-->

whaust

2020年11月19日 星期四

Cisco CCNA命令大全

 

登錄網路設備,USB-COM-COM-RJ45,超級終端/SecureCRT

Would you like to enter the initial configuration dialog? [yes/no]: //回答no,如果回答了yes,會出現大量對話,Ctrl+C中斷對話
% Please answer 'yes' or 'no'.
Router> //使用者模式,只能簡單的show及ping/tracer
Router>enable //從使用者模式進入特權模式
Router# //特權模式,能夠進行所有的show及ping/tracer
Router#configure terminal//從特權模式進入全域配置模式
Router(config)# //全域配置模式,可以進行相關配置
Router(config)#hostname R1//給設備命名
R1#show version //查看設備軟硬體版本資訊,開機時間,記憶體和Flash大小,模組等
R1#show ip interface brief //查看介面資訊
R1#show running-config //查看運行在記憶體中的當前配置
R1#show startup-config //查看開機配置,保存在NVRAM
R1#copy running-config startup-config //將當前運行配置保存到開機配置中
R1#show tech-support //查看設備所有軟硬體的詳細資訊
R1(config)#enable password xxx//配置enable密碼,該密碼show run可見
R1(config)#enable secret xxx //配置enable密碼,該密碼show run不可見,兩個同時配置時,secret密碼生效
R1(config)#line vty 0 4 //進入telnet配置模式
R1(config-line)#login //telnet登陸需要密碼驗證
R1(config-line)#password xxx //配置telnet密碼
R1(config-line)#exit
R1(config)#line vty 0 4 
R1(config-line)#no login //telnet登陸不需要驗證
R1(config-line)#exit 
R1(config)#line vty 0 4
R1(config-line)#login local//telnet登陸需要在本地資料庫查找用戶名密碼進行驗證
R1(config-line)#exit
R1(config)#username spoto password xxx //創建本地用戶名密碼
R1(config)#banner ^!!!!R1!!!!!^ //配置設備登陸提示符,頭尾符號需要一致,中間為提示符內容
R1(config)#line vty 0 4
R1(config-line)#privilege level 15//配置telnet使用者特權等級為15,即登陸後直接進入enable模式
R1(config-line)#exit 
R1(config)#interface fastEthernet x/x //進入介面配置模式
R1(config-if)#ip address x.x.x.x x.x.x.x //配置IP及遮罩
R1(config-if)#no shutdown //打開介面,路由器介面預設處於管理性關閉狀態
R1(config-if)#exit //退出介面配置模式,返回全域配置模式
R1(config)#no ip routing //關閉路由功能,將路由器模擬成PC
R1(config)#ip default-gateway x.x.x.x //配置閘道位址
R1#show ip route //查看關閉路由功能後的閘道配置
R1#show cdp neighbors //查看思科互連設備資訊
R1(config)#interface loopback 0 //創建環回介面0,用於類比網段和測試
R1(config-if)#ip address x.x.x.x x.x.x.x//配置環回介面IP及遮罩,環回介面不需要no shutdown
R1(config-if)#exit
R1(config)#ip route x.x.x.x x.x.x.x x.x.x.x //配置使用下一跳位址的靜態路由
R1(config)#ip route x.x.x.x x.x.x.x fastEthernet x/x //配置使用本地出介面的靜態路由
R1(config)#ip route 0.0.0.0 0.0.0.0 x.x.x.x //配置使用下一跳位址的默認路由
R1(config)#ip route 0.0.0.0 0.0.0.0 fastEthernet x/x //配置使用本地出介面的預設路由
R1#show ip route //查看路由表
R1#ping x.x.x.x //使用出介面作為源IP的普通ping
R1#ping x.x.x.x source x.x.x.x //使用指定源位址的擴展ping
R1#debug ip icmp //打開ping的調試過程顯示
R1#undebug ip icmp //關閉ping的調試過程顯示
R1#traceroute x.x.x.x //路徑跟蹤,查看到達目的地所經過的IP
R1(config)#router rip //運行RIP協定,進入RIP協定配置模式
R1(config-router)#version 2 //配置RIP為版本2
R1(config-router)#no auto-summary//關閉自動匯總功能
R1(config-router)#network x.x.x.x //將相關網段發佈到RIP進程中,所有相關子網都會被發佈,命令配置不支援帶遮罩
