A network administrator wants to ensure that only the server

题目
多选题
A network administrator wants to ensure that only the server can connect to port Fa0/1 on a Catalyst switch. The server is plugged into the switch Fa0/1 port and the network administrator is about to bring the server online. What can the administrator do to ensure that only the MAC address of the server is allowed by switch port Fa0/1 (Choose two.)()。
A

Configure port Fa0/1 to accept connections only from the static IP address of the server.

B

Employ a proprietary connector type on Fa0/1 that is incompatible with other host connectors.

C

Configure the MAC address of the server as a static entry associated with port Fa0/1.

D

Bind the IP address of the server to its MAC address on the switch to prevent other hosts from spoofing the server IP address.

E

Configure port security on Fa0/1 to reject traffic with a source MAC address other than that of the server.

F

Configure an access list on the switch to deny server traffic from entering any port other than Fa0/1.

如果没有搜索结果或未解决您的问题,请直接 联系老师 获取答案。
相似问题和答案

第1题:

The Ezonexam network administrator wants to ensure that only a single web server can connect to pot Fa0/1 on a catalyst switch. The server is plugged into the switch's Fast Eth. 0/1 port and the network administrator is about to bring the server online. What can the administrator do to ensure that only the MAC address of this server is allowed by switch port Fa0/1? (Choose two)

A.Configure port Fa0/1 to accept connections only from the static IP address of the server

B.Configure the MAC address of the server as a static entry associated with port Fa0/1

C.Employ a proprietary connector type on Fa0/1 that is incomputable with other host connectors

D.Configure port security on Fa0/1 to reject traffic with a source MAC address other than that of the server

E.Bind the IP address of the server to its MAC address on the switch to prevent other hosts from spoofing the server IP address


正确答案:BD
解析:Explanation:
You can use port security to block input to an Ethernet, Fast Ethernet, or Gigabit Ethernet port when the MAC address of the station attempting to access the port is different from any of the MAC addresses specified for that port.

When a secure port receives a packet, the source MAC address of the packet is compared to the list of secure source addresses that were manually configured or autoconfigured (learned) on the port. If a MAC address of a device attached to the port differs from the list of secure addresses, the port either shuts down permanently (default mode), shuts down for the time you have specified, or drops incoming packets from the insecure host.

The port's behavior. depends on how you configure it to respond to a security violation. When a security violation occurs, the Link LED for that port turns orange, and a link-down trap is sent to the Simple Network Management Protocol (SNMP) manager. An SNMP trap is not sent if you configure the port for restrictive violation mode. A trap is sent only if you configure the port to shut down during a security violation.

第2题:

Since HTTP is one of the most common protocols used in the internet, what should be done at a firewall level to ensure thatthe protocol is being used correctly? ()

  • A、 Ensure that a stateful firewall allows only HTTP traffic destined for valid web server IP addresses.
  • B、 Ensure that a firewall has SYN flood and DDoS protection applied specifically for valid web servers.
  • C、 Ensure that your firewall enforces HTTP protocol compliance to ensure that only valid flows are allowed inand outof your network.
  • D、 Ensure that HTTP is always authenticated.
  • E、 Ensure that your web server is in a different zone than your backend servers such as SQL and DNS.

正确答案:C

第3题:

Your network consists of a single Active Directory domain. All computers on the network are joined to the domain.You have a server named Server1 that runs Windows Server 2003 Service Pack 2 (SP2). You install a network management application named App1 on Server1.A user named Admin1 logs on to Server1 and reports that the shortcut to App1 does not exist. You log on to Server1 as a local administrator and verify that the shortcut to App1 exists.You need to ensure that a shortcut to App1 is available for Admin1 on Server1 only.What should you do? ()

A. Log on to Server1 as a local administrator. Create a shortcut to App1 in the Default User profile.

B. Log on to Server1 as a local administrator. Create a shortcut to App1 in the All Users profile.

C. In the Netlogon share on a domain controller, create a folder named Default User. Create a shortcut for App1 in the new folder.

