【单选题】
Which information can you display by executing the show crypto ipsec sa command?___
A. ISAKMP SAs that are established between two peers
B. recent changes to the IP address of a peer router
C. proxy infor mation for the connection between two peers
D. IPsec SAs established between two peers
查看试卷,进入试卷练习
微信扫一扫,开始刷题
答案
D
解析
暂无解析
相关试题
【单选题】
How can you prevent NAT rules from sending traffic to incorrect interfaces?___
A. Assign the output interface in the NAT statement
B. Add the no-proxy-arp command to the nat line.
C. Configure twice NAT instead o bject NAT. 5
D. Use packet-tracer rules to reroute misrouted NAT entries.
【单选题】
What term can be defined as the securing, control, and identification of digital data?___
A. cryptography
B. crypto key
C. cryptoanalysis
D. cryptology
【单选题】
Which feature in the dNS security module provide on and off network DNS protection?___
A. Data Loss Prevention
B. Umbrella
C. Real-time sandboxing
D. Layer-4 monitoring
【单选题】
Which a dverse consequence can occur on a network without BPDu guard ?___
A. The olde st switch can be elected as the root bridge
B. Unauthorized switches that are connected to the network can cause spanning-tree loops
C.
D. ouble tagging can cause the switches to experience CAM table overload.
【单选题】
What configuration is required for multitenancy ?___
A. shared infrastructure
B. multiple carriers
C. co-located resources
D. multiple separate zones
【单选题】
Why does ISE require its own certificate issued by a trusted CA?___
A. ISEs certificate allows guest devices to validate it as a trusted network device
B. It generates certificates for guest devices ba sed on its own certificate
C. It requests certificates for guest devices from the Ca server based on its own certificate.
D. ISE's certificate allows it to join the network security framework
【单选题】
which attack involves large numbers of ICMP packets with a spoofed source IP address?___
A. smurf attack
B. Teardrop attack
C. Nuke attack
D. SYN Flood attack
【单选题】
Which statement about interface and global access rules is true?___
A. Interface access rules are processed before global access rules.
B. Global access rules apply only to outbound traffic, but interface access rules can be applied in either direction
C. The implicit allow is proce ssed after both the global and interface access rules
D. If an interface access rule is applied, the global access rule is ignored
【单选题】
Which type of malicious software can create a back-door into a device or network?___
A. bot
B. worm
C. virus
D. Trojan
【单选题】
Which security term refers to the like lihood that a weakness will be exploited to cause damage to an asset?___
A. threat
B. risk
C. countermeasure
D. vulnerability
【单选题】
Which IPS detection method examines network traffic for preconfigured patterns?___
A. signature-based detection
B. honey-pot detection
C. anomaly-based detection
D. policy-based detection
【单选题】
What is an advantage of split tunneling ?___
A. It allows users with a VpN connection to a corporate network to access the internet with sending traffic across the cor porate network.
B. It allows users with a vpn connection to a corporate network to access the internet by using the vPN for security.
C. It protects traffic on the private network from users on the public network
D. It enables the VPN server to filter traffic more efficiently
【单选题】
Which IDS/IPS state misidentifies acceptable behavior as an attack ?___
A. false negative
B. true positive NEKA G
C. true negative
D. false positive
【单选题】
What is the maximum num ber of methods that a single method list can contain?___
A. 4
B. 3
C. 2
D. 5
【单选题】
Which command enables authentication at the oSPFv2 routing process level?___
A. ip ospf authentication message-digest
B. area 0 authentication message-digest
C. ip ospf message-digest-key 1 mds Cisco
D. area 0 authentication ipsec spi 500 md5 1234567890ABCDEF1234567890ABCDEF
【单选题】
Which type of firewall monitors a nd protects a specific system?___
A. firewall
B. application firewall
C. stateless firewall wvp
D. personal firewall
【单选题】
On an ASA, which maps are used to identify traffic?___
A. Route maps
B. Policy maps
C. Class maps
D. Service maps
【单选题】
Which type of social engineering attack targets top executives?___
A. whaling
B. vishin
C. spear phishing ng
D. baiting
【单选题】
What is the minimum Cisco lOS version that supports zone-based firewalls?___
A. 12.1T
B. 15.1
C. 15.0
D. 124
【单选题】
In which type of attack does an attacker overwrite an entry in the CAM table to divert traffic destined to a legitimate host?___
A. DHCP spoofing
B. ARP spoofing
C. CAM table overflow
D. MAC spoofing
【多选题】
Which two attack types can be prevented with the impleme ntation of a Cisco IPS solution?___
