
Pass Your HCNA-Security H12-711 Exam on Oct 21, 2023 with 290 Questions
H12-711 Free Exam Study Guide! (Updated 290 Questions)
Huawei H12-711 Exam is a great certification for IT professionals seeking to help protect organizations from cyber-attacks. It provides the foundations of network security management and protection from external threats. It is an ideal certification for beginners as well as mid-career professionals seeking to enhance their skills, knowledge and career prospects in IT security. It remains a valuable asset in the rapidly evolving world of cybersecurity. As an AI language model, I don't have personal stance or opinion on this topic.
NEW QUESTION # 134
Which of the following description is wrong about the operating system?
- A. The interface between the operating system and the user is a graphical interface.
- B. The operating system is the interface between the user and the computer
- C. The operating system is responsible for managing the execution of all hardware resources and control software of the computer system.
- D. The operating system itself is also a software
Answer: A
NEW QUESTION # 135
Which of the following options are correct about the control actions permit and deny of the firewall interzone forwarding security policy? (Multiple Choice)
- A. The packet is matched immediately after the inter-domain security policy deny action, and the other interzone security policy will not be executed.
- B. Whether the message matches the permit action of the security policy or the deny action, the message will be processed by the UTM module.
- C. The action of the firewall default security policy is deny.
- D. Even if the packet matches the permit action of the security policy, it will not necessarily be forwarded by the firewall.
Answer: A,C,D
NEW QUESTION # 136
In the environment of GRE configuration, which of the following statements are true? (Choose three.)
- A. If both ends enable the configuration of keyword verification, the keyword must be the same
- B. In order to make the ends of the tunnel forward data packets normally, the devices of both ends are configured routing which through the Tunnel interface
- C. When the local device send data packets, by identifying the protocol field value of IP header for GRE to determine whether send the data packet to GRE module for processing
- D. When the opposite end receives data packets, by identifying the protocol field value of IP header for GRE to determine whether send the data packet to GRE module for processing
Answer: A,B,D
NEW QUESTION # 137
The administrator PC and the USG firewall management interface directly connected using the web the way initialization. Which nether following statements are true? (Multiple choice)
- A. Manage PC browser access http://192.168.1.1
- B. IP address ofthe management PC is manually set to 192.168.0.2-'92.168.0.254
- C. Manage PC browser accesshttp://192.168.0.1
- D. Set the NIC ofthe management PC to automatically obtain the IP address.
Answer: B,C
NEW QUESTION # 138
Which of the following options can be used in the advanced settings of windows firewall? (Multiple Choices)
- A. Change notification rules
- B. Set out inbound rules
- C. Set connection security rules
- D. Restore defaults
Answer: A,B,C,D
NEW QUESTION # 139
In most scenarios, NAT Inbound is used to the enterprise private network users to access the Internet scenario.
- A. False
- B. True
Answer: A
NEW QUESTION # 140
Which of the following is the GRE protocol number?
- A. 0
- B. 1
- C. 2
- D. 3
Answer: A
NEW QUESTION # 141
ASPF (Application Specific Packet Filter) is a kind of packet filtering basedon the application layer, it checks the application layer protocol information and monitor the connection state of the application layer protocol.
ASPF by Server Map table achieves a special security mechanism. Which statement about ASPF and Server map table are correct? (Multiple choice)
- A. ASPF dynamically create and delete filtering rules
- B. Quintupleserver-map entries achieve a similar functionality with session table
- C. ASPF monitors the packets in the process of communication
- D. ASPF through server map table realize dynamic to allow multi-channel protocol data to pass
Answer: A,C,D
NEW QUESTION # 142
Regarding the firewall security policy, which of the following options are wrong?
- A. If the security policy is permit, the discarded message will not accumulate the number of hits.
- B. When configuring the security policy name, you cannot reuse the samename.
- C. Adjust the order of security policies without saving the configuration file.
- D. The number of security policy entries of Huawei USG series firewalls cannot exceed 128.
Answer: A
NEW QUESTION # 143
In practical applications, asymmetric encryption is mainly used to encrypt user data
- A. False
- B. True
Answer: A
NEW QUESTION # 144
HTTP packets are carried by UDP, and the HTTPS protocol is based on TCP three-way handshake. Therefore, HTTPS is relatively secure, and HTTPS is recommended.
