單項選擇題

On the basis of the show policy-map type inspect zone-pair session command output provided in theexhibit.What can be determined about this Cisco IOS zone based firewall policy?()




A.Stateful packet inspection will be applied only to HTTP packets that also match ACL 110
B.This is an inbound policy(applied to traffic sourced from the less secured zone destined to the moresecured zone)
C.This is an outbound policy(applied to traffic sourced from the more secured zone destined to the lesssecured zone)
D.All packets will be dropped since the class-default traffic class is matching all traffic


您可能感興趣的試卷

你可能感興趣的試題

1.多項選擇題When using the Cisco SDM Quick Setup Siteto-Site VPN wizard, which three parameters do you configure?()

A.Source interface where encrypted traffic originates
B.IP address for the remote peer
C.Transform set for the IPsec tunnel
D.Interface for the VPN connection

2.單項選擇題Which statement is true about a Smurf attack?()

A.It sends ping requests in segments of an invalid size
B.It intercepts the third step in a TCP three-way handshake to hijack a session
C.It sends ping requests to a subnet, requesting that devices on that subnet send ping replies to a targetsystem
D.It uses Trojan horse applications to create a distributed collection of "zombie" computers, which can beused to launch a coordinated DDoS attack

3.單項選擇題What will be disabled as a result of the no service password-recovery command?()

A.password encryption service
B.changes to the config-register setting
C.the xmodem privilege EXEC mode command to recover the Cisco IOS image
D.ROMMON

4.單項選擇題A standard access control list has been configured on a router and applied to interface Serial 0 in anoutbound direction. No ACL is applied to Interface Serial 1 on the same router. What will happen whentraffic being filtered by the access list does not match the configured ACL statements for Serial 0?()

A.The traffic is dropped
B.The resulting action is determined by the destination IP address
C.The source IP address is checked,and,if a match is not found, traffic is routed out interface Serial 1
D.The resulting action is determined by the destination IP address and port number

5.單項選擇題Regarding constructing a good encryption algorithm, what does creating an avalanche effect indicate?()

A.Altering the key length causes the ciphertext to be completely different
B.Changing only a few bits of a ciphertext message causes the plain text to be completely different
C.Altering the key length causes the plain text to be completely different
D.Changing only a few bits of a plain-text message causes the ciphertext to be completely different

6.單項選擇題Which item is correct regarding Cisco IOS IPS on Cisco IOS Release 12.4(11)T and later ?()

A.requires the Basic or Advanced Signature Definition File
B.uses the built-in signatures that come with the Cisco IOS image as backup
C.supports SDEE,SYSLOG,and SNMP for sending Cisco IPS alerts
D.uses Cisco IPS 5.x signature format

7.單項選擇題After enabling port security on a Cisco Catalyst switch, what is the default action when the configuredmaximum of allowed MAC addresses value is exceeded?()

A.The port’s violation mode is set to restrict
B.The port is shut down
C.The MAC address table is cleared and the new MAC address is entered into the table
D.The port remains enabled, but bandwidth is throttled until old MAC addresses are aged out

8.單項選擇題Stream ciphers run on which of the following?()

A.Fixed-length groups of digits called blocks
B.Individual blocks,one at a time,with the transformations varying during the encryption
C.Individual digits,one at a time,with the transformations varying during the encryption
D.Fixed-length groups of bits called blocks

9.單項選擇題What is the objective of the aaa authentication login console-in local command?()

A.It specifies the login authentication method list named console-in using the local user database on the router
B.It specifies the login authorization method list named console-in using the local RADIUS username-password data base
C.It specifies the login authentication list named console-in using the local username- password data base on the router
D.It specifies the login authorization method list named console-in using the local username- password data base on the router

10.多項選擇題Which statement best describes the Turbo ACL feature? ()

A.The Turbo ACL feature processes ACLs into lookup tables for greater efficiency
B.The Turbo ACL feature leads to increased latency, because the time it takes to match the packet isvariable
C.The Turbo ACL feature leads to reduced latency, because the time it takes to match the packet is fixedand consistent
D.Turbo ACLs increase the CPU load by matching the packet to a predetermined list

最新試題

If you click the Configure button along the top of Cisco SDM is graphical interface,which Tasks buttonpermits you to configure such features as SSH, NTP, SNMP, and syslog?()

題型:單項選擇題

On the basis of the show policy-map type inspect zone-pair session command output provided in theexhibit.What can be determined about this Cisco IOS zone based firewall policy?()

題型:單項選擇題

Refer to the exhibit. Based on the VPN connection shown, which statement is true?()

題型:單項選擇題

Which three are distinctions between asymmetric and symmetric algorithms? ()

題型:多項選擇題

What is the objective of Diffie-Hellman?()

題型:單項選擇題

When configuring role-based CLI on a Cisco router,which action will be taken first ?()

題型:單項選擇題

What will be disabled as a result of the no service password-recovery command?()

題型:單項選擇題

What are two characteristics of the SDM Security Audit wizard?()

題型:多項選擇題

Please choose the correct description about Cisco Self-Defending Network characteristics.()

題型:單項選擇題

A standard access control list has been configured on a router and applied to interface Serial 0 in anoutbound direction. No ACL is applied to Interface Serial 1 on the same router. What will happen whentraffic being filtered by the access list does not match the configured ACL statements for Serial 0?()

題型:單項選擇題