
[Nov-2021] Alibaba ACP-Sec1 Official Cert Guide PDF
Exam ACP-Sec1: ACP Cloud Security Professional - PrepAwayTest
Alibaba ACP-Sec1 Exam Syllabus Topics:
| Topic | Details |
|---|---|
| Topic 1 |
|
| Topic 2 |
|
| Topic 3 |
|
| Topic 4 |
|
| Topic 5 |
|
| Topic 6 |
|
| Topic 7 |
|
| Topic 8 |
|
| Topic 9 |
|
NEW QUESTION 40
You applied for an SSL certificate through Alibaba Cloud's SSL Certificates Service During the application, you selected "Manual" at the "CSR "" step. You now want to install your certificate on a server running Apache What must you do?
- A. You must revoke your certificate and re-apply, this time choosing "Automatic" at the "CSR Generation" step. Otherwise, the SSL certificate cannot be downloaded
- B. You can download a crt file of type "Other" from the SSL Certificates Service console, then use openssl to convert this file to pfx format for use with Apache
- C. You can use the "generate pfx file" function built into the SSL Certificates Service to manually generate and download the pfx file needed by Apache
- D. SSL Certificates Service doesn't support the type of certificates needed by Apache. They cannot be used together
Answer: C
NEW QUESTION 41
Before using the HTTPS protection feature in Alibaba Cloud WAF, you must upload the server certificate and private key beforehand.
- A. False
- B. True
Answer: B
NEW QUESTION 42
Alibaba Cloud ECS instances are common targets of hacker attacks. There are many types of attacks against ECS instances. Which of the following attacks specifically target the operating system of an ECS instance?
(Number of correct answers: 3)
- A. SQL injection
- B. Brute force SSH password cracking
- C. Trojan or Webshell installation
- D. Brute force RDP password cracking
Answer: B,C,D
NEW QUESTION 43
Alibaba Cloud WAF cannot protect against large traffic DDoS attacks which can be solved by Alibaba Cloud Ant-DDoS Service.
- A. False
- B. True
Answer: B
NEW QUESTION 44
Alibaba Cloud's CloudMonitor can not only monitor ECS instances in a secure and efficient way, but also monitor HTTP sites of clients' servers in data centers However, in the latter case, Alibaba Cloud does not provide monitor agent so users need to develop their own scripts to collect data
- A. False
- B. True
Answer: A
NEW QUESTION 45
Your applications are deployed on Alibaba Cloud ECS instances. You want to collect indicators by yourself for application layer monitoring. Which of the following functions provided by Alibaba Cloud CloudMonitor can be used for indicator collection, aggregation, and alerting?
- A. Custom monitoring
- B. Cloud service monitoring
- C. Site monitoring
- D. CloudMonitor cannot meet these requirements
Answer: A
NEW QUESTION 46
Anti-DDoS is one of the major products of Alibaba Cloud Security service Many websites have suffered DDoS attacks of different types. Therefore, accurate understanding of DDoS attacks is critical to the website security protection. Which of the following statements about DDoS attacks is the MOST accurate?
- A. The purpose of a DDoS attack is to steal confidential information
- B. A DDoS attack cracks the servers logon password by means of numerous attempts
- C. DDoS attacks primarily target a database
- D. The main purpose of a DDoS attack is to prevent the target server from providing normal services
Answer: D
NEW QUESTION 47
What are some of the products that support integration with Alibaba Cloud's SSL Certificates Service (Number of correct answers: 3)
- A. ApsaraDB for RDS
- B. Secure Content Distribution Network (SCDN)
- C. Content Distribution Network (CDN)
- D. Server Load Balancer (SLB)
Answer: B,C,D
NEW QUESTION 48
You have bought an ECS instance on Alibaba Cloud After deploying a Python environment on it, which of the following is the easiest and quickest way to monitor whether the Python process is running normally and report an alert if the process is accidentally terminated?
- A. Use site monitoring
- B. Utilize process monitoring feature (can be found in ECS instance
- C. Log on to the ECS instance console
- D. Write a script for monitoring by yourself.
Answer: B
NEW QUESTION 49
Content Moderation Service is an API-based service Like many API services, it employs throttling to make sure that the service cannot be overwhelmed by a large number of simultaneous requests. What is the maximum number of requests per minute you can make against the Content Moderation API?
- A. 0
- B. 1
- C. 2
- D. 3
Answer: B
NEW QUESTION 50
Alibaba Cloud Security Center can record source IP addresses that remotely access a server, and shield suspicious IP addresses that frequently connect to the server. During routine O&M. which of the following functions can be used to set the IP address that are commonly used by the system administrator'?
- A. Webshell detection
- B. Frequent logon location management
- C. Security group
- D. Valid Login IP list
Answer: B
NEW QUESTION 51
After you activate the button Data Risk Control feature in Alibaba Cloud WAF. Which of the following risk control verification modes m displayed if you directly request for a risk control protection URL?
- A. Image verification
- B. Slider verification
- C. QR code verification
- D. Digit verification
Answer: B
NEW QUESTION 52
Alibaba Cloud Security Center provides patch management service, where are the patches published from?
