【多选题】
Which type of attack can exploit design flaws in the implementation of an application without ?___
A. DHCP starvation attacks
B. low-rate dos attacks
C. application DDos flood attacks
D. application DDoS flood attacks
E. volume-based DDoS attacks
查看试卷,进入试卷练习
微信扫一扫,开始刷题
答案
A
解析
暂无解析
相关试题
【单选题】
Which type of firewall can server as the interme diary between a client and a server ?___
A. Stateless firewall
B. application firewall
C. proxy firewall
D. personal firewall
【单选题】
What is the highest security level that can be configured for an interface on an ASA?___
A. 0
B. 50
C. 10
D. 200
【单选题】
Which term refers to the electromagnetic interference that can radiate from network cables?___
A. Gaussian distributions
B. Doppler waves
C. emanations
D. multimode distortion
【单选题】
How does a zone pair handle traffic if the policy de fination of the zone pair is missing?___
A. It inspects all traffic.
B. It drops all traffic.
C. It permits all traffic wihtout logging
D. It permits and logs all traffic
【单选题】
default how does a zone based firewall handle traffic to add from the self zone?___
A. It permits all traffic without inspection
B. It inspects all traffic to determine how it is handled
C. It permits all traffic after inspection
D. It frops all traffic
【单选题】
Which command should beused to ena ble AAA Authentication to determine if a user can access the privilege command level?___
A. aaa authentication enable local
B. aaa authentication enable level=
C. aaa authentication enable method de fault
D. aaa authentication enable defa ult local
【单选题】
On an ASA, the policy indicates that traffic should not be translated is often referred to as which of the following?___
A. NAT zero
B. NAT forward
C. NAT nul
D. NAT allow
【单选题】
Which protocol offers data Integrity encryption, authentication, and anti-replay functions for IPSec VPN?___
A. ESP protocol
B. IKEv3 Protocol
C. AH protoco
D. IKEv1 Protocol
【单选题】
Which component offers a variety of security Solution, including firwall, IF Antivirus and antiphishing features?___
A. Cisco loS router
B. Cisco ASA 5500 Ser ies security appliance
C. Cisco ASA 5500 X series Next Gen Security appliance
D. Cisco 4200 series IPS appliance
【单选题】
Refer to the exhibit, A Network Secur ity administrator check the ASa firewall NAT policy table rith show nat command, which statement is fails?___
A. There are only reverse translation matches for the REAL SERvER object
B. First policy in the Section 1 is a dynamic nat entry defined in the object configuration
C. NAT policy in section 2 is static entry de fined in the object configuration
D. Translation in Section 3 used when a connection does not matches any entries in first two sections
【单选题】
What is true of an aSa in transparent mode ?___
A. It supports OSPF
B. It requires an IP address for each interface
C. It requires a management IP address
D. It allows the use of dynamic NaT
【单选题】
What is the effect of the ip scp server enable command?___
A. It references an access list that allows specific SCP servers
B. It allows the router to initiate requests to an SCP server
C. It allows the router to become an SCP server
D. It adds SCP to the list of allowed copy functions
【单选题】
How can you mitigate attacks in which the attacker attaches more than one vLan tag to a packet?___
A. Assign an access VLAN to every active port on the switch
B. Disable Ether Channel on the switch
C. Explicitly identity each VLAN allowed across the trunk
D.
E. nable transparent VTP on the switch
【单选题】
Which technology can you implement to centrally mitigate potential threats when users on your network download files that might be malicious?___
A. Enable file-reputation services to inspect all files that traverse the company network and block files with low reputation scores
B. Verify that the compa ny IpS blocks all known malicious website
C. Verity that antivirus software is installed and up to date for all users on your network
D. Implement URL filtering on the perimeter firewall
【单选题】
What is the most common implementation of PaT in a standard networked environment?___
A. configuring multiple external hosts to join the self zo ne and to communicate with one another
B. configuring multiple internal hosts to communicate outside of the network using the outside interface IP address
C. configuring multiple internal hosts to communicate outside of the network by using the inside interface IP address
D. configuring an any any rule to enable external hosts to communicate inside the network
【单选题】
Which component of a bYod architecture provides aAa services for endpoint access ?___
A. Integrated Services Router
B. access point
C. ASA
D. Identity Services
E. ngine
【单选题】
You are configuring a NAT rule on a Cisco ASA ,Which description of a mapped interface is true?___
A. It is mandatory for all firewall modes
B. It is optional in routed mode
C. It is optional in transparent mode
D. It is mandatory for ide ntity NAT only
【单选题】
Which description of the use of a private key is true ?___
A. The sender signs a message using the receivers private key
B. The sender signs a message using their private key
C. The sender encrypts a message using the receivers private key
D. The receiver decrypts a n15ssage using the sender's private key
【单选题】
Which mechanism does the FireAMP Connector use to avoid conflicts with other security applications such as antivirus products ?___
A. Virtualization
B. Containers
C. Sandboxing
D.
