wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Testing 3

Total questions: 43

Worksheet time: 22mins

Name
Class
Date
1.

Which of the following statements are correct about the differences between pre-accident prevention strategies and post-accident recovery strategies? (Multi-select)

a)

The prevention strategy focuses on minimizing the likelihood of an accident before it occurs; the recovery strategy focuses on minimizing the impact and loss on the company after the accident.

b)

The role of pre-disaster prevention strategies does not include minimizing economic, reputational, and other losses caused by accidents.

c)

Recovery strategy is used to improve business high availability.

d)

Recovery strategy is part of the business continuity plan.

2.

Which of the following operations are necessary during the administrator upgrade of the USG firewall software version? (Multi-select)

a)

Upload the firewall version software.

b)

Restart the device.

c)

Device factory reset.

d)

Specify the next time you start loading the software version.

3.

If the company structure has undergone a practical change, it is necessary to retest whether the business continuity plan is feasible.

a)

True

b)

False

4.

HTTP packets are carried by UDP, and the HTTPS protocol is based on TCP three-way handshake. Therefore, HTTPS is relatively secure, and HTTPS is recommended.

a)

True

b)

False

5.

The single-point login function of the online user allows the user to authenticate directly to the AD server, and the device does not interfere with the user authentication process. The AD monitoring service needs to be deployed on the USG device to monitor the authentication information of the AD server.

a)

True

b)

False

6.

UDP port scanning means that the attacker sends a zero-byte UDP packet to a specific port of the target host. If the port is open, it will return an ICMP port reachable data packet.

a)

True

b)

False

7.

Which of the following statements are correct about the business continuity plan? (Multi-select)

a)

Business continuity plan lines do not require high-level participation of the company in determining the project scope phase.

b)

BCP needs flexibility because it cannot predict all possible accidents.

c)

Business continuity plan does not require high-level participation of the company before forming a formal document.

d)

Not all security incidents must be reported to company executives.

8.

When the USG series firewall hard disk is in place, which of the following logs can be viewed? (Multi-select)

a)

Operation log

b)

Business log

c)

Alarm information

d)

Threat log

9.

Social engineering is a means of harm such as deception and injury through psychological traps such as psychological weakness, instinctive reaction, curiosity, trust, and greed.

a)

True

b)

False

10.

Apply for emergency response special funds. In which stage does the procurement of emergency response software and hardware equipment belong in the network full emergency response?

a)

Preparation stage

b)

Inhibition phase

c)

Response phase

d)

Recovery phase

11.

Device destruction attacks are generally not easy to cause information leakage, but usually cause network communication services to be interrupted.

a)

True

b)

False

12.

Which of the following descriptions is wrong about Internet users and VPN access user authentication?

a)

The Internet user and the VPN access user share data, and the users’ attribute check (user status, account expiration time, etc.) also takes effect on the VPN access.

b)

The local authentication or server authentication process is basically the same for Internet users. The authentication is performed on the user through the authentication domain.

c)

After the VPN user accesses the network, it can access the network resources of the enterprise headquarters. The firewall can control the accessible network resources based on the user name.

d)

After the VPN access user passes authentication, it will be online on the user online list.

13.

Which of the following descriptions about the patch is wrong?

a)

A patch is a small program made by the original author of the software for the discovered vulnerability.

b)

No patching does not affect the operation of the system, so it is irrelevant whether to patch or not.

c)

Patches are generally updated.

d)

Computer users should download and install new patches to protect their systems in a timely manner.

14.

Which of the following descriptions is wrong about the Intrusion Prevention System (IPS)?

a)

IDS devices need to be linked to the firewall to block the intrusion.

b)

IPS devices cannot be bypassed in the network.

c)

IPS devices can be cascaded at the network boundary and deployed online.

d)

IPS devices can block in real time once they detect intrusion.

15.

Which of the following statements are correct about Huawei routers and switches? (Multi-select)

a)

The router can implement some security functions, and some routers can implement more security functions by adding security boards.

b)

The main function of the router is to forward data. Sometimes the firewall may be a more suitable choice when the enterprise has security requirements.

c)

The switch has some security features, and some switches can implement more security functions by adding security boards.

d)

The switch does not have security features.

16.

Which of the following options does not belong to the log type of the Windows operating system?

a)

Business log

b)

Application log

c)

Security log

d)

System log

17.

