
[Oct-2021] Get 100% Real ACA-Sec1 Exam Questions, Accurate & Verified PracticeTorrent Dumps in the Real Exam!
Pass Your Alibaba Security Exams Fast. All Top ACA-Sec1 Exam Questions Are Covered.
NEW QUESTION 87
Which of the following statements about VLAN are NOT true?(the number of correct answers: 3) Score 1
- A. users in different VLAN can connect each other directly without pre-configuration
- B. VlAN can enhance the network security and data isolation
- C. different VLAN means different physical location of switches
- D. VLAN configuration can be done through an TCP/IP router device
Answer: A,C,D
NEW QUESTION 88
Which of the following statements are true to describe a SQL attack commonly used pattern? (the number of correct answers: 3)
- A. adding ";" or "--" to change the original request purpose with new request attached
- B. Adding more search request together with the original one
- C. use selfmade variable
- D. use incorrect SQL function
- E. adding an absolute true condition to bypass original request
Answer: B,C,E
NEW QUESTION 89
Which of the following statements are true for how to login to different ECS operating system? (the number of correct answers: 2) Score 1
- A. use 'remote desktop connection' for windows
- B. use 'ssh' tool for Linux
- C. use 'remote desktop connection' for Linux
- D. use 'ssh' tool for windows
Answer: A,B
NEW QUESTION 90
Which of the following protocol can be considered as 'application' layer protocol in ISO/OSI 7 layer model?
- A. SMTP
- B. IP
- C. UDP
- D. TCP
Answer: A
NEW QUESTION 91
Which of the following options can be considered as Physical environment security risks in IT infrastructure
- A. Room temperature
- B. Sounder
- C. Data encryption
- D. Rain
Answer: A,B,D
NEW QUESTION 92
Which web server is default one in Windows OS?
- A. Apache
- B. Web Daemon
- C. HTTPD
- D. IIS
Answer: D
NEW QUESTION 93
Identify the attack where the purpose is to stop a workstation or service from functioning?
- A. This attack is known as brute force
- B. This attack is known as TCP/IP hijacking
- C. This attack is known as non-repudiation
- D. This attack is known as denial of service (DoS)
Answer: D
NEW QUESTION 94
You configure a computer to act as a zombie set in order to attack a web server on a specific date.
What would this contaminated computer be part of?
- A. The computer is part of a man-in-the-middle attack
- B. The computer is part of a DDoS attack
- C. The computer is part of a TCP/IP hijacking
- D. The computer is part of a spoofing attack
Answer: B
NEW QUESTION 95
In Linux OS, if access control to a file is shown as '-rwxrw-r--' in shell command, which of the following statements are true?
Score 2
- A. This file is a text file
- B. The access privilege of this user group is read only
- C. Other users (outside of this user group) can execute this file
- D. The owner of this file has read/write/execution privilege to this file
Answer: D
NEW QUESTION 96
Reliable server daily operation and security management are essential for continuous service running. Which of the following statement is NOT correct regarding to this scenario?
- A. disable the ports which are not providing service anymore
- B. set easy to remember password to help administrator quickly login and solve problems
- C. patch system timely and frequently
- D. enable build-in OS firewall and configure it properly
Answer: B
NEW QUESTION 97
User A rented 2 ECS server and one RDS in Alibaba Cloud to setup his company public website. After the web site will become available online, the security risks he/she will face will include: (the number of correct answers: 3)
- A. RDS DB got unknown remote logon
- B. the disk in ECS is broken
- C. website codes has some vulnerability
- D. physical cable is cut by someone
- E. ECS admin password is hacked
Answer: A,C,E
NEW QUESTION 98
Which of the following protocols will not be used for a SYN Flood attack?
- A. IPX/SPX
- B. AppleTalk
- C. UDP
- D. TCP
Answer: A,B,C
NEW QUESTION 99
Alibaba Cloud will provide hot fix to address existing vulnerabilities. Which of the following statements is true about this 'hot fix'?
- A. service will not be available during the hot fix
- B. hot fix means the host need to reach some temperature upper limit to be able to proceed
- C. hot fix is transparent to end user
- D. hot fix doesn't need to reboot physical host
Answer: D
NEW QUESTION 100
Which of following elements are included in a TCP/IP based route table? (the number of correct answers: 3)
- A. Network Destination
- B. Port
- C. Netmask
- D. Gateway IP
- E. Mac Address
Answer: A,C,D
NEW QUESTION 101
You just physically attached one new disk to a Linux server. Before you can write data into that disk with shell command, which of the following steps you have to finish? (the number of correct answers: 4) Score 1
- A. Create Filesystem
- B. Format
- C. Raw Format
- D. Mount
- E. Make Partitions
Answer: A,B,D,E
NEW QUESTION 102
If your company has a lot of employees who would try to simultaneously access ECS server protected by 'Server Guard' using your company's intranet, the 'Sever Guard' may mistakenly identify those access requests as attacks. Which of the following methods is the best way to solve this problem? Score 2
- A. set a highly complexed administrator password
- B. add those IPs which need to access ECS server into 'Server Guard' logon white list
- C. change the rule of security group to unblock all company internal ips
- D. ask employees to access that ECS server not very frequently
Answer: B
NEW QUESTION 103
......
Penetration testers simulate ACA-Sec1 exam: https://www.practicetorrent.com/ACA-Sec1-practice-exam-torrent.html