FAQ
This topic answers frequently asked questions about Security Center.
What's new
Pre-sales questions
Free trial questions
Purchase questions
Product usage questions
Other questions
Purchase and renewal questions
Renewal questions
Upgrade and downgrade questions
Refund questions
Vulnerability fixing billing
Console operation issues
If you encounter one of the following errors in the Security Center console, refresh the page and try again. If the error persists, contact technical support.
Error code | Note |
ConsoleSystemError_1001 | A system error occurred. Please refresh the page and try again later. |
ConsoleSystemError_1007 | This API is no longer available. |
ConsoleSystemError_1008 | PostOnly validation failed. |
ConsoleSystemError_1009 | CSRF token is empty. Please refresh the page and try again. |
ConsoleSystemError_1010 | CSRF token validation failed. Please check the token and try again. |
ConsoleSystemError_1011 | RegionID is empty. Please enter a RegionID. |
ConsoleSystemError_1012 | Invalid RegionID format. Please check the RegionID. |
ConsoleSystemError_1013 | A parameter is empty. Please check your parameters. |
ConsoleSystemError_1014 | Invalid parameter format. Please check your parameters. |
Security score questions
How do I view the version of the virus library of Security Center?
What are the priorities to handle security events that I can access in the Secure Score section?
How does the vulnerability scan level affect the security score?
How does the baseline check level affect the security score?
Asset questions
How do I unbind a server that is not deployed on Alibaba Cloud?
How do I unbind an Elastic Compute Service (ECS) instance from Security Center?
Anti-ransomware questions
What is the anti-ransomware feature? Why is it charged separately?
Do backups start automatically after purchasing anti-ransomware capacity?
How do I view my purchased anti-ransomware capacity and its usage?
How do I clear a large anti-ransomware backup cache that occupies disk space?
Can I change the backup cache location if it uses too much C drive space?
What should I do if the anti-ransomware client consumes excessive CPU or memory resources?
What are the differences between the anti-ransomware solution and snapshot backups?
What should I do if the purchased anti-ransomware capacity is insufficient?
What should I do if a protection policy is in an abnormal state?
Why do .aeqis, .zaegis, or !aegis folders still exist on my server after I disable anti-ransomware?
Does the anti-ransomware service guarantee compensation for ransomware infections?
Is anti-ransomware protection necessary for internal network servers without public network access?
How do I confirm whether a server has been targeted by ransomware when no alerts are generated?
I purchased the anti-ransomware service but haven't used it. Can I request a deferral or refund?
Web tamper proofing questions
Can the validity period of the Security Center edition differ from that of file tamper protection?
What are the requirements for the file tamper protection local backup directory?
Why does configuring a tamper protection directory prompt a path error?
Why does file tamper protection fail after configuring a protection directory?
Can I still write files to a directory after configuring it for protection?
What should I do if tamper protection does not take effect immediately after configuration?
What should I do if I cannot modify website content and images after configuring tamper protection?
Why does the number of tamper protection alerts in the console differ from email notifications?
Does the absence of tamper protection alerts mean the files are safe?
Are tamper protection rules automatically generated after a version upgrade?
Linux software vulnerabilities
Does Security Center support Ubuntu 24.04? How do I manually scan for vulnerabilities?
How do I determine if my Linux kernel version is affected by a specific CVE?
Security Center still reports a kernel vulnerability after an upgrade. What should I do?
What should I do if I get a kernel incompatibility notification when fixing a kernel vulnerability?
How do I handle a timeout when connecting to the Alibaba Cloud Yum source?
Vulnerability fixing
Do I need to restart the server after fixing a vulnerability? What is the impact on business?
What are the risks of not fixing high-risk vulnerabilities (such as Linux Kernel ptrace)?
If a vulnerability fix fails and I click Fix again, am I charged twice?
Does an urgent vulnerability with an Unprotected or Protected status need attention?
Do I need to restart the system after fixing a vulnerability?
Does Security Center support generating and exporting vulnerability scan reports?
How do I determine if my Linux kernel version is affected by a specific CVE?
What is the execution order and concurrency advice for batch vulnerability fixing?
Does Security Center support vulnerability fixing for servers without public IP addresses?
What are the considerations for enabling automatic vulnerability fixing?
What should I do if batch vulnerability fixing shows "no matching records" or an empty list?
What should I do if vulnerability fixing on an ACK cluster is slow or inefficient?
How do I disable automatic vulnerability fixing to avoid extra charges?
Security Center still reports a kernel vulnerability after an upgrade. What should I do?
What should I do if I get a kernel incompatibility notification when fixing a kernel vulnerability?
What should I do if a vulnerability shows no available updates?
How do I view the failure notification after a vulnerability fix fails?
Does manually fixing a vulnerability cause Security Center to generate false positive attack alerts?
What does it mean when a vulnerability is marked as fixed with the reason "Rule Removed"?
Vulnerability detection
Where can I find the latest vulnerability rule classification after rule adjustments?
Does Security Center support Ubuntu 24.04? How do I manually scan for vulnerabilities?
Why isn't an urgent vulnerability included in the "High-priority Vulnerabilities (CVE)" list?
How do I stop automatic scanning for Emergency Vulnerability?
Why does an inactive instance still show high-risk vulnerability alerts?
Does a new scan use or restore historical vulnerability data?
Why don't application vulnerability detection results show specific file paths?
Do Security Center vulnerability scan results overwrite historical data?
Why does a newly purchased ECS instance already have vulnerabilities?
Why do two servers show a significantly different number of vulnerabilities?
Why am I notified that an unfixed high-risk system vulnerability was found?
After connecting a new instance, why is there no data in Vulnerabilities or security alerts?
Baseline checks
Security alerts
How do I determine whether an asset is threatened by crypto-mining?
Virus interception is not enabled and my server is under a crypto-mining attack. What do I do?
I accidentally added a crypto-mining alert to the whitelist. How do I remove it?
How do I verify that automatic virus interception is in effect?
What objects can be added to the whitelist for security alerts?
Brute-force attacks
How do I view the number of brute-force attacks or interception status on my server?
Does brute-force prevention support protecting web applications or websites?
Why do I still receive password brute-force alerts after changing a weak password?
Does ECS logon weak password refer to system-level RDP or SSH scanning?