
Pass Your H12-722-ENU Exam Easily - Real H12-722-ENU Practice Dump Updated Dec 15, 2021
2021 Realistic Verified Free Huawei H12-722-ENU Exam Questions
NEW QUESTION 102
Threats detected by the big data intelligent security analysis platform will be synchronized to each network device at the same time C and then collected from the network device Collect it in the log for continuous learning and optimization.
- A. True
- B. False
Answer: A
NEW QUESTION 103
Which of the following attack types is DDoS attack?
- A. Malformed packet attack
- B. Traffic attack
- C. Snooping scanning attack
- D. Single package attack
Answer: B
NEW QUESTION 104
Which of the following statements is wrong about Huawei anti-virus technology?
- A. Anti-virus engine can detect file type by file extension
- B. The maximum number of unpacked layers of the gateway antivirus default file is 3
- C. Gateway anti-virus implementation is based on proxy scanning and flow scanning
- D. The virus detection system cannot directly detect compressed files
Answer: A
NEW QUESTION 105
In Huawei USG6000 products, IAE provides an integrated solution, all content security detection functions are integrated in a well-designed In the high-performance engine. Which of the following is not the content security detection function supported by this product?
- A. URL classification and filtering
- B. Intrusion prevention
- C. Video content filtering
- D. Application recognition and perception
Answer: C
NEW QUESTION 106
During the infiltration phase of APT attack, which of the following attack behaviors will the attacker generally have?
- A. By phishing emails, attachments carrying a 0day vulnerability cause the user's terminal to become a springboard for attacks.
- B. Long-term latency and key data collection.
- C. Leaks key data information to interested third parties.
- D. The attacker sends C&C attack or other remote command to the infected host, cause the attack to spread horizontally across the intranet.
Answer: D
NEW QUESTION 107
Buffer overflows, Trojans, backdoor attacks, etc. are all application-level attacks.
- A. True
- B. False
Answer: A
NEW QUESTION 108
Anomaly detection establishes the normal behavior characteristics of the system's main body through analysis of system audit data: In the detection, if the audit data in the system is different from the normal behavior characteristics of the established subject, it is considered an intrusion behavior. Which of the following can be used as the system body? (Multiple choices)
- A. A group of users
- B. Host
- C. Single user
- D. A key program and file in the system
Answer: A,B,C,D
NEW QUESTION 109
In the security protection system of cloud era, reforms must be carried out in advance, in the event, and afterwards, and continuous improvement and development of closed loops must be formed.
Which of the following key points should be fulfilled in "in the matter"? (Multiple choices)
- A. Defense in depth
- B. Offensive and defensive situation
- C. Vulnerability information
- D. Counterattacks Hackers
Answer: A,D
NEW QUESTION 110
Which of the following is correct configuration strategy for anti-virus policy?
1. Load feature library
2. Configure security policy and reference AV profile
3. Apply and activate license
4. Configure AV Profile
5. Submit
- A. 3 -> 1 -> 4 -> 2 -> 5
- B. 3 -> 1 -> 2 -> 4 -> 5
- C. 3 -> 2 -> 1 -> 4 -> 5
- D. 3 -> 2 -> 4 -> 1 -> 5
Answer: A
NEW QUESTION 111
Which of the following is correct about the AntiDDoS system configuration?
- A. Configure drainage and injection on the detection device.
- B. Add protection objects on the management center.
- C. Configure drainage and injection on the management center.
- D. Configure port mirroring on the cleaning device.
Answer: B
NEW QUESTION 112
A college user needs are as follows:
1. The environmental traffic is relatively large and can add up to 800M in both directions. Huawei USG6000 series firewalls are deployed at its network nodes.
2. The intranet is divided into student areas, server areas, etc. Users are most concerned about the security of the server area and avoid being attacked by various types of threats.
