2015-2020年软考网络工程师下午真题汇编_第1页
2015-2020年软考网络工程师下午真题汇编_第2页
2015-2020年软考网络工程师下午真题汇编_第3页
2015-2020年软考网络工程师下午真题汇编_第4页
2015-2020年软考网络工程师下午真题汇编_第5页
已阅读5页,还剩114页未读 继续免费阅读

下载本文档

版权说明:本文档由用户提供并上传,收益归属内容提供方,若内容存在侵权,请进行举报或认领

文档简介

目录 2020试题一(20APWLAN【问题一】(10分1、Router[Huawei]sysnameRouter[Router]vlanbatch(1)[Router]interfaceGigabitEthernet[Router-GigabitEthernet1/0/0]portlinktype[Router-GigabitEthernet1/0/0]porttrunkallow-passvlan101[Router-GigabitEthernet1/0/0]quit[Router]interfacevlanif101[Router-Vlanif101]ipaddress(2)2、ACAC[HUAWEI]sysname(3)[AC]vlanbatch100101[AC]interfaceGigabitEthernet[AC-GigabitEthernet0/0/1]portlink-typetrunk[AC-GigabitEthernet0/0/1]porttrunkpvidvlan100[AC-GigabitEthernet0/0/1]porttrunkallow-passvlan100[AC-GigabitEthernet0/0/1]port-isolate(4)//实现端口隔离[AC-GigabitEthernet0/0/1]quit[AC]interface[AC-GigabitEthernet0/0/2]portlink-type[AC-GigabitEthernet0/0/2]porttrunkallow-passvlan101APAP[AC-wlan-view]ap-groupnameap-group1[AC-wlan-view]regulatory-domainprofilenamedefault[AC-wlan-regulate-domaindefault]country-code(5)[AC-wlan-view]ap-groupnameap-[AC-wan-ap-group-apgroup1]regulatory-domain-profileWarning:Modifyingthecountrycodewillclearchannel,powerandantennagainconfigurationsoftheradioandresettheAP.Continue?[Y/N]:y[AC]capwapsourceinterface[AC][AC-wlan-view]apauthmodemac-[AC-wan-view]ap-id0apmac68a8-2845-62fd APMAC[AC-wlan-ap-0]ap-namecentral_APWarning:ThisoperationmaycauseAPreset.Continue?(Y/N]:y[AC-wlan-ap-0]apgroupap-group1Warning:ThisoperationmaycauseAPreset.Ifthecountrycodechanges,itwillclearchannel,powerandantennagainconfigurationsoftheradio,Whethertocontinue?[Y/N]:y[AC-wlan-ap-0]quitVLAN[ACwlan-view]security-profilenamewlan-[AC-wlan-sec-profwlan-net]securitywpa-wpa2pskpase-phrase(8)aes[AC-wlan-sec-prof-wlan-net]quit[AC-wlan-view]ssidprofilenamewlannet[AC-wlan-ssid-prof-wlan-net]ssid(9)[AC-wlan-ssid-prof-wlan-net]quit[AC-wlan-view]vap-profilenamewlan-[AC-wlan-vap-prof-wlan-net]forward-mode[AC-wlan-vap-prof-wlan-net]service-vlanvlan-id(10)[AC-wlan-vap-prof-wlan-net]security-profilewlan-net[AC-wlan-vap-prof-wlan-net]ssid-profilewlan-net[AC-wlan-vap-prof-wlan-net][AC-wlan-view]ap-groupnameap-[AC-wlan-ap-group-ap-group]vap-profilewlan-netwlan1radio[AC-wlan-ap-group-ap-group]vap-profilewlan-netwlan1radio1[AC-wlan-ap-group-ap-group]quit【问题二】(6分(11,通过配置(11)(12)A.MACB.SNC.APD.APAP(13)APdisplayap B.displayvap3(4组播报文对无线网络空口的影响主要有(14)在(15)、(16)配置。(17试题二(201(4分ABAping不通,故障可能是(1)B上能登录互联网即时聊天软件,但无法打开网页,该故障可能是(2)原因造成。(1(2)备选答案 B.DNS配置错 D.IP配置错2(8分)2(8分)段为(5)攻击,应该采取(6)等措施进行防范。 B.SQL注 3(5分(7SAN,比较结果为(9试题三(20/28)/28)以及教育网(网关地址/28R1、R2、R3、R4RIPv2.0PC3-13-21(2ESPIKE。其中用于数据完整性认证和数据源认证的是(12(2R4Internet[R4]iproute-static(2)3(5[R1-rip-1]network(4)[R1-rip-1]version2[R1-rip-1]undosummaryRIPR1displayiprouting-table,RIP1D1D1D1D/24RIP1001D/24RIP1001DPC14(113-1PC1InternetPC38:0018:001R4PC1ACL[R4]acl2000[R4-acl-basic-2000]rule1permitsource(7)[R4-acl-basic-2000]quitPC3[R4]time-rangesatime(8)working-day[R4]aclnumber3001[R4-acl-adv-3001]ruledenysource(9)destination55time-range(10[R4]trafficclassifer[R4-classifier-1]if-matchacl2000[R4]trafficclassifier[R4-classifier-3]if-matchacl30013R4[R4]trafficbehavior1[R4-bchavior-1]redirect(11)[R4]trafficbehavior[R4-behavior-3](12)4R4GigabitEthernet0/0/0[R4]trafficpolicy1[R4-trafficpolicy-1]classier1[R4-trafficpolicy-1]trassifier3(14)[R4]interGigabitEthernet0/0/0[R4-GigabitEthernet0/0/0]trafficpolicy1(15)试题四(15分地址为其分配固定的IP地址,同时还需要到FTP服务器上动态获取启动配置文件configuration.iniDNS,所有地址段均路由可达。