Updated Oct-2023 Exam Engine for H12-711 Exam Free Demo & 365 Day Updates [Q11-Q32]

Share

Updated Oct-2023 Exam Engine for H12-711 Exam Free Demo & 365 Day Updates

Exam Passing Guarantee H12-711 Exam with Accurate Quastions!

NEW QUESTION # 11
The single-point login function of the online user, the user authenticates directly to the AD server, and the device does not interfere with the user authentication process. The AD monitoring service needs to be deployed on the USG device to mcnitorthe authentication information of the AD server.

  • A. False
  • B. True

Answer: A


NEW QUESTION # 12
Which of the following traffic matches the authentication policy triggers authentication?

  • A. The first DNS packet corresponding to the HTTP service data flow
  • B. Traffic of visitors accessing HTTP services
  • C. Access device or device initiated traffic
  • D. DHCP, BGP. OSPF and LDP packets

Answer: B


NEW QUESTION # 13
Which of the following descriptions about the action and security profile of the security policy are correct? (Multiple choice)

  • A. If the action of the security policy is "prohibited", the device will discard this traffic, and then no content security check will be performed.
  • B. The security profile may not be applied to the security policy that the action is allowed and take effect.
  • C. If the security policy action is "Allow", the traffic will not match the security profile.
  • D. The security profile must be applied to the security policy that is allowed to take effect.

Answer: A,D


NEW QUESTION # 14
What is the difference between network address porttranslation (NAT) and conversion-only network address (No- PAT)? (Multiple Choice)

  • A. After NATP conversion, for external network users, all messages are from the same IP address or several IP addresses.
  • B. No-PAT only supports protocol address translationat the application layer.
  • C. No-PAT supports protocol address translation at the network layer
  • D. NAPT only supports protocol address translation at the network layer.

Answer: A,C


NEW QUESTION # 15
After the network intrusion event occurs,according to the plan to obtain the identity of the intrusion, the attack source and other information, and block the intrusion behavior, which links of the above actions are involved in the PDRR network security model? (Multiple Choice)

  • A. Testing link
  • B. Protection link
  • C. Response link
  • D. Recovery link

Answer: A,C


NEW QUESTION # 16
IPSEC VPN technology does not support NAT traversal when encapsulated in ESP security protocol because ESP encrypts the packet header.

  • A. False
  • B. True

Answer: A


NEW QUESTION # 17
In the USG series firewall, which of the following commands can be used to query the NAT translation result?

  • A. display firewall nat translation
  • B. display current nat
  • C. display firewall session table
  • D. display nat translation

Answer: C


NEW QUESTION # 18
Which of the following is not included in the design principles of the questionnaire?

  • A. Specificity
  • B. Consistency
  • C. Integrity
  • D. Openness

Answer: B


NEW QUESTION # 19
Which of the following types of attacks does the DDoS attack belong to?

  • A. Malformed packet attack
  • B. Snooping scanning attack
  • C. Special message attack
  • D. Traffic attack

Answer: D


NEW QUESTION # 20
Regarding SSL VPNtechnology, which of the following options is wrong?

  • A. SSL VPN technology extends the network scope of the enterprise
  • B. SSL VPN technology encryption only takes effect on the application layer
  • C. SSL VPN technology can be perfectly applied to NAT traversal scenarios
  • D. SSL VPN requires a dial-up client

Answer: D


NEW QUESTION # 21
Both A and B communicate data. If an asymmetric encryption algorithm is used for encryption, when A sends data to B.
Which of the following keys will be used for data encryption?

  • A. A public key
  • B. B private key
  • C. A private key
  • D. public key

Answer: D


NEW QUESTION # 22
When you configure a firewall between the domain security policy, if the 192.168.0.0/24 network segment is set to match object, the following configuration, which is correct? (Choose two.)

  • A. policy 1
    policy source 192.168.0.0 255.255.255.0
  • B. policy 1
    policy source 192.168.0.0 mask 255.255.255.0
  • C. policy 1
    policy source 192.168.0.0 0.0.0.255
  • D. policy 1
    policy source 192.168.0.0 mask 0.0.0.255

Answer: B,C


NEW QUESTION # 23
Digital certificate technology solves the problem that public key owners cannot determine in digital signature technology.

  • A. False
  • B. True

Answer: B


NEW QUESTION # 24
Which of the following attacks can DHCP Snooping prevent? (Multiple Choice)

  • A. Intermediaries and IP/MAC spoofing attacks
  • B. Counterfeit DHCP lease renewal packet attack using option82 field
  • C. IP spoofing attack
  • D. DHCP Server counterfeiter attack

Answer: A,B,C,D


NEW QUESTION # 25
Which of the following options can be used in the advanced settings of windows firewall? (Multiple Choices)

  • A. Set connection security rules
  • B. Set out inbound rules
  • C. Restore defaults
  • D. Change notification rules

Answer: A,B,C,D


NEW QUESTION # 26
Information security levelprotection is to improve the overall national security level, while rationally optimizing the distribution of security resources, so that it can return the greatest security and economic benefits

  • A. False
  • B. True

Answer: B


NEW QUESTION # 27
Which of the following statements are correct about Huawei routers and switches? (Multiple Choice)

  • A. The switch does not have security features
  • B. The router can implement some security functions, and some routers can implement more security functions by adding security boards.
  • C. The main function of the router is to forward data. Sometimes the firewall may bea more suitable choice when the enterprise has security requirements.
  • D. The switch has some security features, and some switches can implement more security functions by adding security boards.

Answer: B,C,D


NEW QUESTION # 28
When the sesson authentication mode is used to trigger the firewall's built-in Portal aithentication. the user does not actively perform identity authentication, advanced service access, and device push "redirect" to the authentication page? .. ' * '

  • A. False
  • B. True

Answer: B


NEW QUESTION # 29
As shown in the figure, a TCP connection is established between client A and server B Which of the following two "Tpacket numbers should be?

  • A. a+1: a+1
  • B. a+1: a
  • C. a: a+1
  • D. b+1: b

Answer: A


NEW QUESTION # 30
In Huawei SDSec solution, which layer of equipment does the firewall belong to?

  • A. Control layer
  • B. Executive layer
  • C. Monitoring layer
  • D. Analysis layer

Answer: B


NEW QUESTION # 31
Whenconfiguring a GRE tunnel interface, the destination address generally refers to which of the following parameters?

  • A. Local tunnel interface IP address
  • B. Local end network export IP address
  • C. IP address of the peertunnel interface
  • D. Peer external network export IP address

Answer: D


NEW QUESTION # 32
......

Exam Questions for H12-711 Updated Versions With Test Engine: https://freedumps.validvce.com/H12-711-exam-collection.html