
2021 Real4Prep Huawei H12-722-ENU Dumps and Exam Test Engine
Huawei H12-722-ENU DUMPS WITH REAL EXAM QUESTIONS
NEW QUESTION 32
Which of the following is wrong about intrusion prevention?
- A. Intrusion prevention is a security mechanism that analyzes network traffic and detects intrusions (including buffer overflow attacks, Trojans, worms, etc.).
- B. Intrusion prevention technology, after discovering intrusions, must link firewalls to prevent intrusions
- C. Intrusion prevention is a new type of security technology that can detect and prevent intrusions.
- D. Intrusion prevention can block attacks in real time.
Answer: B
NEW QUESTION 33
The administrator has defined two key words that need to be recognized on the firewall: the weight of the keyword x is 2, and the weight of the key y is 3: defined The alarm interval value from the content is 5, and the blocking threshold value is 10. If the device detects that there is a secondary key space x in the webpage created by the user, the two keywords are Y; Regarding the weight value and monthly household visits to Heshun Street, is the following statement correct?
- A. The weight value is 10, you can ask the web page before
- B. The weight value is 8, the page cannot be accessed
- C. The weight value is 10, and the page cannot be accessed
- D. The weight value is 8, you can visit the web page
Answer: D
NEW QUESTION 34
The configuration command to enable the attack prevention function is as follows; n
[FW] anti-ddos syn-flood source-detect
[FW] anti-ddos udp-flood dynamic-fingerprint-learn
[FW] anti-ddos udp-frag-flood dynamic fingerprint-learn
[FW] anti-ddos http-flood defend alert-rate 2000
[Fwj anti-ddos htp-flood source-detect mode basic
Which of the following options is correct for the description of the attack prevention configuration? (multiple choice)
- A. The firewall uses the first packet drop to defend against UDP Flood attacks.
- B. HTTP Flood attack defense uses enhanced mode for defense
- C. The firewall has enabled the SYN Flood source detection and defense function
- D. The threshold for HTTP Flood defense activation is 2000.
Answer: C,D
NEW QUESTION 35
UDP is a connectionless protocol. A large number of UDP flood attacks cause the performance of network devices that rely on session forwarding to be degraded and even the session table is exhausted, causing network congestion.
Which of the following options does not prevent UDP flood attacks?
- A. Current limiting
- B. UDP fingerprint learning
- C. First packet discarded
- D. Associated defense
Answer: C
NEW QUESTION 36
Regarding HTTP behavior, which of the following statements is wrong?
- A. When the uploaded or downloaded file size, POST operation content size reaches the blocking threshold, the system will only block the uploaded or downloaded file, POST operate.
- B. When the file upload operation is allowed, the alarm threshold and blocking threshold can be configured to control the size of the uploaded file.
- C. When the size of the uploaded or downloaded file and the size of the content of the POST operation reach the alarm threshold, the system will generate log information to prompt the device management And block behavior.
- D. HTTP POST is generally used to send information to the server through a web page, such as forum posting x form submission, username I password login.
Answer: A
NEW QUESTION 37
Huawei WAF products mainly consist of implementing front-end, back-end central systems and databases. The database mainly stores the front-end detection rules and black and white list configuration files.
- A. False
- B. True
Answer: B
NEW QUESTION 38
Which of the following options is wrong for the description of the cleaning center?
- A. Re-injection methods include: policy route re-injection, static route re-injection, VVPN back-injection and layer 2 same.
- B. There are two types of drainage methods: static drainage and dynamic drainage.
- C. The cleaning center completes the functions of drainage, cleaning, and re-injection of the flow after cleaning in the abnormal flow.
- D. The cleaning equipment supports rich and flexible attack prevention technologies, but it is ineffective against cc attacks and ICMP Flood attacks.
Answer: D
NEW QUESTION 39
When the Anti DDoS system finds the attack flow, the state will redirect the attack flow to the cleaning device.
After the cleaning device is cleaned, it will flow back.
Note to the original link, which of the following options does not belong to the method of re-injection?
- A. GRE back note:
- B. BGP back-annotation
- C. Policy routing back annotation,
- D. MPLS LSP back injection
Answer: B
NEW QUESTION 40
Analysis is the core function of intrusion detection. The analysis process of intrusion detection can be divided into three phases. The analyzer is built to analyze, feedback and refine the actual field data.
Which of these are the functions included in the first two phases?
- A. Data Processing, Data Classification, Post Processing
- B. Data Processing, Attack Classification, Post Processing
- C. Data Analysis, Data Classification, Post Processing
- D. Data Processing, Data Classification, Attack Playback
Answer: A
NEW QUESTION 41
UDP is a connectionless protocol. UDP Flood attacks that change sources and ports will cause performance degradation of network devices that rely on session forwarding.
