【单选题】
Which option is the cloud-based security service from Cisco the provides URL filtering, web browsing content security, and roaming user protection?___
A. Cloud Web service
B. Cloud Advanced Malware Protection
C. Cloud We b Security
D. Cloud Web Protection
查看试卷,进入试卷练习
微信扫一扫,开始刷题
答案
C
解析
暂无解析
相关试题
【单选题】
How can you detect a false negative on an IPS?___
A. View the alert on the ips
B. Review the ips log
C. Review the is console
D. Use a third- party system to perform penetration testing.
E. Use a third- party to audit the next generation firewall rules
【单选题】
If a switch port goes directly into a blocked state only when a superior BPDU is received, what mechanism must be in use?___
A. STP BPDU guard
B. Loop guard
C. EtherChannel guard
D. STP Root guard
【单选题】
what improvement does EAP-FASTv2 provide over EAP-FAST? ___
A. It allows multiple credentials to be passed in a single EAP exchange.
B. It supports more secure encryption protocols
C. It allows faster authentication by using fewer packets.
D. It addresses security vulnerabilities found in the original protocol
【单选题】
When users login to the Client less Ssl Vpn using https://209.165.201.2/test ,which group policy will be applied?___
A. test
B. clientless
C. sales
D. DfitGrp Policy
E. Default RAGroup
F. Default WEB VPN
G. roup
【单选题】
Which user authentication method is used when users login to the Clientless SSLVPN portal using https://209.165.201.2/test?___
A. AAA with LOCAL database
B. AAA with RADIUS server
C. Certificate
D. :Both Certificate and aaa with LoCAL database
E. Both Certificate and AAA with RADIUS server
【单选题】
What' s the technology that you can use to prevent non malicious program to runin the computer that is disconnected from the network?___
A. Firewall
B. Sofware Antivirus
C. Network IPS
D. Host IPS
【单选题】
Which statement about the communication between interfaces on the same security level is true?___
A. Interfaces on the same security level require additional configuration to permit interinterface communication
B. Configuring interfaces on the same security level can cause asymmetric routing
C. All traffic is allowed by default between interfaces on the same security level
D. You can configure only one interface on a n individual security level
【单选题】
Which product can be used to provide application layer protection for tcp port 25 traffic?___
A. ESA
B. CWS
C. WSA
D. ASA
【单选题】
which iPS mode is less secure than other options but allows optimal network through put ?___
A. inline mode
B. inline-bypass mode
C. transparent mode
D. Promiscuous mode
【单选题】
Which feature of the Cisco Email security Appliance can mitigate the impact of snowshoe spam and sophisticated phishing attack?___
A. reputation based filtering
B. signature based IPS
C. contextual analysis
D. graymail management and filtering
【单选题】
Which type of social-engineering attack uses normal tele phone service as the attack vector?___
A. smishing
B. dialing
C. phishing
D. vishing
【单选题】
Which quantifiable item should you consider when you organization adopts new technologies?___
A. exploits
B. vulnerability
C. threat
D. Risk
【单选题】
Referencing the ClA model, in which scenario is a hash- only function most appropriate ?___
A. securing data at rest
B. securing real-time traffic
C. securing data in files
D. securing wireless transmissions
【单选题】
Which ports must be open between a aaa server and a microsoft server to permit Active Directory authentications?___
A. 445 and 389
B. 888 and 3389
C. 636 and 4445
D. 363 and 983
【单选题】
Refer to the exhibit for which reason is the tunnel unable to pass traffic___
A. the tunnel is failing to receive traffic from the remote peer
B. the local peer is unable to encrypt the traffic
C. the ip address of the remote peer is incorrect
D. UDP port 500 is blocked
【单选题】
Which type of attack can exploit design flaws in the implementation of an application without___
A. DHCP starvation attacks
B. low-rate dos attacks
C. application DDos flood attacks
D. application DDoS flood attacks
E. volume-based DDoS attacks
【单选题】
How can you protect CDP from reconnaissance attacks?___
A. Enable dynamic ARP inspection on all untrusted ports.
B. Enable dot1x on all ports that are connected to other switches.
C.
D. isable CDP on ports connected to endpoints.
【单选题】
Which type of attack can exploit design flaws in the implementation of an application without ?___
A. DHCP starvation attacks
B. low-rate dos attacks
C. application DDos flood attacks
D. application DDoS flood attacks
E. volume-based DDoS attacks
【单选题】
Which option is a key security compone nt of and MDM deployment ?___
A. using network-specific installer packages
B. using an application tunnel by default
C. using self-signed certificates to validate the server
D. using MS-CHAPv2 as the primary
E. AP method
【单选题】
Which Firepower Management Center feature detects and block exploits and hack attempts?___
A. Content blocker
B. file control
C. intrusion prevention
D. advanced malware protection
【单选题】
hich description of the nonsecret numbers that are used to start a Diffie- Hellman exchange is ture?___
