In the construction of information security, the intrusion detection system plays the role of a monitor. It monitors the flow of key nodes in the information system. In-depth analysis to discover security incidents that are occurring. Which of the following are its characteristics?
-
A
IDS can be linked with firewalls and switches to become a powerful "assistant" of firewalls, which can better and more accurately control access between domains.
-
B
It is impossible to correctly analyze the malicious code doped in the allowed application data stream.
-
C
Unable to detect malicious operations or misoperations from internal killings.
-
D
Cannot do in-depth inspection.
Reveal answer details
Close answer details
Regarding computer viruses, which of the following options is correct?
-
A
Patching the system can completely solve the virus intrusion problem.
-
B
Computer viruses are latent, they may be latent for a long time, and only when they encounter certain conditions will they begin to carry out sabotage activities.
-
C
Computer viruses are contagious. They can spread through floppy disks and CDs, but they will not spread through the Internet.
-
D
All computer viruses must be parasitic in files and cannot exist independently.
Reveal answer details
Close answer details
Question 3
Multiple choice
Configure the following commands on the Huawei firewall: [USG] interface G0/0/1
[USG] ip urpf loose allow-default-route acl 3000 Which of the following options are correct? (Choose Two)
-
A
For loose inspection: if the source address of the packet exists in the FIB of the firewall, the packet passes the inspection directly.
-
B
In the case where the default route is configured but the parameter allow-default-route is not configured, if the source address of the packet does not exist in the FIB table of the firewall, the packet will be rejected.
-
C
When the default route is configured and the parameter allow-default-route is also configured, if the source address of the packet does not exist in the FIB table of the firewall under loose check mode, all packets will pass the URPF check and be forwarded normally.
-
D
When the default route is configured and the parameter allow-default-route is also configured, if the source address of the packet does not exist in the FIB table of the firewall under loose check mode, the packet cannot pass the URPF check.
Reveal answer details
Close answer details
Under the CLI command, which of the following commands can be used to view the AV engine and virus database version?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Regarding the processing process of file filtering, which of the following statements is correct?
-
A
The file filtering module will compare the application type, file type, and transmission direction of the file identified by the previous module with the file filtering rules configured by the administrator, then the lookup table performs matching from top to bottom.
-
B
If all the parameters of the file can match a file filtering rule, then the module will execute the action of that file filtering rule.
-
C
There are two types of actions: warning and blocking.
-
D
If the file type is a compressed file, then after the file filtering check the compressed file will be sent to the file decompression module for decompression to extract the original file. If the decompression fails, the file will not be released.
Reveal answer details
Close answer details
An enterprise has 3 server, which is the most reasonable plan when deploy Policy Center system planning?
-
A
manager + controller + FTP + witness database, controller + master database + FTP, controller + mirror database+ FTP
-
B
manager + controller + FTP + master database, controller + FTP + witness database, controller + FTP + mirror database
-
C
manager + controller + FTP + mirror database, controller + FTP + witness database, controller + FTP + master database
-
D
manager + controller + FTP, controller + FTP + witness databases, controller + FTP + master database
Reveal answer details
Close answer details
Which of the following is not an abnormal situation of the file type recognition result?
-
A
The file extension does not match.
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 8
Multiple choice
In the security protection system of the cloud era, reforms need to be carried out in the three stages: before, during, and after the event, to form a closed-loop of continuous improvement and development. Which of the following key points should be done during the event? (Choose Two)
-
A
Vulnerability intelligence
-
B
-
C
Offensive and defensive situation
-
D
Fight back against hackers
Reveal answer details
Close answer details
Question 9
Multiple choice
Which of the following descriptions about viruses and Trojans are correct? (Choose Two)
-
A
Viruses are triggered by computer users
-
B
Viruses can replicate themselves
-
C
Trojan horses are triggered by computer users
-
D
Trojans can replicate themselves
Reveal answer details
Close answer details
Question 10
Single choice
The virus signature database on the device needs to be continuously upgraded from the security center platform. Which of the following is the website of the security center platform?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 11
Multiple choice
Which of the following options belong to the keyword matching mode? (Choose Two)
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 12
Single choice
Regarding Huawei's anti-virus technology, which of the following statements is wrong?
