[2021] H12-722-ENU PDF Questions - Perfect Prospect To Go With Exam4Tests Practice Exam [Q66-Q89]

Share

[2021] H12-722-ENU PDF Questions - Perfect Prospect To Go With Exam4Tests Practice Exam

Huawei H12-722-ENU Pdf Questions - Outstanding Practice To your Exam

NEW QUESTION 66
Which of the following protocols can be used to construct attack packets for special control packet attacks? (Multiple choices)

  • A. UDP protocol
  • B. ICMP protocol
  • C. FTP protocol
  • D. IP protocol

Answer: A,B,D

 

NEW QUESTION 67
What are the following descriptions of the role of content security filtering technology? (Multiple choices)

  • A. E-mail filtering refers to the management and control of e-mail sending and receiving activities, including the prevention of spam and the proliferation of anonymous e-mails, and the control of illegal sending and receiving.
  • B. Content filtering prevents the leakage of confidential information and the transmission of non-compliant information.
  • C. File Filtering By blocking the transmission of certain types of files, you can reduce the risk of internal networks running malicious code and viruses. You can also prevent employees from leaking corporate confidential files to the Internet.
  • D. The application behavior control function can finely control the common HTTP behavior and FTP behavior.

Answer: A,B,C,D

 

NEW QUESTION 68
Which of the following is not detected action when detecting a virus in a message?

  • A. Delete the attachment
  • B. Alarms
  • C. Blocking
  • D. Announcement

Answer: C

 

NEW QUESTION 69
Configure the following command on the Huawei firewall:
[USG] interface G0/0/1
[USG] ip urpf loose allow-default-route acl 3000
Which of the following options are correct? (Multiple choice)

  • A. If the default route is configured but the parameter allow-default-route is not configured. As long as the source address of the packet does not exist in the FIB table of the firewall, the packet will be rejected.
  • B. For the loose type check, if the source address of the packet exists in the FIB table of the firewall, the packet passes the check.
  • C. If the source address of the packet does not exist in the FIB table of the firewall and the default route is configured and the allow-default-route parameter is also matched, the packet cannot pass the URPF check even if it is a loose type check.
  • D. If the default route is configured and the allow-default-route parameter is also matched, if the source address of the packet does not exist in the FIB table of the firewall, but for the loose type check, the packet will pass through URPF check, and perform normal forwarding.

Answer: A,B,D

 

NEW QUESTION 70
The following figure shows the configuration of the URL filtering configuration file. Which of the following statements is true about this configuration?

  • A. The user visit the website www.exzample.com. When there is no black and white list of hits, the predefined URL category entry is next queried.
  • B. The default action means that all websites allow access. Therefore, this configuration error.
  • C. The firewall will check the blacklist first and then check the whitelist.
  • D. Assume that user visit www.exzample.com, which is part of Humanities and Social Networking category. At this time, the user cannot access the site.

Answer: D

 

NEW QUESTION 71
A college user needs are as follows:
1. The environmental traffic is relatively large and can add up to 800M in both directions. Huawei USG6000 series firewalls are deployed at its network nodes.
2. The intranet is divided into student areas, server areas, etc. Users are most concerned about the security of the server area and avoid being attacked by various types of threats.
3. At the same time, some pornographic websites in the student district are prohibited.
The external network is configured as untrust zone on the firewall, and the internal network is configured as trust zone. How to configure the firewall to meet the above requirements? (Multiple choices)

  • A. You can enable the AV, IPS protection and URL filtering functions in the global environment.
  • B. Enable AV and IPS protection only for the server zone in the untrust direction to protect the server
  • C. Enable URL filtering for the entire campus network in the direction of untrust and filter some classified websites
  • D. untrust to the internal network direction only for the server area to open AV, IPS protection to protect the server

Answer: A,C,D

 

NEW QUESTION 72
Which of the following is correct about special packets attack?

  • A. The special control packets attack is a potential attack and does not have direct destruction.
  • B. Attacks on special control packets can only use ICMP to construct attack packets.
  • C. The attacker probes the network structure by sending special control packets to launch real attack.
  • D. Attacks on special control packets do not have the ability to detect network structures. Only scanning-type attacks can detect the network.

Answer: A

 

NEW QUESTION 73
After the Huawei USG6000 product license expires, the RBL function is unavailable.
Users can only use local black and white lists to filter spam.

  • A. TRUE
  • B. FALSE

Answer: A

 

NEW QUESTION 74
The implementation of the content security filtering technology requires the support of the content security combination license.

  • A. True
  • B. False

Answer: A

 

NEW QUESTION 75
Huawei NIP6000 products provide carrier-grade high-reliability mechanisms at multiple levels to ensure the stable operation of the equipment.
Which of the following options belong to the reliability of the network? (Multiple choices)

  • A. Link-group
  • B. Power 1+1 redundancy backup
  • C. Hardware Bypass
  • D. Hot Standby

Answer: A,D

 

NEW QUESTION 76
Which of the following options is not cyber security threat posed by weak personal security awareness?

