A.used to verify the identity of the peer
B.used between the initiator and the responder to establish a basic security policy
C.used to establish a symmetric shared key via a public key exchange process
D.used for asymmetric public key encryption
您可能感興趣的試卷
你可能感興趣的試題
A.Static secure MAC address
B.Dynamic secure MAC address
C.Pervasive secure MAC address
D.Sticky secure MAC address
A.Enable the highest level of Syslogging available to ensure you log all possible event messages
B.Use SSH to access your Syslog information
C.Log all messages to the system buffer so that they can be displayed when accessing the router
D.Syncronize clocks on the network with a protocol such as Network Time Protocol
Refer to the exhibit. Based on the VPN connection shown, which statement is true?()
A.Traffic that matches access list 103 will be protected
B.This VPN configuration will not work because the tunnel IP and peer IP are the same
C.The tunnel is down because the transform set needs to include the Authentication Header parameter
D.The tunnel is down as result of being a static rule. It should be configured as a Dynamic IPsec policy
A.Broadband service
B.Headend VPN device
C.VPN access device
D.Tunnel
Refer to the exhibit. You are the network security administrator responsible for router security.Your networkuses internal IP addressing according to RFC 1918 specifications.From the default rules shown,whichaccess control list would prevent IP address spoofing of these internal networks?()
A.SDM_Default_197
B.SDM_Default_199
C.SDM_Default_196
D.SDM_Default_198
A.With the method aaa command
B.With the method command
C.With a method list
D.With a method statement
A.SenderBase
B.TrafMon
C.IronPort M-Series
D.E-Base
On the basis of the show policy-map type inspect zone-pair session command output provided in theexhibit.What can be determined about this Cisco IOS zone based firewall policy?()
A.Stateful packet inspection will be applied only to HTTP packets that also match ACL 110
B.This is an inbound policy(applied to traffic sourced from the less secured zone destined to the moresecured zone)
C.This is an outbound policy(applied to traffic sourced from the more secured zone destined to the lesssecured zone)
D.All packets will be dropped since the class-default traffic class is matching all traffic
A.Source interface where encrypted traffic originates
B.IP address for the remote peer
C.Transform set for the IPsec tunnel
D.Interface for the VPN connection
A.It sends ping requests in segments of an invalid size
B.It intercepts the third step in a TCP three-way handshake to hijack a session
C.It sends ping requests to a subnet, requesting that devices on that subnet send ping replies to a targetsystem
D.It uses Trojan horse applications to create a distributed collection of "zombie" computers, which can beused to launch a coordinated DDoS attack
最新試題
Which name is of the e-mail traffic monitoring service that underlies that architecture of IronPort?()
Which two actions can be configured to allow traffic to traverse an interface when zone-based security isbeing employed?()
If you click the Configure button along the top of Cisco SDM is graphical interface,which Tasks buttonpermits you to configure such features as SSH, NTP, SNMP, and syslog?()
Which statement is true about a Smurf attack?()
In an IEEE 802.1x deployment,between which two devices EAPOL messages typically are sent?()
When configuring SSH, which is the Cisco minimum recommended modulus value?()
What are two characteristics of the SDM Security Audit wizard?()
Which one of the aaa accounting commands can be used to enable logging of both the start and stoprecords for user terminal sessions on the router?()
Which one of the Cisco IOS commands can be used to verify that either the Cisco IOS image, theconfiguration files,or both have been properly backed up and secured?()
Which two primary port authentication protocols are used with VSANs?()