
PASS ACP-Sec1 exam with Alibaba Real Exam Questions - 100% Valid!
Actual ACP-Sec1 Exam Recently Updated Questions with Free Demo
NEW QUESTION 47
Anti-DDoS Premium Service is a value-added service intended to address the problem of service interruption caused by DDoS attack to servers including non-Alibaba Cloud hosts) Users can configure a protected IP address so that the attack traffic can be redirected to this IP address, thereby ensuring the stability and reliability of the origin site. When a user configures Anti-DDoS Premium Service and imports an HTTPS certificate, the system prompts an "incorrect parameter format" error Which of the following is NOT the reason of this error?
- A. The name of the certificate is too long to be accepted
- B. The certificate contains strings like "--"
- C. The certificate contains nonstandard content
- D. The name of the certificate contains invalid letters
Answer: C
NEW QUESTION 48
When users log on to ECS instances through SSH or remote desktop from public Internet, Alibaba Cloud Security Center will monitor the log on behaviors If an IP address uses incorrect password to log on to an ECS instance for too many times, an alert "ECS instance suffers brute force password cracking" will be prompted If you receive this alert, which of the following is the safest way to handle this alert?
- A. Inform all users on the service platform of changing their passwords, and eliminate simple passwords using technical measures
- B. Log on immediately to the ECS instance and check the logon logs If no abnormal logon success record is found ignore this alert.
- C. This alert does not matter and can be ignored.
- D. Update the system user password immediately for the ECS instance, and enable the security group firewall to allow only specified IP addresses to connect to the ECS instance
Answer: D
NEW QUESTION 49
For which of the following protection scenarios is Alibaba Cloud WAF applicable? (Number of correct answers: 5)
- A. Data leakage prevention
- B. Virtual vulnerability patches
- C. Defense against website trojans and tampering
- D. Brute force cracking protection
- E. Protection against SMS refresh and service data crawling
- F. Protection against malicious CC attacks
Answer: A,B,C,D,F
NEW QUESTION 50
More and more blackmail attacks (using hacking tools or ransomware) have been detected among recent network security events, causing ever greater damage and financial loss. Which of the following measures can help Alibaba Cloud customers reduce risks in blackmail attacks? (Number of correct answers 3)
- A. Enable images and snapshots for ECS instances, back up data every day, and keep more than three redundant copies
- B. If remote O&M is required use IpsecVPN or SSL VPN remote solutions
- C. Use strong passwords with more than 15 characters for the accounts of all types of cloud services
- D. Deploy different service applications on servers with the same security level and security domain, and ensure unified policy management and defense
- E. When remotely operating and maintaining an ECS instance use the superuser account for login at all times
Answer: A,B,C
NEW QUESTION 51
Border Gateway Protocol (BGP) is mainly used for interconnection between autonomous systems (AS) on the Internet It. Controlling route transmission and selecting the best route Alibaba Cloud uses a BGP multi-line access mechanism for all its IDCs in China. Which of the followings are advantages of a BGP multi-line IDC?
(Number of correct answers 2)
- A. Elimination of access barriers between North China and South China because China is big and North China and South China has different telecom operators
- B. Larger bandwidth
- C. Low bandwidth cost
- D. High-speed interconnection
Answer: A,D
NEW QUESTION 52
In which of the following scenarios is Alibaba Cloud Security Center applicable? (Number of correct answers
3)
- A. Penetration testing
- B. Setting up web server to provide web service to public
- C. Batch server security O&M
- D. Network security protection for ad campaigns or other activities
- E. Creating an ECS with generic software
Answer: A,C,D
NEW QUESTION 53
Anti-DDoS is one of the major products of Alibaba Cloud Security service Many websites have suffered DDoS attacks of different types. Therefore, accurate understanding of DDoS attacks is critical to the website security protection. Which of the following statements about DDoS attacks is the MOST accurate?
- A. DDoS attacks primarily target a database
- B. The main purpose of a DDoS attack is to prevent the target server from providing normal services
- C. A DDoS attack cracks the servers logon password by means of numerous attempts
- D. The purpose of a DDoS attack is to steal confidential information
Answer: B
NEW QUESTION 54
When importing key material into Key Management Service (KMS), you will be given an import token and public encryption key valid for 24 hours. The public key KMS provides must be used to encrypt your key material before upload KMS allows you to choose different public key encryption algorithms Which ones are supported? (Number of correct answers; 3)
- A. RSAES_OAEP_SHA_256
- B. RSAES_OAEP_SHA_1
- C. RSAES PKCS1 V1 5
- D. RSAES_ECDHE_V1 _5
Answer: B,C,D
NEW QUESTION 55
A customer built his website on Alibaba Cloud- To defend against Web attacks he activated Alibaba Cloud WAF However, a week later, the customer finds that his website has suffered intrusion. Which of the following actions should he take to ensure that WAF functions correctly and enhance system security?
(Number of correct answers: 4)
- A. Use Security Center to remove Trojans and fix vulnerabilities
- B. Check whether or not the DNS resolution results point to the WAF address
- C. Configure a security group for the ECS instance.
- D. Resolve the website domain name to the site s source IP address
- E. Delete all snapshots and clear the server
- F. Secure other HTTP services on the ECS instance using WAF
Answer: A,B,C,F
NEW QUESTION 56
baba Cloud security service provides in-depth defense Which of the following services is dedicated for host security?
- A. Anti-DDoS pro Service
- B. WAF
- C. Data Risk Control
- D. Security Center
Answer: A
NEW QUESTION 57
Content Moderation service is useful m a wide variety of scenarios. Which of the following are the *most* suited to Content Moderation's capabilities? (Number of correct answers 2)
- A. Detecting spam posts on a forum
- B. Detecting sensitive customer information such as credit card numbers in uploaded images
- C. Deleting porn on a social networking site
- D. Detecting faces in images
Answer: A,C
NEW QUESTION 58
Alibaba Cloud Security Center provides patch management service, where are the patches published from?
- A. Officially published by application vendors
- B. Officially published by operating system vendors
- C. Developed by Alibaba Cloud
- D. Contributed by netizens from open-source communities
Answer: D
NEW QUESTION 59
There is a limit on the number of Customer Master Keys (CMKs) that users can create using Key Management Service (KMS), but users can raise this limit by submitting a support ticket to Alibaba Cloud.
- A. False
- B. True
Answer: B
NEW QUESTION 60
When using Alibaba Cloud Anti-DDoS Service/WAF in China Mainland, you must finish ICP Filing beforehand.
- A. False
- B. True
Answer: B
NEW QUESTION 61
In a public cloud environment Alibaba Cloud is responsible for security of cloud computing infrastructure (such as the IDC environment, physical server O&M, and virtualization layer of cloud products). However, you still need to perform necessary security optimization measures for the Cloud products you purchased Which of the following actions do you think are safe?
- A. For easy management, change the administrator password for the ECS instance to 123456.
- B. To reduce the communication cost, five administrators of the company use the root account to log on to the ECS instance.
- C. To enable colleagues working at home to update data, open public IP addresses for ApsaraDB for RDS instances, and allow all IP addresses to connect to the instances
- D. After buying an ECS instance, enable the security group firewall for the ECS instance through the console, and only allow a management IP address to remotely log on to the ECS instance.
Answer: D
NEW QUESTION 62
Cross Site Script (XSS) attacks refer to a kind of attack by tampering the webpage using HTML injection to insert malicious scripts so as to control the user's browser when the user browses the webpage XSS vulnerabilities may be used for user identity stealing (particularly the administrator identity), behavior hijacking, Trojan insertion and worm spreading, and also phishing
- A. False
- B. True
Answer: B
NEW QUESTION 63
Before using the HTTPS protection feature in Alibaba Cloud WAF, you must upload the server certificate and private key beforehand.
- A. False
- B. True
Answer: B
NEW QUESTION 64
Which of the following features are available in Alibaba Cloud Anti-DDoS Premium product? (Number of correct answers: 3)
- A. SQL injection Attack blocking
- B. Web application layer DDoS protection
- C. Malformed packets filtering
- D. Transport layer DDoS protection
Answer: B,C,D
NEW QUESTION 65
Alibaba Cloud WAF identifies attacks using human/robot detection, Big Data analysis, model analysis, and other related techniques. Which of the following CC attack defense modes does WAF provide to meet the protection requirements of users? (Number of correct answers 2)
- A. Threat
- B. Attack emergency
- C. Normal
- D. Exception
Answer: B,C
NEW QUESTION 66
Alibaba Cloud ECS instances are common targets of hacker attacks. There are many types of attacks against ECS instances. Which of the following attacks specifically target the operating system of an ECS instance?
(Number of correct answers: 3)
- A. Brute force SSH password cracking
- B. SQL injection
- C. Brute force RDP password cracking
- D. Trojan or Webshell installation
Answer: A,C,D
NEW QUESTION 67
Products like ECS and Server Load Balancer it will be automatically protected by Anti-DDoS Basic service
- A. False
- B. True
Answer: B
NEW QUESTION 68
Clean bandwidth refers to the maximum normal clean bandwidth that can be processed by Anti-DDoS Premium instances when your business is not under attack. Make sure that the Clean bandwidth of the instance is greater than the peak value of the inbound or outbound traffic of all services connected to the Anti-DDoS Premium instances If the actual traffic volume exceeds the maximum Clean bandwidth, your business may be subject to traffic restrictions or random packet losses, and your normal business may be unavailable, slowed, or delayed for a certain period of time
- A. False
- B. True
Answer: B
NEW QUESTION 69
If you install Alibaba Cloud Security Center client on a non-Alibaba Cloud server, which of the following statements allows you to check the server-related reports on the Security Center?
- A. Security Center does not support non-Alibaba Cloud servers
- B. You need to manually install the agent on the external server, and use a verification key to associate it with your account
- C. Associate the Security Center client with your Alibaba Cloud official website account.
- D. You cannot check the reports on the Alibaba Cloud console.
Answer: B
NEW QUESTION 70
......
Alibaba ACP-Sec1 Exam Syllabus Topics:
| Topic | Details |
|---|---|
| Topic 1 |
|
| Topic 2 |
|
| Topic 3 |
|
| Topic 4 |
|
| Topic 5 |
|
| Topic 6 |
|
| Topic 7 |
|
| Topic 8 |
|
ACP-Sec1 Free Sample Questions to Practice One Year Update: https://www.passtorrent.com/ACP-Sec1-latest-torrent.html