【单选题】
When would you configure the ip dhcp snooping trust command on a sw itch?___
A. when the switch is connected to a DHCP server
B. when the switch is working in an edge capacit
C. when the switch is connected to a client system
D. when the switch is serving as an aggregator
查看试卷,进入试卷练习
微信扫一扫,开始刷题

答案
A
解析
暂无解析
相关试题
【单选题】
How does the 802. 1x supplicant communicate with the authentication server?___
A. The supplicant creates EAP packets and sends them to the authenticator, which encapsulates them into RADIUS and forwards them to the authentication server.
B. The supplicant creates RADIUS packets and sends them to the authe nticator, which encapsulates the m into EAP and forwards them to the a uthentication server.
C. The supplicant creates RADIUS packets and sends them to the authenticator, which translates them into eap and forwards them to the a ut hentication server
D. The supplicant creates
E. AP packets and sends them to the authe nticator, which translates them into radius and forwards them to the authentication server.
【单选题】
Which command do you enter to verify the phase I status of a VPN connection?___
A. sh crypto se ssion
B. debug crypto isakmp
C. sh crypto isakmp sa
D. sh crypto ipsec sa
【单选题】
Refer to the exhibit. what is the e ffect of the given configuration?___
A. It enables authentication,
B. It prevents keychain authentication.
C. The two routers receive normal updates from one another.
D. The two device s are able to pass the message digest to one another.
【单选题】
Which command can you enter to configure OSPF to use hashing to authenticate routing updates?___
A. ip ospf aut hentication message-digest
B. neighbor 192 168.0 112 cost md5
C. ip ospf priority 1
D. ip ospf aut hentication-key
【单选题】
Which command can you enter to verify the status of Cisco lOS Resilient Configuration on a Cisco router?___
A. show secure bootset
B. secure boot-image
C. show binary file
D. ure boot-config
【单选题】
A user on your network inadvertently activates a botnet program that was received as an emai attachment. Which type of mechanism does Cisco Firepower use to detect and block only the botnet attack?___
A. network-based access control rule
B. reputation-based
C. user-ba sed access control rule
D. botnet traffic filter
【单选题】
What does the policy map do in CoPP?___
A. defines service parameters
B. defines packet selection parameters
C. defines the packet filter
D. define s the action to be performed
【单选题】
How is management traffic isolated on a Cisco ASR 1002?___
A. Traffic isolation is done on the vlan level
B. There is no management traffic isolation on a Cisco ASR 1002
C. Traffic is isolated based upon how you configure routing on the device
D. The management interface is configured in a special vRF that provides traffic isolation from the default routing table
【单选题】
Which statement about NaT table evaluation in the asa is true?___
A. After-auto NAT polices are appl d first
B. Manual NAT policies are applied first
C. the asa uses the most specific match
D. Auto NAT policies are applied first
【单选题】
Which information can you display by executing the show crypto ipsec sa command?___
A. ISAKMP SAs that are established between two peers
B. recent changes to the IP address of a peer router
C. proxy infor mation for the connection between two peers
D. IPsec SAs established between two peers
【单选题】
How can you prevent NAT rules from sending traffic to incorrect interfaces?___
A. Assign the output interface in the NAT statement
B. Add the no-proxy-arp command to the nat line.
C. Configure twice NAT instead o bject NAT. 5
D. Use packet-tracer rules to reroute misrouted NAT entries.
【单选题】
What term can be defined as the securing, control, and identification of digital data?___
A. cryptography
B. crypto key
C. cryptoanalysis
D. cryptology
【单选题】
Which feature in the dNS security module provide on and off network DNS protection?___
A. Data Loss Prevention
B. Umbrella
C. Real-time sandboxing
D. Layer-4 monitoring
【单选题】
Which a dverse consequence can occur on a network without BPDu guard ?___
A. The olde st switch can be elected as the root bridge
B. Unauthorized switches that are connected to the network can cause spanning-tree loops
C.
