H12-711_V4.0 Exam Questions
800 real H12-711_V4.0 exam questions with expert-verified answers and explanations. Page 15 of 16.
- Question #701
The advantages of symmetric key encryption are high efficiency, simple algorithm, low system overhead, and suitable for encrypting large amounts of data.
- Question #702
After the dual-machine hot standby configuration is completed, you can execute the display hrp state command to view the dual-machine hot standby status, including local and peer d...
- Question #703
The communicating parties in different security zones will exchange messages, so the direction of a traffic should be determined based on the first message that initiates the traff...
- Question #704
Regardless of whether the heartbeat cable is directly connected, the active and backup firewalls need to configure the security policy between the domain where the heartbeat interf...
- Question #705
Triplet NAT allows external devices to actively access the internal PC through the translated address and port. The firewall allows such access packets to pass even if no correspon...
- Question #706
SSH realizes the connection between the SSH client and the server by establishing a secure tunnel in the network. SSH uses a symmetric key to encrypt data.
- Question #707
The intrusion prevention predefined signature has four default actions, namely release, alarm, blocking and adding to the blacklist.
- Question #708
When users in the external network access the internal server, use the two-way NAT function to simultaneously convert the source and destination addresses of the packets, which can...
- Question #709
HTTPS adds a TLS layer to HTTP to provide authentication, encryption and integrity verification for data transmission.
- Question #710
The sub-interface function can be enabled on the firewall interface G0/0/1 and can be divided into different VLANs, but the sub-interface cannot be added to the security zone.
- Question #711
TCP needs to complete the three-way handshake process when establishing a connection, and needs to wave four times when ending the session.
- Question #712
Server-map is used to store a mapping relationship. This mapping relationship can be a data connection relationship negotiated by control data, or it can be an address mapping rela...
- Question #713
In IPsec transmission mode, the AH and ESP headers are inserted before the original IP header, so that the internal IP address can be completely hidden, making security higher.
- Question #714
When the firewall enables ASPF and generates the Server-map table, if a data connection matches the Server-map entry, it can be forwarded normally by the firewall, and a session is...
- Question #715
L2TP VPN is suitable for scenarios where employees on business trips access through VPN dial- up. Employees can access the corporate intranet through remote dialing from any place...
- Question #716
DH algorithm is an asymmetric encryption and decryption algorithm and is generally used by both parties to negotiate a symmetric encryption key.
- Question #717
Although different interfaces of the switch send and receive data independently, they cannot effectively isolate the conflict domains in the network.
- Question #718
Deploying HiSec Insight in the enterprise network can effectively discover potential threats and advanced threats in the network, and achieve network-wide security situation awaren...
- Question #719
SSL VPN is a VPN technology that realizes remote secure access. Encryption only takes effect on the application layer, and users do not need to use a VPN client, so it has wide app...
- Question #720
GRE, as a Layer 2 VPN encapsulation technology, can solve the transmission problem of heterogeneous networks.
- Question #721
If there are multiple levels of CAs in the PKI system, a CA hierarchy will be formed. The top-level CA is the root CA, which has a CA "self-signed" certificate.
- Question #722
When forwarding unicast data, the Layer 2 switch needs to decapsulate the Layer 3 header of the message before forwarding it.
- Question #723
The hash algorithm is collision-resistant, that is, if you input different data, the output Hash value cannot be the same.
- Question #724
FTP protocol is used to realize file transfer between local and remote hosts. It is mainly used for version upgrade, log download, file transfer and configuration storage. It adopt...
- Question #725
The function of the security policy in the firewall is to inspect the data flow passing through the firewall. Only legal data flow that conforms to the security policy can pass the...
- Question #726
By default, Huawei firewall does not enable Telnet login function.
- Question #727
By default, the firewall does not authenticate the data flows passing through it. You need to configure the authentication policy to filter out the data flows that need to be authe...
- Question #728
In a networking environment where the round-trip paths of packets are inconsistent, the firewall may only receive subsequent packets during the communication process, but not the f...
- Question #729
If G0/0/1 is added to the Trust security zone, the network connected to the G0/0/1 interface is considered to belong to the security zone, and the G0/0/1 interface itself belongs t...
- Question #730
There is no priority between custom signatures and predefined signatures. When traffic hits both custom signatures and predefined signatures, the final action will be based on the...
- Question #731
Intrusion prevention is a security mechanism that analyzes network traffic, detects intrusions (including buffer overflow attacks, Trojans, worms, etc.), and terminates intrusions...
- Question #732
If a user/IP address is considered untrustworthy, the user/IP address can be added to the blacklist, and the device will discard all packets from or sent to these users/IP addresse...
- Question #733
In the firewall forwarding process, the matching order of the Server-map entries generated by the ASPF/NAT ALG function precedes the security policy. After the data packet matches...
- Question #734
Intrusion prevention signatures are used to describe the characteristics of attack behavior in the network. Firewalls detect and prevent attacks by comparing data flows with intrus...
- Question #735
Even if the DHCP message matches the firewall authentication policy, authentication will not be triggered.
- Question #736
VPN is a virtual private network, which is used to build a private virtual network on a public network and transmit private network traffic in this virtual network.
- Question #737
In a PKI system, the CA certificate cannot be a self-signed certificate.
- Question #738
The keys used by the IPsec encryption and authentication algorithms can be configured manually or dynamically negotiated through the Internet Key Exchange IKE protocol.
- Question #739
When IPsec VPN technology uses the ESP security protocol and transmission mode to encapsulate data packets, ESP will encrypt the IP packet header.
- Question #740
The firewall security group supports up to three levels of nesting, namely parent security group, security group, and child security group.
- Question #741
If the firewall performs packet-by-packet inspection on all packets, it will cause a large consumption of device resources and a sharp decline in performance. Therefore, the firewa...
- Question #742
Asymmetric encryption algorithms can only use the public key to encrypt data and the private key to decrypt data, and the process is irreversible.
- Question #743
The data flow between security domains is directional, including inbound and outbound.
- Question #744
The purpose of information security is to protect the hardware, software and data in the system from accidental or malicious reasons, and to ensure the continuous, reliable and nor...
- Question #745
Mutual access between users in the same firewall area does not require permission from the security policy.
- Question #746
In dual-machine hot backup, the heartbeat interfaces of the two firewalls must be directly connected, not through an intermediate device.
- Question #747
The Server-map entries generated by the firewall when forwarding multi-channel protocols will age according to the aging time of various protocols if there is no traffic hit.
- Question #748
Network security situational awareness is the ability to dynamically and holistically gain insight into security risks based on the environment. It uses technologies such as data f...
- Question #749
The DMZ area in the firewall usually places some server equipment that provides public access.
- Question #750
SH3 is a commercial algorithm compiled by the State Cryptozoology Administration. It is used for digital signature and verification, message authentication code generation and veri...