Huawei H12-722 Practice Verified Answers - Pass Your Exams For Sure! [2021]
Valid Way To Pass HCNP-Security's H12-722 Exam
NEW QUESTION 93
Why APT attacks are difficult to defend? Part of the reason is that they use zero-day loopholes to attack. This zero-day loopholes usually takes a lot of time to research and analyze and make corresponding defense methods.
- A. True
- B. False
Answer: A
NEW QUESTION 94
The RBL black and white list query result on the firewall is as follows:
Based on the above information, which of the following statements is correct? (Multiple choices)
- A. Mail with source address 10.17.1.0/24 will be released
- B. Mail with source address 10.18.1.0/24 will be released
- C. Mail with source address 10.17.1.0/24 will be blocked
- D. Mail with source address 10.18.1.0/24 will be blocked
Answer: A,B
NEW QUESTION 95
Which of the following statement about IPS is wrong?
- A. The covering signature has a higher priority than the signature in a centralized signature.
- B. Changes to the IPS policy do not take effect immediately. You need to submit a compilation to update the configuration of the IPS policy.
- C. The signature set can contain both pre-defined and custom signatures.
- D. When the source security zone is the same as the destination security zone, the IPS policy is applied in the domain.
Answer: C
NEW QUESTION 96
Which of the following is not an abnormal condition of the file type recognition result?
- A. File damage
- B. File extension does not match
- C. The file type is not recognized
- D. Files are compressed
Answer: D
NEW QUESTION 97
Which of the following options does not belong to the basic DDoS attack prevention configuration process?
- A. The system starts attack defense.
- B. The system performs preventive actions.
- C. The system is associated to configurate application for fingerprint learning.
- D. The system starts traffic statistics.
Answer: C
NEW QUESTION 98
Which of the following statements about intrusion detection/defense devices are correct? (Multiple Choice)
- A. Can quickly adapt changes in threats.
- B. Protect the intranet from external attacks and suppress malicious traffic, such as spyware, worms, etc., flooding and spreading to the intranet.
- C. Can't effectively resist the spread of viruses from the Internet to the Intranet.
- D. NIP6000 can identify applications up to 6000+, implement fine-grained application protection, save export bandwidth, and ensure the business experience of key services.
Answer: A,B,D
NEW QUESTION 99
Huawei USG6000 product can virus scan and process certain file transfer protocols, but which of the following protocol does not include?
- A. FTP
- B. POP3
- C. IMAP
- D. TFTP
Answer: D
NEW QUESTION 100
In the Huawei USG6000 product, after the security profile is created or modified, the configuration does not take effect immediately. You need to click "Submit" in the upper right corner of the page to activate it.
- A. True
- B. False
Answer: A
NEW QUESTION 101
The IPS process has the following steps:
1. Reorganize application data
2. Match signature
3. Message processing
4. Protocol identification
Which of the following is the correct ordering for the processing?
- A. 1-3-2-4
- B. 2-4-1-3
- C. 4-1-2-3
- D. 1-4-2-3
Answer: D
NEW QUESTION 102
Which of the following are the control items for HTTP behavior? (Multiple Choice)
- A. Acting on the Internet
- B. POST operation
- C. Browse the web
- D. File Upload and Download
Answer: A,B,C,D
NEW QUESTION 103
Which of the following statements is wrong about anti-spam answerback codes?
- A. Release the message if the answerback code does not reply to or the replied answerback code is not configured on the USG.
- B. The answerback code will be different for different RBL service providers.
- C. The answerback code is uniformly set as 127.0.0.1.
- D. USG treats the mail that matches the answerback code as spam.
Answer: C
NEW QUESTION 104
Divert traffic using BGP protocol. The configuration command is as follows.
[sysname] route-policy 1 permit node 1
[sysname-route-policy] apply community no-advertise
[sysname-route-policy] quit
[sysname] bgp 100
[sysname-bgp] peer 7.7.1.2 as-number 100
[sysname-bgp] import-route unr
[sysname-bgp] ipv4-family unicast
[sysname-bgp-af-ipv4] peer 7.7.1.2 route-policy 1 export
[sysname-bgp-af-ipv4] peer 7.7.1.2 advertise-community
[sysname-bgp-af-ipv4] quit
[sysname-bgp] quit
Which of the following options are correct for the BGP drainage configuration description? (Multiple choice)
- A. The management center does not need to configure protection objects. When an attack is discovered, the traffic diversion task is automatically delivered.
- B. Use BGP to advertise UNR routes for dynamic traffic diversion.
