Try Before You Buy

Download a free sample of any of our exam questions and answers

  • 24/7 customer support, Secure shopping site
  • Free One year updates to match real exam scenarios
  • If you failed your exam after buying our products we will refund the full amount back to you.

Reliable Alibaba Security ACA-Sec1 Dumps PDF Dec 30, 2021 Recently Updated Questions [Q49-Q72]

Share

Reliable Alibaba Security ACA-Sec1 Dumps PDF Dec 30, 2021 Recently Updated Questions

Pass Your  Alibaba ACA-Sec1 Exam with Correct 145 Questions and Answers


Alibaba ACA-Sec1 Exam Syllabus Topics:

TopicDetails
Topic 1
  • Familiar with operations of Alibaba Cloud Security related products
Topic 2
  • Knowledge of network security, such as firewall policy, key encryption, access control, network security, and network attack and protection methodologies
Topic 3
  • Understanding of the concepts of Alibaba Cloud Security related products
Topic 4
  • Familiar with features of Alibaba Cloud Security related products and key product implementation principles
Topic 5
  • Able to discover and resolve common issues emerged during the use of Alibaba Cloud Security related products
Topic 6
  • Virtualization, storage and networking
  • Familiar with operation on Linux and Windows operating system and be able to configure network and storage related system commands
Topic 7
  • Activating, creating, configuring, starting and stopping and disabling a service
Topic 8
  • Familiar with the concepts and related knowledge of Cloud Computing
Topic 9
  • Aware of main application scenarios of Alibaba Cloud Security related products and know each of these products’ special usage scenario
Topic 10
  • Familiar with common network protocols such as HTTP, FTP, TCP, UDP and ICMP

 

NEW QUESTION 49
Which of the following statements is NOT true about web application security protection best practices?

  • A. always scan input by user through web application
  • B. keep monitoring system processes , performance and status
  • C. enforce security management to any public service
  • D. keep installing official released patches will be good enough

Answer: D

 

NEW QUESTION 50
Which of the following statements are NOT true about 'Server Guard' remote logon detection functionality?

  • A. It needs to setup common logon location in 'Server Guard' configuration
  • B. It can send warning message to 'Server Guard' user
  • C. It can detect the attacking tool used by attacker
  • D. It can detect the remote logon used source IP address

Answer: C

 

NEW QUESTION 51
What design flaw of TCP/IP protocol does SYN flood attack use?

  • A. UDP stateless connectio
  • B. HTTP plain text transmission
  • C. DNS 3 times hands shake
  • D. TCP 3 times hands shake

Answer: D

 

NEW QUESTION 52
Which of the following logs can be accessed through ECS logs provided by Alibaba Cloud?
(the number of correct answers: 2)

  • A. OS system log
  • B. Application log
  • C. Hypervisor log
  • D. Cloud platform log

Answer: A,B

 

NEW QUESTION 53
From which of the following attacks WAF will not provide protection?

  • A. Core files unauthorized access
  • B. SYN Flood
  • C. HTTP Flood
  • D. Web Server vulnerability attack

Answer: B

 

NEW QUESTION 54
Which of the following damages can't be caused by a DDOS attack
Score 2

  • A. military commander system down
  • B. DNS service down
  • C. web service down
  • D. physical server broken

Answer: D

 

NEW QUESTION 55
Which of the following security issues is considered by the OWASP to be the most dangerous issue facing cloud computing?

  • A. Multi-tenant isolation failure
  • B. Injection
  • C. Account or service flow hijacking
  • D. Denial of service

Answer: B

 

NEW QUESTION 56
You are planning on hosting an eCommerce Web server. You are intent on making the server secure against all external attacks possible. Which of the following would be the best way to test your server for its weaknesses? Choose the best answer.

  • A. Check if all the patches and required antivirus software has been loaded o the server
  • B. Simulate a DoS attack on the server
  • C. Ping to the server
  • D. Simulate a DDoS attack on that server

Answer: D

 

NEW QUESTION 57
Which of the following Keys in HTTP heads are related to cache control? (the number of correct answers: 3)

  • A. Date
  • B. Host
  • C. Cache-Control
  • D. Age
  • E. Expires

Answer: B,D

 

NEW QUESTION 58
Which of the following function is NOT provided by 'Server Guard' vulnerability detection?

