Steps Necessary To Pass The ACA-Sec1 Exam from Training Expert PracticeMaterial [Q53-Q71]

Share

Steps Necessary To Pass The ACA-Sec1 Exam from Training Expert PracticeMaterial

Valid Way To Pass Alibaba Security's  ACA-Sec1 Exam

NEW QUESTION 53
Which of the following statements is NOT true about web application security protection best practices?

  • A. keep monitoring system processes , performance and status
  • B. always scan input by user through web application
  • C. enforce security management to any public service
  • D. keep installing official released patches will be good enough

Answer: D

 

NEW QUESTION 54
Using RAM, Alibaba Cloud users can create and manage user accounts and control the operation permissions these user accounts possess for resources under your account. Which of the following descriptions of a RAM usage scenario is NOT correct?

  • A. Temporary authorization management for untrusted client apps
  • B. Prevention of network attacks on enterprises
  • C. Resource operation and authorization management between enterprises
  • D. Enterprise sub-account management and permission assignment

Answer: B

 

NEW QUESTION 55
Which of the following 4 functions can be achieved through ECS security group configuration?

  • A. assign customized IP address to ECS
  • B. make ECS server be able to defend 15Gb/s DDOS attack
  • C. fix XSS vulnerability
  • D. allow specific IP to remote access ECS server

Answer: D

 

NEW QUESTION 56
In making cloud accounts more secure, which of the following is NOT a guiding principle?

  • A. Login verification
  • B. Account permissions
  • C. Anonymous logins
  • D. Authorization distribution

Answer: C

 

NEW QUESTION 57
Which of the following protocols is not an application level protocol in ISO/OSI 7 layer networking model?

  • A. FTP
  • B. TCP
  • C. HTTP
  • D. SNMP

Answer: B

 

NEW QUESTION 58
Which of the following methods can't be used against CC attack?

  • A. change the service providing port
  • B. resolve domain name to a disguised IP
  • C. use WAF
  • D. change HTTP service to HTTPS service

Answer: D

 

NEW QUESTION 59
Customer who bought ECS server doesn't need to worry about :

  • A. OS vulnerability inside ECS
  • B. Web service security inside ECS
  • C. ECS security group setting
  • D. Cloud infrastructure security

Answer: D

 

NEW QUESTION 60
By default, servers in VPC can't communicate with internet. By implementing which of the following products these servers can gain the capability to communicate with internet? (the number of correct answers: 3)

  • A. EIP + NAT Gateway
  • B. Elastic Public IP
  • C. CDN
  • D. EIP + SLB
  • E. DNS service

Answer: A,B,D

 

NEW QUESTION 61
User A rented 2 ECS server and one RDS in Alibaba Cloud to setup his company public website. After the web site will become available online, the security risks he/she will face will include: (the number of correct answers: 3)

  • A. RDS DB got unknown remote logon
  • B. the disk in ECS is broken
  • C. website codes has some vulnerability
  • D. physical cable is cut by someone
  • E. ECS admin password is hacked

Answer: A,C,E

 

NEW QUESTION 62
In Windows OS you can turn off a service through: Score 2

  • A. Create new firewall rule to stop service
  • B. Delete administrator role and related accounts
  • C. Control Panel->windows update->Stop
  • D. Control Panel->Management Tool->Stop the running service

Answer: D

 

NEW QUESTION 63
Security risk may caused by 'Cloud platform', 'ISV' or 'End user', which of the following options are the possible risks may caused by Cloud Platform?

  • A. Cloud platform console and API may lack of security hardenning
  • B. Administration tools on Cloud Platform may have some flaws
  • C. Software development cycle is not formalized
  • D. Security system overall solutions are not complete

Answer: A,B,D

 

NEW QUESTION 64
Which of the following can be termed as the Denial of Service Attack? Choose the best answer.

  • A. Your router is unable to find a destination outside of your network
  • B. A computer on your network has crashed
  • C. Your Web server has gone into a loop trying to service a client request
  • D. You keyboard is no longer responding

Answer: C

 

NEW QUESTION 65
Which of the following issues will NOT be an issue anymore using Alibaba Cloud ECS server? Score 2

  • A. server is under brute force password hacking
  • B. hardware disk or memory broken
  • C. application vulnerability being leveraged by hackers
  • D. infection by Trojan Virus

Answer: B

 

NEW QUESTION 66
Identify the attack where the purpose is to stop a workstation or service from functioning?

  • A. This attack is known as brute force
  • B. This attack is known as TCP/IP hijacking
  • C. This attack is known as non-repudiation
  • D. This attack is known as denial of service (DoS)

Answer: D

 

NEW QUESTION 67
Which command in RedHat Linux shell can be used to check disk usage?

  • A. diskSpace
  • B. df
  • C. ls
  • D. diskUsage

Answer: B

 

NEW QUESTION 68
What modes Alibaba Cloud WAF will provide to defend SQL injection? (the number of correct answers: 2) Score 1

  • A. Warning Mode
  • B. Protection Mode
  • C. Normal Mode
  • D. Restriction Mode

Answer: A,B

 

NEW QUESTION 69
Each host connecting to internet will face the potential attacks from internet as follows : ( the numbers of correct answers : 3)

  • A. Trojan planting
  • B. Lack of storage resource
  • C. Vulnerability scanning
  • D. Content Compliance Requirement
  • E. Brute Force password hacking

Answer: A,C,E

 

NEW QUESTION 70
Which of the following security vulnerability is not a 'Server Side' security issue?

  • A. File uploading vulnerability
  • B. System Command Execution vulnerability
  • C. CSRF(cross site request fraud)vulnerability
  • D. SQL injection

Answer: C

 

NEW QUESTION 71
......

All ACA-Sec1 Dumps and ACA Cloud Security Certification Exam Training Courses: https://www.practicematerial.com/ACA-Sec1-exam-materials.html