- A. Officially published by application vendors
- B. Officially published by operating system vendors
- C. Contributed by netizens from open-source communities
- D. Developed by Alibaba Cloud
Answer: C
NEW QUESTION 53
Alibaba Cloud Data Risk Control utilizes Alibaba Group's Big Data computing capabilities and industry-leading, risk decision making engine to address fraud threats in key service processes (such as account log on, online activity, payment) and avoid financial loss Which of the following is NOT an application scenario of Data Risk Control?
- A. Account registration
- B. Goods payment
- C. Application installation
- D. Transaction rating
Answer: C
NEW QUESTION 54
Alibaba Cloud WAF is a security protection product based on Alibaba Group's web security defense experience accumulated over more than a decade By defending against common OWASP attacks, providing patches to fix vulnerabilities, and allowing users to customize protection policies for website services, WAF can successfully safeguard the security and availability of websites and web applications. Which of the following types of security configurations does WAF provide? (Number of correct answers 3)
- A. Web application attack protection
- B. CC protection
- C. Precision access control
- D. Port access control
Answer: A,B,D
NEW QUESTION 55
Alibaba Cloud CloudMonitor is a service that monitors Alibaba Cloud resources and Internet applications.
Which of the following statements about CloudMonitor is accurate'?
- A. To use CloudMonitor for ECS monitoring, there no agent needs to be installed in ECS.
- B. CloudMonitor cannot be used through the Alibaba Cloud console
- C. CloudMonitor can monitor websites that are not deployed in Alibaba Cloud products.
- D. CloudMonitor must be independently bought and paid for activation
Answer: C
NEW QUESTION 56
Anti-DDoS Premium Service is a value-added service intended to address the problem of service interruption caused by DDoS attack to servers including non-Alibaba Cloud hosts) Users can configure a protected IP address so that the attack traffic can be redirected to this IP address, thereby ensuring the stability and reliability of the origin site. When a user configures Anti-DDoS Premium Service and imports an HTTPS certificate, the system prompts an "incorrect parameter format" error Which of the following is NOT the reason of this error?
- A. The certificate contains nonstandard content
- B. The certificate contains strings like "--"
- C. The name of the certificate is too long to be accepted
- D. The name of the certificate contains invalid letters
Answer: A
NEW QUESTION 57
Which of the following methods can be used to download the metric data of Alibaba Cloud CloudMonitor?
- A. You can only view the reports, but cannot download them.
- B. Download the data from the console
- C. You can download the data through both the console and Open APIs
- D. Download the data through Open APIs
Answer: C
NEW QUESTION 58
Which of the following configurations is NOT a feature provided by Alibaba Cloud Web Application Firewall product?
- A. HTTP ACL Policy
- B. Crawler Detection
- C. Blocked Regions
- D. Data Leakage Prevention
Answer: C
NEW QUESTION 59
baba Cloud security service provides in-depth defense Which of the following services is dedicated for host security?
- A. Security Center
- B. Anti-DDoS pro Service
- C. WAF
- D. Data Risk Control
Answer: B
NEW QUESTION 60
Which of the following attacks can Alibaba Cloud Anti-DDoS Basic defend against? (Number of coned answers 4)
- A. CMP Flood
- B. UDP Flood
- C. SYN Flood
- D. ACK Flood
- E. Brute force password cracking
Answer: B,C,D,E
NEW QUESTION 61
Cloud computing service security requires the joint effort of the cloud service supplier (such as Alibaba Cloud), independent software vendor (ISV), and users The failure of any party to fulfill their responsibilities may lead to security risks. Which of the following are the responsibilities of the cloud computing service users? (Number of correct answers 2)
- A. Provide security protection for physical infrastructure
- B. Strengthen information security management in the company to prevent sensitive information leakage
- C. Regularly change the service system password
- D. Ensure multi-channel power supply in the Cloud data center
Answer: B,C
NEW QUESTION 62
Various profit-oriented hacker groups exist on the Internet. They control a large number of server resources and can launch network attacks against a target server at any time Among those, one type of attack is common and destructive, which completely consumes resources of the target server so that normal customers cannot connect to the server Which of the following belongs to this type of attack?
- A. SQL injection
- B. Webshell attack
- C. XSS attack
- D. DDoS attack
Answer: D
NEW QUESTION 63
To improve ECS instance security, the administrator does not want users on public network to check whether an ECS instance is online using the ping command. Which of the following reinforcement measures designed by the administrator is NOT feasible?
- A. Resolve the IP address of the ECS instance to an uncommon level 4 domain name, and point the promotional domain name to the level 4 domain name through CNAME
- B. Enable an operating system firewall for the ECS instance, and reject ICMP for public network access.
- C. Enable a security group and only allow access from ports 80 and 25 of the public network through TCP
- D. Enable a security group, and reject ICMP for public network access.
Answer: A
NEW QUESTION 64
There is a limit on the number of Customer Master Keys (CMKs) that users can create using Key Management Service (KMS), but users can raise this limit by submitting a support ticket to Alibaba Cloud.
- A. False
- B. True
Answer: B
NEW QUESTION 65
......
Free ACP-Sec1 Exam Dumps to Improve Exam Score: https://www.prepawaytest.com/Alibaba/ACP-Sec1-practice-exam-dumps.html