【单选题】
Which feature of the Cisco Email Security Appliance can mitigate the impact of snowshoe spam and sophisticated phishing attacks?___
A. contextual analysis
B. holistic understanding of threats
C. graymail management and filtering
D. signature-based IPS
查看试卷,进入试卷练习
微信扫一扫,开始刷题

答案
A
解析
暂无解析
相关试题
【单选题】
Refer to the exhibit【nat (inside,outside)dunamic interface】 Which translation technique does this configuration result in?___
A. DynamIc PAT
B. Dynamic NAT
C. Twice NAT
D. Static NAT
【单选题】
While trouble shooting site-to-site VPN, you issued the show crypto isakmp sa command. What does the given output show?___
A. IKE Phase 1 main mode was created on 10.1.1.5, but it failed to negotiate with 10.10 10.2
B. IKE Phase 1 main mode has successfully negotiated between 10.1.1.5 and 10.10..
C. IKE Phase 1 aggressive mode was created on 10.1.1.5, but it failed to negotiate with
【单选题】
Refer to the exhibit All ports on switch 1 have a primary vLan of 300 Which devices can host 1 reach?___
A. host 2
B. server
C. host 4
D. other devices within VLAN303
【单选题】
Which option is the cloud-based security service from Cisco the provides URL filtering, web browsing content security, and roaming user protection?___
A. Cloud Web service
B. Cloud Advanced Malware Protection
C. Cloud We b Security
D. Cloud Web Protection
【单选题】
How can you detect a false negative on an IPS?___
A. View the alert on the ips
B. Review the ips log
C. Review the is console
D. Use a third- party system to perform penetration testing.
E. Use a third- party to audit the next generation firewall rules
【单选题】
If a switch port goes directly into a blocked state only when a superior BPDU is received, what mechanism must be in use?___
A. STP BPDU guard
B. Loop guard
C. EtherChannel guard
D. STP Root guard
【单选题】
what improvement does EAP-FASTv2 provide over EAP-FAST? ___
A. It allows multiple credentials to be passed in a single EAP exchange.
B. It supports more secure encryption protocols
C. It allows faster authentication by using fewer packets.
D. It addresses security vulnerabilities found in the original protocol
【单选题】
When users login to the Client less Ssl Vpn using https://209.165.201.2/test ,which group policy will be applied?___
A. test
B. clientless
C. sales
D. DfitGrp Policy
E. Default RAGroup
F. Default WEB VPN
G. roup
【单选题】
Which user authentication method is used when users login to the Clientless SSLVPN portal using https://209.165.201.2/test?___
A. AAA with LOCAL database
B. AAA with RADIUS server
C. Certificate
D. :Both Certificate and aaa with LoCAL database
E. Both Certificate and AAA with RADIUS server
【单选题】
What' s the technology that you can use to prevent non malicious program to runin the computer that is disconnected from the network?___
A. Firewall
B. Sofware Antivirus
C. Network IPS
D. Host IPS
【单选题】
Which statement about the communication between interfaces on the same security level is true?___
A. Interfaces on the same security level require additional configuration to permit interinterface communication
B. Configuring interfaces on the same security level can cause asymmetric routing
C. All traffic is allowed by default between interfaces on the same security level
D. You can configure only one interface on a n individual security level
【单选题】
Which product can be used to provide application layer protection for tcp port 25 traffic?___
A. ESA
B. CWS
C. WSA
D. ASA
【单选题】
which iPS mode is less secure than other options but allows optimal network through put ?___
A. inline mode
B. inline-bypass mode
C. transparent mode
D. Promiscuous mode
【单选题】
Which feature of the Cisco Email security Appliance can mitigate the impact of snowshoe spam and sophisticated phishing attack?___
A. reputation based filtering
B. signature based IPS
C. contextual analysis
D. graymail management and filtering
【单选题】
Which type of social-engineering attack uses normal tele phone service as the attack vector?___
A. smishing
B. dialing
C. phishing
D. vishing
【单选题】
Which quantifiable item should you consider when you organization adopts new technologies?___
A. exploits
B. vulnerability
C. threat
D. Risk
【单选题】
Referencing the ClA model, in which scenario is a hash- only function most appropriate ?___
A. securing data at rest
B. securing real-time traffic
C. securing data in files
D. securing wireless transmissions
【单选题】
Which ports must be open between a aaa server and a microsoft server to permit Active Directory authentications?___
A. 445 and 389
B. 888 and 3389
C. 636 and 4445
D. 363 and 983
【单选题】
Refer to the exhibit for which reason is the tunnel unable to pass traffic___
A. the tunnel is failing to receive traffic from the remote peer
B. the local peer is unable to encrypt the traffic
C. the ip address of the remote peer is incorrect
D. UDP port 500 is blocked
【单选题】
Which type of attack can exploit design flaws in the implementation of an application without___
A. DHCP starvation attacks
B. low-rate dos attacks
C. application DDos flood attacks
D. application DDoS flood attacks
E. volume-based DDoS attacks
【单选题】
How can you protect CDP from reconnaissance attacks?___
A. Enable dynamic ARP inspection on all untrusted ports.
B. Enable dot1x on all ports that are connected to other switches.
C.