- C. You also need to configure the firewall ddos bgp-next-hop fib-filter command to implement the remarks.
- D. After receiving the UNR route, the peer neighbor will not send it to any BGP neighbors.
Answer: B,D
NEW QUESTION 105
The administrator defines two keywords that need to be identified on the firewall. The keyword x has a weight value of 2, the keyword y has a weight value of 3, and the content filtering alarm threshold is 5 (blocking threshold) 10. If the device detects that there is a keyword x in the page viewed by the user, the two keywords are Y;
What is the following statement about the value of weights and the behavior of users visiting web pages?
- A. The weight value is 10 and you can access the web page.
- B. The weight value is 10 and you cannot access the web page.
- C. The weight value is 8 and you can access the web page.
- D. The weight value is 8 and you cannot access the web page.
Answer: C
NEW QUESTION 106
Which of the following is a false positive for an intrusion detection system?
- A. Web-based attacks have not been detected by the system
- B. Use Ping for network detection and being alerted as an attack
- C. The process of trying to log in to the system was recorded
- D. Unable to detect new worms
Answer: B
NEW QUESTION 107
Traditional firewalls have weak application layer analysis and processing capabilities, and cannot correctly analyze malicious code that is doped in the allowable application data stream. Many attacks or malicious behavior often use firewall open application data streams to cause damage, resulting in application layers threat can penetrate the firewall.
- A. TRUE
- B. FALSE
Answer: A
NEW QUESTION 108
The application behavior control configuration file takes effect immediately after reference, without configuring the submission.
- A. True
- B. False
Answer: A
NEW QUESTION 109
The configuration commands for enabling the attack defense function are as follows:
[FW] anti-ddos syn-flood source-detect
[FW] anti-ddos udp-flood dynamic-fingerprint-learn
[FW] anti-ddos udp-frag-flood dynamic-fingerprint-learn
[FW] anti-ddos http-flood defend alert-rate 2000
[FW] anti-ddos http-flood source-detect mode basic
Which of the following are the correct descriptions of the attack prevention configuration? (Multiple Choices)
- A. The threshold value enabled by HTTP Flood defense is 2000.
- B. The firewall uses the first packet discard to defense the UDP flood attacks.
- C. HTTP flood attack defense uses enhanced mode for defense.
- D. SYN Flood source detection and prevention function is enabled on the firewall.
Answer: A,D
NEW QUESTION 110
Which of the following is correct regarding the order of the mail transfer process?
1. The sending PC sends the mail to the specified SMTP server.
2. The sender SMTP Server encapsulates the mail information in the SMTP message and sends it to the receiver SMTP according to the destination address of the mail.
Server.
3. The sender SMTP Server encapsulates the mail information in the SMTP message and sends it to the receiver POP3/MAP Server based on the destination address of the mail.
4. Recipients send emails.
- A. 1->4->3
- B. 1->2->3
- C. 1->2->4
- D. 1->3->4
Answer: C
NEW QUESTION 111
When configure the URL filtering configuration file, www.bt.com is configured in the URL blacklist, and URL is set to *bt.com in the custom URL classification, and the action for customizing the URL classification is warning. .
Which of the following statements is true about the above configuration? (Multiple choices)
- A. Users can visit www.bt.com website, but administrators will receive warning message.
- B. Users can't access all websites ending with bt.com.
- C. Users will be blocked when they visit www.bt.com.
- D. Users can visit www.videobt.com.
Answer: C,D
NEW QUESTION 112
The following is a description of black and white lists in spam filtering. Which option is wrong?
- A. Enter the IP address and mask of the whitelisted SMTP server in the Whitelist text box. You can enter multiple IP addresses, one IP address one line.
- B. Configure a local blacklist or whitelist: You can configure both blacklist and whitelist at the same time, or you can configure only one of them.
- C. Enter the IP address and mask of the blacklist SMTP server in the Blacklist text box. You can enter multiple IP addresses, one IP address one line.
- D. The priority of the blacklist is higher than that of the whitelist.
Answer: D
NEW QUESTION 113
IPS can't detect which of the following threats?
- A. Worm
- B. DoS
- C. Virus
- D. Spam
Answer: D
NEW QUESTION 114
Information security is the protection of information and information systems against unauthorized access, use, disclosure, interruption, modification, destruction and thereby providing confidentiality, integrity and availability.
- A. True
- B. False
Answer: A
NEW QUESTION 115
......
Huawei H12-722 Pre-Exam Practice Tests | Lead1Pass: https://www.lead1pass.com/Huawei/H12-722-practice-exam-dumps.html