Exam Code: H12-711 (Practice Exam Latest Test Questions VCE PDF)
Exam Name: HCNA-Security - CBSN (Constructing Basic Security Network)
Certification Provider: HUAWEI
Free Today! Guaranteed Training- Pass H12-711 Exam.
Also have H12-711 free dumps questions for you:
NEW QUESTION 1
Electronic evidence preservation is directly related to the legal effect of evidence, in line with the preservation of legal procedures, and its authenticity and reliability are guaranteed. Which of the following is not anevidence preservation technology?
- A. Encryption technology
- B. Digital certificate technology
- C. Digital signature technology
- D. Message tag tracking technology
Answer: D
NEW QUESTION 2
Whenconfiguring a GRE tunnel interface, the destination address generally refers to which of the following parameters?
- A. Local tunnel interface IP address
- B. Local end network export IP address
- C. Peer external network export IP address
- D. IP address of the peertunnel interface
Answer: C
NEW QUESTION 3
When the firewall hard disk is in place, which of the following is correct description for the firewall log?
- A. The administrator can advertise the content log to view the detection and defense records of network threats.
- B. The administrator can use the threat logto understand the user's security risk behavior and the reason for being alarmed or blocked.
- C. The administrator knows the user's behavior, the keywords explored, and the effectiveness of the audit policy configuration through the user activity log.
- D. The administrator can learn the security policy of the traffic hit through the policy hit lo
- E. And use it for fault location when the problem occurs.
Answer: D
NEW QUESTION 4
The configuration commands for the NAT address pool are as follows: nat address-group 1 section 0 202.202.168.10 202.202.168.20 mode no-pat Of which, the meaning of no-pat parameters is:
- A. Do not do address translation
- B. Perform port multiplexing
- C. Do not convert the source port
- D. Do not convert the destination port
Answer: C
NEW QUESTION 5
Which of the following belongs to Layer 2 VPN technology?
- A. SSL VPN
- B. L2TP VPN
- C. GRE VPN
- D. IPSec VPN
Answer: B
NEW QUESTION 6
Security policy conditions can be divided into multiple fields, such as source address, destination address, source port, destination port, etc. These fields are "and " , that is, only information in the message and all fields If you match, you can hit this strategy
- A. True
- B. False
Answer: B
NEW QUESTION 7
Which of the following statements are correct about Huawei routers and switches? (Multiple Choice)
- A. The router can implement some security functions, and some routers can implement more security functions by adding security boards.
- B. The main function of the router is to forward dat
- C. Sometimes the firewall may bea more suitable choice when the enterprise has security requirements.
- D. The switch has some security features, and some switches can implement more security functions by adding security boards.
- E. The switch does not have security features
Answer: ABC
NEW QUESTION 8
Which of the following types of attacksdoes the DDos attack belong to?
- A. Snooping scanning attack
- B. Malformed packet attack
- C. Special packet attack
- D. Traffic attack
Answer: D
NEW QUESTION 9
Which of the following is not the certificate save file format supported by the USG6000 series?
- A. PKCS#12
- B. DER
- C. PEM
- D. PKCS#
Answer: D
NEW QUESTION 10
The process of electronic forensics includes: protecting the site, obtaining evidence, preserving evidence,identifying evidence, analyzing evidence, tracking and presenting evidence
- A. True
- B. False
Answer: A
NEW QUESTION 11
Which of the following options is not the part of the quintet?
- A. Source IP
- B. Source MAC
- C. Destination IP
- D. Destination Port
Answer: B
NEW QUESTION 12
Which of the following are the main implementations of gateway anti-viru3? (Multiple choice)
- A. Agent scanning method
- B. Stream scanning method
- C. Package inspection method
- D. File killing method
Answer: AB
NEW QUESTION 13
Which of the following description is wrong about the operating system?
- A. The operating system is the interface between the user and the computer
- B. The operating system is responsible for managing the execution of all hardware resources and control software of the computer system.
- C. The interface between the operating system and the user is a graphical interface.
- D. The operating system itself is also a software
Answer: C
NEW QUESTION 14
IPSEC VPN technology does not support NAT traversal when encapsulated in ESP security protocol because ESP encrypts the packet header.
- A. True
- B. False
Answer: B
NEW QUESTION 15
Which of the following is true about the description of SSL VPN?
