Free HCNP-Security H12-722-ENU Ultimate Study Guide (Updated 180 Questions) [Q73-Q96]

Share

Free HCNP-Security H12-722-ENU Ultimate Study Guide (Updated 180 Questions)

Get to the Top with H12-722-ENU Practice Exam Questions

NEW QUESTION 73
Regarding firewall and IDS, which of the following statements is correct?

  • A. IDS cannot be linked with firewall
  • B. The firewall is a bypass device, used for fine-grained detection
  • C. The firewall cannot detect malicious operations or misoperations by insiders
  • D. IDS is a straight line equipment and cannot be used for in-depth inspection

Answer: C

 

NEW QUESTION 74
If the Huawei USG600 product uses its own protocol stack cache for all files passing through the device and then performs a virus scan, then the device uses It is the stream scanning method.

  • A. False
  • B. True

Answer: A

 

NEW QUESTION 75
If the regular expression is "abc. de", which of the following will not match the regular expression?

  • A. abcdde
  • B. abc+de
  • C. abcde
  • D. abclde

Answer: C

 

NEW QUESTION 76
Why APT attacks are difficult to defend? Part of the reason is that they use zero-day loopholes to attack. This zero-day loopholes usually takes a lot of time to research and analyze and make corresponding defense methods.

  • A. False
  • B. True

Answer: B

 

NEW QUESTION 77
Which of the following options are correct for the configuration description of the management center ATIC?
(multiple choice)

  • A. The drainage task needs to be configured on the management center, and when an attack is discovered, it will be issued to the cleaning center.
  • B. It is necessary to configure the protection object on the management center to guide the abnormal access flow in etpa
  • C. The reinjection strategy needs to be configured on the management center to guide the flow after cleaning.
  • D. Port mirroring needs to be configured on the management center to monitor abnormal traffic.

Answer: A,B

 

NEW QUESTION 78
Huawei USG6000 product can virus scan and process certain file transfer protocols, but which of the following protocol does not include?

  • A. FTP
  • B. TFTP
  • C. POP3
  • D. IMAP

Answer: B

 

NEW QUESTION 79
Which of the following options is not a feature of big data technology?

  • A. Slow processing speed
  • B. The data boy is huge
  • C. A wide variety of data
  • D. Low value density

Answer: A

 

NEW QUESTION 80
Regarding the process of file filtering, which of the following statements is wrong?

  • A. The file type identification module is responsible for identifying the real type of the file and the extension of the file based on the file data
  • B. Protocol decoding is responsible for parsing the file data and file transfer directions in the data stream.
  • C. The application identification module can identify the type of application hosting the file.
  • D. After the file extraction fails, the file will still be filtered.

Answer: D

 

NEW QUESTION 81
About the description of the file filtering technology in the USG6000, which statement is wrong?

  • A. Even if the file type is modified, it can recognize the true type of the file.
  • B. It supports the filtering of the decompressed contents of the compressed file.
  • C. It can identify the application hosting the file, the file transfer direction, the file type, and the file extension.
  • D. It can identify the types of files transmitted by itself and can block, alert and announce specific type of files.

Answer: D

 

NEW QUESTION 82
Which of the following technologies can achieve content security? (multiple choice)

  • A. Web security protection
  • B. Sandbox and big data analysis
  • C. Global environment awareness
  • D. Intrusion prevention

Answer: A,B,C,D

 

NEW QUESTION 83
Fraggle attack means that both the source address and the destination address of TCP are set to the IP address of a victim. This behavior will cause the victim to send a SYN-ACK message to its own address, which in turn sends back an ACK message and creates an empty connection, causing the system resources to be occupied or the destination host to crash.

  • A. False
  • B. True

Answer: A

 

NEW QUESTION 84
Divert traffic using BGP protocol. The configuration command is as follows.
[sysname] route-policy 1 permit node 1
[sysname-route-policy] apply community no-advertise
[sysname-route-policy] quit
[sysname] bgp 100
[sysname-bgp] peer 7.7.1.2 as-number 100
[sysname-bgp] import-route unr
[sysname-bgp] ipv4-family unicast
[sysname-bgp-af-ipv4] peer 7.7.1.2 route-policy 1 export
[sysname-bgp-af-ipv4] peer 7.7.1.2 advertise-community
[sysname-bgp-af-ipv4] quit
[sysname-bgp] quit
Which of the following options are correct for the BGP drainage configuration description? (Multiple choice)

  • A. You also need to configure the firewall ddos bgp-next-hop fib-filter command to implement the remarks.
  • B. After receiving the UNR route, the peer neighbor will not send it to any BGP neighbors.
  • C. The management center does not need to configure protection objects. When an attack is discovered, the traffic diversion task is automatically delivered.
  • D. Use BGP to advertise UNR routes for dynamic traffic diversion.

Answer: B,D

 

NEW QUESTION 85
Which of the following is correct about special packets attack?

