|
本帖最后由 ccna 于 29-10-2009 15:43 编辑
640-863 Exam 全稱Designing for Cisco Internetwork Solutions ,屬於Cisco CCDA認證考試
1. A Cisco security mechanism has the following attributes:
It is a sensor appliance
It searches for potential attacks by capturing and analyzing traffic
It is a “purpose-built device”
It is installed passively
It introduces no delay or overhead Which Cisco security mechanism is this?
A. IKE
B. PIX
C. HIPS
D. NIDS
E. HMAC
Answer: D
2. You design a network with the following network addresses:
192.168.168.0
192.168.169.0
192.168.170.0
192.168.171.0
192.168.172.0
192.168.173.0
192.168.173.0
192.168.174.0
192.168.175.0
Which route address is the best summary of these network addresses?
A. 192.128.0.0/24
B. 192.128.171.128/3
C. 192.128.168.0/21
D. 192.128.175.0/3
E. 192.128.0.0/16
Answer: C
3. Which two statements about IPv6 addresses are true? (Choose two.)
A. Leading zeros are required.
B. Two colons (::) are used to represent successive hexadecimal fields of zeros.
C. Two colons (::) are used to separate fields.
D. A single interface will have multiple IPv6 addresses of different types.
Answer: BD
4. Which Cisco security solution can quarantine and prevent non-compliant end stations from accessing
the network until they achieve security policy compliance?
A. Cisco Secure Connectivity
B. Adaptive Security Appliance
C. Access Control Server
D. Network Admission Control
E. Network Intrusion Prevention System
F. Cisco Security Monitoring, Analysis, and Response System
Answer: D
5. A manufacturing company has decided to add a website to enhance sales. The web servers in the
E-Commerce module must be accessible without compromising network security. Which two design
recommendations can be made to meet these requirements? (Choose two.)
A. Use private and public key encryption.
B. Move the E-Commerce servers to the WAN module.
C. Use intrusion detection on the E-Commerce server farm.
D. Limit the number of incoming connections to the E-Commerce module.
E. Place E-Commerce servers and application servers on isolated LANs (DMZs).
Answer: CE |
|