What are two possible actions an IOS IPS can take if a packet in a session matches a signature?()A、reset the connectionB、forward the packetC、check the packet against an ACLD、drop the packet

题目

What are two possible actions an IOS IPS can take if a packet in a session matches a signature?()

  • A、reset the connection
  • B、forward the packet
  • C、check the packet against an ACL
  • D、drop the packet

相似考题
更多“What are two possible actions an IOS IPS can take if a packet in a session matches a signature?()A、reset the connectionB、forward the packetC、check the packet against an ACLD、drop the packet”相关问题
  • 第1题:

    If the router R1 has a packet with a destination address 192.168.1.255, what describes the operation of the network()。

    A.R1 will forward the packet out all interfaces.

    B.R1 will drop this packet because this it is not a valid IP address.

    C.As R1 forwards the frame containing this packet, Sw-A will add 192.168.1.255 to its MAC table.

    D.R1 will encapsulate the packet in a frame with a destination MAC address of FF-FF-FF-FF-FF-FF

    E.As R1 forwards the frame containing this packet, Sw-A will forward it to the device assigned the IP address of 192.168.1.255.


    参考答案:B

  • 第2题:

    You can see()on the table

    • A、a packet of prawn
    • B、two packets of prawn
    • C、a packet of prawns

    正确答案:C

  • 第3题:

    How does an IPv6 router deal with a packet that is larger than the outgoing interface MTU?()

    • A、It will fragment the packet at Layer 2.
    • B、It will fragment the packet at Layer 3.
    • C、It will drop the packet and send an ICMPv6 message "packet too big" back to the source.
    • D、It will drop the packet.

    正确答案:C

  • 第4题:

    What is the main reason for using the "ip ips deny-action ips-interface" IOS command?()

    • A、 To selectively apply drop actions to specific interfaces
    • B、 To enable IOS to droptraffic for signatures configured with the Drop action
    • C、 To support load-balancing configurations in which traffic can arrive via multipleinterfaces 
    • D、 This is nota valid IOS command

    正确答案:C

  • 第5题:

    What are three features of the Cisco IOS Firewall feature set?()

    • A、network-based application recognition (NBAR)
    • B、authentication proxy
    • C、stateful packet filtering
    • D、AAA services
    • E、proxy server
    • F、IPS

    正确答案:B,C,F

  • 第6题:

    A router receives an IPv6 packet which is 2000 bytes in length. The MTU of the outgoing interface is 1500 bytes. Which action will the router take?()

    • A、Forward the packet.
    • B、Fragment the packet.
    • C、Drop the packet silently.
    • D、Drop the packet and send an ICMPv6 message.

    正确答案:D

  • 第7题:

    Which two statements about the use of SCREEN options are correct?()

    • A、SCREEN options are deployed at the ingress and egress sides of a packet flow.
    • B、Although SCREEN options are very useful, their use can result in more session creation.
    • C、SCREEN options offer protection against various attacks at the ingress zone of a packet flow.
    • D、SCREEN options examine traffic prior to policy processing, thereby resulting in fewer resouces used formalicious packet processing.

    正确答案:C,D

  • 第8题:

    A packet is evaluated against three user-defined terms within a firewall filter and no match isfound. What correctly describes the action the firewall filter will take for this packet?()

    • A、The filter will permit the packet and take no additional action.
    • B、The filter will reject the packet and send an ICMP message back to the sender.
    • C、The filter will discard the packet and take no additional action.
    • D、The filter will permit the packet and write a log entry to the firewall log.

    正确答案:C

  • 第9题:

    When an SRX series device receives an ESP packet, what happens?()

    • A、If the destination address of the outer IP header of the ESP packet matches the IP address of the ingress interface, it will
    • B、If the destination IP address in the outer IP header of ESP does not match the IP address of the ingress interface, it will
    • C、If the destination address of the outer IP header of the ESP packet matches the IP address of the ingress interface, based packet.
    • D、If the destination address of the outer IP header of the ESP packet matches the IP address of the ingress interface, based of inner header, it will decrypt the packet.

    正确答案:C

  • 第10题:

    多选题
    What are two possible actions an IOS IPS can take if a packet in a session matches a signature?()
    A

    reset the connection

    B

    forward the packet

    C

    check the packet against an ACL

    D

    drop the packet


    正确答案: D,B
    解析: 暂无解析

  • 第11题:

    单选题
    A packet is evaluated against three user-defined terms within a firewall filter and no match is found. What correctly describes the action the firewall filter will take for this packet?()
    A

    The filter will permit the packet and take no additional action

    B

    The filter will reject the packet and send an ICMP message back to the sender

    C

    The filter will discard the packet and take no additional action

    D

    The filter will permit the packet and write a log entry to the firewall log


    正确答案: B
    解析: 暂无解析

  • 第12题:

    多选题
    Firewall filters can perform which two actions?()
    A

    Log packet.

