Practice HCNP-Security H12-722-ENU exam. Online Exam Practice Tests with detailed explanations! Pass H12-722-ENU with confidence!
H12-722-ENU - HCIP-Security-CSSN(Huawei Certified ICT Professional -Constructing Service Security Network) Practice Tests 2021 | BraindumpQuiz
NEW QUESTION 15
For the description of the AntiDDoS system, which of the following option is correct?
- A. The detection center mainly uses the control strategy of the security management center to perform traction and cleaning of the attack traffic. The normal traffic after cleaning is injected back to the customer network and sent to the real destination.
- B. The management center mainly completes the processing of attack events, controls the flow policy and cleaning policy of the cleaning center, and classifies various attack events and attack traffic to generate reports
- C. The main role of the cleaning center is to detect and analyze the DDoS attack traffic for the mirrored or light splitting traffic and provide the analysis data to the management center for judgment.
- D. The firewall can only be a detection device.
Answer: B
NEW QUESTION 16
For compressed files, the virus detection system can directly detect.
- A. True
- B. False
Answer: A
NEW QUESTION 17
The whitelist rule of the firewall antivirus module is configured as *example*. Which of the following matches is used in this configuration?
- A. Suffix matching
- B. Keyword matching
- C. Prefix matching
- D. exact match
Answer: B
NEW QUESTION 18
Which of the following files can be detected by the sandbox? (Multiple choices)
- A. PE file
- B. WWW documents
- C. Picture file
- D. Mail
Answer: A,B,C
NEW QUESTION 19
Fraggle attack means that both the source address and the destination address of TCP are set to the IP address of a victim. This behavior will cause the victim to send a SYN-ACK message to its own address, which in turn sends back an ACK message and creates an empty connection, causing the system resources to be occupied or the destination host to crash.
- A. False
- B. True
Answer: A
NEW QUESTION 20
Which of the following options is correct about the file reputation technology in the anti-virus engine?
- A. File reputation is calculated by calculating the full-text MD5 of the file under test and matching it with the local reputation MD5 cache for virus detection.
- B. File reputation database can only be upgraded by manual upgrade
- C. The local reputation MD5 cache only has static cache and needs to be updated regularly
- D. The update of the file reputation database is achieved only through linkage with the sandbox.
Answer: A
NEW QUESTION 21
SQI injection attacks generally have the following steps:
1, Privilge Escalation
2, Get the data in the database
3, To determine whether there is a vulnerability in the webpage
4, Determine the database type
Which of the following options is correct for the ordering of these steps?
- A. 4, 1, 2, 3
- B. 3, 4, 2, 1
- C. 4, 2, 1, 3
- D. 3, 4, 1, 2
Answer: B
NEW QUESTION 22
What content can be filtered by the content filtering technology of Huawei USG6000? (Multiple Choices)
- A. File types
- B. Direction of file upload
- C. Keywords contained in the download file
- D. Keywords contained in the uploaded file contents
Answer: C,D
NEW QUESTION 23
Which of the following are the keyword matching patterns? (Multiple Choice)
- A. Regular expressions
- B. Community word
- C. Custom Keywords
- D. Text
Answer: A,D
NEW QUESTION 24
The application behavior control configuration file takes effect immediately after reference, without configuring the submission.
- A. True
- B. False
Answer: A
NEW QUESTION 25
Which of the following options is correct about the sequence-by-flow detection of AntiDDoS?
1. The Netflow analysis device samples the current network traffic.
2 Send a drainage command to the cleaning center;
3 Discover DDoS attack traffic;
4. Netflor: analysis equipment sends alarms to ATIC Management Center;
5 abnormal flow is drained to the cleaning center for further inspection and cleaning;
6 The cleaning center sends the host of the attacked object IF address server to the router to implement the drainage.
7 Cleaning logs sent to the management center to generate reports;
8 The cleaned traffic is sent to the original destination server.
- A. 1-3-4-2-5-6-7-8
- B. 1-3-4-2-6-5-8-7
- C. 1-3-2-4-6-5-7-8
- D. 1-3-2-4-6-5-8-7
Answer: B
NEW QUESTION 26
The following figure is the diagram which shows the firewall and sandbox system linkage detection file.
The Web Reputation feature is enabled on the firewall, and Site A is set as a trusted site and Site B is set as a suspicious site. Which of the following statements is correct?
- A. After the detection node detects a suspicious file, it not only informs the firewall in the figure, but also informs other connected network devices.
- B. When the user visits the Site B, although the firewall will extract the file and send it to the detection node, the user can still visit the Site B normally during the detection process.
- C. Assume that Site A is an unknown website, the administrator cannot detect the website's traffic file.
- D. The files which the users obtain from Site A and Site B are sent to the detection node for detection.
Answer: A
NEW QUESTION 27
The virus signature database on the device needs to be continuously upgraded from the security center platform. Which of the following is the URL of the security center platform?
- A. sec.huawei.com
- B. security.huawei.com
- C. www.huawei.com
- D. support.huawei.com
Answer: A
NEW QUESTION 28
The administrator has the following configuration:
1. The signature set Protect, all includes the signature ID 3000, and the entire signature set action is blocked.
2. Overwriting the signature ID3000 action is an alarm.
Which of the following judgments is correct?
- A. No relationship between signature set and coverage signature
- B. Cannot determine the action of signature ID3000
- C. The action of signature ID3000 is blocked
- D. The action of the signature ID3000 is an alarm
Answer: D
NEW QUESTION 29
After the cleaning device establishes a BGP neighbor relationship with the peer router, uses BGP traffic diversion and policy routing reinjection, what configuration needs to be performed on the cleaning device? (Multiple Choice)
- A. [sysname] interface GigabitEthernet 2/0/1 [sysname-GigabitEthernet2/0/1] anti-ddos flow-statistic enable
- B. [sysname] policy-based-route [sysname-policy-pbr] rule name huizhu [sysname-policy-pbr-rule-huizhu] ingress-interface GigabitEthernet 2/0/1 [sysname-policy-pbr-rule-huizhu] action pbr egress-interface GigabitEthernet 2/0/2 next-hop X.X.X.X [sysname-policy-pbr-rule-huizhu] quit
- C. [sysname] route-policy 1 permit node 1 [sysname-route-policy] apply community no-advertise [sysname-route-policy] quit [sysname] bgp 100 [sysname-bgp] peer X.X.X.X as-number 100 [sysname-bgp] import-route unr [sysname-bgp] ipv4-family unicast [sysname-bgp-af-ipv4] peer X.X.X.X route-policy 1 export [sysname-bgp-af-ipv4] peer X.X.X.X advertise-community [sysname-bgp-af-ipv4] quit
- D. <sysname> system-view [sysname] firewall ddos bgp-next-hop X.X.X.X
Answer: B,C
NEW QUESTION 30
Which of the following is correct about enhanced mode in HTTP Flood Source authentication? (Multiple selection)
- A. Some bots have redirection function, or the free agent used during the attack supports the redirection function, resulting in the failure of defense of the basic mode. The enhanced mode can effectively defend.
- B. The enhanced mode is better than the basic mode in the user experience.
- C. Enhanced mode refers to the use of verification code authentication.
- D. The enhanced mode support all HTTP flood source authentication scenarios.
Answer: A,C
NEW QUESTION 31
......
The best H12-722-ENU exam study material and preparation tool is here: https://www.braindumpquiz.com/H12-722-ENU-exam-material.html