【多选题】
What are two default be haviors of the traffic on a zone-based firewall?___
A. Traffic within the self -zone uses an im plicit deny all.
B. All traffic between zones is implicitly blocked
C. Communication is allowed between interfadAss that are members of the same zone
D. Communication is blocked between interfaces that are members of the same zone
E. The CBAC rules that are configured on router interfaces apply to zone interfaces
查看试卷,进入试卷练习
微信扫一扫,开始刷题
答案
BC
解析
暂无解析
相关试题
【多选题】
Which two advantages does the on-premise model for MDM deployment have over the cloud-based model?___
A. The on-premise model is easier and faster to de ploy than the cloud-based model
B. The on-premise model is more scalable than the cloud-based model
C. The on-premise model is generally less expensive than the cloud-based model
D. The on-premise model generally has less latency than the cloud- based model.
E. The on-premise model provides more control of the MDM solution than the cloud
【多选题】
Which two actions can an end usts take to manage a lost or stolen device in Cisco ISE? ___
A. Activate Cisco ISE End point Protection Services to quarantine the device.
B. Add the mac address of the device to a list of blacklisted devices
C. Force the device to be locked with a PIN
D. Request revocation of the digital certificate of the device.
E. Reinstate a device that the user previously marked as lost or stolen
【多选题】
Which two problems can arise when a proxy firewall serves as the gateway between networks?___
A. It can prevent content caching
B. It can limit application support
C. It is unable to prevent direct connections to other networks
D. It can cause reduced throughput.
E. It is unable to provide antivirus protection
【多选题】
When using the Adaptive Security Device Manager(ASDM), which two methods are available to add a new root certificate?___
A. Use sCep
B. Install from SFTP server
C. Install from a file
D. Use Https
E. Use LDAP
【多选题】
Which two are considered basic security principles?___
A. Accountability
B. Redundancy
C. High Availabilit
D. Integrity
E. Confidentiality
【多选题】
Which two roles of the Cisco WSA are true?___
A. IPS
B. firewall
C. antispam
D. web proxy
E. URL filter
【单选题】
Which next-generation encryption algorithm supports four variants?___
A. SHA-2
B. SHA-1
C. MD5
D. HMAC
【单选题】
What aims to remove the abil ity to deny an action?___
A. Non-Repudiation
B. Accountability
C. Integrity
D. Deniability
【单选题】
Which statements about the native VLAN is true ?___
A. It is susceptible to VLAN hopping attacks.
B. It is the Cisco recommended VLAN for switch-management traffic
C. It is most secure when it is a ssigned to vLAn 1.
D. It is the cisco-recomme nded vlan for user traffic
【单选题】
There are two versions of IKE:IKEv1 and IKEv2. Both IKEv1 and IKEv2 protocols operate in phases IKEv1 operates in two phases. IKEv2 operates in how many phases?___
A. 2
B. 3
C. 4
D. 5
【单选题】
What does the dh group refer to?___
A. length of key for hashing C
B. length of key for encryption
C. tunnel lifetime key
D. length of key for key exchange
E. length of key for authentication
【单选题】
Which path do you follow to enable aaa through the SDM ?___
A. Configure Tasks > AAA
B. Configure > Addition Authentication > AAA
C. Configure > AAA
D. Configure > Additional Tasks > AAA
E. Configure Authentication > AAA
【单选题】
which technology cloud be used on top of an MPLS VPN to add confidentiality ?___
A. IPsec
B. 3DES
C. AES
D. SSL
【单选题】
Which term is most closely aligned with the basic purpose of a SIEM solution? ___
A. Non-Repudiation
B. Accountability
C. Causality
D. Repudiation
【单选题】
You have just deployed SNMPv3 in your environment, Your manager asks you to make sure that our SNMP agents can only talk to the SNMP Manager. What would you configure on your SNMI agents to satisfy this request?___
A. A SNMP View containing the SNMP managers
B. Routing Filter with the SNMP managers in it applied outbound
C. A standard ACL containing the SNMP managers applied to the SNMP configuration
