
Reliable Alibaba Security ACA-Sec1 Dumps PDF Dec 30, 2021 Recently Updated Questions
Pass Your Alibaba ACA-Sec1 Exam with Correct 145 Questions and Answers
Alibaba ACA-Sec1 Exam Syllabus Topics:
| Topic | Details |
|---|---|
| Topic 1 |
|
| Topic 2 |
|
| Topic 3 |
|
| Topic 4 |
|
| Topic 5 |
|
| Topic 6 |
|
| Topic 7 |
|
| Topic 8 |
|
| Topic 9 |
|
| Topic 10 |
|
NEW QUESTION 49
Which of the following statements is NOT true about web application security protection best practices?
- A. always scan input by user through web application
- B. keep monitoring system processes , performance and status
- C. enforce security management to any public service
- D. keep installing official released patches will be good enough
Answer: D
NEW QUESTION 50
Which of the following statements are NOT true about 'Server Guard' remote logon detection functionality?
- A. It needs to setup common logon location in 'Server Guard' configuration
- B. It can send warning message to 'Server Guard' user
- C. It can detect the attacking tool used by attacker
- D. It can detect the remote logon used source IP address
Answer: C
NEW QUESTION 51
What design flaw of TCP/IP protocol does SYN flood attack use?
- A. UDP stateless connectio
- B. HTTP plain text transmission
- C. DNS 3 times hands shake
- D. TCP 3 times hands shake
Answer: D
NEW QUESTION 52
Which of the following logs can be accessed through ECS logs provided by Alibaba Cloud?
(the number of correct answers: 2)
- A. OS system log
- B. Application log
- C. Hypervisor log
- D. Cloud platform log
Answer: A,B
NEW QUESTION 53
From which of the following attacks WAF will not provide protection?
- A. Core files unauthorized access
- B. SYN Flood
- C. HTTP Flood
- D. Web Server vulnerability attack
Answer: B
NEW QUESTION 54
Which of the following damages can't be caused by a DDOS attack
Score 2
- A. military commander system down
- B. DNS service down
- C. web service down
- D. physical server broken
Answer: D
NEW QUESTION 55
Which of the following security issues is considered by the OWASP to be the most dangerous issue facing cloud computing?
- A. Multi-tenant isolation failure
- B. Injection
- C. Account or service flow hijacking
- D. Denial of service
Answer: B
NEW QUESTION 56
You are planning on hosting an eCommerce Web server. You are intent on making the server secure against all external attacks possible. Which of the following would be the best way to test your server for its weaknesses? Choose the best answer.
- A. Check if all the patches and required antivirus software has been loaded o the server
- B. Simulate a DoS attack on the server
- C. Ping to the server
- D. Simulate a DDoS attack on that server
Answer: D
NEW QUESTION 57
Which of the following Keys in HTTP heads are related to cache control? (the number of correct answers: 3)
- A. Date
- B. Host
- C. Cache-Control
- D. Age
- E. Expires
Answer: B,D
NEW QUESTION 58
Which of the following function is NOT provided by 'Server Guard' vulnerability detection?
- A. Linux system vulnerability scanning
- B. sensitive data encryption
- C. Trojan detection
- D. weak password detection
Answer: B
NEW QUESTION 59
When we talk about 'security vulnerability' of ECS server, we are referring to: (the number of correct answers: 3)
- A. Application Vulnerability
- B. Hardware fault
- C. Data Center Serviceability
- D. OS vulnerability
- E. Hypervisor Vulnerability
Answer: A,D,E
NEW QUESTION 60
Which of the following security vulnerability is not a 'Server Side' security issue?
- A. SQL injection
- B. System Command Execution vulnerability
- C. CSRF(cross site request fraud)vulnerability
- D. File uploading vulnerability
Answer: C
NEW QUESTION 61
18.in RedHat Linux shell which command can be used to check what file system is mounted and form what disk device it was done?
- A. Du
- B. Ppart
- C. mount
- D. Fdisk
Answer: C
NEW QUESTION 62
Customer who bought ECS server doesn't need to worry about :
- A. Cloud infrastructure security
- B. ECS security group setting
- C. OS vulnerability inside ECS
- D. Web service security inside ECS
Answer: A
NEW QUESTION 63
CC customized protection rule supports you to define customized configuration setting.
Which of following items can be self-defined? (the number of correct answers: 3)
- A. Target IP
- B. How frequently the page is visited by one single source IP
- C. Source IP
- D. How long the detection should last
- E. URI
Answer: B,D,E
NEW QUESTION 64
Which of the following statements are true for how to login to different ECS operating system? (the number of correct answers: 2) Score 1
- A. use 'remote desktop connection' for windows
- B. use 'remote desktop connection' for Linux
- C. use 'ssh' tool for Linux
- D. use 'ssh' tool for windows
Answer: A,C
NEW QUESTION 65
Which Internet protocol is used to implement Linux shell command 'ping'?
Score 2
- A. UDP
- B. TCP
- C. PING
- D. ICMP
Answer: D
NEW QUESTION 66
If WAF service user updated web page content after turning on website tampering protection, what does user need to do on WAF console?
- A. Update cache
- B. turn on protection switch manually
- C. restart the whole WAF service
- D. add one protection rule
Answer: A
NEW QUESTION 67
Which of the following products is designed to provide secured and stable network connection among different VPCs?
- A. Security Group
- B. ECS
- C. Express Connect
- D. SLB
Answer: C
NEW QUESTION 68
In May 2017 a new blackmail virus WannaCry burst globally, using Windows OS open port 445 to initiate its attacks. What is the quickest way to prevent this kind of attacks?
- A. encrypt all data on server side
- B. disable port 445
- C. set a highly complexed administrator password
- D. put sensitive data in some hidden directory
Answer: B
NEW QUESTION 69
Which of the following steps is not a valid step for using anti-DDOS pro?
- A. bind real customer identity to anti-DDOS pro IP
- B. configure to be protected domain name
- C. add new DNS record
- D. if original server is using its own firewall, then need to add Anti-DDOS pro IP to its white list
- E. change source IP
Answer: A
NEW QUESTION 70
If your company has a lot of employees who would try to simultaneously access ECS server protected by 'Server Guard' using your company's intranet, the 'Sever Guard' may mistakenly identify those access requests as attacks. Which of the following methods is the best way to solve this problem? Score 2
- A. set a highly complexed administrator password
- B. add those IPs which need to access ECS server into 'Server Guard' logon white list
- C. change the rule of security group to unblock all company internal ips
- D. ask employees to access that ECS server not very frequently
Answer: B
NEW QUESTION 71
Which of the following scenarios are suitable to use CC emergency mode protection? (the number of correct answers: 2)
- A. Web page
- B. Native APPs
- C. HTML 5 page
- D. API
Answer: A,C
NEW QUESTION 72
......
Latest 2021 Realistic Verified ACA-Sec1 Dumps: https://www.validexam.com/ACA-Sec1-latest-dumps.html