-
A
The virus detection system cannot directly detect compressed files
-
B
The anti-virus engine can detect the file type through the file extension
-
C
Gateway antivirus default file maximum decompression layer is 3 layers
-
D
The implementation of gateway antivirus is based on proxy scanning and stream scanning
Reveal answer details
Close answer details
Question 13
Single choice
For Huawei USG600 products, which of the following statements about mail filtering configuration is correct?
-
A
Cannot control the number of received email attachments.
-
B
When the spam processing action is an alert, the email will be blocked and an alert will be generated.
-
C
You can control the size of the attachment of the received mail.
-
D
Cannot perform keyword filtering on incoming mail.
Reveal answer details
Close answer details
Question 14
Single choice
Which of the following options describes the IntelliSense engine IAE incorrectly?
-
A
lAE's content security detection functions include application identification and perception, intrusion prevention, and Web application security.
-
B
Full English name: intelligent Awareness Engine.
-
C
The core of C.IAE is to organically centralize all content security-related detection functions.
-
D
The security detection of the IAE engine is parallel, using a message-based file processing mechanism, which can receive file fragments and perform security checks.
Reveal answer details
Close answer details
Question 15
Multiple choice
Which of the following protocols can be used to construct attack messages for special control message attacks? (Choose Three)
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 16
Multiple choice
Which of the following options belong to the upgrade method of the anti-virus signature database of Huawei USG6000 products? (Choose Two)
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 17
Single choice
Regarding the Anti-DDoS cloud cleaning solution, which of the following statements is wrong?
-
A
Ordinary attacks will usually be cleaned locally first.
-
B
If there is a large traffic attack on the network, send it to the cloud cleaning center to share the cleaning pressure.
-
C
Since the Cloud Cleaning Alliance will direct larger attack flows to the cloud for cleaning, it will cause network congestion.
-
D
The closer it is to the attacked self-labeled cloud cleaning service, the higher the priority.
Reveal answer details
Close answer details
Question 18
Single choice
UDP is a connectionless protocol. UDP Flood attacks that change sources and ports will cause performance degradation of network devices that rely on session forwarding. Even the session table is exhausted, causing the network to be paralyzed. Which of the following options is not a preventive measure for UDP Flood attacks?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 19
Multiple choice
What content can be filtered by the content filtering technology of Huawei USG6000 products? (Choose Two)
-
A
Keywords contained in the content of the uploaded file
-
B
Keywords contained in the downloaded file
-
C
-
D
Reveal answer details
Close answer details
Question 20
Single choice
Regarding the sequence of the mail transmission process, which of the following is correct? 1. The sender PC sends the mail to the designated SMTP Server. 2. The sender SMTP Server encapsulates the mail information in an SMTP message and sends it to the receiver SMTP Server according to the destination address of the mail 3. The sender SMTP Server encapsulates the mail information in an SMTP message according to the destination address of the mail and sends it to the receiver POP3/MAP Senver 4. The recipient sends an email.
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 21
Single choice
The anti-tampering technology of Huawei WAF products is based on the cache module. Suppose that when user A visits website B, website B shows signs of page tampering. The workflow for the WAF tamper-proof module includes the following steps: WAF starts the learning mode to learn the page content of the user's visit to the website. WAF stores the content of the page in the cache after learning. When the user accesses the webpage, WAF obtains the page content from the server. WAF compares the watermark of the server page content with the page content in the cache. If tampering is detected, WAF uses the cached page to return to the client. For the ordering of these steps, which of the following options is correct?
-
A
WAF starts the learning mode Stores the page content in the cache Obtains page content from the server Compares watermark Uses cached page to return to the client.
-
B
WAF obtains page content from the server Compares watermark Starts the learning mode Stores the page content in the cache Uses cached page to return to the client.
-
C
WAF starts the learning mode Obtains page content from the server Stores the page content in the cache Compares watermark Uses cached page to return to the client.
-
D
WAF obtains the page content from the server Starts the learning mode Stores the page content in the cache Compares watermark Uses cached page to return to the client.
Reveal answer details
Close answer details
Question 22
Single choice
In order to protect the security of data transmission, more and more websites and companies choose to use SSL to encrypt transmissions in the stream. Regarding the use of Huawei NIP6000 products to perform threat detection on SSL streams, which of the following statements is correct?
-
A
NIP6000 does not support SSL threat detection.
-
B
The traffic after threat detection is sent directly to the server without encryption.
-
C
NIP can directly decrypt and detect SSL-encrypted traffic.
