Huawei H12-722-ENU Practice Verified Answers - Pass Your Exams For Sure! [2021]
Valid Way To Pass HCNP-Security's H12-722-ENU Exam
NEW QUESTION 29
Which of the following statements is wrong about HTTP behavior?
- A. When the size of the uploaded or downloaded file or the size of the POST operation reaches the blocking threshold, the system will only block uploads or subsequent file and POST operations.
- B. HTTP POST is generally used to send information to the server through a web page, such as forum posting, form submission, username/password login.
- C. When the size of the uploaded or downloaded file or the size of the POST operation reaches the alarm threshold, the system generates log information to prompt the device administrator and block the action.
- D. When the file upload operation is allowed, alarm thresholds and blocking thresholds can be configured to control the uploaded file size.
Answer: A
NEW QUESTION 30
Which of the following protocols can be used to construct attack packets for special control packet attacks? (Multiple choices)
- A. UDP protocol
- B. ICMP protocol
- C. FTP protocol
- D. IP protocol
Answer: A,B,D
NEW QUESTION 31
What are the typical technologies of anti-virus engines? (Multiple choices)
- A. Heuristic detection technology
- B. Document reputation detection technology
- C. Decryption technology
- D. First packet inspection technology
Answer: A,B,D
NEW QUESTION 32
Which of the following options are correct for the description of the Management Center ATIC configuration? (Multiple Choices)
- A. The drainage task must be configured on the management center and delivered to the cleaning center when an attack is discovered.
- B. The recycle strategy needs to be configured on management center needs to guide the cleaned traffic.
- C. The port mirroring needs to be configured on the management center to monitor abnormal traffic.
- D. The protection object needs to be configured on the management center to guide abnormal access traffic.
Answer: A,D
NEW QUESTION 33
Malicious code usually uses RootKit technology to hide itself. RootKit modifies the kernel of the system by loading special drivers to hide itself and specific files.
- A. TRUE
- B. FALSE
Answer: A
NEW QUESTION 34
Which of the following options does not belong to the security risk of the TCP/IP stack application layer?
- A. Buffer overflow
- B. System vulnerabilities
- C. Port scanning
- D. Virus
Answer: C
NEW QUESTION 35
The security management system is optional, and anti-virus software or anti-hacking technology can be very good against network threats.
- A. False
- B. True
Answer: A
NEW QUESTION 36
Content filtering is a security mechanism for filtering files or applications by Huawei USG6000 products. By deeply identifying the content contained in the traffic, the device can block or alarm the traffic containing specific keywords.
- A. True
- B. False
Answer: A
NEW QUESTION 37
The process of a browser carrying a cookie to request a resource from a server is as shown in the following figure. Which of the following steps have the session ID information in the message?
- A. 1, 3, 4
- B. 3, 4,
- C. 2, 4
- D. 5, 6
Answer: B
NEW QUESTION 38
Which of the following options does not belong to packet message attack?
- A. Large ICMP packet attacks
- B. ICMP redirect packet attack
- C. Tracert packet attacks
- D. IP fragmentation packet attacks
Answer: D
NEW QUESTION 39
Which of the following description are correct about the principles of HTTP Flood and HTTPS flood attack defense? (Multiple Choice)
- A. The principle of HTTPS flood attack is to initiate a large number of HTTPS connections to the target server, resulting in exhaustion of server resources and failure to respond to normal requests.
- B. The principle of HTTPS Flood attack is to use the URI that involves database operations or other URIs that consume system resources, causing server resources to become exhausted and unable to respond to normal requests.
- C. HTTPS flood defense can perform source authentication by limiting the packet request rate.
- D. HTTPS flood defense mode includes basic mode, enhanced mode, and 302 redirects.
Answer: A,B,C
NEW QUESTION 40
For SYN flood attacks, TCP source authentication and TCP proxy can be used for defense.
Which of the following description is correct?
- A. TCP proxy means that the firewall is deployed between the client and the server. When the client sends an SYII packet to the server through the firewall, the firewall instead of the server establishes a three-way handshake with the client. Generally used for scenarios where the path of the packet is inconsistent.
- B. After the TCP source authentication passes the source authentication of the client, it is added to the whitelist. Then the SYN packet of this source still needs to be verified.
- C. TCP source authentication has the same restriction on the path of packets, so the application is not as common as TCP proxy.