D. ouble tagging can cause the switches to experience CAM table overload.
【单选题】
What configuration is required for multitenancy ?___
A. shared infrastructure
B. multiple carriers
C. co-located resources
D. multiple separate zones
【单选题】
Why does ISE require its own certificate issued by a trusted CA?___
A. ISEs certificate allows guest devices to validate it as a trusted network device
B. It generates certificates for guest devices ba sed on its own certificate
C. It requests certificates for guest devices from the Ca server based on its own certificate.
D. ISE's certificate allows it to join the network security framework
【单选题】
which attack involves large numbers of ICMP packets with a spoofed source IP address?___
A. smurf attack
B. Teardrop attack
C. Nuke attack
D. SYN Flood attack
【单选题】
Which statement about interface and global access rules is true?___
A. Interface access rules are processed before global access rules.
B. Global access rules apply only to outbound traffic, but interface access rules can be applied in either direction
C. The implicit allow is proce ssed after both the global and interface access rules
D. If an interface access rule is applied, the global access rule is ignored
【单选题】
Which type of malicious software can create a back-door into a device or network?___
A. bot
B. worm
C. virus
D. Trojan
【单选题】
Which security term refers to the like lihood that a weakness will be exploited to cause damage to an asset?___
A. threat
B. risk
C. countermeasure
D. vulnerability
【单选题】
Which IPS detection method examines network traffic for preconfigured patterns?___
A. signature-based detection
B. honey-pot detection
C. anomaly-based detection
D. policy-based detection
【单选题】
What is an advantage of split tunneling ?___
A. It allows users with a VpN connection to a corporate network to access the internet with sending traffic across the cor porate network.
B. It allows users with a vpn connection to a corporate network to access the internet by using the vPN for security.
C. It protects traffic on the private network from users on the public network
D. It enables the VPN server to filter traffic more efficiently
【单选题】
Which IDS/IPS state misidentifies acceptable behavior as an attack ?___
A. false negative
B. true positive NEKA G
C. true negative
D. false positive
【单选题】
What is the maximum num ber of methods that a single method list can contain?___
A. 4
B. 3
C. 2
D. 5
【单选题】
Which command enables authentication at the oSPFv2 routing process level?___
A. ip ospf authentication message-digest
B. area 0 authentication message-digest
C. ip ospf message-digest-key 1 mds Cisco
D. area 0 authentication ipsec spi 500 md5 1234567890ABCDEF1234567890ABCDEF
【单选题】
Which type of firewall monitors a nd protects a specific system?___
A. firewall
B. application firewall
C. stateless firewall wvp
D. personal firewall
【单选题】
On an ASA, which maps are used to identify traffic?___
A. Route maps
B. Policy maps
C. Class maps
D. Service maps
【单选题】
Which type of social engineering attack targets top executives?___
A. whaling
B. vishin
C. spear phishing ng
D. baiting
【单选题】
What is the minimum Cisco lOS version that supports zone-based firewalls?___
A. 12.1T
B. 15.1
C. 15.0
D. 124
【单选题】
In which type of attack does an attacker overwrite an entry in the CAM table to divert traffic destined to a legitimate host?___
A. DHCP spoofing
B. ARP spoofing
C. CAM table overflow
D. MAC spoofing
【多选题】
Which two attack types can be prevented with the impleme ntation of a Cisco IPS solution?___
