Huawei Certified ICT Professional - Security - CSSN — Free Practice Questions
10 free sample questions from a bank of 95, with the correct answers and explanations. No signup required — start practising right now.
1Regarding the description of file reputation technology in anti-virus engines, which of the following options is correct?
File reputation database can only be upgraded by manual upgrade
File reputation is to perform virus detection by calculating the full text MD5 of the file to be tested and matching it with the local reputation MD5 cache
File reputation database update and upgrade can only be achieved through linkage with sandbox
Local reputation MD5 cache only has static cache, which needs to be updated regularly
Answer: B
The short version
B — File reputation detects by full-file MD5 matched against the local cache. Reputation lookup is a hash allowlist-denylist check, not full content inspection.
Full-text MD5: hash computed over the whole file so identical files share one identifier.
Local reputation cache: locally stored MD5 verdicts for fast offline lookup before cloud query.
Why B is correct
File reputation works by computing the MD5 of the file under test and comparing it with reputation entries cached locally, escalating to the cloud reputation database on a miss. This hash-match design makes detection fast and lightweight, which is exactly what option B states, so the banked answer B is retained.
Why the others are wrong
A. The reputation database supports automatic scheduled updates, not manual-only upgrade.
C. Sandbox linkage is one intelligence source, not the only way to update the database.
D. The local cache is not static-only; it includes dynamic entries learned and aged automatically alongside scheduled updates.
H12-722 exam tip
Remember reputation equals hash matching: MD5 in, verdict out; engine and sandbox do the deep analysis.
2The whitelist rule of the firewall anti-virus module is configured as ("example, which of the following matching methods is used in this configuration?
Prefix matching
Exact match
Keyword matching
Suffix matching
Answer: C
The short version
C — Leading and trailing wildcards mean keyword (substring) matching. The pattern matches the string anywhere it appears.
Key concepts in this question
Whitelist rule: trusted URL or keyword entry that bypasses anti-virus inspection.
Wildcard asterisk: placeholder matching any character sequence.
Keyword matching: substring match anywhere in the target, expressed with wildcards on both sides.
Why C is correct
A value wrapped in asterisks on both sides matches any string containing the keyword, which is the definition of keyword matching in the Huawei anti-virus whitelist. Prefix matching would wildcard only the tail, suffix matching only the head, and exact match would use no wildcard, so C is the only consistent reading and the banked answer is retained.
Why the others are wrong
A. Prefix matching fixes the start of the string and wildcards the end, the opposite of this pattern.
B. Exact match requires the full string with no wildcards, which this configuration does not use.
D. Suffix matching fixes the end of the string and wildcards the start, using only a leading wildcard.
H12-722 exam tip
Read the asterisks: star at both ends means contains, star at end means starts-with, star at front means ends-with.
3In the construction of information security, the intrusion detection system plays the role of a monitor. It monitors the flow of key nodes in the information system.In-depth analysis to discover security incidents that are occurring. Which of the following are its characteristics?. c0O
Cannot do in-depth inspection
It is impossible to correctly analyze the malicious code doped in the allowed application data stream.
IDS can be linked with firewalls and switches to become a powerful "assistant" of firewalls, which can better and more accurately control access between domains.
Unable to detect malicious operations or misoperations from internal killings.
Answer: C
The short version
C — IDS monitors traffic in depth and can link with firewalls and switches. It assists access control with detection intelligence.
Key concepts in this question
IDS monitor role: passive deep analysis of traffic at key nodes to detect ongoing incidents.
Firewall linkage: IDS alarms driving firewall or switch blocking and quarantine actions.
In-depth inspection: protocol and payload analysis, including malicious code hidden in permitted flows.
Why C is correct
An IDS performs deep packet and behavior analysis rather than shallow header checks, and Huawei designs it to interoperate with firewalls and switches so detections become blocking or isolation actions. Option C captures both the monitoring depth and the assistant role to the firewall, so the banked answer C is retained.
Why the others are wrong
A. IDS exists precisely to perform in-depth inspection, so claiming it cannot is backwards.
B. Deep inspection lets IDS find malicious code carried inside allowed application streams.
D. Host and traffic-based detection covers insider misuse and internal attacks, not only external threats.
H12-722 exam tip
Associate IDS with monitor plus helper: it watches deeply and tells the firewall what to block.
4Anti-DDoS defense system includes: management center, detection center and cleaning center.
True
False
Answer: A
The short version
A — True: the system has management, detection, and cleaning centers. These three roles form the standard Huawei Anti-DDoS solution.
Key concepts in this question
Management center: central policy, reporting, and device management plane.
