仅仅允许到主机1.1.1.1的SMTP邮件服务的命令是()。A、access-list 10 permit smtp host 1.1.1.1B、access-list 110 permit ip smtp host 1.1.1.1C、access-list 10 permit tcp any host 1.1.1.1 eq smtpD、access-list 110 permit tcp any host 1.1.1.1 eq smtp

题目

仅仅允许到主机1.1.1.1的SMTP邮件服务的命令是()。

  • A、access-list 10 permit smtp host 1.1.1.1
  • B、access-list 110 permit ip smtp host 1.1.1.1
  • C、access-list 10 permit tcp any host 1.1.1.1 eq smtp
  • D、access-list 110 permit tcp any host 1.1.1.1 eq smtp

相似考题
参考答案和解析
正确答案:D
更多“仅仅允许到主机1.1.1.1的SMTP邮件服务的命令是()。A、access-list 10 permit smtp host 1.1.1.1B、access-list 110 permit ip smtp host 1.1.1.1C、access-list 10 permit tcp any host 1.1.1.1 eq smtpD、access-list 110 permit tcp any host 1.1.1.1 eq smtp”相关问题
  • 第1题:

    在 Cisco 路由器匕用扩展访问控制列表封禁 1P 地址为 211.102.33.24 的主机,正确的配置语句是

    A )

    access-list 99 deny ip host 211.102.33.24 any

    access-list 99 deny ip any host 211.102.33.24

    access-list 99 permit ip any any

    B )

    access-list 100 permit ip any any

    access-list 100 deny ip host 211.102.33.24 any

    access-list 100 deny ip any host 211.102.33.24

    C )

    access-list 199 deny ip host 211.102.33.24 any

    access-list 199 deny ip any host 211.102.33.24

    access-list 199 permit ip any any

    D )

    access-list 166 deny ip host 211.102.33.24 any

    access-list 166 permit ip any any


    正确答案:C

  • 第2题:

    只封禁一台地址为192.168.1.230主机的access-list正确配置是 (5) 。 A.access-list 110 permit中anyany access-list 110 deny中host 192.168.1.230 any access-list 110 deny ip anyhost 192.168.1.230

    B.access-list 110 deny中host 192.168.1.230 any access-list 110 deny中any host 192.168.1.230 access-list 110 permit ip anyany

    C.access-list 110 deny ip host 192.168.1.230 any access-list 110 deny ip any host 192.168.1.230

    D.access-list 110 deny ip host 192.168.1.230 any access-list 110 permit ip anyany access-list 110 deny ip any host 192.168.1.230


    正确答案:(5) B
    (5) B 解析:访问控制列表(ACL)用于过滤流入和流出路由器接口的数据包。它是一种基于接口的控制列表,可根据网络管理员制定的访问控制准则来控制接口对数据包的接收和拒绝,从而提高网络的安全性。
    IP访问控制列表是一个连续的列表,至少由一个“permit(允许)”语句和一个或多个“deny(拒绝)”语句组成。ACL列表用名字(name)或表号(number)标识和引用。配置IP访问控制列表的首要任务就是使用命令“access-list”定义一个访问控制列表。在配置过滤规则时,需要注意的是ACL语句的顺序。因为路由器接口执行哪一条ACL是按照配置的访问控制列表中的条件语句(准则),从第1条开始按顺序执行的。数据包只有在跟前一个判断条件不匹配时,才能跟交给ACL的下一个条件语句进行比较。可见,ACL语句的先后顺序非常重要。例如,只封禁一台地址为192.168.1.230的主机的access-list正确配置示例如下:
    access-list 110 deny ip host 192.168.1.230 any
    access-list 110 deny ip any host192.168.1.230
    access-list 110 permit ip any any
    如果将“access-list 110 permit ip any any”放在ACL规则的最前面(见选项A),则其后两条deny语句将不起作用,即不能按照预期的应用需求正确地控制数据包的接收与拒绝。
    选项C的ACL规则中,缺少“permit(允许)”语句,它将封禁全网所有的通信。
    选项D的ACL规则将封禁地址为192.168.1.230的主机对外的单向通信,允许其他主机或路由器访问 192.168.1.230的主机。

  • 第3题:

    A network administrator wants to add a line to an access list that will block only Telnet access by the hosts on subnet 192.168.1.128/28 to the server at 192.168.1.5. What command should be issued to accomplish this task?()

    A.access-list 101 deny tcp 192.168.1.128 0.0.0.15 192.168.1.5 0.0.0.0 eq 23 access-list 101 permit ip any any

    B.access-list 101 deny tcp 192.168.1.128 0.0.0.240 192.168.1.5 0.0.0.0 eq 23 access-list 101 permit ip any any

    C.access-list 1 deny tcp 192.168.1.128 0.0.0.255 192.168.1.5 0.0.0.0 eq 21 access-list 1 permit ip any any

