[Q18-Q39] Get 100% Passing Success With True ACP-Sec1 Exam! [Oct-2021] | DumpsMaterials

[Q18-Q39] Get 100% Passing Success With True ACP-Sec1 Exam! [Oct-2021]

Share

Get 100% Passing Success With True ACP-Sec1 Exam! [Oct-2021] 

Alibaba ACP-Sec1 PDF Questions - Exceptional Practice To ACP Cloud Security Professional

NEW QUESTION 18
If an ECS instance needs to be accessed by other applications from internet, a corresponding "port" must be enabled For example, HTTP applications work on port 80, while FTP applications work on port 21 If an administrator configures network security policies for this ECS instance, which of the following policies is the safest?

  • A. After buying an ECS instance, the administrator immediately enables the security group firewall on the console and opens all ports for public networks
  • B. After buying an ECS instance, the administrator immediately enables the security group firewall on the console and opens ports 0-1024 for public networks
  • C. The administrator wants to build multiple applications on an ECS instance. For easy management, the administrator uses default settings and allows any IP address to access required service ports
  • D. After buying an ECS instance, the administrator immediately enables the security group firewall on the console and opens only the required service ports for public networks

Answer: D

 

NEW QUESTION 19
Alibaba Cloud CloudMonitor is a service that monitors Alibaba Cloud resources and Internet applications.
Which of the following statements about CloudMonitor is accurate'?

  • A. To use CloudMonitor for ECS monitoring, there no agent needs to be installed in ECS.
  • B. CloudMonitor cannot be used through the Alibaba Cloud console
  • C. CloudMonitor can monitor websites that are not deployed in Alibaba Cloud products.
  • D. CloudMonitor must be independently bought and paid for activation

Answer: C

 

NEW QUESTION 20
A customer built his website on Alibaba Cloud- To defend against Web attacks he activated Alibaba Cloud WAF However, a week later, the customer finds that his website has suffered intrusion. Which of the following actions should he take to ensure that WAF functions correctly and enhance system security?
(Number of correct answers: 4)

  • A. Delete all snapshots and clear the server
  • B. Resolve the website domain name to the site s source IP address
  • C. Check whether or not the DNS resolution results point to the WAF address
  • D. Configure a security group for the ECS instance.
  • E. Use Security Center to remove Trojans and fix vulnerabilities
  • F. Secure other HTTP services on the ECS instance using WAF

Answer: C,D,E,F

 

NEW QUESTION 21
If you activate Alibaba Cloud Security Center on an ECS Linux instance and change the default SSH port (22) to another port, you will no longer receive SMS or email notification related to brute force password cracking

  • A. False
  • B. True

Answer: A

 

NEW QUESTION 22
Anti-DDoS Premium Service is a value-added service intended to address the problem of service interruption caused by DDoS attack to servers including non-Alibaba Cloud hosts) Users can configure a protected IP address so that the attack traffic can be redirected to this IP address, thereby ensuring the stability and reliability of the origin site. When a user configures Anti-DDoS Premium Service and imports an HTTPS certificate, the system prompts an "incorrect parameter format" error Which of the following is NOT the reason of this error?

  • A. The certificate contains nonstandard content
  • B. The certificate contains strings like "--"
  • C. The name of the certificate is too long to be accepted
  • D. The name of the certificate contains invalid letters

Answer: A

 

NEW QUESTION 23
Alibaba Cloud Data Risk Control utilizes Alibaba Group's Big Data computing capabilities and industry-leading, risk decision making engine to address fraud threats in key service processes (such as account log on, online activity, payment) and avoid financial loss Which of the following is NOT an application scenario of Data Risk Control?

  • A. Account registration
  • B. Goods payment
  • C. Application installation
  • D. Transaction rating

Answer: C

 

NEW QUESTION 24
An Alibaba Cloud user buys an ECS instance and deploys Tomcat on it Which of the following is the easiest way for the user to monitor whether port 8080 (used by Tomcat) on this ECS instance is functioning normally or not?

  • A. Use Alibaba Cloud CloudMonitor s site monitor feature to create a new Monitoring Task to monitor the port status.
  • B. Log on to the ECS instance every hour to check the port using the command line.
  • C. Write a script for detection and report the data to CloudMonitor.
  • D. Buy a third-party monitoring tool

Answer: A

 

NEW QUESTION 25
When using Alibaba Cloud Anti-DDoS Service/WAF in China Mainland, you must finish ICP Filing beforehand.

  • A. False
  • B. True

Answer: B

 

NEW QUESTION 26
After you activate the button Data Risk Control feature in Alibaba Cloud WAF. Which of the following risk control verification modes m displayed if you directly request for a risk control protection URL?

  • A. Image verification
  • B. Slider verification
  • C. QR code verification
  • D. Digit verification

Answer: B

 

NEW QUESTION 27
The ScheduleKeyDeletion function lets you schedule a time to delete Key Management Service (KMS) keys.
How far in the future can a key deletion event be scheduled?

  • A. 60 days
  • B. 7 days
  • C. 30 days
  • D. 15 days

Answer: D

 

NEW QUESTION 28
You have helped a customer set up a content filtering solution based on Content Moderation service However, the customer is complaining that certain images are getting incorrectly flagged as pornographic content. What can you do to help fix this?

  • A. Create an "Image Library" from the Content Moderation console and add the images to the Image Library's whitelist
  • B. Open a ticket with Alibaba Cloud support, and send them a copy of the images, so that they can tune Content Moderation's detection algorithms
  • C. Modify the images until Content Moderation service starts marking them as pornographic.
  • D. Ask your customer to use different images on their site

Answer: A

 

NEW QUESTION 29
Users can detach the Security Center client on Alibaba Cloud ECS instances, and reinstall it later when necessary.

