【单选题】
Which command can you enter to verify the status of Cisco lOS Resilient Configuration on a Cisco router?___
A. show secure bootset
B. secure boot-image
C. show binary file
D. ure boot-config
查看试卷,进入试卷练习
微信扫一扫,开始刷题
答案
A
解析
暂无解析
相关试题
【单选题】
A user on your network inadvertently activates a botnet program that was received as an emai attachment. Which type of mechanism does Cisco Firepower use to detect and block only the botnet attack?___
A. network-based access control rule
B. reputation-based
C. user-ba sed access control rule
D. botnet traffic filter
【单选题】
What does the policy map do in CoPP?___
A. defines service parameters
B. defines packet selection parameters
C. defines the packet filter
D. define s the action to be performed
【单选题】
How is management traffic isolated on a Cisco ASR 1002?___
A. Traffic isolation is done on the vlan level
B. There is no management traffic isolation on a Cisco ASR 1002
C. Traffic is isolated based upon how you configure routing on the device
D. The management interface is configured in a special vRF that provides traffic isolation from the default routing table
【单选题】
Which statement about NaT table evaluation in the asa is true?___
A. After-auto NAT polices are appl d first
B. Manual NAT policies are applied first
C. the asa uses the most specific match
D. Auto NAT policies are applied first
【单选题】
Which information can you display by executing the show crypto ipsec sa command?___
A. ISAKMP SAs that are established between two peers
B. recent changes to the IP address of a peer router
C. proxy infor mation for the connection between two peers
D. IPsec SAs established between two peers
【单选题】
How can you prevent NAT rules from sending traffic to incorrect interfaces?___
A. Assign the output interface in the NAT statement
B. Add the no-proxy-arp command to the nat line.
C. Configure twice NAT instead o bject NAT. 5
D. Use packet-tracer rules to reroute misrouted NAT entries.
【单选题】
What term can be defined as the securing, control, and identification of digital data?___
A. cryptography
B. crypto key
C. cryptoanalysis
D. cryptology
【单选题】
Which feature in the dNS security module provide on and off network DNS protection?___
A. Data Loss Prevention
B. Umbrella
C. Real-time sandboxing
D. Layer-4 monitoring
【单选题】
Which a dverse consequence can occur on a network without BPDu guard ?___
A. The olde st switch can be elected as the root bridge
B. Unauthorized switches that are connected to the network can cause spanning-tree loops
C.
D. ouble tagging can cause the switches to experience CAM table overload.
【单选题】
What configuration is required for multitenancy ?___
A. shared infrastructure
B. multiple carriers
C. co-located resources
D. multiple separate zones
【单选题】
Why does ISE require its own certificate issued by a trusted CA?___
A. ISEs certificate allows guest devices to validate it as a trusted network device
B. It generates certificates for guest devices ba sed on its own certificate
C. It requests certificates for guest devices from the Ca server based on its own certificate.
D. ISE's certificate allows it to join the network security framework
【单选题】
which attack involves large numbers of ICMP packets with a spoofed source IP address?___
A. smurf attack
B. Teardrop attack
C. Nuke attack
D. SYN Flood attack
【单选题】
Which statement about interface and global access rules is true?___
A. Interface access rules are processed before global access rules.
B. Global access rules apply only to outbound traffic, but interface access rules can be applied in either direction
C. The implicit allow is proce ssed after both the global and interface access rules
D. If an interface access rule is applied, the global access rule is ignored
【单选题】
Which type of malicious software can create a back-door into a device or network?___
A. bot
B. worm
C. virus
D. Trojan
【单选题】
Which security term refers to the like lihood that a weakness will be exploited to cause damage to an asset?___
A. threat
B. risk
C. countermeasure
D. vulnerability
【单选题】
Which IPS detection method examines network traffic for preconfigured patterns?___
A. signature-based detection
B. honey-pot detection
C. anomaly-based detection
D. policy-based detection
【单选题】
What is an advantage of split tunneling ?___
A. It allows users with a VpN connection to a corporate network to access the internet with sending traffic across the cor porate network.