  • A. The special control packets attack is a potential attack and does not have direct destruction.
  • B. Attacks on special control packets do not have the ability to detect network structures. Only scanning-type attacks can detect the network.
  • C. Attacks on special control packets can only use ICMP to construct attack packets.
  • D. The attacker probes the network structure by sending special control packets to launch real attack.

Answer: A

 

NEW QUESTION 86
Due to differences in network environment and system security strategies, intrusion detection systems are also different in specific implementation. From the perspective of system composition, the main Which four major components are included?

  • A. Incident extraction, intrusion analysis, intrusion response and remote management.
  • B. Incident recording, intrusion analysis, intrusion response and remote management.
  • C. Incident extraction, intrusion analysis, intrusion response and on-site management.
  • D. Event extraction, intrusion analysis, reverse intrusion and remote management.

Answer: A

 

NEW QUESTION 87
Which of the following is a false positive for an intrusion detection system?

  • A. Web-based attacks have not been detected by the system
  • B. Unable to detect new worms
  • C. Use Ping for network detection and being alerted as an attack
  • D. The process of trying to log in to the system was recorded

Answer: C

 

NEW QUESTION 88
Which of the following statements is true about the process of file filtering?

  • A. The file filtering module will match the application type, file type, transmission direction of the file identified by the previous module and the file filter rule query table configured by the administrator from top to bottom.
  • B. If all the parameters of the file can match all the file filtering rules, the module will perform the action of this file filtering rule.
  • C. There are two alarms and blocking actions.
  • D. If the file type is a compressed file, then after file filtering detection, the file will be sent to the file decompression module for decompression and decompressing the original file. If decompression fails, the file will no longer be filtered.

Answer: B

 

NEW QUESTION 89
USG6000V software logical architecture is divided into three planes: the management plane, control plane, and _______.

  • A. configuration plane
  • B. service plane
  • C. data forwarding plane
  • D. log plane

Answer: C

 

NEW QUESTION 90
If you combine security defense with big data technology, which of the following statements are correct?
(multiple choice)

  • A. In the learning process, you should start from collecting samples, analyze their characteristics and then perform machine learning.
  • B. Machine learning only counts a large number of samples, which is convenient for security administrators to view.
  • C. In the detection process, the characteristics of unknown samples need to be extracted and calculated to provide samples for subsequent static comparisons.
  • D. Security source data can come from many places, including data streams, messages, threat events, logs, etc.

Answer: A,C,D

 

NEW QUESTION 91
With regard to APT attacks, the attacker often lurks for a long time and launches a formal attack on the enterprise at the key point of the incident.
Generally, APT attacks can be summarized into four stages:
1. Collecting Information & Intrusion
2. Long-term lurking & mining
3. Data breach
4. Remote control and penetration
Regarding the order of these four stages, which of the following options is correct?

  • A. 2-3-4-1
  • B. 1-4-2-3
  • C. 1-2-4-3
  • D. 2-1-4-3

Answer: B

 

NEW QUESTION 92
The configuration commands for enabling the attack defense function are as follows:
[FW] anti-ddos syn-flood source-detect
[FW] anti-ddos udp-flood dynamic-fingerprint-learn
[FW] anti-ddos udp-frag-flood dynamic-fingerprint-learn
[FW] anti-ddos http-flood defend alert-rate 2000
[FW] anti-ddos http-flood source-detect mode basic
Which of the following are the correct descriptions of the attack prevention configuration? (Multiple Choices)

  • A. The firewall uses the first packet discard to defense the UDP flood attacks.
  • B. SYN Flood source detection and prevention function is enabled on the firewall.
  • C. The threshold value enabled by HTTP Flood defense is 2000.
  • D. HTTP flood attack defense uses enhanced mode for defense.

Answer: B,C

 

NEW QUESTION 93
Misuse detection discovers intrusion activity in system by detecting similar behaviors of user intrusions, or by detecting violations of system security rules indirectly by exploiting system flaws.
Which of the following is not misuse detection feature?

  • A. Easy to implement
  • B. Effective detection of impersonation of legitimate users
  • C. Easy to upgrade
  • D. Accurate detection

Answer: B

 

NEW QUESTION 94
During the infiltration phase of APT attack, which of the following attack behaviors will the attacker generally have?

  • A. Leaks key data information to interested third parties.
  • B. Long-term latency and key data collection.
  • C. By phishing emails, attachments carrying a 0day vulnerability cause the user's terminal to become a springboard for attacks.
  • D. The attacker sends C&C attack or other remote command to the infected host, cause the attack to spread horizontally across the intranet.

Answer: D

 

NEW QUESTION 95
Which of the following options is not a defense against HTTP Flood attacks?

  • A. HTTP Flood source authentication
  • B. HTTP source statistics
  • C. URI source fingerprint learning function
  • D. Baseline learning

Answer: D

 

NEW QUESTION 96
......

Pass Huawei H12-722-ENU exam - questions - convert Tets Engine to PDF: https://www.itpass4sure.com/H12-722-ENU-practice-exam.html