H12-711 Braindumps Real Exam Updated on Apr 04, 2022 with 290 Questions
Latest H12-711 PDF Dumps & Real Tests Free Updated Today
NEW QUESTION 22
Through display ike sa to see the result as follows, which statements are correct? (Multiple choice)
- A. The first stage ike sa has been successfully established
- B. ike is using version v2
- C. ike is using version v1
- D. The second stage ipsec sa has been successfully established
Answer: A,C
NEW QUESTION 23
Policy Center system can implement two dimensions' management functions: organizational management and regional management
- A. False
- B. True
Answer: B
NEW QUESTION 24
Regarding the relationship and role of VRRPA/GMP/HRP. which of the following statements are correct?(Multiple choice)
- A. HRP is responsible for data backup during hot standby operation
- B. VRRP is responsible for sending free ARP to direct traffic to the new primary device during active/standby switchover.
- C. VGMP group in the active state may include the VRRP group in the standby state.
- D. VGMP is responsible for monitoring equipment failures and controlling fast switching of equipment.
Answer: A,B,D
NEW QUESTION 25
Which of the following options does not include the respondents in the questionnaire for safety assessment?
- A. Security administrator
- B. Network System Administrator
- C. Technical leader
- D. HR
Answer: D
NEW QUESTION 26
Manual auditing is a supplement to tool evaluation. It does not require any software to be installed on the target system being evaluated, and has no effect on the operation and status of the target system.
Which of the following options does not include manual auditing?
- A. Manual inspection of the administrator's operation of the equipment process
- B. Manual inspection of the database
- C. Manual detection of the host operating system
- D. Manual inspection of network equipment
Answer: A
NEW QUESTION 27
Which of the following statements is wrong about VPN?
- A. VPN technology is a technology that multiplexes logica channels on actual physical lines.
- B. The generation of VPN technology enables employees on business trips toremotely access internal corporate servers.
- C. VPN technology necessarily involves encryption technology
- D. Virtual private network ischeaper than dedicated line
Answer: C
NEW QUESTION 28
Regarding the comparison between windows and Linux, which of the following statements is wrong?
- A. Getting started with Linux is more difficult and requires some learning and guidance.
- B. windows is open source, you can do what you want.
- C. Linux is open source code, you can do what you want.
- D. Windows can be compatible with most software playing most games
Answer: B
NEW QUESTION 29
In most scenarios, NAT Inbound is used to the enterprise private network users to access the Internet scenario.
- A. False
- B. True
Answer: A
NEW QUESTION 30
In the firewall, detect ftp command to set in which mode? (Choose two.)
- A. Domain Model
- B. Inter-Domain mode
- C. System Model
- D. Interface Mode
Answer: A,B
NEW QUESTION 31
As shown, when configuring the point-to-multipoint scenarios, the headquarters network segment is
10.1.1.0/24, the segment of branch 1 is 10.1.2.0/24, of branch 2 is 10.1.3.0/24.
About the protected data flow configuration which defined by headquarters and branch offices, which of the following combinations can be the full matched requirements?

- A. 1 2 4 6
- B. 3 4 5 6
- C. 1 2
- D. 1 2 3 5
Answer: D
NEW QUESTION 32
In o der to obtain evidence of crime, it is necessary to master the technology ofintrusion tracking Which of the following descriptions are correct about the tracking technology? (Multiple Choice)
- A. Packet Recording Technology marks packets on each passing router by inserting trace data into the tracked IP packets
- B. Packet tagging technology extracts information from attack sources by recording packets on the router and then using data drilling techniques
- C. Link test technology determines the source of the attack by testing the network link between the routers
- D. Snallow mail behavior analysis can analyze the information such as sending IF address, sending time, sending frequency, number of recipients, shallow email heacers and so on.
Answer: A,C,D
NEW QUESTION 33
In the USG series firewall, which of the following commands can be used to query the NAT translation result?
- A. display current nat
- B. display firewall session table
- C. display nat translation
- D. display firewall nat translation
Answer: B
NEW QUESTION 34
In SSL handshake protocol, what is the role of Server Key Exchange message?
