
Verified ACP-Sec1 Exam Dumps Q&As - Provide ACP-Sec1 with Correct Answers
Pass Your ACP-Sec1 Dumps Free Latest Alibaba Practice Tests
Alibaba ACP-Sec1 Exam Syllabus Topics:
| Topic | Details |
|---|---|
| Topic 1 |
|
| Topic 2 |
|
| Topic 3 |
|
| Topic 4 |
|
| Topic 5 |
|
| Topic 6 |
|
| Topic 7 |
|
| Topic 8 |
|
| Topic 9 |
|
NEW QUESTION 28
Which of the following features are available in Alibaba Cloud Anti-DDoS Premium product? (Number of correct answers: 3)
- A. Transport layer DDoS protection
- B. Malformed packets filtering
- C. Web application layer DDoS protection
- D. SQL injection Attack blocking
Answer: A,B,C
NEW QUESTION 29
In a public cloud environment Alibaba Cloud is responsible for security of cloud computing infrastructure (such as the IDC environment, physical server O&M, and virtualization layer of cloud products). However, you still need to perform necessary security optimization measures for the Cloud products you purchased Which of the following actions do you think are safe?
- A. To reduce the communication cost, five administrators of the company use the root account to log on to the ECS instance.
- B. To enable colleagues working at home to update data, open public IP addresses for ApsaraDB for RDS instances, and allow all IP addresses to connect to the instances
- C. After buying an ECS instance, enable the security group firewall for the ECS instance through the console, and only allow a management IP address to remotely log on to the ECS instance.
- D. For easy management, change the administrator password for the ECS instance to 123456.
Answer: C
NEW QUESTION 30
Clean bandwidth refers to the maximum normal clean bandwidth that can be processed by Anti-DDoS Premium instances when your business is not under attack. Make sure that the Clean bandwidth of the instance is greater than the peak value of the inbound or outbound traffic of all services connected to the Anti-DDoS Premium instances If the actual traffic volume exceeds the maximum Clean bandwidth, your business may be subject to traffic restrictions or random packet losses, and your normal business may be unavailable, slowed, or delayed for a certain period of time
- A. True
- B. False
Answer: A
NEW QUESTION 31
Various profit-oriented hacker groups exist on the Internet. They control a large number of server resources and can launch network attacks against a target server at any time Among those, one type of attack is common and destructive, which completely consumes resources of the target server so that normal customers cannot connect to the server Which of the following belongs to this type of attack?
- A. XSS attack
- B. Webshell attack
- C. SQL injection
- D. DDoS attack
Answer: D
NEW QUESTION 32
The protection rules of Alibaba Cloud WAF are updated in real time after a user makes changes in WAF configuration page.
- A. True
- B. False
Answer: A
NEW QUESTION 33
An Alibaba Cloud user buys an ECS instance and deploys Tomcat on it Which of the following is the easiest way for the user to monitor whether port 8080 (used by Tomcat) on this ECS instance is functioning normally or not?
- A. Use Alibaba Cloud CloudMonitor s site monitor feature to create a new Monitoring Task to monitor the port status.
- B. Write a script for detection and report the data to CloudMonitor.
- C. Log on to the ECS instance every hour to check the port using the command line.
- D. Buy a third-party monitoring tool
Answer: A
NEW QUESTION 34
Products like ECS and Server Load Balancer it will be automatically protected by Anti-DDoS Basic service
- A. True
- B. False
Answer: A
NEW QUESTION 35
Alibaba Cloud Anti-DDoS Premium can be used only when the origin site IP address is in Alibaba Cloud.
- A. True
- B. False
Answer: B
NEW QUESTION 36
A customer built his website on Alibaba Cloud- To defend against Web attacks he activated Alibaba Cloud WAF However, a week later, the customer finds that his website has suffered intrusion. Which of the following actions should he take to ensure that WAF functions correctly and enhance system security?
(Number of correct answers: 4)
- A. Check whether or not the DNS resolution results point to the WAF address
- B. Configure a security group for the ECS instance.
- C. Secure other HTTP services on the ECS instance using WAF
- D. Resolve the website domain name to the site s source IP address
- E. Use Security Center to remove Trojans and fix vulnerabilities
- F. Delete all snapshots and clear the server
Answer: A,B,C,E
NEW QUESTION 37
When submitting requests to the Content Moderation service API, which HTTP method should you use?
- A. POST
- B. HEAD
- C. GET
- D. PUT
Answer: A
NEW QUESTION 38
Alibaba Cloud Security Center is consisted of light-weight Agents and cloud engine to provide functions such as webshell scanning and removal, day vulnerability repair, security baseline inspection, and host access control, to protect the server security. Which of the following processes is NOT included in Security Center Agent?
- A. All Safe
- B. AliYunDun
- C. AliHids
- D. AliYunDunUpdate
Answer: A
NEW QUESTION 39
What are some of the products that support integration with Alibaba Cloud's SSL Certificates Service (Number of correct answers: 3)
- A. Server Load Balancer (SLB)
- B. ApsaraDB for RDS
- C. Secure Content Distribution Network (SCDN)
- D. Content Distribution Network (CDN)
Answer: A,C,D
NEW QUESTION 40
After you activate the button Data Risk Control feature in Alibaba Cloud WAF. Which of the following risk control verification modes m displayed if you directly request for a risk control protection URL?
