HCNP-Security H12-722-ENU Dumps Full Questions with Free PDF Questions to Pass
100% Updated Huawei H12-722-ENU Enterprise PDF Dumps
NEW QUESTION 49
The administrator has defined two key words that need to be recognized on the firewall: the weight of the keyword x is 2, and the weight of the key y is 3: defined The alarm interval value from the content is 5, and the blocking threshold value is 10. If the device detects that there is a secondary key space x in the webpage created by the user, the two keywords are Y; Regarding the weight value and monthly household visits to Heshun Street, is the following statement correct?
- A. The weight value is 10, you can ask the web page before
- B. The weight value is 8, the page cannot be accessed
- C. The weight value is 10, and the page cannot be accessed
- D. The weight value is 8, you can visit the web page
Answer: D
NEW QUESTION 50
Which of the following statement about IPS is wrong?
- A. When the source security zone is the same as the destination security zone, the IPS policy is applied in the domain.
- B. The covering signature has a higher priority than the signature in a centralized signature.
- C. The signature set can contain both pre-defined and custom signatures.
- D. Changes to the IPS policy do not take effect immediately. You need to submit a compilation to update the configuration of the IPS policy.
Answer: C
NEW QUESTION 51
The network-based intrusion detection system is mainly used to monitor the information of the critical path of the network in real time, listen to all packets on the network, collect data, and divide Analyze the suspicious object, which of the following options are its main features? (multiple choices)
- A. Need a lot of monitors.
- B. Good concealment, the network-based monitor does not run other applications, does not provide network services, and may not respond to other computers, so Not vulnerable to attack.
- C. The monitoring speed is fast (the problem can be found in microseconds or seconds, and the host-based DS needs to take an analysis of the audit transcripts in the last few minutes
- D. It can detect the source address and destination address, identify whether the address is illegal, and locate the real intruder.
Answer: B,C
NEW QUESTION 52
Which of the following are the control items of HTTP behavior?) (multiple choice)
- A. POST operation
- B. Browse the web
- C. File upload and download
- D. Acting online
Answer: A,B,C,D
NEW QUESTION 53
For the description of the AntiDDoS system, which of the following option is correct?
- A. The detection center mainly uses the control strategy of the security management center to perform traction and cleaning of the attack traffic. The normal traffic after cleaning is injected back to the customer network and sent to the real destination.
- B. The management center mainly completes the processing of attack events, controls the flow policy and cleaning policy of the cleaning center, and classifies various attack events and attack traffic to generate reports
- C. The main role of the cleaning center is to detect and analyze the DDoS attack traffic for the mirrored or light splitting traffic and provide the analysis data to the management center for judgment.
- D. The firewall can only be a detection device.
Answer: B
NEW QUESTION 54
If you combine security defenses with big data technologies, which of the following statements is correct? (Multiple choice)
- A. The security source data can come from many places, including data flows, packets, threat events, logs, and so on.
- B. During the learning process, we should start with collecting samples, analyze their characteristic vectors, and then perform machine learning.
- C. During the detection process, the unknown sample needs to be extracted and the corresponding model is calculated to provide a sample for subsequent static comparison.
- D. Machine learning is only for statistics of a large number of samples, which is convenient for security administrators to view.
Answer: A,B,C
NEW QUESTION 55
Which of the following is the correct about computer virus?
- A. All computer viruses must be parasitic in files and cannot exist independently
- B. The computer virus is contagious. It can spread through floppy disks and optical disks but it does not spread through the network.
- C. Patching the system can completely solve the problem of virus intrusion
- D. The computer virus is latent. It may be lurking for a long time. It will only begin to perform sabotage if certain conditions are met.
Answer: D
NEW QUESTION 56
Which of the following options is incorrect for the IntelliSense engine IAE?
- A. IAE's content security detection capabilities include application identification and awareness, intrusion prevention, and Web application security.
- B. English full name: Intelligent Awareness Engine.
- C. The core of IAE is to organically integrate all content security related detection functions.
- D. IAE engine's security detection is parallel and uses a message-based file processing mechanism that can receive file fragments and perform security checks.
Answer: D
NEW QUESTION 57
Which of the following options belong to the upgrade method of the anti-virus signature database of Huawei USG6000 products? (multiple choice)
- A. Manual upgrade
- B. Online upgrade
- C. Automatic upgrade
- D. Local upgrade
Answer: B,D
NEW QUESTION 58
For the URL is htpt://www.abcd. com:8080/news/education. aspx?name=tom&age=20, which option is path?
- A. htttp://www.abcd. com:8080,te
- B. /news/education. aspx
- C. htttp://www.abcd. com:8080/news/education. aspx
- D. /news/education. aspx?name=tom&age=20
Answer: B
NEW QUESTION 59
The following figure is the diagram which shows the firewall and sandbox system linkage detection file.
The Web Reputation feature is enabled on the firewall, and Site A is set as a trusted site and Site B is set as a suspicious site. Which of the following statements is correct?
- A. After the detection node detects a suspicious file, it not only informs the firewall in the figure, but also informs other connected network devices.
- B. When the user visits the Site B, although the firewall will extract the file and send it to the detection node, the user can still visit the Site B normally during the detection process.