  • A. False
  • B. True

Answer: B

 

NEW QUESTION 30
Alibaba Cloud Anti-DDoS Premium Service can be used to protect against DDoS attacks larger than 100 Gbps. It can be used to protect both Alibaba Cloud hosts and non-Alibaba Cloud hosts

  • A. False
  • B. True

Answer: B

 

NEW QUESTION 31
There is a limit on the number of Customer Master Keys (CMKs) that users can create using Key Management Service (KMS), but users can raise this limit by submitting a support ticket to Alibaba Cloud.

  • A. False
  • B. True

Answer: B

 

NEW QUESTION 32
Your applications are deployed on Alibaba Cloud ECS instances. You want to collect indicators by yourself for application layer monitoring. Which of the following functions provided by Alibaba Cloud CloudMonitor can be used for indicator collection, aggregation, and alerting?

  • A. Custom monitoring
  • B. Cloud service monitoring
  • C. Site monitoring
  • D. CloudMonitor cannot meet these requirements

Answer: A

 

NEW QUESTION 33
To improve ECS instance security, the administrator does not want users on public network to check whether an ECS instance is online using the ping command. Which of the following reinforcement measures designed by the administrator is NOT feasible?

  • A. Resolve the IP address of the ECS instance to an uncommon level 4 domain name, and point the promotional domain name to the level 4 domain name through CNAME
  • B. Enable an operating system firewall for the ECS instance, and reject ICMP for public network access.
  • C. Enable a security group and only allow access from ports 80 and 25 of the public network through TCP
  • D. Enable a security group, and reject ICMP for public network access.

Answer: A

 

NEW QUESTION 34
A website is built using open-source software To prevent hacker attacks and fix vulnerabilities in a timely manner, the administrator of the website wants to use the patch management feature in Security Center. Which of the following statements about patch management is FALSE.

  • A. Rollback of Web vulnerabilities means to restore the original files, while rollback of Windows vulnerabilities means to uninstall the patch upgrade
  • B. Vulnerabilities are automatically fixed Once a self-developed paten is released, it automatically fixes vulnerabilities for all customers who have enabled patch management.
  • C. Before patches for most common Web vulnerabilities are released, the Alibaba Cloud Security O&M team will have fixed the vulnerabilities using self-developed patches
  • D. Patch management can operate machines in batches in the cloud. For large-scale vulnerabilities, it supports one-key patch upgrade, which is easy and convenient

Answer: B

 

NEW QUESTION 35
Alibaba Cloud Security Center provides patch management service, where are the patches published from?

  • A. Officially published by application vendors
  • B. Officially published by operating system vendors
  • C. Contributed by netizens from open-source communities
  • D. Developed by Alibaba Cloud

Answer: C

 

NEW QUESTION 36
Alibaba Cloud Ant.-DDoS Premium Service is an advanced DDoS protection product It can defend against layer 4 and layer 7 attacks. Which of the following statements about Alibaba Cloud Anti-DDoS Premium Service is FALSE?

  • A. Anti-DDoS Premium Service defends against various DDoS attacks, including but not limited to ICMP flood, UDP flood, TCP flood. SYN flood, and ACK flood attacks
  • B. Anti-DDoS Premium Service provides precise traffic reports and attack details in real time to keep you informed of the current service details on time
  • C. Anti-DDoS Premium Service supports 2 billing modes: Unlimited and Insurance.
  • D. You can adjust the anti-DDoS elastic protection threshold to a higher level at any time, with the service interruption period no longer than 3 minutes

Answer: C

 

NEW QUESTION 37
Various profit-oriented hacker groups exist on the Internet. They control a large number of server resources and can launch network attacks against a target server at any time Among those, one type of attack is common and destructive, which completely consumes resources of the target server so that normal customers cannot connect to the server Which of the following belongs to this type of attack?

  • A. SQL injection
  • B. Webshell attack
  • C. XSS attack
  • D. DDoS attack

Answer: D

 

NEW QUESTION 38
Which of the following attacks can Alibaba Cloud Anti-DDoS Basic defend against? (Number of coned answers 4)

  • A. CMP Flood
  • B. UDP Flood
  • C. SYN Flood
  • D. ACK Flood
  • E. Brute force password cracking

Answer: B,C,D,E

 

NEW QUESTION 39
......


Alibaba ACP-Sec1 Exam Syllabus Topics:

TopicDetails
Topic 1
  • web SQL injections among other common security risks and taking appropriate measures for protection
Topic 2
  • Security application solution design, such as correct understanding and handling after receiving alerts from the console, e-mails or text messages
Topic 3
  • Discovering DDoS attacks, brute force password cracking attacks
  • Security advantages of their combined solutions
Topic 4
  • Cloud computing-related product (ECS, Server Load Balancer, OSS, RDS, VPC and CDN) content
Topic 5
  • Characteristics, application scenarios and features of Alibaba Cloud security management-related products
Topic 6
  • Cloud service-related basic security protocols such as HTTP, FTP, TCP, UDP and ICMP
  • Understanding common security risks of the above products
Topic 7
  • Understanding the positioning, main features, working principles and application scenarios of the above products
Topic 8
  • Characteristic, application scenarios, competitive edges and features of Alibaba Cloud Anti-DDos and WAF
Topic 9
  • Core security products: basic operations and management of Anti-DDoS, Security Center, SSL Certificate, Content Moderation, Key Management Service

 

ACP-Sec1 dumps - DumpsMaterials - 100% Passing Guarantee: https://www.dumpsmaterials.com/ACP-Sec1-real-torrent.html