nerdexam
Huawei

H12-725_V4.0 · Question #145

Which of the following descriptions of Huawei IPS deployment methods are incorrect? (Multiple choice)

The correct answer is B. Layer 2 bypass detection deployment can identify and control network traffic in real time D. Layer 2 direct connection deployment, Layer 3 bypass deployment, and Layer 2 bypass detection. B is incorrect because Layer 2 bypass detection is a passive (out-of-band) deployment - traffic is only mirrored to the IPS, not routed through it. The device can analyze copies of packets to identify threats, but it has no ability to block or control live traffic in real time…

Intrusion Prevention System (IPS) and Anti-DDoS

Question

Which of the following descriptions of Huawei IPS deployment methods are incorrect? (Multiple choice)

Options

  • ALayer 2 direct connection deployment, which can identify and control network traffic in real time
  • BLayer 2 bypass detection deployment can identify and control network traffic in real time
  • CLayer 3 bypass deployment, which can identify and control network traffic in real time
  • DLayer 2 direct connection deployment, Layer 3 bypass deployment, and Layer 2 bypass detection

How the community answered

(27 responses)
  • A
    15% (4)
  • B
    78% (21)
  • C
    7% (2)

Explanation

B is incorrect because Layer 2 bypass detection is a passive (out-of-band) deployment - traffic is only mirrored to the IPS, not routed through it. The device can analyze copies of packets to identify threats, but it has no ability to block or control live traffic in real time.

D is incorrect because it incorrectly implies all three methods share the same capabilities. By including Layer 2 bypass detection in the same category as inline methods, it makes a false equivalence - bypass detection fundamentally cannot enforce traffic control, only detection.

A is a correct description because Layer 2 direct connection places the IPS inline (all traffic flows through it like a bridge), so it can both identify and actively block malicious traffic in real time.

C is a correct description because Layer 3 bypass deployment in Huawei's model functions in a routing/inline capacity at Layer 3, meaning traffic is forwarded through the device and can still be controlled - unlike Layer 2 bypass detection which is purely passive.

Memory tip: Think of "bypass detection" as a security camera - it watches traffic but can't stop anything. Direct connection and Layer 3 deployment are like a security guard standing in the doorway - they can both watch and block. The word "detection" in option B is the dead giveaway that control is not possible.

Topics

#IPS deployment modes#bypass detection limitations#traffic control vs detection#inline vs bypass

Community Discussion

No community discussion yet for this question.

Full H12-725_V4.0 Practice