[Q107-Q132] Huawei H12-711-ENU Practice Verified Answers - Pass Your Exams For Sure! [2021]

Share

Huawei H12-711-ENU Practice Verified Answers - Pass Your Exams For Sure! [2021]

Valid Way To Pass HCNA-Security's  H12-711-ENU Exam

NEW QUESTION 107
Regarding SSL VPN technology, which of the following options is wrong?

  • A. SSL VPN technology can be perfectly applied to NAT traversal scenarios
  • B. SSL VPN technology extends the network scope of the enterprise
  • C. SSL VPN requires a dial-up client
  • D. SSL VPN technology encryption only takes effect on the application layer

Answer: C

 

NEW QUESTION 108
The host firewall is mainly used to protect the host from attacks and intrusions from the network.

  • A. True
  • B. False

Answer: A

 

NEW QUESTION 109
In practical applications, asymmetric encryption is mainly used to encrypt user data.

  • A. False
  • B. True

Answer: A

 

NEW QUESTION 110
Which of the following attacks can DHCP Snooping prevent? (Multiple Choice)

  • A. IP spoofing attack
  • B. DHCP Server counterfeiter attack
  • C. Intermediaries and IP/MAC spoofing attacks
  • D. Counterfeit DHCP lease renewal packet attack using option82 field

Answer: A,B,C,D

 

NEW QUESTION 111
Which of the following statement about the NAT is wrong?

  • A. Address Translation can follow the needs of users, providing FTP, WWW, Telnet and other services outside the LAN
  • B. Some application layer protocols carry IP address information in the data, but also modify the IP address information in the data of the upper layer when they are as NAT
  • C. NAT technology can effectively hide the hosts of the LAN, it is an effective network security protection technology
  • D. For some non-TCP, UDP protocols (such as ICMP, PPTP), unable to do the NAT translation

Answer: D

 

NEW QUESTION 112
The Huawei Redundancy Protocol (HRP) is used to synchronize the main firewall configuration and connection status and other data on the backup firewall to synchronize . Which of the following options is not in the scope of synchronization?

  • A. Blacklist
  • B. NAT policy
  • C. IPS signature set
  • D. Security policy

Answer: C

 

NEW QUESTION 113
Which of the following statements is wrong about VPN?

  • A. VPN technology necessarily involves encryption technology
  • B. VPN technology is a technology that multiplexes logical channels on actual physical lines.
  • C. Virtual private network is cheaper than dedicated line
  • D. The generation of VPN technology enables employees on business trips to remotely access internal corporate servers.

Answer: A

 

NEW QUESTION 114
In IPSEC VPN, which of the following scenarios can be applied by tunnel mode?

  • A. between hosts and security gateways
  • B. Between tunnel mode and transport mode
  • C. between security gateways
  • D. between the host and the host

Answer: C

 

NEW QUESTION 115
Which of the following is not included in the Corporate Impact Analysis (BIA)?

  • A. Accident handling priority
  • B. Impact assessment
  • C. Business priority
  • D. Risk identification

Answer: B

 

NEW QUESTION 116
Which of the following description is wrong about the operating system?

  • A. The operating system is responsible for managing the execution of all hardware resources and control software of the computer system.
  • B. The operating system itself is also a software
  • C. The operating system is the interface between the user and the computer
  • D. The interface between the operating system and the user is a graphical interface.

Answer: D

 

NEW QUESTION 117
Manual auditing is a supplement to tool evaluation. It does not require any software to be installed on the target system being evaluated, and has no effect on the operation and status of the target system.
Which of the following options does not include manual auditing?

  • A. Manual inspection of the database
  • B. Manual inspection of network equipment
  • C. Manual detection of the host operating system
  • D. Manual inspection of the administrator's operation of the equipment process

Answer: D

 

NEW QUESTION 118
Which of the following does not belong to the user authentication method in the USG firewall?

  • A. Password authentication
  • B. Free certification
  • C. Single sign-on
  • D. Fingerprint authentication

Answer: D

 

NEW QUESTION 119
When configuring NAT Server on the USG series firewall, the server-map table will be generated. Which of the following does not belong in the table?

  • A. Destination IP
  • B. Source IP
  • C. Agreement number
  • D. Destination port number

Answer: B

 

NEW QUESTION 120
In the IPSec VPN transmission mode, which part of the data packet is encrypted?

