【判断题】
安规所称驻守站是指无人值班、有人值守的站场。[1分]
A. 对
B. 错
【判断题】
报废管道安全防护措施备案后,如现场情况发生变化,应进行修改、调整,整改后不需再备案。( )[1分]
A. 对
B. 错
【判断题】
不准在带有压力(液体压力或气体压力)或带电的设备上进行焊接、气割;在特殊情况下必须在带压和带电设备上进行焊接、气割时,应采取安全措施,并经总经理批准。[1分]
A. 对
B. 错
【判断题】
不准在基坑、沟槽内休息,但可以在升降设备、挖掘设备下方或基坑、沟槽上端边沿站立、走动。[1分]
A. 对
B. 错
【判断题】
采用非常规起重设备、方法,且单件起吊重量在0.5吨及以上的起重吊装工程应编制专项施工方案。[1分]
A. 对
B. 错
【判断题】
采用空气对管道进行通风前,无须对管道内介质进行分析确认。[1分]
A. 对
B. 错
【判断题】
拆除管线的动火作业,必须先查明内部介质及其走向,并制定相应的安全防火措施。[1分]
A. 对
B. 错