- A. Can beused without a client
- B. May encrypt to IP layer
- C. There is a NAT traversal problem
- D. No authentication required
Answer: A
NEW QUESTION 16
Which of the following is not a rating in the network security incident?
- A. Major network security incidents
- B. Special network security incidents
- C. General network security incidents
Answer: B
NEW QUESTION 17
After the firewall uses the hrp standby config enable command to enable the standby device configuration function, all the information that can be backed up can bedirectly configured on the standby device, and the configuration on the standby device can be synchronized to the active device.
- A. True
- B. False
Answer: A
NEW QUESTION 18
Which of the following iscorrect about firewall IPSec policy?
- A. By default, IPSec policy can control unicast packets and broadcast packets.
- B. By default, IPSec policy can control multicast.
- C. By defaul
- D. IPSec policy only controls unicast packets.
- E. By default, IPSec policy can control unicast packets, broadcast packets, and multicast packets °
Answer: C
NEW QUESTION 19
Which of the following is not the identity of the IPSec SA?
- A. spi
- B. Destination address
- C. Source address
- D. Security policy
Answer: C
NEW QUESTION 20
Which of thefollowing 3re the versions of the SNMP protocol? (Multiple choice)
- A. SNMPvl
- B. SNMPv2b
- C. SNMPv2c
- D. SNMPv3
Answer: ACD
NEW QUESTION 21
Which of the following operations are necessary during theadministrator upgrade of the USG firewall software version? (Multiple Choice)
- A. Upload the firewall version software
- B. Restart the device
- C. Device factory reset
- D. Specify the next time you start loading the software version.
Answer: ABD
NEW QUESTION 22
About thecontents of HRP standby configuration consistency check, which of the following is not included?
- A. NAT policy
- B. If the heartbeat interface with the same serial number configured
- C. Next hop and outbound interface of static route
- D. Certification strategy
Answer: C
NEW QUESTION 23
For the process of forwarding the first packet of the session between firewall domains,there are the following steps:
* 1. find the routing table
* 2. find inter-domain packet filtering rules
* 3. find the session table
* 4. find the blacklist
Which of the following is the correct order?
- A. 1->3->2->4
- B. 3->2->1->4
- C. 3->4->1->2
- D. 4->3->1->2
Answer: C
NEW QUESTION 24
Digital signature technology obtains a digital signature by encrypting which of the following data?
- A. User data
- B. Receiver public key
- C. sender public key
- D. Digital fingerprint
Answer: D
NEW QUESTION 25
Regarding the description of the vulnerability scanning, which of the following is wrong?
- A. Vulnerability scanning is a technology based on network remote monitoring of target network or host security performance vulnerability, which can be used for simulated attack experiments and security audits.
- B. Vulnerability scanning is used to detect whether there is a vulnerability in the target host system.Generally, the target host is scanned for specific vulnerabilities.
- C. Vulnerability scanning is a passive preventive measure that can effectively avoid hacker attacks.
- D. Vulnerability scanning can be done based onthe results of ping scan results and port scan
Answer: C
NEW QUESTION 26
IPSec VPN uses an asymmetric encryption algorithm to encrypt the transmitted data
- A. True
- B. False
Answer: B
NEW QUESTION 27
HRP (Huawei Redundancy Protocol) Protocol to backup the connection state of data include: (Multiple Choice)
- A. TCP/UDP sessions table
- B. Ser/er Map table
- C. the dynamic blacklist
- D. the routing table
Answer: ABC
NEW QUESTION 28
Which of the following options does not include the respondents in the questionnaire for safety assessment?
- A. Network System Administrator
- B. Security administrator
- C. HR
- D. Technical leader
Answer: C
NEW QUESTION 29
Which of the following statements is wrong about the firewall gateway's anti-virus response to the HTTP protocol?
- A. When the gateway device blocks the HTTP connection, push the web page to the client andgenerate a log.
- B. Response methods include announcement and blocking
- C. Alarm mode device only generates logs and sends them out without processing the files transmitted by the HTTP protocol.
- D. Blocking means that the device disconnects from the HTTP server and blocks file transfer.
Answer: B
NEW QUESTION 30
......
Thanks for reading the newest H12-711 exam dumps! We recommend you to try the PREMIUM Thedumpscentre.com H12-711 dumps in VCE and PDF here: https://www.thedumpscentre.com/H12-711-dumps/ (294 Q&As Dumps)