ACP-Sec1 Practice Exam and Study Guides - Verified By TestKingsIT Updated 82 Questions [Q22-Q40]

Share

ACP-Sec1 Practice Exam and Study Guides - Verified By TestKingsIT Updated 82 Questions

2021 Updated Verified Pass ACP-Sec1 Study Guides & Best Courses


Alibaba ACP-Sec1 Exam Syllabus Topics:

TopicDetails
Topic 1
  • Discovering DDoS attacks, brute force password cracking attacks
  • Security advantages of their combined solutions
Topic 2
  • Characteristic, application scenarios, competitive edges and features of Alibaba Cloud Anti-DDos and WAF
Topic 3
  • Understanding the positioning, main features, working principles and application scenarios of the above products
Topic 4
  • Cloud computing-related product (ECS, Server Load Balancer, OSS, RDS, VPC and CDN) content
Topic 5
  • Core security products: basic operations and management of Anti-DDoS, Security Center, SSL Certificate, Content Moderation, Key Management Service
Topic 6
  • Security application solution design, such as correct understanding and handling after receiving alerts from the console, e-mails or text messages
Topic 7
  • web SQL injections among other common security risks and taking appropriate measures for protection
Topic 8
  • Cloud service-related basic security protocols such as HTTP, FTP, TCP, UDP and ICMP
  • Understanding common security risks of the above products
Topic 9
  • Characteristics, application scenarios and features of Alibaba Cloud security management-related products

 

NEW QUESTION 22
If an ECS instance needs to be accessed by other applications from internet, a corresponding "port" must be enabled For example, HTTP applications work on port 80, while FTP applications work on port 21 If an administrator configures network security policies for this ECS instance, which of the following policies is the safest?

  • A. The administrator wants to build multiple applications on an ECS instance. For easy management, the administrator uses default settings and allows any IP address to access required service ports
  • B. After buying an ECS instance, the administrator immediately enables the security group firewall on the console and opens all ports for public networks
  • C. After buying an ECS instance, the administrator immediately enables the security group firewall on the console and opens only the required service ports for public networks
  • D. After buying an ECS instance, the administrator immediately enables the security group firewall on the console and opens ports 0-1024 for public networks

Answer: C

 

NEW QUESTION 23
Alibaba Cloud WAF is a security protection product based on Alibaba Group's web security defense experience accumulated over more than a decade By defending against common OWASP attacks, providing patches to fix vulnerabilities, and allowing users to customize protection policies for website services, WAF can successfully safeguard the security and availability of websites and web applications. Which of the following types of security configurations does WAF provide? (Number of correct answers 3)

  • A. Port access control
  • B. Web application attack protection
  • C. Precision access control
  • D. CC protection

Answer: A,B,D

 

NEW QUESTION 24
Data Risk Control feature has been integrated into Alibaba Cloud WAF. When this function is activated, a script must be embedded into the page that wishes to be protected under the corresponding domain name to check whether a client is trustworthy. Which type of script is it?

  • A. Vbscript
  • B. Java
  • C. C++
  • D. JavaScript

Answer: D

 

NEW QUESTION 25
The protection rules of Alibaba Cloud WAF are updated in real time after a user makes changes in WAF configuration page.

  • A. True
  • B. False

Answer: A

 

NEW QUESTION 26
Products like ECS and Server Load Balancer it will be automatically protected by Anti-DDoS Basic service

  • A. True
  • B. False

Answer: A

 

NEW QUESTION 27
More than one CNAME record is generated for the same domain name when Alibaba Cloud Anti-DDoS Premium Service Instance is purchased for load balancing purpose.

  • A. True
  • B. False

Answer: B

 

NEW QUESTION 28
baba Cloud security service provides in-depth defense Which of the following services is dedicated for host security?

  • A. Security Center
  • B. WAF
  • C. Anti-DDoS pro Service
  • D. Data Risk Control

Answer: C

 

NEW QUESTION 29
Alibaba Cloud Anti-DDoS Premium Service can be used to protect against DDoS attacks larger than 100 Gbps. It can be used to protect both Alibaba Cloud hosts and non-Alibaba Cloud hosts

  • A. True
  • B. False

Answer: A

 

NEW QUESTION 30
Among various types of network attacks, "phishing" is one of the most common attacks. A phishing website looks exactly the same as the real website It asks visitors to login with their accounts and passwords; at the same time, record these privacy information for illegal purpose. Which of the following statements about how phishing websites are spread is FALSE?

  • A. Phishing website links are sent through Facebook. Twitter and other IM(instant Messenger) applications.
  • B. Phishing website links are published in batches through emails forums, blogs, and SNS(Social Network Sites).
  • C. Banks publish phishing website links in prominent positions on their official websites
  • D. Advertisements are pushed to search engines and small and medium websites, attracting users to click the phishing website links.