- C. The files which the users obtain from Site A and Site B are sent to the detection node for detection.
- D. Assume that Site A is an unknown website, the administrator cannot detect the website's traffic file.
Answer: A
NEW QUESTION 60
Which two of the following options use similar attack methods and generate a large number of useless reply packets, occupying network bandwidth and consuming device resources?
- A. Fraggle andLand
- B. Fraggle and Smurf
- C. Land and Smurf
- D. Teardrop and Land
Answer: B
NEW QUESTION 61
With the continuous development of the network and the ever-changing applications, enterprise users have begun to transfer files on the network more and more frequently, and the resulting virus threats are also increasing. Only when the company rejects viruses outside the network can it ensure data security and system stability.
So, which of the following are the possible harms of the virus? (Multiple choices)
- A. Threatening user host and network security.
- B. Huawei USG6000 product can easily pass the defense.
- C. Some viruses can be used as invasive tools (such as the Trojan horse virus).
- D. Control host permissions, steal user data, and some viruses can even damage the host hardware.
Answer: A,C,D
NEW QUESTION 62
Which of the following is correct about special packets attack?
- A. The special control packets attack is a potential attack and does not have direct destruction.
- B. Attacks on special control packets do not have the ability to detect network structures. Only scanning-type attacks can detect the network.
- C. Attacks on special control packets can only use ICMP to construct attack packets.
- D. The attacker probes the network structure by sending special control packets to launch real attack.
Answer: A
NEW QUESTION 63
The anti-virus feature configured on the Huawei USG6000 product does not take effect. Which of the following are the possible reasons? (multiple choice)
- A. No virus exceptions are configured.
- B. The virus signature database version is older.
- C. The anti-virus configuration file is configured incorrectly.
- D. The security policy does not reference the anti-virus configuration file.
Answer: B,C,D
NEW QUESTION 64
Which of the following descriptions about the black and white lists in spam filtering is wrong?
- A. Enter the IP address and mask of the SMITP Server to be added to the blacklist in the "Blacklist" text box, you can enter multiple IP addresses, one IP Address one line.
- B. The priority of the blacklist is higher than that of the whitelist.
- C. In the "Whitelist" text box, enter the P address and mask of the SMTP Server to be added to the whitelist. You can enter multiple IP addresses, one IP address Address one line. v
- D. Set local blacklist and whitelist: Both blacklist and whitelist can be configured at the same time, or only one of them can be configured.
Answer: B
NEW QUESTION 65
Which descriptions about viruses and Trojans are correct? (Multiple Choice)
- A. Trojans can self-replicate
- B. Trojans triggered by computer users
- C. Viruses are triggered by computer users
- D. Virus can self-replicate
Answer: C,D
NEW QUESTION 66
The anti-tampering technology of Huawei WAF products is based on the cache module. Assuming that user A accesses website B, website B has signs of page tampering. The workflow of the WAF tamper-resistant module has the following steps:
1, WAF uses the cached page to return to the client
2, WAF compares the server page content with the cached page content
3, After the learning is completed, the page content is stored in the cache
4, When the user accesses the web page, the WAF obtains the page content of the server
5, WAF initiates learning mode to learn the page content of the user visiting the website
Which of the following options is correct for the ordering of these steps?
- A. 5, 1, 2, 4, 3
- B. 3, 4, 2, 5, 1
- C. 5, 3, 4, 2, 1
- D. 2, 4, 1, 5, 3
Answer: C
NEW QUESTION 67
If Huawei USG6000 product uses its own protocol stack cache for all files passing through the device and then performs virus scanning, then the device uses a flow scan mode.
- A. FALSE
- B. TRUE
Answer: A
NEW QUESTION 68
Analysis is the core function of intrusion detection. The analysis and processing process of intrusion detection can be divided into three phases; build an analyzer to perform analysis on actual field data.
Which of the analysis, feedback and refinement is the function included in the first two stages?
- A. Data processing, data classification, post-processing
- B. Data analysis, data classification, post-processing
- C. Data processing, data classification, attack playback
- D. Data processing, attack classification, post-processing
Answer: A
NEW QUESTION 69
Regarding the enhanced mode in HTTP Flood source authentication, which of the following descriptions are correct? Multiple choices
- A. The enhanced mode is superior to the basic mode in terms of user experience.
- B. Enhanced mode supports all HTTP Flood source authentication fields. " WWQQ: 922333
- C. Enhanced mode refers to the authentication method using verification code.
- D. Some bots have a redirection function, or the free proxy used during the attack supports the redirection function, which leads to the failure of the basic mode of defense Effective, enhanced mode can effectively defend.
Answer: C,D
NEW QUESTION 70
Regarding the sequence of file filtering technology processing flow, which of the following is correct?
(1) The security policy is applied as permit
(2) Protocol decoding
(3) File type recognition
(4) Application recognition
(5) File filtering
- A. (1)(2)(4)(3)(5)
- B. (1)(2)(3)(4)(5)
- C. (1)(4)(2)(3)(5)
- D. (1)(3)(2)(4)(5)
Answer: C
NEW QUESTION 71
......
Use Valid Exam H12-722-ENU by Exam4Tests Books For Free Website: https://www.exam4tests.com/H12-722-ENU-valid-braindumps.html