R1(config-router)#exit //退出RIP協定配置模式
R1(config)#router eigrp x //運行EIGRP,配置EIGRP AS號碼,相鄰設備的AS號碼要求一致
R1(config-router)#no auto-summary//關閉自動匯總功能
R1(config-router)#network x.x.x.x //將相關網段發佈到EIGRP進程中,所有相關子網都會被發佈
R1(config-router)#network x.x.x.x x.x.x.x //將相關網段精確發佈到EIGRP進程中,命令配置支援帶反遮罩
R1(config-router)#exit //退出EIGRP協定配置模式
R1#show ip eigrp neighbors//查看EIGRP鄰居表
R1#show ip eigrp topology //查看EIGRP拓撲表
R1(config)#router ospf x //運行OSPF,配置OSPF本地進程號,該號碼僅有本地意義
R1(config-router)#network x.x.x.x x.x.x.x area x //相關網段精確發佈到OSPF區域中,命令配置要求帶反遮罩,相鄰設備區域號要相同
R1(config-router)#auto-cost reference-bandwidth x //修改參考頻寬,單位是兆
R1(config-router)#exit //退出OSPF協定配置模式
R1#show ip ospf neighbor //查看OSPF鄰居表
R1#show ip ospf database //查看OSPF拓撲表
R1#show ip ospf interface //查看OSPF介面狀態資訊,包括RID、網路類型、hello時間等
在C3640上載入NM-16ESW模組來對比交換機。如果是類比2層交換機,需要關閉路由功能。
Switch#vlan database //進入VLAN資料庫模式
Switch(vlan)#vlan x //創建VLAN,刪除時前面加no
Switch(vlan)#exit
Switch#show vlan-switch //查看VLAN表及所屬埠,真實設備或IOU模擬器上的命令為show vlan
Switch#show vtp status //查看VTP資訊,包括功能變數名稱、版本、模式等
Switch(config)#int fastEthernet x/x
Switch(config-if)#switchport mode access //配置埠模式為access
Switch(config-if)#switchport access vlan 10 //將該埠劃入VLAN10,默認所有埠屬於VLAN1
Switch(config-if)#exit
Switch(config)#int fastEthernet x/x //進入單臂路由主介面
Switch(config-if)#switchport trunk encapsulation dot1q //指定trunk封裝使用802.1Q,當交換機支援802.1Q和ISL時使用
Switch(config-if)#switchport mode trunk //配置埠模式為trunk
Switch(config-if)#exit
Switch#show interfaces trunk //查看交換機trunk介面資訊及狀態
Switch(config)#interface vlan x //進入管理IP所在的介面
Switch(config-if)#ip address x.x.x.x x.x.x.x //配置交換機的管理IP
Switch(config-if)#exit
Switch(config)#ip default-gateway x.x.x.x //配置交換機的閘道位址,實現跨網段遠端系統管理
R1(config)#interface fastEthernet x/x
R1(config-if)#no shutdown //單臂路由配置,只需要主介面開啟,子介面會自動繼承開啟
R1(config-if)#exit
R1(config)#interface fastEthernet x/x.x //進入子介面配置模式
R1(config-subif)#encapsulation dot1Q x //配置封裝為802.1Q,並指定該子介面所對應的VLAN
R1(config-subif)#ip address x.x.x.x x.x.x.x //配置該VLAN的閘道位址
R1(config-subif)#exit
R1(config)#access-list x permit x.x.x.x //允許來自某台主機的流量
R1(config)#access-list x permit x.x.x.x x.x.x.x //允許來自某個網段的流量
R1(config)#access-list x deny any //標準ACL的默認操作是拒絕所有流量
R1(config)#interface fastEthernet x/x 
R1(config-if)#ip access-group x in //將CAL應用在介面的入方向
R1(config-if)#ip access-group x out //將ACL應用在介面的出方向
R1(config-if)#exit
R1(config)#line vty 0 4
R1(config-line)#access-class 1 in //telnet遠端控制,有在ACL中被允許的主機能遠端telnet到本機。
R1(config-line)#exit
R1(config)#access-list 100 permit ip x.x.x.x x.x.x.x x.x.x.x x.x.x.x //允許某個網段到某個網段的流量通過