A. DDos
B. man-in-the-middle
C. worms
D. ARP spoofing
E. VLAN hopping
【多选题】
choose four___
A. DHCP snooping ——————————blocks DHCP messages
B. Dynamic ARP inspection——————verifies IP-to-MAC traffic on untrusted ports
C. IP sources guard ——————————provides layer 2 interface security with ports ACLs
D. Port security————————————mitigates MAC-address spoofing at the access interface
【多选题】
choose four___
A. Step1————————run the system setup wizard
B. Step2————————add an authentication realm
C. Step3————————configure identity management
D. Step4————————configure directory group
【多选题】
What are two advanced features of the Cisco AMp solution for endpoints ___
A. contemplation
B. foresight
C. sandboxing
D. reputation
E. reflection
【多选题】
Which two characteristics of RADIUS are true?___
A. It encrypts only the password between user and server.
B. It uses TCP ports 1812/1813
C. It uses UDP ports 1812/1813.
D. It uses UDP port 49
E. It uses TCP port 49
【多选题】
What are two challenges of using a network-based IPS? ___
A. It is unable to determine whether a detected attack was successful
B. It requires additional storage and proce ssor capacity on syslog servers
C. As the network expands, it requires you to add more sensors.
D. It is unable to detect attacks across the entire network
E. It must support multiple operating systems.
【多选题】
What are two default be haviors of the traffic on a zone-based firewall?___
A. Traffic within the self -zone uses an im plicit deny all.
B. All traffic between zones is implicitly blocked
C. Communication is allowed between interfadAss that are members of the same zone
D. Communication is blocked between interfaces that are members of the same zone
E. The CBAC rules that are configured on router interfaces apply to zone interfaces
【多选题】
Which two advantages does the on-premise model for MDM deployment have over the cloud-based model?___
A. The on-premise model is easier and faster to de ploy than the cloud-based model
B. The on-premise model is more scalable than the cloud-based model
C. The on-premise model is generally less expensive than the cloud-based model
D. The on-premise model generally has less latency than the cloud- based model.
E. The on-premise model provides more control of the MDM solution than the cloud
【多选题】
Which two actions can an end usts take to manage a lost or stolen device in Cisco ISE? ___
A. Activate Cisco ISE End point Protection Services to quarantine the device.
B. Add the mac address of the device to a list of blacklisted devices
C. Force the device to be locked with a PIN
D. Request revocation of the digital certificate of the device.
E. Reinstate a device that the user previously marked as lost or stolen
【多选题】
Which two problems can arise when a proxy firewall serves as the gateway between networks?___
A. It can prevent content caching
B. It can limit application support
C. It is unable to prevent direct connections to other networks
D. It can cause reduced throughput.
E. It is unable to provide antivirus protection
【多选题】
When using the Adaptive Security Device Manager(ASDM), which two methods are available to add a new root certificate?___
A. Use sCep
B. Install from SFTP server
C. Install from a file
D. Use Https
E. Use LDAP
【多选题】
Which two are considered basic security principles?___
A. Accountability
B. Redundancy
C. High Availabilit
D. Integrity
E. Confidentiality
【多选题】
Which two roles of the Cisco WSA are true?___
A. IPS
B. firewall
C. antispam
D. web proxy
E. URL filter
【单选题】
Which next-generation encryption algorithm supports four variants?___
A. SHA-2
B. SHA-1
C. MD5
D. HMAC
【单选题】
What aims to remove the abil ity to deny an action?___
A. Non-Repudiation
B. Accountability
C. Integrity
D. Deniability
【单选题】
Which statements about the native VLAN is true ?___
A. It is susceptible to VLAN hopping attacks.
B. It is the Cisco recommended VLAN for switch-management traffic
C. It is most secure when it is a ssigned to vLAn 1.
D. It is the cisco-recomme nded vlan for user traffic
【单选题】
There are two versions of IKE:IKEv1 and IKEv2. Both IKEv1 and IKEv2 protocols operate in phases IKEv1 operates in two phases. IKEv2 operates in how many phases?___
A. 2
B. 3
C. 4
D. 5
【单选题】
What does the dh group refer to?___
A. length of key for hashing C
B. length of key for encryption
C. tunnel lifetime key
D. length of key for key exchange
E. length of key for authentication
【单选题】
Which path do you follow to enable aaa through the SDM ?___
A. Configure Tasks > AAA
B. Configure > Addition Authentication > AAA
C. Configure > AAA
D. Configure > Additional Tasks > AAA
E. Configure Authentication > AAA
【单选题】
which technology cloud be used on top of an MPLS VPN to add confidentiality ?___
A. IPsec
B. 3DES
C. AES
D. SSL
推荐试题
【多选题】
资产管理处置档案包括()。
A. 直接业务档案
B. 间接业务档案
C. 业务参考档案
D.