3. At the same time, some pornographic websites in the student district are prohibited.
The external network is configured as untrust zone on the firewall, and the internal network is configured as trust zone. How to configure the firewall to meet the above requirements? (Multiple choices)
- A. Enable AV and IPS protection only for the server zone in the untrust direction to protect the server
- B. Enable URL filtering for the entire campus network in the direction of untrust and filter some classified websites
- C. untrust to the internal network direction only for the server area to open AV, IPS protection to protect the server
- D. You can enable the AV, IPS protection and URL filtering functions in the global environment.
Answer: B,C,D
NEW QUESTION 113
When configuring the URL filtering configuration file, www.bt.com is configured in the URL blacklist-item:
At the same time, set it in the custom URL category.
A URL is set as bt.com, and the action of customizing URL classification is a warning. Regarding the above configuration, which of the following statements are correct? (More select)
- A. The user can visit the www.bt.com website, but the administrator will receive a warning message.
- B. When users visit www.bt. com, they will be blocked.
- C. Users can visit www.videobt.com website.
- D. User cannot access all the sites ending with bt com.
Answer: B,C
NEW QUESTION 114
Which of the following are typical intrusions? (Multiple choices)
- A. Tampering Web pages
- B. Computer is infected by U disk virus
- C. Copy/View Sensitive Data
- D. The power supply in the equipment room is abnormally interrupted
Answer: A,C
NEW QUESTION 115
In the deployment of Huawei NIP6000 products, traffic mirroring can only be performed using port mirroring.
- A. False
- B. True
Answer: A
NEW QUESTION 116
When a virus is detected in an email, which of the following is not the corresponding action for detection?
- A. Declare
- B. Warning
- C. Block
- D. Delete attachments
Answer: C
NEW QUESTION 117
Which of the following description is incorrect about the cleaning center?
- A. The cleaning equipment supports a variety of flexible attack defense technologies, but it is ineffective for CC attack and ICMP flood attack defense.
- B. The re-injection methods include: policy route reinjection, static route reinjection, VPN reinjection, and Layer 2 peering.
- C. There are two drainage ways of static drainage and dynamic drainage.
- D. The cleaning center completes the function of drainage, cleaning, and flow reinjection after cleaning for abnormal flow.
Answer: A
NEW QUESTION 118
Which three aspects should be considered in the design of cloud platform security solutions? (multiple choice)
- A. Infrastructure security
- B. Hardware maintenance
- C. How to do a good job in management, operation and maintenance
- D. Tenant security
Answer: A,C,D
NEW QUESTION 119
When you suspect that the corporate network is being attacked by hackers, you have conducted technical investigations.
Which of the following options does not belong to the pre-attack behavior?
- A. Loophole attack
- B. Planting Malware
- C. Web Application attack
- D. Brute force cracking
Answer: B
NEW QUESTION 120
Which of the following statements about IPS is wrong?
- A. The signature set can contain either predefined signatures or custom signatures. 832335
- B. The priority of the coverage signature is higher than that of the signature in the signature set.
- C. Modifications to the PS policy will not take effect immediately. You need to submit a compilation to update the configuration of the IPS policy.
- D. When the "source security zone" is the same as the "destination security zone", it means that the IPS policy is applied in the domain.
Answer: A
NEW QUESTION 121
If the processing strategy for SMTP virus files is set to alert, which of the following options is correct?
- A. Delete the content of the email attachment
- B. Generate logs and discard
- C. Add announcement and generate log
- D. Generate logs and forward them
Answer: D
NEW QUESTION 122
For the description of the DNS Request Flood attack, which of the following option is correct?
- A. In the process of source authentication, the firewall triggers the client to send a DNS request with TCP packets to verify the validity of the source IP, but it will consume the TCP connection resources of the DNS cache server to some extent.
- B. For the DNS request flood attack of the authorization server, you can trigger the client to send a DNS request with a TCP packet to verify the validity of the source IP address.
- C. DNS request flood attack on the cache server can use the redirection mode to verify the validity of the source.
- D. Redirection can be implemented not only for the source IP address of the attacked domain name, but also for the destination IP address of the attacked domain name.
Answer: A
NEW QUESTION 123
......
H12-722-ENU Real Exam Questions and Answers FREE: https://www.passleader.top/Huawei/H12-722-ENU-exam-braindumps.html