HCIP-Security-CSSN(Huawei Certified ICT Professional -Constructing Service Security Network) Practice Tests 2021 | Pass H12-722 with confidence!
Practice HCNP-Security H12-722 exam. Online Exam Practice Tests with detailed explanations!
NEW QUESTION 99
Which of the following options is not a feature of big data technology?
- A. Slow processing speed
- B. The data boy is huge
- C. A wide variety of data
- D. Low value density
Answer: A
NEW QUESTION 100
The following figure is the diagram which shows the firewall and sandbox system linkage detection file.
The Web Reputation feature is enabled on the firewall, and Site A is set as a trusted site and Site B is set as a suspicious site. Which of the following statements is correct?
- A. After the detection node detects a suspicious file, it not only informs the firewall in the figure, but also informs other connected network devices.
- B. When the user visits the Site B, although the firewall will extract the file and send it to the detection node, the user can still visit the Site B normally during the detection process.
- C. The files which the users obtain from Site A and Site B are sent to the detection node for detection.
- D. Assume that Site A is an unknown website, the administrator cannot detect the website's traffic file.
Answer: A
NEW QUESTION 101
For APT attacks, attackers often lurk for a long time and initiate formal attacks on the enterprise at key points of the incident. APT attacks can generally be summarized in four stages:
1. Collect Information & Invasion
2. Long-term latency & mining
3. Data leakage
4. Remote control and penetration
Which of the following options is correct regarding the ordering of these four phases?
- A. 2-3-4-1
- B. 1-4-2-3
- C. 1-2-4-3
- D. 2-1-4-3
Answer: B
NEW QUESTION 102
In the construction of information security, the intrusion detection system plays a role as a monitor. Through monitoring the traffic of critical nodes in the information system, it conducts in-depth analysis and explores the security events that are taking place. Which of the following are its characteristics?
- A. Cannot perform in-depth inspection
- B. Unable to detect malicious operations or mis-operations from insiders.
- C. Malicious code that is doped in allowable application data streams cannot be correctly analyzed.
- D. IDS can be linked with firewalls and switches to become a powerful "helper" for firewalls to better and more precisely control access between domains.
Answer: D
NEW QUESTION 103
Which of the following options does not belong to the characteristics of Trojans?
- A. Not self-replicating but parasitic
- B. The ultimate intent is to steal information and implement remote monitoring
- C. Actively Infectious
- D. Trojans replicate themselves
Answer: C
NEW QUESTION 104
Which of the following signature attributes cannot be configured for IP custom signature?
- A. Direction
- B. ID
- C. Agreement
- D. Message length
Answer: D
NEW QUESTION 105
Buffer overflows, Trojan horses, and backdoor attacks are all attacks at the application layer.
- A. False
- B. True
Answer: B
NEW QUESTION 106
Which of the following is not an abnormal condition of the file type recognition result?
- A. Files are compressed
- B. File extension does not match
- C. The file type is not recognized
- D. File damage
Answer: A
NEW QUESTION 107
Regarding worms and viruses, which of the following statements is correct?
- A. Worms exist in a parasitic way
- B. Viruses mainly rely on system vulnerabilities to spread
- C. The virus exists independently in the computer system.
- D. The target of the worm infection is other computer systems on the network.
Answer: D
NEW QUESTION 108
Intrusion detection is a kind of network security technology used to detect any damage or attempt to damage the confidentiality, integrity or availability of the system. Which of the following belongs to the intrusion detection knowledge base?
- A. Complete virus sample
- B. Complete Trojan sample
- C. Specific behavior patterns
- D. Security policy
Answer: C
NEW QUESTION 109
Which of the following attack types is DDoS attack?
- A. Traffic attack
- B. Snooping scanning attack
- C. Single package attack
- D. Malformed packet attack
Answer: A
NEW QUESTION 110
Which of the following description are correct about the principles of HTTP Flood and HTTPS flood attack defense? (Multiple Choice)
- A. The principle of HTTPS flood attack is to initiate a large number of HTTPS connections to the target server, resulting in exhaustion of server resources and failure to respond to normal requests.
- B. The principle of HTTPS Flood attack is to use the URI that involves database operations or other URIs that consume system resources, causing server resources to become exhausted and unable to respond to normal requests.
