【单选题】
Which IDS/IPS state misidentifies acceptable behavior as an attack ?___
A. false negative
B. true positive NEKA G
C. true negative
D. false positive
查看试卷,进入试卷练习
微信扫一扫,开始刷题
答案
D
解析
暂无解析
相关试题
【单选题】
What is the maximum num ber of methods that a single method list can contain?___
A. 4
B. 3
C. 2
D. 5
【单选题】
Which command enables authentication at the oSPFv2 routing process level?___
A. ip ospf authentication message-digest
B. area 0 authentication message-digest
C. ip ospf message-digest-key 1 mds Cisco
D. area 0 authentication ipsec spi 500 md5 1234567890ABCDEF1234567890ABCDEF
【单选题】
Which type of firewall monitors a nd protects a specific system?___
A. firewall
B. application firewall
C. stateless firewall wvp
D. personal firewall
【单选题】
On an ASA, which maps are used to identify traffic?___
A. Route maps
B. Policy maps
C. Class maps
D. Service maps
【单选题】
Which type of social engineering attack targets top executives?___
A. whaling
B. vishin
C. spear phishing ng
D. baiting
【单选题】
What is the minimum Cisco lOS version that supports zone-based firewalls?___
A. 12.1T
B. 15.1
C. 15.0
D. 124
【单选题】
In which type of attack does an attacker overwrite an entry in the CAM table to divert traffic destined to a legitimate host?___
A. DHCP spoofing
B. ARP spoofing
C. CAM table overflow
D. MAC spoofing
【多选题】
Which two attack types can be prevented with the impleme ntation of a Cisco IPS solution?___
A. DDos
B. man-in-the-middle
C. worms
D. ARP spoofing
E. VLAN hopping
【多选题】
choose four___
A. DHCP snooping ——————————blocks DHCP messages
B. Dynamic ARP inspection——————verifies IP-to-MAC traffic on untrusted ports
C. IP sources guard ——————————provides layer 2 interface security with ports ACLs
D. Port security————————————mitigates MAC-address spoofing at the access interface
【多选题】
choose four___
A. Step1————————run the system setup wizard
B. Step2————————add an authentication realm
C. Step3————————configure identity management
D. Step4————————configure directory group
【多选题】
What are two advanced features of the Cisco AMp solution for endpoints ___
A. contemplation
B. foresight
C. sandboxing
D. reputation
E. reflection
【多选题】
Which two characteristics of RADIUS are true?___
A. It encrypts only the password between user and server.
B. It uses TCP ports 1812/1813
C. It uses UDP ports 1812/1813.
D. It uses UDP port 49
E. It uses TCP port 49
【多选题】
What are two challenges of using a network-based IPS? ___
A. It is unable to determine whether a detected attack was successful
B. It requires additional storage and proce ssor capacity on syslog servers
C. As the network expands, it requires you to add more sensors.
D. It is unable to detect attacks across the entire network
E. It must support multiple operating systems.
【多选题】
What are two default be haviors of the traffic on a zone-based firewall?___
A. Traffic within the self -zone uses an im plicit deny all.
B. All traffic between zones is implicitly blocked
C. Communication is allowed between interfadAss that are members of the same zone
D. Communication is blocked between interfaces that are members of the same zone
E. The CBAC rules that are configured on router interfaces apply to zone interfaces
【多选题】
Which two advantages does the on-premise model for MDM deployment have over the cloud-based model?___
A. The on-premise model is easier and faster to de ploy than the cloud-based model
B. The on-premise model is more scalable than the cloud-based model
C. The on-premise model is generally less expensive than the cloud-based model
D. The on-premise model generally has less latency than the cloud- based model.
E. The on-premise model provides more control of the MDM solution than the cloud
【多选题】
Which two actions can an end usts take to manage a lost or stolen device in Cisco ISE? ___
