Unique Top-selling H12-722_V3.0 Exams - New 2022 Huawei Pratice Exam
HCIP-Security Dumps H12-722_V3.0 Exam for Full Questions - Exam Study Guide
NEW QUESTION 57
Network attacks are mainly divided into two categories: single-packet attacks and streaming attacks.
Single-packet attacks include scanning and snooping attacks, malformed packet attacks, and special reports.
Wen attack.
- A. True
- B. False
Answer: A
NEW QUESTION 58
SACG query right-manager information as follows, which options are correct? (Select 2 answers)
- A. master controller IP address is 2.1.1.1.
- B. master controller IP address is 1.1.1.2.
- C. SACG linkage success with controller.
- D. SACG and IP address 2.1.1.1 server linkage is not successful
Answer: C,D
NEW QUESTION 59
Abnormal detection is to establish the normal behavior characteristic profile of the system subject through the analysis of the audit data of the system: check if the audit data in the system If there is a big discrepancy with the normal behavior characteristics of the established subject, it is considered an intrusion. Nasu must be used as the system subject? (multiple choice)
- A. Host
- B. A group of users
- C. Single user
- D. A key program and file in the system
Answer: A,B,C,D
NEW QUESTION 60
Which of the following options describes the IntelliSense engine IAE incorrectly?
- A. Full English name: intelligent Awareness Engine.
- B. The security detection of the IAE engine is parallel, using a message-based file processing mechanism, which can receive file fragments and perform security checks.
- C. lAE's content security detection functions include application identification and perception, intrusion prevention, and Web application security.
- D. The core of C.IAE is to organically centralize all content security-related detection functions.
Answer: B
NEW QUESTION 61
What content can be filtered by the content filtering technology of Huawei USG6000 products? (multiple choice)
- A. Keywords contained in the downloaded file
- B. File upload direction 335
- C. File type
- D. Keywords contained in the content of the uploaded file
Answer: A,D
NEW QUESTION 62
Huawei WAF products are mainly composed of front-end execution, back-end central systems and databases.
Among them, the database mainly stores the front-end detection rules and black Whitelist and other configuration files.
- A. True
- B. False
Answer: A
NEW QUESTION 63
The anti-virus feature configured on the Huawei USG6000 product does not take effect. Which of the following are the possible reasons? (multiple choice)
- A. The security policy does not reference the anti-virus configuration file.
- B. The virus signature database version is older.
- C. No virus exceptions are configured.
- D. The anti-virus configuration file is configured incorrectly.
Answer: A,B,D
NEW QUESTION 64
Regarding the enhanced mode in HTTP Flood source authentication, which of the following descriptions are correct? Multiple choices
- A. The enhanced mode is superior to the basic mode in terms of user experience.
- B. Enhanced mode refers to the authentication method using verification code.
- C. Enhanced mode supports all HTTP Flood source authentication fields. " WWQQ: 922333
- D. Some bots have a redirection function, or the free proxy used during the attack supports the redirection function, which leads to the failure of the basic mode of defense Effective, enhanced mode can effectively defend.
Answer: B,D
NEW QUESTION 65
Regarding the mail content filtering configuration of Huawei USG6000 products, which of the following statements is wrong?.
- A. When a POP3 message is detected, if it is judged to be an illegal email, the firewall's response action only supports sending alarm information, and will not block the email o
- B. Mail filtering will only take effect when the mail filtering configuration file is invoked when the security policy is allowed.
- C. When an IMAP message is detected, if it is judged to be an illegal email; the firewall's response action only supports sending alarm messages and will not block the email.
- D. The attachment size limit is for a single attachment, not for the total size of all attachments.
