nerdexam
Huawei

H12-725_V4.0 · Question #169

Which of the following descriptions of LDAP and AD authentication are correct? (Multiple choice)

The correct answer is A. The AD server is a server that integrates Kerberos and LDAP authentication. B. AD authentication integrates the Kerberos protocol based on LDAP D. iMaster can be used in LDAP authentication architecture. Options A and B are correct because Active Directory is fundamentally built on LDAP as its directory protocol, with Kerberos layered on top to handle the actual authentication - so AD is accurately described both as a server that integrates both protocols (A) and as a system…

Advanced Security Features

Question

Which of the following descriptions of LDAP and AD authentication are correct? (Multiple choice)

Options

  • AThe AD server is a server that integrates Kerberos and LDAP authentication.
  • BAD authentication integrates the Kerberos protocol based on LDAP
  • CLDAP authentication supports network devices to interact directly with the LDAP server
  • DiMaster can be used in LDAP authentication architecture

How the community answered

(24 responses)
  • A
    79% (19)
  • C
    21% (5)

Explanation

Options A and B are correct because Active Directory is fundamentally built on LDAP as its directory protocol, with Kerberos layered on top to handle the actual authentication - so AD is accurately described both as a server that integrates both protocols (A) and as a system that integrates Kerberos based on LDAP (B); these two statements describe the same relationship from slightly different angles.

Option D is correct because Huawei's iMaster network management platform supports LDAP authentication and can serve as an intermediary in an LDAP authentication architecture, relaying authentication requests on behalf of network devices.

Option C is the distractor - in standard LDAP authentication architectures, network devices do not interact directly with the LDAP server; instead, they send authentication requests to an AAA server (such as a RADIUS server), which then queries the LDAP server on their behalf. Direct device-to-LDAP communication is not the supported model.

Memory tip: Think of AD as a two-layer cake - LDAP is the base layer (directory storage and queries), and Kerberos is the top layer (authentication tickets). iMaster fits in as a Huawei-ecosystem middleman. For C, remember the rule: network devices talk to AAA/RADIUS, not directly to LDAP.

Topics

#LDAP#Active Directory#Kerberos#authentication

Community Discussion

No community discussion yet for this question.

Full H12-725_V4.0 Practice