B. It allows users with a vpn connection to a corporate network to access the internet by using the vPN for security.
C. It protects traffic on the private network from users on the public network
D. It enables the VPN server to filter traffic more efficiently
【单选题】
Which IDS/IPS state misidentifies acceptable behavior as an attack ?___
A. false negative
B. true positive NEKA G
C. true negative
D. false positive
【单选题】
What is the maximum num ber of methods that a single method list can contain?___
A. 4
B. 3
C. 2
D. 5
【单选题】
Which command enables authentication at the oSPFv2 routing process level?___
A. ip ospf authentication message-digest
B. area 0 authentication message-digest
C. ip ospf message-digest-key 1 mds Cisco
D. area 0 authentication ipsec spi 500 md5 1234567890ABCDEF1234567890ABCDEF
【单选题】
Which type of firewall monitors a nd protects a specific system?___
A. firewall
B. application firewall
C. stateless firewall wvp
D. personal firewall
【单选题】
On an ASA, which maps are used to identify traffic?___
A. Route maps
B. Policy maps
C. Class maps
D. Service maps
【单选题】
Which type of social engineering attack targets top executives?___
A. whaling
B. vishin
C. spear phishing ng
D. baiting
【单选题】
What is the minimum Cisco lOS version that supports zone-based firewalls?___
A. 12.1T
B. 15.1
C. 15.0
D. 124
【单选题】
In which type of attack does an attacker overwrite an entry in the CAM table to divert traffic destined to a legitimate host?___
A. DHCP spoofing
B. ARP spoofing
C. CAM table overflow
D. MAC spoofing
【多选题】
Which two attack types can be prevented with the impleme ntation of a Cisco IPS solution?___
A. DDos
B. man-in-the-middle
C. worms
D. ARP spoofing
E. VLAN hopping
【多选题】
choose four___
A. DHCP snooping ——————————blocks DHCP messages
B. Dynamic ARP inspection——————verifies IP-to-MAC traffic on untrusted ports
C. IP sources guard ——————————provides layer 2 interface security with ports ACLs
D. Port security————————————mitigates MAC-address spoofing at the access interface
【多选题】
choose four___
A. Step1————————run the system setup wizard
B. Step2————————add an authentication realm
C. Step3————————configure identity management
D. Step4————————configure directory group
【多选题】
What are two advanced features of the Cisco AMp solution for endpoints ___
A. contemplation
B. foresight
C. sandboxing
D. reputation
E. reflection
【多选题】
Which two characteristics of RADIUS are true?___
A. It encrypts only the password between user and server.
B. It uses TCP ports 1812/1813
C. It uses UDP ports 1812/1813.
D. It uses UDP port 49
E. It uses TCP port 49
【多选题】
What are two challenges of using a network-based IPS? ___
A. It is unable to determine whether a detected attack was successful
B. It requires additional storage and proce ssor capacity on syslog servers
C. As the network expands, it requires you to add more sensors.
D. It is unable to detect attacks across the entire network
E. It must support multiple operating systems.
【多选题】
What are two default be haviors of the traffic on a zone-based firewall?___
A. Traffic within the self -zone uses an im plicit deny all.
B. All traffic between zones is implicitly blocked
C. Communication is allowed between interfadAss that are members of the same zone
D. Communication is blocked between interfaces that are members of the same zone
E. The CBAC rules that are configured on router interfaces apply to zone interfaces
【多选题】
Which two advantages does the on-premise model for MDM deployment have over the cloud-based model?___
A. The on-premise model is easier and faster to de ploy than the cloud-based model
B. The on-premise model is more scalable than the cloud-based model
C. The on-premise model is generally less expensive than the cloud-based model
D. The on-premise model generally has less latency than the cloud- based model.
E. The on-premise model provides more control of the MDM solution than the cloud
【多选题】
Which two actions can an end usts take to manage a lost or stolen device in Cisco ISE? ___
A. Activate Cisco ISE End point Protection Services to quarantine the device.
B. Add the mac address of the device to a list of blacklisted devices
C. Force the device to be locked with a PIN
D. Request revocation of the digital certificate of the device.
E. Reinstate a device that the user previously marked as lost or stolen
【多选题】
Which two problems can arise when a proxy firewall serves as the gateway between networks?___
