Classifying and marking traffic should be done as close to the traffic source as possible.
Classifying and marking traffic should be done at the distribution layer.
Traffic is classified and marked as it travels through the network.
If untrusted traffic enters a switch, it can be marked with a new QoS value appropriate for the policy in place.
The trust boundary moves depending on the type of traffic entering the network.
第1题:
A. AH provides data integrity.
B. AH is identified by IP protocol 50.
C. AH is identified by IP protocol 51.
D. AH cannot work in conjunction with ESP
第2题:
A. 1 is the default precedence.
B. A lower number is preferred.
C. A higher number is preferred.
D. 100 is the default precedence.
第3题:
Click the Exhibit button.Assume the default-policy has not been configured.Given the configuration shown in the exhibit, which two statements about traffic from host_a in the HR zone to host_b in the trust zone are true? ()(Choose two.)
A. DNS traffic is denied.
B. HTTP traffic is denied.
C. FTP traffic is permitted.
D. SMTP traffic is permitted.
第4题:
Which two statements are true about traffic shaping?()
第5题:
You have been tasked with setting a trust boundary on the Company network. What is the basic function of this trust boundary?()
第6题:
A. Traffic is permitted from the trust zone to the untrust zone.
B. Intrazone traffic in the trust zone is permitted.
C. All traffic through the device is denied.
D. The policy is matched only when no other matching policies are found.
第7题:
Which two statements about VACLs on Cisco Nexus 7000 Series Switches are true? ()
第8题:
A. PAT is not supported.
B. PAT is enabled by default.
C. It supports the address-persistent configuration option.
D. It supports the junos-global configuration option.
第9题:
Which two statements are true about L2TP tunnels?() (Choose two.)
第10题:
Which two statements about the Cisco Nexus 1000V VSM are true?()