New 2022 Realistic Free Huawei H12-722 Exam Dump Questions & Answer
H12-722 Practice Test Engine: Try These 180 Exam Questions
NEW QUESTION 74
Regarding the enhanced mode in HTTP Flood source authentication, which of the following descriptions are correct? Multiple choices
- A. The enhanced mode is superior to the basic mode in terms of user experience.
- B. Enhanced mode supports all HTTP Flood source authentication fields. " WWQQ: 922333
- C. Enhanced mode refers to the authentication method using verification code.
- D. Some bots have a redirection function, or the free proxy used during the attack supports the redirection function, which leads to the failure of the basic mode of defense Effective, enhanced mode can effectively defend.
Answer: C,D
NEW QUESTION 75
Misuse detection is through the detection of similar intrusions in user behavior, or those that use system flaws to indirectly violate system security rules To detect intrusions in the system. Which of the following is not a feature of misuse detection 2
- A. Easy to implement
- B. Effective detection of impersonation detection of legitimate users
- C. Easy to upgrade
- D. Accurate detection
Answer: B
NEW QUESTION 76
The process of a browser carrying a cookie to request a resource from a server is as shown in the following figure. Which of the following steps have the session ID information in the message?
- A. 1, 3, 4
- B. 2, 4
- C. 3, 4,
- D. 5, 6
Answer: C
NEW QUESTION 77
File filtering technology can filter files based on their application, file transfer direction, file type, and file extension.
- A. FALSE
- B. TRUE
Answer: B
NEW QUESTION 78
Which of the following description is correct about the Management Center?
- A. Management Center is divided into two parts: management server and data collector.
- B. The data collector is responsible for abnormal traffic cleaning, centralized device management configuration, and business report presentation.
- C. The management server of the management center is responsible for the cleaning of abnormal traffic, as well as the collection, analysis, aggregation, and storage of service data, and is responsible for reporting the summarized traffic to the management server for report presentation.
- D. The data collector and management server support distributed deployment and centralized deployment. Centralized deployment has good scalability.
Answer: A
NEW QUESTION 79
When the Anti DDoS system finds the attack flow, the state will redirect the attack flow to the cleaning device.
After the cleaning device is cleaned, it will flow back.
Note to the original link, which of the following options does not belong to the method of re-injection?
- A. GRE back note:
- B. BGP back-annotation
- C. Policy routing back annotation,
- D. MPLS LSP back injection
Answer: B
NEW QUESTION 80
USG6000V software logic architecture is divided into three planes: management plane, control plane and
- A. Data forwarding plane
- B. Configuration plane
- C. Business plane
- D. Log plane
Answer: A
NEW QUESTION 81
An enterprise administrator configures a web reputation website in the form of a domain name and configures the domain name as www.abc.example.com.
Which of the following is an entry that the firewall will match when looking for a website URL?
- A. www.abc.example.com
- B. example.com
- C. www.abc.example
- D. example
Answer: D
NEW QUESTION 82
Misuse detection discovers intrusion activity in system by detecting similar behaviors of user intrusions, or by detecting violations of system security rules indirectly by exploiting system flaws.
Which of the following is not misuse detection feature?
- A. Easy to implement
- B. Effective detection of impersonation of legitimate users
- C. Easy to upgrade
- D. Accurate detection
Answer: B
NEW QUESTION 83
Regarding traditional firewalls, which of the following statements are correct? (multiple choice)
- A. It cannot effectively resist the spread of viruses from the Internet to the intranet.
- B. Ability to quickly adapt to changes in threats.
- C. Lack of effective protection against application layer threats.
- D. Unable to accurately control various applications, such as P2P, online games, etc. .
Answer: A,C,D
NEW QUESTION 84
Regarding the processing flow of file filtering, which of the following statements is wrong?
- A. The application identification module can identify the type of application that carries the file.
- B. After the file decompression fails, the file will still be filtered. .
- C. Protocol decoding is responsible for analyzing the file data and file transmission direction in the data stream.
- D. The file type recognition module is responsible for identifying the true type of the file and the file extension based on the file data
Answer: B
NEW QUESTION 85
Which of the following statements about intrusion detection/defense devices are correct? (Multiple Choice)
- A. Can't effectively resist the spread of viruses from the Internet to the Intranet.