Answer: A
NEW QUESTION 66
Which of the following elements does PDCA include? (Choose 3 answers)
- A. Monitoring
- B. Plan
- C. Implementation
- D. termination
Answer: A,B,C
NEW QUESTION 67
Which of the following types of attacks are DDoS attacks? 2I
- A. Snooping scan attack
- B. Single packet attack
- C. Floating child attack
- D. Malformed message attack
Answer: C
NEW QUESTION 68
Which of the following options belong to the upgrade method of the anti-virus signature database of Huawei USG6000 products? (multiple choice)
- A. Online upgrade
- B. Manual upgrade
- C. Local upgrade
- D. Automatic upgrade
Answer: A,C
NEW QUESTION 69
The processing flow of IPS has the following steps;
1. Reorganize application data
2. Match the signature
3. Message processing
4. Protocol identification
Which of the following is the correct order of the processing flow?
- A. 1-4-2-3
- B. 1-3-2-4
- C. 4-1-2-3
- D. 2-4-1-3
Answer: A
NEW QUESTION 70
An enterprise has 3 server, which is the most reasonable plan when deploy Policy Center system planning?
- A. manager + controller + FTP + master database, controller + FTP + witness database, controller + FTP
+ mirror database - B. manager + controller + FTP + witness database, controller + master database + FTP, controller + mirror database+ FTP
- C. manager + controller + FTP, controller + FTP + witness databases, controller + FTP + master database
- D. manager + controller + FTP + mirror database, controller + FTP + witness database, controller + FTP + master database
Answer: B
NEW QUESTION 71
What equipment do Policy Center supported servers include? (Choose 3 answers)
- A. mail server
- B. log collection server
- C. Internet behavior management equipment
- D. remote control device
Answer: A,C,D
NEW QUESTION 72
In the Policy Center strategy configuration, how many violations rating of definition are there?
- A. 0
- B. 1
- C. 2
- D. 3
Answer: B
NEW QUESTION 73
The following figure is a schematic diagram of the detection file of the firewall and the sandbox system linkage.
The Web reputation function is enabled on the firewall, and website A is set as a trusted website and website B is set as a suspicious website.
Which of the following statements is correct
- A. After the detection node detects the suspicious file, it not only informs the firewall in the figure of the result, but also informs other network devices connected to it.
- B. The files obtained by users from website A and website B will be sent to the inspection node for inspection.
- C. When a user visits website B, although the firewall will extract the file and send it to the detection node, the user can still access normally during the detection process Site B.
- D. Assuming that website A is an unknown website, the administrator cannot detect the traffic file of this website sC
Answer: A
NEW QUESTION 74
Which patches does Policy Center support to management?(Choose 3 answers)
- A. Microsoft SQL Windows database patch
- B. android system patches
- C. Microsoft Internet Explorer patches
- D. Microsoft Windows operating system patches
Answer: A,C,D
NEW QUESTION 75
With regard to APT attacks, the attacker often lurks for a long time and launches a formal attack on the enterprise at the key point of the incident.
Generally, APT attacks can be summarized into four stages:
1. Collecting Information & Intrusion
2. Long-term lurking & mining
3. Data breach
4. Remote control and penetration
Regarding the order of these four stages, which of the following options is correct?
- A. 1-2-4-3
- B. 1-4-2-3
- C. 2-1-4-3
- D. 2-3-4-1
Answer: B
NEW QUESTION 76
Which of the following options will not pose a security threat to the network?
- A. Weak personal safety awareness
- B. Failure to update the virus database in time
- C. Hacking
- D. Open company confidential files
Answer: D
NEW QUESTION 77
The following is a hardware SACG increase firewall configuration, which statement below is true?
- A. Main IP is the Policy Center reaches the next-hop firewall device interface address
- B. Primary IP: 10.1.3.6 on behalf of Policy Center linkage firewall interface IP address, the standby IP can enter another interface IP address of the firewall.
- C. Primary IP: 10.1.3.6 on behalf of Policy Center linkage firewall interface IP address, the standby IP can enter another alternate firewall interface IP address.
- D. Primary IP: 10.1.3.6 on behalf of SM Manager IP address.
Answer: C,D
NEW QUESTION 78
......
Best way to practice test for Huawei H12-722_V3.0: https://www.testkingfree.com/Huawei/H12-722_V3.0-practice-exam-dumps.html