R1(config)#access-list 100 permit ip host x.x.x.x host x.x.x.x //允許某台主機到某台主機的流量通過
R1(config)#access-list 100 permit ip any any //允許任何IP流量通過
R1(config)#access-list 100 permit tcp any any eq x //允許某種TCP流量通過
R1(config)#access-list 100 permit udp any any eq x //允許某種UDP流量通過
R1(config)#access-list 100 permit icmp any any //允許ping包通過
R1(config)#access-list 100 deny ip any any //擴展ACL的默認操作是拒絕所有流量
R1#show access-lists //查看ACL內容及匹配情況
R1(config)#interface fastEthernet x/x
R1(config-if)#ip nat inside //指定介面為NAT的inside端
R1(config)#interface fastEthernet x/x
R1(config-if)#ip nat outside //指定介面為NAT的outside端
R1(config)#ip nat inside source list 1 interface fastEthernet x/x overload//配置基於出介面的PAT
R1(config)#access-list 1 permit any //允許任何IP作為NAT的源位址
R1(config)#ip nat inside source static x.x.x.x x.x.x.x //配置靜態NAT
R1(config)#ip nat pool spoto x.x.x.x x.x.x.x netmask 255.255.255.0 //配置NAT的位址集區
R1(config)#ip nat inside source list 1 pool spoto overload //配置基於位址集區的PAT
R1(config)#ip nat inside source static tcp x.x.x.x x interface FastEthernetx/x x //配置靜態埠映射
R1#show ip nat translations //查看NAT轉換表
R1#clear ip nat translation * //清除NAT轉換表,靜態條目不會被刪除
R1-S/C(config)#int serial x/x
R1-S/C(config-if)#clock rate 64000
R1-S/C(config-if)#encapsulation ppp //將介面封裝從預設的HDLC改為PPP封裝
PAP認證配置,認證伺服器端:
R1-S(config)#username xxx password xxx //在認證伺服器端配置本地用戶名密碼
R1-S(config-if)#ppp authentication pap //在認證伺服器端開啟pap認證要求
PAP認證配置,認證用戶端:
R1-C(config-if)#ppp pap sent-username xxx password xxx //在認證用戶端配置pap發送的用戶名和密碼
CHAP認證配置,認證伺服器端:
R1-S(config)#username xxx password xxx //在認證伺服器端配置本地用戶名密碼
R1-S(config-if)#ppp authentication chap //在認證伺服器端開啟chap認證要求
CHAP認證配置,認證用戶端:
R1-C(config-if)#ppp chap hostname xxx //在認證用戶端配置chap發送的用戶名
R1-C(config-if)#ppp chap password xxx //在認證用戶端配置chap發送的密碼
FRSW(config)#frame-relay switching //將路由器類比成框架轉送交換機
FRSW(config)#int serial x/x
FRSW(config-if)#clock rate 64000
FRSW(config-if)#encapsulation frame-relay //將介面封裝從預設的HDLC改為框架轉送封裝
FRSW(config-if)#frame-relay intf-type dce //指定框架轉送交換機介面類別型為DCE
FRSW(config-if)#frame-relay route xxx interface serial x/x xxx //配置框架轉送交換路徑
FRSW(config-if)#exit
FRR(config)#int serial x/x
FRR(config-if)#encapsulation frame-relay //配置框架轉送路由器介面封裝從預設的HDLC改為FR
FRR(config-if)#ip address x.x.x.x x.x.x.x
FRR(config-if)#frame-relay map ip x.x.x.x x broadcast//靜態配置IP到DLCI的映射關係,指定對端IP及本端使用的DLCI值
FRR(config-if)#exit
FRR#show frame-relay map //查看框架轉送映射表
FRR(config)#int serial x/x
FRR(config-if)#ip ospf network point-to-multipoint //框架轉送下OSPF預設模式是NBMA,無法自動建立鄰居。手動修改網路類型為PTMP或PTP
FRR(config-if)#exit