1(3(1(22(12<HUAWEI>[HUAWEI]sysname[SW1](5)optiontemplate[SW1-dhcp-option-template-template1]gateway-list(6)//配置网关地址[SW1-dhcp-option-template-template1]bootfile(7)//获取配置文件[SW1-dhcp-option-template-template1]next-server(8)//配置获取配置文件地址[SW1-dhcp-option-template-template1]quitIPPhoneIP[SW1]ippoolpool3[SW1-ip-pool-pool3]network(9)mask[SW1-ip-pool-pool3]dns-list(10)[SW1-ip-pool-pool3][SW1-ip-pool-pool3]excluded-ip-address(12)54[SW1-ip-pool-pool3]leaseunlimited[SW1-ip-pool-pool3]static-bindip-address192168.3.2mac-address(13)option-templaletemplate1//使用模板[SW1-ip-pool-pool3]VLANDHCP[SW1]interfacevlanif(14)[SW1-Vlanif300](15)selectglobal[SW1-Vlanif300]quit2020WLAN2[AC-wlan-view]apauthmodemac-authMacAC-wlan-ap-0apgroupzp-group1ACK1 (2)24(3) (4) (5) (6)(7)vlanif (8) (9)wlan- (10)【问题2】(11) (12) (13)【问题3】(14)无线空口拥塞 (15)直连AP的交换机接口 (16)AC的流量模板下 墙会有较大衰减,导致宿舍内信号差,故直接将AP部署在每个房间。(意思接近即可)1】ping2eval(base64_decode($_POST)selectSQLD.APT1B2B 【问题3(7)FC- (8)IP- 4RIPR1Internet4(7)PC1InternetIPPC1IP(8)8:00-18:00satime,8:00to18:00。trafficclassiferACLa.ACL3001denyPC3permitPC3ACLdenyPC3,ACLdeny,流行为中deny,deny。此处也可以参考(11)PC1PC3(15)inbound1】2(2)0【问题3(3)rip1 4(7) (8)8:00to (9) ip-redirectipnexthopdenybehavior1(14)behavior3(15)【问题1】(1)接 2】(8)(9)(11)gateway-list(12)502019试题一(20SwitchA,DHCPServer,IPACL(cameraDMZDMZNATServerDMZWEBGEI/0/0:srcip试题二(202-11】(7.5A.面板式AP B.高密吸顶式AP H.POE交换机2】(8123】(4.54TB),该存储域网络为(12)网络。试题三(20,DNSServer1WebSDNSServer2DNS,WebServer、FTPServer、DNSServer1、DNSServer2WindowsServer2008R21】(6WebServerHTTP,IIS列表框中可以勾选的服务包括“(1)”,“管理工具”以及“FTP3-2Web务器配置界面,“IP(2),“端口”处应填(3),“主机名”处应填(4)。2】(6DNSSDNS域”,选择“新建区域(Z)DNS3-3(5)3-4新建主机的“名称”处应填(6),“IP(7),3-43】(4IP(10)。4】(4根服务器;如果选择(12)DNSIP试题四(151】(6[Switch]vlan(3)102030100200[Switch-GigabitEthernet0/0/1]portlink-[Switch-GigabitEthernet0/0/1]porttrunkallow-passvlan_(6)_[Huawei]interfacevlanif[Switch-Vlanif10]ipaddress.VLAN20301002002】(9[Switch]_(7)_satimc8:00to18:00working-[Switch]acl[Switch-acl-adv-3002]ruledenyipsource.55destinationtimc-rangesatime[Switch]acl[Switch-acl-adv-3003]ruledenyipsource.55destinationtimc-rangesatime[Switch]trafficclassifierc_market[Switch-classifier-c_market]_(9)_acl3002ACL[Switch]trafficclassifierc_rd[Switch-classifier-c_rd]if-matchacl3003ACL[Switch]_(10)_b_market[Switch-behavior-b_market]_(11)_[Switch]trafficbehaviorb_rd[Switch]_(12)_p_market[Switch-trafficpolicy-p_market]classifierc_marketbehavior[Switch]trafficpolicyp_rd[Switch-trafficpolicy-p_rd]classifierc_rdbehaviorb_rd[Switch-GigabitEthernet0/0/2]traffic-policyp_market_(14)_[Switch]interfaceGigabitEthernet2019/24。aclruledenyicmpsource55destination0VLAN101ACSwitchAGE0/0/8,地址为1】(4 (2)/02】(8 (5)允 3】(8 (10)1】86AP,A火墙、IDS/IPS、WAF、数据库审计、FC23228TRAIDRAID0,1,5,6,10IP-SAN和FC-SAN,而本题服务器和存储都连在同一交换机,且服务器没有1】(7.5(1) 2】(8 (9)源(或源3】(4.5(10) (12)IP-IP1】(6(1)Web服务 2】(6 【问题3】(4分 (9) 【问题4】(4分 (11)递 1(6(1)system-2(9(7)time-(9)if-(10)traffic(11)(12)traffic(14)(15)p-2019试题一、阅读以下说明,回答问题1至问题4,CellularInternetRouter1xDSL3G/LTECellularInternet。3G/LTECellular1】(24 B.