Authentic ACP-Sec1 Dumps With 100% Passing Rate Practice Tests Dumps [Q24-Q43]

Share

Authentic ACP-Sec1 Dumps With 100% Passing Rate Practice Tests Dumps

Alibaba ACP-Sec1 Real Exam Questions Guaranteed Updated Dump from PassCollection


Alibaba ACP-Sec1 Exam Syllabus Topics:

TopicDetails
Topic 1
  • web SQL injections among other common security risks and taking appropriate measures for protection
Topic 2
  • Cloud service-related basic security protocols such as HTTP, FTP, TCP, UDP and ICMP
  • Understanding common security risks of the above products
Topic 3
  • Core security products: basic operations and management of Anti-DDoS, Security Center, SSL Certificate, Content Moderation, Key Management Service
Topic 4
  • Cloud computing-related product (ECS, Server Load Balancer, OSS, RDS, VPC and CDN) content
Topic 5
  • Security application solution design, such as correct understanding and handling after receiving alerts from the console, e-mails or text messages
Topic 6
  • Discovering DDoS attacks, brute force password cracking attacks
  • Security advantages of their combined solutions
Topic 7
  • Understanding the positioning, main features, working principles and application scenarios of the above products
Topic 8
  • Characteristic, application scenarios, competitive edges and features of Alibaba Cloud Anti-DDos and WAF
Topic 9
  • Characteristics, application scenarios and features of Alibaba Cloud security management-related products

 

NEW QUESTION 24
More than one CNAME record is generated for the same domain name when Alibaba Cloud Anti-DDoS Premium Service Instance is purchased for load balancing purpose.

  • A. True
  • B. False

Answer: B

 

NEW QUESTION 25
Users can detach the Security Center client on Alibaba Cloud ECS instances, and reinstall it later when necessary.

  • A. True
  • B. False

Answer: A

 

NEW QUESTION 26
Clean bandwidth refers to the maximum normal clean bandwidth that can be processed by Anti-DDoS Premium instances when your business is not under attack. Make sure that the Clean bandwidth of the instance is greater than the peak value of the inbound or outbound traffic of all services connected to the Anti-DDoS Premium instances If the actual traffic volume exceeds the maximum Clean bandwidth, your business may be subject to traffic restrictions or random packet losses, and your normal business may be unavailable, slowed, or delayed for a certain period of time

  • A. True
  • B. False

Answer: A

 

NEW QUESTION 27
Alibaba Cloud Anti-DDoS Premium Service can be used to protect against DDoS attacks larger than 100 Gbps. It can be used to protect both Alibaba Cloud hosts and non-Alibaba Cloud hosts

  • A. True
  • B. False

Answer: A

 

NEW QUESTION 28
Cross Site Script (XSS) attacks refer to a kind of attack by tampering the webpage using HTML injection to insert malicious scripts so as to control the user's browser when the user browses the webpage XSS vulnerabilities may be used for user identity stealing (particularly the administrator identity), behavior hijacking, Trojan insertion and worm spreading, and also phishing

  • A. True
  • B. False

Answer: A

 

NEW QUESTION 29
Products like ECS and Server Load Balancer it will be automatically protected by Anti-DDoS Basic service

  • A. True
  • B. False

Answer: A

 

NEW QUESTION 30
An Alibaba Cloud user buys an ECS instance and deploys Tomcat on it Which of the following is the easiest way for the user to monitor whether port 8080 (used by Tomcat) on this ECS instance is functioning normally or not?

  • A. Use Alibaba Cloud CloudMonitor s site monitor feature to create a new Monitoring Task to monitor the port status.
  • B. Write a script for detection and report the data to CloudMonitor.
  • C. Log on to the ECS instance every hour to check the port using the command line.
  • D. Buy a third-party monitoring tool

Answer: A

 

NEW QUESTION 31
Alibaba Cloud WAF cannot protect against large traffic DDoS attacks which can be solved by Alibaba Cloud Ant-DDoS Service.

  • A. True
  • B. False

Answer: A

 

NEW QUESTION 32
Alibaba Cloud Security Center Agent is installed in ECS instances by default, no need to install it manually Users can detach Security Center Agent at any time they desire.