CCNA關鍵知識:
網路模型、IP&VLSM
靜態路由&預設路由
動態路由RIPv2、EIGRP、OSPF
VLAN、Access、Trunk、VTP、STP、單臂路由、2層交換機遠端系統管理
ACL、NAT
WAN、PPP、
IPv6、WLAN


2020年11月17日 星期二

Palo Alto PSE-Strata

 1) Which two profile types can block a C2 channel? (Choose two.)

a) Anti-Spyware

b) Certification

c) Command and Control

d) Decryption

e) URL Filtering


2) Which Prisma product can secure user network traffic against potential threats?

a) Next Generation Firewall

b) Security Subscriptions

c) Panorama

d) SD-WAN

3) Which Prisma product detects zero-day malware protection?

a) Next Generation Firewall

b) Security Subscriptions

c) Panorama

d) SD-WAN


4) Which Prisma products implements and manages software-defined networking?

a) Next Generation Firewall

b) Security Subscriptions

c) Panorama

d) SD-WAN


5) Which Palo Alto Networks product directly protects corporate laptops people use at work?

a) Strata next-generation firewall

b) Cortex XSOAR

c) Panorama

d) WildFire


6) Which NGFW feature detects zero-day malware?

a) GlobalProtect

b) WildFire

c) URL Filtering

d) Antivirus Security Profile


7) Which two steps are essential parts of the PPA process? (Choose two.)

a) a structured interview with the customer about their security prevention capabilities

b) upload of a file generated by the customer’s firewall capturing the threats they are facing

c) a report to the customer about how to improve their security posture

d) a discussion about expectations of threat prevention in a proof-of-concept

e) a head-to-head comparison of NGFW detected threats vs their current solution(s).

8) Which report provides compelling evidence for existing security gaps for Prospects?

a) BPA

b) PPA

c) BPA Heatmap

d) SLR

9) Which Panorama deployment mode collects forwarded log events without firewall management capability?

a) Panorama mode

b) Legacy mode

c) Management only mode

d) Log collector mode


10) Which deployment mode is supported only by a virtual Panorama?

e) Panorama mode

f) Legacy mode

g) Management only mode

h) Log collector mode

11) Which of the following determines Dynamic user group membership?

i) Security subscription feeds

j) XML API

k) group type

l) tags

12) Which of the following security profiles provides protection against documents containing zero-day malware?

a) Antivirus

b) Anti-spyware

c) Vulnerability protection

d) URL filtering

e) File blocking

f) Wildfire Analysis

g) Data filtering

13) Which of the following security profiles provides protection against a web connection to a known command and control site? (Choose two.)

a) Antivirus

b) Anti-spyware

c) Vulnerability protection

d) URL filtering

e) File blocking

f) Wildfire Analysis

g) Data filtering

14) Which of the following security profiles provides protection against transferring documents containing credit card numbers?

a) Antivirus

b) Anti-spyware

c) Vulnerability protection

d) URL filtering

e) File blocking

f) Wildfire Analysis

g) Data filtering

15) Which of the following security profiles provides control for the types of web sites a user can access?

a) Antivirus

b) Anti-spyware

c) Vulnerability protection

d) URL filtering

e) File blocking

f) Wildfire Analysis

g) Data filtering

16) Which technology identifies potentially infected hosts by correlating user and network activity data in Threat, URL, and Data Filtering logs?

a) Botnet report

b) Correlation object

c) DNS security

d) Autofocus

e) DNS Sinkhole

17) Which of the following processing tasks shows an advantage of a file proxy engine over a stream-based single-pass engine?

e) mapping IP addresses to users

a) using protocol decoders, decryption, and heuristics to identify applications

b) blocking data sent over traditional email protocols

c) scanning traffic for vulnerability exploits, viruses, and spyware

18) Real-time threat signatures used by the Strata firewall are generated by what service?

a) WildFire

b) AutoFocus

c) Expedition

d) Prisma Access


19) If a customer is interested in software-defined networking integrating with security services appropriately for specific use-cases, which reference architecture would be your best reference?

a) Public Cloud

b) Secure Access Service Edge

c) Security Operations

d) Private Data Center

e) Zero Trust

f) Automation


20) Which interface mode do you use to generate the Stats Dump file that can be converted into an SLR? Assume that you want to make the evaluation as non-intrusive as possible.

a) tap

b) virtual wire

c) Layer 2

d) Layer 3


21) Which two success tools are most appropriate for a prospective customer that is using a competitor’s offerings but has no security prevention strategy? (Choose two.)

a) Expedition

b) Prevention Posture Assessment

c) Security Lifecycle Review

d) Best Practice Assessment with Heatmaps

e) Data Center Segmentation Strategy Analyzer

22) Which file types are not supported as an upload sample for file upload by WildFire from the wildfire.paloaltonetworks.com/wildfire/upload page?

a) iOS applications

b) Android applications

c) Windows applications

d) Microsoft Excel files


23) Which kind of attack cannot be stopped by the Palo Alto Networks Security Operating Platform?

a) attacks through SaaS applications, such as exfiltration through Box

b) attacks that do not cross the firewall, regardless of source or destination

c) attacks based on social engineering that mimic normal user behavior

d) denial-of-service attacks from a trusted source

e) intrazone attacks, regardless of source or destination

24) WildFire functionality is like that of a sandbox. Is the statement an accurate description?

