【单选题】
If a switch port goes directly into a blocked state only when a superior BPDU is received, what mechanism must be in use?___
A. STP BPDU guard
B. Loop guard
C. EtherChannel guard
D. STP Root guard
查看试卷,进入试卷练习
微信扫一扫,开始刷题
答案
D
解析
暂无解析
相关试题
【单选题】
what improvement does EAP-FASTv2 provide over EAP-FAST? ___
A. It allows multiple credentials to be passed in a single EAP exchange.
B. It supports more secure encryption protocols
C. It allows faster authentication by using fewer packets.
D. It addresses security vulnerabilities found in the original protocol
【单选题】
When users login to the Client less Ssl Vpn using https://209.165.201.2/test ,which group policy will be applied?___
A. test
B. clientless
C. sales
D. DfitGrp Policy
E. Default RAGroup
F. Default WEB VPN
G. roup
【单选题】
Which user authentication method is used when users login to the Clientless SSLVPN portal using https://209.165.201.2/test?___
A. AAA with LOCAL database
B. AAA with RADIUS server
C. Certificate
D. :Both Certificate and aaa with LoCAL database
E. Both Certificate and AAA with RADIUS server
【单选题】
What' s the technology that you can use to prevent non malicious program to runin the computer that is disconnected from the network?___
A. Firewall
B. Sofware Antivirus
C. Network IPS
D. Host IPS
【单选题】
Which statement about the communication between interfaces on the same security level is true?___
A. Interfaces on the same security level require additional configuration to permit interinterface communication
B. Configuring interfaces on the same security level can cause asymmetric routing
C. All traffic is allowed by default between interfaces on the same security level
D. You can configure only one interface on a n individual security level
【单选题】
Which product can be used to provide application layer protection for tcp port 25 traffic?___
A. ESA
B. CWS
C. WSA
D. ASA
【单选题】
which iPS mode is less secure than other options but allows optimal network through put ?___
A. inline mode
B. inline-bypass mode
C. transparent mode
D. Promiscuous mode
【单选题】
Which feature of the Cisco Email security Appliance can mitigate the impact of snowshoe spam and sophisticated phishing attack?___
A. reputation based filtering
B. signature based IPS
C. contextual analysis
D. graymail management and filtering
【单选题】
Which type of social-engineering attack uses normal tele phone service as the attack vector?___
A. smishing
B. dialing
C. phishing
D. vishing
【单选题】
Which quantifiable item should you consider when you organization adopts new technologies?___
A. exploits
B. vulnerability
C. threat
D. Risk
【单选题】
Referencing the ClA model, in which scenario is a hash- only function most appropriate ?___
A. securing data at rest
B. securing real-time traffic
C. securing data in files
D. securing wireless transmissions
【单选题】
Which ports must be open between a aaa server and a microsoft server to permit Active Directory authentications?___
A. 445 and 389
B. 888 and 3389
C. 636 and 4445
D. 363 and 983
【单选题】
Refer to the exhibit for which reason is the tunnel unable to pass traffic___
A. the tunnel is failing to receive traffic from the remote peer
B. the local peer is unable to encrypt the traffic
C. the ip address of the remote peer is incorrect
D. UDP port 500 is blocked
【单选题】
Which type of attack can exploit design flaws in the implementation of an application without___
A. DHCP starvation attacks
B. low-rate dos attacks
C. application DDos flood attacks
D. application DDoS flood attacks
E. volume-based DDoS attacks
【单选题】
How can you protect CDP from reconnaissance attacks?___
A. Enable dynamic ARP inspection on all untrusted ports.
B. Enable dot1x on all ports that are connected to other switches.
C.
D. isable CDP on ports connected to endpoints.
【单选题】
Which type of attack can exploit design flaws in the implementation of an application without ?___
A. DHCP starvation attacks
B. low-rate dos attacks
C. application DDos flood attacks
D. application DDoS flood attacks
E. volume-based DDoS attacks
【单选题】
Which option is a key security compone nt of and MDM deployment ?___
A. using network-specific installer packages
B. using an application tunnel by default
C. using self-signed certificates to validate the server
D. using MS-CHAPv2 as the primary
E. AP method
【单选题】
Which Firepower Management Center feature detects and block exploits and hack attempts?___
A. Content blocker
B. file control
C. intrusion prevention
D. advanced malware protection
【单选题】
hich description of the nonsecret numbers that are used to start a Diffie- Hellman exchange is ture?___
