[UPDATED 2022] Huawei H12-722_V3.0 Questions Prepare with Free Demo of PDF
NEW 2022 Certification Sample Questions H12-722_V3.0 Dumps & Practice Exam
NEW QUESTION 49
Use BGP protocol to achieve diversion, the configuration command is as follows
[sysname] route-policy 1 permit node 1
[sysname-route-policy] apply community no-advertise
[sysname-route-policy] quit
[sysname]bgp10029
[sysname-bgp] peer
[sysname-bgp] import-route unr
[sysname- bgpl ipv4-family unicast
[sysname-bgp-af-ipv4] peer 7.7.1.2 route-policy 1 export
[sysname-bgp-af-ipv4] peer 7.7. 1.2 advertise community
[sysname-bgp-af-ipv4] quit
[sysname-bgp]quit
Which of the following options is correct for the description of BGP diversion configuration? (multiple choice)
- A. The management center does not need to configure protection objects. When an attack is discovered, it automatically issues a traffic diversion task.
- B. Use BGP to publish UNR routes to achieve dynamic diversion.
- C. You also need to configure the firewall ddos bgp-next-hop fib-filter command to implement back-injection.
- D. After receiving the UNR route, the peer neighbor will not send it to any BGP neighbor.
Answer: B,D
NEW QUESTION 50
The following is a hardware SACG increase firewall configuration, which statement below is true?
- A. Primary IP: 10.1.3.6 on behalf of Policy Center linkage firewall interface IP address, the standby IP can enter another alternate firewall interface IP address.
- B. Primary IP: 10.1.3.6 on behalf of SM Manager IP address.
- C. Primary IP: 10.1.3.6 on behalf of Policy Center linkage firewall interface IP address, the standby IP can enter another interface IP address of the firewall.
- D. Main IP is the Policy Center reaches the next-hop firewall device interface address
Answer: A,B
NEW QUESTION 51
What are the typical technologies of anti-virus engines (multiple choice)
- A. First package detection technology
- B. File reputation detection technology 5
- C. Heuristic detection technology
- D. Decryption technology
Answer: A,B,C
NEW QUESTION 52
Regarding the 3 abnormal situations of the file type recognition result, which of the following option descriptions is wrong?
- A. Unrecognized file type means that the file type cannot be recognized and there is no file extension.
- B. Unrecognized file type means that the file type cannot be recognized, and the file extension cannot be recognized.
- C. File damage means that the file type cannot be identified because the file is damaged.
- D. File extension mismatch means that the file type is inconsistent with the file extension.
Answer: B
NEW QUESTION 53
Regarding traditional firewalls, which of the following statements are correct? (multiple choice)
- A. Ability to quickly adapt to changes in threats.
- B. Unable to accurately control various applications, such as P2P, online games, etc. .
- C. Lack of effective protection against application layer threats.
- D. It cannot effectively resist the spread of viruses from the Internet to the intranet.
Answer: B,C,D
NEW QUESTION 54
Which three aspects should be considered in the design of cloud platform security solutions? (multiple choice)
- A. How to do a good job in management, operation and maintenance
- B. Hardware maintenance
- C. Tenant security
- D. Infrastructure security
Answer: A,C,D
NEW QUESTION 55
USG6000V software logic architecture is divided into three planes: management plane, control plane and
- A. Business plane
- B. Configuration plane
- C. Data forwarding plane
- D. Log plane
Answer: C
NEW QUESTION 56
File filtering technology can filter files based on the application of the file, the file transfer direction, the file type and the file extension.
- A. True
- B. False
Answer: A
NEW QUESTION 57
When using the two-way SSL function to decrypt HTTPS packets, the value of the reverse proxy level represents the number of times the packet can be decrypted.
- A. True
- B. False
Answer: B
NEW QUESTION 58
Intrusion detection is a network security technology used to detect any damage or attempt to damage the confidentiality, integrity or availability of the system. Which of the following What is the content of the intrusion detection knowledge base?
- A. Security Policy
- B. Specific behavior patterns
- C. Complete Trojan Horse
- D. Complete virus sample
Answer: B
NEW QUESTION 59
Among the following options, which attack is a malformed packet attack based on the TCR protocol?
- A. Teardrop attack
- B. IP Spoofng attack
- C. Land attack
- D. Ping of Death attack
Answer: C
NEW QUESTION 60
The following figure shows the configuration of the URL filtering configuration file. Regarding the configuration, which of the following statements is correct?
- A. The default action means that all websites are allowed to visit. So the configuration is wrong here.
- B. The firewall will first check the blacklist entries and then the whitelist entries.
- C. Assuming that the user visits the www.exzample.com website, which belongs to the categories of humanities and social networks at the same time, the user cannot access the website.
- D. The user visits the website www.exzample.com, and when the black and white list is not hit, the next step is to query the predefined URL category entry.
Answer: C
NEW QUESTION 61
Regarding HTTP behavior, which of the following statements is wrong?
- A. HTTP POST is generally used to send information to the server through a web page, such as forum posting x form submission, username I password login.
- B. When the file upload operation is allowed, the alarm threshold and blocking threshold can be configured to control the size of the uploaded file.
- C. When the size of the uploaded or downloaded file and the size of the content of the POST operation reach the alarm threshold, the system will generate log information to prompt the device management And block behavior.
- D. When the uploaded or downloaded file size, POST operation content size reaches the blocking threshold, the system will only block the uploaded or downloaded file, POST operate.
Answer: D
NEW QUESTION 62
Threats detected by the big data intelligent security analysis platform will be synchronized to each network device at the same time C and then collected from the network device Collect it in the log for continuous learning and optimization.
- A. True
- B. False
Answer: A
NEW QUESTION 63
Regarding the mail content filtering configuration of Huawei USG6000 products, which of the following statements is wrong?.
- A. Mail filtering will only take effect when the mail filtering configuration file is invoked when the security policy is allowed.
- B. The attachment size limit is for a single attachment, not for the total size of all attachments.
- C. When an IMAP message is detected, if it is judged to be an illegal email; the firewall's response action only supports sending alarm messages and will not block the email.
- D. When a POP3 message is detected, if it is judged to be an illegal email, the firewall's response action only supports sending alarm information, and will not block the email o
Answer: D
NEW QUESTION 64
Content filtering is a security mechanism for filtering the content of files or applications through Huawei USCG00 products. Focus on the flow through deep recognition Contains content, the device can block or alert traffic containing specific keywords.
- A. True
- B. False
Answer: A
NEW QUESTION 65
Which of the following threats cannot be detected by IPS?
- A. Virus
- B. DoS
- C. Spam
- D. Worms
Answer: C
NEW QUESTION 66
Which of the following options does not belong to the security risk of the application layer of the TCP/IP protocol stack?
- A. Virus
- B. Buffer overflow
- C. System vulnerabilities
- D. Port scan
Answer: D
NEW QUESTION 67
......
H12-722_V3.0 Deluxe Study Guide with Online Test Engine: https://actualtest.updatedumps.com/Huawei/H12-722_V3.0-updated-exam-dumps.html