2021 ACA-Sec1 Premium Files Test pdf - Free Dumps Collection [Q35-Q56]

Share

2021 ACA-Sec1 Premium Files Test pdf - Free Dumps Collection

 Get ready to pass the ACA-Sec1 Exam right now using our Alibaba Security  Exam Package


Alibaba ACA-Sec1 Exam Syllabus Topics:

TopicDetails
Topic 1
  • Familiar with common network protocols such as HTTP, FTP, TCP, UDP and ICMP
Topic 2
  • Activating, creating, configuring, starting and stopping and disabling a service
Topic 3
  • Aware of main application scenarios of Alibaba Cloud Security related products and know each of these products’ special usage scenario
Topic 4
  • Familiar with features of Alibaba Cloud Security related products and key product implementation principles
Topic 5
  • Understanding of the concepts of Alibaba Cloud Security related products
Topic 6
  • Familiar with operations of Alibaba Cloud Security related products
Topic 7
  • Knowledge of network security, such as firewall policy, key encryption, access control, network security, and network attack and protection methodologies
Topic 8
  • Able to discover and resolve common issues emerged during the use of Alibaba Cloud Security related products
Topic 9
  • Familiar with the concepts and related knowledge of Cloud Computing
Topic 10
  • Virtualization, storage and networking
  • Familiar with operation on Linux and Windows operating system and be able to configure network and storage related system commands

 

NEW QUESTION 35
Which of the following options can be considered as Physical environment security risks in IT infrastructure

  • A. Sounder
  • B. Data encryption
  • C. Rain
  • D. Room temperature

Answer: A,C,D

 

NEW QUESTION 36
Which of the following statements are true for how to login to different ECS operating system? (the number of correct answers: 2) Score 1

  • A. use 'remote desktop connection' for Linux
  • B. use 'ssh' tool for windows
  • C. use 'remote desktop connection' for windows
  • D. use 'ssh' tool for Linux

Answer: C,D

 

NEW QUESTION 37
Reliable server daily operation and security management are essential for continuous service running. Which of the following statement is NOT correct regarding to this scenario?

  • A. set easy to remember password to help administrator quickly login and solve problems
  • B. patch system timely and frequently
  • C. enable build-in OS firewall and configure it properly
  • D. disable the ports which are not providing service anymore

Answer: A

 

NEW QUESTION 38
Which of the following methods CANNOT increase account security?

  • A. Periodically reset the user login passwords
  • B. Unite user management, permission management and resource management into a single management process
  • C. Strong password policies
  • D. Adhere to the minimum authorization principle

Answer: B

 

NEW QUESTION 39
Which of the following benefit cannot be provided by 'Server Guard'?
Score 2

  • A. get instant alerts after attacks are detected
  • B. improve the usage of system resource
  • C. lower the risk of sensitive data leak
  • D. lower the cost of security protection

Answer: B

 

NEW QUESTION 40
Which protocol is a 'data link' layer protocol in ISO/OSI 7 layer network model?
Score 2

  • A. FTP
  • B. ICMP
  • C. ARP
  • D. UDP

Answer: C

 

NEW QUESTION 41
18.in RedHat Linux shell which command can be used to check what file system is mounted and form what disk device it was done?

  • A. Fdisk
  • B. Du
  • C. mount
  • D. Ppart

Answer: C

 

NEW QUESTION 42
ECS cloud server is one of the service provided by Alibaba Cloud. If it is attacked by some internet hacker, which of the following consequences such attack could cause? (the number of correct answers: 2)

  • A. Leak of customer sensitive data
  • B. Service running on this ECS become not available
  • C. The datacenter where the ECS belongs to need to shutdown
  • D. Physical Server Damage

Answer: A,B

 

NEW QUESTION 43
Inside cloud, hypervisor vulnerability could cause the following possible consequences: (the number of correct answers: 3)

  • A. One client host can access another client's data
  • B. User service become unavailable
  • C. Incorrect client resource usage calculating
  • D. Hacker can access host server directly

Answer: A,B,D

 

NEW QUESTION 44
Which of the following services can suffer from DDoS attack?

  • A. Offline servers
  • B. Any device internet reachable
  • C. Servers in VPC only configured with private network
  • D. Government website
  • E. Public DNS service

Answer: B,D,E

 

NEW QUESTION 45
Which of the following statements is NOT true about EIP and NAT gateway?

  • A. NAT gateway can support multi servers inside VPC to access public internet through one public IP
  • B. EIP can be bind to different ECS servers at the same time
  • C. NAT gateway can support shared bandwidth between several ips
  • D. Different EIP can't share bandwidth

Answer: B

 

NEW QUESTION 46
If WAF service user updated web page content after turning on website tampering protection, what does user need to do on WAF console?

  • A. turn on protection switch manually
  • B. restart the whole WAF service
  • C. add one protection rule
  • D. Update cache

Answer: D

 

NEW QUESTION 47
Which of the following DDoS descriptions are correct?

  • A. If the target server has no vulnerabilities, the remote attack may still succeed.
  • B. Causes the target server unable to process legitimate requests
  • C. Steal confidential information
  • D. In order to get admin password

Answer: A,B

 

NEW QUESTION 48
What will the correct stops the traffic will flow through if the user used all following cloud service: WAF, Anti-DDOS pro, CDN.

  • A. CDN- >Anti-DDOS Pro->WAF->Original Website
  • B. Anti-DDOS Pro->WAF->CDN->Original website
  • C. Anti-DDOS Pro->CDN->WAF->Original website
  • D. CDN- >WAF->Anti-DDOS Pro->Original website

Answer: C

 

NEW QUESTION 49
In Linux OS, if you want to set a file access privilege to read, write, and execute for the owner only, what octal number will reflect such settings correctly?
Score 2

  • A. 0
  • B. 1
  • C. 2
  • D. 3

Answer: D

 

NEW QUESTION 50
A DoS attack that sends a flood of synchronization (SYN) requests and never sends the final acknowledgement (ACK) is typically known as which of the following?

  • A. Fraggle
  • B. Smurf
  • C. SYN flood
  • D. Ping Flood

Answer: C

 

NEW QUESTION 51
In the Alibaba Cloud, which services can satisfy client user identity management requirements?

  • A. Server Guard
  • B. Resource Access Management (RAM)
  • C. Situational awareness
  • D. Security group

Answer: B

 

NEW QUESTION 52
What of the followings will happen if encounter DoS or DDoS attack?

  • A. unauthorized access control
  • B. Data received successfully
  • C. Slow access web resources
  • D. Delay of data reception

Answer: C,D

 

NEW QUESTION 53
After WAF was purchased, users need to add one DNS record to map their domain name to WAF provided IP. What is the type of that DNS record?

  • A. CNAME Record
  • B. TXT Record
  • C. A record
  • D. MX Record

Answer: A

 

NEW QUESTION 54
Which of the following statements about VLAN are NOT true?(the number of correct answers: 3) Score 1

  • A. different VLAN means different physical location of switches
  • B. VlAN can enhance the network security and data isolation
  • C. VLAN configuration can be done through an TCP/IP router device
  • D. users in different VLAN can connect each other directly without pre-configuration

Answer: A,C,D

 

NEW QUESTION 55
What is the correct action sequence of WAF protection strategy: (1) CC detection (2) Web application attack detection (3) Access control Score 2

  • A. 0
  • B. 1
  • C. 2
  • D. 3

Answer: A

 

NEW QUESTION 56
......

Master 2021 Latest The Questions Alibaba Security and Pass ACA-Sec1  Real Exam!: https://www.pass4surequiz.com/ACA-Sec1-exam-quiz.html