D. A SNMP Group containing the SNMP managers
【单选题】
Which feature prevents loops by moving a nontrunking port into an errdisable state when a BPDU is received on that port?___
A. BPDU filte
B. DHCP snooping
C. BPDU guard
D. Port Fast
【单选题】
Which command enables port security to use sticky MAC addresses on a switch?___
A. switchport port-security violation restrict
B. switchport port-security mac-address sticky
C. switchport port-security violation protect
D. switchport port-security
【单选题】
When you edit an IPS subsignature, what is the effect on the parent signature and the family of subsignatures?___
A. The change applies to the parent signature and the entire family of subsignatures
B. The change applies to the parent signature and the subsignature that you edit
C. The change applies only to subsignatures that are numbered sequentially after the subsignature that you edit
D. Other signatures are unaffected, the change applies only to the subsignature that you dit
【单选题】
Which type of mechanism does Cisco FirePOWER de ploy to protect ag detected moving across other networks?___
A. antivirus scanning
B. policy-based
C. reputation-based
D. signature-based
【单选题】
What action must you take on the ise to blacklist a wired device?___
A. Locate the switch through which the device is connected and push an a cl restricting all access by the device
B. Issue a CoA request for the de vice's mac address to each access switch in the network
C. Revoke the device's certificate so it is unable to authenticate to the network
D. Add the device's MAc address to a list of black listed devices
【单选题】
Which type of firewall can perform deep packet inspection?___
A. packet-filtering firewall
B. stateless firewall
C. application firewall
D. personal firewall
【单选题】
What is the main purpose of Control Plane Policing?___
A. to prevent exhaustion of route-proce ssor resources
B. to organize the egress packet queues
C. to define traffic classes
D. to maintain the policy map
【单选题】
Which attack can be prevented by OSPF authentication?___
A. smurf attack
B. IP spoofing attack
C. denial of service attack
D. buffer overflow attack
【单选题】
What is the best definition of hairpinning?___
A. ingress traffic that traverses the outbound interface on a device
B. traffic that enters one interface on a device and that exits through another interface
C. traffic that enters and exits a device through the same interface
D. traffic that tunnels through a device interface
【单选题】
Which SNMPv3 security level provides authentication using HMAC with MD5, but does not use encryption?___
A. authPriv
B. authNo Priv
C. noAuthNoPriv
D. NoauthPriv
【单选题】
You have implemented a dynamic blacklist, using security intelligence to block illicit network activity. However, the blacklist contains several approved connections that users must access for usiness pur poses. Which action can you take to retain the blacklist while allowing users to access the approve d sites?___
A. Create a whitelist and manually add the approved addresses.
B. Disable the dynamic blacklist and deny the specif ic address on a whitelist while permitting the others
C. Edit the dynamic blacklist to remove the approved addresses
D. Disable the dynamic blacklist and create a static blacklist in its place
【单选题】
When connecting to an external resource,you must change a source IP address to use one IP address from a range of 207.165.201.1 to 207.165.1.30. Which option do you implement ?___
A. dynamic source NAT that uses an IP ad dress as a mapped source
B. static destination NAT that uses a subnet as a real de stination
C. dynamic source NAT that uses a range as a mapped source
D. static destination NAT that uses a subnet as a real source
【单选题】
Refer to the exhibit. 【nat(ins,any)dynamic interface】Which ty pe of NaT is configured on a Cisco ASA?___
A. dynamic NAT
B. source identity NAT
C. dynamic PAT
D. identity twice NAT
【单选题】
Which mitigation technology for web-based threats prevents the removal of confidential data from the network?___
