單項(xiàng)選擇題Which statement about an IPS is true?()

A.The IPS is in the traffic path.
B.Only one active interface is required.
C.Full benefit of an IPS will not be realized unless deployed in conjunction with an IDS.
D.When malicious traffic is detected,the IPS will only send an alert to a management station.


您可能感興趣的試卷

你可能感興趣的試題

1.多項(xiàng)選擇題Which two statements about an IDS are true?()

A.The IDS is in the traffic path.
B.The IDS can send TCP resets to the source device.
C.The IDS can send TCP resets to the destination device.
D.The IDS listens promiscuously to all traffic on the network.
E.Default operation is for the IDS to discard malicious traffic.

2.單項(xiàng)選擇題Which statement describes the Authentication Proxy feature?()

A.All traffic is permitted from the inbound to the outbound interface upon successful authentication of the user.
B.A specific access profile is retrieved from a TACACS+ or RADIUS server and applied to an IOS Firewall based on user provided credentials.
C.Prior to responding to a proxy ARP,the router will prompt the user for a login and password which are authenticated based on the configured AAA policy.
D.The proxy server capabilities of the IOS Firewall are enabled upon successful authentication of the user.

3.多項(xiàng)選擇題What are three features of the Cisco IOS Firewall feature set?()

A.network-based application recognition (NBAR)
B.authentication proxy
C.stateful packet filtering
D.AAA services
E.proxy server
F.IPS

4.多項(xiàng)選擇題Which three statements about IOS Firewall configurations are true?()

A.The IP inspection rule can be applied in the inbound direction on the secured interface.
B.The IP inspection rule can be applied in the outbound direction on the unsecured interface.
C.The ACL applied in the outbound direction on the unsecured interface should be an extended ACL.
D.The ACL applied in the inbound direction on the unsecured interface should be an extended ACL.
E.For temporary openings to be created dynamically by Cisco IOS Firewall,the access-list for thereturning traffic must be a standard ACL.
F.For temporary openings to be created dynamically by Cisco IOS Firewall,the IP inspection rule must be applied to the secured interface.

5.單項(xiàng)選擇題

Refer to the exhibit. MPLS has been configured on all routers in the domain. In order for R2 and R3 to forward frames between them with label headers, what additional configuration will be required on devices that are attached to the LAN segment?()

A.Decrease the maximum MTU requirements on all router interfaces that are attached to the LAN segment.
B.Increase the maximum MTU requirements on all router interfaces that are attached to the LAN segment.
C.No additional configuration is required. Interface MTU size will be automatically adjusted to accommodate the larger size frames.
D.No additional configuration is required. Frames with larger MTU size will be automatically fragmented and forwarded on all LAN segments.

6.單項(xiàng)選擇題

Refer to the exhibit. The show mpls interfaces detail command has been used to display information about the interfaces on router R1 that have been configured for label switching. Which statement is true about the MPLS edge router R1?()

A.Packets can be labeled and forwarded out interface Fa0/1 because of the MPLS operational status of the interface.
B.Because LSP tunnel labeling has not been enabled on interface Fa0/1, packets cannot be labeled and forwarded out interface Fa0/1.
C.Packets can be labeled and forwarded out interface Fa1/1 because MPLS has been enabled on this interface.
D.Because the MTU size is increased above the size limit, packets cannot be labeled and forwarded out interface Fa1/1.

7.單項(xiàng)選擇題What is a reason for implementing MPLS in a network?()

A.MPLS eliminates the need of an IGP in the core.
B.MPLS reduces the required number of BGP-enabled devices in the core.
C.Reduces routing table lookup since only the MPLS core routers perform routing table lookups.
D.MPLS eliminates the need for fully meshed connections between BGP enabled devices.

8.多項(xiàng)選擇題What are two possible actions an IOS IPS can take if a packet in a session matches a signature?()

A.reset the connection
B.forward the packet
C.check the packet against an ACL
D.drop the packet

9.單項(xiàng)選擇題Which statement describes Reverse Route Injection (RRI)?()

A.A static route that points towards the Cisco Easy VPN server is created on the remote client.
B.A static route is created on the Cisco Easy VPN server for the internal IP address of each VPN client.
C.A default route is injected into the route table of the remote client.
D.A default route is injected into the route table of the Cisco Easy VPN server.

10.多項(xiàng)選擇題Which three techniques should be used to secure management protocols?()

A.Configure SNMP with only read-only community strings.
B.Encrypt TFTP and syslog traffic in an IPSec tunnel.
C.Implement RFC 3704 filtering at the perimeter router when allowing syslog access from devices on the outside of a firewall.
D.Synchronize the NTP master clock with an Internet atomic clock.
E.Use SNMP version 2.
F.Use TFTP version 3 or above because these versions support a cryptographic authentication mechanism between peers.

最新試題

Refer to the exhibit. Which statement is true about the configuration of split tunnels using SDM?()

題型:單項(xiàng)選擇題

Refer to the exhibit, which shows a PPPoA diagram and partial SOHO77 configuration.Which command needs to be applied to the SOHO77 to complete the configuration?()

題型:單項(xiàng)選擇題

Which three techniques should be used to secure management protocols?()

題型:多項(xiàng)選擇題

Refer to the exhibit. What type of security solution will be provided for the inside network?()

題型:單項(xiàng)選擇題

Which two statements about the Cisco AutoSecure feature are true?()

題型:多項(xiàng)選擇題

Refer to the exhibit.Which three statements describe the steps that are required to configure an IPsec site-to-site VPN using a GRE tunnel?()

題型:多項(xiàng)選擇題

What is a reason for implementing MPLS in a network?()

題型:單項(xiàng)選擇題

Which statement describes Reverse Route Injection (RRI)?()

題型:單項(xiàng)選擇題

Which form of DSL technology is typically used as a replacement for T1 lines?()

題型:單項(xiàng)選擇題

During the Easy VPN Remote connection process,which phase involves pushing the IP address, Domain Name System (DNS),and split tunnel attributes to the client?()

題型:單項(xiàng)選擇題