单项选择题Which type of attacks can be monitored and mitigated by CS-MARS using NetFlow data?()

A. Man-in-themiddle attack
B. Spoof attack
C. Land.C attack
D. Buffer Overflow
E. Day zero attack
F. Trojan Horse


您可能感兴趣的试卷

你可能感兴趣的试题

1.单项选择题Which best represents a typical attackthat takes advantage of RFC 792, ICMPType 3 messages?()

A. Blind connection-reset
B. Large packet echo request
C. Packet fragmentation offset
D. Broadcast-based echo request
E. Excessive bandwidth consumption

2.多项选择题Cisco IOS IPS sends IPS alert messages using which two protocols? ()

A. SDEE
B. LDAP
C. SYSLOG
D. FTP
E. SNMP
F. SMTP

3.多项选择题When implementing WLAN security, what are three benefits of using the Temporal Key Integrity Protocol (TKIP) instead of WEP? ()

A. TKIP uses an advanced encryption scheme based on AES
B. TKIP provides authentication and integrity checking using Cipher Block Chaining Message Authentication Code (CBC-MAC)
C. TKIP provides per-packet keyingand a rekeying mechanism
D. TKIP provides message integrity check
E. TKIP reduces WEP’s vulnerabilities byusing different hardware encryption chipset
F. TKIP uses a 48 bit InitializationVector

4.多项选择题Which three statements regarding Cisco ASAmulticast routing support are correct? ()

A. ASA supports both stubmulticast routing and PIMmulticast routing. However, you cannot configure bothconcurrently on a single security appliance
B. When configured for stubmulticast routing, the ASA can act as the Rendezvous Point (RP)
C. If the ASAdetects IGMPversion1 routers, the ASAwill automatically switch to IGMP version 1 operations.
D. The ASA supports both PIM-SM and bi-directional PIM
E. Enabling multicast routing globally on the ASA automatically enables PIM and IGMP on all interfaces
F. The ASA can be configured for IGMP snooping toconstrain theflooding of multicast traffic by dynamically configuring themulticast traffic to be forwarded only those interfaces associated with hosts requesting themulticast group

5.单项选择题The key lengths for DES and 3DES, respectively, are:()

A. 128 bits and 256 bits
B. 128 bits and 384 bits
C. 1024 bits and 3072bits
D. 64 bits and 192 bits
E. 56 bits and 168 bits
F. 128 bytes and 384 bytes

6.多项选择题Which algorithms did TKIP add to the 802.11 specification? ()

A. key mixing
B. AES-based encryption
C. anti-replay sequence counter
D.  message integrity check
E. cyclic redundancy check

7.多项选择题Whenever a failover takes place on the ASA (configured for failover), all active connections are droppedand clients must re-establish their connections unless: ()

A. The ASA is configured for Active-Standby failover.
B.  The ASA is configured for Active-Activefailover.
C. The ASA is configured for Active-Active failover and a state failover link has been configured.
D. The ASA is configured for Active-Standby failover and a state failover link has been configured.
E. The ASA is configured to use a serial cable as the failover link.
F. The ASA is configured for LAN-Based failover

8.多项选择题Whattwo things must you do onthe router before generating an SSH key with the "crypto key generate rsa"IOS command? ()

A. Configure the SSH version that the router will use
B. Configure the host name of the router
C. Enable AAA Authentication
D. Configure the default IP domain name that the router will use
E. Enable SSH transport support onthe vty lines

9.单项选择题What is the main reason for using the "ip ips deny-action ips-interface" IOS command?()

A. To selectively apply drop actions to specific interfaces
B. To enable IOS to droptraffic for signatures configured with the Drop action
C. To support load-balancing configurations in which traffic can arrive via multipleinterfaces 
D. This is nota valid IOS command

10.多项选择题Which of the following is true about the Cisco IOS-IPS functionality? ()

A. The signatures available are built into the IOS code.
B. Toupdate signatures youneed to install a new IOS image
C. To activate new signatures you download a new Signature DefiitionFile (SDF) from Cisco’s web site
D. Loading and enabling selected IPS signatures is user configurable
E. Cisco IOS onlyprovides Intrusion Detection functionality
F. Cisco IOS-IPS requires a network module installed in your router running sensor software