  • A. Leaking corporate information
  • B. Disclosing personal information
  • C. Increase the cost of enterprise network operation and maintenance
  • D. Threat internal network

Answer: C

 

NEW QUESTION 77
Which of the following options does not belong to the basic DDoS attack prevention configuration process?

  • A. The system starts attack defense.
  • B. The system performs preventive actions.
  • C. The system is associated to configurate application for fingerprint learning.
  • D. The system starts traffic statistics.

Answer: C

 

NEW QUESTION 78
Malicious code usually uses RootKit technology to hide itself. RootKit modifies the kernel of the system by loading special drivers to hide itself and specific files.

  • A. TRUE
  • B. FALSE

Answer: A

 

NEW QUESTION 79
The core technology of content security lies in anomaly detection. The idea of defense lies in continuous monitoring and analysis.

  • A. True
  • B. False

Answer: A

 

NEW QUESTION 80
In the anti-virus policy configuration of Huawei USG6000 products, which are the HTTP response methods? (Multiple choices)

  • A. Popup warning dialog
  • B. Disable all access for this client
  • C. Alarms
  • D. Blocking and pushing pages

Answer: C,D

 

NEW QUESTION 81
Which of the following options are correct for the description of the Management Center ATIC configuration? (Multiple Choices)

  • A. The drainage task must be configured on the management center and delivered to the cleaning center when an attack is discovered.
  • B. The recycle strategy needs to be configured on management center needs to guide the cleaned traffic.
  • C. The port mirroring needs to be configured on the management center to monitor abnormal traffic.
  • D. The protection object needs to be configured on the management center to guide abnormal access traffic.

Answer: A,D

 

NEW QUESTION 82
When configure the URL filtering configuration file, www.bt.com is configured in the URL blacklist, and URL is set to *bt.com in the custom URL classification, and the action for customizing the URL classification is warning. .
Which of the following statements is true about the above configuration? (Multiple choices)

  • A. Users can visit www.bt.com website, but administrators will receive warning message.
  • B. Users can't access all websites ending with bt.com.
  • C. Users will be blocked when they visit www.bt.com.
  • D. Users can visit www.videobt.com.

Answer: C,D

 

NEW QUESTION 83
Which of the following is correct about the AntiDDoS system configuration?

  • A. Configure drainage and injection on the management center.
  • B. Configure port mirroring on the cleaning device.
  • C. Configure drainage and injection on the detection device.
  • D. Add protection objects on the management center.

Answer: D

 

NEW QUESTION 84
Which of the following statements is wrong about the Anti-DDoS cloud cleaning solution?

  • A. If there is a large traffic attack in the network, send it to the cloud cleaning center to share the cleaning pressure.
  • B. Because the Cloud Cleaning Alliance will direct larger attack traffic to the cloud for cleaning, it will cause network congestion.
  • C. The cloud cleaning service that is closer to the target being attacked will be transferred first.
  • D. Normal attacks are usually cleaned locally first.

Answer: B

 

NEW QUESTION 85
When the AntiDDoS system detects attack traffic, the attack traffic is directed to the cleaning device. After the cleaning device completes cleaning, the traffic is re-injected to the original link. Which of the following options does not belong to the injection method?

  • A. GRE injection
  • B. Policy Routing injection
  • C. BGP injection
  • D. MPLS LSP injection

Answer: C

 

NEW QUESTION 86
AntiDDoS 7-layer defense works from the interface-based defense, global-based defense, and defense-based defense dimension.

  • A. True
  • B. False

Answer: A

 

NEW QUESTION 87
Which of the following statements is wrong about the content filtering configuration of Huawei USG6000?

  • A. The size of attachments is limited to single attachment, not to the total size of all attachments.
  • B. When POP3 message is detected, if it is determined to be illegal, the response action of the firewall only support sending alarm information and does not block the message.
  • C. When IMAP message is detected, if it is determined to be illegal, the response action of the firewall only support sending alarm information and does not block the message.
  • D. Mail filtering will not take effect until the mail filtering configuration file is invoked with the security policy enabled.

Answer: B

 

NEW QUESTION 88
Which of the following statement about IPS is wrong?

  • A. The covering signature has a higher priority than the signature in a centralized signature.
  • B. Changes to the IPS policy do not take effect immediately. You need to submit a compilation to update the configuration of the IPS policy.
  • C. The signature set can contain both pre-defined and custom signatures.
  • D. When the source security zone is the same as the destination security zone, the IPS policy is applied in the domain.

Answer: C

 

NEW QUESTION 89
......

Online Questions - Outstanding Practice To your H12-722-ENU Exam: https://www.exam4tests.com/H12-722-ENU-valid-braindumps.html