【多选题】
对业务发生时间相同且有内在联系的资料,按照()的原则整理。
A. 主件在上,附件在下
B. 主件在下,附件在上
C. 批复在上,请示在下
D. 批复在下,请示在上
【多选题】
不良贷款批量转让必须严格按照规定的对象、条件、程序进行,落实()的要求。
A. 洁净转让
B. 处置优先
C. 真实出售
D. 回购转让
【多选题】
盘活不良贷款必须坚持以()为前提,严禁弄虚作假,使贷款风险进一步加剧、扩大。
A. 贷款式额度不增加
B. 风险不扩大
C. 担保不弱化
D. 化解风险
【多选题】
对认定为损失及退出系统核算的,要()。
A. 逐笔建立台账
B. 保管好档案资料
C. 不用建立台账
D. 不再追偿
【多选题】
委托清收坚持()原则。
A. 依法合规
B. 按劳计酬
C. 权责对等
D. 效益至上
【多选题】
委托清收适用于各农村商业银行()。
A. 五级分类不良贷款
B. 表外登记贷款
C. 抵债资产处置
D. 处置产生次生风险贷款
【多选题】
不良资产委托清收方案内容包括但不限于()等。
A. 尽职调查情况
B. 委托清收理由
C. 受托人确定方式
D.
【多选题】
委托清收受托人应是具有合法资质的()等社会中介和组织。
A. 律师事务所
B. 法律服务所
C. 会计师事务所
D. 资产管理公司
【多选题】
已核销不良资产管理遵循()的工作原则。
A. 账销案存
B. 依法催收
C. 严格保密
D. 规范核算
【判断题】
任何单位和个人不得以任何形式侵占、出借、赠送抵债资产。
A. 对
B. 错
【判断题】
处置抵债资产时,严禁向买受意向人或其关联企业提供贷款用于购买抵债资产,且买受意向人或其关联企业必须无不良记录。
A. 对
B. 错
【判断题】
严禁擅自将抵债资产尤其是不入账的抵债资产转为自用固定资产,确需自用的,必须按固定资产购置有关规定进行办理。
A. 对
B. 错
【判断题】
债权转让时,如受让方自有资金不足,农村商业银行可以提供贷款用以支付转让价款。
A. 对
B. 错
【判断题】
受让方价款支付完毕后,农村商业银行应当将债权转移事项通知债务人(含保证人),并取得已送达的有效证明。债务人(含保证人)拒不配合或下落不明的,应与受让方协商采取其他法定方式予以通知。
A. 对
B. 错
【判断题】
债权转让过程中,农村商业银行应向受让方提示拟转让贷款存在的瑕疵或风险,以避免产生法律纠纷。
A. 对
B. 错
【判断题】
收到转让价款后,农村商业银行应向受让方移交贷款合同、权利证书等资料,不得保留移交资料的复印件。
A. 对
B. 错
【判断题】
债权转让价款按财务制度据实入账,表内贷款转让损失部分应在当年核销。
A. 对
B. 错
【判断题】
债权转让各环节参与人员与债务人(保证人)、意向买受人是近亲属或有其他利害关系的,在相关程序中应当回避。
A. 对
B. 错
【判断题】
农村商业银行转让不良贷款债权时,不得附有任何显性或隐性的回购条件,严禁签订回购协议、即期买断加远期回购协议等方式开展处置。
A. 对
B. 错
【判断题】
对已核销不良资产实行账销案存的管理方式。视同表内资产对待,不因贷款核销而豁免债务人的偿债义务。
A. 对
B. 错
【判断题】
由于国家宏观政策调整等原因致使债务人经营困难,不能按期归还贷款,且担保人无代偿能力的,不得进行债务重组
A. 对
B. 错
【判断题】
依据相关法律法规的规定或经法院裁定,由具有代偿义务的第三人承接债务人(担保人)债务的,但债务承接人暂不具备全额偿还能力的,农商行可以与债务承接人约定新增授信等附加条件。
A. 对
B. 错
【判断题】
