Stuxnet is a computer worm that targets industrial control systems. Which of the following gives the correct sequence of Stuxnet virus attacks?
ASearch for targets -> Reconnaissance organizational structure and personnel Information -> Social engineering penetration -> Lateral movement using USB flash drives -> Launch attacks
BReconnaissance organizational structure and personnel information -> Social engineering penetration -> Lateral movement using USB flash drives -> Search for targets -> Launch, attacks
CSocial engineering penetration ->Reconnaissance organizational structure and personnel information -> Lateral movement using USB flash drives -> Search for targets -> Launch attacks
DReconnaissance organizational structure and personnel information -> Social engineering penetration -> Search for targets -> Lateral movement using USB flash drives -> Launch attacks
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ2
Network Security
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ3
Network Security
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ4
Network Security
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ5
Network Security
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ6
Network Security
An Nginx application is deployed on a Linux host. By reviewing Nginx logs, O&M engineers can obtain the complete URL details submitted by users and determine whether the Linux host is experiencing SQL injection attacks.
ATRUE
BFALSE
Which of the following statements are correct regarding PBR matching conditions?
Choose three
AThe application type of traffic can be specified. The “application” condition allows a firewall to distinguish different applications that use the same protocol and port number, achieving more refined network management.
BTo match traffic with different priorities, you can set the DSCP priority as a matching condition when creating a PBR rule.
CThe source security zone and inbound interface can be sued together to match user traffic more accurately.
DTo enable a PBR rule to take effect only in a specified time range, you can set the time range as a matching condition when creating the PRB rule.
Which of the following statements is incorrect regarding a system version upgrade for firewalls operating in hot standby mode?
AThe system version upgrade has requirements on the device model and source version.
BUpgrade the active firewall before the standby one.
CThe system version upgrade is required when the firewalls need some features that are unavailable in the current version.
DThe system version upgrade is required when the current version has a bug.
To protect against network attacks, it is sufficient to deploy security devices, such as a firewall and IPS, only at the Internet egress. No security device must be deployed on the enterprise intranet.
ATRUE
BFALSE
Save question
If a third-party admission device configured on iMaster NCE-Campus uses the default port 2000 for Portal authentication, the port number in the Portal server template configured on that third-party admission device must likewise be set to 2000.
ATRUE
BFALSE
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ7
Network Security
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ8
Network Security
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ9
Network Security
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ10
Network Security
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ11
Network Security
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ12
Network Security
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ13
Network Security
0
Community Discussion
No comments yet. Be the first to start the discussion!
Ad
Want a break from the ads?
Go ad-free and unlock Learn Mode, Exam Mode, AstroTutor AI and every premium tool — everything you need to walk in prepared, and confident.
No comments yet. Be the first to start the discussion!
QuestionQ15
Network Security
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ16
Network Security
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ17
Network Security
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ18
Network Security
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ19
Network Security
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ20
Network Security
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ21
Network Security
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ22
Network Security
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ23
Network Security
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ24
Network Security
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ25
Network Security
0
Community Discussion
No comments yet. Be the first to start the discussion!
Which statements below are true about virtual systems and VPN instances?
Choose three
AWhen you create a virtual system on the firewall, the firewall automatically generates a VPN instance with the same name.
BThe administrator uses the VPN instance manually created using the ip vpn-instance command.
CBoth virtual systems and VPN instances can implement service isolation and route isolation.
DVPN instances support multicast protocols.
A firewall can stop spam from flooding an intranet by performing IP-address checks.
ATRUE
BFALSE
An IPsec VPN is established using IKEv1 Main Mode. When a NAT device is detected, from which of the following ISAKMP messages does port number translation begin?
AMessage 5
BMessage 3
CMessage 4
DMessage 6
An enterprise must manage and control guest-access behavior while still enabling guest access. Which authentication mode is recommended for these guest-access scenarios?
AMAC address bypass authentication
B802.1X authentication
CPortal authentication
DMAC address authentication
An IPS signature is a collection of signatures that meets defined filtering conditions. Which of the following is not a filtering condition for a signature filter?
AProtocol
BSignature ID
COS
DCategory
Which of the following sequences correctly describes the Huawei intrusion prevention configuration process?
AUpdate the signature database -> Configure an IPS profile -> Configure signatures -> Verify the configuration
BConfigure signatures -> Update the signature database -> Configure an IPS profile ->Verify the configuration
CConfigure an IPS profile -> Update the signature database -> Configure signatures -> ->Verify the configuration
DUpdate the signature database -> Configure signatures -> Configure an IPS profile -> ->Verify the configuration
The Common Vulnerability Scoring System (CVSS) is a broadly used open standard for scoring vulnerabilities. It uses a modular scoring system. Which of the following is not part of CVSS?
AEnvironmental
BBase
CTemporal
DSpatial
Which of the following actions are carried out during the eradication phase of an emergency response?
AEnabling security audit
BUsing antivirus software to remove viruses from terminals
CConfiguring ACLs on an enterprise’s internal switches to prevent viruses from spreading on the internal network
DStrengthening cyber security education and publicity
For SSL VPN, on which of the following dimensions does the firewall base access authorization and control?
AIP address
BMAC address
CRole
DPort number
In MAC address authentication scenarios, users do not need to manually provide a user name and password. Which item is used as the user name for authentication?
AIP address
BInterface number
CMAC address
DAccount
Match the SSL VPN resource release modes to their corresponding concepts.
Drag & Drop
Web proxy
File sharing
Port forwarding
Network extension
Remote access users can securely access web resources on the enterprise intranet through browsers.
Remote access users can securely access the file server on the intranet through browsers.
Remote access users can access TCP-based application services on the enterprise intranet.
IP addresses are delivered to mobile users so that they can directly access all IP resources on the intranet.
For ordinary TCP packets, which of the following flag-bit combinations can occur?
Choose two
ABoth the SYN and RST bits are 1.
BBoth the RST and FIN bits are 1.
CBoth the FIN and URG bits are 1.
DBoth the SYN and ACK bits are 1.
When iMaster NCE-Campus is used as a Portal server, which URL parameter must be configured in the URL template on an access device so that iMaster NCE-Campus can match the corresponding Portal pages based on users’ IP addresses?
Adevice-mac
Buser-ipaddress
Cuser-mac
Dssid
Process checking is used to determine whether abnormal processes exist and whether the service host has been compromised or implanted with Trojan horses or backdoor programs. However, it cannot detect malicious programs that are not running and are hidden within the system.
ATRUE
BFALSE
If any illegitimate email encapsulated in POP3 or IMAP messages is detected, the firewall can only block that email.
ATRUE
BFALSE
In MAC address authentication, users are not required to manually provide a user name and password. Which of the following is used as the user name for authentication?
AAccount
BIP address
CInterface number
DMAC address
Which of the following statements are correct about virtual interfaces?
Choose two
AThe virtual interface is named in the format: Virtual-if+ IP address.
BThe virtual interface of the public system is Virtual- if1.
CA virtual interface must be configured with an IP address and assigned to a security zone. Otherwise, it cannot work properly.
DAfter a virtual system is created, the system automatically creates a virtual interface.
Which of the following parameters is not a condition used to classify global route selection policies?
AWeight
BPort number
CQuality
DBandwidth
On a WLAN where Portal authentication is configured on the WAC, VLAN authorization can be performed without requiring any additional configuration. After Portal authentication is completed, the WAC forwards STA traffic according to the authorized VLANs.
Community Discussion