
Get Latest [Sep-2021] Conduct effective penetration tests using TestBraindump H12-722
Penetration testers simulate H12-722 exam PDF
NEW QUESTION 11
The configuration commands for enabling the attack defense function are as follows:
[FW] anti-ddos syn-flood source-detect
[FW] anti-ddos udp-flood dynamic-fingerprint-learn
[FW] anti-ddos udp-frag-flood dynamic-fingerprint-learn
[FW] anti-ddos http-flood defend alert-rate 2000
[FW] anti-ddos http-flood source-detect mode basic
Which of the following are the correct descriptions of the attack prevention configuration? (Multiple Choices)
- A. The threshold value enabled by HTTP Flood defense is 2000.
- B. The firewall uses the first packet discard to defense the UDP flood attacks.
- C. HTTP flood attack defense uses enhanced mode for defense.
- D. SYN Flood source detection and prevention function is enabled on the firewall.
Answer: A,D
NEW QUESTION 12
About the description of the file filtering technology in the USG6000, which statement is wrong?
- A. Even if the file type is modified, it can recognize the true type of the file.
- B. It supports the filtering of the decompressed contents of the compressed file.
- C. It can identify the application hosting the file, the file transfer direction, the file type, and the file extension.
- D. It can identify the types of files transmitted by itself and can block, alert and announce specific type of files.
Answer: D
NEW QUESTION 13
After the IP policy is enabled, some services are found to be inaccessible. Which of the following may be the cause? (Multiple Choice)
- A. Too much traffic causes the bypass function to be enabled
- B. IPS missed
- C. The same packet passes through the firewall multiple times
- D. Only one direction of packets goes through the firewall
Answer: C,D
NEW QUESTION 14
Which of the following options does not belong to the basic DDoS attack prevention configuration process?
- A. The system starts attack defense.
- B. The system performs preventive actions.
- C. The system is associated to configurate application for fingerprint learning.
- D. The system starts traffic statistics.
Answer: C
NEW QUESTION 15
With the continuous development of the network and the ever-changing applications, enterprise users have begun to transfer files on the network more and more frequently, and the resulting virus threats are also increasing. Only when the company rejects viruses outside the network can it ensure data security and system stability.
So, which of the following are the possible harms of the virus? (Multiple choices)
- A. Control host permissions, steal user data, and some viruses can even damage the host hardware.
- B. Threatening user host and network security.
- C. Some viruses can be used as invasive tools (such as the Trojan horse virus).
- D. Huawei USG6000 product can easily pass the defense.
Answer: A,B,C
NEW QUESTION 16
Which of the following statements is wrong about HTTP behavior?
- A. When the size of the uploaded or downloaded file or the size of the POST operation reaches the blocking threshold, the system will only block uploads or subsequent file and POST operations.
- B. HTTP POST is generally used to send information to the server through a web page, such as forum posting, form submission, username/password login.
- C. When the size of the uploaded or downloaded file or the size of the POST operation reaches the alarm threshold, the system generates log information to prompt the device administrator and block the action.
- D. When the file upload operation is allowed, alarm thresholds and blocking thresholds can be configured to control the uploaded file size.
Answer: A
NEW QUESTION 17
Which of the following statement about IPS is wrong?
- A. The covering signature has a higher priority than the signature in a centralized signature.
- B. Changes to the IPS policy do not take effect immediately. You need to submit a compilation to update the configuration of the IPS policy.
- C. The signature set can contain both pre-defined and custom signatures.
- D. When the source security zone is the same as the destination security zone, the IPS policy is applied in the domain.
Answer: C
NEW QUESTION 18
When the AntiDDoS system detects attack traffic, the attack traffic is directed to the cleaning device. After the cleaning device completes cleaning, the traffic is re-injected to the original link. Which of the following options does not belong to the injection method?
- A. GRE injection
- B. Policy Routing injection
- C. BGP injection
- D. MPLS LSP injection
Answer: C
NEW QUESTION 19
USG6000V software logical architecture is divided into three planes: the management plane, control plane, and _______.
- A. service plane
- B. log plane
- C. data forwarding plane
- D. configuration plane
Answer: C
NEW QUESTION 20
When misuse detection techniques are used, false positives are reported if the normal user behavior matches the intrusion signature repository successfully.
- A. True
- B. False
Answer: A
NEW QUESTION 21
The Huawei USG6000 product can identify the actual types of common files and filter inspection to content. Even if the file is hidden in a zip file, or if you change the extension, you can't escape the eyes of the firewall.
- A. True
- B. False
Answer: A
NEW QUESTION 22
Which of the following are true about the description of keywords? (Multiple Choices)
- A. The minimum length of a keyword that a text can match is 2 bytes.
- B. Keywords include predefined keywords and custom keywords.
- C. Keywords are content that the device needs to recognize when content is filtered.
- D. Custom keywords can only be defined in text mode.