    B

    Count packet.

    C

    Set packet metric.

    D

    Decrement packet TTL.

    E

    Change destination IP address.


    正确答案: E,D
    解析: 暂无解析

  • 第13题:

    A packet is evaluated against three user-defined terms within a firewall filter and no match is found. What correctly describes the action the firewall filter will take for this packet?()

    • A、The filter will permit the packet and take no additional action
    • B、The filter will reject the packet and send an ICMP message back to the sender
    • C、The filter will discard the packet and take no additional action
    • D、The filter will permit the packet and write a log entry to the firewall log

    正确答案:C

  • 第14题:

    You can see()on the table.

    • A、a packet of prawn
    • B、two packets of prawn
    • C、a packet of prawns

    正确答案:C

  • 第15题:

    Refer to the exhibit. A router has a 256 kbps Frame Relay circuit connected to interface serial 0/0. As a large FTP packet is being placed into the hardware transmit queue of interface serial 0/0, a voice packet is placed into the priority queue of that interface. How, and in what order, wi the packets be transmitted?()

    • A、the voice packet will be transmitted first, followed by the FTP packet in its entirety
    • B、the voice packet will be transmitted first, followed by the fragmented FTP packet
    • C、the FTP packet will be fragmented and the voice packet will be interleaved
    • D、the FTP packet will be transmitted first in its entirety, follow by the voice packet

    正确答案:D

  • 第16题:

    What is a static packet-filtering firewall used for ?()

    • A、It validates the fact that a packet is either a connection request or a data packet belonging to a connection
    • B、It evaluates network packets for valid data at the application layer before allowing connections
    • C、It analyzes network traffic at the network and transport protocol layers
    • D、It keeps track of the actual communication process through the use of a state table

    正确答案:C

  • 第17题:

    A router receives an IPv6 packet which is 2000 bytes in length. The MTU of the outgoing interface is 1500 bytes. What action will the router take?()

    • A、forwards the packet
    • B、fragments the packet
    • C、drops the packet silently
    • D、drops the packet and sends an ICMP message

    正确答案:D

  • 第18题:

    Which two statements about the use of SCREEN options are correct? ()(Choose two.)

    • A、SCREEN options offer protection against various attacks
    • B、SCREEN options are deployed prior to route and policy processing in first path packet processing
    • C、SCREEN options are deployed at the ingress and egress sides of a packet flow
    • D、SCREEN options, you must take special care to protect OSPF

    正确答案:A,B

  • 第19题:

    Firewall filters can perform which two actions?()

    • A、Log packet.
    • B、Count packet.
    • C、Set packet metric.
    • D、Decrement packet TTL.
    • E、Change destination IP address.

    正确答案:A,B

  • 第20题:

    Firewall filters can perform which two actions?()

    • A、Log packets.
    • B、Set packet metrics.
    • C、Count packets.
    • D、Decrement packet's TTL value.

    正确答案:A,C

  • 第21题:

    What are two features of Packet Flow Acceleration?() (Choose two.)

    • A、Policy-Based Multipath
    • B、TCP Acceleration (AFP)
    • C、Forward Error Correction
    • D、Molecular Sequence Reduction

    正确答案:B,C

  • 第22题:

    单选题
    A router receives a packet on interface 172.16.45.66/26. The source IP of the packet is 172.16.45.127/26 and the destination is 172.16.46.191/26.How will the router handle the packet?()
    A

    The destination is a host on another subnet, so the router will not forward the packet.

    B

    The destination is a host on the same subnet, so the router will forward the packet.

    C

    The destination is a broadcast address, so the router will not forward the packet.

    D

    The destination is a network address, so the router will forward the packet.


    正确答案: B
    解析: 暂无解析

  • 第23题:

    单选题
    A packet is evaluated against three user-defined terms within a firewall filter and no match is found. What correctly describes the action the firewall filter will take for this packet?()
    A

    The filter will permit the packet and take no additional action.

    B

    The filter will reject the packet and send an ICMP message back to the sender.

    C

    The filter will discard the packet and take no additional action.

    D

    The filter will permit the packet and write a log entry to the firewall log.


    正确答案: C
    解析: 暂无解析