IP address
MAC address
protocol
port
session ID
第1题:
A.from protocol tcp
B.from url
C.from community
D.from acl
第2题:
Which three statements about firewall modes are correct? ()
第3题:
What are three firewall filter terminating actions?()
第4题:
What are two valid match criteria for a routing policy?()
第5题:
You have a firewall filter containing two terms applied in an inbound direction on a customer interface. You would like this filter to protect your network from a spoofed denial of service attack. What match criterion should be used in the first term of the filter?()
第6题:
What are three valid match criteria in a firewall filter applied to a Layer 3 interface?()
第7题:
A packet is evaluated against three user-defined terms within a firewall filter and no match isfound. What correctly describes the action the firewall filter will take for this packet?()
第8题:
A firewall in routed mode has one IP address
A firewall in transparent mode has one IP address
In routed mode, the firewall is considered to be a Layer 2 dew
In routed mode, the firewall is considered to be a Layer 3 device
In transparent mode, the firewall is considered to be a Layer 2 device
In transparent mode, the firewall is considered to be a Layer 3 device
第9题:
IP address
MAC address
protocol
port
session ID
第10题:
OSPF are a ID
prefix list
port
time-to-live(TTL)
第11题:
The filter will permit the packet and take no additional action
The filter will reject the packet and send an ICMP message back to the sender
The filter will discard the packet and take no additional action
The filter will permit the packet and write a log entry to the firewall log
第12题:
The IP inspection rule can be applied in the inbound direction on the secured interface
The IP inspection rule can be applied in the outbound direction on the unsecured interface
The ACL applied in the inbound direction on the unsecured interface should be an extendedACL.
For temporary openings to be created dynamically by Cisco IOS Firewall, the access-list for thereturning traffic must be a standard ACL
第13题:
A packet is evaluated against three user-defined terms within a firewall filter and no match is found. What correctly describes the action the firewall filter will take for this packet?()
第14题:
You have a firewall filter containing two terms applied in an inbound direction on a customer interface.You would like this filter to protect your network from a spoofed denial of service attack. Which match criterion should be configured ito identify unwanted packets?()
第15题:
What is a vaild match criteria for a firewall filter?()
第16题:
Which three statements about IOS Firewall configurations are true?()
第17题:
You need to control SSH, HTTP, and Telnet access to an MX240 router through any interface. You have decided to use a firewall filter. How should you apply the firewall filter?()
第18题:
What are two valid match criteria for a routing policy? ()
第19题:
A firewall filter is applied as an input filter on a transit interface. What three types of traffic will this affect? ()
第20题:
accept
log
reject
discard
drop
第21题:
inbound traffic transiting the router
outbound traffic transiting the router
traffic destined to the Routing Engine
traffic destined to the interface address on which the filter is applied
第22题:
OSPF area ID
prefix list
port
time-to-live (TTL)
第23题:
The filter will permit the packet and take no additional action.
The filter will reject the packet and send an ICMP message back to the sender.
The filter will discard the packet and take no additional action.
The filter will permit the packet and write a log entry to the firewall log.
第24题:
The IP inspection rule can be applied in the inbound direction on the secured interface.
The IP inspection rule can be applied in the outbound direction on the unsecured interface.
The ACL applied in the outbound direction on the unsecured interface should be an extended ACL.
The ACL applied in the inbound direction on the unsecured interface should be an extended ACL.
For temporary openings to be created dynamically by Cisco IOS Firewall,the access-list for thereturning traffic must be a standard ACL.
For temporary openings to be created dynamically by Cisco IOS Firewall,the IP inspection rule must be applied to the secured interface.