D. In the Netlogon share on a domain controller, create a folder named All Users. Create a shortcut for App1 in the new folder.


参考答案:B

第4题:

A customer wants to increase the performance of an existing server. They are running a very network intensive application and feel that increasing the bandwidth to the network will fix their problem.  They are running two 24-port autosensing 10/100 hubs, tied together with a standard Ethernet crossover cable in port 24.  The server is running IPX. After adding a second network card and plugging one card into each hub, they have not seen any performance improvement.  Which two are likely reasons why implementing network adapter teaming has not improved performance?()

  • A、 Adapter teaming is designed to work with switches.
  • B、 Adapter teaming only functions with gigabit network cards.
  • C、 Adapter teaming only provides fault tolerance, not additional bandwidth.
  • D、 Adapter teaming only works with IPX when using switches and network cards with special features that support teaming.

正确答案:A,D

第5题:

You are the network administrator for All network servers run Windows Server 2003. Recently, another network administrator create a scheduled task to perform a normal backup of Microsoft Exchange Server 2003 compuer every Saturday night. You need to perform maintenance tasks on the Exchange server on this Saturday night only. If the backup starts while you are performing the maintenance tasks,data might be corrupted. You need to ensure that the backup task does not start while you perform the maintenance tasks. What are two possible ways to achieve this goal? (Each correct answer presents a complete solution.()Choose two.)

  • A、In the Backup utility, clear the Enabled (scheduled tasks runs at specified time) check box.
  • B、In Control Panel, use Scheduled Tasks to pause Task Scheduler.
  • C、Run the Schtasks command with the /end /p parameters.
  • D、Use the Services snap-in to change the startup type of the Task Scheduler service from Automatic to Manual.

正确答案:A,B

第6题:

A network administrator wants to detect a login attack against a router. What IOS command can make the attack recorded in syslog server?()

  • A、Logging detect fail-login
  • B、Login on-failure log
  • C、Login detect login-failure log
  • D、Logging login on-failure
  • E、none of the above

正确答案:B

第7题:

Users report that they are unable to connect to a server. An administrator confirms that it is unreachable across the network. Other administrators have been working in the server room throughout the day.  Which of the following is the NEXT step the administrator should take?()

  • A、 Verify the configuration of the connected port on the network switch.
  • B、 Reboot the server.
  • C、 Install a new NIC on the server.
  • D、 Verify that network cables are connected.

正确答案:D

第8题:

Your network contains a server named Server1 that runs Windows Server 2008 R2. The network contains multiple subnets.An administrator reports that Server1 fails to communicate with computers on remote subnets.You run route.exe print on Server1 as shown in the exhibit. (Click the Exhibit button.)You need to ensure that Server1 can communicate with all computers on the network.What should you do?()

A. Disable IPv6.

B. Change the subnet mask.

C. Add a default gateway address.

D. Change the default metric to 100.


参考答案:C

第9题:

A network administrator wants to ensure that only the server can connect to port Fa0/1 on a Catalyst switch. The server is plugged into the switch Fa0/1 port and the network administrator is about to bring the server online. What can the administrator do to ensure that only the MAC address of the server is allowed by switch port Fa0/1?()

  • A、Configure port Fa0/1 to accept connections only from the static IP address of the server.
  • B、Employ a proprietary connector type on Fa0/1 that is incompatible with other host connectors.
  • C、Configure the MAC address of the server as a static entry associated with port Fa0/1.
  • D、Bind the IP address of the server to its MAC address on the switch to prevent other hosts from spoofing the server IP address.
  • E、Configure port security on Fa0/1 to reject traffic with a source MAC address other than that of the server.
  • F、Configure an access list on the switch to deny server traffic from entering any port other than Fa0/1.

正确答案:C,E

第10题:

An administrator replaces the network card in a web server. After replacing the network card some users can access the server but others cannot. Which of the following is the FIRST thing the administrator should check?()

  • A、Default gateway
  • B、The ports on the switch
  • C、Port security on the server's switch port
  • D、Ethernet cable

正确答案:A

更多相关问题