Prepare H12-722 Question Answers Free Update With 100% Exam Passing Guarantee [Q38-Q60]

Share

Prepare H12-722 Question Answers Free Update With 100% Exam Passing Guarantee [2022]

Dumps Real Huawei H12-722 Exam Questions [Updated 2022]

NEW QUESTION 38
The network-based intrusion detection system is mainly used to monitor the information of the critical path of the network in real time, listen to all packets on the network, collect data, and divide Analyze the suspicious object, which of the following options are its main features? (multiple choices)

  • A. Need a lot of monitors.
  • B. It can detect the source address and destination address, identify whether the address is illegal, and locate the real intruder.
  • C. Good concealment, the network-based monitor does not run other applications, does not provide network services, and may not respond to other computers, so Not vulnerable to attack.
  • D. The monitoring speed is fast (the problem can be found in microseconds or seconds, and the host-based DS needs to take an analysis of the audit transcripts in the last few minutes

Answer: C,D

 

NEW QUESTION 39
For the basic mode of HTTP Flood Source authentication, which of the following are the correct descriptions? (Multiple choices)

  • A. The basic mode will not affect the user experience, so the defense effect is higher than the enhanced mode.
  • B. The basic mode effectively blocks access from non-browser clients.
  • C. When there is an HTTP proxy server in the network, the firewall will add the proxy server IP address to the whitelist, but the basic source authentication of the zombie host is still valid.
  • D. The zombie tool does not implement a complete HTTP protocol stack and does not support automatic redirection. Therefore, the basic mode can effectively defend against HTTP flood attacks.

Answer: B,D

 

NEW QUESTION 40
Which of the following is wrong about the 3 types of abnormalities in the file type recognition result?

  • A. Unrecognized file type means that the file type can't be recognized and the file extension can't be recognized.
  • B. Unrecognized file type means that the file type can't be identified and there is no file extension.
  • C. File extension mismatch means that the file type does not match the file extension.
  • D. File corruption means that the file type can't be identified because the file is damaged.

Answer: A

 

NEW QUESTION 41
Which of the following are true about the description of keywords? (Multiple Choices)

  • A. The minimum length of a keyword that a text can match is 2 bytes.
  • B. Custom keywords can only be defined in text mode.
  • C. Keywords are content that the device needs to recognize when content is filtered.
  • D. Keywords include predefined keywords and custom keywords.

Answer: C,D

 

NEW QUESTION 42
Regarding the local black and white list of anti-spam messages, which of the following statements is wrong?

  • A. Black and white lists are matched by extracting the source IP address of the SMTP connection
  • B. The black and white list is matched by the sender's dns suffix
  • C. The black and white list is matched by extracting the destination IP address of the SMTP connection
  • D. Block the connection if the source IP address of the SMTP connection matches the blacklist

Answer: B

 

NEW QUESTION 43
What content can be filtered by the content filtering technology of Huawei USG6000? (Multiple Choices)

  • A. Keywords contained in the uploaded file contents
  • B. File types
  • C. Direction of file upload
  • D. Keywords contained in the download file

Answer: A,D

 

NEW QUESTION 44
Huawei NIP6000 products provide carrier-grade high-reliability mechanisms at multiple levels to ensure the stable operation of the equipment.
Which of the following options belong to the reliability of the network? (Multiple choices)

  • A. Power 1+1 redundancy backup
  • B. Hot Standby
  • C. Hardware Bypass
  • D. Link-group

Answer: B,D

 

NEW QUESTION 45
For the description of the Anti DDOS system, which of the following options is correct? C

  • A. The firewall can only be used for inspection equipment
  • B. The main function of the Green Washing Center is to detect and analyze DDoS attack traffic on the flow from mirroring or splitting, and provide analysis data to The management center makes a judgment.
  • C. The management center mainly completes the processing of attack events, controls the drainage strategy and cleaning strategy of the cleaning center, and responds to various attack events and attack flows.
    View in categories and generate reports.
  • D. The detection center is mainly to pull and clean the attack flow according to the control strategy of the security management center, and re-inject the cleaned normal flow back to the customer.
    User network, send to the real destination.

Answer: C

 

NEW QUESTION 46
In the penetration stage of an APT attack, which of the following attack behaviors will the attacker generally have?

  • A. Leak the acquired key data information to a third party of interest
  • B. Long-term latency and collection of key data.
  • C. The attacker sends a C&C attack or other remote commands to the infected host to spread the attack horizontally on the intranet.
  • D. Through phishing emails, attachments with 0day vulnerabilities are carried, causing the user's terminal to become a springboard for attacks.

Answer: C

 

NEW QUESTION 47
Which of the following options is correct for the description of the Anti DDoS system configuration?