A. They are preconfigured prime integers.
B. They are large pseudorandom numbers.
C. They are very small numbers chosen from a table of known valuses
D. They are numeric values extracted from ha shed system hostnames
【多选题】
Which two characteristics of an application layer firewall are true?___
A. provides stateful firewal functionality
B. has low processor usage
C. provides protection for multiple applications
D. provides rever se proxy services
E. is immune to URL manipulation
【多选题】
Which two devices are components of the BYOD architectural framework?___
A. Nexus 7010 switch
B. Cisco 3945 Router
C. Identify Services Engine
D. Wireless Access oints
E. Prime Infrastructure
【多选题】
Which two actions can a zone based firewall take when looking at traffic? ___
A. forward
B. inspect
C. drop
D. broadcast
E. filter
【多选题】
n which two situations should you use in-band management?___
A. when management applications need concurrent access to the device
B. when you require administrator access from multiple locations
C. when a network device fails to forward packets
D. when you require ROMMON access
E. when the control plane fails to respond
【多选题】
What are two ways to prevent eavesdropping when you perform device management tasks?___
A. Use an SSH connection.
B. Use SNMPv3
C. Use out-of-band management
D. Use SNMP
E. Use in-band management
【多选题】
Which two features are commonly used CoPP and CPPr to protect the control plane? ___
A. QoS
B. traffic classification
C. access lists
D. policy maps
E. class maps
F. Cisco Express Forwarding
【多选题】
Which four tunne ling prot ocols are enabled in the Dfit GrpPolicy group policy ?___
A. Clientless SSL VPN
B. SSL VPN Client
C. PPTP
D. L2TP/IPsec
E. IPsec IKEv1
F. IPsec IKEv2
【多选题】
Which two statements regarding the aSA VPN configurations are correct?___
A. The asa has a certificate issued by an external certificate authority associated to the ASDM TrustPoint1
B. The Default WEBVPNGroup Connection Profile is using the aaa with RADIUS server method
C. The Inside-srvbook mark references the https://192.168.1.2url
D. Only Clientless SSL VPN access is allowed with the Sales group policy
E. Any Connect, IPSec IKEv1, and IPSec IKEv2 VPN access is enabled on the outside interface
F. The Inside -SRV bookmark has not been applied to the Sales group policy
【多选题】
Which three ESP fields can be encrypted during transmission?___
A. Security Parameter Index
B. Sequence Number
C. MAC Address
D. Padding
E. Pad length
F. Next Header
【多选题】
.Which three statements de scribe DHCP spoofing attacks?___
A. They can modify traffic in transit.
B. They are used to perform man- in-the-middle attacks
C. They use ARP poisoning
D. They can access most network devices
E. They protect the ide ntity of the attacker by masking the DHCP address.
F. They are can physically modify the network gateway.
【多选题】
Which statement about the communication between interfaces on the same security level is true?___
A. Interfaces on the same security level require additional configuration to permit interinterface communication
B. Configuring interfaces on the same security level can cause asymmetric routing
C. All traffic is allowed by default between interfaces on the same security level
D. You can configure only one interface on a n individual security level
【多选题】
In which two situations should you use in band management? ___
A. when the control plane fails to respond
B. when you require administrator access from multiple locations
C. when you require ROMMON access.
D. where a network device fails to forward packets
E. when multiple ma nagement applications need concument access to the device.
【多选题】
Which two features are supported in a VRF-aware softwar infrastructure before VRF-lite?___
A. multicast
B. fair queuing
C. WCCP
D.
E. IGRP
【多选题】
.Which loS command do you enter to test authentication again a AAA server?___
A. dialer aaa suffix <suffix> password <password>
B. ppp authentication chap pap test
C. test aaa-server authentication dialer group user name <user> password <password>
D. aaa authentication enable default test group tacases
【多选题】
Which two statements about the self zone on a cisco Xone based policy firewall are true?___
