
Valid HCIP-Security H12-722_V3.0 Dumps Ensure Your Passing
H12-722_V3.0 Dumps Real Exam Questions Test Engine Dumps Training
NEW QUESTION 110
Based on the anti-virus gateway of streaming scan, which of the following descriptions is wrong?
- A. Rely on state detection technology and protocol analysis technology
- B. The performance is higher than the agent-based method
- C. The detection rate is higher than the proxy-based scanning method
- D. The cost is smaller than the agent-based approach
Answer: C
NEW QUESTION 111
When configuring the terminal visits, we put some equipment configured exception equipment ,which of the following statements are true about the exception equipment?
- A. the exception equipment IP is not in controlled network segment.
- B. only through security authentication terminals can access exception equipment.
- C. terminal in isolation domain can not access exception equipment .
- D. through identity authentication terminals can access exception equipment.
Answer: A,D
NEW QUESTION 112
Which of the following options is not a special message attack?
- A. Tracert packet attack
- B. ICMP redirect message attack) 0l
- C. IP fragment message item
- D. Oversized ICMP packet attack
Answer: C
NEW QUESTION 113
In the penetration stage of an APT attack, which of the following attack behaviors will the attacker generally have?
- A. Long-term latency and collection of key data.
- B. Through phishing emails, attachments with 0day vulnerabilities are carried, causing the user's terminal to become a springboard for attacks.
- C. Leak the acquired key data information to a third party of interest
- D. The attacker sends a C&C attack or other remote commands to the infected host to spread the attack horizontally on the intranet.
Answer: D
NEW QUESTION 114
Tianyu Nei answered the role of safety filtering technology, which of the following is still correct? (multiple choice)
- A. Mail filtering refers to the management and control of mail sending and receiving, including preventing the flooding of spam and anonymous emails, and controlling the sending and receiving of illegal emails.
- B. File filtering can reduce the risk of malicious code execution and virus infection in the internal network by blocking the transmission of fixed types of files, and it can also prevent Prevent employees from leaking company confidential documents to the Internet.
- C. The application behavior control function can finely control common HTTP behaviors and FTP behaviors.
- D. Content filtering can prevent the disclosure of confidential information and the transmission of illegal information
Answer: A,B,C,D
NEW QUESTION 115
For SYIN Flood attacks, TCP source authentication and TCP proxy can be used for defense. Which of the following descriptions is correct?
- A. TCP source authentication has the restriction that the return path must be consistent, so the application of TCP proxy is not common. State "QQ: 9233
- B. TCP proxy means that the firewall is deployed between the client and the server. When the SYI packet sent by the client to the server passes through the firewall, the The firewall replaces the server and establishes a three-way handshake with the client. Generally used in scenarios where the back and forth paths of packets are inconsistent.
- C. During the TCP proxy process, the firewall will proxy and respond to each SYN message received, and maintain a semi-connection, so when the SYN message is When the document flow is heavy, the performance requirements of the firewall are often high.
- D. TCP source authentication is added to the whitelist after the source authentication of the client is passed, and the SYN packet of this source still needs to be verified in the future.
Answer: C
NEW QUESTION 116
Which of the following options is not a cyber security threat caused by weak personal security awareness?
- A. Increasing the cost of enterprise network operation and maintenance
- B. Leaking corporate information
- C. Disclosure of personal information
- D. Threats to the internal network
Answer: A
NEW QUESTION 117
In the big data intelligent security analysis platform, it is necessary to collect data from data sources, and then complete a series of actions such as data processing, detection and analysis, etc.
Which of the following options does not belong to the action that needs to be completed in the data processing part?
- A. Data preprocessing
- B. Distributed storage
- C. Distributed index
- D. Threat determination
Answer: D
NEW QUESTION 118
Regarding scanning and snooping attacks, which of the following descriptions is wrong?
- A. It is usually the network detection behavior before the attacker launches the real attack.
