H12-722 exam questions for practice in 2021 Updated 180 Questions [Q58-Q81]

Share

H12-722 exam questions for practice in 2021 Updated 180 Questions

Updated Dec-2021 Premium H12-722 Exam Engine pdf - Download Free Updated 180 Questions

NEW QUESTION 58
Regarding the processing flow of file filtering, which of the following statements is wrong?

  • A. The file type recognition module is responsible for identifying the true type of the file and the file extension based on the file data
  • B. After the file decompression fails, the file will still be filtered. .
  • C. The application identification module can identify the type of application that carries the file.
  • D. Protocol decoding is responsible for analyzing the file data and file transmission direction in the data stream.

Answer: B

 

NEW QUESTION 59
About firewalls and IDS, which of the following is true?

  • A. IDS can't interact with the firewall
  • B. Firewall is unable to detect insider malicious operation or misoperation
  • C. Firewall is a bypass device for fine-grained detection
  • D. IDS is a straight-path device and can't perform depth detection

Answer: B

 

NEW QUESTION 60
What are the typical technologies of anti-virus engines (multiple choice)

  • A. First package detection technology
  • B. File reputation detection technology 5
  • C. Heuristic detection technology
  • D. Decryption technology

Answer: A,B,C

 

NEW QUESTION 61
Which of the following statement about IPS is wrong?

  • A. Changes to the IPS policy do not take effect immediately. You need to submit a compilation to update the configuration of the IPS policy.
  • B. The signature set can contain both pre-defined and custom signatures.
  • C. The covering signature has a higher priority than the signature in a centralized signature.
  • D. When the source security zone is the same as the destination security zone, the IPS policy is applied in the domain.

Answer: B

 

NEW QUESTION 62
Which of the following are typical intrusions? "Multiple choice)

  • A. Copy/view sensitive data
  • B. Abnormal power interruption in the computer room
  • C. Tampering with Web pages
  • D. Computer is infected by U disk virus

Answer: A,C

 

NEW QUESTION 63
Which of the following options is not a cyber security threat caused by weak personal security awareness?

  • A. Disclosure of personal information
  • B. Leaking corporate information
  • C. Threats to the internal network
  • D. Increasing the cost of enterprise network operation and maintenance

Answer: D

 

NEW QUESTION 64
Which of the following descriptions about the black and white lists in spam filtering is wrong?

  • A. Set local blacklist and whitelist: Both blacklist and whitelist can be configured at the same time, or only one of them can be configured.
  • B. Enter the IP address and mask of the SMITP Server to be added to the blacklist in the "Blacklist" text box, you can enter multiple IP addresses, one IP Address one line.
  • C. In the "Whitelist" text box, enter the P address and mask of the SMTP Server to be added to the whitelist. You can enter multiple IP addresses, one IP address Address one line. v
  • D. The priority of the blacklist is higher than that of the whitelist.

Answer: D

 

NEW QUESTION 65
Regarding scanning and snooping attacks, which of the following descriptions is wrong?

  • A. Scanning attacks include address scanning and port scanning.
  • B. When a worm virus breaks out, it is usually accompanied by an address scanning attack, so scanning attacks are offensive.
  • C. It is usually the network detection behavior before the attacker launches the real attack.
  • D. The source address of the scanning attack is real, so it can be defended by adding direct assistance to the blacklist.

Answer: B

 

NEW QUESTION 66
Which of the following attacks are belong to attacks against Web servers? (Multiple choices)

  • A. SQL injection
  • B. Cross-site scripting attacks
  • C. Website fishing fraud
  • D. Website Trojan

Answer: A,B

 

NEW QUESTION 67
Fage attack means that the original address and target address of TOP are both set to the IP address of a certain victim. This behavior will cause the victim to report to it.
SYN-ACK message is sent from the address, and this address sends back an ACK message and creates an empty connection, which causes the system resource board to occupy or target The host crashed.

  • A. True
  • B. False

Answer: B

 

NEW QUESTION 68
Which of the following features are supported by the Huawei NIP intrusion prevention device?

  • A. SSL traffic detection
  • B. Application Identification and Control
  • C. Mail detection
  • D. Virtual Patch

Answer: A,B,D

 

NEW QUESTION 69
When using the misuse check technology, if the normal user behavior is successfully matched with the intrusion feature knowledge base, it will be falsely reported.

