Nov-2021 Huawei H12-722-ENU Actual Questions and 100% Cover Real Exam Questions
H12-722-ENU Free Exam Questions & Answers PDF Updated on Nov-2021
NEW QUESTION 42
Which two of the following options use similar attack methods and generate a large number of useless reply packets, occupying network bandwidth and consuming device resources?
- A. Fraggle andLand
- B. Fraggle and Smurf
- C. Teardrop and Land
- D. Land and Smurf
Answer: B
NEW QUESTION 43
The whitelist rule of the firewall antivirus module is configured as *example*. Which of the following matches is used in this configuration?
- A. Keyword matching
- B. Prefix matching
- C. exact match
- D. Suffix matching
Answer: A
NEW QUESTION 44
Which of the following is wrong about the 3 types of abnormalities in the file type recognition result?
- A. Unrecognized file type means that the file type can't be recognized and the file extension can't be recognized.
- B. Unrecognized file type means that the file type can't be identified and there is no file extension.
- C. File extension mismatch means that the file type does not match the file extension.
- D. File corruption means that the file type can't be identified because the file is damaged.
Answer: A
NEW QUESTION 45
Regarding the file filtering technology in the USG6000 product, which of the following options is wrong?
- A. Even if the file type is modified, it can also identify the true type of the file
- B. It can identify the application that carries the file, the file transfer direction, the file type and the file extension.
- C. It supports filtering the contents of compressed files after decompression. "
- D. It can identify the type of files transmitted by itself, and can block, alert and announce specific types of files.
Answer: D
NEW QUESTION 46
The security management system is only optional, and anti-virus software or anti-hacking technology can be a good defense against network threats.
- A. True
- B. False
Answer: B
NEW QUESTION 47
Huawei NIP6000 products provide carrier-class high-reliability mechanisms from multiple levels to ensure the stable operation of equipment.
Which of the following options belong to the network reliability? (multiple choice)
- A. Power supply. 1+1 redundant backup
- B. Dual machine hot backup
- C. Hardware Bypass
- D. Link-group
Answer: B,D
NEW QUESTION 48
If a company wants to detect image files, Shellcode code files and PDF files, which of the following types of sandboxes can be used? (More select)
- A. PDF heuristic sandbox
- B. Heavyweight sandbox (virtual execution)
- C. PE heuristic sandbox
- D. Web heuristic sandbox
Answer: A,B,D
NEW QUESTION 49
Huawei USG6000 products can scan and process certain file transfer protocols for viruses, but which of the following protocols is not included?
- A. TFTP
- B. IMAP
- C. FTP
- D. POP3
Answer: A
NEW QUESTION 50
Regarding the anti-spam response code, which of the following statements is wrong?
- A. If the response code is not returned or the response code is not configured on the USG, the mail is released.
- B. The response code will vary depending on the RBL service provider.
- C. USG treats mails that match the answer code as spam.
- D. The response code is specified as 127.0.0.1 in the second system.
Answer: D
NEW QUESTION 51
After enabling the IP policy, some services are found to be unavailable. Which of the following may be caused by? (multiple choice)
- A. Only packets in one direction pass through the firewall
- B. The same message passes through the firewall multiple times
- C. IPS underreporting
- D. Excessive traffic causes the Bypass function to be enabled
Answer: A,B
NEW QUESTION 52
An enterprise administrator configures the Web reputation system as shown in the figure.
Which of the following statements is true about this configuration?
- A. After the configuration is complete, you need to submit the configuration for it to take effect.
- B. The content of number 2 is mandatory.
- C. In addition to this page configuration, you need to enable the linkage between the firewall and the sandbox. Otherwise, the page configuration is invalid.
- D. The content of number 4 is mandatory.
Answer: C
NEW QUESTION 53
Which of the following options is not a defense against HTTP Flood attacks?
- A. HTTP source statistics
- B. URI source fingerprint learning function
- C. HTTP Flood source authentication
- D. Baseline learning
Answer: D
NEW QUESTION 54
Single-packet attacks are divided into scanning and snooping attacks, malformed packet attacks, and special packet attacks. Ping of death is a special packet attack.
- A. True
- B. False
Answer: B
NEW QUESTION 55
In the security protection system of the cloud era, reforms need to be carried out in the three stages before, during and after the event, and a closed-loop continuous improvement should be formed.
And development. Which of the following key points should be done in "things"? (multiple choice)
- A. Offensive and defensive situation
- B. Defense in Depth
- C. Vulnerability intelligence
- D. Fight back against hackers
Answer: B,D
NEW QUESTION 56
The processing flow of IPS has the following steps;
1. Reorganize application data
2. Match the signature
3. Message processing
4. Protocol identification
Which of the following is the correct order of the processing flow?
