【多选题】
What are two reasons to recommend SNMPv 3 over SNMPv2?___
A. SNMPv3 is secure because you can configure authe ntication and privacy
B. SNMPv3 is insecure because it send in formation in clear text
C. SNMPv2 is insecure because it send information in clear text
D. SNMPv3 is a Cisco proprietary protocol
E. SNMPv2 is secure because you can configure authentication and privacy
查看试卷,进入试卷练习
微信扫一扫,开始刷题

答案
AC
解析
暂无解析
相关试题
【多选题】
Which two actions can a zone- based firewall apply to a packet as it transits a zone pair?___
A. drop
B. inspect
C. queue
D. quarantine
【单选题】
Which security principle has been violated if data is altered in an unauthorized manner?___
A. accountability
B. confidentiality
C. availability
D. integrity
【单选题】
Which IKE Phase 1 parameter can you use to require the site-to-site VPN to use a pre-shared ?___
A. encryption
B. authentication
C. group
【单选题】
Which command successfully creates an administrative user with a password of "cisco"on a Cisco router?___
A. username Operator privilege 7 password cisco
B. username Operator privilege 1 password cisco
C. username Operator privilege 15 password cisco
D. username Operator password cisco privilege 15
【单选题】
Which EAP method authenticates a client against Active Directory without the use of client-side 802.1X certificates?___
A. EAP-TLS
B. EAP-MSCHAPv2
C. EAP-PEAP
D.
E. AP-GTC
【单选题】
What is a limitation of network-based IPS?___
A. It must be in dividually configured to support every operating system on the network.
B. It is most effective at the in dividual host level
C. It is unable to monitor attacks across the entire netw ork
D. Large installations require numerous sensors to fully protect the network
【单选题】
When would you configure the ip dhcp snooping trust command on a sw itch?___
A. when the switch is connected to a DHCP server
B. when the switch is working in an edge capacit
C. when the switch is connected to a client system
D. when the switch is serving as an aggregator
【单选题】
How does the 802. 1x supplicant communicate with the authentication server?___
A. The supplicant creates EAP packets and sends them to the authenticator, which encapsulates them into RADIUS and forwards them to the authentication server.
B. The supplicant creates RADIUS packets and sends them to the authe nticator, which encapsulates the m into EAP and forwards them to the a uthentication server.
C. The supplicant creates RADIUS packets and sends them to the authenticator, which translates them into eap and forwards them to the a ut hentication server
D. The supplicant creates
E. AP packets and sends them to the authe nticator, which translates them into radius and forwards them to the authentication server.
