Huawei HCIP-Security-CSSN(Huawei Certified ICT Professional -Constructing Service Security Network) - H12-722-ENU Exam Practice Test
The network-based intrusion detection system is mainly used for real-time monitoring of critical network path information, listening to all packets on the network, collecting data, and analyzing suspicious objects. Which of the following options are its main features? (Multiple Choice)
Correct Answer: B,D
A college user needs are as follows:
1. The environmental traffic is relatively large and can add up to 800M in both directions. Huawei USG6000 series firewalls are deployed at its network nodes.
2. The intranet is divided into student areas, server areas, etc. Users are most concerned about the security of the server area and avoid being attacked by various types of threats.
3. At the same time, some pornographic websites in the student district are prohibited.
The external network is configured as untrust zone on the firewall, and the internal network is configured as trust zone. How to configure the firewall to meet the above requirements? (Multiple choices)
1. The environmental traffic is relatively large and can add up to 800M in both directions. Huawei USG6000 series firewalls are deployed at its network nodes.
2. The intranet is divided into student areas, server areas, etc. Users are most concerned about the security of the server area and avoid being attacked by various types of threats.
3. At the same time, some pornographic websites in the student district are prohibited.
The external network is configured as untrust zone on the firewall, and the internal network is configured as trust zone. How to configure the firewall to meet the above requirements? (Multiple choices)
Correct Answer: A,B,D
Which of the following statement is wrong about a network intrusion detection system (NIDS)?
Correct Answer: A
Regarding the local black and white list of anti-spam messages, which of the following statements is wrong?
Correct Answer: A
About firewalls and IDS, which of the following is true?
Correct Answer: C
To protect the security of data transmission, more and more websites or companies choose to encrypt traffic through SSL.
Which of the following statements is true about the threat detection of SSL traffic using Huawei NIP6000?
Which of the following statements is true about the threat detection of SSL traffic using Huawei NIP6000?
Correct Answer: C
Which of the following is correct about the AntiDDoS system configuration?
Correct Answer: A
For compressed files, the virus detection system can directly detect.
Correct Answer: A
Information security is the protection of information and information systems against unauthorized access, use, disclosure, interruption, modification, destruction and thereby providing confidentiality, integrity and availability.
Correct Answer: A
When the AntiDDoS system detects attack traffic, the attack traffic is directed to the cleaning device. After the cleaning device completes cleaning, the traffic is re-injected to the original link. Which of the following options does not belong to the injection method?
Correct Answer: B
The DDoS attack defense configuration process is as follows:
1, start the flow statistics function;
2. Set different protection thresholds for different types of attacks;
3. When the traffic exceeds the preset threshold, the system starts attack defense.
1, start the flow statistics function;
2. Set different protection thresholds for different types of attacks;
3. When the traffic exceeds the preset threshold, the system starts attack defense.
Correct Answer: B
Configure the following command on the Huawei firewall:
[USG] interface G0/0/1
[USG] ip urpf loose allow-default-route acl 3000
Which of the following options are correct? (Multiple choice)
[USG] interface G0/0/1
[USG] ip urpf loose allow-default-route acl 3000
Which of the following options are correct? (Multiple choice)
Correct Answer: A,B,C
Threat after the big data intelligent security analysis platform detect will be synchronized to each network device, and then continue to learn and optimize by collecting to the logs from the network device.
Correct Answer: A
Which of the following attacks are belong to attacks against Web servers? (Multiple choices)
Correct Answer: B,C