- B. Scanning attacks include address scanning and port scanning.
- C. The source address of the scanning attack is real, so it can be defended by adding direct assistance to the blacklist.
- D. When a worm virus breaks out, it is usually accompanied by an address scanning attack, so scanning attacks are offensive.
Answer: D
NEW QUESTION 119
The status code in the HTTP response message indicates the type of the response message, and there are many possible values. Which of the following status codes represents the client request The resource does not exist?
- A. 0
- B. 1
- C. 2
- D. 400.
Answer: A
NEW QUESTION 120
Part of the reason why the APT attack becomes difficult to defend is that it uses the vulnerabilities to attack.
This kind of zero-day hole usually requires flowers
A lot of time to research and analyze and produce corresponding defense methods.
- A. False
- B. True
Answer: B
NEW QUESTION 121
If the processing strategy for SMTP virus files is set to alert, which of the following options is correct?
- A. Add announcement and generate log
- B. Generate logs and discard
- C. Delete the content of the email attachment
- D. Generate logs and forward them
Answer: D
NEW QUESTION 122
In the construction of information security, the intrusion detection system plays the role of a monitor. It monitors the flow of key nodes in the information system.
In-depth analysis to discover security incidents that are occurring. Which of the following are its characteristics?. c0O
- A. IDS can be linked with firewalls and switches to become a powerful "assistant" of firewalls, which can better and more accurately control access between domains.
- B. It is impossible to correctly analyze the malicious code doped in the allowed application data stream.
- C. Unable to detect malicious operations or misoperations from internal killings.
- D. Cannot do in-depth inspection
Answer: A
NEW QUESTION 123
Which of the following options are common reasons for IPS detection failure? (multiple choices)
- A. IPS policy is not submitted for compilation
- B. False Policy IDs are associated with IPS policy domains
- C. Bypass function is closed in IPS
- D. The IPS function is not turned on
Answer: A,B,D
NEW QUESTION 124
Huawei WAF products are mainly composed of front-end execution, back-end central systems and databases.
Among them, the database mainly stores the front-end detection rules and black Whitelist and other configuration files.
- A. False
- B. True
Answer: B
NEW QUESTION 125
Which of the following options is not a feature of Trojan horses?
- A. Not self-replicating but parasitic
- B. Actively infectious
- C. Trojans self-replicate and spread
- D. The ultimate intention is to steal information and implement remote monitoring
Answer: B
NEW QUESTION 126
The administrator of a certain enterprise wants employees of Yangzhi to visit the shopping website during working hours. So a URL filtering configuration file is configured to divide the predefined The shopping website in the category is selected as blocked. But employee A can still use the company's network to shop online during lunch break. Then what are the following possible reasons some?
- A. The administrator has not applied the URL pass-through configuration file to the security policy.
- B. The administrator has not set the time to vote every day from 9:00 to 18:00
- C. The shopping website does not belong to the predefined shopping website category
- D. The administrator did not submit the configuration after completing the configuration.
Answer: A,C,D
NEW QUESTION 127
Regarding the description of file reputation technology in anti-virus engines, which of the following options is correct?
- A. File reputation is to perform virus detection by calculating the full text MD5 of the file to be tested and matching it with the local reputation MD5 cache
- B. Local reputation MD5 cache only has static cache, which needs to be updated regularly
- C. File reputation database update and upgrade can only be achieved through linkage with sandbox
- D. File reputation database can only be upgraded by manual upgrade
Answer: A
NEW QUESTION 128
USG6000V software logic architecture is divided into three planes: management plane, control plane and
- A. Data forwarding plane
- B. Configuration plane
- C. Business plane
- D. Log plane
Answer: A
NEW QUESTION 129
......
Huawei H12-722_V3.0: Selling HCIP-Security Products and Solutions: https://www.2pass4sure.com/HCIP-Security/H12-722_V3.0-actual-exam-braindumps.html