- 积分
- 106
- 鸿鹄币
- 个
- 好评度
- 点
- 精华
- 最后登录
- 1970-1-1
- 阅读权限
- 20
- 听众
- 收听
助理工程师
 
|
海外,88X 分过的,考试时故意错了几个题。参考了坛子里多个版本 (alomar,lining7, romantictriv等),在这里一并感谢。 感觉Alomar的124Q是最好的,因为有截图。Romantictriv的125Q VCE适合考前练习,没有截图,不便于记忆。
: a7 Y8 {, _3 k! a w3 E# x针对124Q的一些答案,我有自己的看法,在这里列出来,供后来者参考。记得是参考!!) w5 i, M0 B% K: C
Q2,Which criteria does ASA use for packet classificaton if multiple contexts share an ingrss interface MAC address?
4 Q0 @) w$ P. d' CF, ASA NAT configuration1 N/ E3 |( @/ \8 Y3 Q
7 l$ C$ W$ E% q: c0 t5 N+ V' kQ18, SenderBase reputation scoring?/ Q& @) v3 C3 q" E: L4 a
D, You can configure a custom score threshold for whitelisting messages% Q; \% V0 ^" r. r) N: z- u2 L* ~
" m- d* k# v# N/ OQ19. Router(config)# cts sxp reconsiliation period 180+ G0 e) {: w+ K6 k" Z+ I3 M
B, If a peer reconects to the device within 120 seconds of terminating..
& K1 \ V+ \! n6 b/ _; B# N/ j% LC. If a peer re-establiehes a conneciton to the device before hold-down timer expires....
/ K, l& |- t4 t1 ?5 `
# X8 L5 d' q# HQ27. which statement about securing conneciton using MACsee is true?, ^; e: m( s3 v5 D( Z
这个比较纠结,答案F it provides network layer encryption on a wired network 显然是错的,应该是MAC layer的加密
) x, x) N: d. m9 T) t貌似可能的答案:8 t1 |. \( K/ W; E A" h0 g
C. a switch use session keys to calculate encrypted packet ICV value..问题是,交换机是先decrypt packet之后再计算的ICV value
6 W: x$ Q/ ^' Z N' oD. switch configured for MACSec can accept MACSec frame from the MACSec client. 考前我觉得应该是这个,因为A device that uses MACsec accepts either MACsec or non-MACsec frames, depending on the policy associated with the client.但考试的时候答案稍微不同,多了一个字:switch configured for MACSec can ONLY accept MACSec frame from the MACSec client.; X) a# _. {& j/ X9 S8 g
+ O8 L- _7 d9 j" ?+ RQ41 which statement about Remote Triggerd Black Hoel: Z9 \1 K' K! F
E. it drops malicious traffic at the customer edge router by forwading it to a Null0 interface9 z: C+ v5 k3 A/ k: b% ]' O
D显然是错的,因为RTBH可以基于source (RFC5635)或destination (RFC3883)做 k% u7 x) B$ e- c0 O0 f
- p# E0 g$ C4 T1 W8 Z/ {
Q42 which statement about Cisco VSG functionality
$ R5 a! ^" {/ }2 B# @E. it provides trusted access to VMs in an enterprise data center 其实这个答案也不太对,但别的的答案都是明显错,比如
4 P% L2 b7 r1 F, q; |! Y, ZA it allows..security administrator to author and manage port profile - 应该是network administrato才能管理port profile,所以不对
0 X% i/ L% u% ~ R, l0 m+ U/ \# E
Q52 which 3 similarities between container and virtual machines?
: H/ G: r9 r1 J7 O4 B& s0 UA. prviate space for processing, E. private network address F. allow custom routes 这是来自freecodecampe网站的一段原话, f, @- K; I1 o, ^. i
; f# D6 o, }" K% I5 X) |Q58 in order to enable CA featue using SCEP, which 3 confguration steps
, P( k! {+ [; B! P7 _B. set an authoritative clock source E. enable ip http server F. issue no shut under the crypto ski CCO上的参考配置5 F8 p# l3 O# Q* K* O1 C- z
: h5 d7 L" ?1 q8 R$ q" F
Q74 which security capablility cn best prevent zero-day malware and attacks?
% J. V8 s" |0 h1 i gB. threat intelligent. 不太可能是A. IPS 因为这里针对的是zero-day的malware
8 K) \$ {/ X6 E0 w# J4 ^3 l4 \& b/ ]/ l
Q90 configuring URL Redirect for Cisco ISE posture validation, you need to create redirect ACL's on switch and WLC, you will. O( B: `4 d/ | m; j+ p
B. Permit traffic to ISE on the switch ACL and deny traffic to ISE in the WLC ACL. 这个应该是实现redirect的标准做法,其它都不对
4 m* v/ }5 H9 I4 a% W/ [2 V/ F, ], V* `0 E
Q99 which of the following statement aobut CisocTrustSec is incorect. K% U5 E; a/ u0 U$ y1 d
A. SXP is required for SGT propogation SGT propogation还有另外一种方式 (硬件支持) u1 R) U( D+ [. H
9 t5 G1 P; a0 H% K0 e: d
Q109 which statement correctly describe how DMVPN can be used to provide nework segmentation' J9 q# x, z# W* R+ S. ?
B DVMPN can be used to transport MPLS packets inside of an mGRC tunnel
$ f! B: v' ]/ f+ ^
; ~( U+ U; V3 K* S6 ?5 O& B再次强调,这个是我个人的判断,仅供参考。祝考试顺利。
1 u3 D7 {0 l) y4 w% Q: \+ J8 h: ~: I$ z" {8 M
8 z# y* f. L0 v! E5 e3 N- I
* X% Q* @$ z5 {$ r6 a5 r) M, m |
评分
-
查看全部评分
|