After a network intrusion event occurs, according to the plan to obtain the identity of the intrusion, the attack source, and other information, and to block the intrusion behavior, which links of these actions are involved in the PDRR network security model? (Multi-select)

a)

Protection link

b)

Testing link

c)

Response link

d)

Recovery link

18.

Which of the following is wrong about the scanning of vulnerabilities?

a)

The vulnerability was undiscovered beforehand and discovered afterwards.

b)

Vulnerabilities are generally repairable.

c)

Vulnerabilities are security risks that can expose computers to hackers.

d)

Vulnerabilities can be avoided.

19.

When user single sign-on is configured, the receiving PC message mode is adopted. The authentication process has the following steps: 1) The visitor PC executes the login script and sends the user login information to the AD monitor; 2) The firewall extracts the correspondence between the user and the IP from the login information and adds to the online user table; 3) The AD monitor connects to the AD server to query the login user information and forwards the queried user information to the firewall; 4) The visitor logs in to the AD domain, the AD server returns the login success message to the user, and delivers the login script. Which of the following orders is correct?

a)

1-2-3-4

b)

4-1-3-2

c)

3-2-4

d)

1-4-3-2

20.

The administrator wants to create a web configuration administrator, set the HTTPS device management port number to 20000, and set the administrator to the administrator level. Which of the following command sequences is correct?

a)

Step1: web-manager security enable port 20000 Step2: AAA View [USG] aaa [USG aaa] manager-user client001 [USG-aaa-manager-user-client001] service-type web [USG-aaa-manager-user-client001] level 15 [USG-aaa-manager-user-client001] password cipher Admin@123

b)

Step1: web-manager enable port 20000 Step2: AAA View [USG] aaa [USG aaa] manager-user client001 [USG-aaa-manager-user-client001] service-type web [USG-aaa-manager-user-client001] password cipher Admin@123

c)

Step1: web-manager security enable port 20000 Step2: AAA View [USG] aaa [USG aaa] manager-user client001 level 1 [USG-aaa-manager-user-client001] service-type web [USG-aaa-manager-user-client001] password cipher

d)

Step1: web-manager security enable port 20000 Step2: AAA View [USG] aaa [USG aaa] manager-user client001 [USG-aaa-manager-user-client001] service-type web [USG-aaa-manager-user-client001] level 1 [USG-aaa-manager-user-client001] password cipher Admin@123

21.

Which of the following descriptions are correct about the security policy action and the security configuration file? (Multiple Choice)

a)

If the action of the security policy is 'prohibited', the device will discard this traffic and will not perform content security check later.

b)

The security configuration file can be applied without being applied to the security policy allowed by the action.

c)

The security configuration file must be applied to the security policy that is allowed to take effect.

d)

If the security policy action is "Allow", the traffic will not match the security configuration file.

22.

Which of the following are the same features of Windows and LINUX systems? (Multiple Choice)

a)

Support multitasking

b)

Support graphical interface operations

c)

Open source system

d)

Support multiple terminal platforms

23.

During the configuration of NAT, in which of the following cases will the device generate a server-map entry? (Multiple Choice)

a)

Automatically generate server-map entries when configuring source NAT.

b)

After the NAT server is configured successfully, the device automatically generates a server-map entry.

c)

A server-map entry is generated when easy-ip is configured.

d)

After configuring NAT No-PAT, the device will create a server-map table for the configured multi-channel protocol data stream.

24.

NAT technology can securely transmit data by encrypting data.

a)

True

b)

False

25.

Which of the following is the correct order for event response management? Items: 1 detection, 2 report, 3 relief, 4 summarizing experience, 5 repair, 6 recovery, 7 response.

a)

1-3-2-7-5-6-4

b)

1-3-2-7-5-6-4

c)

1-2-3-7-5-6-4

d)

1-7-3-2-5-6-4

26.

Which of the following statement is wrong about L2TP VPN?

a)

Applicable to business employees dialing access to the intranet

b)

Will not encrypt the data

c)

Can be used in conjunction with IPsec VPN

d)

Belongs to Layer 3 VPN technology

27.

Encryption technology can transform readable information into unreadable information in a certain way.

a)

True

b)

False

28.

ASPF (Application Specific Packet Filter) is a packet filtering technology based on the application layer and implements a special security mechanism through the server-map table. Which of the following statements about the ASPF and server-map tables are correct? (Multiple Choice)

a)

ASPF monitors messages during communication.

b)

ASPF can dynamically create a server-map.

c)

ASPF dynamically allows multi-channel protocol data to pass through the server-map table.

d)

The quintuple server-map entry implements a similar function to the session table.

