Try Before You Buy

Download a free sample of any of our exam questions and answers

  • 24/7 customer support, Secure shopping site
  • Free One year updates to match real exam scenarios
  • If you failed your exam after buying our products we will refund the full amount back to you.

[Jan-2022] Exam H12-722_V3.0 New Brain Dump Professional - ValidExam [Q50-Q71]

Share

[Jan-2022] Exam H12-722_V3.0: New Brain Dump Professional - ValidExam

Free H12-722_V3.0 Exam Dumps to Improve Exam Score

NEW QUESTION 50
Which of the following descriptions are correct for proxy-based anti-virus gateways? (multiple choice)

  • A. System overhead will be relatively small
  • B. The detection rate is higher than the flow scanning method
  • C. Cache all files through the gateway's own protocol stack
  • D. More advanced operations such as decompression, shelling, etc. can be performed

Answer: B,C,D

 

NEW QUESTION 51
The administrator of a certain enterprise wants employees of Yangzhi to visit the shopping website during working hours. So a URL filtering configuration file is configured to divide the predefined The shopping website in the category is selected as blocked. But employee A can still use the company's network to shop online during lunch break. Then what are the following possible reasons some?

  • A. The administrator did not submit the configuration after completing the configuration.
  • B. The shopping website does not belong to the predefined shopping website category
  • C. The administrator has not applied the URL pass-through configuration file to the security policy.
  • D. The administrator has not set the time to vote every day from 9:00 to 18:00

Answer: A,B,C

 

NEW QUESTION 52
The configuration command to enable the attack prevention function is as follows; n
[FW] anti-ddos syn-flood source-detect
[FW] anti-ddos udp-flood dynamic-fingerprint-learn
[FW] anti-ddos udp-frag-flood dynamic fingerprint-learn
[FW] anti-ddos http-flood defend alert-rate 2000
[Fwj anti-ddos htp-flood source-detect mode basic
Which of the following options is correct for the description of the attack prevention configuration? (multiple choice)

  • A. The firewall has enabled the SYN Flood source detection and defense function
  • B. The firewall uses the first packet drop to defend against UDP Flood attacks.
  • C. The threshold for HTTP Flood defense activation is 2000.
  • D. HTTP Flood attack defense uses enhanced mode for defense

Answer: A,C

 

NEW QUESTION 53
Regarding the mail content filtering configuration of Huawei USG6000 products, which of the following statements is wrong?.

  • A. When a POP3 message is detected, if it is judged to be an illegal email, the firewall's response action only supports sending alarm information, and will not block the email o
  • B. Mail filtering will only take effect when the mail filtering configuration file is invoked when the security policy is allowed.
  • C. When an IMAP message is detected, if it is judged to be an illegal email; the firewall's response action only supports sending alarm messages and will not block the email.
  • D. The attachment size limit is for a single attachment, not for the total size of all attachments.

Answer: A

 

NEW QUESTION 54
Since the sandbox can provide a virtual execution environment to detect files in the network, the sandbox can be substituted when deploying security equipment Anti-Virus, IPS, spam detection and other equipment.

  • A. True
  • B. False

Answer: B

 

NEW QUESTION 55
The user needs of a university are as follows:
1. The environment is large, and the total number of two-way traffic can reach 800M. Huawei USG6000 series firewall is deployed at its network node.
2. The intranet is divided into student area, server area, etc., users are most concerned about the security of the server area to avoid attacks from various threats.
3. At the same time, some pornographic websites in the student area are prohibited.
The external network has been configured as an untrust zone and the internal network has been configured as a trust zone on the firewall. How to configure the firewall to meet the above requirements?

  • A. In the direction of untrust to the intranet, only the AV and IPS protection functions are turned on for the server area to protect the server
  • B. You can directly turn on the AV, IRS protection functions, and URL filtering functions in the global environment to achieve the requirements
  • C. Go to the untrust direction to open the URL filtering function for the entire campus network, and filter some classified websites
  • D. To the untrust direction, only enable AV and IPS protection functions for the server zone to protect the server

Answer: A,B,C

 

NEW QUESTION 56
Attacks on the Web can be divided into three types of attacks on the client, server, or communication channel.

  • A. True
  • B. False

Answer: A

 

NEW QUESTION 57
The core technology of content security lies in anomaly detection, and the concept of defense lies in continuous monitoring and analysis.

  • A. True
  • B. False

Answer: A

 

NEW QUESTION 58
Which of the following is the default port number of Portal authentication service?