A. Activate Cisco ISE End point Protection Services to quarantine the device.
B. Add the mac address of the device to a list of blacklisted devices
C. Force the device to be locked with a PIN
D. Request revocation of the digital certificate of the device.
E. Reinstate a device that the user previously marked as lost or stolen
【多选题】
Which two problems can arise when a proxy firewall serves as the gateway between networks?___
A. It can prevent content caching
B. It can limit application support
C. It is unable to prevent direct connections to other networks
D. It can cause reduced throughput.
E. It is unable to provide antivirus protection
【多选题】
When using the Adaptive Security Device Manager(ASDM), which two methods are available to add a new root certificate?___
A. Use sCep
B. Install from SFTP server
C. Install from a file
D. Use Https
E. Use LDAP
【多选题】
Which two are considered basic security principles?___
A. Accountability
B. Redundancy
C. High Availabilit
D. Integrity
E. Confidentiality
【多选题】
Which two roles of the Cisco WSA are true?___
A. IPS
B. firewall
C. antispam
D. web proxy
E. URL filter
【单选题】
Which next-generation encryption algorithm supports four variants?___
A. SHA-2
B. SHA-1
C. MD5
D. HMAC
【单选题】
What aims to remove the abil ity to deny an action?___
A. Non-Repudiation
B. Accountability
C. Integrity
D. Deniability
【单选题】
Which statements about the native VLAN is true ?___
A. It is susceptible to VLAN hopping attacks.
B. It is the Cisco recommended VLAN for switch-management traffic
C. It is most secure when it is a ssigned to vLAn 1.
D. It is the cisco-recomme nded vlan for user traffic
【单选题】
There are two versions of IKE:IKEv1 and IKEv2. Both IKEv1 and IKEv2 protocols operate in phases IKEv1 operates in two phases. IKEv2 operates in how many phases?___
A. 2
B. 3
C. 4
D. 5
【单选题】
What does the dh group refer to?___
A. length of key for hashing C
B. length of key for encryption
C. tunnel lifetime key
D. length of key for key exchange
E. length of key for authentication
【单选题】
Which path do you follow to enable aaa through the SDM ?___
A. Configure Tasks > AAA
B. Configure > Addition Authentication > AAA
C. Configure > AAA
D. Configure > Additional Tasks > AAA
E. Configure Authentication > AAA
【单选题】
which technology cloud be used on top of an MPLS VPN to add confidentiality ?___
A. IPsec
B. 3DES
C. AES
D. SSL
【单选题】
Which term is most closely aligned with the basic purpose of a SIEM solution? ___
A. Non-Repudiation
B. Accountability
C. Causality
D. Repudiation
【单选题】
You have just deployed SNMPv3 in your environment, Your manager asks you to make sure that our SNMP agents can only talk to the SNMP Manager. What would you configure on your SNMI agents to satisfy this request?___
A. A SNMP View containing the SNMP managers
B. Routing Filter with the SNMP managers in it applied outbound
C. A standard ACL containing the SNMP managers applied to the SNMP configuration
