[Q27-Q45] Verified ACP-Sec1 dumps Q&As - Pass Guarantee Exam Dumps Test Engine [2021]

Share

Verified ACP-Sec1 dumps Q&As - Pass Guarantee Exam Dumps Test Engine [2021]

ACP-Sec1 dumps and 82 unique questions


Alibaba ACP-Sec1 Exam Syllabus Topics:

TopicDetails
Topic 1
  • Cloud computing-related product (ECS, Server Load Balancer, OSS, RDS, VPC and CDN) content
Topic 2
  • Characteristic, application scenarios, competitive edges and features of Alibaba Cloud Anti-DDos and WAF
Topic 3
  • Security application solution design, such as correct understanding and handling after receiving alerts from the console, e-mails or text messages
Topic 4
  • web SQL injections among other common security risks and taking appropriate measures for protection
Topic 5
  • Cloud service-related basic security protocols such as HTTP, FTP, TCP, UDP and ICMP
  • Understanding common security risks of the above products
Topic 6
  • Core security products: basic operations and management of Anti-DDoS, Security Center, SSL Certificate, Content Moderation, Key Management Service
Topic 7
  • Understanding the positioning, main features, working principles and application scenarios of the above products
Topic 8
  • Characteristics, application scenarios and features of Alibaba Cloud security management-related products
Topic 9
  • Discovering DDoS attacks, brute force password cracking attacks
  • Security advantages of their combined solutions

 

NEW QUESTION 27
To improve ECS instance security, the administrator does not want users on public network to check whether an ECS instance is online using the ping command. Which of the following reinforcement measures designed by the administrator is NOT feasible?

  • A. Enable an operating system firewall for the ECS instance, and reject ICMP for public network access.
  • B. Resolve the IP address of the ECS instance to an uncommon level 4 domain name, and point the promotional domain name to the level 4 domain name through CNAME
  • C. Enable a security group, and reject ICMP for public network access.
  • D. Enable a security group and only allow access from ports 80 and 25 of the public network through TCP

Answer: B

 

NEW QUESTION 28
Alibaba Cloud's Content Moderation service cannot detect advertising or spam content.

  • A. True
  • B. False

Answer: B

 

NEW QUESTION 29
Users can detach the Security Center client on Alibaba Cloud ECS instances, and reinstall it later when necessary.

  • A. True
  • B. False

Answer: A

 

NEW QUESTION 30
Data transfer between Internet devices requires specific specifications, which are called "protocols" Among those, the invention of a certain protocol played a decisive role in the creation of the Internet. By using those protocols, tens of thousands of computers can be connected and communicate with each other What is the following protocol is not defined in OSI 7 layer model?

  • A. UDP
  • B. SOAP
  • C. TCP
  • D. HTTP

Answer: B

 

NEW QUESTION 31
You have helped a customer set up a content filtering solution based on Content Moderation service However, the customer is complaining that certain images are getting incorrectly flagged as pornographic content. What can you do to help fix this?

  • A. Open a ticket with Alibaba Cloud support, and send them a copy of the images, so that they can tune Content Moderation's detection algorithms
  • B. Ask your customer to use different images on their site
  • C. Modify the images until Content Moderation service starts marking them as pornographic.
  • D. Create an "Image Library" from the Content Moderation console and add the images to the Image Library's whitelist

Answer: D

 

NEW QUESTION 32
When applying for an SSL certificate through Alibaba Cloud's SSL Certificates Service, there is an offline review process which can take 3-5 business days or 5-7 business days depending on the type of certificate you have applied for:

  • A. True
  • B. False

Answer: A

 

NEW QUESTION 33
If an ECS instance needs to be accessed by other applications from internet, a corresponding "port" must be enabled For example, HTTP applications work on port 80, while FTP applications work on port 21 If an administrator configures network security policies for this ECS instance, which of the following policies is the safest?

  • A. The administrator wants to build multiple applications on an ECS instance. For easy management, the administrator uses default settings and allows any IP address to access required service ports
  • B. After buying an ECS instance, the administrator immediately enables the security group firewall on the console and opens all ports for public networks
  • C. After buying an ECS instance, the administrator immediately enables the security group firewall on the console and opens only the required service ports for public networks
  • D. After buying an ECS instance, the administrator immediately enables the security group firewall on the console and opens ports 0-1024 for public networks

Answer: C

 

NEW QUESTION 34
The ScheduleKeyDeletion function lets you schedule a time to delete Key Management Service (KMS) keys.
How far in the future can a key deletion event be scheduled?