Answer: B,C
NEW QUESTION 23
The implementation of the content security filtering technology requires the support of the content security combination license.
- A. True
- B. False
Answer: A
NEW QUESTION 24
For the basic mode of HTTP Flood Source authentication, which of the following are the correct descriptions? (Multiple choices)
- A. When there is an HTTP proxy server in the network, the firewall will add the proxy server IP address to the whitelist, but the basic source authentication of the zombie host is still valid.
- B. The basic mode effectively blocks access from non-browser clients.
- C. The basic mode will not affect the user experience, so the defense effect is higher than the enhanced mode.
- D. The zombie tool does not implement a complete HTTP protocol stack and does not support automatic redirection. Therefore, the basic mode can effectively defend against HTTP flood attacks.
Answer: B,D
NEW QUESTION 25
URL filtering technology can access control URLs for users according to different time objects and address objects, and achieve the purpose of accurately managing user online behavior.
- A. TRUE
- B. FALSE
Answer: A
NEW QUESTION 26
Regarding the local black and white list of anti-spam messages, which of the following statements is wrong?
- A. The black and white list is matched by the sender's dns suffix
- B. Black and white lists are matched by extracting the source IP address of the SMTP connection
- C. The black and white list is matched by extracting the destination IP address of the SMTP connection
- D. Block the connection if the source IP address of the SMTP connection matches the blacklist
Answer: A
NEW QUESTION 27
Which descriptions about viruses and Trojans are correct? (Multiple Choice)
- A. Viruses are triggered by computer users
- B. Virus can self-replicate
- C. Trojans can self-replicate
- D. Trojans triggered by computer users
Answer: A,B
NEW QUESTION 28
Which of the following options does not pose security threat to the network?
- A. Poor personal safety awareness
- B. The virus database was not updated in time
- C. Open company confidential documents
- D. Hacking
Answer: C
NEW QUESTION 29
If you combine security defenses with big data technologies, which of the following statements is correct? (Multiple choice)
- A. The security source data can come from many places, including data flows, packets, threat events, logs, and so on.
- B. During the learning process, we should start with collecting samples, analyze their characteristic vectors, and then perform machine learning.
- C. Machine learning is only for statistics of a large number of samples, which is convenient for security administrators to view.
- D. During the detection process, the unknown sample needs to be extracted and the corresponding model is calculated to provide a sample for subsequent static comparison.
Answer: A,B,D
NEW QUESTION 30
Which of the following is correct regarding the order of the mail transfer process?
1. The sending PC sends the mail to the specified SMTP server.
2. The sender SMTP Server encapsulates the mail information in the SMTP message and sends it to the receiver SMTP according to the destination address of the mail.
Server.
3. The sender SMTP Server encapsulates the mail information in the SMTP message and sends it to the receiver POP3/MAP Server based on the destination address of the mail.
4. Recipients send emails.
- A. 1->4->3
- B. 1->2->3
- C. 1->2->4
- D. 1->3->4
Answer: C
NEW QUESTION 31
The whitelist rule of the firewall antivirus module is configured as *example*. Which of the following matches is used in this configuration?
- A. Suffix matching
- B. Keyword matching
- C. Prefix matching
- D. exact match
Answer: B
NEW QUESTION 32
What are the following descriptions of the role of content security filtering technology? (Multiple choices)
- A. E-mail filtering refers to the management and control of e-mail sending and receiving activities, including the prevention of spam and the proliferation of anonymous e-mails, and the control of illegal sending and receiving.
- B. Content filtering prevents the leakage of confidential information and the transmission of non-compliant information.
- C. File Filtering By blocking the transmission of certain types of files, you can reduce the risk of internal networks running malicious code and viruses. You can also prevent employees from leaking corporate confidential files to the Internet.
- D. The application behavior control function can finely control the common HTTP behavior and FTP behavior.
Answer: A,B,C,D
NEW QUESTION 33
Which of the following are the possible causes for the failure to include a signature after the IPS policy is configured? (Multiple choices)
- A. Direction is not enabled
- B. Severity configuration is too high
- C. Incorrect protocol selection
- D. Direction opened, but no specific direction was chosen
Answer: B,C,D
NEW QUESTION 34
Analysis is the core function of intrusion detection. The analysis process of intrusion detection can be divided into three phases. The analyzer is built to analyze, feedback and refine the actual field data.
Which of these are the functions included in the first two phases?
- A. Data Processing, Attack Classification, Post Processing
- B. Data Analysis, Data Classification, Post Processing
- C. Data Processing, Data Classification, Attack Playback
- D. Data Processing, Data Classification, Post Processing
Answer: D
NEW QUESTION 35
What are the risks to information security caused by unauthorized access? (Multiple choices)
- A. Availability
- B. Confidentiality
- C. Integrity
- D. recoverability
Answer: B,C
NEW QUESTION 36
......
Tested Material Used To H12-722 Test Engine: https://www.testbraindump.com/H12-722-exam-prep.html