E. xclusions
【单选题】
Which network to pology de scribes multiple LANS in a gec? ___
A. SOHO
B. MAN
C. pan
D. CAN
【单选题】
Which statement represents a difference between an access list on an aSa versus an access list on a router?___
A. The asa does not support number access lists
B. The aSa does not support standard access list
C. The asa does not ever use a wildcard mask
D. The asa does not support extended access lists
【单选题】
Which command do you enter to verify the status and settings of an iKE Phase 1 tunnel?___
A. show crypto ipsec as output
B. show crypto isakmp
C. show crypto isakmp policy
D. show crypto ipsec transform
【单选题】
Which feature can help a router or switch maintain packet forwarding and protocol states despite an attack or heavy traffic load on the router or switch?___
A. service Policy
B. Control Plane Policing
C. Policy Map
D. Cisco
E. xpress
F. orwarding
【单选题】
Which STP feature can prevent an attacker from becoming the root bridge by immediately shutting down the interface when it receives a BPDU?___
A. root guard
B. Port Fast
C. BPDU guard
D. BPDU filtering
【单选题】
Which technology can best protect data at rest on a user system?___
A. full-disk encryption
B. IPsec tunnel
C. router ACL
D. network IPS
【多选题】
Which two primary security concerns can you mitigate with a BYOD solution ?___
A. schedule for patching the device
B. securing access to a trusted corporate network
C. compliance with applicable policies
D. connections to public Wi-Fi networks
E. device tagging and invento
【多选题】
choose five___
A. MD5————————inserure
B. DES————————insercure
C. SDES———————legacy
D. SHA-1———————legacy
E. HMAC-MD5—————legacy
【多选题】
Which two characteristics of symmetric encryption are true?___
A. It uses digital certificates
B. It requires more resources than asymmetric ancryption
C. It uses the same key to enctypt and decrupt traffic
D. It uses a public key and a pricate key to encrypt and decrypt traffic.
E. It is faster than asymmetric encryption
【多选题】
which two characteristics of PVLAN are true?___
A. Promiscuous porta can communicate with PVLAN ports.
B. Isolated ports cannot communicate with other ports on the same VLAN
C. Community ports have to be a part of the trunk.
D. They require VTP to be enabled in server mode
E. PVLAN ports can be configured as Ether Channel ports
【多选题】
What are two options for running Cisco SDM?___
A. Running SDM from a mobile device
B. Running SDM from within CiscoWorks
C. Running SDM from a router's flash
D. Running SDM from the Cisco web porta
E. Running SDM from a PC
【多选题】
Which two options are the primary deployment modeles for mobile device management?___
A. multisite
B. cloud-based
C. on premises
D. hybrid cloud basedo
E. single site
【多选题】
Drag the recommendation on the left to the Cryptographic algorithms on the right, Options will be used more than once.___
A. Avoid——————————————DES,MD5
B. Legacy——————————————SDES,SHA1,HMAC-MD5
【多选题】
Which two are valid types of vLans using PVLANS ?___
A. Community VLAN
B. Backup VLAN
C. Secondary VLAN
D. Isolated VLAN
E. Isolated VLAN
【多选题】
Which two commands are used to implement Resilient lOS Configuration ___
A. Secure boot-config
B. copy running-config tftp
C. copy flash:ios bin tftp
D. copy running-config startup-config
E. secure boot-image
【多选题】
Which two types of firewalls work at layer 4 and above ?___
A. Stateful inspection
B. Network Address Translation
C. Circuit-Level gateway
D. Static packet filter
E. Application Level firewall
【多选题】
Which two default settings for port security are true ?___
A. Violation is Protect
B. Violation is Restrict
C. Violation is Shutdown
D. Maximum number of MAC addresses is 2
E. Maximum number of MAC addresses is 1
【多选题】
Which two are characteristics of RADIUS?___
A. Uses UDP ports 1812 /1813
B. Uses TCP port 49
C. Uses UDP port 49
D.