Detection center: traffic anomaly detection and diversion decision point.
Cleaning center: scrubbing of attack traffic with clean traffic reinjection.
Why A is correct
Huawei Anti-DDoS defense is documented as a three-center architecture: the detection center spots anomalies, the cleaning center diverts and scrubs, and the management center orchestrates policy and reporting. The statement lists exactly these three components, so it is true and the banked answer A is retained.
Why the others are wrong
B. False would deny a documented three-center design; detection plus cleaning plus management is the standard deployment model.
H12-722 exam tip
Memorize the trio manage, detect, clean; any question listing all three is describing the full solution.
5In the penetration stage of an APT attack, which of the following attack behaviors will the attacker generally have?
Through phishing emails, attachments with 0day vulnerabilities are carried, causing the user's terminal to become a springboard for attacks.
Long-term latency and collection of key data.
The attacker sends a C&C attack or other remote commands to the infected host to spread the attack horizontally on the intranet.
Leak the acquired key data information to a third party of interest
Answer: C
The short version
C — In the penetration and lateral-spread phase the attacker uses C and C to drive intranet expansion. Remote commands push the foothold sideways.
Key concepts in this question
APT penetration stage: expanding from the initial foothold across the internal network.
C and C channel: remote command path from attacker to compromised hosts.
Horizontal movement: infecting additional intranet hosts from the beachhead.
Why C is correct
After initial compromise, the penetration phase centers on controlling infected hosts through C and C and using them as springboards for lateral movement inside the network. Option C describes exactly that behavior, while the other options belong to earlier or later APT phases, so the banked answer C is retained.
Why the others are wrong
A. Phishing with a zero-day attachment is the initial intrusion vector, not the penetration-expansion behavior.
B. Long-term dormancy and data collection describe the persistence and harvest phase.
D. Exfiltrating data to an interested third party is the final leakage stage.
H12-722 exam tip
Map APT order: phish in, C and C sideways, quietly collect, then leak; penetration means sideways.
6Which of the following iterations is correct for the description of the management center?
The management center is divided into two parts: management server and teaching data collector.
The management server of the management center is responsible for the cleaning of abnormal flow, as well as the collection and analysis of business data, and storage, and is responsible for the summary The stream is reported to the management server for report presentation.
The data coking device is responsible for the cleaning of abnormal flow, the centralized management and configuration of equipment, and the presentation of business reports.
The data collector and management server support distributed deployment and centralized deployment.Centralized deployment has good scalability.
Answer: A
The short version
A — The management center splits into management server and data collector. One presents and manages, the other gathers data.
Key concepts in this question
Management server: configuration, reporting, and centralized device control.
Data collector: collection, analysis, and storage of service and traffic data.
Deployment modes: centralized versus distributed placement of the two parts.
Why A is correct
The Huawei management center is structured as a management server plus a data collector, with the collector feeding summarized service data to the server for display. Option A states that two-part split correctly, while the alternatives swap cleaning duties or misstate scalability, so the banked answer A is retained.
Why the others are wrong
B. Cleaning of abnormal traffic belongs to the cleaning center, not the management server.
C. The data collector gathers and analyzes data; it does not scrub traffic or centrally configure devices.
D. Deployment modes are reversed: distributed deployment gives the better scalability, not centralized.
H12-722 exam tip
Split the roles cleanly: cleaning center scrubs, collector gathers, server shows and manages.
7The processing flow of IPS has the following steps;1. Reorganize application data2. Match the signature3. Message processing4. Protocol identificationWhich of the following is the correct order of the processing flow?
4-1-2-3
2-4-1-3
1-4-2-3
1-3-2-4
Answer: C
The short version
C — The IPS order is reassemble, identify protocol, match signature, then handle. Reassembly comes before reliable identification and matching.
Key concepts in this question
Application data reassembly: rebuilding fragmented streams so inspection sees the whole payload.
Protocol identification: determining the application protocol to select the right signatures.
Signature matching and message handling: detecting attacks then acting per policy.
Why C is correct
IPS must first reassemble application data, then identify the protocol on the complete stream, then match signatures, and finally process the message with allow, alarm, or block. That sequence is 1-4-2-3, exactly option C, so the banked answer is retained.
Why the others are wrong
A. Starting with protocol identification before reassembly risks misidentifying fragmented application data.
B. Matching signatures before reassembly and protocol identification means matching incomplete or misclassified data.
D. Handling the message before signature matching skips the detection decision entirely.
H12-722 exam tip
Chant the IPS pipeline reassemble, identify, match, act; only 1-4-2-3 keeps that order.
