H12-725_V4.0 Exam Questions
518 real H12-725_V4.0 exam questions with expert-verified answers and explanations. Page 2 of 11.
- Question #51Intrusion Prevention System (IPS) and Anti-DDoS
Which of the following descriptions of cleaning centers is incorrect?
DDoS mitigationTraffic diversion methodsBack-injection techniquesAttack prevention - Question #52Firewall Technologies and Deployment
When a firewall performs email filtering, which of the following email transfer protocols does it support?
Email FilteringSMTPS ProtocolFirewall Traffic InspectionEmail Security - Question #53Intrusion Prevention System (IPS) and Anti-DDoS
IPS devices work based on specific intrusion prevention mechanisms. Which of the following is the correct ranking of intrusion prevention mechanisms?
IPS Detection MechanismsProtocol IdentificationFeature MatchingData Processing Pipeline - Question #54Network Security Solution Design
When using iMaster NCE-Campus as the Portal server, in order to allow iMaster NCE-Campus to match the corresponding Portal page according to the user's IP address. When configuring...
Portal ConfigurationUser IdentificationURL Template ParametersAccess Control - Question #55Network Security Solution Design
To implement the access control function through Huawei iMaster NCE-Campus controller, which of the following is not required for authentication and authorization configuration?
access controlauthentication & authorizationiMaster NCE-Campusidentity management - Question #56Intrusion Prevention System (IPS) and Anti-DDoS
Which of the following is not a function of the Anti-DDoS Management Center?
Anti-DDoS Management CenterAlarm managementPerformance managementDDoS architecture - Question #57VPN Technologies
Which of the following descriptions of the network expansion process in SSL VPN is incorrect?
SSL VPNNetwork ExpansionVPN TunnelsVirtual Adapter - Question #58VPN Technologies
Use IKE v1 main mode to establish an IPSec VPN. After detecting the presence of a NAT device, which of the following ISAKMP messages will be followed by port number conversion?
IKE v1 main modeNAT DetectionISAKMP message flowUDP encapsulation - Question #59VPN Technologies
As shown in the figure, enterprise A and enterprise B need to communicate securely, and an IPSec tunnel is established between firewall A and firewall B. Which of the following sec...
IPSec protocols (AH vs ESP)Tunnel vs Transport modeEnterprise firewall VPNConfidentiality and authentication - Question #60Advanced Security Features
The network architecture of an enterprise is as shown in the figure below. Portal authentication is deployed on SW2. Its authentication-free template is as shown in the figure. Whi...
Portal authenticationauthentication-free templateDNS resolutiongateway - Question #61Advanced Security Features
Which of the following descriptions about virtual system resource allocation is incorrect?
virtual systemsresource allocationquota resourcesshared resources - Question #62Network Security Solution Design
Which of the following descriptions of BFD detection characteristics is incorrect?
BFDbidirectional forwarding detectionfault detectionnetwork convergence - Question #63Intrusion Prevention System (IPS) and Anti-DDoS
The figure shows the defense principle of HTTP Flood. Which source detection technology is shown in the figure?
HTTP FloodDDoS defensesource detectionenhanced mode - Question #64Advanced Security Features
Which of the following descriptions of abnormal file type identification results is incorrect?
file type identificationcontent securityfile extension mismatchabnormal files - Question #65Security O&M and Management
To check whether there is an abnormal task plan (not set by the user) on the Linux host, which of the following commands can be used?
Linux securitycrontabtask schedulinghost hardening - Question #66Security O&M and Management
According to the provisions of the "National Cyber Security Incident Emergency Plan", when national secret information, important sensitive information and relevant educational rec...
Incident Response LevelsSecurity Incident ClassificationEmergency Response PlanningCyber Security Policy - Question #67Intrusion Prevention System (IPS) and Anti-DDoS
Which of the following is the correct ranking of the firewall DDoS attack prevention process? 1. The system performs preventive actions 2. Traffic exceeds the set threshold 3. Syst...
DDoS preventionattack defense processtraffic statisticsthreshold - Question #68Network Security Solution Design
The "Stuxnet" virus is a worm that attacks industrial control systems. Which of the following is the correct ranking of the Stuxnet virus attack process?
Stuxnet AttackReconnaissanceSocial EngineeringAttack Methodology - Question #69Security O&M and Management
On a Linux host, which of the following files can be viewed to count all user names and login methods in the current system?
Linux authenticationuser management/etc/passwdsystem configuration - Question #70Firewall Technologies and Deployment
Which of the following is not a URL matching method?
URL matching methodsWeb filteringFirewall rulesPattern matching - Question #71VPN Technologies
Which of the following is not a feature of ESP?
ESPIPSecdata encryptiondata integrity - Question #72Network Security Solution Design
The RADIUS protocol supports authentication, authorization and accounting functions. Which of the following messages does the RADIUS server issue authorization through?
RADIUS ProtocolAAAAccess-AcceptAuthorization - Question #73Network Security Solution Design
Huawei iMaster NCE-Campus can be used as an authentication server to authorize authenticated users. Which of the following is not an authorizable parameter of iMaster NCE-Campus?
Authentication & AuthorizationiMaster NCE-CampusNetwork Access ControlAuthorization Parameters - Question #74Network Security Solution Design
Which vulnerability in the TCP port does the "WannaCry" ransomware exploit to launch network attacks on Windows systems?
WannaCry ransomwareSMB vulnerabilityTCP port 445Windows network attacks - Question #75Firewall Technologies and Deployment
Which of the following descriptions about URL black and white lists is incorrect?