无法定代偿义务的第三人自愿承接债务的,应当由债务承接人与原债务人达成《债务转让协议》,并经农商行同意,债务承接人以受让原贷款抵(质)押物作为附加条件的,农商行应当确保原抵(质)押权不丧失。
A. 对
B. 错
【判断题】
依据相关法律法规的规定或经法院裁定,由具有代偿义务的第三人承接债务人(担保人)债务的,农商银行可以与债务承接人另行约定新增授信等附加条件。
A. 对
B. 错
【判断题】
农户、个体工商户等自然类不良贷款的债务重组,可以经农商银行有权决策人授权后简化程序办理,无须经过不良资产管理委员会审议。
A. 对
B. 错
【判断题】
已核销不良资产纳入责任清收范围,统一清收处置标准,以现金清收为主,其他方式为辅。
A. 对
B. 错
【判断题】
核销不良资产实行严格保密制度。不得向任何机构和部门披露有关核销资产的任何信息。
A. 对
B. 错
【判断题】
根据《关于规范资产置换不良贷款工作的意见》规定,在资产置换不良贷款过程中,预计置入资产两年内无法处置变现的,确定意向后必须先向当地银监局和省联社汇报。未经同意,不得进行资产置换。
A. 对
B. 错
【判断题】
根据《关于规范资产置换不良贷款工作的意见》规定,对通过资产置换置入的资产两年内难以处置变现的,要根据实际经营状况、未来业务发展情况以及置入资产可能形成的减值等,合理确定置入资产的摊销年限,但最长不得超过省联社规定的年限。
A. 对
B. 错
【判断题】
根据《关于规范资产置换不良贷款工作的意见》规定,对通过资产置换方式置入的土地等资产进行严格把关,严禁将权属不明、纠纷未决等有瑕疵的资产置入。
A. 对
B. 错
【判断题】
根据《山东省农村信用社不良资产推介管理暂行办法》规定,对拟推介资产进行尽职调查时,应采取查阅资产档案、询问资产经办人、实地调查资产等方式,不得委托中介机构进行调查。
A. 对
B. 错
【判断题】
根据《山东省农村信用社不良资产推介管理暂行办法》规定,不良资产推介信息包括:资产编号、项目名称、资产构成、资产状况、联系人及联系电话等,信息中不包括资产瑕疵。
A. 对
B. 错
【判断题】
根据《山东省农村信用社不良资产推介管理暂行办法》规定,利用平面媒体、电子媒体等进行推介招商的,应当尽量大面积、集中披露不良资产信息,做到有序推介,减少推介成本。
A. 对
B. 错
【判断题】
根据《山东省农村信用社不良资产推介管理暂行办法》规定,不良资产推介过程中,对于地域性和专业性较强的资产,要向具有地缘优势和专业优势的客户重点推介。
A. 对
B. 错
【判断题】
根据《山东省农村信用社不良资产诉讼管理办法》规定,农商银行资产管理部门负责人要根据诉讼台账和档案记录情况,至少每季对辖内的未执结案件进行一次全面排查。
A. 对
B. 错
【判断题】
根据《山东省农村信用社不良资产诉讼管理办法》规定,在不良资产诉讼授权决策时,决策人对不良资产管理委员会表决同意起诉的结果可以否决。
A. 对
B. 错
【判断题】
根据《关于不良贷款诉讼时效的法律指导意见》规定,债务人下落不明或拒绝签收《逾期贷款催收通知书》,农商银行可以委托当地公证机关进行公证催收。
A. 对
B. 错
【判断题】
根据《关于不良贷款诉讼时效的法律指导意见》规定,债务人涉嫌违法犯罪,农商银行向公检法报案或控告的,诉讼时效中断。刑事案件审理完毕刑事判决文书生效之日起,诉讼时效期间重新计算。
A. 对
B. 错
【判断题】
根据《关于不良贷款诉讼时效的法律指导意见》规定,因在保证期间内未要求保证人承担保证责任,造成保证责任灭失的,农商银行可以通过向保证人发出《保证人继续履行担保责任通知书》,由保证人签字认可来重新确定保证关系。
A. 对
B. 错