-
D
After the process of "decryption," "threat detection," and "encryption," the traffic is sent securely.
Reveal answer details
Close answer details
Question 23
Single choice
SQL injection attacks generally have the following steps: Elevate the right Get the data in the database Determine whether there are loopholes in the webpage Determine the database type For the ordering of these steps, which of the following options is correct?
-
A
Determine whether there are loopholes in the webpage Determine the database type Get the data in the database Elevate the right.
-
B
Determine the database type Determine whether there are loopholes in the webpage Get the data in the database Elevate the right.
-
C
Determine whether there are loopholes in the webpage Get the data in the database Determine the database type Elevate the right.
-
D
Get the data in the database Determine whether there are loopholes in the webpage Determine the database type Elevate the right.
Reveal answer details
Close answer details
Question 24
Single choice
Which of the following options is not a feature of big data technology?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 25
Multiple choice
Use the BGP protocol to achieve diversion. The configuration commands are as follows: [sysname] route-policy 1 permit node 1 [sysname-route-policy] apply community no-advertise [sysname-route-policy] quit [sysname] bgp 100 [sysname-bgp] peer [sysname-bgp] import-route unr [sysname-bgp] ipv4-family unicast [sysname-bgp-af-ipv4] peer 7.7.1.2 route-policy 1 export [sysname-bgp-af-ipv4] peer 7.7.1.2 advertise community [sysname-bgp-af-ipv4] quit [sysname-bgp] quit Which of the following options is correct for the description of the BGP diversion configuration? (Choose Two)
-
A
Use BGP to publish UNR routes to achieve dynamic diversion.
-
B
After receiving the UNR route, the peer neighbor will not send it to any BGP neighbor.
-
C
You also need to configure the firewall anti-ddos bgp-next-hop fib-filter command to implement back injection.
-
D
The management center does not need to configure protection objects. When an attack is discovered, it automatically issues a traffic diversion task.
Reveal answer details
Close answer details
Question 26
Single choice
If the processing strategy for SMTP virus files is set to alert, which of the following options is correct?
-
A
Generate logs and discard
-
B
Generate logs and forward them
-
C
Delete the content of the email attachment
-
D
Add announcement and generate log
Reveal answer details
Close answer details
Question 27
Multiple choice
The anti-virus feature configured on the Huawei USG6000 product does not take effect. Which of the following are the possible reasons? (Choose Three)
-
A
The security policy does not reference the anti-virus configuration file.
-
B
The anti-virus configuration file is configured incorrectly.
-
C
The virus signature database version is older.
-
D
No virus exceptions are configured.
Reveal answer details
Close answer details
Question 28
Single choice
The security management system is only optional, and anti-virus software or anti-hacking technology can be a good defense against network threats.
-
A
-
B
Reveal answer details
Close answer details
Question 29
Single choice
Since the sandbox can provide a virtual execution environment to detect files in the network, the sandbox can be substituted when deploying security equipment Anti-Virus, IPS, spam detection and other equipment.
-
A
-
B
Reveal answer details
Close answer details
Question 30
Single choice
For the description of the Anti-DDoS system, which of the following options is correct?
-
A
The detection center mainly pulls and cleans the attack traffic according to the control strategy of the security management center and re-injects the cleaned normal traffic back into the user network, sending it to the real destination.
-
B
The management center mainly processes attack events, controls the diversion and cleaning strategies of the cleaning center, categorizes and analyzes various attack events and attack traffic, and generates reports.
-
C
The main function of the cleaning center is to detect and analyze DDoS attack traffic from mirrored or split traffic and provide analysis data to the management center for judgment.
-
D
The firewall can only be used as inspection equipment.
Reveal answer details
Close answer details
Question 31
Multiple choice
For the description of URPF technology, which of the following options are correct? (Choose Two)
-
A
The main function is to prevent network attacks based on source address spoofing.
-
B
In strict mode, it does not check whether the interface matches. As long as there is a route to the source address, the message can pass.
-
C
The loose mode not only requires corresponding entries in the forwarding table, but also requires that the interface must match to pass the URPF check.
-
D
Use URPF's loose mode in an environment where routing symmetry cannot be guaranteed.
Reveal answer details
Close answer details
Question 32
Multiple choice
Which of the following options belong to the network layer attack of the TCP/IP protocol stack? (Choose Two)
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
|