D. A SNMP Group containing the SNMP managers
【单选题】
Which feature prevents loops by moving a nontrunking port into an errdisable state when a BPDU is received on that port?___
A. BPDU filte
B. DHCP snooping
C. BPDU guard
D. Port Fast
【单选题】
Which command enables port security to use sticky MAC addresses on a switch?___
A. switchport port-security violation restrict
B. switchport port-security mac-address sticky
C. switchport port-security violation protect
D. switchport port-security
【单选题】
When you edit an IPS subsignature, what is the effect on the parent signature and the family of subsignatures?___
A. The change applies to the parent signature and the entire family of subsignatures
B. The change applies to the parent signature and the subsignature that you edit
C. The change applies only to subsignatures that are numbered sequentially after the subsignature that you edit
D. Other signatures are unaffected, the change applies only to the subsignature that you dit
【单选题】
Which type of mechanism does Cisco FirePOWER de ploy to protect ag detected moving across other networks?___
A. antivirus scanning
B. policy-based
C. reputation-based
D. signature-based
【单选题】
What action must you take on the ise to blacklist a wired device?___
A. Locate the switch through which the device is connected and push an a cl restricting all access by the device
B. Issue a CoA request for the de vice's mac address to each access switch in the network
C. Revoke the device's certificate so it is unable to authenticate to the network
D. Add the device's MAc address to a list of black listed devices
【单选题】
Which type of firewall can perform deep packet inspection?___
A. packet-filtering firewall
B. stateless firewall
C. application firewall
D. personal firewall
【单选题】
What is the main purpose of Control Plane Policing?___
A. to prevent exhaustion of route-proce ssor resources
B. to organize the egress packet queues
C. to define traffic classes
D. to maintain the policy map
【单选题】
Which attack can be prevented by OSPF authentication?___
A. smurf attack
B. IP spoofing attack
C. denial of service attack
D. buffer overflow attack
【单选题】
What is the best definition of hairpinning?___
A. ingress traffic that traverses the outbound interface on a device
B. traffic that enters one interface on a device and that exits through another interface
C. traffic that enters and exits a device through the same interface
D. traffic that tunnels through a device interface
【单选题】
Which SNMPv3 security level provides authentication using HMAC with MD5, but does not use encryption?___
A. authPriv
B. authNo Priv
C. noAuthNoPriv
D. NoauthPriv
【单选题】
You have implemented a dynamic blacklist, using security intelligence to block illicit network activity. However, the blacklist contains several approved connections that users must access for usiness pur poses. Which action can you take to retain the blacklist while allowing users to access the approve d sites?___
