[Dec-2021] Study resources for the Valid H12-722-ENU Braindumps! [Q101-Q118]

Share

[Dec-2021] Study resources for the Valid H12-722-ENU Braindumps!

Updated H12-722-ENU Tests Engine pdf - All Free Dumps Guaranteed!

NEW QUESTION 101
Which of the following threats cannot be detected by IPS?

  • A. Worms
  • B. Virus
  • C. DoS
  • D. Spam

Answer: D

 

NEW QUESTION 102
The realization of content security filtering technology requires the support of the content security combination license.

  • A. False
  • B. True

Answer: B

 

NEW QUESTION 103
An enterprise administrator configures a Web reputation website in the form of a domain name, and configures the domain name as www. abc; example. com. .
Which of the following is the entry that the firewall will match when looking up the website URL?

  • A. www. abc. example. com
  • B. example. com
  • C. www.abc. example
  • D. example

Answer: D

 

NEW QUESTION 104
Which of the following features does Huawei NIP intrusion prevention equipment support? (multiple choice)

  • A. SSL traffic detection
  • B. Mail detection
  • C. Application identification and control
  • D. Virtual patch

Answer: A,C,D

 

NEW QUESTION 105
Which of the following files can the sandbox detect? (multiple choice)

  • A. PE file
  • B. Picture file
  • C. www file
  • D. Mail

Answer: A,B,C

 

NEW QUESTION 106
The application behavior control configuration file takes effect immediately after reference, without configuring the submission.

  • A. False
  • B. True

Answer: B

 

NEW QUESTION 107
Anti-DDoS defense system includes: management center, inspection center and cleaning center.

  • A. False
  • B. True

Answer: B

 

NEW QUESTION 108
To protect the security of data transmission, more and more websites or companies choose to encrypt traffic through SSL.
Which of the following statements is true about the threat detection of SSL traffic using Huawei NIP6000?

  • A. Threat-detected traffic is sent directly to the server without encryption.
  • B. NIP000 does not support SSL traffic threat detection.
  • C. NIP can directly crack and detect SSL encryption.
  • D. Processes such as "decryption," "threat detection," and "encryption."

Answer: D

 

NEW QUESTION 109
After the cleaning device establishes a BGP neighbor relationship with the peer router, uses BGP traffic diversion and policy routing reinjection, what configuration needs to be performed on the cleaning device? (Multiple Choice)

  • A. <sysname> system-view [sysname] firewall ddos bgp-next-hop X.X.X.X
  • B. [sysname] interface GigabitEthernet 2/0/1 [sysname-GigabitEthernet2/0/1] anti-ddos flow-statistic enable
  • C. [sysname] route-policy 1 permit node 1 [sysname-route-policy] apply community no-advertise [sysname-route-policy] quit [sysname] bgp 100 [sysname-bgp] peer X.X.X.X as-number 100 [sysname-bgp] import-route unr [sysname-bgp] ipv4-family unicast [sysname-bgp-af-ipv4] peer X.X.X.X route-policy 1 export [sysname-bgp-af-ipv4] peer X.X.X.X advertise-community [sysname-bgp-af-ipv4] quit
  • D. [sysname] policy-based-route [sysname-policy-pbr] rule name huizhu [sysname-policy-pbr-rule-huizhu] ingress-interface GigabitEthernet 2/0/1 [sysname-policy-pbr-rule-huizhu] action pbr egress-interface GigabitEthernet 2/0/2 next-hop X.X.X.X [sysname-policy-pbr-rule-huizhu] quit

Answer: C,D

 

NEW QUESTION 110
Which of the following signature properties cannot be configured for IP custom signatures?

  • A. protocol
  • B. Direction
  • C. ID
  • D. Packet length

Answer: D

 

NEW QUESTION 111
The following commands are configured on the Huawei firewall:
[USG] firewall defend ip-fragment enable
Which of the following situations will be recorded as an attack? (Multiple Choices)

  • A. DF bit is 0 and Fragment Offset + Length > 65535.
  • B. DF bit is 0, the MF bit is 1 or the Fragment Offset is not 0.
  • C. DF bit is 1 and Fragment Offset + Length < 65535.
  • D. DF bit is 1 and the MF bit is also 1 or the Fragment Offset is not 0.

Answer: A,D

 

NEW QUESTION 112
What are the three aspects that need to be considered when designing a cloud platform security solution? (Multiple choices)

  • A. Infrastructure security
  • B. Hardware Maintenance
  • C. Tenant security
  • D. How to manage the operation and maintenance

Answer: A,C,D

 

NEW QUESTION 113
Fage attack means that the original address and target address of TOP are both set to the IP address of a certain victim. This behavior will cause the victim to report to it.
SYN-ACK message is sent from the address, and this address sends back an ACK message and creates an empty connection, which causes the system resource board to occupy or target The host crashed.

  • A. False
  • B. True

Answer: A

 

NEW QUESTION 114
In Huawei USG6000 products, IAE provides an integrated solution, all content security detection functions are integrated in a well-designed In the high-performance engine. Which of the following is not the content security detection function supported by this product?

  • A. Application recognition and perception
  • B. URL classification and filtering
  • C. Video content filtering
  • D. Intrusion prevention

Answer: C

 

NEW QUESTION 115
In the anti-virus policy configuration of Huawei USG6000 products, which are the HTTP response methods? (Multiple choices)

  • A. Popup warning dialog
  • B. Blocking and pushing pages
  • C. Disable all access for this client
  • D. Alarms

Answer: B,D

 

NEW QUESTION 116
IPS is an intelligent intrusion detection and prevention product. It can not only detect the occurrence of intrusion, but also can stop the occurrence and development of intrusion in real time through a certain response method and protect the information system from substantive attack in real time.
Which of the following statement is wrong about the description of IPS?

  • A. IPS makes IDS and firewalls unified.
  • B. IPS is an intrusion detection system that can block in real-time when an intrusion is discovered.
  • C. The common IPS deployment mode is straight-line deployment.
  • D. IPS must be deployed in bypass mode on the network.

Answer: D

 

NEW QUESTION 117
Single-packet attacks are classified into scanning and snooping attacks, malformed packet attacks, and special packet attacks. Ping of death belongs to special packet attacks.

  • A. False
  • B. True

Answer: A

 

NEW QUESTION 118
......

H12-722-ENU Dumps Updated Practice Test and 180 unique questions: https://www.real4prep.com/H12-722-ENU-exam.html