以太 2】(26Router1DHCP[Huawei]dhcpenable[Huawei]interfacevlanif[Huawei-Vlanif123]dhcpselectglobal//(3)[Huawei-Vlanif123]quit[Huawei][Huawei-ip-pool-lan]gateway-[Huawei-ip-pool-lan]networkmask24[Huawei-ip-pool-lan]quit3】(16Router1NAT[Huawei]aclnumber[Huawei-acl-adv-3002]rule5permitipsource55[Huawei-acl-adv-3002]quit[Huawei]interfacevirtual-template10//(6)[Huawei-Virtual-Template10]ipaddressppp-negotiate[Huawei-Virtual-Template10]natoutbound(7)[Huawei-Virtual-Template10]quitATM[Huawei]interfaceatm[Huawei-Atm1/0/0]pvcvoip1/35//PVC(ATM[Huawei-atm-pvc-Atm1/0/0-1/35-voip]mappppvirtual-template10PVCPPPoA[Huawei-atm-pvc-Atm1/0/0-1/35-voip][Huawei-Atm1/0/0]standbyinterfacecellular0/0/0//(8)[Huawei-Atm1/0/0]quitAPN[Huawei]apnprofile3gprofile[Huawei-apn-profile-3gprofile]apnwcdma[Huawei-apn-profile-3gprofile]quit[Huawei]interfacecellular0/0/0[Huawei-Cellular0/0/0]modewcdma(9)/3G[Huawei-Cellular0/0/0]dialerenable-circularDCC[Huawei-Cellular0/0/0]apn-profile(10)3GCellularAPN[Huawei-Cellular0/0/0]shutdown[Huawei-Cellular0/0/0]undoshutdown[Huawei-Cellular0/0/0]quitDCC[Huawei]dialer-rule[Huawei-dialer-rule]dialer-rule1ippermit[Huawei-dialer-rule]quit[Huawei]interfacecellular0/0/0[Huawei-Cellular0/0/0]link-protocolppp[Huawei-Cellular0/0/0]ipaddressppp-negotiate[Huawei-Cellular0/0/0]dialer-group1[Huawei-Cellular0/0/0]dialertimeridle(11)[Huawei-Cellular0/0/0]dialernumber*99#[Huawei-Cellular0/0/0]natoutbound3002[Huawei-Cellular0/0/0]quit4】(24(12)备选答案:A. B. C. D.试题二、阅读以下说明,回答问题1至问题3,1】(162-2RAID(1),01RAID(2)12】(1.562-2RAID(7)2-3RAID(8)%。RAID(9)RAID读写的关系型数据库;图(10)RAID3】(28WebDDoS2-4段,该攻击为(11),针对该攻击行为,可部署(12)DDoS(分布式拒绝服务)攻击,可采用(13)、(14)WebA.跨站脚本攻 B.SQL注入攻 D.CC攻A.漏洞扫描系 B.堡垒 试题三、阅读以下说明,回答问题1至问题4,3-1WindowsServer2008R2IPSecWindowsServer2008R2IPSecAB1】(26IPSecSA(SecurityAssociation)。IKE(InternetKeyExchange)协议将协商工作分为两个阶段,第一阶段协商(1)SA(又称IKESA),新建一个安全的、经过身份验证的通信管道,之后在第二阶段中协商(2)SA(又称IPSecSA)后,便可以通过这个安全的信道来通信。使用(3)命令,可以查看协商结果。A. B.快 C.传 D.信(3)A.displayike B.displayipsecC.displayike D.displayike2】(24WindowsServer2008R2IPSecIPSec(4)、(5)以及进行4 B.创建IP安全策略 3】(26主机B(1)BA(2)14】(24试题四、阅读以下说明,回答问题1至问题3,1】(15<Huawei>(1)[Huawei]sysname(2)[RouterA](3)/IPv6[RouterA]interfaces0[RouterA-s0]ipaddress(4)[RouterA-s0]quit[RouterA]interfacegigabitethernet[RouterA-GigabitEthernet0/0/1](5)address2002::1/64[RouterA-GigabitEthernet0/0/1]quit2】(16[RouterA]interfacetunnel0/0/1//[RouterA-Tunnel0/0/1](7)ipv6-ipv4(8)/Tunnel[RouterA-Tunnel0/0/1]ipv6(9)[RouterA-Tunnel0/0/1]ipv6address::/96//(10)[RouterA-Tunnel0/0/1]sources0//(11)[RouterA-Tunnel0/0/1]3】(24(12)A.兼 20191】(1)(2)题干告诉:ADSLInternet3G/LTECellularInternetxDSL3G/LTEAC。4IPSecVPN【问题1】 3创建虚拟接口wcdma- 【问题4】(12) 13.加密传1012RAID10;RAID5【问题1】 (3)2或 【问题2】 (9)图2-2(10)图2-【问题3】(11)- 【问题1】(1)-(3) 【问题2】(4) (5)【问题3】 (8)任【问题4】(9) (10)把图3-5中的“接受不安全的通讯,但始终用IPSEC响应(C)”【问题1(1)system- 【问题2(6)创建隧道接 (7)tunnel- (8)auto- 指定tunnel接口的ipv6地 【问题3 