【单选题】
Which type of firewall can perform deep packet inspection?___
A. packet-filtering firewall
B. stateless firewall
C. application firewall
D. personal firewall
查看试卷,进入试卷练习
微信扫一扫,开始刷题

答案
A
解析
暂无解析
相关试题
【单选题】
What is the main purpose of Control Plane Policing?___
A. to prevent exhaustion of route-proce ssor resources
B. to organize the egress packet queues
C. to define traffic classes
D. to maintain the policy map
【单选题】
Which attack can be prevented by OSPF authentication?___
A. smurf attack
B. IP spoofing attack
C. denial of service attack
D. buffer overflow attack
【单选题】
What is the best definition of hairpinning?___
A. ingress traffic that traverses the outbound interface on a device
B. traffic that enters one interface on a device and that exits through another interface
C. traffic that enters and exits a device through the same interface
D. traffic that tunnels through a device interface
【单选题】
Which SNMPv3 security level provides authentication using HMAC with MD5, but does not use encryption?___
A. authPriv
B. authNo Priv
C. noAuthNoPriv
D. NoauthPriv
【单选题】
You have implemented a dynamic blacklist, using security intelligence to block illicit network activity. However, the blacklist contains several approved connections that users must access for usiness pur poses. Which action can you take to retain the blacklist while allowing users to access the approve d sites?___
A. Create a whitelist and manually add the approved addresses.
B. Disable the dynamic blacklist and deny the specif ic address on a whitelist while permitting the others
C. Edit the dynamic blacklist to remove the approved addresses
D. Disable the dynamic blacklist and create a static blacklist in its place
【单选题】
When connecting to an external resource,you must change a source IP address to use one IP address from a range of 207.165.201.1 to 207.165.1.30. Which option do you implement ?___
A. dynamic source NAT that uses an IP ad dress as a mapped source
B. static destination NAT that uses a subnet as a real de stination
C. dynamic source NAT that uses a range as a mapped source
D. static destination NAT that uses a subnet as a real source
【单选题】
Refer to the exhibit. 【nat(ins,any)dynamic interface】Which ty pe of NaT is configured on a Cisco ASA?___
A. dynamic NAT
B. source identity NAT
C. dynamic PAT
D. identity twice NAT
【单选题】
Which mitigation technology for web-based threats prevents the removal of confidential data from the network?___
A. CTA
B. DCA
C. AMP
D. DLP
【单选题】
Refer to the exhibit. What is the effect of the given configuration?___
A. It establishes the preshared key for the switch
B. It establishes the preshared key for the firewall.
C. It establishes the preshared key for the Cisco ISE appliance
D. It establishes the preshared key for the router.
【多选题】
What are two major considerations when choosing between a SPAN and a TAP when plementing IPS?___
A. the type of analysis the iS will perform
B. the amount of bandwidth available
C. whether RX and TX signals will use separate ports
D. the way in which media errors will be handled
E. the way in which dropped packets will be handled
【多选题】
What are two direct-to-tower methods for redirecting web traffic to Cisco Cloud Web Security?___
A. third-party proxies
B. Cisco Catalyst platforms
C. Cisco NAC Agent
D. hosted PAC files
E. CiSco ISE
【多选题】
Which three descriptions of RADIUS are true? ___
A. It uses TCP as its transport protocol.
B. Only the password is encrypted
C. It supports multiple transport protocols
D. It uses UDP as its transport protocol
E. It combines authentication and authorization
F. It separates authentication,authorization,and accounting
【多选题】
Which two configurations can prevent VLAN hopping attack from attackers at VLAN 10?___
