
Certification Training for ACP-Sec1 Exam Dumps Test Engine [2021]
Sep 14, 2021 Step by Step Guide to Prepare for ACP-Sec1 Exam
NEW QUESTION 25
Data Risk Control feature has been integrated into Alibaba Cloud WAF. When this function is activated, a script must be embedded into the page that wishes to be protected under the corresponding domain name to check whether a client is trustworthy. Which type of script is it?
- A. Java
- B. C++
- C. Vbscript
- D. JavaScript
Answer: D
NEW QUESTION 26
In which of the following scenarios is Alibaba Cloud Security Center applicable? (Number of correct answers
3)
- A. Creating an ECS with generic software
- B. Setting up web server to provide web service to public
- C. Penetration testing
- D. Network security protection for ad campaigns or other activities
- E. Batch server security O&M
Answer: C,D,E
NEW QUESTION 27
When applying for an SSL certificate through Alibaba Cloud's SSL Certificates Service, there is an offline review process which can take 3-5 business days or 5-7 business days depending on the type of certificate you have applied for:
- A. True
- B. False
Answer: A
NEW QUESTION 28
Which of the following attacks can Alibaba Cloud Anti-DDoS Basic defend against? (Number of coned answers 4)
- A. CMP Flood
- B. SYN Flood
- C. UDP Flood
- D. ACK Flood
- E. Brute force password cracking
Answer: B,C,D,E
NEW QUESTION 29
Cross Site Script (XSS) attacks refer to a kind of attack by tampering the webpage using HTML injection to insert malicious scripts so as to control the user's browser when the user browses the webpage XSS vulnerabilities may be used for user identity stealing (particularly the administrator identity), behavior hijacking, Trojan insertion and worm spreading, and also phishing
- A. True
- B. False
Answer: A
NEW QUESTION 30
Alibaba Cloud Security's Data R.sk Control can effectively resolve junk registration, database hacking, and other service risk identification problems To use this service. you need to first collect service data. Which of the following methods can be used to collect information off Web application systems?
- A. HTML5
- B. JavaScript, SDK
- C. JavaScript
- D. SDK
Answer: C
NEW QUESTION 31
When you receive a security alert from Alibaba Cloud Security Center, which of the following actions should you do?
- A. Shield the alert because it is not important
- B. Once you receive an alert, you need to determine the specific risk and perform troubleshooting For example, change the password, or upgrade application software
- C. The alert is dangerous You must immediately report it to the police
- D. There is no need to care about the alert Alibaba Cloud Security Center will handle it.
Answer: B
NEW QUESTION 32
Alibaba Cloud WAF is a security protection product based on Alibaba Group's web security defense experience accumulated over more than a decade By defending against common OWASP attacks, providing patches to fix vulnerabilities, and allowing users to customize protection policies for website services, WAF can successfully safeguard the security and availability of websites and web applications. Which of the following types of security configurations does WAF provide? (Number of correct answers 3)
- A. Web application attack protection
- B. Precision access control
- C. CC protection
- D. Port access control
Answer: A,C,D
NEW QUESTION 33
Alibaba Cloud's CloudMonitor can not only monitor ECS instances in a secure and efficient way, but also monitor HTTP sites of clients' servers in data centers However, in the latter case, Alibaba Cloud does not provide monitor agent so users need to develop their own scripts to collect data
- A. False
- B. True
Answer: A
NEW QUESTION 34
When a Layer-4 forwarding rule is configured with multiple origin site IP addresses, Alibaba Cloud Anti-ODoS Premium Service will perform load balancing for Layer-4 requests using balancing algorithm
- A. True
- B. False
Answer: A
NEW QUESTION 35
Alibaba Cloud WAF cannot protect against large traffic DDoS attacks which can be solved by Alibaba Cloud Ant-DDoS Service.
- A. True
- B. False
Answer: A
NEW QUESTION 36
If a user has multiple ECS instances on Alibaba Cloud but has no professional O&M team or is unwilling to put efforts in O&M, the user can activate Alibaba Cloud Security Center which provides security expert services like manual security checking, Trojan removing and hosted service monitoring.
- A. True
- B. False
Answer: A
NEW QUESTION 37
Which of the following methods can be used to download the metric data of Alibaba Cloud CloudMonitor?
- A. You can only view the reports, but cannot download them.