2018试题一、阅读以下说明,回答问题1至问题3,1】(82[HUAWEI]sysnameSwitch3[Switch3]vlan[Switch3]interfaceGigabitEthernet0/0/3[Switch3-GigabitEthernet0/0/3]portlink-type(3)[Switch3-GigabitEthernet0/0/3]porttrunkallow-passvlan1020[Switch3-GigabitEthernet0/0/3]quit[Switch3]interfaceGigabitEthernet0/0/1[Switch3-GigabiEthernet0/0/1]portlink-type(4)[Switch3-GigabitEthernet0/0/1]portdefaultvlan10[Switch3-GigabitEthernet/0/1]quit[Switch3]stpbpdu-2】(82<HUAWEI>system-view[HUAWEI]sysnameSwitch1[Switchl]vlan[Switch1]interface[Switchl-GigabitEthernet0/0/1]portlink-typetrunk[Switchl-GigabitEthernet0/0/1]porttrunkallow-pass(6)[Switch1-GigabitEthernet0/0/1]quit[Switch1]interfaceVlanif[Switch1-Vlanif10]ipaddress24[Switch1-Vlanif10]quit[Switch1]interfaceVlanif[Switch1-Vlanif20]ipaddress24[Switch1-Vlanif20]quit[Switchl]interfaceGigabitEthernet[Switchl-GigabitEthernet0/0/7]portlink-type[Switch1-GigabitEthernet0/0/7]porttrunkallow-passvlan100[Switch1-GigabitEthernet0/0/7]quit[Switch1]interfaceVlanif100[Switch1-Vlanif100]ipaddress(7)[Switch1-Vlanif100]quit[Switch1]interfaceGigabitethernet[Switch1-GigabitEthernet0/0/5]portlink-typeaccess[Switch1-GigabitEthernet0/0/5]portdefaultvlan[Switchl-GigabitEthernet0/0/5]quit[Switch1interfaceVlanif300[Switchl-Vlanif300]ipaddress(8)[Switchl-Vlanif300]quit3】(42Switch1Router[Switchl]iproute-static(9)//默认优先级[Switchl]iproute-staticpreference70[Router]iproute-static(10)//默认优先级[Router]iproute-static[Router]iproute-static[Router]iproute-static[Router]iproute-static试题二、阅读下列说明,回答问题1至问题4,2-1为A,ADHCPIP/24,IP,IP;IP1】(42听、拒绝服务、病毒、木马、(1 C.违规外联控 2】(62 C.木 D.SQL注~(5)备选答案:A.源主机安装杀毒软件并查杀 C.将上图所示URL加入上网行为管理设备黑名单 3】(41AIPSECVPNAA2-3为A4】(6100试题三、阅读以下说明,回答问题1至问题3,1】(62。在使用租期过去(3)DHCPREQUEST备选答案:A.单播B.多播C.广播D.备选答案:A2DHCP服务器B.DHCPCDHCPD.IP备选答案 2】(51为(5),默认网关为(6)IP3-3IP址”处应填写(7)。通常无线子网的默认租约时间为(8)。备选答案:A.8 B.6 C.2 D.6或8小3】(42(9备选答案 试题四、阅读以下说明,回答问题1至问题3,。1】(131公司内部有两个网段,/24/24,SwitchBVLAN[SwitchB]acl[SwitchB-acl-adv-3000]rulepermitipsource55destination[SwitchB-acl-adv-3000]rulepermitipsource55destination[SwitchB-acl-adv-3000][SwitchB]acl3001///24[SwitchB-acl-adv-3001]rulepermitipsource(1)55[SwitchBacl-adv-3001]quit[SwitchB]acl3002///24网段的用户数据流[SwitchB-acl-adv-3002]rulepermitip(2)55[SwitchB-acl-adv-3002]quit[SwitchB]trafficclassifierc0operatoror[SwitchB-classifier-c0](3)acl3000[SwitchB-classifer-c0]quit[SwitchB]trafficclassifierc1(4)or[SwitchB-classifier-c1]if-matchacl3001[SwitchB-classifer-c1]quit[SwitchB]trafficclassifierc2operatoror[SwitchB-classifer-c2]if-matchacl(5)[SwitchB]trafficbehaviorb0[SwitchB-behavior-bO]quit[SwitchB]trafficbehaviorbl[SwitchB-behavior-b1]redirectip-nexthop(8)[SwitchB-behavior-b1]quit[SwitchB]trafficbehavior[SwitchB-behavior-b2]redirectip-nexthop(9)[SwitchB-behavior-b2]quit[SwitchB]trafficpolicy[SwitchB-trafficpolicy-p1]classifierc0behavior(10)[SwitchB-trafficpolicy-p1]classifierc1behavior(11)[SwitchB-trafficpolicy-p1]classifierc2behaviorb2[SwitchB-trafficpolicy-p1]quit[SwitchB][SwitchB-GigabitEthenet0/0/3]traffic-policypl(13)SwitchB-GigabitEthernet0/0/3]return2】(21ACL300014)3】(51公司需要访问IntermetNATISP1~;ISP2~。[SwitchB]nataddress-group0[SwitchB]nataddress-group1[SwitchB]aclnumber2000[SwitchB-acl-basic-2000]rule5(15)source55[SwitchB]aclnumber2001[SwitchB-acl-basic-2001]rule5permitsource55[SwitchB]interfaceGigabitEthernet0/0/3[SwitchB-GigabitEthernet0/0/3]natoutbound(16)addressgroup0no-pat[SwitchB-GigabitEthernnet0/0/3]natoutbound(17)addressgroup1no-pat[SwitchB-GigabitEthernet0/0/3]quit[SwitchB]iproute-static55(18)[SwitchB]iproute-static20181】(82system- 2】(82(5)1020100 (6)vlan10(7) (8)3】(42(9)(10)1】(1)BC,DA2(4)(5)49URL34:01】(42 2】(62 3】(41 1222DHCP31】(62 2】(51 3】(42 (1) (6) 2018试题一(201(102(41-11-11-1A(6)3(6detect-groupdetect-list1ipaddresstimerloopiproute-staticDialer0preferenceiproute-staticpreference60detect-group(10 备选答案 试题二(20【说明】2-1AP(无线访问接入点)供内部员1(6((2(3A.APACB.APD.AC、APE.AC2(4(4(5(6(7 A.