【多选题】
choose four___
A. DHCP snooping ——————————blocks DHCP messages
B. Dynamic ARP inspection——————verifies IP-to-MAC traffic on untrusted ports
C. IP sources guard ——————————provides layer 2 interface security with ports ACLs
D. Port security————————————mitigates MAC-address spoofing at the access interface
查看试卷,进入试卷练习
微信扫一扫,开始刷题
答案
ABCD
解析
暂无解析
相关试题
【多选题】
choose four___
A. Step1————————run the system setup wizard
B. Step2————————add an authentication realm
C. Step3————————configure identity management
D. Step4————————configure directory group
【多选题】
What are two advanced features of the Cisco AMp solution for endpoints ___
A. contemplation
B. foresight
C. sandboxing
D. reputation
E. reflection
【多选题】
Which two characteristics of RADIUS are true?___
A. It encrypts only the password between user and server.
B. It uses TCP ports 1812/1813
C. It uses UDP ports 1812/1813.
D. It uses UDP port 49
E. It uses TCP port 49
【多选题】
What are two challenges of using a network-based IPS? ___
A. It is unable to determine whether a detected attack was successful
B. It requires additional storage and proce ssor capacity on syslog servers
C. As the network expands, it requires you to add more sensors.
D. It is unable to detect attacks across the entire network
E. It must support multiple operating systems.
【多选题】
What are two default be haviors of the traffic on a zone-based firewall?___
A. Traffic within the self -zone uses an im plicit deny all.
B. All traffic between zones is implicitly blocked
C. Communication is allowed between interfadAss that are members of the same zone
D. Communication is blocked between interfaces that are members of the same zone
E. The CBAC rules that are configured on router interfaces apply to zone interfaces
【多选题】
Which two advantages does the on-premise model for MDM deployment have over the cloud-based model?___
A. The on-premise model is easier and faster to de ploy than the cloud-based model
B. The on-premise model is more scalable than the cloud-based model
C. The on-premise model is generally less expensive than the cloud-based model
D. The on-premise model generally has less latency than the cloud- based model.
E. The on-premise model provides more control of the MDM solution than the cloud
【多选题】
Which two actions can an end usts take to manage a lost or stolen device in Cisco ISE? ___
A. Activate Cisco ISE End point Protection Services to quarantine the device.
B. Add the mac address of the device to a list of blacklisted devices
C. Force the device to be locked with a PIN
D. Request revocation of the digital certificate of the device.
E. Reinstate a device that the user previously marked as lost or stolen
【多选题】
Which two problems can arise when a proxy firewall serves as the gateway between networks?___
A. It can prevent content caching
B. It can limit application support
C. It is unable to prevent direct connections to other networks
D. It can cause reduced throughput.
E. It is unable to provide antivirus protection
【多选题】
When using the Adaptive Security Device Manager(ASDM), which two methods are available to add a new root certificate?___
A. Use sCep
B. Install from SFTP server
C. Install from a file
D. Use Https
E. Use LDAP
【多选题】
Which two are considered basic security principles?___
A. Accountability
B. Redundancy
C. High Availabilit
D. Integrity
E. Confidentiality
【多选题】
Which two roles of the Cisco WSA are true?___
A. IPS
B. firewall
C. antispam
D. web proxy
E. URL filter
【单选题】
Which next-generation encryption algorithm supports four variants?___
A. SHA-2
B. SHA-1
C. MD5
D. HMAC
【单选题】
What aims to remove the abil ity to deny an action?___
A. Non-Repudiation
B. Accountability
C. Integrity
D. Deniability
【单选题】
Which statements about the native VLAN is true ?___
A. It is susceptible to VLAN hopping attacks.
B. It is the Cisco recommended VLAN for switch-management traffic
C. It is most secure when it is a ssigned to vLAn 1.
D. It is the cisco-recomme nded vlan for user traffic
【单选题】
There are two versions of IKE:IKEv1 and IKEv2. Both IKEv1 and IKEv2 protocols operate in phases IKEv1 operates in two phases. IKEv2 operates in how many phases?___
A. 2
B. 3
C. 4
D. 5
【单选题】
What does the dh group refer to?___
A. length of key for hashing C
B. length of key for encryption
C. tunnel lifetime key
D. length of key for key exchange
E. length of key for authentication
【单选题】
Which path do you follow to enable aaa through the SDM ?___
A. Configure Tasks > AAA
B. Configure > Addition Authentication > AAA
C. Configure > AAA
D. Configure > Additional Tasks > AAA
E. Configure Authentication > AAA
【单选题】
which technology cloud be used on top of an MPLS VPN to add confidentiality ?___
A. IPsec
B. 3DES
C. AES
D. SSL
【单选题】
Which term is most closely aligned with the basic purpose of a SIEM solution? ___
A. Non-Repudiation
B. Accountability
C. Causality
D. Repudiation
【单选题】
You have just deployed SNMPv3 in your environment, Your manager asks you to make sure that our SNMP agents can only talk to the SNMP Manager. What would you configure on your SNMI agents to satisfy this request?___
A. A SNMP View containing the SNMP managers
B. Routing Filter with the SNMP managers in it applied outbound
C. A standard ACL containing the SNMP managers applied to the SNMP configuration
D. A SNMP Group containing the SNMP managers
【单选题】
Which feature prevents loops by moving a nontrunking port into an errdisable state when a BPDU is received on that port?___
A. BPDU filte
B. DHCP snooping
C. BPDU guard
D. Port Fast
【单选题】
Which command enables port security to use sticky MAC addresses on a switch?___
A. switchport port-security violation restrict
B. switchport port-security mac-address sticky
C. switchport port-security violation protect
D. switchport port-security
【单选题】
When you edit an IPS subsignature, what is the effect on the parent signature and the family of subsignatures?___
A. The change applies to the parent signature and the entire family of subsignatures
B. The change applies to the parent signature and the subsignature that you edit
C. The change applies only to subsignatures that are numbered sequentially after the subsignature that you edit
D. Other signatures are unaffected, the change applies only to the subsignature that you dit
【单选题】
Which type of mechanism does Cisco FirePOWER de ploy to protect ag detected moving across other networks?___
A. antivirus scanning
B. policy-based
C. reputation-based
D. signature-based
【单选题】
What action must you take on the ise to blacklist a wired device?___
A. Locate the switch through which the device is connected and push an a cl restricting all access by the device
B. Issue a CoA request for the de vice's mac address to each access switch in the network
C. Revoke the device's certificate so it is unable to authenticate to the network
D. Add the device's MAc address to a list of black listed devices
【单选题】
Which type of firewall can perform deep packet inspection?___
A. packet-filtering firewall
B. stateless firewall
C. application firewall
D. personal firewall
【单选题】
What is the main purpose of Control Plane Policing?___
A. to prevent exhaustion of route-proce ssor resources
B. to organize the egress packet queues
C. to define traffic classes
D. to maintain the policy map
【单选题】
Which attack can be prevented by OSPF authentication?___
A. smurf attack
B. IP spoofing attack
C. denial of service attack
D. buffer overflow attack
【单选题】
What is the best definition of hairpinning?___
A. ingress traffic that traverses the outbound interface on a device
B. traffic that enters one interface on a device and that exits through another interface
C. traffic that enters and exits a device through the same interface
D. traffic that tunnels through a device interface
【单选题】
Which SNMPv3 security level provides authentication using HMAC with MD5, but does not use encryption?___
A. authPriv
B. authNo Priv
C. noAuthNoPriv
D. NoauthPriv
【单选题】
You have implemented a dynamic blacklist, using security intelligence to block illicit network activity. However, the blacklist contains several approved connections that users must access for usiness pur poses. Which action can you take to retain the blacklist while allowing users to access the approve d sites?___
A. Create a whitelist and manually add the approved addresses.
B. Disable the dynamic blacklist and deny the specif ic address on a whitelist while permitting the others
C. Edit the dynamic blacklist to remove the approved addresses
D. Disable the dynamic blacklist and create a static blacklist in its place
【单选题】
When connecting to an external resource,you must change a source IP address to use one IP address from a range of 207.165.201.1 to 207.165.1.30. Which option do you implement ?___
A. dynamic source NAT that uses an IP ad dress as a mapped source
B. static destination NAT that uses a subnet as a real de stination
C. dynamic source NAT that uses a range as a mapped source
D. static destination NAT that uses a subnet as a real source
【单选题】
Refer to the exhibit. 【nat(ins,any)dynamic interface】Which ty pe of NaT is configured on a Cisco ASA?___
A. dynamic NAT
B. source identity NAT
C. dynamic PAT
D. identity twice NAT
【单选题】
Which mitigation technology for web-based threats prevents the removal of confidential data from the network?___
A. CTA
B. DCA
C. AMP
D. DLP
【单选题】
Refer to the exhibit. What is the effect of the given configuration?___
A. It establishes the preshared key for the switch
B. It establishes the preshared key for the firewall.
C. It establishes the preshared key for the Cisco ISE appliance
D. It establishes the preshared key for the router.
【多选题】
What are two major considerations when choosing between a SPAN and a TAP when plementing IPS?___
A. the type of analysis the iS will perform
B. the amount of bandwidth available
C. whether RX and TX signals will use separate ports
D. the way in which media errors will be handled
E. the way in which dropped packets will be handled
【多选题】
What are two direct-to-tower methods for redirecting web traffic to Cisco Cloud Web Security?___
A. third-party proxies
B. Cisco Catalyst platforms
C. Cisco NAC Agent
D. hosted PAC files
E. CiSco ISE
【多选题】
Which three descriptions of RADIUS are true? ___
A. It uses TCP as its transport protocol.
B. Only the password is encrypted
C. It supports multiple transport protocols
D. It uses UDP as its transport protocol
