H12-725_V4.0 Exam Questions
518 real H12-725_V4.0 exam questions with expert-verified answers and explanations. Page 3 of 11.
- Question #101Intrusion Prevention System (IPS) and Anti-DDoS
Which of the following is not a malformed message attack?
malformed messagesWinNukeICMP attacksIP spoofing - Question #102Intrusion Prevention System (IPS) and Anti-DDoS
A certain enterprise's network is as shown in the figure. Which of the following is a suitable reinjection method?
traffic reinjectionrouting methodsnetwork security architectureIPS deployment - Question #103Network Security Solution Design
Which of the following descriptions of Web rewriting in Web proxies is incorrect?
web rewritingweb proxiesproxy mechanismscontent modification - Question #104VPN Technologies
The entire IPSec protocol framework contains multiple protocols. Which of the following protocols does not belong to the IPSec protocol framework?
IPSec frameworkIKEAHESP - Question #105VPN Technologies
If the IPSec security protocols supported by both peers are inconsistent, which of the following consequences will result?
IPSec protocolsSA establishmentPeer negotiationProtocol consistency - Question #106VPN Technologies
ESP (Encapsulating Security Payload) is a protocol of IPSec that is used to provide confidentiality and anti-replay services for IP, including confidentiality of data packet conten...
ESPIPSecProtocol numbersVPN - Question #107VPN Technologies
IKEv1 negotiation phase 1 supports two negotiation modes. How many bidirectional exchanges does the main mode include?
IKEv1Main ModePhase 1Key Exchange - Question #108Firewall Technologies and Deployment
Which of the following descriptions of health examinations is incorrect?
Health CheckPolicy RoutingNetwork ConnectivityFirewall Monitoring - Question #109Firewall Technologies and Deployment
Which of the following descriptions about firewall session persistence is incorrect?
Session PersistenceFirewall Load BalancingHigh AvailabilitySession State Management - Question #110Firewall Technologies and Deployment
Which of the following is the correct user name format for a firewall virtual system?
virtual systemusername formatfirewall administrationauthentication - Question #111Intrusion Prevention System (IPS) and Anti-DDoS
Which of the following descriptions of source detection technology is incorrect?
DDoS attack detectionSource IP verificationUDP FloodAttack mitigation - Question #112Network Security Solution Design
As shown in the figure below, the administrator has performed the configuration related to Protall authentication on the network access device. Which of the following authenticatio...
Protall authenticationPortal protocolNetwork access controlAuthentication methods - Question #113VPN Technologies
Which of the following descriptions of the AH and ESP protocols is correct?
IPsecAH and ESP protocolsAuthentication mechanismsCryptographic verification - Question #114VPN Technologies
In SSL VPN, the firewall performs access authorization and access control based on which of the following dimensions?
SSL VPNRole-Based Access ControlFirewall AuthorizationAccess Control - Question #115Intrusion Prevention System (IPS) and Anti-DDoS
If the regular expression is "abc.de", which of the following will not match the regular expression?
regex metacharacterspattern matchingdot operatorstring matching - Question #116VPN Technologies
In IPSec, if the Security ACL does not match the actual data flow to be protected, which of the following consequences will occur?
IPSecSecurity ACLIKE negotiationTraffic matching - Question #117Intrusion Prevention System (IPS) and Anti-DDoS
Which of the following DDoS attack types can be prevented by current limiting technology?
DDoS Attack MitigationRate LimitingICMP FloodNetwork Layer Defense - Question #118Firewall Technologies and Deployment
Which of the following descriptions of the file filtering process is correct?
file filteringcompressed filescontent inspectionfirewall detection - Question #119Firewall Technologies and Deployment
Firewall application behavior control technology cannot control which of the following application behaviors?
Application Behavior Control (ABC)SSH EncryptionProtocol InspectionFirewall Application Layer - Question #120Network Security Solution Design
Which of the following attacks uses return timeout messages with a TTL of 0 to spy on the structure of the target network?
traceroute-attackTTL-based-reconnaissanceICMP-timeout-messagesnetwork-topology-discovery - Question #121Network Security Solution Design
In order to prevent internal employees from making inappropriate remarks on the Internet, which of the following content security filtering technologies can be deployed on fire pre...
content filteringweb security policyemployee monitoringdata protection - Question #123Firewall Technologies and Deployment
In a virtual system, which of the following ownership relationships is recorded in the traffic diversion table?
virtual systemstraffic diversionIP routingfirewall tables - Question #124VPN Technologies
After NAT traversal is enabled, when a NAT device is detected between two gateways, the ESP message will be encapsulated in a UDP header. Which of the following is the source and d...
NAT TraversalIPsec ESPUDP Port 4500NAT-T - Question #125Network Security Solution Design
Which of the following tools is commonly used for port scanning during penetration testing?
Port ScanningPenetration TestingNmapNetwork Reconnaissance - Question #126Advanced Security Features
Which of the following descriptions about the difference between web link and web rewriting is incorrect?
Web LinkWeb RewritingEncryptionTraffic Forwarding - Question #127Firewall Technologies and Deployment
Which of the following descriptions about firewall bandwidth policies is correct?