  • A. True
  • B. False

Answer: B

 

NEW QUESTION 33
Alibaba Cloud ECS instances are common targets of hacker attacks. There are many types of attacks against ECS instances. Which of the following attacks specifically target the operating system of an ECS instance?
(Number of correct answers: 3)

  • A. Brute force RDP password cracking
  • B. Brute force SSH password cracking
  • C. Trojan or Webshell installation
  • D. SQL injection

Answer: A,B,C

 

NEW QUESTION 34
When users log on to ECS instances through SSH or remote desktop from public Internet, Alibaba Cloud Security Center will monitor the log on behaviors If an IP address uses incorrect password to log on to an ECS instance for too many times, an alert "ECS instance suffers brute force password cracking" will be prompted If you receive this alert, which of the following is the safest way to handle this alert?

  • A. Inform all users on the service platform of changing their passwords, and eliminate simple passwords using technical measures
  • B. This alert does not matter and can be ignored.
  • C. Log on immediately to the ECS instance and check the logon logs If no abnormal logon success record is found ignore this alert.
  • D. Update the system user password immediately for the ECS instance, and enable the security group firewall to allow only specified IP addresses to connect to the ECS instance

Answer: D

 

NEW QUESTION 35
The protection rules of Alibaba Cloud WAF are updated in real time after a user makes changes in WAF configuration page.

  • A. True
  • B. False

Answer: A

 

NEW QUESTION 36
You have helped a customer set up a content filtering solution based on Content Moderation service However, the customer is complaining that certain images are getting incorrectly flagged as pornographic content. What can you do to help fix this?

  • A. Open a ticket with Alibaba Cloud support, and send them a copy of the images, so that they can tune Content Moderation's detection algorithms
  • B. Ask your customer to use different images on their site
  • C. Modify the images until Content Moderation service starts marking them as pornographic.
  • D. Create an "Image Library" from the Content Moderation console and add the images to the Image Library's whitelist

Answer: D

 

NEW QUESTION 37
Which of the following attacks can Alibaba Cloud Anti-DDoS Basic defend against? (Number of coned answers 4)

  • A. SYN Flood
  • B. Brute force password cracking
  • C. ACK Flood
  • D. CMP Flood
  • E. UDP Flood

Answer: A,B,C,E

 

NEW QUESTION 38
Alibaba Cloud Security Center provides patch management service, where are the patches published from?

  • A. Developed by Alibaba Cloud
  • B. Officially published by application vendors
  • C. Contributed by netizens from open-source communities
  • D. Officially published by operating system vendors

Answer: C

 

NEW QUESTION 39
baba Cloud security service provides in-depth defense Which of the following services is dedicated for host security?

  • A. Security Center
  • B. WAF
  • C. Anti-DDoS pro Service
  • D. Data Risk Control

Answer: C

 

NEW QUESTION 40
Content Moderation service is useful m a wide variety of scenarios. Which of the following are the *most* suited to Content Moderation's capabilities? (Number of correct answers 2)

  • A. Detecting sensitive customer information such as credit card numbers in uploaded images
  • B. Detecting spam posts on a forum
  • C. Detecting faces in images
  • D. Deleting porn on a social networking site

Answer: B,D

 

NEW QUESTION 41
In which of the following scenarios is Alibaba Cloud Security Center applicable? (Number of correct answers
3)

  • A. Setting up web server to provide web service to public
  • B. Penetration testing
  • C. Creating an ECS with generic software
  • D. Batch server security O&M
  • E. Network security protection for ad campaigns or other activities

Answer: B,D,E

 

NEW QUESTION 42
If an ECS instance needs to be accessed by other applications from internet, a corresponding "port" must be enabled For example, HTTP applications work on port 80, while FTP applications work on port 21 If an administrator configures network security policies for this ECS instance, which of the following policies is the safest?

  • A. The administrator wants to build multiple applications on an ECS instance. For easy management, the administrator uses default settings and allows any IP address to access required service ports
  • B. After buying an ECS instance, the administrator immediately enables the security group firewall on the console and opens all ports for public networks
  • C. After buying an ECS instance, the administrator immediately enables the security group firewall on the console and opens only the required service ports for public networks
  • D. After buying an ECS instance, the administrator immediately enables the security group firewall on the console and opens ports 0-1024 for public networks

Answer: C

 

NEW QUESTION 43
......

Verified Pass ACP-Sec1 Exam in First Attempt Guaranteed: https://www.passcollection.com/ACP-Sec1_real-exams.html