【单选题】
Which command do you enter to verify the phase I status of a VPN connection?___
A. sh crypto se ssion
B. debug crypto isakmp
C. sh crypto isakmp sa
D. sh crypto ipsec sa
【单选题】
Refer to the exhibit. what is the e ffect of the given configuration?___
A. It enables authentication,
B. It prevents keychain authentication.
C. The two routers receive normal updates from one another.
D. The two device s are able to pass the message digest to one another.
【单选题】
Which command can you enter to configure OSPF to use hashing to authenticate routing updates?___
A. ip ospf aut hentication message-digest
B. neighbor 192 168.0 112 cost md5
C. ip ospf priority 1
D. ip ospf aut hentication-key
【单选题】
Which command can you enter to verify the status of Cisco lOS Resilient Configuration on a Cisco router?___
A. show secure bootset
B. secure boot-image
C. show binary file
D. ure boot-config
【单选题】
A user on your network inadvertently activates a botnet program that was received as an emai attachment. Which type of mechanism does Cisco Firepower use to detect and block only the botnet attack?___
A. network-based access control rule
B. reputation-based
C. user-ba sed access control rule
D. botnet traffic filter
【单选题】
What does the policy map do in CoPP?___
A. defines service parameters
B. defines packet selection parameters
C. defines the packet filter
D. define s the action to be performed
【单选题】
How is management traffic isolated on a Cisco ASR 1002?___
A. Traffic isolation is done on the vlan level
B. There is no management traffic isolation on a Cisco ASR 1002
C. Traffic is isolated based upon how you configure routing on the device
D. The management interface is configured in a special vRF that provides traffic isolation from the default routing table
【单选题】
Which statement about NaT table evaluation in the asa is true?___
A. After-auto NAT polices are appl d first
B. Manual NAT policies are applied first
C. the asa uses the most specific match
D. Auto NAT policies are applied first
【单选题】
Which information can you display by executing the show crypto ipsec sa command?___
A. ISAKMP SAs that are established between two peers
B. recent changes to the IP address of a peer router
C. proxy infor mation for the connection between two peers
D. IPsec SAs established between two peers
【单选题】
How can you prevent NAT rules from sending traffic to incorrect interfaces?___
A. Assign the output interface in the NAT statement
B. Add the no-proxy-arp command to the nat line.
C. Configure twice NAT instead o bject NAT. 5
D. Use packet-tracer rules to reroute misrouted NAT entries.
【单选题】
What term can be defined as the securing, control, and identification of digital data?___
A. cryptography
B. crypto key
C. cryptoanalysis
D. cryptology
【单选题】
Which feature in the dNS security module provide on and off network DNS protection?___
A. Data Loss Prevention
B. Umbrella
C. Real-time sandboxing
D. Layer-4 monitoring
【单选题】
Which a dverse consequence can occur on a network without BPDu guard ?___
A. The olde st switch can be elected as the root bridge
B. Unauthorized switches that are connected to the network can cause spanning-tree loops
C.
D. ouble tagging can cause the switches to experience CAM table overload.
【单选题】
What configuration is required for multitenancy ?___
A. shared infrastructure
B. multiple carriers
C. co-located resources
D. multiple separate zones
【单选题】
Why does ISE require its own certificate issued by a trusted CA?___
A. ISEs certificate allows guest devices to validate it as a trusted network device
B. It generates certificates for guest devices ba sed on its own certificate
C. It requests certificates for guest devices from the Ca server based on its own certificate.
D. ISE's certificate allows it to join the network security framework
【单选题】
which attack involves large numbers of ICMP packets with a spoofed source IP address?___
A. smurf attack
B. Teardrop attack
C. Nuke attack
D. SYN Flood attack
【单选题】
Which statement about interface and global access rules is true?___
A. Interface access rules are processed before global access rules.
B. Global access rules apply only to outbound traffic, but interface access rules can be applied in either direction
C. The implicit allow is proce ssed after both the global and interface access rules
D. If an interface access rule is applied, the global access rule is ignored
【单选题】
Which type of malicious software can create a back-door into a device or network?___
A. bot
B. worm
C. virus
D. Trojan
【单选题】
Which security term refers to the like lihood that a weakness will be exploited to cause damage to an asset?___
A. threat
B. risk
C. countermeasure
D. vulnerability
【单选题】
Which IPS detection method examines network traffic for preconfigured patterns?___
A. signature-based detection
B. honey-pot detection
C. anomaly-based detection
D. policy-based detection
【单选题】
What is an advantage of split tunneling ?___
A. It allows users with a VpN connection to a corporate network to access the internet with sending traffic across the cor porate network.