  • A. 0
  • B. 1
  • C. 2
  • D. 3

Answer: A,C

 

NEW QUESTION 59
In the security protection system of the cloud era, reforms need to be carried out in the three stages before, during and after the event, and a closed-loop continuous improvement should be formed.
And development. Which of the following key points should be done in "things"? (multiple choice)

  • A. Offensive and defensive situation
  • B. Defense in Depth
  • C. Fight back against hackers
  • D. Vulnerability intelligence

Answer: B,C

 

NEW QUESTION 60
For Huawei USG600 products, which of the following statements about mail filtering configuration is correct?

  • A. Cannot control the number of received email attachments
  • B. You can control the size of the attachment of the received mail
  • C. When the spam processing action is an alert, the email will be blocked and an alert will be generated
  • D. Cannot perform keyword filtering on incoming mail

Answer: B

 

NEW QUESTION 61
Which of the following options is not a special message attack?

  • A. IP fragment message item
  • B. Tracert packet attack
  • C. Oversized ICMP packet attack
  • D. ICMP redirect message attack) 0l

Answer: A

 

NEW QUESTION 62
The realization of content security filtering technology requires the support of the content security combination license.

  • A. True
  • B. False

Answer: A

 

NEW QUESTION 63
Regarding the network intrusion detection system (NIDS), which of the following statements is wrong?

  • A. Real-time monitoring through the network adapter, and analysis of all communication services through the network;
  • B. Use the newly received network packet as the data source;
  • C. Used to monitor network traffic, and can be deployed independently.
  • D. It is mainly used for real-time monitoring of the information of the critical path of the network, listening to all packets on the network, collecting data, and analyzing suspicious objects

Answer: B

 

NEW QUESTION 64
In the Huawei USG6000 product, after creating or modifying the security configuration file, the configuration content will not take effect immediately: you need to click the "Prompt" in the upper right corner of the interface.
"Hand in" to activate.

  • A. True
  • B. False

Answer: A

 

NEW QUESTION 65
Use BGP protocol to achieve diversion, the configuration command is as follows
[sysname] route-policy 1 permit node 1
[sysname-route-policy] apply community no-advertise
[sysname-route-policy] quit
[sysname]bgp10029
[sysname-bgp] peer
[sysname-bgp] import-route unr
[sysname- bgpl ipv4-family unicast
[sysname-bgp-af-ipv4] peer 7.7.1.2 route-policy 1 export
[sysname-bgp-af-ipv4] peer 7.7. 1.2 advertise community
[sysname-bgp-af-ipv4] quit
[sysname-bgp]quit
Which of the following options is correct for the description of BGP diversion configuration? (multiple choice)

  • A. The management center does not need to configure protection objects. When an attack is discovered, it automatically issues a traffic diversion task.
  • B. Use BGP to publish UNR routes to achieve dynamic diversion.
  • C. After receiving the UNR route, the peer neighbor will not send it to any BGP neighbor.
  • D. You also need to configure the firewall ddos bgp-next-hop fib-filter command to implement back-injection.

Answer: B,C

 

NEW QUESTION 66
What content can be filtered by the content filtering technology of Huawei USG6000 products? (multiple choice)

  • A. Keywords contained in the downloaded file
  • B. File upload direction 335
  • C. File type
  • D. Keywords contained in the content of the uploaded file

Answer: A,D

 

NEW QUESTION 67
After enabling the IP policy, some services are found to be unavailable. Which of the following may be caused by? (multiple choice)

  • A. The same message passes through the firewall multiple times
  • B. Only packets in one direction pass through the firewall
  • C. Excessive traffic causes the Bypass function to be enabled
  • D. IPS underreporting

Answer: A,B

 

NEW QUESTION 68
Regarding the anti-spam response code, which of the following statements is wrong?

  • A. USG treats mails that match the answer code as spam.
  • B. The response code will vary depending on the RBL service provider.
  • C. The response code is specified as 127.0.0.1 in the second system.
  • D. If the response code is not returned or the response code is not configured on the USG, the mail is released.

Answer: C

 

NEW QUESTION 69
Regarding Huawei's anti-virus technology, which of the following statements is wrong?

  • A. The implementation of gateway antivirus is based on proxy scanning and stream scanning
  • B. The virus detection system cannot directly detect compressed files
  • C. Gateway antivirus default file maximum decompression layer is 3 layers
  • D. The anti-virus engine can detect the file type through the file extension

Answer: D

 

NEW QUESTION 70
When you suspect that the company's network has been attacked by hackers, you have carried out a technical investigation. Which of the following options does not belong to the behavior that occurred in the early stage of the attack?

  • A. Web application attacks
  • B. Vulnerability attack
  • C. Planting malware
  • D. Brute force

Answer: C

 

NEW QUESTION 71
......

Powerful H12-722_V3.0 PDF Dumps for H12-722_V3.0 Questions: https://www.validexam.com/H12-722_V3.0-latest-dumps.html