[Sep-2021] Valid Way To Pass Huawei Exam Dumps with H12-722-ENU Exam Study Guide
All H12-722-ENU Dumps and HCIP-Security-CSSN(Huawei Certified ICT Professional -Constructing Service Security Network) Training Courses Help candidates to study and pass the Exams hassle-free!
NEW QUESTION 105
If the user's FTP operation matches the FTP filtering policy, which actions can be performed? (Multiple choice)
- A. Alerts
- B. Execution
- C. Blocking
- D. Announcement
Answer: A,C
NEW QUESTION 106
USG6000V software logical architecture is divided into three planes: the management plane, control plane, and _______.
- A. service plane
- B. log plane
- C. data forwarding plane
- D. configuration plane
Answer: C
NEW QUESTION 107
When a device identifies a keyword during content filtering detection, what response actions can the device perform? (Multiple Choice)
- A. Alarm
- B. Operate by weight
- C. Blocking
- D. Announcement
Answer: A,B,C
NEW QUESTION 108
With the continuous development of the network and the ever-changing applications, enterprise users have begun to transfer files on the network more and more frequently, and the resulting virus threats are also increasing. Only when the company rejects viruses outside the network can it ensure data security and system stability.
So, which of the following are the possible harms of the virus? (Multiple choices)
- A. Control host permissions, steal user data, and some viruses can even damage the host hardware.
- B. Threatening user host and network security.
- C. Some viruses can be used as invasive tools (such as the Trojan horse virus).
- D. Huawei USG6000 product can easily pass the defense.
Answer: A,B,C
NEW QUESTION 109
Which of the following options does not pose security threat to the network?
- A. Poor personal safety awareness
- B. The virus database was not updated in time
- C. Open company confidential documents
- D. Hacking
Answer: C
NEW QUESTION 110
Which of the following is the correct about computer virus?
- A. The computer virus is latent. It may be lurking for a long time. It will only begin to perform sabotage if certain conditions are met.
- B. All computer viruses must be parasitic in files and cannot exist independently
- C. The computer virus is contagious. It can spread through floppy disks and optical disks but it does not spread through the network.
- D. Patching the system can completely solve the problem of virus intrusion
Answer: A
NEW QUESTION 111
Divert traffic using BGP protocol. The configuration command is as follows.
[sysname] route-policy 1 permit node 1
[sysname-route-policy] apply community no-advertise
[sysname-route-policy] quit
[sysname] bgp 100
[sysname-bgp] peer 7.7.1.2 as-number 100
[sysname-bgp] import-route unr
[sysname-bgp] ipv4-family unicast
[sysname-bgp-af-ipv4] peer 7.7.1.2 route-policy 1 export
[sysname-bgp-af-ipv4] peer 7.7.1.2 advertise-community
[sysname-bgp-af-ipv4] quit
[sysname-bgp] quit
Which of the following options are correct for the BGP drainage configuration description? (Multiple choice)
- A. The management center does not need to configure protection objects. When an attack is discovered, the traffic diversion task is automatically delivered.
- B. Use BGP to advertise UNR routes for dynamic traffic diversion.
- C. You also need to configure the firewall ddos bgp-next-hop fib-filter command to implement the remarks.
- D. After receiving the UNR route, the peer neighbor will not send it to any BGP neighbors.
Answer: B,D
NEW QUESTION 112
Huawei NIP6000 products have zero-setting network parameters and plug-and-play functionality because interfaces pairs only work on Layer 2 and do not need to set IP address.
- A. True
- B. False
Answer: A
NEW QUESTION 113
If you combine security defenses with big data technologies, which of the following statements is correct? (Multiple choice)
- A. The security source data can come from many places, including data flows, packets, threat events, logs, and so on.
- B. During the learning process, we should start with collecting samples, analyze their characteristic vectors, and then perform machine learning.
- C. Machine learning is only for statistics of a large number of samples, which is convenient for security administrators to view.
- D. During the detection process, the unknown sample needs to be extracted and the corresponding model is calculated to provide a sample for subsequent static comparison.
Answer: A,B,D
NEW QUESTION 114
Which of the following are the possible causes for the failure to include a signature after the IPS policy is configured? (Multiple choices)
- A. Direction is not enabled
- B. Severity configuration is too high
- C. Incorrect protocol selection
- D. Direction opened, but no specific direction was chosen
Answer: B,C,D
NEW QUESTION 115
The core technology of content security lies in anomaly detection. The idea of defense lies in continuous monitoring and analysis.
- A. True
- B. False
Answer: A
NEW QUESTION 116
Due to the differences in network environment and system security policies, intrusion detection systems also differ in their implementation.
In terms of system composition, what are the four major components?
- A. Event recording, intrusion analysis, intrusion response, and remote management.
- B. Event extraction, intrusion analysis, reverse intrusion, and remote management.
- C. Event extraction, intrusion analysis, intrusion response, and field management.
- D. Event extraction, intrusion analysis, intrusion response, and remote management.
Answer: D
NEW QUESTION 117
Which of the following are typical intrusions? (Multiple choices)
- A. The power supply in the equipment room is abnormally interrupted
- B. Computer is infected by U disk virus
- C. Tampering Web pages
- D. Copy/View Sensitive Data
Answer: C,D
NEW QUESTION 118
Which of the following is correct about the order of the file filtering technology process?
(1) Security policy application is permit
(2) Protocol decoding
(3) File Type Identification
(4) Application identification
(5) File Filtering
- A. (1) (3) (2) (4) (5)
- B. (1) (2) (3) (4) (5)
- C. (1) (4) (2) (3) (5)
- D. (1) (2) (4) (3) (5)
Answer: C
NEW QUESTION 119
Attacks against the Web can be divided into three attacks on the client, server or communication channel.
- A. True
- B. False
Answer: A
NEW QUESTION 120
The RBL black and white list query result on the firewall is as follows:
Based on the above information, which of the following statements is correct? (Multiple choices)
- A. Mail with source address 10.17.1.0/24 will be released
- B. Mail with source address 10.18.1.0/24 will be released
- C. Mail with source address 10.17.1.0/24 will be blocked
- D. Mail with source address 10.18.1.0/24 will be blocked
Answer: A,B
NEW QUESTION 121
Which of the following statements is wrong about anti-spam answerback codes?
- A. Release the message if the answerback code does not reply to or the replied answerback code is not configured on the USG.
- B. The answerback code will be different for different RBL service providers.
- C. The answerback code is uniformly set as 127.0.0.1.
- D. USG treats the mail that matches the answerback code as spam.
Answer: C
NEW QUESTION 122
Which of the following statement is wrong about a network intrusion detection system (NIDS)?
- A. Real-time monitoring through network adapters and analysis of all communication traffic through the network;
- B. Use newly received network packets as a data source;
- C. Mainly used for real-time monitoring of critical network path information, listening to all packets on the network, collecting data, and analyzing suspicious objects
- D. Used to monitor network traffic and can be deployed independently.
Answer: B
NEW QUESTION 123
Which of the following is correct about special packets attack?
- A. The special control packets attack is a potential attack and does not have direct destruction.
- B. Attacks on special control packets can only use ICMP to construct attack packets.
- C. The attacker probes the network structure by sending special control packets to launch real attack.
- D. Attacks on special control packets do not have the ability to detect network structures. Only scanning-type attacks can detect the network.
Answer: A
NEW QUESTION 124
......
Get Latest [Sep-2021] Conduct effective penetration tests using ExamBoosts H12-722-ENU