B. It allows users with a vpn connection to a corporate network to access the internet by using the vPN for security.
C. It protects traffic on the private network from users on the public network
D. It enables the VPN server to filter traffic more efficiently
【单选题】
Which IDS/IPS state misidentifies acceptable behavior as an attack ?___
A. false negative
B. true positive NEKA G
C. true negative
D. false positive
【单选题】
What is the maximum num ber of methods that a single method list can contain?___
A. 4
B. 3
C. 2
D. 5
【单选题】
Which command enables authentication at the oSPFv2 routing process level?___
A. ip ospf authentication message-digest
B. area 0 authentication message-digest
C. ip ospf message-digest-key 1 mds Cisco
D. area 0 authentication ipsec spi 500 md5 1234567890ABCDEF1234567890ABCDEF
【单选题】
Which type of firewall monitors a nd protects a specific system?___
A. firewall
B. application firewall
C. stateless firewall wvp
D. personal firewall
【单选题】
On an ASA, which maps are used to identify traffic?___
A. Route maps
B. Policy maps
C. Class maps
D. Service maps
【单选题】
Which type of social engineering attack targets top executives?___
A. whaling
B. vishin
C. spear phishing ng
D. baiting
【单选题】
What is the minimum Cisco lOS version that supports zone-based firewalls?___
A. 12.1T
B. 15.1
C. 15.0
D. 124
【单选题】
In which type of attack does an attacker overwrite an entry in the CAM table to divert traffic destined to a legitimate host?___
A. DHCP spoofing
B. ARP spoofing
C. CAM table overflow
D. MAC spoofing
【多选题】
Which two attack types can be prevented with the impleme ntation of a Cisco IPS solution?___
A. DDos
B. man-in-the-middle
C. worms
D. ARP spoofing
E. VLAN hopping
【多选题】
choose four___
A. DHCP snooping ——————————blocks DHCP messages
B. Dynamic ARP inspection——————verifies IP-to-MAC traffic on untrusted ports
C. IP sources guard ——————————provides layer 2 interface security with ports ACLs
D. Port security————————————mitigates MAC-address spoofing at the access interface
