單項(xiàng)選擇題

Refer to the exhibit. What statement is true about the interface S1/0 on router R1?()

A.Labeled packets can be sent over an interface.
B.MPLS Layer 2 negotiations have occurred.
C.IP label switching has been disabled on this interface.
D.None of the MPLS protocols have been configured on the interface.


您可能感興趣的試卷

你可能感興趣的試題

1.多項(xiàng)選擇題Which two statements describe the functions and operations of IDS and IPS systems?()

A.A network administrator entering a wrong password would generate a true-negative alarm.
B.A false positive alarm is generated when an IDS/IPS signature is correctly identified.
C.An IDS is significantly more advanced over IPS because of its ability to prevent network attacks.
D.Cisco IDS works inline and stops attacks before they enter the network.
E.Cisco IPS taps the network traffic and responds after an attack.
F.Profile-based intrusion detection is also known as "anomaly detection".

2.多項(xiàng)選擇題Which two statements about common network attacks are true?()

A.Access attacks can consist of password attacks,trust exploitation,port redirection,and man-in-the-middle attacks.
B.Access attacks can consist of password attacks,ping sweeps,port scans,and man-in-the-middle attacks.
C.Access attacks can consist of packet sniffers,ping sweeps,port scans,and man-in-the-middle attacks.
D.Reconnaissance attacks can consist of password attacks,trust exploitation,port redirection and Internet information queries.
E.Reconnaissance attacks can consist of packet sniffers,port scans,ping sweeps,and Internet information queries.
F.Reconnaissance attacks can consist of ping sweeps,port scans,man-in-middle attacks and Internet information queries.

3.多項(xiàng)選擇題Which three statements are true about Cisco IOS Firewall?()

A.It can be configured to block Java traffic.
B.It can be configured to detect and prevent SYN-flooding denial-of-service (DoS) network attacks.
C.It can only examine network layer and transport layer information.
D.It can only examine transport layer and application layer information.
E.The inspection rules can be used to set timeout values for specified protocols.
F.The ip inspect cbac-name command must be configured in global configuration mode.

4.多項(xiàng)選擇題Which three features are benefits of using GRE tunnels in conjunction with IPsec for building site-to-site VPNs?()

A.allows dynamic routing over the tunnel
B.supports multi-protocol (non-IP) traffic over the tunnel
C.reduces IPsec headers overhead since tunnel mode is used
D.simplifies the ACL used in the crypto map
E.uses Virtual Tunnel Interface (VTI) to simplify the IPsec VPN configuration

5.多項(xiàng)選擇題What are three objectives that the no ip inspect command achieves?()

A.removes the entire CBAC configuration
B.removes all associated static ACLs
C.turns off the automatic audit feature in SDM
D.denies HTTP and Java applets to the inside interface but permits this traffic to the DMZ
E.resets all global timeouts and thresholds to the defaults
F.deletes all existing sessions

6.多項(xiàng)選擇題

Refer to the exhibit. On the basis of the information that is provided, which two statements are true?()

A.An IPS policy can be edited by choosing the Edit button.
B.Right-clicking on an interface will display a shortcut menu with options to edit an action or to set severity levels.
C.The Edit IPS window is currently in Global Settings view.
D.The Edit IPS window is currently in IPS Policies view.
E.The Edit IPS window is currently in Signatures view.
F.To enable an IPS policy on an interface, click on the interface and deselect Disable.

7.多項(xiàng)選擇題

Refer to the exhibit. On the basis of the information in the exhibit,which two statements are true?()

A.Any traffic matching signature 1107 will generate an alarm, reset the connection,and be dropped.
B.Signature 1102 has been modified, but the changes have not been applied to the router.
C.Signature 1102 has been triggered because of matching traffic.
D.The Edit IPS window is currently displaying the Global Settings information.
E.The Edit IPS window is currently displaying the signatures in Details view.
F.The Edit IPS window is currently displaying the signatures in Summary view.

8.多項(xiàng)選擇題

Refer to the exhibit. Which two statements about the AAA configuration are true?()

A.A good security practice is to have the none parameter configured as the final method used to ensure that no other authentication method will be used.
B.If a TACACS+ server is not available, then a user connecting via the console port would not be able to gain access since no other authentication method has been defined.
C.If a TACACS+ server is not available, then the user Bob could be able to enter privileged mode as long as the proper enable password is entered.
D.The aaa new-model command forces the router to override every other authentication method previously configured for the router lines.
E.To increase security, group radius should be used instead of group tacacs+.
F.Two authentication options are prescribed by the displayed aaa authentication command.

9.多項(xiàng)選擇題

Refer to the exhibit. Which two statements about the SDF Locations window of the IPS Rule wizard are true?()

A.An HTTP SDF file location can be specified by clicking the Add button.
B.If all specified SDF locations fail to load, the signature file that is named default.sdf will be loaded.
C.The Autosave feature automatically saves the SDF alarms if the router crashes.
D.The Autosave feature is automatically enabled for the default built-in signature file.
E.The name of the built-in signature file is default.sdf.
F.The Use Built-In Signatures (as backup) check box is selected by default.

最新試題

What are two possible actions an IOS IPS can take if a packet in a session matches a signature?()

題型:多項(xiàng)選擇題

Which three statements about the Cisco Easy VPN feature are true?()

題型:多項(xiàng)選擇題

What are three features of the Cisco IOS Firewall feature set?()

題型:多項(xiàng)選擇題

What are the four fields in an MPLS label?()

題型:多項(xiàng)選擇題

What are three configurable parameters when editing signatures in Security Device Manager (SDM)?()

題型:多項(xiàng)選擇題

Refer to the exhibit. Which statement is true about the partial MPLS configuration that is shown?()

題型:?jiǎn)雾?xiàng)選擇題

Refer to the exhibit. What type of security solution will be provided for the inside network?()

題型:?jiǎn)雾?xiàng)選擇題

When configuring the Cisco VPN Client,what action is required prior to installing Mutual Group Authentication?()

題型:?jiǎn)雾?xiàng)選擇題

Which statement describes Reverse Route Injection (RRI)?()

題型:?jiǎn)雾?xiàng)選擇題

Refer to the exhibit.What are the two options that are used to provide High Availability IPsec?()

題型:多項(xiàng)選擇題