检查传输介 C.重启交换 D.更换网络适配3(6(8(9用户安全认证,配置基于(13)RASIUSA.端口扫描B.非授权用户接入C.非法入侵D.sql备选答案:A.IEEE B.IEEE4(4(DAS(NAS(14(15试题三(20\h1(6(1;(2“IP(32(4(4DNS\h3-3示的图中做何操作?(53(2A.查找本地hosts文 D.使用NETBIOS名字解4(2(8 5(46(2(11A.增加网络带 B.在Web服务器上添加虚拟主 D.添加一台Web服务试题四(15和B:/2528/25。1(2(1(22(10部门ADHCP[Router](4)GigabitEthernet0/0/1[Router-interfaceGigabitEthernet0/0/1]ipaddress28[Router-interfaceGigabitEthernet0/0/1]dhcpselect(5)//接口工作在全局地址池模式[Router-interfaceGigabitEthernet0/0/1](6)[Router]ippool[Router-ip-pool-pool1]networkmask(7)[Router-ip-pool-pool1]excluded-ip-address(8)[Router-ip-pool-pool1](9)DNS[Router-ip-pool-pool1](10)[Router-ip-pool-pool1](11)day30hour0minute0[Router-ip-pool-pool1](12)[Router-ip-pool-pool1]部门BDHCP3(3IP/24,请根据描述,将下面的配置代码补充完整。[Router]nataddress-group0[Router]aclnumber2000[Router-acl-basic-2000]rule5(13)source55[Router-GigabitEthernet0/0/0]interfaceGigabitEthernet0/0/3[Router-GigabitEthernet0/0/1]nat(14)2000address-group0no-pat[Router-GigabitEthernet0/0/1]quit[Router]iproute-static20181(2)(3)核心交换机默认路由应该指向出口路由器,/0GE2/0/3,则应用于该出接口上;2IPIP,混合模式则为二者叠加。3(9)(10)根据路由配置,Dialer0ISP2100,ISP160,ISP1intelnet,ISP1ISP21 (5)2防火 3 34NAS。(IP-SAN)1(1)A 2 3 (12)IDS4NAS12IP3DNSNetBIOS4/5:重点命令要会,这两道题上午选择题也考过;1 2把域名转变为 34 5ipconfig (10)ipconfig612(3)system-(9)dns-gateway-(12)domain-32017试题一、阅读以下说明,回答问题1至问题4,1-11-1SSIDEmployee,SSIDVisitor。1(6NAT1-22(4(53(64(4(10试题二(20【说明】14,2-11(6(1(2D.135/137/139/445TCP2(82-1A.散 B.轮 IP/27,请将配置代码补充完整。ifcfg-emlDEVICE=emlDEFROUTE=yes3(4SQL(8)A.杀毒软 4(2试题三(20WindowsServer2008IP3-11(4(1)(2 D.远程访问/VPN服务B.Intranet2(4(4备选答案 备选答案 备选答案 3(8(7(8(9备选答案:A.周期性是更新模式B备选答案:A.RIPv1B.RIPv2C.RIPv2备选答案:ARIPv1B.RIPv2C.RIPv1v2D.忽略传入数据包(10备选答案:A.可以不同B.4(43-3(11(12(13(14网BA备选答案 备选答案 D.任试题四(151(5VLAN,VLANIP4-1IP2(10公司申请了14IP09-22,18-22作为服务器和接口地址保留,其他公网IP地址用于公司访问InternetPATPleaseconfiguretheloginpassword(maximumlength16):huawei[R1]int[R1-GigabitEthernet0/0/0]ipaddress4252[R1-acl-2000](11)5permitsource(12)[R1]nataddress-group1(13)17[R1]interrfaceGigabitEthemet0/0/1[R1-GigabitEthemet0/0/1]ipaddress(14)[R1-GigabitEthemet0/0/1](15)outbound2000address-group1[R1-rip-1]version[R1-rip-1]network2017目的地是/32,个人觉得写/24/322】IPSECVPNACLIP3】Switch1ACLVLAN99,源55,deny。4】trunk,APaccess,VLAN10【问题1】 2】IP【问题3】(6)VLAN 【问题4】 (10)2】linux(8(9)web4】FC-SAN1】(1)A(2)C(3)【问题2】(4)负载均衡设 (5) (6) (7)【问题3】(8) (9)4】(10)FC-1(1)(3(4)(5(6win73】RIPv1RIPv14】windowsACLAB,1】2】3】4】28IP90。1(1)92110052】(6)sysnameconsole0consolepasswordconsolequitaclruleACL550919R1IP2017141-11(1,设备②处部署A.入侵防御系统 B.交换 C.负载均2(4(5(4)~(5)A.双绞 B.同轴电 C.光31-141-1(8(9)1-1(10)设备可实现内部网络和外部网络之间的边界防护,依据访问规则,允许或者限制1312-1(3;(5(1)~(5) G.目的的IP地址H.源IP地 I.源端 J.目的端2(6(8(6)—(8)是备选项A.外部网 C.非军事3EWebTelnetWeb(2)禁止外网用户访问财务服务器,禁止财务部门访问Intemet,允许生产部门和行政部门访问Intemet。2-34(16) C.Web服务器将受到安全威胁 【说明】Windows1DC(DomainController),需要通过命令行方式运行(2)命令;(3DHCPDC(4,否则服务报错。备选答案 23-2hosts3-35)WEB 3-3https8000,URL33-4(8)在"驱动程序'选项卡中会显示驱动程序提供商、驱动程序日期、驱动程序版本和(9)信息。 