- B. Can quickly adapt changes in threats.
- C. NIP6000 can identify applications up to 6000+, implement fine-grained application protection, save export bandwidth, and ensure the business experience of key services.
- D. Protect the intranet from external attacks and suppress malicious traffic, such as spyware, worms, etc., flooding and spreading to the intranet.
Answer: B,C,D
NEW QUESTION 86
Part of the reason why the APT attack becomes difficult to defend is that it uses the vulnerabilities to attack.
This kind of zero-day hole usually requires flowers
A lot of time to research and analyze and produce corresponding defense methods.
- A. False
- B. True
Answer: B
NEW QUESTION 87
The IPS process has the following steps:
1. Reorganize application data
2. Match signature
3. Message processing
4. Protocol identification
Which of the following is the correct ordering for the processing?
- A. 2-4-1-3
- B. 1-4-2-3
- C. 4-1-2-3
- D. 1-3-2-4
Answer: B
NEW QUESTION 88
The anti-tampering technology of Huawei WAF products is based on the cache module. Assuming that user A accesses website B, website B has signs of page tampering. The workflow of the WAF tamper-resistant module has the following steps:
1, WAF uses the cached page to return to the client
2, WAF compares the server page content with the cached page content
3, After the learning is completed, the page content is stored in the cache
4, When the user accesses the web page, the WAF obtains the page content of the server
5, WAF initiates learning mode to learn the page content of the user visiting the website
Which of the following options is correct for the ordering of these steps?
- A. 5, 1, 2, 4, 3
- B. 3, 4, 2, 5, 1
- C. 5, 3, 4, 2, 1
- D. 2, 4, 1, 5, 3
Answer: C
NEW QUESTION 89
Which of the following options are correct for the description of URPF technology? (Multiple Choices)
- A. The main function is to prevent network attacks based on source address spoofing.
- B. Use the loose mode of URPF in an environment where route symmetry is not guaranteed.
- C. Does not check whether the interfaces match in the strict mode. As long as there is a route to the source address, the packets can pass.
- D. In loose mode, not only the corresponding entries in the forwarding table are required, but also the interfaces must match to pass the URPF check.
Answer: A,B
NEW QUESTION 90
Which of the following are the control items of HTTP behavior?) (multiple choice)
- A. POST operation
- B. Browse the web
- C. File upload and download
- D. Acting online
Answer: A,B,C,D
NEW QUESTION 91
Which of the following descriptions about the black and white lists in spam filtering is wrong?
- A. Enter the IP address and mask of the SMITP Server to be added to the blacklist in the "Blacklist" text box, you can enter multiple IP addresses, one IP Address one line.
- B. The priority of the blacklist is higher than that of the whitelist.
- C. In the "Whitelist" text box, enter the P address and mask of the SMTP Server to be added to the whitelist. You can enter multiple IP addresses, one IP address Address one line. v
- D. Set local blacklist and whitelist: Both blacklist and whitelist can be configured at the same time, or only one of them can be configured.
Answer: B
NEW QUESTION 92
Regarding intrusion detection I defense equipment, which of the following statements are correct? (multiple choice)
- A. It cannot effectively prevent the virus from spreading from the Internet to the intranet.
- B. The number of applications that NIP6000 can recognize reaches 6000+, which realizes refined application protection, saves export bandwidth, and guarantees key business services Experience.
- C. Ability to quickly adapt to threat changes
- D. Protect the intranet from external attacks, and inhibit malicious flows, such as spyware, worms, etc.
from flooding and spreading to the intranet.
Answer: B,C,D
NEW QUESTION 93
Which of the following belong to content security filtering technologies? (Multiple Choice)
- A. Content Filtering
- B. Application behavior control
- C. File Filtering
- D. Mail filtering
Answer: A,B,C,D
NEW QUESTION 94
Single-packet attacks are classified into scanning and snooping attacks, malformed packet attacks, and special packet attacks. Ping of death belongs to special packet attacks.
- A. False
- B. True
Answer: A
NEW QUESTION 95
......
Guaranteed Success in HCNP-Security H12-722 Exam Dumps: https://www.itcertmagic.com/Huawei/real-H12-722-exam-prep-dumps.html