The Huawei H12-711_V4.0 Questions & Practice Test are Available On-Demand [Q12-Q35]

Share

The Huawei H12-711_V4.0 Questions & Practice Test are Available On-Demand

Valid H12-711_V4.0 Exam Dumps Ensure you a HIGH SCORE

NEW QUESTION 12
Which of the following is the numbering range of Layer 2 ACLs?

  • A. The 3000~3999
  • B. The 1000~1999
  • C. @2000~2999
  • D. The 4000~4999

Answer: A

 

NEW QUESTION 13
What type of ACL does ACL number 3001 correspond to?

  • A. interface ACL
  • B. Layer 2 ACL
  • C. Basic ACL
  • D. Advanced ACLs

Answer: D

 

NEW QUESTION 14
The following description of digital certificates, which one is wrong

  • A. Digital certificates contain the owner's public key and related identity information.
  • B. In general, the key of a digital certificate has an expiration date.
  • C. The simplest certificate consists of a public key, a name, and a digital signature from a certificate authority.
  • D. Digital certificates do not solve the problem of digital signature technology where the public key cannot be determined to be the designated owner.

Answer: D

 

NEW QUESTION 15
Social engineering is a means of harm such as deception, harm, etc. through psychological traps such as psychological weaknesses, instinctive reactions, curiosity, trust, and greed of victims ( )

  • A. False
  • B. TURE

Answer: B

 

NEW QUESTION 16
The shard cache technology will wait for the arrival of the first shard packet, and then reassemble and decrypt all the packets, and then do subsequent processing by the device to ensure that the session can proceed normally in some application scenarios.

  • A. TRUE
  • B. FALSE

Answer: A

 

NEW QUESTION 17
Which of the following descriptions of single sign-on is correct?

  • A. Visitors obtain the SMS verification code through the Portal authentication page, and then enter the SMS verification code to pass the authentication.
  • B. The visitor recited the Portal authentication page and sent the username and password to FT to identify his/her identity, and the password was not stored on the FT, and the FI sent the username and password to the third-party authentication server, and the authentication process was carried out on the authentication server.
  • C. The visitor sends the username and password that identifies his identity to the third-party authentication server, and after the authentication is passed, the third-party authentication server sends the visitor's identity information to FW. F7 only records the identity information of the visitor and does not participate in the authentication process
  • D. The visitor sends the username and password that identifies them to the FW through the portal authentication page, on which the password is stored and the verification process takes place on the FW.

Answer: C

 

NEW QUESTION 18
Compared with the software architecture of C/S, B/S does not need to install a browser, and users are more flexible and convenient to use.

  • A. TRUE
  • B. FALSE

Answer: A

 

NEW QUESTION 19
Which of the following descriptions about the heartbeat interface is wrong ( )?[Multiple choice]*

  • A. The interface MTU value is greater than 1500 and cannot be used as a heartbeat interface
  • B. MGMT interface (Gigabi tEtherneto/0/0) cannot be used as heartbeat interface
  • C. It is recommended to configure at least two heartbeat interfaces. - One heartbeat interface is used as the master, and the other heartbeat interface is used as the backup.
  • D. The connection method of the heartbeat interface can be directly connected, or it can be connected through a switch or router

Answer: A

 

NEW QUESTION 20
ARP man-in-the-middle attacks are a type of spoofing attack technique.

  • A. TRUE
  • B. FALSE

Answer: A

 

NEW QUESTION 21
The following description of the intrusion fire protection system IPS, which is correct?

  • A. Oral IPS has the ability to customize intrusion prevention rules.
  • B. The port IPS can be attached to the switch and port mirrored through the switch.
  • C. The port IPS can be concatenated at the network boundary.
  • D. The IPS cannot prevent intrusion from occurring in real time.

Answer: A,B,C

 

NEW QUESTION 22
Which of the following NAT technologies can implement a public network address to provide source address translation for multiple private network addresses ( )*

  • A. NAPT
  • B. NAT Server
  • C. NAT No-PAT
  • D. Easy-ip
    CT Jinglu

Answer: B

 

NEW QUESTION 23
When using passive mode to establish an FTP connection, the control channel uses port 20 and the data channel uses port 21. ( )[Multiple choice]*

  • A. True
  • B. False

Answer: B

 

NEW QUESTION 24
IKE SA is a one-way logical connection, and only one IKE SA needs to be established between two peers.