A. It can prevent content caching
B. It can limit application support
C. It is unable to prevent direct connections to other networks
D. It can cause reduced throughput.
E. It is unable to provide antivirus protection
【多选题】
When using the Adaptive Security Device Manager(ASDM), which two methods are available to add a new root certificate?___
A. Use sCep
B. Install from SFTP server
C. Install from a file
D. Use Https
E. Use LDAP
【多选题】
Which two are considered basic security principles?___
A. Accountability
B. Redundancy
C. High Availabilit
D. Integrity
E. Confidentiality
【多选题】
Which two roles of the Cisco WSA are true?___
A. IPS
B. firewall
C. antispam
D. web proxy
E. URL filter
【单选题】
Which next-generation encryption algorithm supports four variants?___
A. SHA-2
B. SHA-1
C. MD5
D. HMAC
【单选题】
What aims to remove the abil ity to deny an action?___
A. Non-Repudiation
B. Accountability
C. Integrity
D. Deniability
推荐试题
【多选题】
库房内可以采用以下哪类移动式照明?___
A. 防爆手电筒
B. 手提式防爆灯
C. 电网供电的移动手提灯
【多选题】
运输爆破器材时,遇到下列哪些情况,应当立即报告当地公安机关和本单位?___
A. 发现爆破器材丢失、短少的
B. 因故滞留的
C. 必须过夜泊车的
【多选题】
检验爆破器材的作业人员应该掌握和熟悉下列哪些内容?___
A. 熟悉产品的结构、工作原理、使用方法
B. 掌握规定的质量检查项目、检查方法
C. 掌握产品合格标准、检查时的安全要点
【多选题】
装运爆破器材的车(船),应具有___、防雨、防潮、防静电等安全性能。
A. 防热
B. 防超载
C. 防盗
D. 防火
【多选题】
安全员需要考核以下哪些内容?___
A. 爆破作业现场安全管理要求
B. 民用爆炸物品领取、发放、清退安全管理规定
C. 手持机操作技术
【多选题】
下列哪些措施是政府主管部门在民用爆炸物品安全管理中经常使用的?___
A. 行政许可
B. 罚款
C. 追究刑事责任
D. 监督检查
【多选题】
爆破从业人员从事爆破作业活动中,下列哪些行为是禁止的?___
A. 伪造爆破作业单位、人员许可证
B. 租借爆破作业单位、人员许可证
C. 出示爆破作业单位、人员许可证
【多选题】
___可直接用于有水的深孔爆破和浅孔爆破作业。
A. 乳化炸药
B. 水胶炸药
C. 铵油炸药
D. 粉状炸药
【多选题】
多孔粒状铵油炸药由___组成。
A. 多孔粒状硝酸铵
B. 梯恩梯
C. 柴油
D. 木粉
【多选题】
下列哪些元件是组成导爆管起爆网路的必需元件?___
A. 激发元件
B. 传爆元件
C. 起爆元件
D. 加热元件
【多选题】
下面哪些是导爆管起爆网路的优点?___
A. 不受外界电能的影响
B. 起爆网路起爆的药包数量不受限制
C. 网路不需要进行复杂的计算
D. 可以测量线路通不通
【多选题】
深孔和硐室爆破可选用哪些起爆方法?___
A. 电力起爆
B. 导爆索起爆
C. 导爆管起爆
【多选题】
以下哪些可以引爆导爆管起爆网路?___
A. 专用起爆器
B. 导爆索
C. 雷管
D. 打火机
【多选题】
岩石(土)种类很多,按照它的形成原因可以分为岩浆岩、___和(C )三大类型。
A. 沉积岩
B. 花岗岩
C. 变质岩
D. 玄武岩
【多选题】
下列哪些部位适合作为安排警戒点的位置?___
A. 爆破危险区外
B. 交通道口
C. 各种角落
D. 视野开阔的地方
【多选题】
在煤矿井下掘进爆破中,下列确定警戒距离的原则哪些是对的?___
A. 回采工作面一般不得小于30米
