[Dec-2023] Pass Huawei H12-711 Tests Engine pdf - All Free Dumps [Q152-Q175]

Share

[Dec-2023] Pass Huawei H12-711 Tests Engine pdf - All Free Dumps

HCIA-Security V3.0 Practice Tests 2023 | Pass H12-711 with confidence!

NEW QUESTION # 152
When the IPSec VPN tunnel mode is deployed, the AH protocol is used for packet encapsulation. In the new IP packet header field, which of the following parameters does not require data integrity check?

  • A. Source IP address
  • B. Destination IP address
  • C. TTL
  • D. Idetification

Answer: C


NEW QUESTION # 153
In the USG system firewall, the________function can be used to provide well-known applica'.ionservices for non-known ports.

  • A. Port mapping
  • B. Packet filtering
  • C. Long connection
  • D. MAC and IP address binding

Answer: A


NEW QUESTION # 154
Which VPN access modes are suitable for mobile office workers? (Choose three.)

  • A. SSL VPN
  • B. L2TP VPN
  • C. L2TP over IPsec
  • D. GRE VPN

Answer: A,B,C


NEW QUESTION # 155
Which of the following is the GRE protocol number?

  • A. 0
  • B. 1
  • C. 2
  • D. 3

Answer: A


NEW QUESTION # 156
The host firewall is mainly used to protect the host from attacks and intrusions from the network

  • A. False
  • B. True

Answer: B


NEW QUESTION # 157
Which of the following attacks is not a cyber-attack?

  • A. IP spoofing attack
  • B. Smurf attack
  • C. ICMP attack
  • D. MAC address spoofing attack

Answer: D


NEW QUESTION # 158
About the description of firewall active-standby, which of the following is correct?(Multiple Choice)

  • A. The firewall active-standby requires the information such as the session table. MAC table, routing table and so on synchronous backup between primary devices and slave devices.
  • B. When a plurality of regions on the firewall needs to provide dual-machine backup function, you need to configure multiple VRRP backup groups on the firewall.
  • C. VGMP is to ensureall VRRP backup groups' consistency of switching
  • D. It requires the state of all the VRRP backup groups in the same VGMP management group on the same firewall should be consistent.

Answer: B,C,D


NEW QUESTION # 159
Which of the following options does not belong to the log type of the Windows operating system?

  • A. Business log
  • B. System log
  • C. Application log
  • D. Security log

Answer: A


NEW QUESTION # 160
Based on the GRE encapsulation and de-encapsulation, which description is error?

  • A. Encapsulation Process: After GRE module packaging, the data packet will enter the IP module for further processing
  • B. Encapsulation Process: The original data packetstransmit the data packets through looking up routing to the Tunnel interface to trigger GRE encapsulation.
  • C. De-encapsulation Process: After the destination receives GRE packets, transmitting the data packets through looking up the routing to the Tunnel interfaces to trigger GRE encapsulation.
  • D. De-encapsulation Process: After GRE module de-encapsulation, the data packets will enter the IPmodule for further processing.

Answer: C


NEW QUESTION # 161
Which of the following is wrong about the scanning of vulnerabilities?

  • A. Vulnerabilities are security risks that can expose computers to hackers
  • B. The vulnerability was discovered beforehand and discovered afterwards
  • C. Vulnerabilities are generally repairable
  • D. Vulnerabilities can be avoided

Answer: D


NEW QUESTION # 162
In the classification of the information security level protection system, which of the following levels defines the damage to the social order and the public interest if the information system is destroyed? (Multiple choice)

  • A. Fourth level Structured protection
  • B. First level User-independent protection level
  • C. Second level System audit protection level
  • D. Third level Security mark protection

Answer: A,B,C,D


NEW QUESTION # 163
Which of the following is true about the description of the TCP/IP protocol stack packet encapsulation?
(Multiple choice)

  • A. The data packet is firsttransmitted to the data link layer. After parsing, the data link layer information is stripped, and the network layer information is known according to the parsing information, such as IP.
  • B. After the application layer receives the data packet, the application layer information is stripped after parsing, and the user data displayed at the end is exactly the same as the data sent by the sender host.
  • C. After the transport layer (TCP) receives the data packet, the transport layer information is stripped after parsing, and the upper layer processing protocol, such as UDP, is known according to the parsing information
  • D. After receiving the data packet, the network layer is stripped after parsing, and the upper layer processing protocol is known according to the parsing information, such as HTTP

Answer: A,B


NEW QUESTION # 164
Which of the following options are correct about the control actions permit and deny of the firewall interzone forwarding security policy? (Multiple Choice)

  • A. The action of the firewall default security policy is deny.
  • B. The packet is matched immediately after the inter-domain security policy deny action, and the other interzone security policy will not be executed.
  • C. Even if the packet matches the permit action of the security policy, it will not necessarily be forwarded by the firewall.
  • D. Whether the message matches the permit action of the security policy or the deny action, the message will be processed by the UTM module.

Answer: A,B,C


NEW QUESTION # 165
Which of the following descriptions of the firewall fragment cache function are correct? (Multiple choice)

  • A. After the fragmented packet is directly forwarded, the firewall forwards the fragment according to the interzone security policy if it is not the fragmented packet of the first packet.
  • B. For fragmented packets, NAT ALG does not support the processing of SIP fragmen:ed packets.
  • C. By default, the number of largefragment caches of an IPV4 packet is 32, and the number of large fragmentation buffers of an IPV6 packet is 255
  • D. By default, the firewall caches fragmented packets.

Answer: B,C,D


NEW QUESTION # 166
When configuring security policy, a security policy can reference an address set or configure multiple destination IP addresses.

  • A. False
  • B. True

Answer: B


NEW QUESTION # 167
In SSL handshake protocol, what is the role of Server Key Exchange message?

  • A. in the server key exchange message, it contains the negotiated CipherSuite which is copied to the state of the current connection
  • B. it contains an X.509 certificate in server key exchange message, the public key is contained in the certificate, which is issued to the client to verify signatures or to encrypt messages when key exchange
  • C. server key exchange message indicates that the server has finished sending all the information
  • D. in the server key exchange message, it contains set of parameters required for completing key exchange

Answer: D


NEW QUESTION # 168
In the SSL handshake protocol, which of the following message is optional? (Choose two.)

  • A. Certificate verify
  • B. Server Key Exchange
  • C. ServerHelloDone
  • D. ChangeCipherSpec

Answer: A,B

Explanation:
Explanation/Reference:


NEW QUESTION # 169
When the user single sign-on is configured, the receiving PC message mode is adopted. The authentication process has the following steps: 1 The visitor PC executes the login script and sends the user login information to the AD monitor. 2 The firewall extracts the correspondence between the user and the IP from the login information. Add to the online user table 3 AD monitor connects to the AD server to query the login user information, and forwards the queried user information to the firewall. 4 The visitor logs in to the AD domain. The AD server returns the login success message to the user and delivers the login script. which of the following order is correct?

  • A. 4-1-3-2
  • B. 1-2-3-4
  • C. 3-2-1-4
  • D. 1-4-3-2

Answer: A


NEW QUESTION # 170
Which of the following option belongs to DES key length?

  • A. 0
  • B. 1
  • C. 2
  • D. 3

Answer: A


NEW QUESTION # 171
When the following conditions occur in the VGMP group, the VGMPmessage will not be sent to the peer end actively?

  • A. Manually switch the active and standby status of the firewall.
  • B. Firewall service interface failure
  • C. Dual hot backup function enabled
  • D. Session table entry changes

Answer: D


NEW QUESTION # 172
Which of the following are remote authentication methods? (Multiple choice)

  • A. HWTACACS
  • B. Local
  • C. LLDP
  • D. RADIUS

Answer: A,D


NEW QUESTION # 173
Which of the following is not a key technology for anti-virus software?

  • A. Format the disk
  • B. Real-time upgrade ofthe virus database
  • C. Shelling technology
  • D. Self-protection

Answer: A


NEW QUESTION # 174
Which of the following traffic matches the authentication policy triggers authentication?

  • A. Traffic of visitors accessing HTTP services
  • B. The first DNS packet corresponding to the HTTP service data flow
  • C. Access device or device initiated traffic
  • D. DHCP, BGP. OSPF and LDP packets

Answer: A


NEW QUESTION # 175
......

Online Exam Practice Tests with detailed explanations!: https://exampasspdf.testkingit.com/Huawei/latest-H12-711-exam-dumps.html