350-701試験の準備方法|一番優秀な350-701赤本合格率試験|素敵なImplementing and Operating Cisco Security Core Technologies勉強の資料当社から350-701学習教材を購入する場合、高品質の350-701学習問題と最高のサービスを提供できてうれしいです。当社の理念は「品質は命、顧客は神」です。当社はすべての顧客に完璧な品質保証システムと健全な管理システムを提供することを約束できます。当社の350-701学習教材の品質とサービスについて心配する必要はありません。弊社から350-701学習問題を購入することを決めた場合、想像をはるかに超えるものを受け取ることになります。 Cisco Implementing and Operating Cisco Security Core Technologies 認定 350-701 試験問題 (Q129-Q134):質問 # 129
An engineer is configuring device-hardening on a router in order to prevent credentials from being seen if the router configuration was compromised. Which command should be used?
A. service password-recovery
B. service password-encryption
C. username < username> password <password>
D. username <username> privilege 15 password <password>
正解:B
質問 # 130
An engineer wants to automatically assign endpoints that have a specific OUI into a new endpoint group.
Which
probe must be enabled for this type of profiling to work?
A. SNMP
B. NMAP
C. DHCP
D. NetFlow
正解:B
解説:
Cisco ISE can determine the type of device or endpoint connecting to the network by performing "profiling." Profiling is done by using DHCP, SNMP, Span, NetFlow, HTTP, RADIUS, DNS, or NMAP scans to collect as much metadata as possible to learn the device fingerprint.
NMAP ("Network Mapper") is a popular network scanner which provides a lot of features. One of them is the OUI (Organizationally Unique Identifier) information. OUI is the first 24 bit or 6 hexadecimal value of the MAC address.
Note: DHCP probe cannot collect OUIs of endpoints. NMAP scan probe can collect these endpoint attributes:
+ EndPointPolicy
+ LastNmapScanCount
+ NmapScanCount
+ OUI
+ Operating-system
Reference: http://www.network-node.com/blog/2016/1/2/ise-20-profiling