  • A. Configure drainage and re-injection on the management center.
  • B. Configure port mirroring on the cleaning device.
  • C. Configure drainage and re-injection on the testing equipment.
  • D. Add protection objects on the management center.

Answer: D

 

NEW QUESTION 48
For SYN flood attacks, TCP source authentication and TCP proxy can be used for defense.
Which of the following description is correct?

  • A. During the TCP proxy process, the firewall proxies and responds to every SYN packet received and maintains half-connection. Therefore, when the traffic of the SYN packet is heavy, the firewall requires very high performance.
  • B. TCP proxy means that the firewall is deployed between the client and the server. When the client sends an SYII packet to the server through the firewall, the firewall instead of the server establishes a three-way handshake with the client. Generally used for scenarios where the path of the packet is inconsistent.
  • C. TCP source authentication has the same restriction on the path of packets, so the application is not as common as TCP proxy.
  • D. After the TCP source authentication passes the source authentication of the client, it is added to the whitelist. Then the SYN packet of this source still needs to be verified.

Answer: A

 

NEW QUESTION 49
Which three aspects should be considered in the design of cloud platform security solutions? (multiple choice)

  • A. How to do a good job in management, operation and maintenance
  • B. Hardware maintenance
  • C. Tenant security
  • D. Infrastructure security

Answer: A,C,D

 

NEW QUESTION 50
Which of the following statements is wrong about the Anti-DDoS cloud cleaning solution?

  • A. Normal attacks are usually cleaned locally first.
  • B. The cloud cleaning service that is closer to the target being attacked will be transferred first.
  • C. If there is a large traffic attack in the network, send it to the cloud cleaning center to share the cleaning pressure.
  • D. Because the Cloud Cleaning Alliance will direct larger attack traffic to the cloud for cleaning, it will cause network congestion.

Answer: D

 

NEW QUESTION 51
Which of the following attacks are belong to attacks against Web servers? (Multiple choices)

  • A. SQL injection
  • B. Cross-site scripting attacks
  • C. Website fishing fraud
  • D. Website Trojan

Answer: A,B

 

NEW QUESTION 52
Regarding the processing process of file overwhelming, which of the following statements is correct?

  • A. If all the parameters of Wenzhu can match all file filtering rules, then the module will execute the action of this file filtering rule.
  • B. The file filtering module will compare the application type, file type, and transmission direction of the file identified by the previous module with the file filtering rules configured by the administrator.
    Then the lookup table performs matching from top to bottom.
  • C. If the file type is a compressed file, then after the file filtering check, the female file will be sent to the file decompression module for decompression and decompression.
    Press out the original file. If the decompression fails, the file will not be re-filed.
  • D. There are two types of actions: warning and blocking.

Answer: A

 

NEW QUESTION 53
The process of a browser carrying a cookie to request a resource from a server is as shown in the following figure. Which of the following steps have the session ID information in the message?

  • A. 1, 3, 4
  • B. 3, 4,
  • C. 2, 4
  • D. 5, 6

Answer: B

 

NEW QUESTION 54
Which of the following technologies can achieve content security? (multiple choice)

  • A. Sandbox and big data analysis
  • B. Global environment awareness
  • C. Web security protection
  • D. Intrusion prevention

Answer: A,B,C,D

 

NEW QUESTION 55
When misuse detection techniques are used, false positives are reported if the normal user behavior matches the intrusion signature repository successfully.

  • A. True
  • B. False

Answer: A

 

NEW QUESTION 56
If the user's FTP operation matches the FTP filtering policy, which actions can be performed? (Multiple choice)

  • A. Blocking
  • B. Execution
  • C. Announcement
  • D. Alerts

Answer: A,D

 

NEW QUESTION 57
When configure the URL filtering configuration file, www.bt.com is configured in the URL blacklist, and URL is set to *bt.com in the custom URL classification, and the action for customizing the URL classification is warning. .
Which of the following statements is true about the above configuration? (Multiple choices)

  • A. Users can visit www.videobt.com.
  • B. Users can visit www.bt.com website, but administrators will receive warning message.
  • C. Users will be blocked when they visit www.bt.com.
  • D. Users can't access all websites ending with bt.com.

Answer: A,C

 

NEW QUESTION 58
Information security is the protection of information and information systems to prevent unauthorized access, use, leakage, interruption, modification, damage, and to improve For confidentiality, integrity and availability. ,

  • A. True
  • B. False

Answer: A

 

NEW QUESTION 59
Under the CLI command, which of the following commands can be used to view the AV engine and virus database version?

  • A. display utm av version
  • B. display utm version
  • C. display av utm version
  • D. display version av-sdb

Answer: D

 

NEW QUESTION 60
......

H12-722 Exam Dumps, H12-722 Practice Test Questions: https://www.passcollection.com/H12-722_real-exams.html