  • A. 15 days
  • B. 60 days
  • C. 7 days
  • D. 30 days

Answer: A

 

NEW QUESTION 35
When you receive a security alert from Alibaba Cloud Security Center, which of the following actions should you do?

  • A. Once you receive an alert, you need to determine the specific risk and perform troubleshooting For example, change the password, or upgrade application software
  • B. The alert is dangerous You must immediately report it to the police
  • C. There is no need to care about the alert Alibaba Cloud Security Center will handle it.
  • D. Shield the alert because it is not important

Answer: A

 

NEW QUESTION 36
When the agent of Alibaba Cloud Security Center running on a server, it normally uses less than 1% of the CPU and 10 MB of memory, which can void affecting the server's performance

  • A. True
  • B. False

Answer: A

 

NEW QUESTION 37
Alibaba Cloud WAF is a security protection product based on Alibaba Group's web security defense experience accumulated over more than a decade By defending against common OWASP attacks, providing patches to fix vulnerabilities, and allowing users to customize protection policies for website services, WAF can successfully safeguard the security and availability of websites and web applications. Which of the following types of security configurations does WAF provide? (Number of correct answers 3)

  • A. Port access control
  • B. Web application attack protection
  • C. Precision access control
  • D. CC protection

Answer: A,B,D

 

NEW QUESTION 38
Which of the following features are available in Alibaba Cloud Anti-DDoS Premium product? (Number of correct answers: 3)

  • A. Transport layer DDoS protection
  • B. Malformed packets filtering
  • C. Web application layer DDoS protection
  • D. SQL injection Attack blocking

Answer: A,B,C

 

NEW QUESTION 39
User A is the system administrator of a company, who often takes business trips to Shanghai Each time when he remotely logs on to the Shanghai an alert is reported, prompting "Someone is remotely logging on to the server Please pay attention to your server security" Which of the following methods can be used to quickly and automatically resolve this issue?

  • A. Ask the company leaders for help
  • B. Log on to the Alibaba Cloud Security Center, and add a frequent logon location to the configuration item of Security Center.
  • C. Call a friend, who is a famous hacker in the industry, for help.
  • D. Open a ticket immediately to consult Alibaba Cloud engineers

Answer: B

 

NEW QUESTION 40
The protection rules of Alibaba Cloud WAF are updated in real time after a user makes changes in WAF configuration page.

  • A. True
  • B. False

Answer: A

 

NEW QUESTION 41
Your applications are deployed on Alibaba Cloud ECS instances. You want to collect indicators by yourself for application layer monitoring. Which of the following functions provided by Alibaba Cloud CloudMonitor can be used for indicator collection, aggregation, and alerting?

  • A. Site monitoring
  • B. Custom monitoring
  • C. Cloud service monitoring
  • D. CloudMonitor cannot meet these requirements

Answer: B

 

NEW QUESTION 42
What are some of the products that support integration with Alibaba Cloud's SSL Certificates Service (Number of correct answers: 3)

  • A. Server Load Balancer (SLB)
  • B. ApsaraDB for RDS
  • C. Secure Content Distribution Network (SCDN)
  • D. Content Distribution Network (CDN)

Answer: A,C,D

 

NEW QUESTION 43
When users log on to ECS instances through SSH or remote desktop from public Internet, Alibaba Cloud Security Center will monitor the log on behaviors If an IP address uses incorrect password to log on to an ECS instance for too many times, an alert "ECS instance suffers brute force password cracking" will be prompted If you receive this alert, which of the following is the safest way to handle this alert?

  • A. Inform all users on the service platform of changing their passwords, and eliminate simple passwords using technical measures
  • B. This alert does not matter and can be ignored.
  • C. Log on immediately to the ECS instance and check the logon logs If no abnormal logon success record is found ignore this alert.
  • D. Update the system user password immediately for the ECS instance, and enable the security group firewall to allow only specified IP addresses to connect to the ECS instance

Answer: D

 

NEW QUESTION 44
Before using the HTTPS protection feature in Alibaba Cloud WAF, you must upload the server certificate and private key beforehand.

  • A. True
  • B. False

Answer: A

 

NEW QUESTION 45
......

ACP-Sec1 Dumps for Pass Guaranteed - Pass ACP-Sec1 Exam: https://www.itpass4sure.com/ACP-Sec1-practice-exam.html