- C. HTTPS flood defense mode includes basic mode, enhanced mode, and 302 redirects.
- D. HTTPS flood defense can perform source authentication by limiting the packet request rate.
Answer: A,B,D
NEW QUESTION 111
Regarding the description of intrusion detection technology, which of the following statements is correct?
- A. Unable to detect violation of security policy.
- B. Cannot find the trace of the system being attacked.
- C. Can detect authorized and non-authorized intrusions.
- D. is an active, static security defense technology.
Answer: C
NEW QUESTION 112
Regarding the Anti-DDoS cloud cleaning solution; which of the following statements is wrong?
- A. Ordinary attacks will usually be cleaned locally first.
- B. The closer to the attacked self-labeled cloud cleaning service, the priority will be called.
- C. If there is a large traffic attack on the network, send it to the cloud cleaning center to share the cleaning pressure.
- D. Since the Cloud Cleaning Alliance will direct larger attack flows to the cloud for cleaning, it will cause network congestion.
Answer: D
NEW QUESTION 113
To protect the security of data transmission, more and more websites or companies choose to encrypt traffic through SSL.
Which of the following statements is true about the threat detection of SSL traffic using Huawei NIP6000?
- A. Threat-detected traffic is sent directly to the server without encryption.
- B. NIP000 does not support SSL traffic threat detection.
- C. NIP can directly crack and detect SSL encryption.
- D. Processes such as "decryption," "threat detection," and "encryption."
Answer: D
NEW QUESTION 114
Which of the following are the common causes of IPS detection failures? (Multiple choices)
- A. Bypass function in IPS is turned off
- B. IPS policy is not submitted for compilation
- C. Policy IDs with incorrect associations between IPS policy domains
- D. IPS function is not enabled
Answer: B,C,D
NEW QUESTION 115
In order to protect the security of data transmission, more and more websites or companies choose to use SSL to encrypt transmissions in the stream. About using Huawei NIP6000 The product performs threat detection on (SSL stream boy, which of the following statements is correct?
- A. After the process of "decryption", "threat detection", and "encryption"
- B. NIP0OO does not support SSL Threat Detection.
- C. NIP can directly crack and detect SSL encryption.
- D. The traffic after threat detection is sent directly to the server without encryption
Answer: A
NEW QUESTION 116
The anti-virus feature configured on the Huawei USG6000 product does not take effect. Which of the following are the possible reasons? (multiple choice)
- A. No virus exceptions are configured.
- B. The virus signature database version is older.
- C. The anti-virus configuration file is configured incorrectly.
- D. The security policy does not reference the anti-virus configuration file.
Answer: B,C,D
NEW QUESTION 117
Which of the following statements is wrong about Huawei anti-virus technology?
- A. The virus detection system cannot directly detect compressed files
- B. Gateway anti-virus implementation is based on proxy scanning and flow scanning
- C. The maximum number of unpacked layers of the gateway antivirus default file is 3
- D. Anti-virus engine can detect file type by file extension
Answer: D
NEW QUESTION 118
Which of the following options does not belong to the security risk of the application layer of the TCP/IP protocol stack?
- A. Virus
- B. System vulnerabilities
- C. Buffer overflow
- D. Port scan
Answer: D
NEW QUESTION 119
After enabling the IP policy, some services are found to be unavailable. Which of the following may be caused by? (multiple choice)
- A. Excessive traffic causes the Bypass function to be enabled
- B. The same message passes through the firewall multiple times
- C. IPS underreporting
- D. Only packets in one direction pass through the firewall
Answer: B,D
NEW QUESTION 120
Regarding HTTP behavior, which of the following statements is wrong?
- A. When the uploaded or downloaded file size, POST operation content size reaches the blocking threshold, the system will only block the uploaded or downloaded file, POST operate.
- B. When the file upload operation is allowed, the alarm threshold and blocking threshold can be configured to control the size of the uploaded file.
- C. When the size of the uploaded or downloaded file and the size of the content of the POST operation reach the alarm threshold, the system will generate log information to prompt the device management And block behavior.
- D. HTTP POST is generally used to send information to the server through a web page, such as forum posting x form submission, username I password login.
Answer: A
NEW QUESTION 121
......
The best H12-722 exam study material and preparation tool is here: https://www.updatedumps.com/Huawei/H12-722-updated-exam-dumps.html