
Updated Aug-2021 Test Engine to Practice Test for H12-722-ENU Exam Questions and Answers!
HCIP-Security-CSSN(Huawei Certified ICT Professional -Constructing Service Security Network) Certification Sample Questions and Practice Exam
NEW QUESTION 50
Viruses can damage computer systems and falsify or damage business data: Spyware collects, use and disseminate sensitive information from employees. These malicious software seriously interfere with the normal business operations of enterprises. Desktop anti-virus software can solve the problem of viruses and spyware globally.
- A. False
- B. True
Answer: A
NEW QUESTION 51
For the description of the AntiDDoS system, which of the following option is correct?
- A. The detection center mainly uses the control strategy of the security management center to perform traction and cleaning of the attack traffic. The normal traffic after cleaning is injected back to the customer network and sent to the real destination.
- B. The management center mainly completes the processing of attack events, controls the flow policy and cleaning policy of the cleaning center, and classifies various attack events and attack traffic to generate reports
- C. The main role of the cleaning center is to detect and analyze the DDoS attack traffic for the mirrored or light splitting traffic and provide the analysis data to the management center for judgment.
- D. The firewall can only be a detection device.
Answer: B
NEW QUESTION 52
When you suspect that the corporate network is being attacked by hackers, you have conducted technical investigations.
Which of the following options does not belong to the pre-attack behavior?
- A. Web Application attack
- B. Brute force cracking
- C. Planting Malware
- D. Loophole attack
Answer: C
NEW QUESTION 53
Which of the following are the keyword matching patterns? (Multiple Choice)
- A. Regular expressions
- B. Community word
- C. Custom Keywords
- D. Text
Answer: A,D
NEW QUESTION 54
Which of the following options is incorrect for the IntelliSense engine IAE?
- A. English full name: Intelligent Awareness Engine.
- B. The core of IAE is to organically integrate all content security related detection functions.
- C. IAE's content security detection capabilities include application identification and awareness, intrusion prevention, and Web application security.
- D. IAE engine's security detection is parallel and uses a message-based file processing mechanism that can receive file fragments and perform security checks.
Answer: D
NEW QUESTION 55
The implementation of the content security filtering technology requires the support of the content security combination license.
- A. True
- B. False
Answer: A
NEW QUESTION 56
Which of the following statement about IPS is wrong?
- A. The covering signature has a higher priority than the signature in a centralized signature.
- B. Changes to the IPS policy do not take effect immediately. You need to submit a compilation to update the configuration of the IPS policy.
- C. The signature set can contain both pre-defined and custom signatures.
- D. When the source security zone is the same as the destination security zone, the IPS policy is applied in the domain.
Answer: C
NEW QUESTION 57
UDP is a connectionless protocol. A large number of UDP flood attacks cause the performance of network devices that rely on session forwarding to be degraded and even the session table is exhausted, causing network congestion.
Which of the following options does not prevent UDP flood attacks?
- A. First packet discarded
- B. Current limiting
- C. UDP fingerprint learning
- D. Associated defense
Answer: A
NEW QUESTION 58
The application behavior control configuration file takes effect immediately after reference, without configuring the submission.
- A. True
- B. False
Answer: A
NEW QUESTION 59
Which of the following are the control items for HTTP behavior? (Multiple Choice)
- A. Acting on the Internet
- B. POST operation
- C. Browse the web
- D. File Upload and Download
Answer: A,B,C,D
NEW QUESTION 60
In Huawei's USG6000 products, IAE provides an integrated solution. All content security detection functions are integrated in a well-designed, high-performance engine.
Which of the following is not a content security detection feature that the product supports?
- A. Application identification and awareness
- B. Video content filtering
- C. Intrusion Prevention
- D. URL classification and filtering
Answer: B
NEW QUESTION 61
Huawei NIP6000 products provide carrier-grade high-reliability mechanisms at multiple levels to ensure the stable operation of the equipment.
Which of the following options belong to the reliability of the network? (Multiple choices)
- A. Link-group
- B. Power 1+1 redundancy backup
- C. Hardware Bypass
- D. Hot Standby
Answer: A,D
NEW QUESTION 62
For the URL is http://www.abcd.com:8080/news/education.aspx?name=tom&age=20, where is the path option?