- A. QR code verification
- B. Image verification
- C. Slider verification
- D. Digit verification
Answer: C
NEW QUESTION 41
Alibaba Cloud ECS instances are common targets of hacker attacks. There are many types of attacks against ECS instances. Which of the following attacks specifically target the operating system of an ECS instance?
(Number of correct answers: 3)
- A. Brute force RDP password cracking
- B. Brute force SSH password cracking
- C. Trojan or Webshell installation
- D. SQL injection
Answer: A,B,C
NEW QUESTION 42
Which of the following configurations is NOT a feature provided by Alibaba Cloud Web Application Firewall product?
- A. Data Leakage Prevention
- B. Crawler Detection
- C. HTTP ACL Policy
- D. Blocked Regions
Answer: D
NEW QUESTION 43
For which of the following protection scenarios is Alibaba Cloud WAF applicable? (Number of correct answers: 5)
- A. Data leakage prevention
- B. Protection against SMS refresh and service data crawling
- C. Brute force cracking protection
- D. Defense against website trojans and tampering
- E. Protection against malicious CC attacks
- F. Virtual vulnerability patches
Answer: A,C,D,E,F
NEW QUESTION 44
You have set an alert policy for the disk usage of an ECS instance by using Alibaba Cloud CloudMonitor Each measurement cycle lasts for 5 minutes, during which the average disk usage is measured If the average disk usage exceeds 80% for five consecutive measurement cycles, an alert will be reported After your average disk usage exceeds 80%, how long will it take to receive an alert with the best case scenario?
- A. 20 minutes
- B. 0 minutes
- C. 30 minutes
- D. 40 minutes
Answer: C
NEW QUESTION 45
Alibaba Cloud CloudMonitor is a service that monitors Alibaba Cloud resources and Internet applications Which of the following functions are currently provided by CloudMonitor? (Number of correct answers: 4)
- A. Custom firewall
- B. Site monitoring
- C. Custom monitoring
- D. Cloud service monitoring
- E. Alerting
Answer: B,C,D,E
NEW QUESTION 46
Users can detach the Security Center client on Alibaba Cloud ECS instances, and reinstall it later when necessary.
- A. True
- B. False
Answer: A
NEW QUESTION 47
When importing key material into Key Management Service (KMS), you will be given an import token and public encryption key valid for 24 hours. The public key KMS provides must be used to encrypt your key material before upload KMS allows you to choose different public key encryption algorithms Which ones are supported? (Number of correct answers; 3)
- A. RSAES_OAEP_SHA_256
- B. RSAES_OAEP_SHA_1
- C. RSAES_ECDHE_V1 _5
- D. RSAES PKCS1 V1 5
Answer: B,C,D
NEW QUESTION 48
A website is built using open-source software To prevent hacker attacks and fix vulnerabilities in a timely manner, the administrator of the website wants to use the patch management feature in Security Center. Which of the following statements about patch management is FALSE.
- A. Rollback of Web vulnerabilities means to restore the original files, while rollback of Windows vulnerabilities means to uninstall the patch upgrade
- B. Patch management can operate machines in batches in the cloud. For large-scale vulnerabilities, it supports one-key patch upgrade, which is easy and convenient
- C. Vulnerabilities are automatically fixed Once a self-developed paten is released, it automatically fixes vulnerabilities for all customers who have enabled patch management.
- D. Before patches for most common Web vulnerabilities are released, the Alibaba Cloud Security O&M team will have fixed the vulnerabilities using self-developed patches
Answer: C
NEW QUESTION 49
More than one CNAME record is generated for the same domain name when Alibaba Cloud Anti-DDoS Premium Service Instance is purchased for load balancing purpose.
- A. True
- B. False
Answer: B
NEW QUESTION 50
Border Gateway Protocol (BGP) is mainly used for interconnection between autonomous systems (AS) on the Internet It. Controlling route transmission and selecting the best route Alibaba Cloud uses a BGP multi-line access mechanism for all its IDCs in China. Which of the followings are advantages of a BGP multi-line IDC?
(Number of correct answers 2)
- A. High-speed interconnection
- B. Larger bandwidth
- C. Low bandwidth cost
- D. Elimination of access barriers between North China and South China because China is big and North China and South China has different telecom operators
Answer: A,D
NEW QUESTION 51
Alibaba Cloud Security's Data R.sk Control can effectively resolve junk registration, database hacking, and other service risk identification problems To use this service. you need to first collect service data. Which of the following methods can be used to collect information off Web application systems?
- A. SDK
- B. JavaScript, SDK
- C. JavaScript
- D. HTML5
Answer: C
NEW QUESTION 52
Alibaba Cloud Security Center can record source IP addresses that remotely access a server, and shield suspicious IP addresses that frequently connect to the server. During routine O&M. which of the following functions can be used to set the IP address that are commonly used by the system administrator'?
- A. Security group
- B. Valid Login IP list
- C. Webshell detection
- D. Frequent logon location management
Answer: D
NEW QUESTION 53
......
Get Top-Rated Alibaba ACP-Sec1 Exam Dumps Now: https://www.prep4away.com/Alibaba-certification/braindumps.ACP-Sec1.ete.file.html