Jan-2024 Pass Huawei H12-711 Exam in First Attempt Easily
Free H12-711 Exam Files Downloaded Instantly 100% Dumps & Practice Exam
NEW QUESTION # 164
Which of the following is the analysis layer device inthe Huawei SDSec solution? r a.
- A. Firehunter
- B. cis
- C. switch
- D. Agile Controller
Answer: A
NEW QUESTION # 165
The following security policy command, representatives of the meaning:
- A. banned from trust region access to untrust region and the source address is 10.2.10.10 host to all the hosts ICMP message
- B. banned from trust region access to untrust region and the destination address is 10.1.0.0/16 segment all hosts ICMP message
- C. banned from trust region access to untrust region and the source address is 10.1.0.0/16 segment all the hosts ICMP message
- D. banned from trust region access to untrust region and the destination address is 10.1.10.10 host ICMP message
Answer: C
NEW QUESTION # 166
Typical remote authentication modes are: (Multiple Choice)
- A. Local
- B. HWTACACS
- C. RADIUS
- D. LLDP
Answer: B,C
NEW QUESTION # 167
In order to obtain evidence of crime, it is necessary to master the technology of intrusion tracking. Which of the following descriptions are correct about the tracking technology? (Multiple Choice)
- A. Packet tagging technology extracts information from attack sources by recording packets on the router and then using data drilling techniques
- B. Packet Recording Technology marks packets on each passing router by inserting trace data into the tracked IP packets
- C. Link test technology determines the source of the attack by testing the network link between the routers
- D. Shallow mail behavior analysis can analyze the information such as sending IP address, sending time, sending frequency, number of recipients, shallow email headers and so on.
Answer: B,C,D
NEW QUESTION # 168
The following security policy command, representatives of the meaning:
- A. banned from trust region access to untrust region and the destination address is 10 1 10 10 host ICMP message
- B. banned from trust region access to untrust region and the source address is10.2.10.10 host to all the hosts ICMP message
- C. banned from trust region access to untrust region and the source address is 10.1 0 0/16 segment all the hosts ICMP message
- D. banned from trust region access to untrust region and the destination address is 10.1 0 0/16 segment all hosts ICMP message
Answer: C
NEW QUESTION # 169
Which of the following are in the certification area of ISO27001? (Multiple choice)
- A. Business continuity management
- B. Vulnerability management
- C. Access control
- D. Personnel safety
Answer: A,B,C,D
NEW QUESTION # 170
Which of the following are key elements of information securityprevention? (Multiple choice)
- A. Security products and technologies
- B. Security operation and management
- C. Personnel
- D. Asset management
Answer: A,B,C,D
NEW QUESTION # 171
Which of the following options does not belong to the log type of the Windows operating system?
- A. Business log
- B. Security log
- C. System log
- D. Application log
Answer: A
NEW QUESTION # 172
Which of the following are the status information that can be backed up by the HRP (Huawei Redundancy Protocol)protocol? (Multiple choice)
- A. ServerMap entry
- B. Routing table
- C. Session table
- D. Dynamic blacklist
Answer: A,C,D
NEW QUESTION # 173
Which of the following attacks can DHCP Snooping prevent? (Multiple Choice)
- A. Intermediaries and IP/MAC spoofing attacks
- B. IP spoofing attack
- C. Counterfeit DHCP lease renewal packet attack using option82 field
- D. DHCP Server counterfeiter attack
Answer: A,B,C,D
NEW QUESTION # 174
In the IPSec VPN transmission mode, which part of the data packet is encrypted?
- A. New IP packet header
- B. Network layer and upper layer data packet
- C. Original IP packet header
- D. Transport layer and upper layer data packet
Answer: D
NEW QUESTION # 175
Which of the following statement about the NAT configuration is wrong?
- A. When there is VoIP service in the network, you do not need to configure NAT ALG
- B. The IP address in the address pool can overlap with the public IP address of the NAT server
- C. The firewall does not support NAPT conversion for ESP and AH packets.
- D. Configure source NAT in -.transparent mode, the firewall does not support easy-ip mode
Answer: C
NEW QUESTION # 176
Which ofthe following optionsis the correct sequence ofthe four phases ofthe Information Security Management System (ISMS)?
- A. Plan->Do->Check->Action
- B. Plan->Check->Do->Action
- C. Check->Plan->Do->Action
- D. Plan->Check->Action->Do
Answer: A
NEW QUESTION # 177
Which of the following are correct about configuring the firewall security zone?(Multiple Choice)
- A. When data flows between different security zones, the device security check is triggered and the corresponding security policy is implemented
- B. The firewall has four security zones by default, and the four security zone priorities do not support modification.
- C. The firewall can create two security zones of the same priority
- D. Firewall can have 12 security zones at most.
Answer: A,B
NEW QUESTION # 178
NAT technology can securely transmit data by encrypting data.
- A. False
- B. True
Answer: A
NEW QUESTION # 179
Which of the following options is not the part of the quintet?
- A. Source MAC
- B. Destination Port
- C. Source IP
- D. Destination IP
Answer: A
NEW QUESTION # 180
......
Free Exam Updates H12-711 dumps with test Engine Practice: https://www.practicevce.com/Huawei/H12-711-practice-exam-dumps.html
Updated Verified H12-711 dumps Q&As - 100% Pass Guaranteed: https://drive.google.com/open?id=1jqH_Jy5_hRMVmdqgd1ciDC2kM-gZeocz