A. They are preconfigured prime integers.
B. They are large pseudorandom numbers.
C. They are very small numbers chosen from a table of known valuses
D. They are numeric values extracted from ha shed system hostnames
【多选题】
Which two characteristics of an application layer firewall are true?___
A. provides stateful firewal functionality
B. has low processor usage
C. provides protection for multiple applications
D. provides rever se proxy services
E. is immune to URL manipulation
【多选题】
Which two devices are components of the BYOD architectural framework?___
A. Nexus 7010 switch
B. Cisco 3945 Router
C. Identify Services Engine
D. Wireless Access oints
E. Prime Infrastructure
【多选题】
Which two actions can a zone based firewall take when looking at traffic? ___
A. forward
B. inspect
C. drop
D. broadcast
E. filter
【多选题】
n which two situations should you use in-band management?___
A. when management applications need concurrent access to the device
B. when you require administrator access from multiple locations
C. when a network device fails to forward packets
D. when you require ROMMON access
E. when the control plane fails to respond
【多选题】
What are two ways to prevent eavesdropping when you perform device management tasks?___
A. Use an SSH connection.
B. Use SNMPv3
C. Use out-of-band management
D. Use SNMP
E. Use in-band management
【多选题】
Which two features are commonly used CoPP and CPPr to protect the control plane? ___
A. QoS
B. traffic classification
C. access lists
D. policy maps
E. class maps
F. Cisco Express Forwarding
【多选题】
Which four tunne ling prot ocols are enabled in the Dfit GrpPolicy group policy ?___
A. Clientless SSL VPN
B. SSL VPN Client
C. PPTP
D. L2TP/IPsec
E. IPsec IKEv1
F. IPsec IKEv2
【多选题】
Which two statements regarding the aSA VPN configurations are correct?___
A. The asa has a certificate issued by an external certificate authority associated to the ASDM TrustPoint1
B. The Default WEBVPNGroup Connection Profile is using the aaa with RADIUS server method
C. The Inside-srvbook mark references the https://192.168.1.2url
D. Only Clientless SSL VPN access is allowed with the Sales group policy
E. Any Connect, IPSec IKEv1, and IPSec IKEv2 VPN access is enabled on the outside interface
F. The Inside -SRV bookmark has not been applied to the Sales group policy
【多选题】
Which three ESP fields can be encrypted during transmission?___
A. Security Parameter Index
B. Sequence Number
C. MAC Address
D. Padding
E. Pad length
F. Next Header
【多选题】
.Which three statements de scribe DHCP spoofing attacks?___
A. They can modify traffic in transit.
B. They are used to perform man- in-the-middle attacks
C. They use ARP poisoning
D. They can access most network devices
E. They protect the ide ntity of the attacker by masking the DHCP address.
F. They are can physically modify the network gateway.
【多选题】
Which statement about the communication between interfaces on the same security level is true?___
A. Interfaces on the same security level require additional configuration to permit interinterface communication
B. Configuring interfaces on the same security level can cause asymmetric routing
C. All traffic is allowed by default between interfaces on the same security level
D. You can configure only one interface on a n individual security level
【多选题】
In which two situations should you use in band management? ___
A. when the control plane fails to respond
B. when you require administrator access from multiple locations
C. when you require ROMMON access.
D. where a network device fails to forward packets
E. when multiple ma nagement applications need concument access to the device.
【多选题】
Which two features are supported in a VRF-aware softwar infrastructure before VRF-lite?___
A. multicast
B. fair queuing
C. WCCP
D.
E. IGRP
【多选题】
.Which loS command do you enter to test authentication again a AAA server?___
A. dialer aaa suffix <suffix> password <password>
B. ppp authentication chap pap test
C. test aaa-server authentication dialer group user name <user> password <password>
D. aaa authentication enable default test group tacases
【多选题】
Which two statements about the self zone on a cisco Xone based policy firewall are true?___