E. ncrypts only the password between user and server
【多选题】
When setting up a site-to-site VPN with PSK authentication on a Cisco router, which two elements must be configured under crypto map?___
A. pfs
B. nat
C. reverse route
D. peer
E. transform-set
【多选题】
When using the Adaptive Security Device Manager(ASDM), which two options are available to add a new root certificate?___
A. Install from SFTP server
B. Usehttps
C. Install from a file
D. Use LDAP
E. Use SCEP
【多选题】
Which two SNMPv3 services support its capabilities as a secure networ k manage protocol? ___
A. access control
B. the shared secret key
C. authentication
D. authorization
E. accounting
推荐试题
【判断题】
依据《北京市乡镇、街道(园区)安全生产专职安全员检查办法》的规定,专职安全员检查工作应遵循公正、公开、公平的原则
A. 对
B. 错
【判断题】
对同一家生产经营单位进行多次检查的,累计检查次数计入年度检查任务
A. 对
B. 错
【判断题】
专职安全员个人年度检查任务完成情况应该作为个人年度考核的基本参考依据
A. 对
B. 错
【判断题】
安全生产检查队年度检查任务完成情况应该作为乡镇、街道(园区)年度安全生产考核的基本参考依据
A. 对
B. 错
【判断题】
专职安全员应在现场将安全生产事故隐患用笔记录下来,作为隐患认定的依据
A. 对
B. 错
【判断题】
专职安全员应在检查结束后,集中向被检查单位反馈检查情况,并告知处理措施
A. 对
B. 错
【判断题】
安全生产监督管理部门应当加强对监督检查人员的冶金专业知识培训,提高行政执法能力
A. 对
B. 错
【判断题】
安全生产监督管理部门应当建立健全建设项目安全预评价、安全专篇、安全验收评价的备案管理制度,加强建设项目安全设施的“三同时”的监督检查
A. 对
B. 错
【判断题】
北京市乡镇、街道(园区)安全生产专职安全员工作档案名称的填写要准确,文字简练通顺,结构完整,不用揭示卷内文件的内容和成份
A. 对
B. 错
【判断题】
北京市乡镇、街道(园区)安全生产专职安全员工作时需要归档的文件资料一旦形成,累计一定数量时再归档
A. 对
B. 错
【判断题】
《北京市乡镇、街道(园区)安全生产专职安全员工作档案管理办法》规定,需要查阅借阅专职安全员档案的,直接借阅但需按期归还
A. 对
B. 错
【判断题】
建筑施工单位应当配备必要的应急救援器材、设备和物资,并进行经常性维护、保养,保证正常运转
A. 对
B. 错
【判断题】
北京市区县(开发区)安全监管局对各乡镇、街道(园区)推荐的优秀专职安全员进行初评,并最终确定本区县参评人选上报市安全监管局
A. 对
B. 错
【判断题】
对于北京市举报安全生产事故隐患和非法违法行为的举报人应依法保护其合法权益、严格遵守保密制度
A. 对
B. 错
【判断题】
安全生产监督管理部门应当加强对工贸企业有限空间作业的监督检查,但不应将检查纳入年度执法工作计划
A. 对
B. 错
【判断题】
安全生产监督管理部门应当建立健全职业卫生监督检查制度,加强行政执法人员职业卫生知识的培训,提高行政执法人员的业务素质
A. 对
B. 错
【判断题】
安全生产监督管理部门行政执法人员依法履行监督检查职责时,可不用出示有效的执法证件
A. 对
B. 错
【判断题】
北京市区县安全生产监督管理局应当按照有关规定,建立本辖区内重大危险源安全监管工作机制,及时与有关部门和街道办事处、乡镇人民政府沟通协调工作情况,重要情况应当及时报上级人民政府