D. isable CDP on ports connected to endpoints.
【单选题】
Which type of attack can exploit design flaws in the implementation of an application without ?___
A. DHCP starvation attacks
B. low-rate dos attacks
C. application DDos flood attacks
D. application DDoS flood attacks
E. volume-based DDoS attacks
【单选题】
Which option is a key security compone nt of and MDM deployment ?___
A. using network-specific installer packages
B. using an application tunnel by default
C. using self-signed certificates to validate the server
D. using MS-CHAPv2 as the primary
E. AP method
【单选题】
Which Firepower Management Center feature detects and block exploits and hack attempts?___
A. Content blocker
B. file control
C. intrusion prevention
D. advanced malware protection
【单选题】
hich description of the nonsecret numbers that are used to start a Diffie- Hellman exchange is ture?___
A. They are preconfigured prime integers.
B. They are large pseudorandom numbers.
C. They are very small numbers chosen from a table of known valuses
D. They are numeric values extracted from ha shed system hostnames
【多选题】
Which two characteristics of an application layer firewall are true?___
A. provides stateful firewal functionality
B. has low processor usage
C. provides protection for multiple applications
D. provides rever se proxy services
E. is immune to URL manipulation
【多选题】
Which two devices are components of the BYOD architectural framework?___
A. Nexus 7010 switch
B. Cisco 3945 Router
C. Identify Services Engine
D. Wireless Access oints
E. Prime Infrastructure
【多选题】
Which two actions can a zone based firewall take when looking at traffic? ___
A. forward
B. inspect
C. drop
D. broadcast
E. filter
【多选题】
n which two situations should you use in-band management?___
A. when management applications need concurrent access to the device
B. when you require administrator access from multiple locations
C. when a network device fails to forward packets
D. when you require ROMMON access
E. when the control plane fails to respond
【多选题】
What are two ways to prevent eavesdropping when you perform device management tasks?___
A. Use an SSH connection.
B. Use SNMPv3
C. Use out-of-band management
D. Use SNMP
E. Use in-band management
【多选题】
Which two features are commonly used CoPP and CPPr to protect the control plane? ___
A. QoS
B. traffic classification
C. access lists
D. policy maps
E. class maps
F. Cisco Express Forwarding
【多选题】
Which four tunne ling prot ocols are enabled in the Dfit GrpPolicy group policy ?___
A. Clientless SSL VPN
B. SSL VPN Client
C. PPTP
D. L2TP/IPsec
E. IPsec IKEv1
F. IPsec IKEv2
【多选题】
Which two statements regarding the aSA VPN configurations are correct?___
A. The asa has a certificate issued by an external certificate authority associated to the ASDM TrustPoint1
B. The Default WEBVPNGroup Connection Profile is using the aaa with RADIUS server method
C. The Inside-srvbook mark references the https://192.168.1.2url
D. Only Clientless SSL VPN access is allowed with the Sales group policy
E. Any Connect, IPSec IKEv1, and IPSec IKEv2 VPN access is enabled on the outside interface
F. The Inside -SRV bookmark has not been applied to the Sales group policy
【多选题】
Which three ESP fields can be encrypted during transmission?___
A. Security Parameter Index
B. Sequence Number
C. MAC Address
D. Padding
E. Pad length
F. Next Header
【多选题】
.Which three statements de scribe DHCP spoofing attacks?___
A. They can modify traffic in transit.
B. They are used to perform man- in-the-middle attacks
C. They use ARP poisoning
D. They can access most network devices
E. They protect the ide ntity of the attacker by masking the DHCP address.
F. They are can physically modify the network gateway.
【多选题】
Which statement about the communication between interfaces on the same security level is true?___
A. Interfaces on the same security level require additional configuration to permit interinterface communication
B. Configuring interfaces on the same security level can cause asymmetric routing
C. All traffic is allowed by default between interfaces on the same security level
D. You can configure only one interface on a n individual security level
【多选题】
In which two situations should you use in band management? ___
A. when the control plane fails to respond
B. when you require administrator access from multiple locations
C. when you require ROMMON access.
D. where a network device fails to forward packets
E. when multiple ma nagement applications need concument access to the device.
【多选题】
Which two features are supported in a VRF-aware softwar infrastructure before VRF-lite?___
A. multicast
B. fair queuing
C. WCCP
D.
