nerdexam
Huawei

H12-725_V4.0 · Question #42

Malicious URLs refer to URLs that contain malicious information. Which of the following is not the source of malicious URLs?

The correct answer is B. Malicious URLs reported by the intrusion prevention function. Option B is correct because intrusion prevention (IPS) focuses on detecting and blocking network-based exploit traffic using signature matching against attack patterns - it is not a source that generates or reports malicious URL intelligence. Sandboxes (A) actively execute and…

Advanced Security Features

Question

Malicious URLs refer to URLs that contain malicious information. Which of the following is not the source of malicious URLs?

Options

  • AMalicious URLs reported by the sandbox
  • BMalicious URLs reported by the intrusion prevention function
  • CURLs included in local reputation
  • DMalicious URLs reported by the anti-virus function

How the community answered

(39 responses)
  • A
    8% (3)
  • B
    74% (29)
  • C
    15% (6)
  • D
    3% (1)

Explanation

Option B is correct because intrusion prevention (IPS) focuses on detecting and blocking network-based exploit traffic using signature matching against attack patterns - it is not a source that generates or reports malicious URL intelligence. Sandboxes (A) actively execute and analyze suspicious URLs in an isolated environment, making them a direct source of malicious URL discovery. Local reputation (C) is a built-in database of known-bad URLs stored on the device, which is a foundational source by definition. Anti-virus functions (D) scan content for malware and can identify malicious URLs embedded in files or web traffic, contributing them to threat intelligence.

Memory tip: Think of URL sources as things that discover bad URLs - sandboxes test them, AV detects them in files, and reputation databases catalog them. IPS is a blocker, not a reporter - it reacts to attack signatures in network sessions, not URLs specifically.

Topics

#malicious URLs#URL filtering#sandbox#threat intelligence

Community Discussion

No community discussion yet for this question.

Full H12-725_V4.0 Practice