图4-1为某学校网络拓扑图,运营商分配的公网IP地址为/29,运营商网关地址为DHCPDHCP3VLAN,VLAN10141,补齐(1)~(6WAN[Huawei]sysname(1)[Router]interface(2)[Router-GigabitEthernet1/0/0]ipaddress[Router-GigabitEthernet1/0/0]quit[Router]iproute-static0.0.0(4)[Router-acI-basic-2000]rule5permitsource10.0.0(5)[Router-acl-basic-2000]quit[Router]interfaceGigabitEthernet1/0/0[Router-GigabitEthernet1/0/0]natoutbound(6)[Router-GigabitEthernet1/0/0]quit24-1,7)~(10)GEO/0/2VLAN20,VLAN[Switch]inlterfaceGigabitEthernet0/0/2[Switch-GigabitEthernet0/0/2]portlink-type(7)[Switch-GigabitEthernet0/0/2]porthybridpvidvlan20[Switch-GigabitEthernet0/0/2]porthybriduntaggedvlan20[Switch]interfacevlanif20[Switch-Vlanif20]ipaddress(8)[Switch-Vlanif20]quitDHCP3[Switch]dhcp(9)[Switch]ippoolpooll[Switch-ip-pool-pooll]networkmask[Switch-ip-pool-pooll]dns-list[Switch-ip-pool-pooll]gateway-list[Switch-ip-pool-pooll]lesaeday(10)[Switch-ip-pool-pooll]quit[Switch]interfacevlanif20[Switch-Vlanif20]dhcpselectglobal[Switch-Vlanif20]quit2017(2【问题1 (2)A【问题2 3(6)目的(7)4(8)(9)IPS(10)1999扩展访问列表(100~199、2000-2699)两种:ACL:2000~2999可使用IPv4IP内部区域(内网外部区域(外网:指Internet非军事区(DMZ,又称停火区:是一个隔离的网络,或几个网络。位于区域内的主机或服务器被WeMail3ACLACL(permit)语句,意味着ACLPermit34【问题1 【问题2 (7)C3 2【问题1(1) (4)授2(5HostsIP(写清楚点,防止扣分)【问题3(8)更新驱动程序 1(9IPACL2000NAT2(6以太网端口的三种链路类型:Access、HybridAccess1VLAN,IPdhcpenableDHCPleaseday331(9(1)Router(2)GigabitEthernet (3) (5)552(6 (8)(9)enable//开启DHCP服 2016试题一(20分ERP1(4(12(43(44(35(36(2试题二(20分2-1CentOS(Linux,WebWindows20081(6(1(2(3(42(3RAID5RAID1RAID5RAID53(8(7,应采用 A.磁盘故 C.网卡故 A.更换磁 C.更换网 4(3((10(11E.WebG.VLAN试题三(20分某公司的IDC(互联网数据中心)服务器Server1采用WindowsServer2003操作系统,IP地址为28/24WebDNS\h、\h,company1上传文件和浏览目录。和对应的网站目录分别为company1-web、company2-webcompany3-web3-11(21(2 2(423(61company1(5,company2company31025(6)范围内任意选择,在访company2company3(7)符号连接。设置完成后,管理员3-4(8)。(8)备选答案:A.IP地址对应错误 B.未指明company1的端口号C.未指明company2的端口号 区域为三个网站域名分别添加(9)company2(104(82\h\h用了(11)3-6(14(14)备选答案:A.循环B.网络掩码排序试题四(151(101R1R1#configtR1(config)#interfaceFastEthernet0/0R1(config-if)#ipaddress(1(2)R1(config-if)#noshutdownR1(config-if)#exitR1(config)#ipR1(dhcp-config)#networkR1(dhcp-config)#default-router54R1(dhcp-config)#dns-server(4)R1(dhcp-config)#lease0(5)0R1(dhcp-config)#exitR1(config)#ipdhcppooldepart2network(6(7)R1(dhcp-config)#default-router54R1(dhcp-config)#dns-server53R1(dhcp-config)#lease0120R1(dhcp-config)#exitR1(config)#ipdhcpexcluded-address(8(9)R1(config)#ipdhcpexcluded-address(10)IPR1(config)#ipdhcpexcluded-address542(51S1S1#configterminalS1(config)#interfacevlanS1(config-if)#ipaddress54S1(config)#interfacevlanS1(config-if)#iphelper-address(11)DHCPS1(config)#interfacevlanS1(config)#interfacef0/24S1(config-if)#switchportmode(12)S1(config-if)#switchporttrunk(13)vlanallVLANS1(config)#interfacef0/21S1(config-if)#switchportmodeaccessS1(config-if)#switchportaccessvlan5S1(config)#interfacef0/22S1(config-if)#switchportmodeaccessS1(config-if)#switchportaccess(14)S1(config)#interfacef0/23S1(config-if)#switchportmodeaccessS1(config-if)#switchport2016IP(1) (3) 1】(1.56(1(2(3(4)NFS,WebCIFS。