Logo ExamsQA
Exit
Free 0/10
1
Question

Which of the following statements regarding the default zone of USG series firewalls is true?

Options
A

The default zone can be deleted.

B

The level of the default zone can be changed.

C

The default zone cannot be deleted, but its level can be changed.

D

There are four default zones.

2
Question

Which of the following attacks is not the network layer attack?

Options
A

IP spoofing attack

B

Smurf attack

C

ARP spoofing attack

D

ICMP attack

3
Question

In most cases, an IP address that is dynamically assigned by a DHCP server has a lease. Which of the following statements regarding the IP address lease is false?

Options
A

The lease renewal timer is 50% of the total lease. When the lease renewal timer expires, the DHCP server must renew the IP address lease.

B

The rebinding timer is 87.5% of the total lease.

C

If the rebinding timer expires but the DHCP client does not receive any responses from the DHCP server, the DHCP client keeps sending DHCP Request packets to the DHCP server which assigned an IP address to it before, until the total lease expires.

D

If the DHCP client receives a DHCP NAK packet within the lease, the client stops using the current IP address immediately and returns to the initialization state. The DHCP client then applies for a new IP address.

4
Question

In a MPLS VPN network, two-layer MPLS labels are added into data packets before they are transmitted over the public network. Which of the following statements regarding data packet processing are true? (Multiple Choice)

Select 2
Options
A

The penultimate hop removes the outer label before forwarding the data packet to a peer PE.

B

The IP data packet received by the peer PE does not carry labels.

C

The penultimate hop removes the outer label if the outer label in the data packet is explicit null label 3.

D

The peer PE sends the data packet to the correct VPN based on the inner label.

5
Question

For interzone packet filtering, which traffic is belong to transmitted to outbound direction?

Options
A

Trusted zone -> Untrusted zone

B

Untrusted zone -> Trusted zone

C

Untrusted zone -> DMZ

D

Trusted zone -> Local zone

6
Question

Which command is used to configure association between VRRP and a physical interface?

Options
A

vrrp vrid 1 track interface GigabitEthernet-0/0/0

B

track vrrp vrid 1 interface GigabitEthernet0/0/0

C

vrrp vrid 1 interface GigabitEthernet0/0/0 track

D

vrrp vrid 1 interface GigabitEthernet0/0/0

7
Question

VXLAN technology is only used to build an inter-DC Layer 2 network.

Options
A

TRUE

B

FALSE

8
Question

Besides resource discovery, allocation, and management, which function else does the VIM management module of NFV provide?

Options
A

Resource scheduling

B

Resource monitoring

C

Resource reclaiming

D

Troubleshooting

9
Question

SDN and NFV are essentially the same concept and both define network function visualization.

Options
A

TRUE

B

FALSE

10
Question

Which of the following statements regarding packet marking is false?

Options
A

QoS information of packets can be marked.

B

The DSCP priority or IP precedence of IP packets can be marked.

C

The 802.1P priority of VLAN packets can be marked

D

The MAC address of packets can be marked.