a) Yes, WildFire functionality is exactly that of a virtual sandbox in the cloud, provided to test files that customers upload or download.

b) No, WildFire does not supply sandbox functionality, although it competes with products that do.

c) No, WildFire provides dynamic analysis, machine learning, and other techniques along with sandbox functionality.

d) Yes, WildFire provides all its functionality as part of its virtual-physical hybrid sandbox environment

25) Which option is an example of how the next-generation firewall can provide visibility and enforcement around SaaS applications?

a) Through partnership with SaaS application vendors, special virtual firewalls that support a subset of full firewall functionality are used inside the SaaS applications themselves.

b) A built-in default security rule in the firewall blocks dangerous SaaS applications based on an automatically updated database of dangerous SaaS applications.

c) Built-in default functionality in the firewall sends all files sent or received by SaaS applications to WildFire.

d) The firewall can filter SaaS applications based on whether they comply with industry certifications such as SOC1, HIPAA, and FINRAA.

26) When a cloud deployment is secured, which role does the next-generation firewall play?

a) A member of the VM-Series is attached to each VM in the cloud environment, to stop malware, exploits, and ransomware before they can compromise the virtual systems they are attached to.

b) The NGFW exports its Security policy through Panorama, which in turn distributes that policy to the cloud based Prisma SaaS service that enforces the NGFW Security policy against each VM used in the cloud environment.

c) The NGFW exports its Security policy to WildFire, which lives in the cloud and enforces the NGFW Security policy throughout the cloud environment.

d) The NGFW is used to consistently control access to applications and data based on user credentials and traffic payload content for private or public cloud, internet, data center, or SaaS applications.

27) Which dedicated High Availability port is used for which plane in HA Pairs?

a) HA1 for the data plane, HA2 for the management plane

b) HA1 for the management plane, HA2 for the data plane

c) MGT for the management plane; HA2 as a backup

d) HA1 for the management plane, HA2 for the data plane in the PA-7000 Series

28) Which value should be used as a typical log entry size if no other information is available about log sizes?

a) 0.5KB

b) 0.5MB

c) 0.5GB

d) 0.5TB

29) Which feature is not supported in active/active (A/A) mode?

a) IPsec tunneling

b) DHCP client

c) link aggregation

d) configuration synchronization

30) Which two updates should be scheduled to occur once a day? (Choose two.)

a) Antivirus

b) PAN-DB URL Filtering

c) WildFire

d) Applications and Threats

e) SMS channel


31) What does the phrase “Prisma Access extends security to remote network locations and mobile users” mean in the context of the security that firewalls provide to a network?

a) Prisma Access independently provides the same type of protection as the firewalls, rebuilt for the various infrastructures used for remote network locations and mobile users.

b) Prisma Access independently provides the exact same protection as the firewalls, rebuilt for the various infrastructures used for remote network locations and mobile users.

c) Prisma Access securely routes traffic for remote network locations and mobile users through the same PAN-OS based firewalls used to protect the network.

d) Prisma Access leverages native cloud security and other security infrastructure to provide security to remote network locations and mobile users.

32) A customer’s interest in prevention, detection and response for Security Operations is best addressed by which reference architecture?

a) Public Cloud

b) Secure Access Service Edge

c) Security Operations

d) Private Data Center

e) Zero Trust

f) Automation


33) Which security posture is most likely to stop unknown attacks?

a) allow all the traffic that is not explicitly denied

b) deny all the traffic that is not explicitly allowed

c) deny all the traffic that is not explicitly allowed from the outside, and allow all the traffic that is not explicitly denied from the inside

d) deny all the traffic that is not explicitly allowed from the inside, and allow all the traffic that is not explicitly denied from the outside


34) Which profile type is used to protect against most protocol-based attacks?

a) Antivirus

b) URL Filtering

c) Vulnerability Protection

d) Anti-Spyware


35) How does an administrator specify in the firewall that certain credentials should not be sent to certain URLs?

a) with a URL Filtering Profile

b) with User-ID

c) with App-ID

d) with a Credential Theft Profile


36) Which SD-WAN configuration element contains data used to trigger a new path selection based on excessive latency?

a) SD-WAN Interface Profile

b) SD-WAN Interface

c) Path Quality Profile

d) Traffic Distribution Profile


37) Which Panorama screen provides an overall status display of SD-WAN Errors and their impacts?

a) SD-WAN Traffic Characteristics

b) SD-WAN Link Characteristics

c) SD-WAN Monitoring

d) SD-WAN Impacted Clusters

38) In Panorama, which policy gets evaluated first?

a) device group pre-rules

b) device group post-rules

c) shared pre-rules

d) shared post-rules

e) local firewall rules

39) Can the same rule allow traffic from different sources on different firewalls?

a) No, rules mean the same on all firewalls that receive the same policy.

b) No, because device groups are pushed from Panorama to all firewalls.

c) Yes, because different firewalls can have different zone definitions.

d) Yes, because there could be clauses in a rule with effects limited to a specific device group.