A. Multiple interfaces can be assigned to the self zone
B. it supports stateful inspections for multicast traffic
C. zone pairs that include the self zone apply to traffic transiting the device.
D. it can be either the source zone or the destination zone
E. traffic entering the self zone must match a rule
【多选题】
Which type of attack can exploit design flaws in the implementation of an application without ?___
A. DHCP starvation attacks
B. low-rate dos attacks
C. application DDos flood attacks
D. application DDoS flood attacks
E. volume-based DDoS attacks
【单选题】
Which type of firewall can server as the interme diary between a client and a server ?___
A. Stateless firewall
B. application firewall
C. proxy firewall
D. personal firewall
【单选题】
What is the highest security level that can be configured for an interface on an ASA?___
A. 0
B. 50
C. 10
D. 200
【单选题】
Which term refers to the electromagnetic interference that can radiate from network cables?___
A. Gaussian distributions
B. Doppler waves
C. emanations
D. multimode distortion
推荐试题
【判断题】
检验不合格的进口固体废物,进口者或者承运人可以选择放弃。
A. 对
B. 错
【判断题】
重点固体废物可以与非重点固体废物混装于同一集装箱内。
A. 对
B. 错
【判断题】
配备H986设备的海关,查验危险品时优先采用机检方式。
A. 对
B. 错
【判断题】
为加强进口葡萄酒管理,查验人员在填写《海关货物查验记录单》以及录入查验结果时,须记录所查葡萄酒的容器容积和年份等信息。
A. 对
B. 错
【判断题】
查验工具车是指配备海关专用监管检查技术设备,喷涂海关徽记,用于执行海关监管任务的专用车辆。
A. 对
B. 错
【判断题】
查验工具箱专用于海关查验现场,辅助查验关员对货物进行查验。
A. 对
B. 错
【判断题】
金属探测仪不能用于对孕妇实施探测。
A. 对
B. 错
【判断题】
对讲机通话不得有涉密内容。
A. 对
B. 错
【判断题】
录证设备主要指照相机、摄像机、录音笔等具备采集、保存图像或影音信息功能的设备。
A. 对
B. 错
【判断题】
录证设备采集的资料应能详尽的反映相关事件的全部过程和整体情况。
A. 对
B. 错
【判断题】
现场使用防爆罐进行防护作业时,应将爆炸疑似物安全放入防爆罐罐体中,并迅速加盖盖子。
A. 对
B. 错
【判断题】
海关配发的有毒生物化学品防护服,包括防护上衣、防护裤子、防护面具、防护手套、防护靴套等,可有效防御各种蒸汽状和小液体毒剂对人体的伤害。
A. 对
B. 错
【判断题】
海关监管车辆的电子车牌等同于车辆牌照号。
A. 对
B. 错
【判断题】
集装箱箱号识别设备发生箱号识别错误时,卡口值守人员应以手工方式录入集装箱号。
A. 对
B. 错
【判断题】
设置地磅的监管现场,货运量小于地磅运作负荷的,应逐票过磅。
A. 对
B. 错
【判断题】
进出境物品申报手续应由旅客本人填写申报单证向海关办理,不可以委托他人。
A. 对
B. 错
【判断题】
在过境期限内离开海关监管区的过境旅客,携带的行李物品中属于《旅客进出境行李物品分类表》第三类物品的,海关不予放行。
A. 对
B. 错
【判断题】
香港人张某获准在我国内地定居,他可以申请免税进境自用摩托车1辆。
A. 对
B. 错
【判断题】
访问学者在外进修1年以上回国工作的,可免税进口汽车1辆。
A. 对
B. 错
【判断题】
登山用氧气设备不属于《中华人民共和国海关关于境外登山团体和个人进出境物品管理规定》所列“特准进口物品”范围。
A. 对
B. 错
【判断题】
驻华使馆人员进境自用物品以直接需用数量为限,该数量由海关核准。
A. 对
B. 错
【判断题】
列入禁止进境范围的所有物品,禁止出境。
A. 对
B. 错
【判断题】
濒危植物限制进境,但其繁殖材料除外。
A. 对
B. 错
【判断题】
大麻属于精神药品。
A. 对
B. 错
【判断题】
散发性宗教类印刷品及音像制品,是指运输、携带、邮寄进境,不属于自用、合理数量范围并且具有明显传播特征,违反国家宗教事务法规及有关政策的印刷品及音像制品。
A. 对
B. 错
【判断题】
旅客携带珍贵文物出境,经国家主管部门批准并发给证明,海关准予放行。
A. 对
B. 错
【判断题】
未向海关申报携运文物出口,虽无藏匿情节,亦属走私行为。
A. 对
B. 错
【判断题】
人民币既属于限制进境物品,又属于限制出境物品。
A. 对
B. 错
【判断题】
旅客携带金银入境,申报数量不受限制。
A. 对
B. 错
【判断题】
对旅客携带入境的美元有价证券,海关不予管理。
A. 对
B. 错
【判断题】
旅检现场没收的犀牛角和虎骨,海关应当作销毁处理。
A. 对
B. 错
【判断题】
旅客携带伴侣猫进境向海关申报时,应当交验输出国官方兽医检疫机关出具的检疫证书和狂犬病免疫证书。
A. 对
B. 错
【判断题】
某旅客携带单行本文学书籍20册入境,海关予以免税验放。
A. 对
B. 错
【判断题】
外国国宾代表团入境访问结束后,随行记者应及时将采访器材复运出境。
A. 对
B. 错
【判断题】
外国短期来华采访记者采访活动结束后,应及时将采访器材复运出境,并在出境地海关办理担保函或保证金结案手续。
A. 对
B. 错
【判断题】
对旅客携带出境的羚羊角,海关凭质检总局核发的《允许出口证明书》放行。
A. 对
B. 错
【判断题】
旅客携带人体血液制品进出境,海关严格凭检验检疫部门的批件或证书办理验放手续。
A. 对
B. 错
【判断题】
无线电收发信机不属于限制进境物品。
A. 对
B. 错
【判断题】
居民旅客携带一个价值8000元人民币的LV手提包进境,经海关审核需全额征税。
A. 对
B. 错
【判断题】
对于实际购买价格是《中华人民共和国进境物品完税价格表》列明完税价格1/2以下的应税进境物品,海关可以另行确定完税价格。
A. 对
B. 错