Spring Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: buysanta

Exact2Pass Menu

HCIA-Security V4.0 Exam

Last Update 4 hours ago Total Questions : 153

The HCIA-Security V4.0 Exam content is now fully updated, with all current exam questions added 4 hours ago. Deciding to include H12-711_V4.0 practice exam questions in your study plan goes far beyond basic test preparation.

You'll find that our H12-711_V4.0 exam questions frequently feature detailed scenarios and practical problem-solving exercises that directly mirror industry challenges. Engaging with these H12-711_V4.0 sample sets allows you to effectively manage your time and pace yourself, giving you the ability to finish any HCIA-Security V4.0 Exam practice test comfortably within the allotted time.

Question # 11

Which of the following types of packets cannot be filtered by a packet filtering firewall?

A.

Non-fragmented packets

B.

Forged ICMP error packets

C.

Initial fragments

D.

Non-initial fragments

Question # 12

Which of the following statements are incorrect about the differences between routers and Layer 2 switches?

A.

By default, routers can isolate broadcast domains but not collision domains.

B.

Switches flood broadcast packets.

C.

Routers forward broadcast packets.

D.

By default, switches can isolate collision domains but not broadcast domains.

Question # 13

In cases where some configurations alter existing session table entries and want them to take effect immediately, you can regenerate the session table by clearing the session table information. All session table information can be cleared by executing the _____firewall session table command.

Question # 14

In the automatic backup mode of hot standby on the second machine, which of the following sessions is backed up?

A.

ICMP session

B.

TCP half-connection session

C.

Self-session to the firewall

D.

UDP first packet session

Question # 15

ARP man-in-the-middle attacks are a type of spoofing attack technique.

A.

TRUE

B.

FALSE

Question # 16
A.

1

B.

2

C.

3

D.

4

Question # 17

Which of the following are the default zones of Huawei firewalls?

A.

Untrust

B.

Local

C.

DMZ

D.

Trust

Question # 18

The following description of the construction of a digital certificate, which item is wrong

A.

The name of the device that issued the certificate can be different from the subject name in the issuer certificate.

B.

The structure of the certificate follows the specification of the X.509 v3 version.

C.

The simplest certificate consists of a public key, a name, and a digital signature from a certificate authority.

D.

The issuer signs the certificate information with the private key.

Question # 19

What is correct in the following description of Security Alliance in IPSec?

There are two ways to set up an IPSec SA

A.

manual and IKE.

IPSec SA is uniquely identified by a triple.

B.

IPSec SA is a one-way logical connection, usually established in pairs (Inbound and Outbound).

C.

Security Alliance SA is a communication peer agreement for certain elements that describes how peers can communicate securely using secure services such as encryption.

Question # 20

When the Layer 2 switch receives a unicast frame and the MAC address table entry of the switch is empty, the switch discards the unicast frame.

A.

TRUE

B.

FALSE

Go to page: