Get Special Discount Offer on H12-711_V3.0 Dumps PDF [UPDATED Nov-2022]
PDF Download Huawei Test To Gain Brilliante Result!
NEW QUESTION 91
Firewall in addition to supporting built-inPortalIn addition to authentication, it also supports customizationPortalauthentication, when using customPortalDuring authentication, there is no need to deploy externalPortalserver.
- A. True
- B. False
Answer: B
NEW QUESTION 92
TCSECWhich of the following protection levels are included in the standard? (multiple choice)
- A. Mandatory protection level
- B. Passive protection level
- C. autonomous protection level
- D. Verify protection level
Answer: A,C,D
NEW QUESTION 93
ASPF (Application specific Packet Filter) is a packet filtering technology based on the application layer and implements a special security mechanism through the server-map table. Regarding ASPF and server-map tables, which of the following are correct? (Multiple choice)
- A. ASPF can dynamically create server-map
- B. ASPF dynamically allows multi-channel protocol data to pass through the server-map table
- C. The five-tuple server-map table entry implements a function similar to the session table
- D. ASPF monitors the packets in the communication process
Answer: A,B,D
NEW QUESTION 94
Regarding the description of the intrusion detection system, which of the following is wrong?
- A. Intrusion detection system includes all software and hardware systems used for intrusion detection
- B. The immersion detection system can be linked with firewalls and switches, becoming a powerful "assistant" of the firewall, and better and more precise control of traffic access between domains
- C. Once the intrusion detection system finds any behavior that violates the security policy or the system has traces of being attacked, it can implement blocking operations
- D. The intrusion detection system can dynamically collect a large amount of key information through the network and computer, and can analyze and judge the current state of the entire system environment in time
Answer: C
NEW QUESTION 95
Which of the following protocols cannot be encrypted by SSL VPN?
- A. IP
- B. PPP
- C. UDP
- D. HTTP
Answer: B
NEW QUESTION 96
The trigger authentication method for firewall access user authentication does not include which of the following? ( )[Multiple choice]*
- A. MPLS VPN
- B. L2TP VPN
- C. IPSec VPN
- D. SSL VPN
Answer: A
NEW QUESTION 97
Which of the following is an action to be taken during the summary phase of a cybersecurity emergency response? (multiple choice)
- A. Establish a defense system and specify control measures
- B. Judging the effectiveness of isolation measures
- C. Evaluate members of emergency response organizations
- D. Evaluate the implementation of emergency plans and propose follow-up improvement plans
Answer: C,D
NEW QUESTION 98
In the process of using the server, there are various security threats. Which of the following options is not a server security threat?
- A. Natural disasters
- B. DDos attack
- C. Malicious program
- D. Hacking
Answer: A
NEW QUESTION 99
In practical applications, asymmetric encryption is mainly used to encrypt user data.
- A. True
- B. False
Answer: B
NEW QUESTION 100
As shown in the figure, nat server global202.106.1.1 inside10.10.1.1 is configured on the firewall. Which of the following is the correct configuration for interzone rules? ( )[Multiple choice]*
- A. rule name c. source-zone untrust. destination-zone trust. destination-address 202.106.1.132, action permit
- B. rule name b, source-zone untrust, destination-zone trust, source-address202.106.l.1 32, action permit
- C. rule name b, source- zone untrust, destination- zone trust, source- address10.10.1.1 32, action permit
- D. rule name d, source- zone untrust. destination- zone trust. destination- address10.l0.1.1 32, action permit
Answer: D
NEW QUESTION 101
The attacker sendsICMPAnswer the request and set the destination address of the request packet as the broadcast address of the victim network. What kind of attack is this behavior?
- A. SYN floodattack
- B. Smurfattack
- C. IPspoofing attack
- D. ICMPredirect attack
Answer: B
NEW QUESTION 102
According to the number of users operating at the same time, the operating system can be divided into single-user operating system and multi-user operating system. Which of the following items is not a multi-user operating system?
- A. OS/2
- B. UNIX
- C. Linux
- D. MSDOS
Answer: A,D
NEW QUESTION 103
When the firewall upgrades the signature database and virus database online through the security service center, the firewall must first be able to connect to the Internet, and secondly, the correct DNS address must be configured.
- A. False
- B. True
Answer: B
NEW QUESTION 104
Which of the following options belong to the same characteristics of windows system and LINUX system? (Multiple choice)
- A. Support multitasking
- B. Support graphical interface operation
- C. Support multiple terminal platforms
- D. Open-source system
Answer: A,B,C
NEW QUESTION 105
existClient-Initiated VPNDuring the configuration, it is generally recommended to plan the address pool and the headquarters network address as different network segments. Otherwise, the proxy forwarding function needs to be enabled on the gateway device.
- A. True
- B. False
Answer: B
NEW QUESTION 106
The SSL VPN routing mode determines the routing of the packets sent by the client. In the ______ mode, no matter what resource is accessed, the data will be intercepted by the virtual network card and forwarded to the virtual gateway for processing.[fill in the blank]*
Answer:
Explanation:
network extension
NEW QUESTION 107
Which of the following is an encryption technique used in digital envelopes?
- A. Symmetric encryption algorithm
- B. Stream Encryption Algorithm
- C. Asymmetric encryption algorithm
- D. hash algorithm
Answer: A,C
NEW QUESTION 108
Which of the following options are malicious programs? (Multiple choice)
- A. Worms
- B. Trojan Horse
- C. Viruses
- D. Vulnerabilities
Answer: A,B,C
NEW QUESTION 109
The repair of anti-virus software only needs to repair some system files that were accidentally deleted when scanning and killing viruses to prevent the system from crashing
- A. False
- B. True
Answer: B
NEW QUESTION 110
Which of the following attacks is not a malformed packet attack?
- A. Smurfattack
- B. ICMPUnreachable Packet Attack
- C. Teardropattack
- D. TCPFragmentation attack
Answer: B
NEW QUESTION 111
Network administrators can collect data that needs to be analyzed on network devices through packet capture, port mirroring or logs.
- A. False
- B. True
Answer: B
NEW QUESTION 112
At this stage, we have mastered three source NAT technologies, namely NAT No-PAT and ______ Easy IP.
- A. NATP
Answer: A
NEW QUESTION 113
Which of the following attacks can DHCP Snooping prevent? (Multiple choice)
- A. Fake DHCP lease renewal packet attack using option82 field
- B. middleman and IP/MAC spoofing attacks
- C. DHCP Server counterfeit attack
- D. IP spoofing attack
Answer: A,B,C
NEW QUESTION 114
aboutNATConfiguration statement, which of the following is false?
- A. in the networkVoIPWhen doing business, no configuration is requiredNATALG
- B. Configure sources in transparent modeNAT, the firewall does not supporteasy-ipWay
- C. Firewall does not supportESPandAHmessageNAPTconvert
- D. in the address poolIPaddress can beNATserverpublic networkIPaddress overlap
Answer: C
NEW QUESTION 115
Regarding the actions of the security policy and the description of the security configuration file, which of the following options are correct? (Multiple choice)
- A. If the security policy action is "Allow", the traffic will not match the security profile
- B. Prohibited If the action of the security policy is "prohibited", the device will discard this traffic, and no further content security checks will be performed
- C. The security configuration file must be applied to the security policy whose action is allowed to take effect.
- D. The security configuration file can take effect without being applied to the security policy where the action is allowed
Answer: B,C
NEW QUESTION 116
......
H12-711_V3.0 Dumps are Available for Instant Access: https://www.actual4cert.com/H12-711_V3.0-real-questions.html