RAID150%,RAID5(N-1)采用RAID5RAID5【问题1(1)FC (2)IP 3】(28 4(13 1 23)运行脚本3 \h411)启用循环(12)(13)1 (4)53(5)12 (7)(8) 2 20161(142(24)AR2220[AR2220]acl2000[AR2220-acl-2000]rulenormalpermitsource55[AR2220-acl-2000]rulenormaldenysourceany[AR2220-acl-2000][AR2220]interface[AR2220-Ethernet0]ipaddress[AR2220-Ethernet0]quit[AR2220]interface[AR2220-Ethernet1]ipaddress00[AR2220-Ethernet1]natoutbound2000interface[AR2220-Ethernet1][AR2220]iproute-static(63(26ftphttp1JavaAppletsUSG3000[USG3000]aclnumber[USG3000-acl-adv-3000]rulepermittcpdestination-porteqwww[USG3000-acl-adv-3000]rulepermittcpdestination-porteqftp[USG3000-acl-adv-3000]rulepermittcpdestination-porteqftp-data[USG3000]aclnumber2010[USG3000-acl-basic-2010]rule(7)source.0[USG3000-acl-basic-2010]rulepermitsourceany[USG3000](8)interzonetrustuntrust[USG3000-interzone-tust-untrust]packet-filter3000(9)[USG3000-interzone-tust-untrust]detectftp[USG3000-interzone-tust-untrust]detect[USG3000-interzone-tust-untrust]detectjava-blocking 4(261-Evlaninterfacevlanif300ipaddress(10)interfacevlanif1000ipaddressEripnetworkEtrunkintportlink-typetrunk//(12)porttrunkpermitvlanall1常用的IP访问控制列表有两种,它们是编号为(1)和1300~1999的标准访问控制列表和编为(2)和2000~2699的扩展访问控制列表、其中,标准访问控制列表是根据IP报的(3)来对IP报文进(4(52(110ACLACLR1(config)#access-list1(8(9)55R1(config)#access-Iist1denyR1(config)#access-list1deny55R1(config)#access-Iist1deny(10)55R1(config)#interface(11)R1(config-if)#ipaccess-group1ACLInterntRoute-Switch(config)#time-rangejspRoute-Switch(config-time-range)#periodicdaily(13)Route-Switch(config)#time-rangexsssq//定义学生宿舍区时间范围Route-Switch(config-time-range)#periodic(14)18:00t024:00Route-Switch(config-time-range)#exitRoute-Switch(config)#access-list100permitip55Route-Switch(config)#access-list100permitip55anyRoute-Switch(config)#access-list100denyip(15)55time-rangejspRoute-Switch(config)#access-list100denyip(16)55time-rangexsssqRoute-Switch(config)#interface(17)Route-Switch(config-if)#ipaccess-group1003(13Route-Switch(config)#ipaccess-listextendedRoute-Switch(config-ext-nacl)#permitipany55reflectjsp//(18)Route-Switch(config-ext-nacl)#exitRoute-Switch(config)#ipaccess-listextendedoutfilterRoute-Switch(config-ext-nacl)#evaluatejsp//(19)Route-Switch(config-ext-nacl)#exitRoute-Switch(config)#interfacefastethernet0/1Route-Switch(config-if)#ipaccess-groupinfilterinRoute-Switch(config-if)#ipaccess-groupoutfilteroutWindowsServer2003DHCP、DNSWEB1(14DHCP~30,其中02(1.59DNS3-43-4(。A.XACHINA-1DC0B33IP14()B.该域名服务器无法解析的域名转发到14C.DNS()

(D.DNSDNS(E.(F.(3(24Web3-53-3-5\h\h网站配置是(()备选答案:相同的IP地址,不同的端口号 B.不同的IP地址,相同的目录C.相同的IP地址,不同的目录 2.除了主机头方式,还可以采用()方式在一台服务器上配置多网站。4(13WindowsServer20033-63-6(,设备打“x”的含义是(3-61394?(3-1(111R1NAPTR1>enableR1#configR1(config)#interfacefastethernetR1(config-if)#ipaddress52R1(config-if)#noshutdownRl(config-if)#R1(config)#interfacefastethernetR1(config-if)#ipaddress52R1(config-if)#noshutdownR1(config-if)#R1(config)#interfacefastethernetR1(config-if)#ipaddress()R1(config-if)#noshutdownR1(config-if)#exitR1(config)#interfaceserial0R1(config-if)#ipaddress48R1(config-if)#noshutdownR1(corffig)#ipnatpoolss()netmask(R1(corffig)#interface()fastethernet0/0-1R1(config-if)#ipnat()R1(config-if)#interfaceserial0R1(config-if)#ipnat()R1(config-if)#exitR1(config)#access-list1permit()R1(config)#ipnatinside()list()pool(()2(24R1、R2R3OSPFR1、R2R3行号配置代码R1(config)#routerospfR1(config-router)#network55areaRl(config-router)#networkareaRl(config-router)#networkareaR2>R2#configR2(config)#routerospfR2(config-router)#netvrork55areaR2(config-router)#network55area0R2(config-router)#network00.0.3area11R3>12R3#config13R3(config)#routerospf14R3(config-router)#netvrork192168.0.800.0.3area15R3(config-router)#networkareaR1R2pingR3(A.