B. 煤巷掘进工作面直线爆破不得小于75米
C. 对有直角弯的工作面不得小于50米
D. 煤巷掘进工作面直线爆破不得小于100米
【多选题】
下列措施中哪些是处理深孔爆破盲炮时需要遵守的?___
A. 爆破网路未受破坏,且最小抵抗线无变化者,可重新连接起爆;最小抵抗线有变化者,应验算安全距离,并加大警戒范围后,再连接起爆
B. 可在距盲炮孔口不少于10倍炮孔直径处另打平行孔装药起爆
C. 可钻平行孔装药爆破,平行孔距盲炮孔不应小于0.3m
D. 可在安全地点外用远距离操纵的风水喷管吹出盲炮填塞物及炸药
【多选题】
下列哪些参数是深孔爆破方法的特征?___
A. 钻孔直径大于50mm
B. 炮孔深度大于5米
C. 设备是进口的
D. 一次爆破量大
【多选题】
在爆破工程施工中,防止因迟爆发生安全事故的有效措施是___。
A. 不使用已过期的爆炸材料
B. 正确选用起爆器
C. 发现起爆后炮未响时,不要急于当盲炮处理,应留有足够的等待时间
D. 由安全员负责起爆操作
【多选题】
爆破产生的有害效应除了爆破振动、爆破冲击波、爆破毒气以外还有哪些?___
A. 爆破效果
B. 爆破噪声
C. 爆破飞散物
D. 爆破烟尘
【多选题】
在焚烧法销毁爆炸危险品中,下列哪些是制作点火药包应该特别注意的问题?___
A. 要对制成的电点火药包进行试验,确认其可靠性
B. 点火药包上的电点火装置要与药包中的火药紧密接触
C. 严禁在点火药包内混入雷管
【多选题】
用焚烧法可以销毁下列哪些爆炸物品?___
A. 鳞片状梯恩梯
B. 烟火剂
C. 发射药
【多选题】
在领取、发放爆破器材时,交接双方都应当对下列哪些项目进行检查?___
A. 包装外观
B. 警示标识
C. 登记标识
【多选题】
库房内可以采用以下哪类移动式照明?___
A. 防爆手电筒
B. 手提式防爆灯
C. 电网供电的移动手提灯
【多选题】
以下哪些条件是爆破员、安全员、保管员应具备的?___
A. 18周岁以上,60周岁以下
B. 高中以上文化程度
C. 无妨碍爆破作业的疾病和生理缺陷
【多选题】
下列哪些属于原国防科工委、公安部公布的《民用爆炸物品品名表》中的民爆物品?___
A. 工业炸药
B. 工业雷管
C. 工业索类火工品
【多选题】
爆破从业人员从事爆破作业活动中,下列哪些行为是禁止的?___
A. 爆破从业人员同时受聘于两个以上爆破作业单位
B. 违反国家有关标准和规范实施爆破作业
C. 扣押爆破从业人员许可证
【多选题】
一般地说,以下哪些是炸药特有的相容性?___
A. 组分相容性
B. 物理相容性
C. 化学相容性
D. 爆炸相容性
【多选题】
以下哪些属于炸药的安定性?___
A. 化学安定性
B. 物理安定性
C. 热安定性
D. 水溶解性
【多选题】
以下哪些是电起爆网路预防雷电的措施?___
A. 将全部电爆网路埋入土中,深度不小于25cm
B. 用一根裸线(可用有刺铁丝)与电爆网路的导电线并排敷设
C. 用树枝将起爆线路覆盖起来
D. 起爆站干线的末端分开放置,并进行绝缘
【多选题】
下列哪些元件是组成导爆管起爆网路的必需元件?___
A. 激发元件
B. 传爆元件
C. 起爆元件
D. 加热元件
【多选题】
电子雷管由以下哪些部分组成?___
A. 管壳
B. 装药部分
C. 电子电路
D. 排气孔
【多选题】
深孔爆破可选用的起爆方法有哪些?___
A. 导爆管起爆法
B. 电力起爆法
C. 导爆索起爆法
【多选题】
当炸药置于无限大的均匀岩石介质中爆炸时,将会在岩石中形成以炸药为中心的由近及远的不同破坏区域,分别称为___。
A. 装药区
B. 粉碎区
C. 裂隙区
D. 振动区
【多选题】
在井巷掘进爆破中,下列哪些掏槽方法是常用的?___
A. 锥形掏槽
B. 直孔掏槽
C. 混合掏槽
【多选题】
下列哪些是防止堵孔的措施?___
A. 将孔口岩石碎块清理干净,防止掉落孔内
B. 每个炮孔钻完后立即将孔口用木塞或塑料塞堵好,防止雨水或其他杂物进入炮孔
C. 一个爆区钻孔完成后应尽快实施爆破
D. 炮孔钻好后要进行登记、编号
【多选题】
下面哪些工作是爆破时安全警戒人员的任务?___
A. 清场
B. 在指定位置站岗
C. 管制交通
D. 整理剩余爆破器材
【多选题】
在每次爆破中,起爆前后一共有三次信号,以下哪些是爆破警戒信号?___。
A. 预警信号
B. 解除信号
C. 联络信号
D. 起爆信号
【多选题】
以下措施中哪些有助于防止因静电感应引起的早爆?___
A. 对于现场易产生静电的机械、设备等应与大地相接通以疏导静电
B. 按设计要求进行填塞,保证填塞质量和长度
C. 施工人员不穿易产生静电的工作服
D. 采用抗静电雷管
【多选题】
在拆除爆破中,下列哪些材料适合用于爆破区域的防护?___
A. 草帘
B. 砂土袋
C. 块石
D. 篷布