Summer Sale Special - Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: sntaclus

IPv6 defines multiple types of addresses. Which of the following statements is false about these addresses?

A.

Link-local addresses can be quickly generated using the EUI-64 method.

B.

Anycast addresses can be used only as destination addresses.

C.

Each interface can have multiple global unicast addresses with different network prefixes.

D.

Manually configured link-local addresses have a higher priority than automatically generated ones.

A session is an entry used to record the connection status of a protocol and is fundamental for the firewall to forward packets. Which of the following protocol packets will the firewall create sessions for?

A.

Subsequent fragment

B.

ICMP error packet

C.

GRE

D.

TCP

In the VRP, by default, the routes imported by BGP will be automatically summarized.

A.

TRUE

B.

FALSE

ASPF enables the firewall to support multi-channel protocols such as FTP and to define security policies for complex applications.

A.

TRUE

B.

FALSE

When an SSH client accesses an SSH server for the first time and the SSH server ' s public key is not configured on the SSH client, you can enable first-time authentication on the SSH client. This allows the SSH client to access the SSH server and saves the SSH server ' s public key on the SSH client. In this way, the next time the SSH client accesses the SSH server, the SSH client can use the saved public key to authenticate the SSH server.

A.

TRUE

B.

FALSE

IP multicast effectively conserves network bandwidth and reduces network load. Therefore, it is widely used in network services, such as IPTV, real-time data transmission, and multimedia conferencing.

A.

TRUE

B.

FALSE

Which of the following PIM protocol packets have unicast destination addresses.

A.

Register Stop

B.

Bootstrap

C.

Graft

D.

Assert

The main objective of security policies is to reduce the intrusion success rate and detect attackers. To ensure that detection and prevention are performed throughout the attack lifecycle, a series of plans need to be made. Which of the following statements is false about security policy planning?

A.

If possible, do not reference the content security profile in all security policy rules whose action is permit, so as to facilitate quick check.

B.

Files with unknown threats can be sent to the sandbox for inspection. The firewall periodically reads the inspection result from the sandbox and blocks subsequent traffic based on the inspection result.

C.

To further reduce the attack surface, enable URL filtering and file blocking on the basis of the security policy that permits an application, so as to prevent users from accessing high-risk websites and downloading high-risk files.

D.

Before setting security policies, the administrator must fully understand the applications, users, and contents on the network. This is necessary for properly setting security policies so that the firewall can check the corresponding user traffic.

Four routers run IS-IS and have established adjacencies. The area IDs and router levels are marked in the following figure. R1 and R2 are connected through a PPP link, and R3 is the DIS. Which of the following statements are true?

A.

If R2 sends a Level-2 LSP, R3 needs to send a PSNP for acknowledgment.

B.

R3 periodically sends CSNPs to implement Level-2 LSDB synchronization.

C.

R2 sends an LSP to R3 and R4 in unicast mode.

D.

If R1 sends an LSP, R2 needs to send a PSNP for acknowledgment.

On a broadcast network, IS-IS elects a DIS, and OSPF elects a DR. Which of the following statements are true about the differences between a DIS and a DR?

A.

The DIS and DR provide different functions. The DIS is mainly used to create and update pseudonodes.

B.

Adjacency establishment in a DIS scenario is different from that in a DR scenario. In IS-IS, adjacencies are also established between non-DIS routers.

C.

The DIS and DR are elected according to different rules. In DIS election, devices first compare priorities and then IP addresses. In DR election, devices first compare IP addresses and then priorities.

D.

DIS election and DR election take place at different times. The DIS is elected after an adjacency is established.