    D.access-list 1 deny tcp 192.168.1.128 0.0.0.15 host 192.168.1.5 eq 23 access-list 1 permit ip any any


    参考答案:A

  • 第4题:

    下面 ACL 语句中,准备表达“允许访问服务器 202.110.10.1 的 WWW 服务”的是()。




    A. access-list 101 permit any 202.110.10.1
    B. access-list 101 permit tcp any host 202.110.10.1 eq www
    C. access-list 101 deny any 202.110.10.1
    D. access-list 101 deny tcp any host 202.110.10.1 eq www

    答案:B
    解析:

  • 第5题:

    要创建一个扩展命名访问控制列表cisco,仅允许HTTP流量进入网络196.15.7.0/24,下面命令是错误的有()。

    • A、ip access-list extended cisco permit tcp any 196.15.7.0 0.0.0.255 eq www
    • B、ip access-list extended cisco deny tcp any 196.15.7.0 eq www
    • C、ip access-list extended cisco permit 196.15.7.0 0.0.0.255 eq www
    • D、ip access-list extended cisco permit ip any 196.15.7.0 0.0.0.255
    • E、ip access-list extended cisco permit www 196.15.7.0 0.0.0.255

    正确答案:B,C,D,E

  • 第6题:

    A network administrator wants to add a line to an access list that will block only Telnet access by the hosts on subnet 192.168.1.128/28 to the server at 192.168.1.5. What command should be issued to accomplish this task?()

    • A、access-list 101 deny tcp 192.168.1.128 0.0.015 192.168.1.5 0.0.0.0 eq 23 access-list 101 permit ip any any
    • B、access-list 1 deny tcp 192.168.1.128 0.0.0.15 host 192.168.1.5 eq 23 access-list 1 permit ip any any
    • C、access-list 1 deny tcp 192.168.1.128 0.0.0.255 192.168.1.5 0.0.0.0 eq 21 access-list 1 permit ip any any
    • D、access-list 101 deny tcp 192.168.1.128 0.0.0.240 192.168.1.5 0.0.0.0 eq 23 access-list 101 permit ip any any
    • E、access-list 101 deny ip 192.168.1.128 0.0.0.240 192.158.1.5 0.0.0.0 eq 23 access-list 101 permit ip any any
    • F、access-list 101 deny ip 192.168.1.128 0.0.0.15 192.168.1.5 0.0.0.0 eq 23 access-list 101 permit ip any any

    正确答案:A

  • 第7题:

    A network administrator wants to add a line to an access list that will block only Telnet access by the hosts on subnet 192.168.1.128/28 to the server at 192.168.1.5.What command should be issued to accomplish this task?()

    • A、access-list 101 deny tcp192.168.1.1280.0.0.15192.168.1.50.0.0.0eq23 access-list 101 permit ip any any
    • B、access-list 101 deny tcp192.168.1.1280.0.0.240192.168.1.50.0.0.0eq23 access-list101permit ip any any
    • C、access-list 1 deny tcp192.168.1.1280.0.0.255192.168.1.50.0.0.0eq21 access-list1permit ip any any
    • D、access-list 1 deny tcp192.168.1.1280.0.0.15host192.168.1.5eq23 access-list1permit ip any any

    正确答案:A

  • 第8题:

    仅仅允许到主机1.1.1.1的SMTP邮件服务的命名访问控制列表语句是()。

    • A、ip access-list standard cisco permit smtp host 1.1.1.1
    • B、ip access-list extended cisco permit ip smtp host 1.1.1.1
    • C、ip access-list standard cisco permit tcp any host 1.1.1.1 eq smtp
    • D、ip access-list extended cisco permit tcp any host 1.1.1.1 eq smtp

    正确答案:D

  • 第9题:

    Which item represents the standard IP ACL?()

    • A、access-list 50 deny 192.168.1.1 0.0.0.255
    • B、access-list 110 permit ip any any
    • C、access-list 2500 deny tcp any host 192.168.1.1 eq 22
    • D、access-list 101 deny tcp any host 192.168.1.1

    正确答案:A

  • 第10题:

    A network administrator wants to add a line to an access list that will block only Telnet access by the hosts on subnet 192.168.1.128/28 to the server at 192.168.1.5. What command should be issued to accomplish this task?()

    • A、access-list 101 deny tcp 192.168.1.128 0.0.0.15 192.168.1.5 0.0.0.0 eq 23  access-list 101 permit ip any any
    • B、access-list 101 deny tcp 192.168.1.128 0.0.0.240 192.168.1.5 0.0.0.0 eq 23  access-list 101 permit ip any any
    • C、access-list 1 deny tcp 192.168.1.128 0.0.0.255 192.168.1.5 0.0.0.0 eq 21  access-list 1 permit ip any any
    • D、access-list 1 deny tcp 192.168.1.128 0.0.0.15 host 192.168.1.5 eq 23  access-list 1 permit ip any any