【多选题】
choose four___
A. Step1————————run the system setup wizard
B. Step2————————add an authentication realm
C. Step3————————configure identity management
D. Step4————————configure directory group
推荐试题
【多选题】
下列情况通常会被拒收的是___
A. 故意行为所致的损毁钞票不予收兑。
B. 有政治性宣传口号或商业性广告的钞票不予收兑。
C. 改变钞票形象,如涂改、添画等的不予收兑。
D. 非同一钞票拼接而成的、被揭张的钞票不予收兑。
E. 被防爆烟箱的烟雾污染的钞票不
【多选题】
特殊残缺、污损人民币是指票面因火灾,虫蛀鼠咬、霉烂等特殊原因,造成___不宜再继续流通使用的人民币。
A. 外观质地
B. 防伪特征受损
C. 纸张炭化变形
D. 图案不清晰
【多选题】
大小票币兑换要求:___
A. 办理票币兑换业务必须坚持先兑入,后兑出,当面点清,一笔一清。
B. 兑出款项配妥,交付款项时,须核对兑出款项。
C. 已离开柜员双手、递出柜的现金,客户要求退回重新兑换的款项,柜员收入后应重新清点。
【多选题】
残缺、污损硬币的兑换方法___
A. 先辨别真伪
B. 确认为真币的,只要能辨别正面的图案、背面的数字、边部设计,即可兑换全额
C. 确认为假币的,按假币收缴办法办理
D. 无法辨别真伪的,可不予办理,但必须做好客户解释工作
E. 如遇特殊情况,留下客户的联系方式和身份证号码,并及时请示上级会计管理部门后再作妥善处理
【多选题】
B、人民币纸币形状、尺寸发生变化,票幅长边与标准规格相差( )以上,或票幅宽边与标准规格相差( )以上的,为不宜流通人民币。___
A. 2% 4%
B. 2% 5%
C. 3% 5%
D. 3% 6%
【多选题】
下列为不宜流通人民币的是___
A. 票面出现一处脱墨,脱墨面积大于80mm2的;
B. 票面出现多处脱墨,累计脱墨面积大于60mm2的;
C. 票面脱墨面积虽未超过以上标准,但重要防伪特征之一脱墨严重,影响防伪功能的;
D. 票面出现多处脱墨,累计脱墨面积大于70mm2的。
【多选题】
人民币纸币票面出现皱褶、折痕,有下列情形之一的,为不宜流通人民币: ___
A. 票面出现4处以上皱褶,褶纹明显、无法恢复原状,累计皱褶长度大于20mm,或票面单个皱褶长度大于10mm的;
B. 票面出现3处以上皱褶,褶纹明显、无法恢复原状,累计皱褶长度大于20mm,或票面单个皱褶长度大于8mm的;
C. 票面出现2处以上皱褶,褶纹明显、无法恢复原状,累计皱褶长度大于20mm,或票面单个皱褶长度大于10mm的;
D. 票面出现2处以上皱褶,褶纹明显、无法恢复原状,累计皱褶长度大于20mm,或票面单个皱褶长度大于5mm的。
【多选题】
人民币纸币在流通过程中因受到侵蚀,形成票面局部污渍,有下列情形之一的,为不宜流通人民币: ___
A. 印刷区域出现多处污渍,累计污渍面积大于150mm2,或单个污渍面积大于100mm2的;
B. 印刷区域出现多处污渍,累计污渍面积大于60mm2,或单个污渍面积大于50mm2的;
C. 非印刷区域出现多处污渍,累计污渍面积大于60mm2,或单个污渍面积大于50mm2的;
D. 非印刷区域出现多处污渍,累计污渍面积大于150mm2,或单个污渍面积大于100mm2的;
E. 污渍面积虽未超过规定标准,但遮盖重要防伪特征之一,影响防伪功能的。
【多选题】
人民币纸币票面撕裂,有下列情形之一的,为不宜流通人民币:___
A. 票面出现一处撕裂,撕裂长度大于9mm的;
B. 票面出现多处撕裂,最短撕裂长度大于3mm,累计撕裂长度大于9mm的
C. 票面出现一处撕裂,撕裂长度大于10mm的;
D. 票面出现多处撕裂,最短撕裂长度大于5mm,累计撕裂长度大于10mm的
【多选题】
人民币纸币票面出现人为的文字、图画、符号或其他标记,有下列情形之一的,为不宜流通人民币: ___
A. 票面出现一处涂写,其涂写面积大于200mm2的;
B. 票面出现多处涂写,累计涂写面积大于100mm2的;
C. 票面出现多处涂写,累计涂写面积大于200mm2的;
D. 票面涂写面积虽未超过规定标准,但遮盖了重要防伪特征之一,影响防伪功能的。
E. 人民币纸币票面缺损,有下列情形之一的,为不宜流通人民币: (A.B.C)
【多选题】
人民币硬币在流通过程中出现磨损,有下列情形之一的,为不宜流通人民币: ___