40) Which is not an advantage of using Panorama?

a) centralized management

b) higher throughput on the firewalls

c) centralized view of collected logs

d) automatic event correlation

41) How is the Cortex Data Lake integration with Panorama facilitated?

a) No integration is necessary; data flows from Panorama to the Cortex data lake and vice versa.

b) A Panorama plugin is installed in the Cortex Data Lake.

c) A Cloud Services plugin is installed in Panorama.

d) Agents run in both the Cortex Data Lake and Panorama.

42) What is the maximum number of servers supported by a single User-ID agent?

a) 10

b) 50

c) 100

d) 500

43) How does the firewall know that a specific connection comes from a specific user?

a) Every connection has a user ID encoded in it.

b) User-ID is supported only in protocols that use user authentication, which provides the user identity to the firewall and the back end.

c) The firewall always uses the IP address in the IP header to locate the user ID, but this initial identification is overridden by additional techniques such as HTTP proxies that provide the client’s IP address in the HTTP header.

d) Usually the firewall uses the IP address in the IP header to locate the user ID, but additional techniques are available as alternatives such as HTTP proxies providing the client’s IP address in the HTTP header.


44) A customer has a proprietary user authentication system that is not supported by User-ID. Can you provide User-ID information to their firewall, and if so, how?

a) It is impossible. The customer will need to upgrade to something more standard.

b) It can be done, but only for HTTP applications because HTTP supports XFF headers.

c) It can be done using the XML API.

d) It can be done, but it requires programming that can be performed only by the Palo Alto Networks Professional Services organization.


45) Should you limit the permission of the user who runs the User-ID agent? If so, why?

a) Yes, because of the principle of least privilege. You should give processes only those permissions that are necessary for them to work.

b) Yes, to an extent. You can give it most privileges, but there is no actual user, so you should not let it start an interactive login.

c) Yes, to an extent. You can give it most privileges, but there is no actual user, so you should not let it have remote access.

d) No, there is nothing wrong with using the administrator’s account.


46) Which types of file does WildFire analyze as executables? (Choose three.)

a) JAR

b) Portable Document Format

c) MP4

d) Portable Executable

e) Office Open XML (.docx)

f) Executable and Linkable Format

g) BMP


47) Which reasons could cause a firewall that is fully configured, including decryption, to not recognize an application? (Choose three.)

a) The application is running over SSL.

b) There is no App-ID signature for an unanticipated application.

c) The application is running over ICMP.

d) The application is running over UDP.

e) A TCP handshake completed but no application traffic reached the firewall.

f) Payload reached the firewall, but not enough data packets to identify the application.


48) Which decryption mode or modes require(s) the private key of the destination server? (Choose a single answer.)

a) Forward Proxy

b) Inbound Inspection

c) Both Forward Proxy and Inbound Inspection

d) SSH Proxy


49) Which parameter cannot be used in a Decryption policy rule?

a) User-ID

b) App-ID

c) Source Zone

d) Destination Zone

2020年11月10日 星期二

[PSE-Strata] Palo Alto Networks System Engineer Professional – Strata Exam

 NO.1 Which two features are found in a Palo Alto Networks NGFW but are absent in a legacy firewall product? (Choose two.)

A. Policy match is based on application

B. Traffic is separated by zones

C. Traffic control is based on IP port, and protocol

D. Identification of application is possible on any port 


Answer: A,D


NO.2 When log sizing is factored for the Cortex Data Lake on the NGFW, what is the average log size used in calculation?

A. 18 bytes

B. 8MB

C. 1500 bytes

D. depends on the Cortex Data Lake tier purchased


Answer: C

Explanation:

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClVMCA0


NO.3 Which license is required to receive weekly dynamic updates to the correlation objects on the firewall and Panorama?