E. IGRP
【多选题】
.Which loS command do you enter to test authentication again a AAA server?___
A. dialer aaa suffix <suffix> password <password>
B. ppp authentication chap pap test
C. test aaa-server authentication dialer group user name <user> password <password>
D. aaa authentication enable default test group tacases
推荐试题
【单选题】
票据贴现,是指以购买借款人未到期商业汇票的方式,向持票人融通资金的一种行为。农信社票据贴现期限自贴现之日起到票据到期日止,最长不得超过___个月。
A. 4
B. 5
C. 6
D. 3
【单选题】
对借款人不能依照合同约定归还贷款本息或不能落实还本付息事宜的,应当及时进行___,必要时可以依法在新闻媒体披露或采取诉讼等法律措施。
A. 依法起诉
B. 封存财产
C. 公示催收
D. 债权保全
【单选题】
借款人申请办理展期,应在贷款到期___日前提出书面申请,填写《河南省农村信用社借款展期申请表》,并提交不能按期归还贷款的相关证明文件及担保人同意担保等农信社要求的其他条件。
A. 10
B. 15
C. 20
D. 30
【单选题】
新建立信贷业务的公司类客户应每月检查一次, 存量贷款中正常、关注类客户___检查一次,不良贷款按照重点检查进行实施,并填写《河南省农村信用社贷后跟踪检查表》。
A. 每月
B. 每季
C. 每半年
D. 每年
【单选题】
信贷档案的保管期限分永久和定期两类。定期保管的期限分为5年、10年、15年。同一介质上有不同保管期限的信贷档案,应按___保管。
A. 最长期限
B. 最短期限
C. 合同期限
D. 借据期限
【单选题】
以下有关贷款审批描述不正确的是___
A. 贷款审批是决策过程的方案设计和方案选择阶段
B. 方案选择就是贷与不贷、贷多贷少、贷款期限长短等
C. 银行应当建立审贷分离、分级审批的贷款管理制度
D. 审批人员根据信贷业务预计给银行带来的效益和风险决定是否批准
【单选题】
接入信贷系统的计算机必须安装正版防病毒软件,并及时更新,___至少要用防病毒软件进行一次全面的病毒查杀。严禁无关人员在信贷微机上操作。
A. 每天
B. 每周
C. 每月
D. 每季
【单选题】
抵押与质押的区别在于___
A. 抵押中的债务人保留对抵押财产的所有权
B. 质押中的债务人保持对质押财产的占有权
C. 抵押中的债权人取得抵押财产的所有权或部分所有权
D. 质押中的债权人保留对质押财产的所有权
【单选题】
以下关于贷款保证风险表述不正确的是___
A. 保证贷款逾期2年期间,银行未采取任何措施中断诉讼时效,则银行将丧失胜诉权
B. 就保证责任而言,如果保证合同对保证期间有约定,应依约定
C. 如果保证合同未约定或约定不明,则保证责任自主债务履行期届满之日起1年
D. 在规定的时期内债权人未要求保证人承担保证责任,保证人免除保证责任
【单选题】
借款人还款能力的主要标志就是___
A. 借款人的现金流量是否充足
B. 借款人的资产负债比率是否足够低
C. 借款人的管理水平是否很高
D. 借款人的销售收入和利润是否足够高
【单选题】
客户经理应对客户提供的资料以及所收集信息的合法性、真实性进行核实,核实的过程和结果应予以记载。核实应以___为主。
A. 电话访谈
B. 实地调查
C. 间接调查
D. 外部调查
【单选题】
借款人自主支付是指贷款人根据借款人的提款申请将贷款资金发放至借款人账户后,由借款人自主支付给符合合同约定用途的哪类对象?___
A. 客户方
B. 借款人交易对手
C. 股东
D. 合伙人
【单选题】
采用贷款人受托支付的,贷款人应在何时审核借款人相关交易资料是否符合合同约定条件?___
A. 贷款资金发放时
B. 贷款资金发放前
C. 贷款资金发放后
D. 支付给借款人交易对手的同时
【单选题】
60.按贷款风险分类法分类,尽管借款人目前有能力偿还贷款本息,但存在一些可能对偿还产生不利影响的因素,这类贷款应划为 ___。
A. 正常;
B. 关注;
C. 次级;
D. 可疑。
【单选题】
冻结超过冻结时效时___。
A. 自动解冻
B. 有权部门人员需凭“解冻通知书”办理解冻手续
C. 有权部门人员需凭有效身份证件办理解冻手续
D. 有权部门人员需凭工作证办理解冻结手续
【单选题】
市场经济条件下,用人单位越来越看重人才的道德品质。这表明( )。
A. 职业道德品质高的员工更有助于企业增强持久的竞争力
B. 对于用人单位来说,员工的职业技能水平问题已经得到较好的解决
C. 这些企业原有员的职业道德品质不高
D. 职业道德品质高的人,其职业技能水平也越高
【单选题】
下列选项对“慎独”理解正确的是( )。
A. “慎独”就是在一个独自闯荡时,要小心谨慎,防范别人
B. “慎独"是指在没有外界监督的情况下,即使独自一个人也能自觉遵守道德规范,不做对国家对社会、对他人不道德的事情
C. “慎独”是针对那些从事机密工作的人而言的,跟般人没有多大关系
D. “慎独”是指要慎重考虑是否要一个人独自做事业