A. 币面出现一处磨损,深度大于0.1mm,磨损面积大于标准面积的5%;
B. 币面出现多处磨损,深度大于0.1mm,累计磨损面积大于标准面积的10%;
C. 币面文字、数字、图案之一受损,影响辨别面额或真伪。
【多选题】
人民币硬币在流通过程中出现裂纹或裂口及划痕,有下列情形之一的,为不宜流通人民币: ___
A. 币面边沿内出现裂纹或裂口,径向深度大于1mm,单个裂纹或裂口长度超过3mm,且累计长度大于标准周长的10%;
B. 币面出现划痕,径向深度大于1mm,单个划痕长度大于2 mm,且累计长度大于标准周长的15%;
C. 文字、数字、图案之一受损,影响辨别面额或真伪。
D. 币面出现划痕,径向深度大于1mm,单个划痕长度大于2 mm,且累计长度大于标准周长的10%;
【多选题】
日间库管理的基本原则___
A. 布防监控、专人看守
B. 钱账分管、双人管库
C. 双人调款、双人装箱、双人加锁、双人结库、同开同关
D. 现金、实物“先入库后记账,先记账后出库”,保管物品出入库分类逐项序时登记
E. 日清日结,确保账款、账实、账账相符
【多选题】
下列说法正确的是___
A. 每日营业终了、大宗款项出入库以及查库人员查库后,管库员必须即行结库;
B. 不经常发生出入库业务的库存实物,必须在发生业务后即行结库;
C. 一个月以上不发生出入库业务的库存实物,每月至少结库一次;
D. 经有关部门封存的库存实物、重要物品和代保管物品,每月至少验封一次。
【多选题】
ATM机短款非人为原因造成,且无法追回的,需上报总行相关部门审核,经___签字批准后,作短款损失处理。
A. 分支行分管行长
B. 分支行负责人
C. 总行会计部负责人
D. 总行分管行长
【多选题】
___发现长、短款,应保留原捆票币及腰条、封签,写出情况报告,经手人、复核人签章,经负责人及主管领导审核后,连同原封签、腰条等送当地人民银行审查处理。
A. 系统内调拨现金
B. 系统外调拨现金
C. 原封新票币
【多选题】
确定为短款后,将短款在待查错账科目中挂账,并在《自助设备管理登记簿》长短款栏中做好短款登记,并由___签名盖章;
A. 经办人
B. 会计主管
C. 机构负责人
D. 主管领导
【多选题】
关于现金长短款差错处理说法错误的是___
A. 会计主管或指定人员核实凭证金额,核点现金实物,确认错款金额后,按错款金额大小经有权人审核批准后入应收应付账户;
B. 系统内调拨现金发现长、短款,保管好原封签,腰条等资料,立即向上级管理部门报告并与调出机构联系查找原因;
C. 原封新票币发现长、短款,应保留原捆票币及腰条、封签,写出情况报告,经手人、复核人签章即可;
D. 发生出纳案件,应根据案件处理规定及时逐级上报并保护现场。
【多选题】
系统内调拨现金发现长、短款,应___。
A. 保管好原封签,腰条等资料。
B. 立即向上级管理部门报告并与调出机构联系查找原因。
C. 确认为调出机构差错时以清点的实际金额入账。
D. 确认调出行差错时,由调出行处理;不能确认调出行差错时,由调入行按审批权限报批。
【多选题】
ATM长短款除在《自助设备管理登记簿》中做好差错登记外,还要在当日按照我行长短款相关处理规定在待查错账暂时挂账,等查明原因再作处理,严禁___。
A. 长款寄库
B. 短款空库
C. 以长补短
【多选题】
发生现金错款,必须___
A. 立即报告会计主管,做到长款不寄库,短款不空库
B. 会计主管或指定人员核实凭证金额,核点现金实物
C. 确认错款金额后,按错款金额大小经有权人审核批准后入应收应付账户
D. 采取相应的办法及时查找,做到长款不寄库,短款不空库
【多选题】
ATM机因日常清机加钞或客户反映取款未记客户账等情况进行双人盘点钞箱现金时发现账款不符,应___
A. 重复盘点各钞箱金额,打开设备保险柜进行仔细查找
B. 确定为短款后,将短款在待查错账科目中挂账,并在《自助设备管理登记簿》长短款栏中做好短款登记,并由经办人签名盖章
C. 取下自助设备的交易流水日志,并和业务系统交易流水进行逐笔勾对,找出短款可疑交易
D. 查看可疑交易的监控录像,确定差错日期、短款卡号、金额、短款性质
【多选题】
ATM发生短款后的注意事项___
A. 发生短款后,自助设备管理员核对流水及时向相关管理部门报告短款差错情况;
B. 对经过网点管理人员查找后仍无法确定的短款,可请总行相关部门协助查证;
C. 短款发生情况在自助设备登记簿中进行登记,相关操作人员签字或签章确认
【多选题】
ATM发生长款,查明为本行卡后,操作的注意事项___
A. 需要查找交易流水日志
B. 账号异常无法入账的,由会计主管审批激活后入账
C. 遇到节假日可由柜员交叉审批
D. 需要上传1603截屏