URL filteringblacklist/whitelist priorityaccess controlsecurity policy - Question #76VPN Technologies
Which of the following does not belong to the process of remote users accessing intranet resources through SSLVPN?
SSL VPNRemote AccessUser AuthenticationAccess Control - Question #77Firewall Technologies and Deployment
As shown in the figure, the firewall is active and backup in a backup network. By checking the HRP status on firewall A, the following information is obtained: Which of the followi...
HRP (High Reliability Protocol)Firewall redundancyHeartbeat communicationDual-machine hot backup - Question #78Intrusion Prevention System (IPS) and Anti-DDoS
The signature filter of IPS is a collection of signatures that meet specified filtering conditions. Which of the following does the signature filter's filter criteria not include?
IPS Signature FilteringThreat CategoryIntrusion DetectionSignature Management - Question #79Intrusion Prevention System (IPS) and Anti-DDoS
If an Anti-DDoS defense solution is deployed in the network, which of the following is not a necessary configuration of the management center?
Anti-DDoS ManagementManagement Center ConfigurationNetwork Defense ArchitectureTraffic Steering - Question #80Advanced Security Features
Which of the following descriptions of inbound traffic in the firewall virtual system is correct?
virtual systemsinbound traffictraffic directionsecurity policy - Question #81Network Security Solution Design
In the Portal authentication scenario, when iMaster NCE-Campus is used as the Portal server and the Huawei wireless controller is the access device, which of the following port num...
Portal AuthenticationWireless ControllerAAA ProtocolPort Configuration - Question #82Firewall Technologies and Deployment
There are two methods for processing MAC authentication user passwords: PAP and CHAP. When using the PAP method, the device arranges the MAC address, shared secret key, and random...
MAC authenticationPAP/CHAP protocolsMD5 hashingPassword attributes - Question #83Security O&M and Management
Huawei iMaster NCE-Cam p us is a Web-based centralized management and control system of the ClouCampus solution. It supports user access management and can serve as multiple types...
iMaster NCE-CampusAuthentication serversAccess managementServer types - Question #84Security O&M and Management
An enterprise uses high-end modular switches as core switches in its business network. Recently, a switching board of the modular switch failed, causing some business traffic to be...
equipment failure classificationsecurity event typesinfrastructure reliabilityfault management - Question #85Intrusion Prevention System (IPS) and Anti-DDoS
Which of the following does the filter condition of the IPS device signature filter not include?
IPS signature filteringfilter conditionssignature-based detectionnetwork security controls - Question #86Intrusion Prevention System (IPS) and Anti-DDoS
If an attacker forges a large number of users to launch a DDoS attack on a business server, which of the following is an effective measure for false source attacks?
DDoS PreventionSource AuthenticationIP SpoofingAnti-DDoS - Question #87Firewall Technologies and Deployment
For normal TCP packets, which of the following situations may occur in the flag bit?
TCP flagsThree-way handshakeProtocol fundamentalsNormal vs abnormal states - Question #88VPN Technologies
Mobile office users access the enterprise's internal Web server through a Web proxy. Which of the following descriptions is correct?
VPN gateway authenticationHTTPS/SSL encryptionSecure remote accessWeb proxy integration - Question #89Advanced Security Features
Which of the following descriptions of quota control strategies is incorrect?
quota control policybandwidth limitingtraffic detectiontraffic management - Question #90Network Security Solution Design
Which of the following descriptions about Eth-Trunk is incorrect?
Eth-TrunkLink AggregationLACP vs Manual ModeNetwork Redundancy - Question #91VPN Technologies
Which of the following is the function of Message1 and Message2 during the main mode negotiation in the first phase of IKEv1 negotiation?
IKEv1 main modeSecurity proposal negotiationPhase 1 negotiationKey exchange - Question #92VPN Technologies
Which of the following is not a method of IKE verifying remote peers?
IKE peer authenticationpre-shared keydigital certificatesVPN protocols - Question #93Security O&M and Management
When configuring the Portal page push policy on iMaster NCE-Campus, which of the following is not supported as a matching condition?
Portal authenticationPolicy matching conditionsCampus network managementAccess control - Question #94Advanced Security Features
In 802.1X authentication, in order to support the EAP relay mode, the RADIUS protocol adds some new attributes. Which of the following RADIUS attributes is used to encapsulate EAP...
802.1X AuthenticationRADIUS ProtocolEAP MessagesNetwork Access Control - Question #95Network Security Solution Design
The business form of an enterprise is complex, and multiple protocols are used to communicate between modules. In order to ensure the security of communication data and prevent thi...
Protocol SecurityHTTP vs HTTPSData EncryptionSecure Communication - Question #96Intrusion Prevention System (IPS) and Anti-DDoS
Which of the following is the correct ordering of Huawei's intrusion prevention feature configuration process?
signature database updateIPS configuration sequencethreat intelligence deploymentsecurity policy rollout - Question #97Intrusion Prevention System (IPS) and Anti-DDoS
Which of the following is a signature included in the intrusion prevention signature database?
IPS signaturespredefined signaturessignature databaseintrusion prevention - Question #98Security O&M and Management
Which of the following descriptions of black box testing in penetration testing is incorrect?
penetration testingblack box testingcode coveragetesting methodology - Question #99Firewall Technologies and Deployment
The keyword group "Keyword" is called in the content filtering configuration file on the firewall for the upload direction of HTTP applications. The action is blocking and is calle...
Content FilteringRegular ExpressionsFirewall PolicyHTTP Security - Question #100Intrusion Prevention System (IPS) and Anti-DDoS
Which of the following does not belong to the single packet attack type?
single packet attacksDoS attacksattack classificationnetwork security