A. using switchport trunk native vlan 10 command on trunk ports
B. enabling BPDU guard on all access ports
C. creating VLAN 99 and using switchport trunk native vlan 99 command on trunk ports
D. applying ACl between VLAN
E. using switchport mode access command on all host ports
F. using switchport nonegotiate command on dynamic desirable ports
【多选题】
What are two features of transparent firewall mode ___
A. It conceals the presence of the firewall from attackers
B. It allows some traffic that is blocked in routed mode
C. It enables the aSA to perform as a router.
D. It acts as a routed hop in the network.
E. It is configured by default
【多选题】
Which two models of A sa tend to be used in a data center?___
A. 5555X
B. 5585X
C. ASA service module
D. 5512X
E. 5540
F. 5520
【多选题】
Which two statements about hardware-based encrption are true?___
A. It is widely accessible
B. It is potentially easier to compromise than software-based encryption. It requires minimal configuration
C. It requires minimal configuration
D. It can be implemented without impacting performance
E. It is highly cost-effective
【多选题】
In which two modes can the Cisco We b Security appliance be de ployed?___
A. as a transparent proxy using the Secure Sockets Layer protocol
B. as a transparent proxy using the Web Cache Communication Protocol
C. explicit proxy mode
D. as a transparent proxy using the Hyper Text Transfer Protocol
E. explicit active mode
推荐试题
【判断题】
按照《商业银行市场风险管理指引》规定,商业银行应当建立全面、严密的压力测试程序,不定期对突发的大概率事件,如市场价格发生剧烈变动,或者发生意外的政治、经济事件可能造成的潜在损失进行模拟和估计,以评估本行在极端不利情况下的亏损承受能力
A. 对
B. 错
【判断题】
按照《商业银行市场风险管理指引》规定,商业银行应当避免其薪酬制度和激励机制与市场风险管理目标产生利益冲突。董事会和高级管理层应当避免薪酬制度具有鼓励过度冒险投资的负面效应,防止绩效考核过于注重短期投资收益表现,而不考虑长期投资风险
A. 对
B. 错
【判断题】
商业银行甲希望能在短期内获得投资收益,根据《商业银行市场风险管理指引》董事会和高级管理层商讨并制定了若半年内业绩上涨50%,则对主要业务人员进行加薪升职奖励
A. 对
B. 错
【判断题】
按照《中国银监会关于进一步加强商业银行市场风险工作的通知》规定,各行应结合本行的风险管理架构和特点,指定专门部门统一负责掌控全行总体市场风险状况,并负责向专门委员会和高管层汇报,应将境内外分支机构的市场风险管理纳入统一的市场风险管理中,并建立统一的市场风险管理信息系统
A. 对
B. 错
【判断题】
按照《中国银监会关于进一步加强商业银行市场风险工作的通知》规定,各行应使从事市场风险管理的部门及人员与承担风险的业务经营部门及人员完全独立,从事市场风险管理的部门与承担风险的业务经营部门应向同一高管人员报告工作
A. 对
B. 错
【判断题】
按照《中国银监会关于进一步加强商业银行市场风险工作的通知》规定,各行应加强对市场风险管理部门的人力资源配置。从事市场风险管理的部门负责人应具备十年以上与市场风险管理相关的工作经验,该部门下设的与市场风险管理工作相关的团队(或处室)主要负责人应具备五年以上与市场风险管理相关的工作经验
A. 对
B. 错
【判断题】
按照《中国银监会关于进一步加强商业银行市场风险工作的通知》规定,各行应以现有人民币国债和相关产品交易价格为基础,采用国际通用的方法研究并建立基于市场的人民币国债价格变动曲线,作为人民币产品定价和风险管理的基础
A. 对
B. 错
【判断题】
按照《中国银监会关于进一步加强商业银行市场风险工作的通知》规定,各行应加强对复杂衍生产品的风险管理工作,将复杂衍生产品纳入到市场风险管理系统之中,应在人民币国债收益率曲线的基础上,研发具体有效的产品定价模型,并在此基础上计算相关的风险参数,为对冲各类风险提供参考
A. 对
B. 错
【判断题】
甲为从事市场风险管理部门的员工,乙为承担风险的业务经营部门的员工,根据《中国银监会关于进一步加强商业银行市场风险工作的通知》甲乙都向高管丁报告各自工作进度
A. 对
B. 错
【判断题】
根据《中国银监会关于进一步加强商业银行市场风险工作的通知》,商业银行甲招收了一名具备两年与市场风险管理相关的工作经验的优秀人才作为从事市场风险管理部门的负责人
A. 对
B. 错
【判断题】
按照《中国银监会关于加大防范操作风险工作力度的通知》规定,对大额出账和走账,手续上必须按照不同额度设限,分别由基层行单人人验核或由上级行独立进行复审、批准
A. 对
B. 错
【判断题】
按照《中国银监会关于加大防范操作风险工作力度的通知》规定,基层主管轮岗轮调和强制性休假制度可以由人事部门按照规定就拟轮岗轮调和休假主管的顶替人员,结合实际工作进行临时安排
A. 对
B. 错
【判断题】
按照《商业银行声誉风险管理指引》规定,商业银行应将声誉风险管理纳入公司治理及全面风险管理体系,建立和制定声誉风险管理机制、办法、相关制度和要求,主动、有效地防范声誉风险和应对声誉事件,最大程度地减少对商业银行造成的损失和负面影响
A. 对
B. 错
【判断题】
按照《商业银行声誉风险管理指引》规定,商业银行董事会应制定与本行战略目标一致且适用于全行的声誉风险管理政策,建立全行声誉风险管理体系,监控全行声誉风险管理的总体状况和有效性,承担声誉风险管理的最终责任
A. 对
B. 错
【判断题】
2008年美国次贷危机爆发,在雷曼兄弟公司倒闭后,持有雷曼兄弟公司金融资产的XX银行被曝存在大额投资亏损的可能。该行积极应对,一方面迅速清查风险敞口情况,通过各种途径挽回损失;另一方面,及时回应媒体报道, 避免了声誉事件的扩大。此后,该行股价又回归正常。依据《商业银行声誉风险管理指引》规定,该行主动、有效地防范了声誉风险和应对声誉事件,最大程度地减少了对社会公众造成的损失和负面影响
A. 对
B. 错
【判断题】
今年以来,商业银行收费问题又成为社会和媒体关注的热点,广受诟病。依据《商业银行声誉风险管理指引》规定,可以看出个别商业银行在出台相关政策、措施前调研不够、考虑不周,在声誉风险管理方面还有待进一步提高
A. 对
B. 错
【判断题】
按照《商业银行合规风险管理指引》规定,商业银行合规负责人应全面协调商业银行合规风险的识别和管理,监督合规管理部门根据合规风险管理计划履行职责,定期向董事会提交合规风险评估报告
A. 对
B. 错
【判断题】
按照《商业银行合规风险管理指引》规定,合规负责人应全面协调商业银行合规风险的识别和管理,监督合规管理部门根据合规风险管理计划履行职责,定期向高级管理层提交合规风险评估报告。合规负责人可以分管业务条线
A. 对
B. 错
【判断题】
某银行高管十分重视发展业务,认为银行作为企业,应以利润指标为核心,其他一切不直接产生利润的活动都毫无意义。依据《中国银监会办公厅关于加强银行业金融机构社会责任的意见》,此银行高管的看法是否正确?
A. 对
B. 错