A. CTA
B. DCA
C. AMP
D. DLP
【单选题】
Refer to the exhibit. What is the effect of the given configuration?___
A. It establishes the preshared key for the switch
B. It establishes the preshared key for the firewall.
C. It establishes the preshared key for the Cisco ISE appliance
D. It establishes the preshared key for the router.
【多选题】
What are two major considerations when choosing between a SPAN and a TAP when plementing IPS?___
A. the type of analysis the iS will perform
B. the amount of bandwidth available
C. whether RX and TX signals will use separate ports
D. the way in which media errors will be handled
E. the way in which dropped packets will be handled
【多选题】
What are two direct-to-tower methods for redirecting web traffic to Cisco Cloud Web Security?___
A. third-party proxies
B. Cisco Catalyst platforms
C. Cisco NAC Agent
D. hosted PAC files
E. CiSco ISE
【多选题】
Which three descriptions of RADIUS are true? ___
A. It uses TCP as its transport protocol.
B. Only the password is encrypted
C. It supports multiple transport protocols
D. It uses UDP as its transport protocol
E. It combines authentication and authorization
F. It separates authentication,authorization,and accounting
【多选题】
Which two configurations can prevent VLAN hopping attack from attackers at VLAN 10?___
A. using switchport trunk native vlan 10 command on trunk ports
B. enabling BPDU guard on all access ports
C. creating VLAN 99 and using switchport trunk native vlan 99 command on trunk ports
D. applying ACl between VLAN
E. using switchport mode access command on all host ports
F. using switchport nonegotiate command on dynamic desirable ports
【多选题】
What are two features of transparent firewall mode ___
A. It conceals the presence of the firewall from attackers
B. It allows some traffic that is blocked in routed mode
C. It enables the aSA to perform as a router.
D. It acts as a routed hop in the network.
E. It is configured by default
【多选题】
Which two models of A sa tend to be used in a data center?___
A. 5555X
B. 5585X
C. ASA service module
D. 5512X
E. 5540
F. 5520
【多选题】
Which two statements about hardware-based encrption are true?___
A. It is widely accessible