    正确答案:A

  • 第11题:

    单选题
    仅仅允许到主机1.1.1.1的SMTP邮件服务的命名访问控制列表语句是()。
    A

    ip access-list standard cisco permit smtp host 1.1.1.1

    B

    ip access-list extended cisco permit ip smtp host 1.1.1.1

    C

    ip access-list standard cisco permit tcp any host 1.1.1.1 eq smtp

    D

    ip access-list extended cisco permit tcp any host 1.1.1.1 eq smtp


    正确答案: B
    解析: 暂无解析

  • 第12题:

    单选题
    仅仅允许到主机1.1.1.1的SMTP邮件服务的命令是()。
    A

    access-list 10 permit smtp host 1.1.1.1

    B

    access-list 110 permit ip smtp host 1.1.1.1

    C

    access-list 10 permit tcp any host 1.1.1.1 eq smtp

    D

    access-list 110 permit tcp any host 1.1.1.1 eq smtp


    正确答案: C
    解析: 暂无解析

  • 第13题:

    只封禁一台IP地址为203.168.47.59主机的access-list的正确配置是(41) 。

    A.access-list 110permit ip any any access-list 110deny ip host 203.168.47.59 any access-list 110deny ip any host 203.168.47.59

    B.access-list 110deny ip host 203.168.47.59any access-list 110deny ip any host 203.168.47.59 access-list 110permit ip any any

    C.access-list 110deny ip host 203.168.47.59 any access-list 110deny ip any host 203.168.47.59

    D.access-list 110deny ip host 203.168.47.59 any access-list 110permit ip any any access-list 110deny ip any host 203.168.47.59


    正确答案:B
    解析:访问控制列表(ACL)用于过滤流入和流出路由器接口的数据包。它是一种基于接口的控制列表,可根据网络管理员制订的访问控制准则来控制接口对数据包的接收和拒绝,具有包过滤功能,能做到限制网络流量、限制用户和设备对网络的访问,减少网络欺骗和拒绝服务,以提高网络的安全性。
      IP访问控制列表是一个连续的列表,至少由一个“permit(允许)”语句和一个或多个“deny(拒绝)”语句组成。ACL列表用名字(Name)或表号(Number)标识和引用。配置IP访问控制列表的首要任务就是使用命令“access-list”定义一个访问控制列表。在配置过滤规则时,需要注意的是ACL语句的顺序。因为路由器接口执行哪一条ACL是按照配置的访问控制列表中的条件语句(准则),从第1条开始顺序执行的。数据包只有在跟前一个判断条件不匹配时,才能被交给ACL中的下一个条件语句进行比较。可见, ACL语句的先后顺序非常重要。例如,只封禁一台地址为203.168.47.59主机的access-list的正确配置如下:
      access-list 110 deny ip host
      access-list 110 deny ip any host 203.168.47.59
      access-list 110 permit ip any any
      如果将“access-list 110 permit ip any any”放在ACL规则的最前面(见选项A),则其后两条deny语句将不起作用,即不能按照预期的应用需求正确地控制数据包的接收与拒绝。
      选项C的ACL规则中,缺少“permit(允许)”语句,它将封禁全网所有的通信。
      选项D的ACL规则,将封禁地址为203.168.47.59的主机对外的单向通信,允许其他主机或路由器访问203.168.47.59的主机。

  • 第14题:

    下面是在防火墙中的部分配置命令,请解释其含义:

    global(outside)1 202.134.135.98-202.134.135.100(8)

    conduit permit tcp host 202.134.135.99 eq www any(9)

    access-list 10 permit ip any any(10)


    正确答案:(8)指定外网口Ⅳ地址范围为202.134.135.98-202.134.135.100 (9)允许任意外网主机访问202.134.135.99提供的WWW服务 (10)允许任意IP数据包进出
    (8)指定外网口Ⅳ地址范围为202.134.135.98-202.134.135.100 (9)允许任意外网主机访问202.134.135.99提供的WWW服务 (10)允许任意IP数据包进出 解析:本题考查的ACL规则。各规则解释如下:
    global (outside) 1 202.134.135.98- 202.134.135.100
    //指定外网口IP地址范围为202.134.135.98-202.134.135.100
    conduit permit tcp host 202.134.135.99 eq www any
    //允许任意外网主机访问202.134.135.99提供的WWW服务
    access- list 10 permit ip any any
    //允许任意IP数据包进出

  • 第15题:

    只封禁一台地址为193.62.40.230主机的access-list的正确配置是

    A.access-list 110 permit ip any any access-list 110 deny ip host 193.62.40.230 any access-list 110 deny ip any host 193.62.40.230