  • A. FALSE
  • B. TRUE

Answer: A

 

NEW QUESTION 25
Which of the following types of malicious code on your computer includes?

  • A. Oral spyware
  • B. Trojan horses
  • C. Port SQL injection
  • D. Oral virus

Answer: A,B,C,D

 

NEW QUESTION 26
Database operation records can be used as ___ evidence to backtrack security events.[fill in the blank]*

  • A. phases
  • B. electronic

Answer: B

 

NEW QUESTION 27
Which of the following operating modes does NTP support?

  • A. Mouth broadcast mode
  • B. Mouth multicast mode
  • C. Mouth client/server mode
  • D. Mouth peer mode

Answer: A,B,C,D

 

NEW QUESTION 28
Please match the following information security risks to information security incidents one by one.[fill in the blank]* physical security risk Enterprise server permissions are loosely set Information Security Management Risk Infected Panda Burning Incense Information Access Risk Fire destroyed equipment in computer room application risk Talk to people about leaking company secrets

  • A. 0
  • B. 1

Answer: B

 

NEW QUESTION 29
When IPSec VPN uses tunnel mode to encapsulate packets, which of the following is not within the encryption scope of the ESP security protocol? ( )[Multiple choice]*

  • A. TCP Header
  • B. Raw IP Header
  • C. ESP Header
  • D. ESP Tail

Answer: C

 

NEW QUESTION 30
As shown in the figure, nat server global202.106.1.1 inside10.10.1.1 is configured on the firewall. Which of the following is the correct configuration for interzone rules? ( )[Multiple choice]*

  • A. rule name b, source- zone untrust, destination- zone trust, source- address10.10.1.1 32, action permit
  • B. rule name d, source- zone untrust. destination- zone trust. destination- address10.l0.1.1 32, action permit
  • C. rule name b, source-zone untrust, destination-zone trust, source-address202.106.l.1 32, action permit
  • D. rule name c. source-zone untrust. destination-zone trust. destination-address 202.106.1.132, action permit

Answer: B

 

NEW QUESTION 31
The network environment is becoming more and more complex, and network security incidents occur frequently. While accelerating the construction of informatization, enterprises must not only resist external attacks, but also prevent internal management personnel from being involved in data leakage and operation and maintenance accidents due to operational errors and other issues. Which of the following options might reduce operational risk?

  • A. Oral Each department system is independently authenticated and uses a single static password for authentication.
  • B. Each system is independently operated, maintained and managed, and the access process is not audited and monitored.
  • C. According to the administrator configuration, the O&M user corresponds to the background resource account, and restricts the unauthorized use of the account. mouth Based on the password security policy, the O&M security audit system automatically modifies the password of the background resource account at regular intervals.

Answer: C

 

NEW QUESTION 32
What are the correct entries in the following description of firewall security zones?

  • A. Normally, the two communicating parties must exchange messages, that is, there are messages transmitted in both directions between security domains.
  • B. The DMZ security zone solves the problem of server placement well, and this security area can place devices that need to provide network services to the outside world.
  • C. Data flows between security domains are directional, including Inbound and Outbound.
  • D. The Local zone is the highest security zone with a priority of 99.

Answer: A,B,C

 

NEW QUESTION 33
Which of the following is not the default security zone of the firewall ( )[Multiple choice]*

  • A. trust zone
  • B. untrust trust
  • C. isp zone)
  • D. dmz zone

Answer: C

 

NEW QUESTION 34
According to the level protection requirements, which of the following behaviors belong to the scope of information security operation and maintenance management? ( )*

  • A. Security hardening of the host
  • B. Participate in information security training
  • C. Backup or restore data
  • D. Develop an emergency response plan

Answer: A,B,C,D

 

NEW QUESTION 35
......

H12-711_V4.0 Exam Practice Questions prepared by Huawei Professionals: https://www.briandumpsprep.com/H12-711_V4.0-prep-exam-braindumps.html

Pass H12-711_V4.0 Exam with Latest Questions: https://drive.google.com/open?id=1Ub0I-FTh-3P8j5PPHQQegozKYH2_rWO3