Answer: C

 

NEW QUESTION 31
You applied for an SSL certificate through Alibaba Cloud's SSL Certificates Service During the application, you selected "Manual" at the "CSR "" step. You now want to install your certificate on a server running Apache What must you do?

  • A. You can download a crt file of type "Other" from the SSL Certificates Service console, then use openssl to convert this file to pfx format for use with Apache
  • B. SSL Certificates Service doesn't support the type of certificates needed by Apache. They cannot be used together
  • C. You can use the "generate pfx file" function built into the SSL Certificates Service to manually generate and download the pfx file needed by Apache
  • D. You must revoke your certificate and re-apply, this time choosing "Automatic" at the "CSR Generation" step. Otherwise, the SSL certificate cannot be downloaded

Answer: C

 

NEW QUESTION 32
When applying for an SSL certificate through Alibaba Cloud's SSL Certificates Service, there is an offline review process which can take 3-5 business days or 5-7 business days depending on the type of certificate you have applied for:

  • A. True
  • B. False

Answer: A

 

NEW QUESTION 33
After you activate the button Data Risk Control feature in Alibaba Cloud WAF. Which of the following risk control verification modes m displayed if you directly request for a risk control protection URL?

  • A. QR code verification
  • B. Image verification
  • C. Slider verification
  • D. Digit verification

Answer: C

 

NEW QUESTION 34
Alibaba Cloud Data Risk Control utilizes Alibaba Group's Big Data computing capabilities and industry-leading, risk decision making engine to address fraud threats in key service processes (such as account log on, online activity, payment) and avoid financial loss Which of the following is NOT an application scenario of Data Risk Control?

  • A. Application installation
  • B. Transaction rating
  • C. Account registration
  • D. Goods payment

Answer: A

 

NEW QUESTION 35
A customer built his website on Alibaba Cloud- To defend against Web attacks he activated Alibaba Cloud WAF However, a week later, the customer finds that his website has suffered intrusion. Which of the following actions should he take to ensure that WAF functions correctly and enhance system security?
(Number of correct answers: 4)

  • A. Check whether or not the DNS resolution results point to the WAF address
  • B. Configure a security group for the ECS instance.
  • C. Secure other HTTP services on the ECS instance using WAF
  • D. Resolve the website domain name to the site s source IP address
  • E. Use Security Center to remove Trojans and fix vulnerabilities
  • F. Delete all snapshots and clear the server

Answer: A,B,C,E

 

NEW QUESTION 36
Anti-DDoS is one of the major products of Alibaba Cloud Security service Many websites have suffered DDoS attacks of different types. Therefore, accurate understanding of DDoS attacks is critical to the website security protection. Which of the following statements about DDoS attacks is the MOST accurate?

  • A. DDoS attacks primarily target a database
  • B. The main purpose of a DDoS attack is to prevent the target server from providing normal services
  • C. The purpose of a DDoS attack is to steal confidential information
  • D. A DDoS attack cracks the servers logon password by means of numerous attempts

Answer: B

 

NEW QUESTION 37
The ScheduleKeyDeletion function lets you schedule a time to delete Key Management Service (KMS) keys.
How far in the future can a key deletion event be scheduled?

  • A. 15 days
  • B. 60 days
  • C. 7 days
  • D. 30 days

Answer: A

 

NEW QUESTION 38
Alibaba Cloud ECS instances are common targets of hacker attacks. There are many types of attacks against ECS instances. Which of the following attacks specifically target the operating system of an ECS instance?
(Number of correct answers: 3)

  • A. Brute force RDP password cracking
  • B. Brute force SSH password cracking
  • C. Trojan or Webshell installation
  • D. SQL injection

Answer: A,B,C

 

NEW QUESTION 39
In a public cloud environment Alibaba Cloud is responsible for security of cloud computing infrastructure (such as the IDC environment, physical server O&M, and virtualization layer of cloud products). However, you still need to perform necessary security optimization measures for the Cloud products you purchased Which of the following actions do you think are safe?

  • A. To reduce the communication cost, five administrators of the company use the root account to log on to the ECS instance.
  • B. To enable colleagues working at home to update data, open public IP addresses for ApsaraDB for RDS instances, and allow all IP addresses to connect to the instances
  • C. After buying an ECS instance, enable the security group firewall for the ECS instance through the console, and only allow a management IP address to remotely log on to the ECS instance.
  • D. For easy management, change the administrator password for the ECS instance to 123456.

Answer: C

 

NEW QUESTION 40
......

Ultimate Guide to the ACP-Sec1 - Latest Edition Available Now: https://www.testkingit.com/Alibaba/latest-ACP-Sec1-exam-dumps.html