H12-711_V4.0 Exam Questions
800 real H12-711_V4.0 exam questions with expert-verified answers and explanations. Page 16 of 16.
- Question #751
The user group name of the firewall is not allowed to have the same name, and the full path of the organizational structure must be unique.
- Question #752
DDoS attack means that the attacker controls a large number of zombie hosts and sends a large number of attack messages to the attack target, causing link congestion on the network...
- Question #753
If the firewall works in active/standby backup mode, you need to configure the status of all VRRP backup groups on one firewall to active, and configure the status of all VRRP back...
- Question #754
The firewall supports the creation of custom security zones and allows network administrators to implement various special packet detection and security functions based on the secu...
- Question #755
TCP session hijacking is an attack method in which attackers snoop on user messages and forge TCP messages with legal sequence numbers.
- Question #756
Telnet is a remote login service protocol that uses port 23 of the UDP protocol.
- Question #757
Information security violations by corporate employees may cause security threats to corporate networks
- Question #758
The data link layer is located between the network layer and the physical layer and can provide services to IP, IPv6 and other protocols of the network layer. PDUs at the data link...
- Question #759
Use the reset firewal1 session table command to clear all session table information. The end user needs to reinitiate the connection to restart communication.
- Question #760
In a dual-machine hot standby network, if the firewall does not receive the heartbeat message from the peer for five consecutive heartbeat cycles, it will determine that the peer d...
- Question #761
VRRP backup group has three states: Initialize, Master and Backup.
- Question #762
The DMZ security area solves the problem of server placement very well. This security area can place equipment that needs to provide external network services, such as WWW servers,...
- Question #763
Predefined signatures are signatures included in the intrusion prevention signature database. The contents of predefined signatures (except actions) are not fixed and can be create...
- Question #764
When the firewall is used as a bypass detection device, the detection interface needs to be set to a Layer 3 interface. Configuring the bypass detection function on the detection i...
- Question #765
A PKI system consists of four parts: terminal entity, certificate certification authority, certificate registration authority and certificate/CRL repository.
- Question #766
In IPsec, ESP is an encapsulating security payload protocol and only provides data encryption functions.
- Question #767
Huawei equipment saves certificates in PKCS#12 format, which must contain private key information.
- Question #768
A self-signed certificate, also known as a root certificate, is a certificate issued to itself, that is, the issuer and subject names in the certificate are the same.
- Question #769
Against the threat of eavesdropping, digital envelopes can be used to ensure the confidentiality of information.
- Question #770
A router is a network layer device, and its main function is to forward messages between different networks.
- Question #771
UDP is a connection-oriented, reliable transport layer communication protocol.
- Question #772
Only when data flow occurs between different security zones, the security check of the firewall will be triggered and the corresponding security policy will be implemented.
- Question #773
Firewall intrusion prevention signatures are divided into two categories, predefined signatures and custom signatures.
- Question #774
Triplet NAT is an address translation method that simultaneously translates addresses and ports, allowing multiple private network addresses to share one or more public network add...
- Question #775
For ICMP messages, the firewall only supports status detection for Ping echo request messages and Ping echo response messages. Other types of ICMP messages do not perform status de...
- Question #776
SSL is a security protocol that provides secure connections for TCP-based application layer protocols.
- Question #777
In the PKI certificate revocation process, the user needs to send a signed and encrypted email to R& to apply for certificate revocation.
- Question #778
In IPsec VPN, if IKE v1 main mode is used to establish IKE SA, the identity of the peer is verified in messages 5 and 6.
- Question #779
Compared with symmetric encryption algorithms, asymmetric encryption algorithms have a higher security factor.
- Question #780
Digital signature refers to the data obtained by encrypting the digital fingerprint with the sender's own public key.
- Question #781
Multiple security zones can be configured on Huawei firewalls. By default, high-priority security zones can access low-priority security zones.
- Question #782
Level protection objects refer to objects in network security level protection work. They usually refer to systems composed of computers or other information terminals and related...
- Question #783
The fifth-level security protection capability is a dedicated protection level and is generally applicable to extremely important systems in important national fields and departmen...
- Question #784
The firewall considers that data flow within the same security zone does not pose security risks and does not require the implementation of any security policy.
- Question #785
Users can change any configuration of the Local area itself, including adding interfaces to the Local area.
- Question #786
When the administrator configures the user's authentication mode to server authentication and the authorization method to local authorization, the user can go online normally even...
- Question #787
After the firewall enables dual-machine hot backup, when the VGMP group priority of the local firewall is greater than the VGMP group priority of the peer firewall, the VGMP group...
- Question #788
The security factor of digital signatures is very high. Even if an attacker obtains the sender's public key, he cannot spy on the private data.
- Question #845
When the Layer 2 switch receives a unicast frame and the MAC address table entry of the switch is empty, the switch discards the unicast frame.
- Question #847
WAF can accurately control and manage users' online behavior and user traffic.
- Question #936
The scenario for internal enterprise users to access the Internet is as shown in the figure. The user online process includes: The following correct sequence of processes should: 1...
- Question #937
Please sequence the following steps according to the hierarchical protection process.
- Question #938
Please sequence the following digital envelope encryption and decryption processes correctly.
- Question #939
Drag the stages of network security emergency response on the left into the box on the right, and arrange them from top to bottom in order of execution.
- Question #940
Please sequence the following steps regarding the PKI life cycle correctly.
- Question #941
Drag the steps of electronic evidence collection on the left into the box on the right to summarize them, and sort them from top to bottom according to the order of execution.
- Question #942
Please sort the following project implementation steps starting from project launch.
- Question #943
Drag the warning levels of network security emergency response on the left into the box on the right, and arrange them from top to bottom in order of severity from high to low.
- Question #944
Please sort according to the table processing priority of iptables from large to small.
- Question #945
When configuring user single sign-on, if you use the mode of querying the AD server security log, please sort the following authentication processes.