Exam Name: HCIP-Security-CTSS(Huawei Certified ICT Professional -Constructing Terminal Security System)

Updated: 2019-06-16

Q & A: 177

Question No : 1

IPS custom signature in UTM supports you to set direction and protocol type.
Answer: A

Question No : 2

Which of the following behaviors IPS can not detect?
A. Virus
B. Worm
C. Spam
Answer: C

Question No : 3

Administrator creates the correct IPS strategy, applied to domain or inter-domain , but found that no matter in the IPS signature set movement is blocking or alarm, when the invasion attack, only produce the alarm..
What is the reason for this problem?
A. Set IPS work mode in the IPS global parameters for alarm
B. did not select the correct domain
C. did not configure corresponding IPS strategy
D. congigure Firewall running mode for Firewall mode
Answer: A

Question No : 4

IPS signature set priorities can not be adjusted.
Answer: B

Question No : 5

Enterprise Intranet users access to the Internet, what may cause the UFL filtering function failure? (Select 3 answers)
A. no reference URL filtering strategy in Web filtering policy
B. no Web filtering strategy applied in the corresponding direction in inter-domain
B. the URL filtering strategy in the corresponding filter sub-function switch did not open
C. Web content filtering is not enabled
Answer: ABC

Question No : 6

The greater Virus Scan rating value, the higher the virus detection rate, but the smaller the probability of false positives.
Answer: B

Question No : 7

URL filtering configure exact match www.test.com/news field, then not meet the URL of the filtering strategy include:
A. http://www.test.com/news
B. www.test.com/news/
D. www.test.com/news.aspx
Answer: D

Question No : 8

Perform the UTM upgrade in the process of operation, appeared the following information:
Error: Executing the update, please wait.
USG may be executed (choose 3 answers)
A. online upgrade
B. there are business flow being processed
C. local upgrade
D. install the factory default version
Answer: ACD

Question No : 9

Which statement is wrong about SA principle configuration?
A. feature detection to identify the different applications by matching message feature and Knowledge Base feature set
B. reduce the maximum number of packets detection threshold, can reduce the sas module identification number of packets, thus improve the recognition rate agreement
C. There are some protocol packets are carried in other agreements, enable sa whole packet inspection can better detect such messages
D. Configure SA associated protocol identification is mainly used for the same data stream signaling channel and data channel associated with the identification , and thus identify protocol
Answer: B

Question No : 10

URL filtering, according to the classification of the remote or local classification, the user can create multiple urls strategy, determines the corresponding processing action in URL strategies, a URL strategy was applied to the domain, which can realize the corresponding URL filtering.
Answer: A

Question No : 11

Which of the following statement is wrong about NIP?
A. NIP compare the data packet and application knowledge base, identify specific data flow
B. NIP support for specific IP network segment, in a specific time period, for strategy processing
C. NIP using leading hardware architecture, FPGA realization of the application layer acceleration, ESP achieve forward acceleration
D. NIP Manager supports mail alarm response mode
Answer: C

Question No : 12

For security priority application environment, should be closed Huawei firewall UTM overload protection function.
Answer: A

Question No : 13

URL filtering, remote classification list provided and maintained by a third-party classification servers, devices can be synchronous updated automatically or manually from third-party classification servers.
Answer: A

Question No : 14

In SA detection technology, which feature detection matching method does not include?
A. single packet match
B. IP match
C. multi-Pack match
D. multi-stream match
Answer: B

Question No : 15

Which of the following statement is correct IDS and IPS?
A. IDS only supports Inline online deployment
B. IPS deployed as a bypass mode is similar to the function of ID
C. the core technology of IPS is deep packet inspection and bypass inspection
D. With the IPS does not need to deploy a firewall and IDS
Answer: B