Even the session table is exhausted, causing the network to be paralyzed. Which of the following options is not a preventive measure for UDP Flood attacks?
- A. UDP fingerprint learning
- B. current limit
- C. First packet discarded
- D. Associated defense
Answer: C
NEW QUESTION 42
Which of the following options is not a feature of big data technology?
- A. Slow processing speed
- B. The data boy is huge
- C. A wide variety of data
- D. Low value density
Answer: A
NEW QUESTION 43
For the basic mode of HTTP Flood Source authentication, which of the following are the correct descriptions? (Multiple choices)
- A. The basic mode will not affect the user experience, so the defense effect is higher than the enhanced mode.
- B. The basic mode effectively blocks access from non-browser clients.
- C. The zombie tool does not implement a complete HTTP protocol stack and does not support automatic redirection. Therefore, the basic mode can effectively defend against HTTP flood attacks.
- D. When there is an HTTP proxy server in the network, the firewall will add the proxy server IP address to the whitelist, but the basic source authentication of the zombie host is still valid.
Answer: B,C
NEW QUESTION 44
URL filtering technology can access control URLs for users according to different time objects and address objects, and achieve the purpose of accurately managing user online behavior.
- A. FALSE
- B. TRUE
Answer: B
NEW QUESTION 45
Which of the following statements about intrusion detection/defense devices are correct? (Multiple Choice)
- A. Can't effectively resist the spread of viruses from the Internet to the Intranet.
- B. Can quickly adapt changes in threats.
- C. NIP6000 can identify applications up to 6000+, implement fine-grained application protection, save export bandwidth, and ensure the business experience of key services.
- D. Protect the intranet from external attacks and suppress malicious traffic, such as spyware, worms, etc., flooding and spreading to the intranet.
Answer: B,C,D
NEW QUESTION 46
Huawei NIP6000 products provide carrier-class high-reliability mechanisms from multiple levels to ensure the stable operation of equipment.
Which of the following options belong to the network reliability? (multiple choice)
- A. Power supply. 1+1 redundant backup
- B. Hardware Bypass
- C. Link-group
- D. Dual machine hot backup
Answer: C,D
NEW QUESTION 47
Intrusion detection is a kind of network security technology used to detect any damage or attempt to damage the confidentiality, integrity or availability of the system. Which of the following belongs to the intrusion detection knowledge base?
- A. Complete virus sample
- B. Complete Trojan sample
- C. Specific behavior patterns
- D. Security policy
Answer: C
NEW QUESTION 48
Regarding computer viruses, which of the following options is correct?
- A. All computer viruses must be parasitic in files and cannot exist independently
- B. Patching the system can completely solve the virus intrusion problem
- C. Computer viruses are latent, they may be latent for a long time, and only when they encounter certain conditions will they begin to carry out sabotage activities
- D. Computer viruses are contagious. They can spread through floppy disks and CDs, but they will not spread through the Internet.
Answer: C
NEW QUESTION 49
Regarding the processing process of file overwhelming, which of the following statements is correct?
- A. The file filtering module will compare the application type, file type, and transmission direction of the file identified by the previous module with the file filtering rules configured by the administrator.
Then the lookup table performs matching from top to bottom. - B. There are two types of actions: warning and blocking.
- C. If the file type is a compressed file, then after the file filtering check, the female file will be sent to the file decompression module for decompression and decompression.
Press out the original file. If the decompression fails, the file will not be re-filed. - D. If all the parameters of Wenzhu can match all file filtering rules, then the module will execute the action of this file filtering rule.
Answer: D
NEW QUESTION 50
Which of the following options are common reasons for IPS detection failure? (multiple choices)
- A. IPS policy is not submitted for compilation
- B. False Policy IDs are associated with IPS policy domains
- C. Bypass function is closed in IPS
- D. The IPS function is not turned on
Answer: A,B,D
NEW QUESTION 51
Network attacks are classified into two types: single-packet attacks and traffic-based attacks. Single-packet attacks include scanning and snooping attacks, malformed packet attacks and special packet attacks.
- A. False
- B. True
Answer: B
NEW QUESTION 52
Which of the following are the upgrade methods for the anti-virus feature database of Huawei USG6000 product? (Multiple Choices)
- A. Manual upgrade
- B. Online upgrade
- C. Automatic upgrade
- D. Local upgrade
Answer: B,D
NEW QUESTION 53
If the user's FTP operation matches the FTP filtering policy, what actions can be performed? (multiple choice)
- A. Execution
- B. Block
- C. Declare
- D. Alarm
Answer: B,D
NEW QUESTION 54
......
2021 New Real4Prep H12-722-ENU PDF Recently Updated Questions: https://www.real4prep.com/H12-722-ENU-exam.html