[Dec-2021] Use Real H12-722 Dumps - 100% Free H12-722 Exam Dumps
H12-722 PDF Dumps Exam Questions – Valid H12-722 Dumps
NEW QUESTION 71
The user needs of a university are as follows:
1. The environment is large, and the total number of two-way traffic can reach 800M. Huawei USG6000 series firewall is deployed at its network node.
2. The intranet is divided into student area, server area, etc., users are most concerned about the security of the server area to avoid attacks from various threats.
3. At the same time, some pornographic websites in the student area are prohibited.
The external network has been configured as an untrust zone and the internal network has been configured as a trust zone on the firewall. How to configure the firewall to meet the above requirements?
- A. Go to the untrust direction to open the URL filtering function for the entire campus network, and filter some classified websites
- B. In the direction of untrust to the intranet, only the AV and IPS protection functions are turned on for the server area to protect the server
- C. You can directly turn on the AV, IRS protection functions, and URL filtering functions in the global environment to achieve the requirements
- D. To the untrust direction, only enable AV and IPS protection functions for the server zone to protect the server
Answer: A,B,C
NEW QUESTION 72
Huawei WAF products mainly consist of implementing front-end, back-end central systems and databases. The database mainly stores the front-end detection rules and black and white list configuration files.
- A. True
- B. False
Answer: A
NEW QUESTION 73
The most common form of child-like attack is to send a large number of seemingly legitimate packets to the target host through Flood, which ultimately leads to network bandwidth.
Or the equipment resources are exhausted. Which of the following options is not included in traffic attack packets?
- A. ICMP message
- B. FTP message
- C. TCP packets
- D. UDP packet
Answer: B
NEW QUESTION 74
Regarding the 3 abnormal situations of the file type recognition result, which of the following option descriptions is wrong?
- A. Unrecognized file type means that the file type cannot be recognized and there is no file extension.
- B. Unrecognized file type means that the file type cannot be recognized, and the file extension cannot be recognized.
- C. File damage means that the file type cannot be identified because the file is damaged.
- D. File extension mismatch means that the file type is inconsistent with the file extension.
Answer: B
NEW QUESTION 75
Regarding the Anti-DDoS cloud cleaning solution; which of the following statements is wrong?
- A. Ordinary attacks will usually be cleaned locally first.
- B. If there is a large traffic attack on the network, send it to the cloud cleaning center to share the cleaning pressure.
- C. Since the Cloud Cleaning Alliance will direct larger attack flows to the cloud for cleaning, it will cause network congestion.
- D. The closer to the attacked self-labeled cloud cleaning service, the priority will be called.
Answer: C
NEW QUESTION 76
Which of the following options describes the IntelliSense engine IAE incorrectly?
- A. Full English name: intelligent Awareness Engine.
- B. The security detection of the IAE engine is parallel, using a message-based file processing mechanism, which can receive file fragments and perform security checks.
- C. The core of C.IAE is to organically centralize all content security-related detection functions.
- D. lAE's content security detection functions include application identification and perception, intrusion prevention, and Web application security.
Answer: B
NEW QUESTION 77
Anti-DDoS defense system includes: management center, inspection center and cleaning center.
- A. True
- B. False
Answer: A
NEW QUESTION 78
The following figure shows the configuration of the URL filtering configuration file. Which of the following statements is true about this configuration?
- A. The default action means that all websites allow access. Therefore, this configuration error.
- B. The user visit the website www.exzample.com. When there is no black and white list of hits, the predefined URL category entry is next queried.
- C. The firewall will check the blacklist first and then check the whitelist.
- D. Assume that user visit www.exzample.com, which is part of Humanities and Social Networking category. At this time, the user cannot access the site.
Answer: D
NEW QUESTION 79
An enterprise administrator configures a web reputation website in the form of a domain name and configures the domain name as www.abc.example.com.
Which of the following is an entry that the firewall will match when looking for a website URL?
- A. www.abc.example
- B. www.abc.example.com
- C. example.com
- D. example
Answer: D
NEW QUESTION 80
After enabling the IP policy, some services are found to be unavailable. Which of the following may be caused by? (multiple choice)
- A. Only packets in one direction pass through the firewall
- B. The same message passes through the firewall multiple times
- C. IPS underreporting
- D. Excessive traffic causes the Bypass function to be enabled
Answer: A,B
NEW QUESTION 81
The status code in the HTTP response message describes the type of response message. There are many possible values.
Which of the following status codes indicates that the resource requested by the client does not exist?
- A. 0
- B. 1
- C. 2
- D. 3
Answer: A
NEW QUESTION 82
Anti DDoS seven-layer defense can work from the dimensions of interface-based defense, global defense and defense object-based defense.
- A. True
- B. False
Answer: A
NEW QUESTION 83
Anomaly detection establishes the normal behavior characteristics of the system's main body through analysis of system audit data: In the detection, if the audit data in the system is different from the normal behavior characteristics of the established subject, it is considered an intrusion behavior. Which of the following can be used as the system body? (Multiple choices)
- A. Host
- B. Single user
- C. A group of users
- D. A key program and file in the system
Answer: A,B,C,D
NEW QUESTION 84
Which of the following statements is wrong about HTTP behavior?
- A. When the file upload operation is allowed, alarm thresholds and blocking thresholds can be configured to control the uploaded file size.
- B. HTTP POST is generally used to send information to the server through a web page, such as forum posting, form submission, username/password login.
- C. When the size of the uploaded or downloaded file or the size of the POST operation reaches the alarm threshold, the system generates log information to prompt the device administrator and block the action.
- D. When the size of the uploaded or downloaded file or the size of the POST operation reaches the blocking threshold, the system will only block uploads or subsequent file and POST operations.
Answer: D
NEW QUESTION 85
The core technology of content security lies in anomaly detection, and the concept of defense lies in continuous monitoring and analysis.
- A. True
- B. False
Answer: A
NEW QUESTION 86
Which of the following options is not a special message attack?
- A. Oversized ICMP packet attack
- B. IP fragment message item
- C. ICMP redirect message attack) 0l
- D. Tracert packet attack
Answer: B
NEW QUESTION 87
In order to protect the security of data transmission, more and more websites or companies choose to use SSL to encrypt transmissions in the stream. About using Huawei NIP6000 The product performs threat detection on (SSL stream boy, which of the following statements is correct?
- A. The traffic after threat detection is sent directly to the server without encryption
- B. NIP can directly crack and detect SSL encryption.
- C. After the process of "decryption", "threat detection", and "encryption"
- D. NIP0OO does not support SSL Threat Detection.
Answer: C
NEW QUESTION 88
In the security protection system of the cloud era, reforms need to be carried out in the three stages before, during and after the event, and a closed-loop continuous improvement should be formed.
And development. Which of the following key points should be done in "things"? (multiple choice)
- A. Offensive and defensive situation
- B. Defense in Depth
- C. Vulnerability intelligence
- D. Fight back against hackers
Answer: B,D
NEW QUESTION 89
Which of the following belong to content security filtering technologies? (Multiple Choice)
- A. Mail filtering
- B. Application behavior control
- C. Content Filtering
- D. File Filtering
Answer: A,B,C,D
NEW QUESTION 90
......
Ultimate H12-722 Guide to Prepare Free Latest Huawei Practice Tests Dumps: https://www.validexam.com/H12-722-latest-dumps.html