A. DDos
B. man-in-the-middle
C. worms
D. ARP spoofing
E. VLAN hopping
【多选题】
choose four___
A. DHCP snooping ——————————blocks DHCP messages
B. Dynamic ARP inspection——————verifies IP-to-MAC traffic on untrusted ports
C. IP sources guard ——————————provides layer 2 interface security with ports ACLs
D. Port security————————————mitigates MAC-address spoofing at the access interface
【多选题】
choose four___
A. Step1————————run the system setup wizard
B. Step2————————add an authentication realm
C. Step3————————configure identity management
D. Step4————————configure directory group
【多选题】
What are two advanced features of the Cisco AMp solution for endpoints ___
A. contemplation
B. foresight
C. sandboxing
D. reputation
E. reflection
【多选题】
Which two characteristics of RADIUS are true?___
A. It encrypts only the password between user and server.
B. It uses TCP ports 1812/1813
C. It uses UDP ports 1812/1813.
D. It uses UDP port 49
E. It uses TCP port 49
【多选题】
What are two challenges of using a network-based IPS? ___
A. It is unable to determine whether a detected attack was successful
B. It requires additional storage and proce ssor capacity on syslog servers
C. As the network expands, it requires you to add more sensors.
D. It is unable to detect attacks across the entire network
E. It must support multiple operating systems.
【多选题】
What are two default be haviors of the traffic on a zone-based firewall?___
A. Traffic within the self -zone uses an im plicit deny all.
B. All traffic between zones is implicitly blocked
C. Communication is allowed between interfadAss that are members of the same zone
D. Communication is blocked between interfaces that are members of the same zone
E. The CBAC rules that are configured on router interfaces apply to zone interfaces
【多选题】
Which two advantages does the on-premise model for MDM deployment have over the cloud-based model?___
A. The on-premise model is easier and faster to de ploy than the cloud-based model
B. The on-premise model is more scalable than the cloud-based model
C. The on-premise model is generally less expensive than the cloud-based model
D. The on-premise model generally has less latency than the cloud- based model.
E. The on-premise model provides more control of the MDM solution than the cloud
【多选题】
Which two actions can an end usts take to manage a lost or stolen device in Cisco ISE? ___
A. Activate Cisco ISE End point Protection Services to quarantine the device.
B. Add the mac address of the device to a list of blacklisted devices
C. Force the device to be locked with a PIN
D. Request revocation of the digital certificate of the device.
E. Reinstate a device that the user previously marked as lost or stolen
【多选题】
Which two problems can arise when a proxy firewall serves as the gateway between networks?___
A. It can prevent content caching
B. It can limit application support
C. It is unable to prevent direct connections to other networks
D. It can cause reduced throughput.
E. It is unable to provide antivirus protection
推荐试题
【单选题】
违反ATM管理规定,违反ATM密码、钥匙管理使用规定的,给予有关责任人员___处分;后果或情节严重的,给予记大过至开除处分
A. 通报批评至警告
B. 警告至记大过
C. 警告至记过
D. 记过至撤职
【单选题】
违反现金收付、整点、票币兑换及现金调拨规定进行业务操作的,给予有关责任人员___处分;后果或情节严重的,给予记大过至开除处分。
A. 罚款
B. 通报批评
C. 警告至记过
D. 诫勉谈话
【单选题】
处分期间发生新的违规行为,加重处理,处分期为___
A. 原处分期尚未执行的期限与新处分期限之和
B. 原处分期尚未执行的期限
C. 新处分期限
D. 原处分期尚未执行的期限或新处分期限
【单选题】
“重大责任事故”其中包括:一人死亡或三人重伤,或造成___损失责任事故的
A. 20万元以上(含)
B. 30万元以上(含)
C. 50万元以上(含)
D. 100万元以上(含)
【单选题】
扣减绩效收入,每人每次原则上不得超过相当于本人___。赔偿经济损失金额不得超出实际风险或损失金额。责任人全额赔偿后又挽回损失的,超出实际损失部分退还有关赔偿责任人。
A. 3个月的绩效工资
B. 6个月的绩效工资
C. 一年的绩效工资
D. 二年的绩效工资
【单选题】
违反反洗钱管理规定,对大额交易应报告未报告或对可疑交易未尽职调查的,给予有关责任人员___处分;后果或情节严重的,给予记大过至开除处分。
A. 警告至记过
B. 记过至撤职
C. 记大过至开除
D. 警告至记大过
【单选题】
不履行或不正确履行职责,致使农信社受到司法机关或银行监管、审计、税务等行政机关处罚的,给予有关责任人员___处分。
A. 记过
B. 记过至撤职
C. 记大过至开除
D. 警告至记大过
【单选题】
公募理财产品是指商业银行面向()公开发行的理财产品,公开发行认定的标准包括向()募集资金、或向特定对象募集资金累计超过()人,以及法律、行政法规规定的其他情形。___
A. 不特定社会公众、不特定对象、200
B. 不特定社会公众、不特定对象、100
C. 不特定社会公众、不特定对象、150
D. 不特定社会公众、不特定对象、300
【单选题】
目前联社发行的预期收益型一般个人理财产品属于()理财产品,私人银行专属理财产品及机构理财产品属于()。___
A. 个人、定制
B. 个人、私募
C. 公募、私募
D. 公募、定制
【单选题】
基金与银行理财产品的比较,有误的是___。
A. 从投资范围来看,银行理财产品的投资领域更为宽广
B.