- A. http://www.abcd.com:8080/news/education.aspx
- B. /news/education.aspx
- C. /news/education.aspx?name=tom&age=20
- D. http://www.abcd.com:8080
Answer: B
NEW QUESTION 63
About the description of the file filtering technology in the USG6000, which statement is wrong?
- A. Even if the file type is modified, it can recognize the true type of the file.
- B. It supports the filtering of the decompressed contents of the compressed file.
- C. It can identify the application hosting the file, the file transfer direction, the file type, and the file extension.
- D. It can identify the types of files transmitted by itself and can block, alert and announce specific type of files.
Answer: D
NEW QUESTION 64
The following is a description of black and white lists in spam filtering. Which option is wrong?
- A. Enter the IP address and mask of the whitelisted SMTP server in the Whitelist text box. You can enter multiple IP addresses, one IP address one line.
- B. Configure a local blacklist or whitelist: You can configure both blacklist and whitelist at the same time, or you can configure only one of them.
- C. Enter the IP address and mask of the blacklist SMTP server in the Blacklist text box. You can enter multiple IP addresses, one IP address one line.
- D. The priority of the blacklist is higher than that of the whitelist.
Answer: D
NEW QUESTION 65
What content can be filtered by the content filtering technology of Huawei USG6000? (Multiple Choices)
- A. File types
- B. Direction of file upload
- C. Keywords contained in the download file
- D. Keywords contained in the uploaded file contents
Answer: C,D
NEW QUESTION 66
Which of the following are true about the e-mail protocol? (Multiple choices)
- A. Use IMAP, the client software download all unread messages to the computer and the mail server deletes the message.
- B. Use IMAP, the user directly operates the mail on the server, and does not need to download all the mails locally and perform various operations.
- C. Use POP3, the client software download all unread messages to the computer and the mail server deletes the message.
- D. Use POP3, the user directly operates the mail on the server, and does not need to download all the mails locally and perform various operations.
Answer: B,C
NEW QUESTION 67
For the Huawei USG6000 product, which of the following statements about mail filtering configuration is correct?
- A. When the processing actions and alarms for spam emails are blocked, the emails will be blocked and an alarm will be generated.
- B. You can control the size of the attachments that receive mail
- C. Unable to filter incoming mail for keyword.
- D. Cannot control the number of incoming email attachments
Answer: B
NEW QUESTION 68
Which of the following attack types is DDoS attack?
- A. Traffic attack
- B. Malformed packet attack
- C. Single package attack
- D. Snooping scanning attack
Answer: A
NEW QUESTION 69
What are the risks to information security caused by unauthorized access? (Multiple choices)
- A. Availability
- B. Confidentiality
- C. Integrity
- D. recoverability
Answer: B,C
NEW QUESTION 70
Regarding the process of file filtering, which of the following statements is wrong?
- A. The application identification module can identify the type of application hosting the file.
- B. After the file extraction fails, the file will still be filtered.
- C. The file type identification module is responsible for identifying the real type of the file and the extension of the file based on the file data
- D. Protocol decoding is responsible for parsing the file data and file transfer directions in the data stream.
Answer: B
NEW QUESTION 71
The configuration commands for enabling the attack defense function are as follows:
[FW] anti-ddos syn-flood source-detect
[FW] anti-ddos udp-flood dynamic-fingerprint-learn
[FW] anti-ddos udp-frag-flood dynamic-fingerprint-learn
[FW] anti-ddos http-flood defend alert-rate 2000
[FW] anti-ddos http-flood source-detect mode basic
Which of the following are the correct descriptions of the attack prevention configuration? (Multiple Choices)
- A. The threshold value enabled by HTTP Flood defense is 2000.
- B. The firewall uses the first packet discard to defense the UDP flood attacks.
- C. HTTP flood attack defense uses enhanced mode for defense.
- D. SYN Flood source detection and prevention function is enabled on the firewall.
Answer: A,D
NEW QUESTION 72
The Huawei USG6000 product can identify the actual types of common files and filter inspection to content. Even if the file is hidden in a zip file, or if you change the extension, you can't escape the eyes of the firewall.
- A. True
- B. False
Answer: A
NEW QUESTION 73
......
Certification dumps HCNP-Security H12-722-ENU guides - 100% valid: https://www.pass4surecert.com/Huawei/H12-722-ENU-practice-exam-dumps.html