B. It is potentially easier to compromise than software-based encryption. It requires minimal configuration
C. It requires minimal configuration
D. It can be implemented without impacting performance
E. It is highly cost-effective
【多选题】
In which two modes can the Cisco We b Security appliance be de ployed?___
A. as a transparent proxy using the Secure Sockets Layer protocol
B. as a transparent proxy using the Web Cache Communication Protocol
C. explicit proxy mode
D. as a transparent proxy using the Hyper Text Transfer Protocol
E. explicit active mode
【单选题】
1.三相刀开关的图形符号与交流接触器的主触点符号是___。
A. 一样的
B. 可以互换
C. 有区别的
D. 没有区别
【单选题】
2.刀开关的文字符号是___。
A. QS
B. SQ
C. SA
D. KM
推荐试题
【多选题】
原状态为___的抵质押品,不能在柜面直接做临时出库交易,需要在信贷系统将状态维护为“临时出库中”,才能进行临时出库操作。
A. 未入库
B. 入库中
C. 出库
D. 入库
【多选题】
抵、质押品风险预警是针对___过程中发现的风险,发布风险信号进行风险预警或风险提示。
A. 贷前审查
B. 贷前报告
C. 贷后监管
D. 贷后检查
【多选题】
抵质押物临时出入库/再回库,该交易须___审批。
A. 客户经理
B. 分管行长
C. 信贷系统
【多选题】
抵质押品类别不包括___
A. 抵押
B. 质押
C. 电子汇票抵押
D. 电子汇票质押
【多选题】
抵质押品入库交易码? ___
A. 3801
B. 3802
C. 3803
D. 3804
【多选题】
以下关于抵质押物出库的说法错误的有___。
A. 该交易须信贷系统审批;
B. 原状态为“入库”的抵质押品,可以在柜面做临时出库交易;
C. 原状态为“临时出库”的抵质押品,不能在柜面直接做再回库交易;
D. 只有状态为“入库中”的抵质押品,才可以进行再回库操作。
【多选题】
以保本型理财产品办理理财产品质押贷款的,理财产品质押贷款的质押率原则上不应超过理财产品合同交易金额的( )。___
A. 50%
B. 70%
C. 90%
D. 100%
【多选题】
二十九、抵质押品出库交易码为:___
A. 3801
B. 3802
C. 3803
D. 3804
【多选题】
出入库类别选项的选择类型有___
A. 未入库
B. 入库
C. 临时出库
D. 入库中
E. 临时出库中
F. 出库
【多选题】
下列表述正确的是:___
A. 抵、质押品管理是对抵质押品分类、价值评估、担保设立与变更、保管、贷后监管、风险预警、返还与处置等全流程管理。
B. 抵、质押品价值评估应按照国家有关法律、法规和我行相关制度,运用适当的评估方法,对评估基准日抵质押品价值进行分析、估算并发表评估意见。
C. 抵、质押品贷后监管是在贷款发放后,对抵质押品进行现场检查、价值重估和合同履约管理。
D. 抵、质押品管理应遵循合法性、有效性、审慎性原则。
【多选题】
抵质押品出库应审核:___
A. 抵质押物出库凭证是否有客户经理及审核人签字
B. 柜员取出专夹保管的抵质押品收据单底卡联,核对信息、取出封包
C. 客户留存联、客户经理留存联抵质押品收据单是否与底卡联、封包联信息一致
D. 所有抵质押品收据单是否有抵质押人签章,是否有信贷部门经办人员签字
【多选题】
保证金追减锁定业务,打印二联通用空白凭证,一联作主凭证,调整通知书作附件;一联交 ___留存。
A. 客户
B. 业务管理部门
C. 信贷部门
【多选题】
银承维护交易不能在___操作保证金追加减业务
A. 银承签发日
B. 银承签发日次日
C. 银承到期日
D. 银承到期日前一天
【多选题】
当选择___时,可以针对不指定的业务进行保证金锁定,但需手工锁定和解锁。
A. 纸质汇票
B. 电子汇票
C. 国际业务
D. 其他业务
【多选题】
保证金子账号账户余额减锁定金额应___本次追加金额
A. 大于
B. 大于等于
C. 小于
D. 小于等于
【多选题】
电子银行承兑汇票承兑时如需使用保证金的,在信贷部门审批后,需通过___追加保证金交易追加锁定对应的保证金,会计人员方可在电票系统进行审核处理。
A. 信贷系统
B. 信贷审核系统
C. 核心系统
D. 票据系统
【多选题】
第二次活期保证金追加,票据系统维护时,保证金金额应输入___
A. 本次追加的金额
B. 两次追加的金额之和
C. 票面金额
【多选题】
保证金追加锁定业务适用于柜面哪些业务?___
A. 纸质汇票
B. 电子汇票
C. 国际业务