  • A. True
  • B. False

Answer: A

 

NEW QUESTION 70
Which of the following options are correct for the description of URPF technology? (Multiple Choices)

  • A. Does not check whether the interfaces match in the strict mode. As long as there is a route to the source address, the packets can pass.
  • B. The main function is to prevent network attacks based on source address spoofing.
  • C. In loose mode, not only the corresponding entries in the forwarding table are required, but also the interfaces must match to pass the URPF check.
  • D. Use the loose mode of URPF in an environment where route symmetry is not guaranteed.

Answer: B,D

 

NEW QUESTION 71
Anti-DDoS defense system includes: management center, detection center and cleaning center.

  • A. True
  • B. False

Answer: A

 

NEW QUESTION 72
The administrator of a certain enterprise wants employees of Yangzhi to visit the shopping website during working hours. So a URL filtering configuration file is configured to divide the predefined The shopping website in the category is selected as blocked. But employee A can still use the company's network to shop online during lunch break. Then what are the following possible reasons some?

  • A. The administrator has not applied the URL pass-through configuration file to the security policy.
  • B. The administrator did not submit the configuration after completing the configuration.
  • C. The shopping website does not belong to the predefined shopping website category
  • D. The administrator has not set the time to vote every day from 9:00 to 18:00

Answer: A,B,C

 

NEW QUESTION 73
Regarding the statement of the mail protocol, which of the following is correct? (multiple choice)

  • A. Use JIMAP; the client software will download all unread mails to the computer, and the mail server will delete the mails.
  • B. Using POP3, the client software will download all unread mails to the computer, and the mail server will delete the mails.
  • C. With IMAP, users can directly operate on the mail on the server, without downloading all the mails locally to perform various operations.
  • D. Using POP3, users can directly operate on the mail on the server without sending all mails to the local to perform various operations.

Answer: B,C

 

NEW QUESTION 74
Among the following options, which attack is a malformed packet attack based on the TCR protocol?

  • A. Teardrop attack
  • B. IP Spoofng attack
  • C. Land attack
  • D. Ping of Death attack

Answer: C

 

NEW QUESTION 75
In the construction of information security, the intrusion detection system plays a role as a monitor. Through monitoring the traffic of critical nodes in the information system, it conducts in-depth analysis and explores the security events that are taking place. Which of the following are its characteristics?

  • A. Cannot perform in-depth inspection
  • B. Malicious code that is doped in allowable application data streams cannot be correctly analyzed.
  • C. IDS can be linked with firewalls and switches to become a powerful "helper" for firewalls to better and more precisely control access between domains.
  • D. Unable to detect malicious operations or mis-operations from insiders.

Answer: C

 

NEW QUESTION 76
Which of the following statements about intrusion detection/defense devices are correct? (Multiple Choice)

  • A. Can quickly adapt changes in threats.
  • B. Can't effectively resist the spread of viruses from the Internet to the Intranet.
  • C. Protect the intranet from external attacks and suppress malicious traffic, such as spyware, worms, etc., flooding and spreading to the intranet.
  • D. NIP6000 can identify applications up to 6000+, implement fine-grained application protection, save export bandwidth, and ensure the business experience of key services.

Answer: A,C,D

 

NEW QUESTION 77
In order to protect the security of data transmission, more and more websites or companies choose to use SSL to encrypt transmissions in the stream. About using Huawei NIP6000 The product performs threat detection on (SSL stream boy, which of the following statements is correct?

  • A. The traffic after threat detection is sent directly to the server without encryption
  • B. NIP can directly crack and detect SSL encryption.
  • C. After the process of "decryption", "threat detection", and "encryption"
  • D. NIP0OO does not support SSL Threat Detection.

Answer: C

 

NEW QUESTION 78
Which of the following options is not cyber security threat posed by weak personal security awareness?

  • A. Leaking corporate information
  • B. Disclosing personal information
  • C. Threat internal network
  • D. Increase the cost of enterprise network operation and maintenance

Answer: D

 

NEW QUESTION 79
Which of the following types of attacks are DDoS attacks? 2I

  • A. Malformed message attack
  • B. Floating child attack
  • C. Single packet attack
  • D. Snooping scan attack

Answer: B

 

NEW QUESTION 80
Which of the following descriptions about viruses and Trojans are correct? (multiple choices)

  • A. Viruses can replicate themselves
  • B. Trojan horses are triggered by computer users
  • C. Viruses are triggered by computer users
  • D. Trojans can replicate themselves

Answer: A,C

 

NEW QUESTION 81
......

Authentic H12-722 Dumps With 100% Passing Rate Practice Tests Dumps: https://evedumps.testkingpass.com/H12-722-testking-dumps.html