A. Create a whitelist and manually add the approved addresses.
B. Disable the dynamic blacklist and deny the specif ic address on a whitelist while permitting the others
C. Edit the dynamic blacklist to remove the approved addresses
D. Disable the dynamic blacklist and create a static blacklist in its place
推荐试题
【单选题】
在列车运行速度超过120 km/h的双线区段,采用速差式自动闭塞,列车紧急制动距离由___及以上闭塞分区长度保证。
A. 一个
B. 两个
C. 三个
【单选题】
LKJ设备应按高于线路允许速度___km/h常用制动设置模式曲线。
A. 3
B. 5
C. 8
【单选题】
机车轮对踏面擦伤深度不得超过___ mm。
A. 0.5
B. 0.7
C. 1
【单选题】
车轮踏面上的缺陷或剥离长度不超过40mm,深度不超过___mm。
A. 0.5
B. 0.7
C. 1
【单选题】
接触网标称电压值为___kV,最高工作电压为27.5kV,短时(5min)最高工作电压为29kV,最低工作电压为19kV。
A. 20
B. 23
C. 25
【单选题】
为保证人身安全,除专业人员执行有关规定外,其他人员(包括所携带的物件)与牵引供电设备带电部分的距离,不得小于___mm。
A. 1500
B. 1800
C. 2000
【单选题】
在设有接触网的线路上,___攀登车顶及在车辆装载的货物之上作业;如确需作业时,须在指定的线路上,将接触网停电接地并采取安全防护措施后,方准进行。
A. 确认安全距离后可以
B. 严禁
C. 可以在有人监护下
【单选题】
在调度集中区段,调度集中控制车站有关行车工作由该区段___指挥。
A. 车站值班员
B. 列车调度员
C. 车站值班员和列车调度员共同
【单选题】
指挥列车运行的命令(运行揭示调度命令除外)和口头指示,只能由___发布。
A. 车站值班员
B. 机车调度员
C. 列车调度员
【单选题】
双管供风的旅客列车运行途中改为单管供风时,列车调度员___。
A. 须发给司机调度命令
B. 给予司机口头指示
C. 通知车辆乘务员即可
【单选题】
驾驶机车的人员,必须持有___颁发的驾驶证。
A. 铁路局
B. 铁路总公司
C. 国家铁路局
【单选题】
编组超重列车时,在中间站应得到___的同意,并均须经列车调度员准许。
A. 司机
B. 车站值班员
C. 车站调度员
【单选题】
旅客列车列尾装置尾部主机的安装与摘解、风管及电源的连结与摘解,由___人员负责。
A. 车辆部门
B. 车务部门
C. 机务部门
【单选题】
货物列车列尾装置尾部主机的安装与摘解,由___人员负责。
A. 车辆部门
B. 车务部门
C. 机务部门
【单选题】
补机原则上应挂于本务机车的___,在特殊区段或需途中返回时,经铁路局批准,可挂于列车后部。
A. 前位
B. 次位
C. 前位或次位
【单选题】
单机挂车的辆数,线路坡度不超过12‰的区段,以___辆为限;超过12‰的区段,由铁路局规定。
A. 5
B. 10
C. 15
【单选题】
单机挂车在区间被迫停车后的防护工作由___负责,开车前应确认附挂辆数和制动主管贯通状态是否良好。
A. 机车乘务组
B. 车辆乘务员
C. 车站人员
【单选题】
机车、车辆长度的计算,以前后两钩舌内侧面距离按___m为换算单位(一辆)。
A. 10
B. 11
C. 15
【单选题】
特快及快速货物班列自动制动机主管压力为___kPa。
A. 500
B. 550
C. 600
【单选题】
遇机车换挂需将自动制动机列车主管压力由600kPa改为500kPa时,摘机前应对列车主管实施一次___kPa的最大减压量操纵。
A. 100
B. 140
C. 170
【单选题】
编入货物列车的关门车数超过现车总辆数的___%时,按规定计算闸瓦压力,并填发制动效能证明书交与司机。
A. 6
B. 10
C. 12
【单选题】
关门车编入货物列车时,不得挂于机车后部___辆车之内。
A. 一
B. 两
C. 三
【单选题】
关门车编入货物列车时,在列车中连续连挂不得超过___辆。
A. 一
B. 两
C. 三
【单选题】
运行速度不超过120km/h的旅客列车(动车组列车除外)在任何线路上的紧急制动距离限值为___m。
A. 800
B. 1000
C. 1200
【单选题】
运行速度不超过120km/h的快速货物班列在任何线路上的紧急制动距离限值为___m。
A. 800
B. 1000
C. 1100
【单选题】
列车中相互连挂的车钩中心水平线的高度差,不得超过___ mm。
A. 75
B. 80
C. 85
【单选题】
列车机车与第一辆车的连挂,由___负责。
A. 调车作业人员
B. 机车乘务员
C. 车站值班员
【单选题】
旅客列车运行途中遇车辆空气弹簧故障时,运行速度不得超过___km/h。
A. 100
B. 120
C. 140
【单选题】
采用密接式车钩的旅客列车,在运行途中因故障更换15号过渡车钩后,运行速度不得超过___km/h。
A. 100
B. 120
C. 140
【单选题】
列车停留超过___min时,应对列车自动制动机应进行简略试验。
A. 10
B. 15
C. 20
【单选题】
挂有列尾装置的货物列车,对列车自动制动机进行简略试验时,由___负责。
A. 列检
B. 车站
C. 司机
【单选题】
调车作业由___单一指挥。
A. 调车领导人
B. 调车指挥人
C. 连结员
【单选题】
调车人员不足___人,不准进行调车作业。
A. 1
B. 2
C. 3
【单选题】
在调车作业中,单机运行或牵引车辆运行时,前方进路的确认由___负责。
A. 调车人员
B. 司机
C. 扳道员
【单选题】
调车作业要准确掌握速度,在空线上推进运行时,不准超过___km/h。
A. 30
B. 40
C. 45
【单选题】
电力机车在有接触网终点的线路上调车时,应控制速度,机车距接触网终点标应有___m 的安全距离。
A. 10
B. 20
C. 30
【单选题】
调动乘坐旅客或装载爆炸品、气体类危险货物、超限货物的车辆时,不准超过___km/h。
A. 10
B. 15
C. 20
【单选题】
调车作业要准确掌握速度,接近被连挂的车辆时,不准超过___ km/h。
A. 3
B. 5
C. 7
【单选题】
调车作业要准确掌握速度,在空线上牵引运行时,不准超过___km/h 。
A. 15
B. 30
C. 40
【单选题】
在尽头线上调车时,距线路终端应有___m 的安全距离。
A. 10
B. 20
C. 30