
ACA-Sec1 Exam Dumps, ACA-Sec1 Practice Test Questions
PDF (New 2021) Actual Alibaba ACA-Sec1 Exam Questions
Alibaba ACA-Sec1 Exam Syllabus Topics:
| Topic | Details |
|---|---|
| Topic 1 |
|
| Topic 2 |
|
| Topic 3 |
|
| Topic 4 |
|
| Topic 5 |
|
| Topic 6 |
|
| Topic 7 |
|
| Topic 8 |
|
| Topic 9 |
|
NEW QUESTION 55
Which of the following scenarios is the one that 'Server Guard' will support for brute force password hacking detection?
- A. RDS remote connection
- B. Linux CRM application remote logon
- C. Windows shared directory access
- D. ECS server remote logon or inside DB remote logon
Answer: D
NEW QUESTION 56
When we talk about 'security vulnerability' of ECS server, we are referring to: (the number of correct answers: 3)
- A. Hardware fault
- B. Data Center Serviceability
- C. OS vulnerability
- D. Hypervisor Vulnerability
- E. Application Vulnerability
Answer: C,D,E
NEW QUESTION 57
Which of following statements about the possible reasons that cause web server vulnerabilities are true? (the number of correct answers: 2) Score 1
- A. End user didn't follow the user manual
- B. Software used or OS itself contain some logic flaw
- C. Hardware configuration is not up to date
- D. Bugs generated during common component development
Answer: B,D
NEW QUESTION 58
If your company's official website is tampered, the consequence of such attack could NOTbe:
- A. Physical server is damaged
- B. Public image or reputation of your company is damaged
- C. Website is used for some illegal attempts
- D. Business is impacted
Answer: A
NEW QUESTION 59
Which of the following risks are considered as common network security risk? (the number of correct answers: 2)
- A. Massive traffic flood attack
- B. Software version is not up to date
- C. Physical Fiber Channel Cable is broken
- D. Data under transferring is being sniffed
Answer: B,D
NEW QUESTION 60
Security risk may caused by 'Cloud platform', 'ISV' or 'End user', which of the following options are the possible risks may caused by Cloud Platform?
- A. Administration tools on Cloud Platform may have some flaws
- B. Security system overall solutions are not complete
- C. Software development cycle is not formalized
- D. Cloud platform console and API may lack of security hardenning
Answer: A,B,D
NEW QUESTION 61
Which of the following descriptions of the shared responsibilities security model is CORRECT?
- A. After beginning to use cloud service, users only need to pay attention to the security of their own apps and data. All other security will be the responsibility of the cloud service provider.
- B. After beginning to use cloud service, the user and the cloud service provider will be jointly responsible for cloud security, with each responsible for different layers of security.
- C. After beginning to use cloud service, the cloud service provider will become responsible for all of the user's security.
- D. After beginning to use cloud service, users must still take care of physical and environmental security.
Answer: B
NEW QUESTION 62
Which of the following options could NOT be the reason that causes website tampering
- A. Share password between different users
- B. Wrong security configuration
- C. Botnet attack
- D. system vulnerability is not fixed in time
Answer: C
NEW QUESTION 63
What type of attack is likely occuring if you see a significant increase in network traffic and users complain that the web server is hung up?
- A. DoS
- B. MITM
- C. DNS spoofing
- D. Ping sweep
Answer: A
NEW QUESTION 64
Which of the following protocol is dedicated to resolve IP and MAC addresses?
- A. ICMP
- B. TCP
- C. ARP
- D. DNS
Answer: C
NEW QUESTION 65
Which of the following can be termed as the Denial of Service Attack? Choose the best answer.
- A. You keyboard is no longer responding
- B. Your Web server has gone into a loop trying to service a client request
- C. A computer on your network has crashed
- D. Your router is unable to find a destination outside of your network
Answer: B
NEW QUESTION 66
Which of the following services can suffer from DDoS attack?
- A. Public DNS service
- B. Government website
- C. Any device internet reachable
- D. Offline servers
- E. Servers in VPC only configured with private network
Answer: A,B,C
NEW QUESTION 67
Which of the following issues would not happen if ECS server is under attack by hackers?
- A. physical server damage
- B. compromise the reputation of service provider on that server
- C. service running on that server is not available
- D. sensitive data leak
Answer: A
NEW QUESTION 68
A DoS attack that sends a flood of synchronization (SYN) requests and never sends the final acknowledgement (ACK) is typically known as which of the following?
- A. Smurf
- B. Fraggle
- C. SYN flood
- D. Ping Flood
Answer: C
NEW QUESTION 69
Which of the following statements are true for how to login to different ECS operating system? (the number of correct answers: 2) Score 1
- A. use 'remote desktop connection' for windows
- B. use 'ssh' tool for windows
- C. use 'remote desktop connection' for Linux
- D. use 'ssh' tool for Linux
Answer: A,D
NEW QUESTION 70
Which of the following methods can't be used to prevent SQL injection attack?
- A. Use secured function call
- B. Strict input check
- C. Warning message for abnormal input
- D. SQL precompiling and variable binding
Answer: C
NEW QUESTION 71
Which of the following options is the top 1 web application security risk based on OWASP 2017 report?
- A. SQL Injection
- B. Server Information Theft
- C. Code Execution
- D. XSS Attack
Answer: A
NEW QUESTION 72
What are the advantages of anti-DDOS pro comparing to anti-DDOS basics service?
(the number of correct answers: 3)
- A. can protect IDC outside Alibaba Cloud
- B. stronger defending attacks capability
- C. elastic protection bandwidth
- D. can do anti-fraud protection
- E. no upper limit to the attack traffic need to be handled
Answer: A,B,C
NEW QUESTION 73
Which of the following Keys in HTTP heads are related to cache control? (the number of correct answers: 3)
- A. Host
- B. Expires
- C. Age
- D. Date
- E. Cache-Control
Answer: A,C
NEW QUESTION 74
......
Updated Dec-2021 Pass ACA-Sec1 Exam - Real Practice Test Questions: https://pass4itsure.passleadervce.com/Alibaba-Security/reliable-ACA-Sec1-exam-learning-guide.html