- A. in the server key exchange message, it contains set of parameters required for completing key exchange
- B. in the server key exchange message, it contains the negotiated CipherSuite which is copied to the state of the current connection
- C. server key exchange message indicates that the server has finished sending all the information
- D. it contains an X.509 certificate in server key exchange message, the public key is contained in the certificate, which is issued to the client to verify signatures or to encrypt messages when key exchange
Answer: A
NEW QUESTION 35
Intrusion prevention system technical characteristics include (Multiple choice)
- A. Straight road deployment
- B. Self-learning and adaptive
- C. Real-time blocking
- D. Online mode
Answer: B,C,D
NEW QUESTION 36
Which of the following traffic matches the authentication policy triggers authentication?
- A. The first DNS packet corresponding to the HTTP service data flow
- B. Access device or device initiated traffic
- C. Traffic of visitors accessing HTTP services
- D. DHCP, BGP. OSPF and LDP packets
Answer: C
NEW QUESTION 37
Which of the following is the encryption technology used by digital envelopes?
- A. Asymmetric encryption algorithm
- B. Symmetric encryption algorithm
Answer: A
NEW QUESTION 38
As shown in the figure, a TCP connection is established between client A and server
B. Which of the following two "?" packet numbers should be?
- A. a+1: a
- B. b+1: b
- C. a+1: a+1
- D. a: a+1
Answer: C
NEW QUESTION 39
Which of the following is an action to be t3ken during the summary phase of the cyber security emergency response? (Multiple Choice)
- A. Evaluation of members of the emergency response organization
- B. Establish a defense system and specify control measures
- C. Determine the effectiveness nf the isnhtinn measures
- D. Evaluate the implementation of the contingency plan and propose a follow-up improvement plan
Answer: A,D
NEW QUESTION 40
ASPF (Application Specific Packet Filter) is a kind of packet filtering basedon the application layer, it checks the application layer protocol information and monitor the connection state of the application layer protocol.
ASPF by Server Map table achieves a special security mechanism. Which statement about ASPF and Server map table are correct? (Multiple choice)
- A. Quintupleserver-map entries achieve a similar functionality with session table
- B. ASPF monitors the packets in the process of communication
- C. ASPF through server map table realize dynamic to allow multi-channel protocol data to pass
- D. ASPF dynamically create and delete filtering rules
Answer: B,C,D
NEW QUESTION 41
Which of the following options are correct about the control actions permit and deny of the firewall interzone forwarding security policy? (Multiple Choice)
- A. The packet is matched immediately after the inter-domain security policy deny action, and the other interzone security policy will not be executed.
- B. The action of the firewall default security policy is deny.
- C. Whether the message matches the permit action of the security policy or the deny action, the message will be processed by the UTM module.
- D. Even if the packet matches the permit action of the security policy, it will not necessarily be forwarded by the firewall.
Answer: A,B,D
NEW QUESTION 42
Which of the following is not included in the steps of the safety assessment method?
- A. Questionnaire survey
- B. Manual audit
- C. Penetration test
- D. Data analysis
Answer: D
NEW QUESTION 43
Which of the following attacks does not belong to special packet attack?
- A. IP address scanning attack
- B. ICMP unreachable packet attack
- C. Large ICMP packet attack
- D. ICMP redirect packet attack
Answer: A
NEW QUESTION 44
What are the main security capability of encryption service? (Choose three.)
- A. Scalability
- B. Integrity
- C. Non-repudiation
- D. Confidentiality
Answer: B,C,D
NEW QUESTION 45
In Huawei SDSec solution, which layer of equipment does the firewall belong to?
- A. Control layer
- B. Executive layer
- C. Analysis layer
- D. Monitoring layer
Answer: B
NEW QUESTION 46
......
H12-711 Dumps With 100% Verified Q&As - Pass Guarantee or Full Refund: https://www.examdumpsvce.com/H12-711-valid-exam-dumps.html
Pass Huawei H12-711 Exam With Practice Test Questions Dumps Bundle: https://drive.google.com/open?id=1ehIPblQZGO3VWGP8fSgq07VNA-1MiZyB