29.

Antivirus software and host firewall have the same effect.

a)

True

b)

False

30.

The process of electronic forensics includes: protecting the site, obtaining evidence, preserving evidence, identifying evidence, analyzing evidence, tracking and presenting evidence.

a)

True

b)

False

31.

Execute the command on the firewall and display the following information, which of the following descriptions is correct? (Multiple Choice) HRP_A [USG_A] display vrrp interfaceGigabitEthernet 0/0/1 | GigabitEthernet0/0/1 | Virtual Router 1VRRP Group: Active state: Active Virtual IP: 202.38.10.1 Virtual MAC: 0000-5e00-0101 Primary IP: 202 38.10.2 PriorityRun: 100 PriorityConfig: 100 MasterPriority: 100 Preempt: YES Delay Time: 10

a)

The status of this firewall VGMP group is Active.

b)

This firewall G1/0/1 virtual interface IP address 202.30.10.2

c)

This firewall VRID is 1 the VRRP priority to backup group 100

d)

Will not switch when the primary device fails

32.

In the USG series firewall system view, the device configuration will be restored to the default configuration after the reset saved-configuration command is executed. No other operations are required.

a)

True

b)

False

33.

The host firewall is mainly used to protect the host from attacks and intrusions from the network.

a)

True

b)

False

34.

What is the difference between network address port translation (NAT) and conversion-only network address (No-PAT)? (Multiple Choice)

a)

After NATP conversion, for external network users, all messages are from the same IP address or several IP addresses.

b)

No-PAT only supports protocol address translation at the application layer.

c)

NAPT only supports protocol address translation at the network layer.

d)

No-PAT supports protocol address translation at the network layer

35.

Which of the following descriptions are correct about the buffer overflow attack? (Multiple Choice)

a)

Buffer overflow attack is the use of software system for memory operation defects, running attack code with high operation authority.

b)

Buffer overflow attacks are not related to operating system vulnerabilities and architectures.

c)

Buffer overflow attacks are the most common method of attacking software systems.

d)

Buffer overflow attack belongs to application layer attack behavior.

36.

Which of the following is not the scope of business of the National Internet Emergency Center?

a)

Emergency handling of security incidents

b)

Early warning notification of security incidents

c)

Providing security evaluation services for government departments, enterprises and institutions

d)

Cooperate with other agencies to provide training services

37.

Which of the following are international organizations related to information security standardization? (Multiple Choice)

a)

International Organization for Standardization (ISO)

b)

International Electrotechnical Commission (IEC)

c)

International Telecommunication Union (ITU)

d)

Wi-Fi Alliance

38.

In order to obtain evidence of crime, it is necessary to master the technology of intrusion tracking. Which of the following descriptions are correct about the tracking technology? (Multiple Choice)

a)

Packet recording technology marks packets on each passing router by inserting trace data into the tracked IP packets.

b)

Link test technology determines the source of the attack by testing the network link between the routers.

c)

Packet tagging technology extracts information from attack sources by recording packets on the router and then using data drilling techniques.

d)

Shallow mail behavior analysis can analyze information such as sending IP address, sending time, sending frequency, number of recipients, shallow email headers and so on.

39.

Digital signature technology obtains a digital signature by encrypting which of the following data?

a)

User data

b)

Receiver public key

c)

Sender public key

d)

Digital fingerprint

40.

On the USG series firewalls, the default security policy does not support modification.

a)

True

b)

False

41.

In the classification of the information security level protection system, which of the following levels defines the damage to the social order and the public interest if the information system is destroyed? (Multiple Choice)

a)

First level User-independent protection level

b)

Second level System audit protection level

c)

Third level Security mark protection

d)

Fourth level Structured protection

42.

Which of the following is the analysis layer device in the Huawei SDSec solution?

a)

cis

b)

Agile Controller

c)

switch

d)

Firehunter

43.

Which of the following options are correct about the control actions permit and deny of the firewall interzone forwarding security policy? (Multiple Choice)

a)

The action of the firewall default security policy is deny

b)

The packet is matched immediately after the inter-domain security policy deny action, and the other interzone security policy will not be executed

c)

Even if the packet matches the permit action of the security policy, it will not necessarily be forwarded by the firewall

d)

Whether the message matches the permit action of the security policy or the deny action, the message will be processed by the UTM module