    B.access-list 110 deny ip host 193.62.40.230any access-list 110 deny ip any host 193.62.40.230 access-list 110 permit ip any any

    C.access-list 110 deny ip host 193.62.40.230 any access-list 110 deny ip any host 193.62.40.230

    D.access-list 110 deny ip host 193.62.40.230 any access-list 110 permit ip any any access-list 110 deny ip any host 193.62.40.230


    正确答案:B

  • 第16题:

    计费服务器的ip地址在192.168.1.0/24子网内,为了保证计费服务器的安全,不允许任何用户telnet到该服务器,则需要配置的访问列表条目为:()

    • A、access-list  11 deny  tcp 192.168.1.0   0.0.0.255 eq telnet/access-list 111 permit ip any any
    • B、access-list  111 deny  tcp any  192.168.1.0   eq telnet/access-list 111 permit ip any any
    • C、access-list  111 deny udp 192.168.1.0   0.0.0.255 eq telnet/access-list 111 permit ip any any
    • D、access-list  111 deny  tcp any  192.168.1.0   0.0.0.255 eq telnet/access-list 111 permit ip any any

    正确答案:D

  • 第17题:

    仅允许HTTP流量进入网络196.15.7.0,下面命令错误的是()。

    • A、access-list 100 permit tcp any 196.15.7.0 0.0.0.255 eq www
    • B、access-list 10 deny tcp any 196.15.7.0 eq www
    • C、access-list 100 permit 196.15.7.0 0.0.0.255 eq www
    • D、access-list 110 permit ip any 196.15.7.0 0.0.0.255
    • E、access-list 110 permit www 196.15.7.0 0.0.0.255

    正确答案:B,C,D,E

  • 第18题:

    Which of the following IOS commands can detect whether the SQL slammer virus propagates in yournetworks?()

    • A、access-list 100 permit any any udp eq 1434
    • B、access-list 100 permit any any udp eq 1434 log
    • C、access-list 110 permit any any udp eq 69
    • D、access-list 110 permit any any udp eq 69 log
    • E、None of above.

    正确答案:B

  • 第19题:

    Which item represents the standard IPACL?()

    • A、access-list 50 deny 192.168.1.10.0.0.255
    • B、access-list 110 permit ip any any
    • C、access-list 2500 deny tcp any host 192.168.1.1 eq22
    • D、access-list 101 deny tcp any host 192.168.1.1

    正确答案:A

  • 第20题:

    哪个选项代表了标准的IP ACL?()

    • A、 access-list 50 deny 192.168.1.1 0.0.0.255
    • B、 access-list 110 permit ip any any
    • C、 access-list 2500 deny tcp any host 192.168.1.1 eq 22
    • D、 access-list 101 deny tcp any host 192.168.1.1

    正确答案:C

  • 第21题:

    Which item represents the standard IP ACL?()

    • A、access-list 50 deny 192.168.1.10.0.0.255
    • B、access-list 110 permitip any any
    • C、access-list 2500 deny tcp any host 192.168.1.1eq22
    • D、access-list 101 deny tcp any host 192.168.1.1

    正确答案:A

  • 第22题:

    单选题
    哪个选项代表了标准的IP ACL?()
    A

     access-list 50 deny 192.168.1.1 0.0.0.255

    B

     access-list 110 permit ip any any

    C

     access-list 2500 deny tcp any host 192.168.1.1 eq 22

    D

     access-list 101 deny tcp any host 192.168.1.1


    正确答案: D
    解析: 暂无解析

  • 第23题:

    单选题
    A network administrator wants to add a line to an access list that will block only Telnet access by the hosts on subnet 192.168.1.128/28 to the server at 192.168.1.5. What command should be issued to accomplish this task?()
    A

    access-list 101 deny tcp 192.168.1.128 0.0.015 192.168.1.5 0.0.0.0 eq 23 access-list 101 permit ip any any

    B

    access-list 1 deny tcp 192.168.1.128 0.0.0.15 host 192.168.1.5 eq 23 access-list 1 permit ip any any

    C

    access-list 1 deny tcp 192.168.1.128 0.0.0.255 192.168.1.5 0.0.0.0 eq 21 access-list 1 permit ip any any

    D

    access-list 101 deny tcp 192.168.1.128 0.0.0.240 192.168.1.5 0.0.0.0 eq 23 access-list 101 permit ip any any

    E

    access-list 101 deny ip 192.168.1.128 0.0.0.240 192.158.1.5 0.0.0.0 eq 23 access-list 101 permit ip any any

    F

    access-list 101 deny ip 192.168.1.128 0.0.0.15 192.168.1.5 0.0.0.0 eq 23 access-list 101 permit ip any any


    正确答案: A
    解析: 暂无解析