C. 银行理财产品的流动性相对较高
D. 银行理财产品投资门槛通常较高,限制了资金较少的投资者
E. 银行理财产品信息披露程度一般不如基金
【单选题】
以下不属于理财产品风险揭示书必须包含的内容是___。
A. 理财非存款、产品有风向、投资需谨慎
B. 理财产品的类型、期限、风险评级结果
C. 投资者风险承受能力评级
D. 第三方专业机构出具的评价结果
【单选题】
对于风险评估过期的机构投资者,不属于理财办理流程的是___。
A. 投资者填写风险评估问卷、投资者理财风险等级修改
B. 投资者签约
C. 投资者填写转账支票
D. 通过4700进行理财认购交易,同时做双录
【单选题】
商业银行从事理财产品销售,下列行为没有违反《商业银行理财产品销售管理办法》的是___。
A. 通过电视、电台渠道对具体理财产品进行宣传
B. 通过电话、短信开展理财产品宣传
C. 销售人员代替投资者签署文件
D. 将理财产品与其他产品进行捆绑销售
【单选题】
商业银行下列行为不正确的是:___
A. 商业银行应当建立健全销售人员资格考核、继续培训、跟踪评价等管理制度
B. 商业银行采用销售人员采用以销售业绩作为单一的考核和奖励指标的考核方法
C. 商业银行对65岁(含)的投资者进行风险承受能力评估时,应当充分考虑投资者年龄、相关投资经验等因素。
D. 商业银行应当定期或不定期地采用当面或网上银行方式对投资者进行风险承受能力持续评估。
【单选题】
企业开立___时,需要先通过人民币银行结算账户管理系统审核存款账户的唯一性,未通过唯一性审核的不得为其开立。
A. 基本存款账户
B. 专用存款账户
C. 临时存款账户
D. 一般存款账户
【单选题】
企业申请开立基本存款账户时,银行应当向___核实企业开户意愿,并留存相关工作记录。
A. 单位法定代表人或单位负责人
B. 单位实际控制人
C. 单位财务总监
D. 单位收益所有人
【多选题】
机构平账时提示有未处理业务,下列哪些业务会影响柜员正常签退?___
A. 存在在途现金
B. 存在在途凭证、卡、空白卡等
C. 存在待处理的授权业务
D. 存在当日必须核销的待销账
E. 存在录入未复核的业务
【多选题】
目前全省农信社个人存款使用的存单类型有哪几种?___
A. 10万以下使用的普通存单
B. 100万(含)以上使用的芯片存单
C. 全部使用普通存单
D. 10万(含)到100万使用的全息标存单
【多选题】
关于客户号合并,下列说法中正确的是___。
A. 出现疑似一户多号的两个客户号其中之一是信贷客户的,信贷客户必须作为保留客户。
B. 保留客户号信息会覆盖被合并客户号的信息,被合并客户号下的所有证件,只要与保留客户不重复的,都会自动添加到保留客户号下。
C. 如果保留的信贷客户号信息有误,先进行合并再进行证件信息修改操作。
D. 对于个人客户,保留客户号对应的证件类型必须是经联网核查通过的身份证。
【多选题】
做客户号合并业务时,下面哪种情况下柜面柜员无法进行合并,需要提交到县清算管理岗进行合并?___
A. 系统标识的“疑似一户多号”的客户号
B. 经操作员核实两个客户确为同一人,而系统未标识为“疑似一户多号”
C. 疑似一户多号的两个客户其中之一是信贷客户、客户信息有误且无法修改正确
D. 其他特殊原因,前台无法合并的
【多选题】
关于对公账户电子回单的打印,下列说法中正确的有___
A. 通过现金形式入对公账户的,由存入现金方提供现金缴款单给对公客户,作为凭证;
B. 本系统内通过【8080】入客户账的,由对公客户开户行通过【7572】打印电子回单;
C. 通过大小额支付、农信银系统渠道入客户账的,可通过【6153】查询交易明细,通过【6180】打印;
D. 通过网银渠道的系统内转账凭证可通过【7572】打印来账凭证。
E. 通过网银渠道的跨行转账的,通过【6180】打印。
F. 客户结息入账凭证,使用【7571】、【7572】交易查询打印。
【多选题】
下列会计档案中,属于永久保管会计档案的有___。
A. 会计档案保管登记簿及销毁清册
B. 存、贷款开销户登记簿
C. 机构变动交接清册
D. 有权机关查询、冻结(解冻)及扣划书
E. 客户挂失申请书、挂失登记簿
F. 会计凭证及附件
【多选题】
已经限制非柜面交易的账户解除控制,下列说法正确的有___
A. 只能由客户本人办理
B. 持账户被限制的银行卡或存折
C. 持开户的有效身份证件
D. 只能到开户营业网点办理
【多选题】
关于初始密码的激活,下列说法正确的___。
A. 新系统批量开的银行卡,用3030激活初始密码
B. 新系统批量开立的社保卡,用3010激活初始密码
C. 新系统批量开的单折,用7124密码修改进行初始密码激活
D. 老系统存量的批量开卡、批量开折,均使用7124密码修改进行初始密码激活。