- A. False
- B. True
Answer: A
NEW QUESTION # 145
Which of the following attacks is not a malformed packet attack?
- A. Smurf attack
- B. ICMP unreachable packet attack
- C. Teardrop attack
- D. TCP fragmentation attack
Answer: B
NEW QUESTION # 146
Data analysis technology is to find and -natch keywords or key ohrases in the acquired data stream or information flow, and analyze: he correlation of time. Which of the following is not an evidence analysis technique?
- A. Password deciphering, data decryption technology
- B. Spam tracking technology
- C. Techniques for discovering the connections between different evidences
- D. Document Digital Abstract Analysis Technology
Answer: B
NEW QUESTION # 147
For the occurrence of network security incidents, the remote emergency response is generally adopted first. If the problem cannot be solved for the customer through remote access, after the customer confirms, it is transferred to the local emergency response process.
- A. True
- B. False
Answer: A
NEW QUESTION # 148
Which of the following is correct for the command to view the number of security pclicy matches?
- A. display security-policy all
- B. display security-policy count
- C. display firewall sesstiontable
- D. count security-policy hit
Answer: A
NEW QUESTION # 149
Which of the following statements about IPSec SA is true?
- A. Used to generate a secret algorithm
- B. IPSec SA is two-way
- C. used to generate anencryption key
- D. IPSec SA is one-way
Answer: D
NEW QUESTION # 150
Which of the following statement about :he NAT is wrong?
- A. NAT technology can effectively hide the hosts of the LAN. it is an effective network security protection technology
- B. Some application layer protocols earn/ IP address information in the data, but also modify the P address information in the data of the upper layer when they are as NAT
- C. For some non-TCP. UDP protocols (such as ICMP. PPTP), unable to do the NAT translation
- D. Address Translation can follow the needs of users, providing FTP. WWW, Telnet and other services outside the LAN
Answer: C
NEW QUESTION # 151
Which ofthe following are the standard port numbers for the FTP protocol? (Multiple choice)
- A. 0
- B. 1
- C. 2
- D. 3
Answer: A,D
NEW QUESTION # 152
If the administrator uses the default authentication domain to authenticate a user, you only need to enter a user name when the user logs, if administrators use the newly created authentication domain to authenticate the user, the user will need to enter login "username @ Certified domain name"
- A. True
- B. False
Answer: A
NEW QUESTION # 153
In the IPSec VPN transmission mode, which part of the data packet is encrypted?
- A. New IP packet header
- B. Network layer and upper layer data packet
- C. Original IP packet header
- D. Transport layer and upper layer data packet
Answer: D
NEW QUESTION # 154
Some applications, such as Oracle database application, there is no data transfer for a long time, so that firewall session connection is interrupted, thus resulting in service interruption, which of the following technology can solve this problem?
- A. Configure default session aging time
- B. Configure a long business connection
- C. Turn fragment cache
- D. Optimization of packet filtering rules
Answer: B
NEW QUESTION # 155
Regarding SSL VPNtechnology, which of the following options is wrong?
- A. SSL VPN requires a dial-up client
- B. SSL VPN technology can be perfectly applied to NAT traversal scenarios
- C. SSL VPN technology extends the network scope of the enterprise
- D. SSL VPN technology encryption only takes effect on the application layer
Answer: A
NEW QUESTION # 156
The administrator PC and the USG firewall management interface directly connected using the web the way initialization, which of the following statements are true? (Multiple choice)
- A. Manage PC browser access http://192.168.1.1
- B. Manage PC browser access http://192.168.0.1
- C. IP address of the management PC is manually set to 192.168.0.2-192.168.0.254
- D. Set the NIC of the management PC to automatically obtain the IP address.
Answer: B,C
NEW QUESTION # 157
......
Huawei H12-711 (HCIA-Security V3.0) certification exam is a comprehensive exam that covers all aspects of network security. It is designed to test the candidate's ability to apply their knowledge of network security to real-world scenarios. H12-711 exam is computer-based and consists of multiple-choice questions. H12-711 exam is designed to be challenging and requires a high level of preparation.
H12-711 Dumps for HCNA-Security Certified Exam Questions and Answer: https://freetorrent.dumpsmaterials.com/H12-711-real-torrent.html