D. 国内证业务
【多选题】
保证金修改功能有哪些?___
A. 保证金追加锁定业务
B. 保证金修改业务
C. 保证金追减锁定业务
D. 保证金开户业务
【多选题】
履约付款时,履约付款金额应小于等于合同金额,如实际履约付款___合同金额时,表外销的仍是合同金额
A. 大于
B. 小于
C. 等于
D. 以上均错
【多选题】
履约付款时先支付___再支付(),若保证金销户时金额()履约付款金额,则剩余部分返回申请人账户。
A. 结算帐户;保证金;大于
B. 保证金;结算帐户;大于
C. 保证金;结算帐户;小于
D. 结算帐户;保证金;小于
【多选题】
银行保函业务是指银行应客户申请而开立的具有担保性质的书面承诺文件,一旦申请人未按其与受益人签订的合同的约定偿还债务或履行约定义务时,由___履行担保责任。
A. 申请人
B. 银行
C. 受益人
D. 客户
【多选题】
全额保证金及全额存单质押开具保函时手续费一次性收取,每笔___元。
A. 300
B. 250
C. 200
D. 100
【多选题】
如客户需要对保函进行展期的,申请人应在保函有效期满前___,向我行提出书面申请。
A. 一周
B. 15天
C. 20天
D. 一个月
【多选题】
开立保函时,需要申请人交足一定的保证金,保证金账户为___
A. 活期账户
B. 定期账户
C. 活期或定期账户
D. 一年
【多选题】
关于保函业务,下列说法错误的是___
A. 保证金锁定金额应小于等于保证金可用余额;
B. 履约付款时,履约付款金额应小于合同金额,如实际履约付款小于合同金额时,表外销的仍是合同金额;
C. 履约付款时,申请人账号为活期账户,保证金本息与申请人账户可用余额应足以支付履约金额。余额不足时产生垫款;
D. 履约付款时先支付保证金再支付结算帐户,若保证金销户时金额大于履约付款金额,则剩余部分返回申请人账户。
【多选题】
U、申请保函业务的客户对象为经我国工商行政管理机关(或主管机关)核准登记的企事业法人、其他经济组织、个体工商户及自然人。___仅可以申请办理低风险的非融资性保函业务。
A. 企事业法人
B. 其他经济组织
C. 个体工商户
D. 自然人
【多选题】
目前我行贷款产品宽限期默认设置___天,如果个人贷款产品中的贷款账户需要设置宽限期,可维护。
A. 0
B. 1
C. 2
D. 3
【多选题】
处理贷款维护业务,在贷款利率调整时,基准年利率___修改。
A. 可以
B. 不可以
C. 经行长批准后可以
【多选题】
还款账号可做变更/新增/删除,一个贷款最多可以关联___个还款账号。
A. 1
B. 2
C. 3
D. 4
【多选题】
下列哪种维护不用客户经理在信贷系统进行审批___
A. 贷款利率
B. 还款账号
C. 欠款顺序调整
D. 按揭还款方式变更5
【多选题】
三十七、在贷款维护中,以下哪下业务可以不通过信贷系统审批,由客户提出申请在柜面办理。___
A. 还款账号
B. 宽限期
C. 欠款顺序调整
D. 自主还款计划变更
【多选题】
新利率调整生效时间有 ___等几种方式
A. 不生效
B. 次年1月1日调整
C. 次年对月对日调整
D. 下一结息日生效
E. 立即生效
【多选题】
贷款维护是指对已发放的贷款借据进行维护修改。可维护修改___
A. 贷款利率
B. 还款账号
C. 自主还款计划变更
D. 按揭还款方式变更
E. 宽限期
F. 利率调整生效时间
G. 欠款顺序调整
【多选题】
贷款的还款顺序为___
A. 非减值时先还息再还本
B. 非减值时先还本再还息
C. 减值时先还本再还息
D. 减值时先还息再还本
【多选题】
按揭还款方式变更支持___,但在变更前如有欠款,需先将欠款归还。
A. 等额本息按月与等额本息按季互换
B. 等额本金按月与等额本金按季互换
C. 等额本息按月与等额本金按月互换
D. 等额本息按季与等额本金按季互换
【多选题】
预收本息签约后在本息扣收日,如果账户余额仍然不足,系统将预收本息日产生的冻结金额全额解冻,扣除该账户可用余额,差额部分___进行追缴,直到贷款欠款归还完毕。
A. 每日
B. 每周
C. 代发工资当日
D. 贷款本息扣收日
【多选题】
预收本息的贷款客户2016年7月12日代发工资2100元,应冻金额和应还本息金额为2500元,则系统在工资发放后会冻结该账户___元
A. 2100
B. 400
C. 2000
D. 2500
【多选题】
D、在本息扣收日,若账户余额仍然不足,系统将预收本息日产生的冻结金额部分解冻,扣除该账户可用余额,差额部分每日进行追缴,直到贷款欠款归还完毕。5、办理预收本息业务时客户一笔借据能关联几个签约存款账户___
A. 1
B. 2
C. 3
D. 4
【多选题】
预收本息签约业务中,以下___为正确。
A. 月预收金额即预扣本息日(工资发放日)冻结金额,可大于月还款金额。
B. 一笔借据只能关联一个签约存款账户,一个签约存款账户可以关联多笔借据。
C. 预收本息签约仅支持还款方式为等额本金按月以及等额本息按月的贷款。
D. 如果签约账号/卡号不是该借据号的还款账号,需要在“3004借据查询维护”交易中将签约账号/卡号维护为该借据号的第一还款账号。