A. URL Filtering on the firewall, and MineMeld on Panorama

B. WildFire on the firewall, and AutoFocus on Panorama

C. GlobalProtect on the firewall, and Threat Prevention on Panorama

D. Threat Prevention on the firewall, and Support on Panorama 


Answer: D


NO.4 An endpoint, inside an organization, is infected with known malware that attempts to make a command-and-control connection to a C2 server via the destination IP address Which mechanism prevents this connection from succeeding?

A. DNS Proxy

B. Anti-Spyware Signatures

C. Wildfire Analysis

D. DNS Sinkholing 


Answer: D


NO.5 A service provider has acquired a pair of PA-7080s for its data center to secure its customer base's traffic. The server provider's traffic is largely generated by smart phones and averages 6.000,000 concurrent sessions.

Which Network Processing Card should be recommended in the Bill of Materials?

A. PA-7000-40G-NPC

B. PA-7000-20GQ-NPC

C. PA-7000-20GQXM-NPC

D. PA-7000-20G-NPC

Answer: C


NO.6 Which three methods used to map users to IP addresses are supported in Palo Alto Networks firewalls? (Choose three.)

A. eDirectory monitoring

B. Active Directory monitoring

C. TACACS

D. Lotus Domino

E. SNMP server

F. RADIUS

G. Client Probing


Answer: C,F,G

Explanation:

https://www.paloaltonetworks.com/documentation/80/pan-os/pan-os/user-id/user-id-concepts/user-mapping


2020年10月29日 星期四

重置KRBTGT 帳號 (KRBTGT account reset)

#KRBTGT   #Zerologon


1. 確認KRBTGT帳號密碼最後設定日期是否在 180 天內

在  DC , 用 Powershell 

> Get-ADUser krbtgt -Property PasswordLastSet

確認 Password History 低於 180 天.


2. 重置KRBTGT帳號密碼

a. 按一下 [ 開始],指向 [ 主控台],指向 [系統 管理工具],然後按一下 [ Active Directory 消費者和電腦]。

b. 按一下 [檢視]****,然後按一下 [進階功能] 。

c. 在主控台樹中,按兩下 [網域] 容器,然後按一下 [ 使用者]。

d. 在詳細資料窗格中,以滑鼠右鍵按一下 krbtgt 使用者帳戶,然後按一下 [ 重設密碼]。

e. 在 [ 新密碼] 中輸入新密碼,在 [ 確認密碼] 中重新輸入密碼,然後按一下 [確定]。 您指定的密碼並不重要,因為系統會自動產生與您指定的密碼無關的強式密碼。




3. KRBTGT帳戶說明

KRBTGT帳戶是本地默認帳戶,充當密鑰分發中心(KDC)服務的服務帳戶。該帳戶無法刪除,並且帳戶名稱也無法更改。無法在Active Directory中啟用KRBTGT帳戶。

根據RFC 4120的規定,KRBTGT也是KDC用於Windows Server域的安全主體名稱。KRBTGT帳戶是KRBTGT安全主體的實體,並且在創建新域時自動創建。

Windows Server Kerberos身份驗證通過使用帶有對稱密鑰的特殊Kerberos票證授予票證(TGT)來實現。該密鑰來自請求訪問的服務器或服務的密碼。僅Kerberos服務知道KRBTGT帳戶的TGT密碼。為了請求會話票,必須將TGT提交給KDC。TGT從KDC發布給Kerberos客戶端。

4. KRBTGT帳戶維護注意事項

強密碼會自動分配給KRBTGT帳戶。確保定期更改密碼。KDC帳戶的密碼用於派生用於加密和解密已發出的TGT請求的密鑰。域信任帳戶的密碼用於導出域間密鑰,用於加密推薦票證。

有時,例如當嘗試更改KRBTGT帳戶上的密碼失敗時,需要重置KRBTGT帳戶密碼。為了解決此問題,您可以使用Active Directory用戶和計算機兩次重置KRBTGT用戶帳戶密碼。您必須重置密碼兩次,因為KRBTGT帳戶在密碼歷史記錄中僅存儲了兩個最新密碼。通過兩次重置密碼,可以有效地清除密碼歷史記錄中的所有密碼。

重置密碼要求您或者是Domain Admins組的成員,或者必須具有適當的權限委派。此外,您必須是本地Administrators組的成員,或者必須已委派了適當的權限。

