Summer Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: buysanta

Exact2Pass Menu

Huawei Certified ICT Professional - Constructing Infrastructure of Security Network

Last Update 23 hours ago Total Questions : 217

The Huawei Certified ICT Professional - Constructing Infrastructure of Security Network content is now fully updated, with all current exam questions added 23 hours ago. Deciding to include H12-721 practice exam questions in your study plan goes far beyond basic test preparation.

You'll find that our H12-721 exam questions frequently feature detailed scenarios and practical problem-solving exercises that directly mirror industry challenges. Engaging with these H12-721 sample sets allows you to effectively manage your time and pace yourself, giving you the ability to finish any Huawei Certified ICT Professional - Constructing Infrastructure of Security Network practice test comfortably within the allotted time.

Question # 1

On the following virtual firewall network, the USG unified security gateway provides leased services to the enterprise. The VPN instance vfw1 is leased to enterprise A. The networking diagram is as follows. The PC C of the enterprise A external network user needs to access the intranet DMZ area server B through NAT. To achieve this requirement, what are the following key configurations?

A.

[USG] ip vpn-instance vfw1 vpn-id

B.

[USG] ip vpn-instance vfw1 [USG-vpn-vfw1] route-distinguisher 100:1 [USG-vpn-vfw1] quit

C.

[USG] nat server zone vpn-instance vfw1 untrust global 2.1.2.100 inside 192.168.1.2 vpn-instance vfw1

D.

[USG]nat address-group 1 2.1.2.5 2.1.2.10 vpn-instance vfw1

Question # 2

Which of the following statements about the blacklist is correct?

A.

When logging in to the device through Web or Telnet, if the username and password are incorrectly entered 3 times, the administrator ' s IP address will be blacklisted.

B.

Blacklists are classified into static blacklists and dynamic blacklists.

C.

. After the device detects the attack attempt of the user with a specific IP address according to the behavior of the packet, the device dynamically uses the dynamic blacklist technology to blacklist the IP address.

D.

When the packet arrives at the firewall, it first performs packet filtering check and then matches the blacklist.

Question # 3

An administrator can view the status of the device components by the following command: The status of the Slot3 board is Abnormal. What are the possible causes of the following faults?

A.

This slot is not supported in this slot of device A.

B.

interface card is damaged

C.

The pin on the backplane or motherboard is damaged. If the incorrect board is installed, the pin is tilted.

D.

ADSL telephone line failure

Question # 4

In the TCP/IP protocol, the TCP protocol provides a reliable connection service, which is implemented using a 3-way handshake. First handshake: When establishing a connection, the client sends a SYN packet (SYN=J) to the server and enters the SYN_SENT state, waiting for the server to confirm; the second handshake: the server receives the SYN packet and must send an ACK packet (ACK=1) To confirm the SYN packet of the client, and also send a SYN packet (SYN=K), that is, the SYN-ACK packet, the server enters the SYN_RCVD state; the third handshake: the client receives the SYN-ACK packet of the server. Send the acknowledgement packet ACK (SYN=2 ACK=3) to the server. After the packet is sent, the client and server enter the ESTABUSHED state and complete the handshake. Regarding the three parameters in the 3-way handshake process, which one is correct?

A.

1=J+1 2=J+1 3=K+1

B.

1=J 2=K+1 3=J+1

C.

1=J+1 2=K+1 3=J+1

D.

1=J+1 2=J 3=K+1

Question # 5

In the firewall DDoS attack defense technology, the data packet of the session table is not defended. If the data packet of the session has been established, it is directly released.

A.

TRUE

B.

FALSE

Question # 6

After the BFD session is established, the two systems periodically send BFD control packets. If a system does not receive any packets from the peer within the detection time, the status of the BFD session is considered to be Down. Which mode of detection is this mode called BFD?

A.

sync mode

B.

detection mode

C.

asynchronous mode

D.

query mode

Question # 7

The SSL VPN authentication is successful, but the Web-link resources cannot be accessed. What is the correct one?

A.

server does not open web service

B.

policy restricts user access

C.

device and intranet server are unreachable

D.

SSL VPN users reach the maximum limit

Question # 8

In a dual-system hot standby environment, if the path of the packet back and forth is inconsistent, which of the following conditions may result in packet loss?

A.

does not enable session fast synchronization

B.

Heartbeat bandwidth is insufficient

C.

turned off the status monitoring function

D.

specifies the wrong heartbeat port

Question # 9

What is the correct statement about the Eth-trunk function?

A.

Improve the communication bandwidth of the link

B.

Improve data security

C.

traffic load sharing

D.

Improve the reliability of the link

Question # 10

When an attack occurs, many packets are found on the attacked host (1.1.129.32) as shown in the figure. According to the analysis of the attack, what kind of attack is this attack?

A.

Smurf

B.

Land

C.

WinNuke

D.

Ping of Death

Go to page: