【多选题】
choose four___
A. Step1————————run the system setup wizard
B. Step2————————add an authentication realm
C. Step3————————configure identity management
D. Step4————————configure directory group
查看试卷,进入试卷练习
微信扫一扫,开始刷题
答案
ABCD
解析
暂无解析
相关试题
【多选题】
What are two advanced features of the Cisco AMp solution for endpoints ___
A. contemplation
B. foresight
C. sandboxing
D. reputation
E. reflection
【多选题】
Which two characteristics of RADIUS are true?___
A. It encrypts only the password between user and server.
B. It uses TCP ports 1812/1813
C. It uses UDP ports 1812/1813.
D. It uses UDP port 49
E. It uses TCP port 49
【多选题】
What are two challenges of using a network-based IPS? ___
A. It is unable to determine whether a detected attack was successful
B. It requires additional storage and proce ssor capacity on syslog servers
C. As the network expands, it requires you to add more sensors.
D. It is unable to detect attacks across the entire network
E. It must support multiple operating systems.
【多选题】
What are two default be haviors of the traffic on a zone-based firewall?___
A. Traffic within the self -zone uses an im plicit deny all.
B. All traffic between zones is implicitly blocked
C. Communication is allowed between interfadAss that are members of the same zone
D. Communication is blocked between interfaces that are members of the same zone
E. The CBAC rules that are configured on router interfaces apply to zone interfaces
【多选题】
Which two advantages does the on-premise model for MDM deployment have over the cloud-based model?___
A. The on-premise model is easier and faster to de ploy than the cloud-based model
B. The on-premise model is more scalable than the cloud-based model
C. The on-premise model is generally less expensive than the cloud-based model
D. The on-premise model generally has less latency than the cloud- based model.
E. The on-premise model provides more control of the MDM solution than the cloud
【多选题】
Which two actions can an end usts take to manage a lost or stolen device in Cisco ISE? ___
A. Activate Cisco ISE End point Protection Services to quarantine the device.
B. Add the mac address of the device to a list of blacklisted devices
C. Force the device to be locked with a PIN
D. Request revocation of the digital certificate of the device.
E. Reinstate a device that the user previously marked as lost or stolen
【多选题】
Which two problems can arise when a proxy firewall serves as the gateway between networks?___
A. It can prevent content caching
B. It can limit application support
C. It is unable to prevent direct connections to other networks
D. It can cause reduced throughput.
E. It is unable to provide antivirus protection
【多选题】
When using the Adaptive Security Device Manager(ASDM), which two methods are available to add a new root certificate?___
A. Use sCep
B. Install from SFTP server
C. Install from a file
D. Use Https
E. Use LDAP
【多选题】
Which two are considered basic security principles?___
A. Accountability
B. Redundancy
C. High Availabilit
D. Integrity
E. Confidentiality
【多选题】
Which two roles of the Cisco WSA are true?___
A. IPS
B. firewall
C. antispam
D. web proxy
E. URL filter
【单选题】
Which next-generation encryption algorithm supports four variants?___
A. SHA-2
B. SHA-1
C. MD5
D. HMAC
【单选题】
What aims to remove the abil ity to deny an action?___
A. Non-Repudiation
B. Accountability
C. Integrity
D. Deniability
【单选题】
Which statements about the native VLAN is true ?___
A. It is susceptible to VLAN hopping attacks.
B. It is the Cisco recommended VLAN for switch-management traffic
C. It is most secure when it is a ssigned to vLAn 1.
D. It is the cisco-recomme nded vlan for user traffic
【单选题】
There are two versions of IKE:IKEv1 and IKEv2. Both IKEv1 and IKEv2 protocols operate in phases IKEv1 operates in two phases. IKEv2 operates in how many phases?___
A. 2
B. 3
C. 4
D. 5
【单选题】
What does the dh group refer to?___
A. length of key for hashing C
B. length of key for encryption
C. tunnel lifetime key
D. length of key for key exchange
E. length of key for authentication
【单选题】
Which path do you follow to enable aaa through the SDM ?___
A. Configure Tasks > AAA
B. Configure > Addition Authentication > AAA
C. Configure > AAA
D. Configure > Additional Tasks > AAA
E. Configure Authentication > AAA
【单选题】
which technology cloud be used on top of an MPLS VPN to add confidentiality ?___
A. IPsec
B. 3DES
C. AES
D. SSL
【单选题】
Which term is most closely aligned with the basic purpose of a SIEM solution? ___
A. Non-Repudiation
B. Accountability
C. Causality
D. Repudiation
【单选题】
You have just deployed SNMPv3 in your environment, Your manager asks you to make sure that our SNMP agents can only talk to the SNMP Manager. What would you configure on your SNMI agents to satisfy this request?___
A. A SNMP View containing the SNMP managers
B. Routing Filter with the SNMP managers in it applied outbound
C. A standard ACL containing the SNMP managers applied to the SNMP configuration
D. A SNMP Group containing the SNMP managers
【单选题】
Which feature prevents loops by moving a nontrunking port into an errdisable state when a BPDU is received on that port?___
A. BPDU filte
B. DHCP snooping
C. BPDU guard
D. Port Fast
【单选题】
Which command enables port security to use sticky MAC addresses on a switch?___
A. switchport port-security violation restrict
B. switchport port-security mac-address sticky
C. switchport port-security violation protect
D. switchport port-security
【单选题】
When you edit an IPS subsignature, what is the effect on the parent signature and the family of subsignatures?___
A. The change applies to the parent signature and the entire family of subsignatures
B. The change applies to the parent signature and the subsignature that you edit
C. The change applies only to subsignatures that are numbered sequentially after the subsignature that you edit
D. Other signatures are unaffected, the change applies only to the subsignature that you dit
【单选题】
Which type of mechanism does Cisco FirePOWER de ploy to protect ag detected moving across other networks?___
A. antivirus scanning
B. policy-based
C. reputation-based
D. signature-based
【单选题】
What action must you take on the ise to blacklist a wired device?___
A. Locate the switch through which the device is connected and push an a cl restricting all access by the device
B. Issue a CoA request for the de vice's mac address to each access switch in the network
C. Revoke the device's certificate so it is unable to authenticate to the network
D. Add the device's MAc address to a list of black listed devices
【单选题】
Which type of firewall can perform deep packet inspection?___
A. packet-filtering firewall
B. stateless firewall
C. application firewall
D. personal firewall
【单选题】
What is the main purpose of Control Plane Policing?___
A. to prevent exhaustion of route-proce ssor resources
B. to organize the egress packet queues
C. to define traffic classes
D. to maintain the policy map
【单选题】
Which attack can be prevented by OSPF authentication?___
A. smurf attack
B. IP spoofing attack
C. denial of service attack
D. buffer overflow attack
【单选题】
What is the best definition of hairpinning?___
A. ingress traffic that traverses the outbound interface on a device
B. traffic that enters one interface on a device and that exits through another interface
C. traffic that enters and exits a device through the same interface
D. traffic that tunnels through a device interface
【单选题】
Which SNMPv3 security level provides authentication using HMAC with MD5, but does not use encryption?___
A. authPriv
B. authNo Priv
C. noAuthNoPriv
D. NoauthPriv
【单选题】
You have implemented a dynamic blacklist, using security intelligence to block illicit network activity. However, the blacklist contains several approved connections that users must access for usiness pur poses. Which action can you take to retain the blacklist while allowing users to access the approve d sites?___
A. Create a whitelist and manually add the approved addresses.
B. Disable the dynamic blacklist and deny the specif ic address on a whitelist while permitting the others
C. Edit the dynamic blacklist to remove the approved addresses
D. Disable the dynamic blacklist and create a static blacklist in its place
【单选题】
When connecting to an external resource,you must change a source IP address to use one IP address from a range of 207.165.201.1 to 207.165.1.30. Which option do you implement ?___
A. dynamic source NAT that uses an IP ad dress as a mapped source
B. static destination NAT that uses a subnet as a real de stination
C. dynamic source NAT that uses a range as a mapped source
D. static destination NAT that uses a subnet as a real source
【单选题】
Refer to the exhibit. 【nat(ins,any)dynamic interface】Which ty pe of NaT is configured on a Cisco ASA?___
A. dynamic NAT
B. source identity NAT
C. dynamic PAT
D. identity twice NAT
【单选题】
Which mitigation technology for web-based threats prevents the removal of confidential data from the network?___
A. CTA
B. DCA
C. AMP
D. DLP
【单选题】
Refer to the exhibit. What is the effect of the given configuration?___
A. It establishes the preshared key for the switch
B. It establishes the preshared key for the firewall.
C. It establishes the preshared key for the Cisco ISE appliance
D. It establishes the preshared key for the router.
【多选题】
What are two major considerations when choosing between a SPAN and a TAP when plementing IPS?___
A. the type of analysis the iS will perform
B. the amount of bandwidth available
C. whether RX and TX signals will use separate ports
D. the way in which media errors will be handled
E. the way in which dropped packets will be handled
【多选题】
What are two direct-to-tower methods for redirecting web traffic to Cisco Cloud Web Security?___
A. third-party proxies
B. Cisco Catalyst platforms
C. Cisco NAC Agent
D. hosted PAC files
E. CiSco ISE
【多选题】
Which three descriptions of RADIUS are true? ___
A. It uses TCP as its transport protocol.
B. Only the password is encrypted
C. It supports multiple transport protocols
D. It uses UDP as its transport protocol
E. It combines authentication and authorization
F. It separates authentication,authorization,and accounting
【多选题】
Which two configurations can prevent VLAN hopping attack from attackers at VLAN 10?___
A. using switchport trunk native vlan 10 command on trunk ports
B. enabling BPDU guard on all access ports
C. creating VLAN 99 and using switchport trunk native vlan 99 command on trunk ports
D. applying ACl between VLAN
E. using switchport mode access command on all host ports
F. using switchport nonegotiate command on dynamic desirable ports
【多选题】
What are two features of transparent firewall mode ___
A. It conceals the presence of the firewall from attackers
B. It allows some traffic that is blocked in routed mode
C. It enables the aSA to perform as a router.
D. It acts as a routed hop in the network.
E. It is configured by default
【多选题】
Which two models of A sa tend to be used in a data center?___
A. 5555X
B. 5585X
C. ASA service module
D. 5512X
E. 5540
F. 5520
推荐试题
【单选题】
在解放战争时期,革命的主要对象是___。
A. 帝国主义支持下的北洋军阀
B. 日本帝国主义
C. 国民党新军阀
D. 美帝国主义支持下的国民党反动派
【单选题】
___是中国革命最基本的动力。
A. 农民
B. 民族资产阶级
C. 无产阶级
D. 城市小资产阶级
【单选题】
___是中国革命的主力军。
A. 农民
B. 民族资产阶级
C. 无产阶级
D. 城市小资产阶级
【单选题】
___是无产阶级的可靠同盟者
A. 农民
B. 民族资产阶级
C. 无产阶级
D. 城市小资产阶级
【单选题】
___也是中国革命的动力之一。
A. 农民
B. 民族资产阶级
C. 无产阶级
D. 城市小资产阶级
【单选题】
___是中国革命的中心问题,也是新民主主义革命理论的核心问题。
A. 革命的性质
B. 无产阶级的领导权
C. 革命的前途
D. 革命的动力
【单选题】
___,是中国革命取得胜利的根本保证。
A. 无产阶级及其政党的领导
B. 对农民问题的重视
C. 有稳固的群众基础
D. 革命的前途是社会主义
【单选题】
无产阶级及其政党实现对各革命阶级的领导,必须建立___,这是实现领导权的关键。
A. 人民军队
B. 以工农联盟为基础的广泛的统一战线
C. 革命根据地
D. 各革命阶级的联合专政
【单选题】
加强___,是实现无产阶级领导权的根本保证
A. 无产阶级政党的建设
B. 无产阶级政党的思想建设
C. 无产阶级政党组织学习
D. 无产阶级政党的作风建设
【单选题】
建立一支无产阶级领导的___,是保证领导权的坚强支柱。
A. 以农民为主的主力军
B. 有民族资产阶级参加的统一战线
C. 以农民为主体的强大的革命武装
D. 以民族资产阶级为主体的强大的革命武装
【单选题】
___。
A. 社会主义革命
B. 资产阶级民主主义革命
C. 新民主主义革命
D. 资产阶级革命
【单选题】
毛泽东指出:“民主主义革命是社会主义革命的___,社会主义革命是民主主义革命的(A)”。
A. 必要准备;必然趋势
B. 必然趋势;必要准备
C. 必要准备;必然基础
D. 必然准备,必然趋势
【单选题】
新民主主义革命的前途是___。
A. 资本主义
B. 新民主主义社会
C. 社会主义
D. 社会主义改造
【单选题】
___,是新民主主义经济纲领中极具特色的一项内容。
A. 没收封建地主阶级的土地归农民所有
B. 没收官僚资本归新民主主义国家所有
C. 没收官僚资本归社会主义国家所有
D. 保护民族工商业
【单选题】
我国新民主主义革命阶段基本结束和社会主义革命阶段开始的标志是___
A. 中华人民共和国的成立
B. 土地改革的完成
C. 社会主义改造基本完成
D. 第一届全国人民代表大会召开
【单选题】
从中华人民共和国成立到社会主义改造基本完成,中国社会是新民主主义社会,它从属于___
A. 社会主义范畴
B. 资本主义范畴
C. 民主主义范畴
D. 共产主义范畴
【单选题】
土地改革基本完成后中国国内的主要阶级矛盾是___
A. 人民大众和封建主义的矛盾
B. 工人阶级和资产阶级的矛盾
C. 农民阶级和地主阶级的矛盾
D. 人民对于经济文化迅速发展的需要同当前经济文化不能满足人民需要的矛盾
【单选题】
在新民主主义社会的经济成分里,在国民经济中占有绝对优势地位的是___
A. 通过没收官僚资本形成的社会主义国营经济
B. 私人资本主义经济
C. 农业和手工业为主体的个体经济
D. 国家资本主义
【单选题】
在新民主主义社会主要经济成分里居于领导地位的是___
A. 个体经济
B. 合作经济
C. 国营经济
D. 私人资本主义经济
【单选题】
经过了以土地革命为主要内容的新民主主义革命,广大无地少地的农民者得到了土地,这时的农民得到的是土地的___
A. 所有权
B. 经营使用权
C. 受益权
D. 继承权
【单选题】
新民主主义社会性质是___
A. 资本主义社会
B. 后资本主义社会
C. 社会主义社会
D. 由新民主主义向社会主义转变的过渡性社会
【单选题】
在新中国成立后的一个时期内半社会主义性质的合作经济是___
A. 私人资本主义经济向社会主义国营经济的过渡形式
B. 个体经济向社会主义集体经济的过渡形式
C. 个体经济向社会主义公有制经济过渡的形式
D. 资本主义个体经济向社会主义个体经济过渡形式
【单选题】
新中国成立后的一个时期国家资本主义经济本质上是___
A. 资本主义经济
B. 社会主义经济
C. 社会主义国营经济
D. 新民主主义国家政权控制和调节的具有社会主义取向的资本主义经济
【单选题】
过渡时期的总路线和总任务是___
A. 无产阶级领导的人民大众的反对帝国主义封建主义官僚资本主义的革命
B. 要在一个相当长的时期内逐步实现国家的社会主义工业化并逐步实现国家对农业、手工业和对资本主义工商业的社会主义改造
C. 鼓足干劲,力争上游,多快好省的建设社会主义
D. 以经济建设为中心,坚持四项基本原则,坚持改革开放,自力更生,艰苦创业,为把中国建设成为富强民主文明的社会主义现代化国家奋斗
【单选题】
1952 年提出的过渡时期总路线的过渡时期是指___
A. 从中华人民共和国成立到社会主义建成
B. 从国民经济恢复到社会主义改造完成
C. 从中华人民共和国成立到社会主义改造基本完成
D. 从总路线提出到建成社会主义
【单选题】
过渡时期总路线的主要内容被概括为“一化三改”,其中“一化”是指___
A. 社会主义工业化
B. 社会主义现代化
C. 农业机械化
D. 农业集体化
【单选题】
党的过渡时期总路线内容的主体是___
A. 三大改造
B. 对农业的社会主义改造
C. 社会主义革命和社会主义建设同时并举
D. 实现工业化
【单选题】
过渡时期总路线最显著的特点是___
A. 社会主义改造和工业化同时并举
B. 民主革命和社会主义革命同时并举
C. 先合作化后工业化
D. 社会主义改造和社会主义改革同时并举
【单选题】
过渡时期总路线是中国共产党在一个较长时期内对中国农业、手工业和资本主义工商业改造的指导性路线,党中央制造这个总路线的主旨是___
A. 变革经济体制
B. 变革所有制
C. 变革政治制度
D. 变革生产力
【单选题】
我国农业合作化具有社会主义萌芽性质的农业生产组织形式的最初形式是___
A. 换工劳动
B. 互助组
C. 初级社
D. 高级社
【单选题】
农业社会主义改造过程中具有半社会主义性质的过渡形式是___
A. 互助组
B. 初级社
C. 高级社
D. 人民公社
【单选题】
我国资本主义工商业进行社会主义改造中一个创新性办法是对民族资本实行___
A. 和平赎买
B. 剥夺生产资料
C. 公司合营
D. 生活上给出路
【单选题】
新中国在对资本主义工商业实行社会主义改造的过程中,在利润分配上采取的是___
A. 统筹兼顾
B. 劳资两利
C. 公私兼顾
D. 四马分肥
【单选题】
新中国进入社会主义初级阶段的标志是___
A. 中华人民共和国成立
B. 社会主义改造基本完成
C. 中共十一届三中全会
D. 文化大革命结束
【单选题】
第一届全国人民代表大会召开的时间是___
A. 1949 年
B. 1952 年
C. 1954 年
D. 1956 年
【单选题】
资本主义工商业的社会主义改造基本完成的标志是___
A. 计划订购统购包销全面铺开
B. 个别企业的公司合营开始
C. 全行业公私合营全面完成
D. 取消定息
【单选题】
中华人民共和国的第一部宪法是___
A. 《中国人民政治协商会议共同纲领》
B. 1954 年宪法
C. 1976 年宪法
D. 1982 年宪法
【单选题】
年三大社会主义改造的基本完成,标志着我国___
A. 实现了国民经济的全面恢复
B. 社会主义制度的基本确立
C. 第二个五年计划的胜利完成
D. 新民主义社会的开始
【单选题】
毛泽东正式提出过渡时期总路线和总任务是在___年。
A. 1951
B. 1952
C. 1953
D. 1954
【单选题】
高级形式的国家资本主义是___
A. 个别企业的公私合营和全行业公私合营
B. 和平赎买
C. 委托加工
D. 计划订货