重置KRBTGT密碼後,請確保將(Kerberos)Key-Distribution-Center事件源中的事件ID 6寫入系統事件日誌。

5. 安全注意事項

重置KRBTGT帳戶密碼也是一種最佳做法,以確保新還原的域控制器不會與受感染的域控制器進行複制。在這種情況下,在分佈於多個位置的大型林恢復中,您不能保證所有域控制器都已關閉,並且如果關閉它們,則在執行所有適當的恢復步驟之前,不能再次重新引導它們。重置KRBTGT帳戶後,另一個域控制器無法使用舊密碼來複製此帳戶密碼。

懷疑KRBTGT帳戶的域受到損害的組織應考慮使用專業的事件響應服務。恢復帳戶所有權的影響是整個領域的,需要大量勞動,這是較大恢復工作的一部分。

KRBTGT密碼是所有Kerberos信任鏈都可信任的密鑰。重置KRBTGT密碼類似於使用新密鑰續訂根CA證書,並且立即不信任舊密鑰,導致幾乎所有後續的Kerberos操作都將受到影響。

對於所有帳戶類型(用戶,計算機和服務)

  • 所有已發行和分發的TGT均將無效,因為DC將拒絕它們。這些票證已使用KRBTGT加密,因此任何DC都可以對其進行驗證。更改密碼後,票證將失效。

  • 在需要重新驗證服務票證之前,登錄用戶的所有當前已驗證會話(基於其服務票證)已建立到資源(例如文件共享,SharePoint網站或Exchange服務器)的會話良好。

  • NTLM身份驗證的連接不受影響



Source :  https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-R2-and-2012/dn745899(v=ws.11)?redirectedfrom=MSDN


2020年10月17日 星期六

EACの実際の値の計算方法

 推定完了値完了時の推定(EAC)

EACの計算方法は、現在の実際のコスト(実際のコスト(AC))を累積し、次に可能なコスト(推定完了(ETC))を計算することです。

式として記述、
EAC = AC + ETC

そしてETCにはいくつかの仮定があります

A.フォローアップ計画が完全に信頼できないと仮定して、完全に再見積もりします

このとき、ETCは各ジョブの残存コストに応じて累積されます

言い換えれば、各仕事に何人の人が関与するか(リソース)、何時間の人員が投資されるか(残りの労働単位)を再評価するとします。

現時点では、残りの労働単位*各リソースの単価は、作業の残りのコストを取得します

すべての残りのコストの累積はETCを取得します

B.ベースラインの計画に従って継続すると仮定する

計算方法は

各ジョブの(完了時の元の予算-現在の実績値(獲得値))をパフォーマンスファクターで変換した後、各ジョブのETCを取得し、最終的に累積します。

これはそれが式として書かれている方法です

ETC =(BAC-EV)* PF

現時点では、PFには4つの仮定があります。

I.楽観的な仮定

PF = 1

現時点では、BAC-EVが次に費やされるすべてのお金であると想定しています。

これは、現在の過剰支出(または予算不足)が異常であり、将来的に元の計画に従うことができることを意味します。

例:元の推定100人時の作業、現在の完了度が最大20人時であるとすると、ETC = 100-20 = 80人時となります。

この方法では、実際の投資状況を考慮せず、20人時の重量比を達成しています。

II。客観的な仮定

PF = 1 / CPI

これは、現在のコスト使用状況によるものです(CPIは、投資された1ドルの価値を表す、お金を使う効率です)。効率がわずか80%であると仮定すると、この効率は引き続き発生すると想定されます。

例:100人時の作業の当初の見積もり、20人時の重量比の現在の完了度、およびCPI = 0.8であると仮定します。

次に、ETC =(100-20)/0.8 = 100人力時間です。これは、前の人員容量が当初の見積もりの​​80%しかないため、次の80時間の作業には実際に100人力時間が必要であることを意味します。

III。保守的な仮定

PF = 1 /(CPI * SPI)

コスト使用状況に加えて、スケジュール状況も考慮されます。

コスト利用状況が良くない場合(CPI <1)、時間経過状況が良くない場合(SPI <1)、PFは非常に控えめな調整ウェイトになります。非常に高いETCが計算されます。

IV。カスタム

PF =カスタム値

通常、パーティAがパーティBのパフォーマンスを評価するときに、契約で定義された値に使用されます。


実際の値の基本式

時間経過の差:SV = EV – PV
コストの差:CV = EV – AC
時間経過パフォーマンスインジケーター:SPI = EV / PV
コストパフォーマンスインジケーター:CPI = EV / AC
推定完了コスト:EAC = AC +(* BAC-EV )x * PF
完了率:パフォーマンス%完了=(累積EV)/ BAC

Popular