- D. During the TCP proxy process, the firewall proxies and responds to every SYN packet received and maintains half-connection. Therefore, when the traffic of the SYN packet is heavy, the firewall requires very high performance.
Answer: D
NEW QUESTION 41
A business administrator wants to prevent employees from accessing shopping websites during business hours. A URL filtering configuration file was then configured to select the shopping site in the predefined category as blocked. However, employee A can still use the company's network to shop online during the lunch break.
What are the possible reasons for the following? (Multiple choices)
- A. The shopping site does not belong to the predefined shopping site category.
- B. The administrator did not submit the configuration after configuration.
- C. The administrator did not apply the URL filtering profile to the security policy.
- D. The administrator did not set the time period to 9:00-18:00 daily.
Answer: A,B,C
NEW QUESTION 42
After the cleaning device establishes a BGP neighbor relationship with the peer router, uses BGP traffic diversion and policy routing reinjection, what configuration needs to be performed on the cleaning device? (Multiple Choice)
- A. [sysname] interface GigabitEthernet 2/0/1 [sysname-GigabitEthernet2/0/1] anti-ddos flow-statistic enable
- B. [sysname] policy-based-route [sysname-policy-pbr] rule name huizhu [sysname-policy-pbr-rule-huizhu] ingress-interface GigabitEthernet 2/0/1 [sysname-policy-pbr-rule-huizhu] action pbr egress-interface GigabitEthernet 2/0/2 next-hop X.X.X.X [sysname-policy-pbr-rule-huizhu] quit
- C. [sysname] route-policy 1 permit node 1 [sysname-route-policy] apply community no-advertise [sysname-route-policy] quit [sysname] bgp 100 [sysname-bgp] peer X.X.X.X as-number 100 [sysname-bgp] import-route unr [sysname-bgp] ipv4-family unicast [sysname-bgp-af-ipv4] peer X.X.X.X route-policy 1 export [sysname-bgp-af-ipv4] peer X.X.X.X advertise-community [sysname-bgp-af-ipv4] quit
- D. <sysname> system-view [sysname] firewall ddos bgp-next-hop X.X.X.X
Answer: B,C
NEW QUESTION 43
Which of the following are typical intrusions? (Multiple choices)
- A. The power supply in the equipment room is abnormally interrupted
- B. Computer is infected by U disk virus
- C. Tampering Web pages
- D. Copy/View Sensitive Data
Answer: C,D
NEW QUESTION 44
Due to the differences in network environment and system security policies, intrusion detection systems also differ in their implementation.
In terms of system composition, what are the four major components?
- A. Event recording, intrusion analysis, intrusion response, and remote management.
- B. Event extraction, intrusion analysis, reverse intrusion, and remote management.
- C. Event extraction, intrusion analysis, intrusion response, and field management.
- D. Event extraction, intrusion analysis, intrusion response, and remote management.
Answer: D
NEW QUESTION 45
Regarding the file filtering configuration file global configuration of the Huawei USG6000 product, which of the following is correct?
- A. When the file type is not recognized, file filtering, content filtering, and anti-virus detection are not performed.
- B. File filtering, content filtering and anti-virus detection are not available when the file is corrupted. At this time, the file can be released or blocked according to business requirements.
- C. When the number of the file compressed layers is greater than the configured maximum number of uncompressed layers, the firewall cannot filter the file.
- D. When the file extension does not match, if the action is "Allow" or "Alert", file filtering, content filtering, and anti-virus detection are performed according to the file type.
Answer: C
NEW QUESTION 46
SQI injection attacks generally have the following steps:
1, Privilge Escalation
2, Get the data in the database
3, To determine whether there is a vulnerability in the webpage
4, Determine the database type
Which of the following options is correct for the ordering of these steps?
- A. 4, 1, 2, 3
- B. 3, 4, 2, 1
- C. 4, 2, 1, 3
- D. 3, 4, 1, 2
Answer: B
NEW QUESTION 47
The anti-virus feature configured on the Huawei USG6000 product does not take effect. Which of the following are possible causes? (Multiple Choice)
- A. The security policy does not reference the anti-virus configuration file.
- B. Antivirus configuration file configuration error.
- C. No virus exceptions are configured.
- D. The version of the virus signature database is older.
Answer: A,B,D
NEW QUESTION 48
......
Huawei H12-722-ENU Pre-Exam Practice Tests | Exam4Tests: https://www.exam4tests.com/H12-722-ENU-valid-braindumps.html