
Jul-2021 Latest ExamcollectionPass H12-722 Exam Dumps with PDF and Exam Engine Free Updated Today!
Following are some new H12-722 Real Exam Questions!
NEW QUESTION 91
Which of the following statements about intrusion detection/defense devices are correct? (Multiple Choice)
- A. Can quickly adapt changes in threats.
- B. Protect the intranet from external attacks and suppress malicious traffic, such as spyware, worms, etc., flooding and spreading to the intranet.
- C. Can't effectively resist the spread of viruses from the Internet to the Intranet.
- D. NIP6000 can identify applications up to 6000+, implement fine-grained application protection, save export bandwidth, and ensure the business experience of key services.
Answer: A,B,D
NEW QUESTION 92
The cloud sandbox refers to deploying the sandbox to the cloud and providing tenants with remote detection services. The process includes:
1. Report suspicious files
2. Backtracking attacks
3. Firewall defense linkage
4. Cloud sandbox detection
Which of the following option is correct for the sorting of this process?
- A. 1-3-4-2
- B. 1-4-3-2
- C. 3-1-4-2
- D. 1-4-2-3
Answer: B
NEW QUESTION 93
After the cleaning device establishes a BGP neighbor relationship with the peer router, uses BGP traffic diversion and policy routing reinjection, what configuration needs to be performed on the cleaning device? (Multiple Choice)
- A. [sysname] interface GigabitEthernet 2/0/1 [sysname-GigabitEthernet2/0/1] anti-ddos flow-statistic enable
- B. [sysname] policy-based-route [sysname-policy-pbr] rule name huizhu [sysname-policy-pbr-rule-huizhu] ingress-interface GigabitEthernet 2/0/1 [sysname-policy-pbr-rule-huizhu] action pbr egress-interface GigabitEthernet 2/0/2 next-hop X.X.X.X [sysname-policy-pbr-rule-huizhu] quit
- C. [sysname] route-policy 1 permit node 1 [sysname-route-policy] apply community no-advertise [sysname-route-policy] quit [sysname] bgp 100 [sysname-bgp] peer X.X.X.X as-number 100 [sysname-bgp] import-route unr [sysname-bgp] ipv4-family unicast [sysname-bgp-af-ipv4] peer X.X.X.X route-policy 1 export [sysname-bgp-af-ipv4] peer X.X.X.X advertise-community [sysname-bgp-af-ipv4] quit
- D. <sysname> system-view [sysname] firewall ddos bgp-next-hop X.X.X.X
Answer: B,C
NEW QUESTION 94
Which of the following are true about the e-mail protocol? (Multiple choices)
- A. Use IMAP, the client software download all unread messages to the computer and the mail server deletes the message.
- B. Use IMAP, the user directly operates the mail on the server, and does not need to download all the mails locally and perform various operations.
- C. Use POP3, the client software download all unread messages to the computer and the mail server deletes the message.
- D. Use POP3, the user directly operates the mail on the server, and does not need to download all the mails locally and perform various operations.
Answer: B,C
NEW QUESTION 95
Which of the following options does not belong to packet message attack?
- A. Large ICMP packet attacks
- B. ICMP redirect packet attack
- C. Tracert packet attacks
- D. IP fragmentation packet attacks
Answer: D
NEW QUESTION 96
To protect the security of data transmission, more and more websites or companies choose to encrypt traffic through SSL.
Which of the following statements is true about the threat detection of SSL traffic using Huawei NIP6000?
- A. Threat-detected traffic is sent directly to the server without encryption.
- B. Processes such as "decryption," "threat detection," and "encryption."
- C. NIP000 does not support SSL traffic threat detection.
- D. NIP can directly crack and detect SSL encryption.
Answer: B
NEW QUESTION 97
Due to the differences in network environment and system security policies, intrusion detection systems also differ in their implementation.
In terms of system composition, what are the four major components?
- A. Event recording, intrusion analysis, intrusion response, and remote management.
- B. Event extraction, intrusion analysis, reverse intrusion, and remote management.
- C. Event extraction, intrusion analysis, intrusion response, and field management.
- D. Event extraction, intrusion analysis, intrusion response, and remote management.
Answer: D
NEW QUESTION 98
Which of the following statements is wrong about the Anti-DDoS cloud cleaning solution?
- A. If there is a large traffic attack in the network, send it to the cloud cleaning center to share the cleaning pressure.
- B. Because the Cloud Cleaning Alliance will direct larger attack traffic to the cloud for cleaning, it will cause network congestion.
- C. The cloud cleaning service that is closer to the target being attacked will be transferred first.
- D. Normal attacks are usually cleaned locally first.
Answer: B
NEW QUESTION 99
With regard to traditional firewalls, which of the following statements are correct? (Multiple choice)
- A. It is unable to effectively resist the spread of viruses from the Internet to the internal network.
- B. Lack of effective protection against application layer threats.
- C. Cannot accurately control various applications such as P2P, online games, etc.
- D. Can quickly adapt to changes in threats.
Answer: A,B,C
NEW QUESTION 100
If the regular expression is "abc.de", which of the following will not match the regular expression?
- A. abc.de
- B. abc+de
- C. abcdde
- D. abcde
Answer: D
NEW QUESTION 101
Which of the following are the network layer attacks of the TCP/IP stack? (Multiple Choices)
- A. Buffer overflow
- B. Address scan
- C. Port scanning
- D. IP spoofing
Answer: B,D
NEW QUESTION 102
In the big data intelligent security analysis platform, it is necessary to collect data from the data source, and then complete a series of actions such as data processing, detection and analysis.
Which of the following options does not belong to the data processing part that needs to be completed?
- A. Threat assessment
- B. Data preprocessing
- C. Distributed Index
- D. Distributed storage
Answer: A
NEW QUESTION 103
For the description of the AntiDDoS system, which of the following option is correct?
- A. The detection center mainly uses the control strategy of the security management center to perform traction and cleaning of the attack traffic. The normal traffic after cleaning is injected back to the customer network and sent to the real destination.
- B. The management center mainly completes the processing of attack events, controls the flow policy and cleaning policy of the cleaning center, and classifies various attack events and attack traffic to generate reports
- C. The main role of the cleaning center is to detect and analyze the DDoS attack traffic for the mirrored or light splitting traffic and provide the analysis data to the management center for judgment.
- D. The firewall can only be a detection device.
Answer: B
NEW QUESTION 104
Which of the following statement about IPS is wrong?
- A. The covering signature has a higher priority than the signature in a centralized signature.
- B. Changes to the IPS policy do not take effect immediately. You need to submit a compilation to update the configuration of the IPS policy.
- C. The signature set can contain both pre-defined and custom signatures.
- D. When the source security zone is the same as the destination security zone, the IPS policy is applied in the domain.
Answer: C
NEW QUESTION 105
What content can be filtered by the content filtering technology of Huawei USG6000? (Multiple choice)
- A. Voice content filtering
- B. File content filtering
- C. Application content filtering
- D. Video content filtering
Answer: B,C
NEW QUESTION 106
......
Resources From:
- 2021 Latest ExamcollectionPass H12-722 Exam Dumps (PDF & Exam Engine) Free Share: https://www.examcollectionpass.com/Huawei/H12-722-practice-exam-dumps.html
Free Resources from ExamcollectionPass, We Devoted to Helping You 100% Pass All Exams!