E. It combines authentication and authorization
F. It separates authentication,authorization,and accounting
【多选题】
Which two configurations can prevent VLAN hopping attack from attackers at VLAN 10?___
A. using switchport trunk native vlan 10 command on trunk ports
B. enabling BPDU guard on all access ports
C. creating VLAN 99 and using switchport trunk native vlan 99 command on trunk ports
D. applying ACl between VLAN
E. using switchport mode access command on all host ports
F. using switchport nonegotiate command on dynamic desirable ports
【多选题】
What are two features of transparent firewall mode ___
A. It conceals the presence of the firewall from attackers
B. It allows some traffic that is blocked in routed mode
C. It enables the aSA to perform as a router.
D. It acts as a routed hop in the network.
E. It is configured by default
推荐试题
【多选题】
以国共两党第二次合作为基础的抗日民族统一战线正式形成的标志是 ___
A. 1937年国民党五届三中全会
B. 1937年蒋介石发表承认共产党合法地位的谈话
C. 国民党中央通讯社发表《中国共产党为公布国共合作宣言》
D. 西安事变的和平解决
【多选题】
1938年5月至6月间,毛泽东在《论持久战》中论述的中日矛盾双方的特点是 ___
A. 敌强我弱
B. 敌小国我大国
C. 敌退步我进步
D. 敌寡助我多助
【多选题】
中国共产党在中国革命中战胜敌人的三个主要法宝是 ___
A. 独立自主
B. 统一战线
C. 武装斗争
D. 党的建设
【多选题】
在20世纪30年代后期和40年代前期,毛泽东论述新民主主义革命理论的著作是___
A. 《论持久战》
B. 《(共产党人)发刊词》
C. 《中国革命和中国共产党》
D. 《新民主主义论》
【多选题】
1941年和1942年毛泽东为延安整风所作的报告是 ___
A. 《改造我们的学习》
B. 《整顿党的作风》
C. 《反对党八股》
D. 《中国革命和中国共产党》
【多选题】
抗日战争时期延安整风运动的主要内容是 ___
A. 反对主观主义以整顿学风
B. 反对主观主义以整顿党风
C. 反对宗派主义以整顿党风
D. 反对党八股以整顿文风
【多选题】
在抗日民族统一战线中,中国共产党争取的中间势力指的是 ___
A. 民族资产阶级
B. 开明绅士
C. 城市小资产阶级
D. 地方实力派
【多选题】
1939年7月,针对蒋介石消极抗日、积极反共,中国共产党明确提出的政治方针是___
A. 坚持抗战,反对妥协
B. 坚持团结,反对分裂
C. 坚持进步,反对倒退
D. 坚持抗战,反对投降
【多选题】
在抗日战争时期,蒋介石集团为代表的国民党亲英美派 ___
A. 坚持片面抗战路线
B. 坚持既抗日,又限共、融共、反共方针
C. 组织国民党军队担负正面战场的抗战
D. 是抗日民族统一战线中的顽固势力
【多选题】
中国共产党为了战胜困难,坚持长期抗战,争取最后胜利,先后制定了巩固解放区的十大政策。其中,两个中心环节是 ___
A. 整风运动
B. 大生产运动
C. 减租减息
D. 精兵简政
【多选题】
毛泽东在《新民主主义论》中提出了党关于新民主主义革命的三大纲领是 ___
A. 政治纲领
B. 经济纲领
C. 军事纲领
D. 文化纲领
【多选题】
毛泽东在《论持久战》中指出,抗日战争要经过三个阶段是___
A. 战略相持
B. 战略反攻
C. 战略防御
D. 战略退却
【多选题】
在敌后军民的艰苦抗战中,涌现了无数可歌可泣的民族英雄,他们是 ___
A. 左权
B. 赵尚志
C. 杨靖宇
D. 彭雪枫
【多选题】
中国共产党民主革命中战胜敌人的三大法宝是:___
A. 土地革命
B. 武装斗争
C. 统一战线
D. 党的建设
【多选题】
皖南事变中遇难的新四军将领有 ___
A. 叶挺
B. 项英
C. 袁国平
D. 彭雪枫
【多选题】
中国共产党在抗日民族统一战线中的策略总方针是 ___
A. 发展进步势力
B. 争取中间势力
