Pass ACA-Sec1 Exam - Real Test Engine PDF with 145 Questions [Q41-Q58]

Share

Pass ACA-Sec1 Exam - Real Test Engine PDF with 145 Questions

Get New ACA-Sec1 Certification Practice Test Questions Exam Dumps


Alibaba ACA-Sec1 Exam Syllabus Topics:

TopicDetails
Topic 1
  • Activating, creating, configuring, starting and stopping and disabling a service
Topic 2
  • Familiar with operations of Alibaba Cloud Security related products
Topic 3
  • Aware of main application scenarios of Alibaba Cloud Security related products and know each of these products’ special usage scenario
Topic 4
  • Understanding of the concepts of Alibaba Cloud Security related products
Topic 5
  • Knowledge of network security, such as firewall policy, key encryption, access control, network security, and network attack and protection methodologies
Topic 6
  • Familiar with features of Alibaba Cloud Security related products and key product implementation principles
Topic 7
  • Familiar with common network protocols such as HTTP, FTP, TCP, UDP and ICMP
Topic 8
  • Virtualization, storage and networking
  • Familiar with operation on Linux and Windows operating system and be able to configure network and storage related system commands
Topic 9
  • Familiar with the concepts and related knowledge of Cloud Computing
Topic 10
  • Able to discover and resolve common issues emerged during the use of Alibaba Cloud Security related products

 

NEW QUESTION 41
What modes Alibaba Cloud WAF will provide to defend SQL injection? (the number of correct answers: 2) Score 1

  • A. Protection Mode
  • B. Normal Mode
  • C. Warning Mode
  • D. Restriction Mode

Answer: A,C

 

NEW QUESTION 42
ECS cloud server is one of the service provided by Alibaba Cloud. If it is attacked by some internet hacker, which of the following consequences such attack could cause? (the number of correct answers: 2)

  • A. Leak of customer sensitive data
  • B. Service running on this ECS become not available
  • C. The datacenter where the ECS belongs to need to shutdown
  • D. Physical Server Damage

Answer: A,B

 

NEW QUESTION 43
Identify the attack where the purpose is to stop a workstation or service from functioning?

  • A. This attack is known as non-repudiation
  • B. This attack is known as TCP/IP hijacking
  • C. This attack is known as brute force
  • D. This attack is known as denial of service (DoS)

Answer: D

 

NEW QUESTION 44
Which of the following options can be considered as Data and Application security risks in IT infrastructure

  • A. Data access control
  • B. Data integrity
  • C. Data readiness
  • D. Data encryption

Answer: A,B,D

 

NEW QUESTION 45
Using ECS security group can help you achieve:

  • A. enlarge your network bandwidth
  • B. better CPU usage
  • C. apply QOS to a specific IP
  • D. fine grained access control to you server

Answer: D

 

NEW QUESTION 46
Which of the following protection rules are provided by WAF to better protect from CC attack? (the number of correct answers: 2)

  • A. Strict
  • B. Emergency
  • C. Normal
  • D. Loose

Answer: A,D

 

NEW QUESTION 47
Which of following elements are included in a TCP/IP based route table? (the number of correct answers: 3)

  • A. Netmask
  • B. Port
  • C. Gateway IP
  • D. Network Destination
  • E. Mac Address

Answer: A,C,D

 

NEW QUESTION 48
Anti-DDOS basic is provided by Alibaba Cloud for free. Which of the following statements about this service are NOT true? (the number of correct answers: 2) Score 1

  • A. basic anti-DDOS service can protect any server connect to internet
  • B. basic anti-DDOS service can detect attack traffic and migrate them automatically
  • C. no protection upper limit to the rate of attack traffic
  • D. CC attack protection need to be turned on manually

Answer: B,C

 

NEW QUESTION 49
User A rented 2 ECS server and one RDS in Alibaba Cloud to setup his company public website. After the web site will become available online, the security risks he/she will face will include: (the number of correct answers: 3)

  • A. RDS DB got unknown remote logon
  • B. ECS admin password is hacked
  • C. physical cable is cut by someone
  • D. the disk in ECS is broken
  • E. website codes has some vulnerability

Answer: A,B,E

 

NEW QUESTION 50
18.in RedHat Linux shell which command can be used to check what file system is mounted and form what disk device it was done?

  • A. Fdisk
  • B. Du
  • C. mount
  • D. Ppart

Answer: C

 

NEW QUESTION 51
Which Internet protocol is used to implement Linux shell command 'ping'?
Score 2

  • A. ICMP
  • B. PING
  • C. TCP
  • D. UDP

Answer: A

 

NEW QUESTION 52
What will the correct stops the traffic will flow through if the user used all following cloud service: WAF, Anti-DDOS pro, CDN.

  • A. CDN- >Anti-DDOS Pro->WAF->Original Website
  • B. Anti-DDOS Pro->WAF->CDN->Original website
  • C. Anti-DDOS Pro->CDN->WAF->Original website
  • D. CDN- >WAF->Anti-DDOS Pro->Original website

Answer: C

 

NEW QUESTION 53
Which of following statement about 'Server Guard' Trojan scanning functionality is NOT correct?
Score 2

  • A. Server Guard will delete any suspicious webshell file immediately
    My
  • B. Server Guard Agent will automatically scan your web pages directories and look for any webshell file.
  • C. A change to a file in the web pages directories will trigger a scan for that file
  • D. you can log on to the Server Guard console to isolate webshell files with one click.

Answer: A

 

NEW QUESTION 54
Inside cloud, hypervisor vulnerability could cause the following possible consequences: (the number of correct answers: 3)

  • A. One client host can access another client's data
  • B. User service become unavailable
  • C. Incorrect client resource usage calculating
  • D. Hacker can access host server directly

Answer: A,B,D

 

NEW QUESTION 55
Which of the following 2 security risks are not included in OWASP published 2017 Top 10 Web Application Security Risks

  • A. Unvalidated Redirects and Forwards
  • B. Cross-Site Scripting(XSS)
  • C. Injection
  • D. Cross-Site Request Forgery(CSRF)

Answer: A,D

 

NEW QUESTION 56
CC attacks can cause serious damages. Which of the following statements about CC attack is not correct?
Score 2

  • A. CC attack is done on network layer
  • B. Will consume massive sever side resource
  • C. The request generated by CC attack is hard to be distinguished from normal requests
  • D. CC attack will simulate real user requests

Answer: A

 

NEW QUESTION 57
Which of these options contains the three basic target categories for a DoS or a DDoS?

  • A. Systems, memory, network access card
  • B. Networks, systems and applications
  • C. Network access card, applications, peripheral devices
  • D. Resources, printers and storage devices

Answer: B

 

NEW QUESTION 58
......

ACA-Sec1 Exam Dumps - PDF Questions and Testing Engine: https://www.certkingdompdf.com/ACA-Sec1-latest-certkingdom-dumps.html