  • A. New IP packet header
  • B. Transport layer and upper layer data packet
  • C. Network layer and upper layer data packet
  • D. Original IP packet header

Answer: B

 

NEW QUESTION 121
Which of the following statements are correct about the differences between pre-accident prevention strategies and post-accident recovery strategies? (Multiple Choice)

  • A. The role of pre-disaster prevention strategies does not include minimizing economic, reputational, and other losses caused by accidents.
  • B. Recovery strategy is used to improve business high availability
  • C. Recovery strategy is part of the business continuity plan
  • D. The prevention strategy focuses on minimizing the likelihood of an accident before the story occurs. The recovery strategy focuses on minimizing the impact and loss on the company after the accident

Answer: B,C,D

 

NEW QUESTION 122
Which of the following are the necessary configurations of IPSec VPN? (Multiple Choice)

  • A. Configure IKE SA related parameters
  • B. Configure the stream of interest
  • C. Configuring IPSec SA related parameters
  • D. Configuring IKE neighbors

Answer: A,B,C,D

 

NEW QUESTION 123
In the USG series firewall, you can use the ______ function to provide well-known application services for non-known ports.

  • A. Port mapping
  • B. MAC and IP address binding
  • C. Long connection
  • D. Packet filtering

Answer: A

 

NEW QUESTION 124
When Firewall does dual-system hot backup networking, in order to achieve the overall status of the backup group switching, which of the following protocol technology need to be used?

  • A. VGMP
  • B. HRP
  • C. OSPF
  • D. VRRP

Answer: A

 

NEW QUESTION 125
Evidence identification needs to resolve the integrity verification of the evidence and determine whether it meets the applicable standards. Which of the following statements is correct about the standard of evidence identification?

  • A. Objective standard means that the acquisition, storage, and submission of electronic evidence should be legal, and the basic rights such as national interests, social welfare, and personal privacy are not strictly violated.
  • B. Relevance criterion means that if the electronic evidence can have a substantial impact on the facts of the case to a certain extent, the court should determine that it is relevant.
  • C. Legality standard is to ensure that the electronic evidence is collected from the initial collection, and there is no change in the content of the evidence submitted as evidence.
  • D. Fairness standard refers to the evidence obtained by the legal subject through legal means, which has the evidence ability.

Answer: B

 

NEW QUESTION 126
Which of the following options can be used in the advanced settings of Windows Firewall? (Multiple choice)

  • A. Set connection security rules
  • B. Change notification rules
  • C. Restore defaults
  • D. Set out inbound rules

Answer: A,B,C,D

 

NEW QUESTION 127
The administrator wants to know the current session table. Which of the following commands is correct?

  • A. display firewall session table
  • B. reset firewall session table
  • C. clear firewall session table
  • D. display session table

Answer: B

 

NEW QUESTION 128
Which of the following is not a key technology for anti-virus software?

  • A. Shelling technology
  • B. Self-protection
  • C. Real-time upgrade of the virus database
  • D. Format the disk

Answer: D

 

NEW QUESTION 129
Fire Trust domain FTP client wants to access an Untrust server FTP service has allowed the client to access the server TCP 21 port, the client in the Windows command line window can log into the FTP server, but can not download the file, what are the following solutions? (Multiple choice)

  • A. Trust Untrust domain configuration is enabled detect ftp
  • B. FTP works with Passive mode modify the domain inbound direction between the Untrust Trust default access policy to allow
  • C. the FTP works with the port mode modify the Untrust Trust domain to allow the inbound direction between the default access strategy
  • D. take the Trust between Untrust domain to allow two-way default access strategy

Answer: A,C,D

 

NEW QUESTION 130
Which of the following statements is wrong about the firewall gateway's anti-virus response to the HTTP protocol?

  • A. Alarm mode device only generates logs and sends them out without processing the files transmitted by the HTTP protocol.
  • B. Response methods include announcement and blocking
  • C. Blocking means that the device disconnects from the HTTP server and blocks file transfer.
  • D. When the gateway device blocks the HTTP connection, push the web page to the client and generate a log.

Answer: B

 

NEW QUESTION 131
The European TCSEC Code is divided into two modules, Function and Evaluation, which are mainly used in the military, government and commercial fields.

  • A. True
  • B. False

Answer: A

 

NEW QUESTION 132
......

Huawei H12-711-ENU Pre-Exam Practice Tests | ExamCost: https://www.examcost.com/H12-711-ENU-practice-exam.html