在R3上未宣告局域网路由 B.以上配置中第7行和第13行配置错误C.第1行配置错误 D.R1、R2未宣告直连路由(()Rl#default-informatonoriginateB.R1(config-if)#default-informationoriginateC.R1(config-router)#default-informationoriginateD.Rl(config)#default-informationoriginate2016【问题1 【问题2(5)Ethernet 【问题3 4(10)(11)(12)E0/1TRUNKACL:2000~2999IPv4IPACL:3000~3999既可使用IPv4IP【问题1(1)1- (4)源地(5)目的地 【问题2 (13)8:00to18:00(14)daily 312(5)错(6)对(7)对(8)错(9)对(10)3454题目给出了网段/22计算出此网址的最后一个能用的ip地址是(3)48(4)range//1-22(5)inside:ipnatinside,ipnatoutsidebluegarden,ipnatinsidesourcelist*pool*(11)overload20151(4互联;网络,而前端网络则负责正常的(4)传输。A.iSCSIB.TCP/IPC.以太网技术E.文件服务器F.光纤通道技术G.视频管理子系统H.2(43(6VLAN(5)VLAN(6)trunkVLANManageVLANOLTOLTIP(7)方式分配,IPC4(6(8) B.IP组 C.IP任意备选答案 (10) C.EPON系统管 (VLAN1(VLAN2(VLAN3(VLAN4(VLAN5(VLAN61(7访问控制列表ACLACL(1)技术来达到访问控制目的。ACL分为标准ACL和扩展ACL两种,标准访问控制列表的编号为(2)和1300~1999之间的数字,标准访问控制列表只使用(3)进行过滤,扩展的ACL的编号使用2000~2699每一个正确的访问列表都至少应该有一条(5)语句,具有严格限制条件的语句应放在访问列表所(6ACL,在靠近(7)的网络接口上设置标准AC。2(5网管要求除了主机6telnettehet(0((1:1521IP33(4该企业要求在上班时间内(9:00-18:00)禁止内部员工浏览网页(TCP80TCP443,禁止使TCP8080、TCP3128TCP10804(4Vlan(或解释)以下配置命令。WindowsServer2003Web、FTP1(4Web3-13-2(1(1)(22(43-1()D.CGI(6)3(6FTP3-3(7,FTP 4(6(12( B.发 D.转 C.安装POP3组件 4-1/241(22(93(2Commandrejected:Aninterfacewhosetrunkencapsulationis"Auto"cannotbeconfigured"trunk"(12)A.noshutdown4(2(132015SAN(StorageAreaNetwork)存储区域网络,是一种高速的、专门用于存储操作的网络,通常独立于计算机局域网(LAN)。SANSANSAN2】EPON(EthernetPassiveOpticalNetwork,以太网无源光网络)PONPON一般应用在以太网电缆无法覆盖、必须使用光纤来延长传输距离的实际网络环境中,且通常定位于宽41(1)H(2)F(3)C23(5)ONU(6)OLT(7)4(8)B(9)B1(1)对数据包进行过滤(2)1-99(3)源地址(4)100-允许(6)源端(7)【问题2 (11)33(13)9:00interfacevlan3VLAN34(17)vlan4(18)55(19)vlan5(20)vlan6(19(20)WindowsIIS4】MX(MailExchanger)记录是邮件交换记录,它指向一个邮件服务器,用于电子邮件系统发邮件时根据收信人的地址后缀来定位邮件服务器。例如,当Internet上的某用户要发一封信给\hMX1(1)B(2)ODBC2(3)错(4)对(5)对(6)3(7)相同(8)多个4(10)MX(11)A(12)A、C、RIPv24VLANSVI(SwitchVisualInterface)1(1)542(3)configterminal(4)S1vlan10(7)49 3420151(4(1;(2(3(4 B.监视针对DMZ中系统的攻击 2(4(6)3(4(7(8)备选答案:A. 4(6(10(11(10(11)备选答案:A.MasterB.BackupC.VTPServer5(2Switch1Switch1(config)#interfacevlan20Switch1(corifig-if)#ipaddress53Switch1(config-if)#standby2ip50Switch1(config-if)#standby2preemptSwitch1(config-iD#exit(12VLAN20preempt(13址段/24。采用一台Linux服务器作为接入服务器,服务器内部局域网接口地址为54,ISP2。1(2认准淘宝旺旺ID:认准淘宝旺旺ID:(12(8IP53,MAC01:A8:71:8C:9A:BB;IP52,MAC01:15:71:8C:77:BC4为方便管理,公司使用DHCP服务器为客户机动态配置IP地址,下面是Linux服务器为92/26DHCP{optionrouters54;optionsubnet-mask(4;address(5;optiontime-offset-18000;range(6(7;default-lease-time21600;max-lease-time43200;hostserversethemet(8;fixed-hardwareethemet01:15:71:8C:77:BC;fixed-address(9}3(2配置代码中“optiontime-offset-18000”的含义是(10)default-lease-time21600 4(3(122-(12)DHCPIP8D.DHCPIP8WindowsServer2003FTPDHCP1(8(1(1)备选答案:A. C. D.Intemet3-1Web“ActiveServerPages(2(2)InternetWebURL(3)(2\h \h Intemet6(42(8FTP3-23-3(5(6(7(83(4DHCP3-43-53-4IP(9)

温馨提示

  • 1. 本站所有资源如无特殊说明,都需要本地电脑安装OFFICE2007和PDF阅读器。图纸软件为CAD,CAXA,PROE,UG,SolidWorks等.压缩文件请下载最新的WinRAR软件解压。
  • 2. 本站的文档不包含任何第三方提供的附件图纸等,如果需要附件,请联系上传者。文件的所有权益归上传用户所有。
  • 3. 本站RAR压缩包中若带图纸,网页内容里面会有图纸预览,若没有图纸预览就没有图纸。
  • 4. 未经权益所有人同意不得将文件中的内容挪作商业或盈利用途。
  • 5. 人人文库网仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对用户上传分享的文档内容本身不做任何修改或编辑,并不能对任何下载内容负责。
  • 6. 下载文件中如有侵权或不适当内容,请与我们联系,我们立即纠正。
  • 7. 本站不保证下载资源的准确性、安全性和完整性, 同时也不承担用户因使用这些下载资源对自己和他人造成任何形式的伤害或损失。

评论

0/150

提交评论