- B. Download the data through Open APIs
- C. You can download the data through both the console and Open APIs
- D. Download the data from the console
Answer: C
NEW QUESTION 38
Alibaba Cloud Ant.-DDoS Premium Service is an advanced DDoS protection product It can defend against layer 4 and layer 7 attacks. Which of the following statements about Alibaba Cloud Anti-DDoS Premium Service is FALSE?
- A. You can adjust the anti-DDoS elastic protection threshold to a higher level at any time, with the service interruption period no longer than 3 minutes
- B. Anti-DDoS Premium Service supports 2 billing modes: Unlimited and Insurance.
- C. Anti-DDoS Premium Service defends against various DDoS attacks, including but not limited to ICMP flood, UDP flood, TCP flood. SYN flood, and ACK flood attacks
- D. Anti-DDoS Premium Service provides precise traffic reports and attack details in real time to keep you informed of the current service details on time
Answer: B
NEW QUESTION 39
After you activate the button Data Risk Control feature in Alibaba Cloud WAF. Which of the following risk control verification modes m displayed if you directly request for a risk control protection URL?
- A. QR code verification
- B. Slider verification
- C. Digit verification
- D. Image verification
Answer: B
NEW QUESTION 40
Alibaba Cloud CloudMonitor is a service that monitors Alibaba Cloud resources and Internet applications Which of the following functions are currently provided by CloudMonitor? (Number of correct answers: 4)
- A. Custom monitoring
- B. Site monitoring
- C. Alerting
- D. Custom firewall
- E. Cloud service monitoring
Answer: A,B,C,E
NEW QUESTION 41
If an ECS instance needs to be accessed by other applications from internet, a corresponding "port" must be enabled For example, HTTP applications work on port 80, while FTP applications work on port 21 If an administrator configures network security policies for this ECS instance, which of the following policies is the safest?
- A. The administrator wants to build multiple applications on an ECS instance. For easy management, the administrator uses default settings and allows any IP address to access required service ports
- B. After buying an ECS instance, the administrator immediately enables the security group firewall on the console and opens all ports for public networks
- C. After buying an ECS instance, the administrator immediately enables the security group firewall on the console and opens only the required service ports for public networks
- D. After buying an ECS instance, the administrator immediately enables the security group firewall on the console and opens ports 0-1024 for public networks
Answer: C
NEW QUESTION 42
When users log on to ECS instances through SSH or remote desktop from public Internet, Alibaba Cloud Security Center will monitor the log on behaviors If an IP address uses incorrect password to log on to an ECS instance for too many times, an alert "ECS instance suffers brute force password cracking" will be prompted If you receive this alert, which of the following is the safest way to handle this alert?
- A. This alert does not matter and can be ignored.
- B. Log on immediately to the ECS instance and check the logon logs If no abnormal logon success record is found ignore this alert.
- C. Update the system user password immediately for the ECS instance, and enable the security group firewall to allow only specified IP addresses to connect to the ECS instance
- D. Inform all users on the service platform of changing their passwords, and eliminate simple passwords using technical measures
Answer: C
NEW QUESTION 43
Which of the following features are available in Alibaba Cloud Anti-DDoS Premium product? (Number of correct answers: 3)
- A. Malformed packets filtering
- B. SQL injection Attack blocking
- C. Web application layer DDoS protection
- D. Transport layer DDoS protection
Answer: A,C,D
NEW QUESTION 44
The protection rules of Alibaba Cloud WAF are updated in real time after a user makes changes in WAF configuration page.
- A. True
- B. False
Answer: A
NEW QUESTION 45
Alibaba Cloud Anti-DDoS Premium Service can be used to protect against DDoS attacks larger than 100 Gbps. It can be used to protect both Alibaba Cloud hosts and non-Alibaba Cloud hosts
- A. True
- B. False
Answer: A
NEW QUESTION 46
Users can detach the Security Center client on Alibaba Cloud ECS instances, and reinstall it later when necessary.
- A. True
- B. False
Answer: A
NEW QUESTION 47
baba Cloud security service provides in-depth defense Which of the following services is dedicated for host security?
- A. WAF
- B. Security Center
- C. Data Risk Control
- D. Anti-DDoS pro Service
Answer: D
NEW QUESTION 48
......
Ultimate Guide to Prepare ACP-Sec1 Certification Exam for Alibaba Security: https://www.prepawaypdf.com/Alibaba/ACP-Sec1-practice-exam-dumps.html