A. 对
B. 错
【判断题】
依据《北京市乡镇、街道(园区)安全生产专职安全员检查办法》的规定,专职安全员检查数据以全市安全生产执法检查系统填报数据为准,在规定的时间内未录入数据可延长30分钟补录
A. 对
B. 错
【判断题】
依据《北京市乡镇、街道(园区)安全生产专职安全员招聘工作暂行办法》的规定,报考人员的体检参照《公务员录用体检通用标准(试行)》(2010年修订)组织体检
A. 对
B. 错
【判断题】
依据《北京市乡镇、街道(园区)安全生产专职安全员招聘工作暂行办法》的规定,确定体检机构需要按照《关于指定北京市行政机关公务员录用体检机构的通知》(京人社录发〔2011〕327号)的文件所列名录执行
A. 对
B. 错
【判断题】
依据《北京市乡镇、街道(园区)安全生产优秀专职安全员评选表彰暂行办法》的规定,优秀专职安全员每年评选表彰两次
A. 对
B. 错
【判断题】
依据《北京市乡镇、街道(园区)安全生产优秀专职安全员评选表彰暂行办法》的规定,优秀专职安全员应具备坚持依法履职,熟悉安全生产法律法规、规程和标准,具有较高的工作水平,工作无差错
A. 对
B. 错
【判断题】
依据《北京市乡镇、街道(园区)安全生产优秀专职安全员评选表彰暂行办法》的规定,优秀专职安全员应具备密切联系群众,作风优良,具有较强的服务意识,为企业做实事,办好事,群众无不良印象
A. 对
B. 错
【判断题】
依据《北京市乡镇、街道(园区)安全生产优秀专职安全员评选表彰暂行办法》的规定,优秀专职安全员需经区县(开发区)安全监管局对辖区全部专职安全员进行初评,并最终确定本区县参评人选上报市安全监管局
A. 对
B. 错
【判断题】
北京市某区专职安全员李某2015年共检查生产经营单位198家,依据《北京市乡镇、街道(园区)安全生产专职安全员检查办法》的规定,李某已经超常完成了核定检查任务
A. 对
B. 错
【判断题】
依据《北京市乡镇、街道(园区)安全生产专职安全员检查办法》的规定,对生产经营单位进行复查计入年度检查任务数量
A. 对
B. 错
【判断题】
北京市负有安全生产监督管理职责的部门应当按照各自职责,制定相关行业、领域的事故隐患目录
A. 对
B. 错
【判断题】
北京市安全生产监督管理局负责建立本市重大危险源安全监管体系,组织开展重大危险源监管工作,检查、指导区县安全生产监督管理局监管工作
A. 对
B. 错
【判断题】
制定《消防法》的目的是预防火灾和减少火灾危害,加强应急救援工作,保护人身、财产安全,维护公共安全
A. 对
B. 错
【判断题】
制定《特种设备安全法》的目的是加强特种设备安全工作,预防特种设备事故,保障人身和财产安全,促进经济社会发展
A. 对
B. 错
【判断题】
安全监管监察部门不必对生产经营单位按照国家规定提取和使用安全生产费用,安排用于配备劳动防护用品、进行安全生产教育和培训的经费,以及其他安全生产投入的情况进行重点监督检查
A. 对
B. 错
【判断题】
安全监管监察部门不必对生产经营单位新建工程项目的安全设施与主体工程同时设计、同时施工、同时投入生产和使用的情况进行重点监督检查
A. 对
B. 错
【判断题】
生产经营单位应当建立健全安全生产隐患排查治理体系,按照要求建立“一企一标准、一岗一清单”,定期排查事故隐患,发现隐患立即整改
A. 对
B. 错
【判断题】
《北京市乡镇、街道(园区)安全生产专职安全员管理暂行办法》是根据市政府办公厅《关于在全市乡镇、街道(园区)建立安全生产专职安全员队伍的意见》,结合工作实际制定的
A. 对
B. 错
【判断题】
制定《北京市安全生产检查员资格管理办法》的目的是规范本市乡镇、街道(园区)安全生产检查员资格管理工作
A. 对
B. 错
【判断题】
北京市乡镇、街道(园区)安全生产管理机构中具有行政或事业编制身份的人员不可以申请取得《北京市安全生产检查员证》
A. 对
B. 错
【判断题】
在岗安全生产检查员每年度的培训时间不得少于40学时。其中,法制培训时间不少于24学时
A. 对
B. 错
【单选题】
___0001.生产经营单位的( )对本单位的安全生产工作全面负责。
A. 安全负责人
B. 主要负责人
C. 安全管理人员
D. 各部门负责人
【单选题】
___0002.生产经营单位的工会依法对安全生产工作进行( )。
A. 检查
B. 监管
C. 监督
D. 评价