C. 孤立顽固势力
D. 打击资产阶级
【多选题】
九一八事变发生后,国民党军队中的部分爱国官兵进行的局部抗战活动有 ___
A. 原东北军为主体的抗日义勇军在东北抗日
B. 国民党第19路军的凇沪抗战
C. 冯玉祥组织察哈尔民众抗日同盟军
D. 国民党第19路军将领蔡廷锴、蒋光鼐发动福建事变
【多选题】
关于西安事变,正确的表述有 ___
A. 是爱国将领张杨两将军发动的反蒋抗日的“兵谏”
B. 西安事变的和平解决成为时局转换的枢纽
C. 迫使蒋介石作出停止剿共、联合红军抗日等六项承诺
D. 中国共产党采取了促成事变和平解决的基本方针
【多选题】
八路军在华北开辟的抗日根据地有 ___
A. 晋察冀
B. 晋西北
C. 晋冀豫
D. 湘鄂西
【多选题】
抗日战争中,中国共产党领导的游击战争的战略地位和作用表现为 ___
A. 在战略防御阶段,对正面战场起到配合与辅助作用
B. 在战略防御阶段,对阻止日军进攻、减轻正面战场压力,使战争转入相持阶段起到关键作用
C. 在战略相持阶段,成为主要的抗日作战方式
D. 在战略相持阶段,牵制着侵华日军兵力的一半以上
【多选题】
中国抗日战争在世界反法西斯战争中的重要地位表现为 ___
A. 是世界反法西斯的东方主战场
B. 抗击和牵制着日本陆军的主力
C. 是世界反法西斯战争的五大国之一
D. 中国的持久抗战。大大减轻了其他反法西斯战场的压力
【多选题】
1935年日本策动“防共自治运动”,其中华北五省是___
A. 河北
B. 察哈尔
C. 绥远
D. 山西
【多选题】
抗日战争期间,日本在东北设立的两大垄断企业是___
A. 东亚银行
B. 南满铁路株式会社
C. 满洲重工业股份公司
D. 东北开发股份公司
【多选题】
1936年5月,发起成立全国各界救国联合会的爱国民主人士包括___
A. 宋庆龄
B. 沈钧儒
C. 邹韬奋
D. 陶行知
【多选题】
抗战初期,国民党正面战场除了除了台儿庄战役取得大捷外,其他战役几乎都是以退却、失败而结束的,造成这种状况的原因___
A. 由于在敌我力量对比上,日军占很大优势
B. 国民党战略指导方针上的失误
C. 实行片面抗战路线
D. 没有采取积极防御的方针
【多选题】
1939年,国民党成立“防共委员会”,其方针为___
A. 防共
B. 限共
C. 剿共
D. 溶共
【多选题】
1945年,联合发表波茨坦公告的三个国家是___
A. 法国
B. 中国
C. 美国
D. 英国
【多选题】
抗日民族统一战线的策略总方针是___
A. 发展进步势力
B. 争取中间势力
C. 孤立顽固势力
D. 反对投降势力
【多选题】
抗日战争时期,中国共产党主办的___报刊在国民党统治区公开发行,及时宣传党的主张,鼓舞和激励群众的抗战热情
A. 《新华日报》
B. 《群众》周刊
C. 《向导》周报
D. 《热血日报》
【多选题】
1945年重庆谈判前,中共中央提出的三大口号是 ___
A. 和平
B. 民主
C. 统一
D. 团结
【多选题】
促使民主党派与蒋介石集团决裂,同中国共产党并肩战斗的原因有 ___
A. 国民党撕毁协议,发动全面内战
B. 蒋介石非法召开“国民大会”,制定伪宪法
C. 人民解放军转入进攻,国统区反蒋斗争高涨
D. 三大战役胜利,全国解放在望
【多选题】
抗战胜利后,中国各民主党派的共同点在于 ___
A. 主张爱国
B. 主张民主
C. 反对卖国
D. 反对独裁
【多选题】
下列事件发生在1947年的是 ___
A. 一·二一运动
B. 民盟被解散
C. 《中国土地法大纲》的制定
D. 五二0运动
【多选题】
下列事件中,不是在台湾发生的有 ___
A. 抗议美军暴行运动
B. “反饥饿、反内战、反迫害”运动
C. 二二八起义
D. 李公朴、闻一多被暗杀
【多选题】
下列与国统区严重经济危机有关的是 ___
A. 财政金融极其紊乱,赤字惊人
B. 工商企业大量倒闭破产,工人失业
C. 农业生产衰退,粮荒严重
D. 物价飞涨
【多选题】
下列属于《中国土地法大纲》主要内容的有 ___
A. 废除封建剥削的土地制度
B. 保护中小工商业者
C. 实行耕者有其田的土地制度
D. 分地给无地或少地的农民
【多选题】
出席中国人民政治协商会议的代表,除中共和各民主党派外,还有 ___
A. 各人民团体的代表
B. 各地区各民族和海外华侨代表
C. 中国人民解放军各部队代表
D. 特别邀请代表
【多选题】
1945年8月到1946年6月的中国 ___
A. 处于民族战争向国内战争的过渡阶段
B. 国内阶级矛盾上升为主要矛盾
C. 政治斗争的基本内容是争取和平民主、反对独裁内战
D. 斗争的焦点是建立一个怎样的国家
【多选题】
1O.下列关于重庆谈判的表述,正确的是 ___
A. 共产党与国民党进行了不妥协的斗争
B. 国民党被迫承认和平建国基本方针
C. 《双十协定》的签订是人民力量的胜利
D. 中共取得了政治上的主动地位
【多选题】
1945年8月到重庆参加与蒋介石谈判的中共代表是 ___
A. 刘少奇
B. 毛泽东
C. 周恩来
D. 王若飞