8The following commands are configured on the Huawei firewall:[USG] firewall defend ip-fragment enableWhich of the following situations will be recorded as an offensive behavior? (multiple choice)
DF, bit is down, and MF bit is also 1 or Fragment Offset is not 0,
DF bit is 023, MF bit is 1 or Fragment Offset is not 0,
The DF bit is 1, and Fragment Ofset + Length <65535.
DF bit is 0, and Fragment Offset + Length> 65535.
Answer: A, D
The short version
A and D — Contradictory DF settings and oversized fragment reassembly flag attacks. Both indicate malformed or hostile fragmentation.
Key concepts in this question
DF flag: do-not-fragment bit requesting no fragmentation of the packet.
MF flag and Fragment Offset: fields marking more fragments and each fragment position.
Fragment overlap and oversize: reassembly size beyond the IP limit signals teardrop or ping-of-death style abuse.
Why A and D are correct
A set DF combined with MF set or a nonzero offset is self-contradictory, since unfragmentable packets must not carry fragment markers, so A is an attack. Likewise a reassembly length above the maximum IP size cannot occur legitimately, so D is an attack. Together they are the two fragment anomalies the defense logs, and the banked answer is retained.
Why the others are wrong
B. This option is garbled and does not state a coherent DF and MF combination, so it cannot define an attack condition.
C. DF set with a normal small reassembly length is ordinary non-fragmented traffic, not an offense.
H12-722 exam tip
Treat DF plus any fragment marker as a lie, and any reassembly over the max as an overflow attack.
9Regarding the mail content filtering configuration of Huawei USG6000 products, which of the following statements is wrong?.
When an IMAP message is detected, if it is judged to be an illegal email; the firewall's response action only supports sending alarm messages and will not block the email.
Mail filtering will only take effect when the mail filtering configuration file is invoked when the security policy is allowed.
The attachment size limit is for a single attachment, not for the total size of all attachments.
When a POP3 message is detected, if it is judged to be an illegal email, the firewall's response action only supports sending alarm information, and will not block the email o
Answer: D
The short version
D — The wrong claim is that POP3 violations can only raise alarms. POP3 handling supports blocking responses, unlike the stated limitation.
Key concepts in this question
Mail filtering profile: content rules applied through the security policy on allowed traffic.
IMAP versus POP3 handling: protocol-dependent response actions for illegal mail.
Attachment size limit: per-attachment threshold rather than a total across all attachments.
Why D is correct
The question asks for the wrong statement, and option D misdescribes POP3 response actions by claiming alarm-only handling with no blocking. POP3 retrieval can be acted upon while IMAP detection is the alarm-oriented case, so D is the false description and the banked answer is retained.
Why the others are wrong
A. IMAP illegal-mail handling being alarm-oriented is a correct protocol limitation.
B. Mail filtering taking effect only when its profile is invoked by a permitting security policy is correct.
C. The attachment limit applying per single attachment rather than the aggregate total is correct.
H12-722 exam tip
For wrong-statement questions, anchor the true rules first: policy invocation, per-file limit, IMAP alarm-only; the odd one out is POP3.
10Regarding HTTP behavior, which of the following statements is wrong?
When the uploaded or downloaded file size, POST operation content size reaches the blocking threshold, the system will only block the uploaded or downloaded file, POST operate.
When the file upload operation is allowed, the alarm threshold and blocking threshold can be configured to control the size of the uploaded file.
HTTP POST is generally used to send information to the server through a web page, such as forum posting x form submission, username I password login.
When the size of the uploaded or downloaded file and the size of the content of the POST operation reach the alarm threshold, the system will generate log information to prompt the device management And block behavior.
Answer: A
The short version
A — The wrong claim is that breaching the block threshold only blocks the file. Reaching it blocks the behavior or connection, not just the object.
Key concepts in this question
Alarm versus blocking threshold: log at the lower limit, enforce at the higher limit.
Upload, download, and POST control: size limits on files and web-submitted content.
HTTP POST: client-to-server submission used for logins, posts, and form data.
Why A is correct
The question asks for the wrong statement. When upload, download, or POST size reaches the blocking threshold, the device blocks the action or connection per policy rather than merely dropping the file object while letting the operation continue. Option A understates that enforcement, so it is the false description and the banked answer is retained.
Why the others are wrong
B. Configurable alarm and blocking thresholds for permitted uploads is a correct control description.
C. POST carrying forum posts, form submissions, and login credentials to the server is correct.
D. Generating logs at the alarm threshold to warn administrators is a correct threshold behavior.
H12-722 exam tip
Separate warn from stop: alarm writes a log, block stops the behavior; only-block-the-file understates blocking.