  • A. Linux system vulnerability scanning
  • B. sensitive data encryption
  • C. Trojan detection
  • D. weak password detection

Answer: B

 

NEW QUESTION 59
When we talk about 'security vulnerability' of ECS server, we are referring to: (the number of correct answers: 3)

  • A. Application Vulnerability
  • B. Hardware fault
  • C. Data Center Serviceability
  • D. OS vulnerability
  • E. Hypervisor Vulnerability

Answer: A,D,E

 

NEW QUESTION 60
Which of the following security vulnerability is not a 'Server Side' security issue?

  • A. SQL injection
  • B. System Command Execution vulnerability
  • C. CSRF(cross site request fraud)vulnerability
  • D. File uploading vulnerability

Answer: C

 

NEW QUESTION 61
18.in RedHat Linux shell which command can be used to check what file system is mounted and form what disk device it was done?

  • A. Du
  • B. Ppart
  • C. mount
  • D. Fdisk

Answer: C

 

NEW QUESTION 62
Customer who bought ECS server doesn't need to worry about :

  • A. Cloud infrastructure security
  • B. ECS security group setting
  • C. OS vulnerability inside ECS
  • D. Web service security inside ECS

Answer: A

 

NEW QUESTION 63
CC customized protection rule supports you to define customized configuration setting.
Which of following items can be self-defined? (the number of correct answers: 3)

  • A. Target IP
  • B. How frequently the page is visited by one single source IP
  • C. Source IP
  • D. How long the detection should last
  • E. URI

Answer: B,D,E

 

NEW QUESTION 64
Which of the following statements are true for how to login to different ECS operating system? (the number of correct answers: 2) Score 1

  • A. use 'remote desktop connection' for windows
  • B. use 'remote desktop connection' for Linux
  • C. use 'ssh' tool for Linux
  • D. use 'ssh' tool for windows

Answer: A,C

 

NEW QUESTION 65
Which Internet protocol is used to implement Linux shell command 'ping'?
Score 2

  • A. UDP
  • B. TCP
  • C. PING
  • D. ICMP

Answer: D

 

NEW QUESTION 66
If WAF service user updated web page content after turning on website tampering protection, what does user need to do on WAF console?

  • A. Update cache
  • B. turn on protection switch manually
  • C. restart the whole WAF service
  • D. add one protection rule

Answer: A

 

NEW QUESTION 67
Which of the following products is designed to provide secured and stable network connection among different VPCs?

  • A. Security Group
  • B. ECS
  • C. Express Connect
  • D. SLB

Answer: C

 

NEW QUESTION 68
In May 2017 a new blackmail virus WannaCry burst globally, using Windows OS open port 445 to initiate its attacks. What is the quickest way to prevent this kind of attacks?

  • A. encrypt all data on server side
  • B. disable port 445
  • C. set a highly complexed administrator password
  • D. put sensitive data in some hidden directory

Answer: B

 

NEW QUESTION 69
Which of the following steps is not a valid step for using anti-DDOS pro?

  • A. bind real customer identity to anti-DDOS pro IP
  • B. configure to be protected domain name
  • C. add new DNS record
  • D. if original server is using its own firewall, then need to add Anti-DDOS pro IP to its white list
  • E. change source IP

Answer: A

 

NEW QUESTION 70
If your company has a lot of employees who would try to simultaneously access ECS server protected by 'Server Guard' using your company's intranet, the 'Sever Guard' may mistakenly identify those access requests as attacks. Which of the following methods is the best way to solve this problem? Score 2

  • A. set a highly complexed administrator password
  • B. add those IPs which need to access ECS server into 'Server Guard' logon white list
  • C. change the rule of security group to unblock all company internal ips
  • D. ask employees to access that ECS server not very frequently

Answer: B

 

NEW QUESTION 71
Which of the following scenarios are suitable to use CC emergency mode protection? (the number of correct answers: 2)

  • A. Web page
  • B. Native APPs
  • C. HTML 5 page
  • D. API

Answer: A,C

 

NEW QUESTION 72
......

Latest 2021 Realistic Verified ACA-Sec1 Dumps: https://www.validexam.com/ACA-Sec1-latest-dumps.html