- A. 2-4-1-3
- B. 1-3-2-4
- C. 4-1-2-3
- D. 1-4-2-3
Answer: D
NEW QUESTION 57
Which of the following description is incorrect about the cleaning center?
- A. The cleaning equipment supports a variety of flexible attack defense technologies, but it is ineffective for CC attack and ICMP flood attack defense.
- B. There are two drainage ways of static drainage and dynamic drainage.
- C. The re-injection methods include: policy route reinjection, static route reinjection, VPN reinjection, and Layer 2 peering.
- D. The cleaning center completes the function of drainage, cleaning, and flow reinjection after cleaning for abnormal flow.
Answer: A
NEW QUESTION 58
The network-based intrusion detection system is mainly used to monitor the information of the critical path of the network in real time, listen to all packets on the network, collect data, and divide Analyze the suspicious object, which of the following options are its main features? (multiple choices)
- A. Need a lot of monitors.
- B. It can detect the source address and destination address, identify whether the address is illegal, and locate the real intruder.
- C. Good concealment, the network-based monitor does not run other applications, does not provide network services, and may not respond to other computers, so Not vulnerable to attack.
- D. The monitoring speed is fast (the problem can be found in microseconds or seconds, and the host-based DS needs to take an analysis of the audit transcripts in the last few minutes
Answer: C,D
NEW QUESTION 59
For SYN flood attacks, TCP source authentication and TCP proxy can be used for defense.
Which of the following description is correct?
- A. During the TCP proxy process, the firewall proxies and responds to every SYN packet received and maintains half-connection. Therefore, when the traffic of the SYN packet is heavy, the firewall requires very high performance.
- B. TCP proxy means that the firewall is deployed between the client and the server. When the client sends an SYII packet to the server through the firewall, the firewall instead of the server establishes a three-way handshake with the client. Generally used for scenarios where the path of the packet is inconsistent.
- C. TCP source authentication has the same restriction on the path of packets, so the application is not as common as TCP proxy.
- D. After the TCP source authentication passes the source authentication of the client, it is added to the whitelist. Then the SYN packet of this source still needs to be verified.
Answer: A
NEW QUESTION 60
Regarding the mail content filtering configuration of Huawei USG6000 products, which of the following statements is wrong?.
- A. Mail filtering will only take effect when the mail filtering configuration file is invoked when the security policy is allowed.
- B. The attachment size limit is for a single attachment, not for the total size of all attachments.
- C. When an IMAP message is detected, if it is judged to be an illegal email; the firewall's response action only supports sending alarm messages and will not block the email.
- D. When a POP3 message is detected, if it is judged to be an illegal email, the firewall's response action only supports sending alarm information, and will not block the email o
Answer: D
NEW QUESTION 61
Which of the following is not detected action when detecting a virus in a message?
- A. Blocking
- B. Alarms
- C. Announcement
- D. Delete the attachment
Answer: A
NEW QUESTION 62
Which of the following options are the possible reasons why a certain signature is not included after the IPS policy configuration is completed? (multiple choice)
- A. The severity level of the configuration is too high
- B. The protocol selection technique is correct
- C. The direction is turned on, but no specific direction is selected
- D. Direction is not enabled
Answer: A,B,C
NEW QUESTION 63
When misuse detection techniques are used, false positives are reported if the normal user behavior matches the intrusion signature repository successfully.
- A. True
- B. False
Answer: A
NEW QUESTION 64
Which of the following options does not belong to the characteristics of big data technology?
- A. Low value density
- B. Variety of data
- C. Slow processing
- D. Huge amounts of data
Answer: C
NEW QUESTION 65
File filtering technology can filter files based on the application of the file, the file transfer direction, the file type and the file extension.
- A. True
- B. False
Answer: A
NEW QUESTION 66
Regarding the enhanced mode in HTTP Flood source authentication, which of the following descriptions are correct? Multiple choices
- A. Some bots have a redirection function, or the free proxy used during the attack supports the redirection function, which leads to the failure of the basic mode of defense Effective, enhanced mode can effectively defend.
- B. The enhanced mode is superior to the basic mode in terms of user experience.
- C. Enhanced mode supports all HTTP Flood source authentication fields. " WWQQ: 922333
- D. Enhanced mode refers to the authentication method using verification code.
Answer: A,D
NEW QUESTION 67
......
Huawei H12-722-ENU Real 2021 Braindumps Mock Exam Dumps: https://www.actualtests4sure.com/H12-722-ENU-test-questions.html