A. Multiple interfaces can be assigned to the self zone
B. it supports stateful inspections for multicast traffic
C. zone pairs that include the self zone apply to traffic transiting the device.
D. it can be either the source zone or the destination zone
E. traffic entering the self zone must match a rule
【多选题】
Which type of attack can exploit design flaws in the implementation of an application without ?___
A. DHCP starvation attacks
B. low-rate dos attacks
C. application DDos flood attacks
D. application DDoS flood attacks
E. volume-based DDoS attacks
【单选题】
Which type of firewall can server as the interme diary between a client and a server ?___
A. Stateless firewall
B. application firewall
C. proxy firewall
D. personal firewall
【单选题】
What is the highest security level that can be configured for an interface on an ASA?___
A. 0
B. 50
C. 10
D. 200
【单选题】
Which term refers to the electromagnetic interference that can radiate from network cables?___
A. Gaussian distributions
B. Doppler waves
C. emanations
D. multimode distortion
【单选题】
How does a zone pair handle traffic if the policy de fination of the zone pair is missing?___
A. It inspects all traffic.
B. It drops all traffic.
C. It permits all traffic wihtout logging
D. It permits and logs all traffic
【单选题】
default how does a zone based firewall handle traffic to add from the self zone?___
A. It permits all traffic without inspection
B. It inspects all traffic to determine how it is handled
C. It permits all traffic after inspection
D. It frops all traffic
推荐试题
【单选题】
变压器箱、电缆盒的电缆配线,紧固在相应的端子上,芯线的长度需留有可做_______接头的余量。[321030203]___
A. 1次~2次
B. 2次~3次
C. 3~5次
D. 5次以上
【单选题】
自方向盒方向引来的电缆,进入电缆盒_______。[321030203]___
A. 防护管
B. 主管
C. 副管
D. 钢管
【单选题】
48芯星绞组电缆的备用芯数为_______。[311030203]___
A. 1对
B. 2对
C. 3对
D. 4对
【单选题】
16芯星绞组电缆的备用芯数为_______。[311030203]___
A. 1对
B. 2对
C. 3对
D. 4对
【单选题】
28芯星绞组电缆的备用芯数为_______。[311030203]___
A. 1对
B. 2对
C. 3对
D. 4对
【单选题】
61芯电缆,当音频与非音频设备合用同一电缆时,其中之_______作为非音频设备的备用芯线。[311030203]___
A. 1芯
B. 2芯
C. 3芯
D. 4芯
【单选题】
信号电缆与热力管、煤气管、燃料管交叉时,交叉点的垂直距离大于500mm时,可_______防护。[311030203]___
A. 用钢管
B. 不加
C. 用水泥管
D. 用陶瓷管
【单选题】
根据有关技术标准的规定,计算机联锁系统的安全度为_______。[321010105]___
A. 106h
B. 108h
C. 1010h
D. 1011h
【单选题】
TDCS站机显示器使用_______电源。[321010103]___
A. UPS
B. 非UPS
C. 照明
D. 自闭
【单选题】
信号电缆当其扭绞型式(星绞组+单芯线)为:14×4+5时,备用芯数为_______。[311030203]___
A. 3对
B. 3对+2芯
C. 2对+2芯
D. 5芯
【单选题】
根据计算,控制某组双动道岔所需的电缆芯线为11芯,这时应该选用_______电缆。[311030203]___
A. 12芯
B. 13芯
C. 14芯
D. 16芯
【单选题】
42芯综合扭绞信号电缆其备用芯线为_______。[311030203]___
A. 3芯
B. 4芯
C. 5芯
D. 7芯
【单选题】
