基本141Q题目覆盖90%,碰到几个新题和之前有人发过的题,一并总结如下:3 B0 p6 {. b9 I
141Q里面的答案不一定对,但是要记住考过应该问题不大。
( w# X5 z( ^+ f其他人考过的,提到的题目这次都碰到了。6 D! x9 N: Y+ E' X$ A
1. BGP TTL Security,可以查下cisco文档,http://www.cisco.com/c/en/us/td/ ... /guide/fs_btsh.html. Z, I% x7 F- Z. J5 L _8 J0 { @$ \4 G
BGP Support for TTL Security Check! X& s9 c) G9 t# f; u# _* ~4 \$ T) {
The BGP Support for TTL Security Check feature introduces a lightweight security mechanism to protect external Border Gateway Protocol (eBGP) peering sessions from CPU utilization-based attacks using forged IP packets. Enabling this feature prevents attempts to hijack the eBGP peering session by a host on a network segment that is not part of either BGP network or by a host on a network segment that is not between the eBGP peers. 2. CoA : 主要考session terminate,reauthentication等,看看这个文档吧 http://www.cisco.com/c/en/us/td/ ... ok/sec-rad-coa.html
1 F3 l+ o7 Y: R5 \3. 还有一个问哪个是stream cipher?! D" _6 ]" E2 Z5 h
9 r4 C1 j8 g* y, {0 F! G
4.
& b5 b# x0 ]9 {$ n j0 L# zWhich three statements about the keying methods used by MACSec are true? (Choose three.) | ) l3 r2 \8 i4 L+ Q' @7 H7 O* j
| B. A valid mode for SAP is NULL. | C. MKA is implemented as an EAPoL packet exchange. | # S" }: d. C$ B" t; V
| E. SAP is not supported on switch SVIs. | 5 |