Bandwidth ManagementSource NATFirewall PoliciesPolicy Hierarchy - Question #128Firewall Technologies and Deployment
Which of the following is not a matching condition for policy routing?
Policy RoutingMatching ConditionsTraffic ClassificationFirewall Rules - Question #129VPN Technologies
Which of the following commands can display the IPSec SA negotiation results and IPSec policy configuration information?
IPSec SAVPN CommandsIKE vs IPSecPolicy Configuration - Question #130VPN Technologies
As shown in the figure, FW_A establishes an IPSec tunnel with FW_B, and executes the display ike sa command on FW_A. The following information is obtained: < FW A > display ike sa...
IPSec Phase 1 (IKE)Tunnel negotiationTroubleshootingAccess lists - Question #131Network Security Solution Design
In the 802.1x authentication scenario of a certain WLAN network, the authorized static ACL configuration on the authentication device is as follows. Which of the following network...
802.1x AuthenticationACL ConfigurationNetwork Access ControlWLAN Security - Question #132Firewall Technologies and Deployment
Which of the following parameters cannot be configured in the bandwidth channel of the firewall?
bandwidth channelsQoS configurationconnection limitsfirewall parameters - Question #133VPN Technologies
Which of the following is not a parameter that needs to be configured for the IKE security proposal? (Multiple choice)
IKESecurity ProposalIPsec Phase 1VPN Configuration - Question #135Firewall Technologies and Deployment
Which of the following functions are virtualization that can be achieved by firewalls? (Multiple choice)
Firewall virtualizationRouting virtualizationResource virtualizationSecurity function virtualization - Question #136VPN Technologies
Which of the following descriptions of virtual systems and VPN instances are correct? (Multiple choice)
VPN InstancesVirtual SystemsNetwork IsolationRouting Isolation - Question #137VPN Technologies
IPSec VPN ensures the safe transmission of user business data on the Internet through which of the following aspects? (Multiple choice)
IPSec VPNEncryption & ConfidentialityAuthentication & Identity VerificationReplay Protection - Question #138VPN Technologies
In IPSec networking, which of the following scenarios are policy templates suitable for? (Multiple choice)
IPSec Policy TemplatesVPN TopologyFixed/Variable AddressesTemplate Suitability - Question #139Intrusion Prevention System (IPS) and Anti-DDoS
Which of the following descriptions of the Anti-DDoS solution networking mode are correct? (Multiple choice)
Anti-DDoS deployment modesbypass architecturetraffic diversionscrubbing center - Question #140Intrusion Prevention System (IPS) and Anti-DDoS
Which of the following are traffic-based attacks? (Multiple choice)
DoS/DDoS attackstraffic-based attacksattack classificationnetwork threats - Question #141Firewall Technologies and Deployment
Which control items of HTTP can a firewall control? (Multiple choice)
HTTP filteringfirewall capabilitiescontent inspectionproxy functionality - Question #142Firewall Technologies and Deployment
Which of the following email security protection functions does Huawei firewall support? (Multiple choice)
email securityfirewall featurescontent filteringthreat protection - Question #143Intrusion Prevention System (IPS) and Anti-DDoS
In Huawei IPS equipment, which of the following are the working modes of the physical interface? (Multiple choice)
IPS interface modesExchange modeRouting modeBypass detection - Question #144Intrusion Prevention System (IPS) and Anti-DDoS
Which of the following categories can IPS signature objects be divided into? (Multiple choice)
IPS SignaturesSignature ClassificationClient-Server ArchitectureNetwork Traffic Analysis - Question #145Intrusion Prevention System (IPS) and Anti-DDoS
Which of the following descriptions of Huawei IPS deployment methods are incorrect? (Multiple choice)
IPS deployment modesbypass detection limitationstraffic control vs detectioninline vs bypass - Question #146Security O&M and Management
A customer's current network uses Huawei wireless controllers to deploy Portal authentication. During the debugging process, engineers found that the terminal has been unable to su...
Portal authenticationwireless controllerNAC troubleshootingPortal server - Question #147Advanced Security Features
802.1X authentication is a port-based network access control protocol, which verifies user identity and controls access rights at the port level of the access device. Which of the...
802.1XEAPoL-Startport-based access controlauthentication triggers - Question #148Advanced Security Features
NAC (Network Access Control) is an "end-to-end" security technology that needs to cooperate with AAA to jointly realize the access authentication function. Which of the following d...
NACAAA802.1X authenticationMAC authentication - Question #149Advanced Security Features
RADIUS supports the use of PAP and CHAP methods to verify user identity information. Which of the following descriptions of the CHAP method are correct? (Multiple choice)
RADIUSCHAPPAPauthentication protocol - Question #150Network Security Solution Design
Which of the following descriptions of BFD characteristics are correct? (Multiple choice)
BFDdetection mechanismsession establishmentcontrol packets - Question #151Firewall Technologies and Deployment
Which of the following resources are manually allocated to the virtual system? (Multiple choice)
virtual systemresource allocationVLANinterface management - Question #152Network Security Solution Design
As shown in the figure, the scenario is that an external network user accesses an internal server. Which of the following descriptions of this scenario are correct? (Multiple choic...
ISP routingmulti-ISPDNS resolutionnetwork access