信号电缆中的导电线芯,宜采用直径为_______的软铜线,其允许工作电压不低于工频500V或直流1000V。[311030203]___
A. 0.5mm
B. 1mm
C. 1.5mm
D. 2mm
【单选题】
信号电缆芯线备用量:12芯~21芯电缆备用_______。[311030203]___
A. 1芯
B. 2芯
C. 3芯
D. 4芯
【单选题】
电缆径路图中:196-48(6)<20>的表中,196表示_______。[322030204]___
A. 电缆长度
B. 电缆总芯数
C. 备用芯线数
D. 电缆编号
【单选题】
电缆径路图中:196-48(6)<20>的表中,20表示_______。[322030204]___
A. 电缆长度
B. 电缆总芯数
C. 备用芯线数
D. 电缆编号
【单选题】
电力电缆与信号电缆平行敷设时的间距应不小于_______。[321030203]___
A. 300mm
B. 400mm
C. 500mm
D. 600mm
【单选题】
采用接地的金属线槽或钢管防护的电力电缆与信号电缆平行敷设时的间距应不小于_______。[321030203]___
A. 300mm
B. 400mm
C. 500mm
D. 600mm
【单选题】
ZPW-2000A的匹配变压器变比为_______。[3212010103]___
A. 1:1
B. 9:1
C. 3:1
D. 6:1
【单选题】
雷害严重的站(场)或电子设备集中的区域,可在距电子设备和机房_______以外的地点安装多支独立避雷针和建筑物屋顶设置避雷带和避雷网。[321030205]___
A. 15m
B. 20m
C. 25m
D. 30m
【单选题】
防雷保安器接地线长度应不大于_______。[311030203]___
A. 800mm
B. 1000mm
C. 1200mm
D. 1500mm
【单选题】
用于电源电路的防雷保安器,应单独设置,应具有阻断续流的性能,工作电压在_______以上的应有劣化指示。[331010102]___
A. 60V
B. 80V
C. 110V
D. 220V
【单选题】
室外架空交流电源防雷保安器,冲击通流容量不小于20kA,限制电压应不大于_______。[331010101]___
A. 380V
B. 500V
C. 1000V
D. 1500V
【单选题】
电源防雷箱的的功率应不大于被保护设备总用电量的_______。[331010103]___
A. 1.2倍
B. 2倍
C. 2.2倍
D. 2.5倍
【单选题】
室内数据传输线长度在_______时,可在一端设备接口处设置防雷保安器。[332030203]___
A. 30m~50m
B. 50m~80m
C. 50m~100m
D. 60m~120m
【单选题】
室内数据传输线长度大于_______时,宜在两端设备接口处设置防雷保安器。[322030203]___
A. 50m
B. 80m
C. 100m
D. 120m
【单选题】
采集驱动信号传输线选用冲击通流量1.5kA,限制电压不大于_______的防雷保安器。[331010102]___
A. 60V
B. 80V
C. 110V
D. 220V
【单选题】
视频信号传输线选用冲击通流量1.5kA,限制电压不大于_______的防雷保安器。[331010101]___
A. 10V
B. 30V
C. 50V
D. 60V
【单选题】
交流轨道电路选用防雷保安器:工作电压小于36V时,限制电压应小于或等于_______。[331010101]___
A. 60V
B. 110V
C. 190V
D. 220V
【单选题】
交流轨道电路选用防雷保安器:工作电压36V~60V时,限制电压应小于或等于_______。[331010101]___
A. 220V
B. 330V
C. 350V
D. 380V
【单选题】
交流轨道电路选用防雷保安器:工作电压60V~110V时,限制电压应小于或等于_______。[331010101]___
A. 380V
B. 500V
C. 700V
D. 1000V
【单选题】
交流轨道电路选用防雷保安器:工作电压110V~220V时,限制电压应小于或等于_______。[331010101]___
A. 380V
B. 500V
C. 700V
D. 1000V
【单选题】
直流轨道电路选用防雷保安器:工作电压小于24V时,限制电压应小于或等于_______。[331010102]___
A. 60V
B. 75V
C. 110V
D. 220V
【单选题】
贯通地线在信号机房建筑物一侧每隔2m~3m用裸铜线与环形接地装置连接,两端各连接_______。[311030203]___
A. 一次
B. 两次
C. 三次
D. 四次
【单选题】
无线天线避雷针的接地装置应单独设置,并距环形接地装置_______以上。[311010103]___
A. 15m
B. 20m
C. 25m
D. 30m
【单选题】
无线天线避雷针的接地装置应单独设置,特殊情况下距环形接地装置不应小于_______。[311010103]___
A. 5m
B. 8m
C. 10m
D. 15m
【单选题】
ZPW-2000A无绝缘移频自动闭塞系统补偿电容采用_______进行现场设置。[312030201]___
A. △法
B. 每100m装一个
C. 等差法
D. 等间距法
【单选题】
ZC-8接地电阻测量仪在使用时,两接地棒即电位探针P'和电流探针C'沿直线相距_______。[322010103]___
A. 15m
B. 20m
C. 25m
D. 30m
【单选题】
S700K型电动转辙机因故不能转换到底时,电流一般不大于_______。[313010102]___
A. 1A
B. 3A
C. 5A
D. 8A
【单选题】
S700K电动转辙机的单线圈电阻不大于_______。[323010103]___
A. 50Ω
B. 54Ω
C. 58Ω
D. 64Ω