H12-725_V4.0 Exam Questions
518 real H12-725_V4.0 exam questions with expert-verified answers and explanations. Page 7 of 11.
- Question #304Firewall Technologies and Deployment
Virtual systems realize mutual access through virtual interfaces, and the link layer and protocol layer of the virtual interface are always Up.
virtual systemsvirtual interfaceslink layerprotocol layer - Question #305Firewall Technologies and Deployment
The firewall virtual system can not only isolate routing, but also achieve business isolation.
virtual systemsrouting isolationbusiness isolationfirewall - Question #306Advanced Security Features
In the face of applications such as P2P downloading and online video, the traditional method of limiting bandwidth is no longer able to cope with evasion solutions such as long-ter...
quota controlbandwidth managementP2P traffictraffic control - Question #307Advanced Security Features
In the same group of parent-child policies, the current limiting method can only be "set uplink and downlink bandwidth separately" or "set uplink and downlink total bandwidth" at t...
parent-child policiesbandwidth controluplink downlinktraffic policy - Question #308Network Security Solution Design
Deploying multiple links at the enterprise exit can improve the reliability of the user network.
link redundancynetwork reliabilityenterprise exitmulti-link - Question #309Network Security Solution Design
Policy routing can be associated with IP-Link or BFD to determine the availability of policy routing based on the status check results of IP-Link or BFD.
policy routingIP-LinkBFDavailability detection - Question #310VPN Technologies
IPSec VPN uses symmetric keys to encrypt business data.
IPSec VPNsymmetric encryptiondata encryptionVPN - Question #311VPN Technologies
In a point-to-multipoint scenario, and the headquarters address is fixed and the branch address is not fixed, it is recommended to use IPSec policy template method to establish VPN...
IPSec VPNpolicy templatepoint-to-multipointdynamic address - Question #312VPN Technologies
SSL VPN works between the transport layer and the network layer and does not change the IP header and TCP header.
SSL VPNtransport layernetwork layerprotocol stack - Question #313Intrusion Prevention System (IPS) and Anti-DDoS
When configuring policy routing traffic diversion, you need to configure it on both the traffic diversion device and the cleaning device.
traffic diversionDDoS cleaningpolicy routinganti-DDoS deployment - Question #314Advanced Security Features
File filtering not only identifies the type of files received, it can even filter based on the direction in which the files were transferred.
file filteringcontent inspectiontransfer directionfile type - Question #315Advanced Security Features
The application behavior control function of Huawei firewall can accurately control users' HTTP behavior, FTP behavior and IM behavior.
application behavior controlHTTP behaviorFTP behaviorIM control - Question #316Security O&M and Management
A Linux host has deployed an Nginx application. By viewing Nginx related logs, the operation and maintenance engineer can obtain the complete URL information submitted by the user,...
SQL injectionlog analysisNginxattack detection - Question #317Advanced Security Features
Enterprises deploy access control technology to control the behavior of employees, but cannot control the behavior of visitors.
access controlvisitor managementemployee controlnetwork access - Question #318Security O&M and Management
When configuring a third-party access device on iMaster NCE-Campus, the authentication and accounting key, authorization key, terminal IP address list, etc. need to be configured i...
RADIUS authenticationiMaster NCE-Campusthird-party deviceAAA - Question #319Firewall Technologies and Deployment
As shown in the figure, the firewall dual-machine hot backup load is deployed uniformly. For the Trust: area, two VRPP backup groups need to be deployed. One group has firewall A a...
dual-machine hot backupVRRPload balancingfirewall redundancy - Question #320Firewall Technologies and Deployment
For multi-level policies, the firewall first matches the parent policy, and then matches the sub- policy until it matches the sub-policy that can be matched at the last level.
multi-level policiesparent policysub-policypolicy matching - Question #321VPN Technologies
When GRE over IPSec is used to connect between gateways, the IPSec encapsulation mode can only be tunnel mode.
GRE over IPSectunnel modetransport modeencapsulation - Question #322VPN Technologies
As shown in the figure, if firewall A actively initiates IKE negotiation, you only need to configure the security policy on firewall A, and no configuration is required on firewall...
IKE negotiationsecurity policyIPSecbidirectional configuration - Question #323Advanced Security Features
The predefined URL categories in Huawei firewall are preset categories that come with the factory and do not require users to manually load them.
URL filteringpredefined categoriesHuawei firewallcontent filtering - Question #324Intrusion Prevention System (IPS) and Anti-DDoS
IPS devices can intercept viruses, Trojans or malicious codes that exploit unknown vulnerabilities to spread and attack, and protect key office data such as privacy, identity, and...
IPS capabilitiesmalware detectionunknown vulnerabilitiesintrusion prevention - Question #325Network Security Solution Design
When responding to network attacks, it is only necessary to deploy security devices (such as firewalls, IPS, etc.) at the Internet exit. There is no need to deploy security devices...
defense in depthsecurity deploymentnetwork security architectureintranet security - Question #326Advanced Security Features
If 802.1x authentication is used, the user needs to install the client or use the system's own client to initiate 802.1x authentication.
802.1Xnetwork access controlauthentication clientport-based authentication - Question #327VPN Technologies
In IPSec VPN transmission mode, neither AH nor ESP supports NAT traversal.
IPSecNAT traversalAH protocolESP protocol - Question #328Security O&M and Management
When configuring authorization rules on iMaster NCE-Campus, multiple authentication methods are supported, including: user access authentication, HAC authentication, and device man...
iMaster NCE-Campusauthorization rulesHAC authenticationauthentication methods - Question #329Advanced Security Features
The 802.1X protocol is a port-based network access control protocol. Its authentication messages and data messages can be separated through logical interfaces to improve security.
802.1Xport-based access controlauthentication separationlogical interfaces - Question #330Intrusion Prevention System (IPS) and Anti-DDoS
SYN scanning technology generally does not leave scanning traces on the target host, and does not require root privileges of the target host.
SYN scanningport scanningnetwork reconnaissancestealth scanning - Question #331Intrusion Prevention System (IPS) and Anti-DDoS
The SYN Flood attack mainly achieves the purpose of denial of service by initiating large-traffic access and consuming network bandwidth.
SYN FloodDoS attackTCP handshake exhaustionconnection table - Question #332Intrusion Prevention System (IPS) and Anti-DDoS
Anti-DDoS detection center supports traffic detection technology based on Netflow.
Anti-DDoSNetflowtraffic detectionflow analysis - Question #333Firewall Technologies and Deployment
In a dual-machine hot standby network, in order to ensure the consistency of link switching, Huawei firewall implements device status management based on VGMP groups.
dual-machine hot standbyVGMPhigh availabilityfirewall clustering - Question #334Advanced Security Features
In the access authentication scheme, authorization information is divided into two categories: authorization information issued by the server and authorization information under th...
authorization schemeAAAaccess authenticationserver authorization - Question #335Security O&M and Management
iMaster NCE-Campus has a built-in LDAP module, which can be used as an LDAP server and supports connection with access devices through the LDAP protocol.
iMaster NCE-CampusLDAPauthentication serverdirectory services - Question #336Firewall Technologies and Deployment
The virtual system administrator of the firewall can only enter the configuration interface of the virtual system to which it belongs, and the services that can be configured and v...
virtual systemVSYSadministrator rolesprivilege isolation - Question #337Intrusion Prevention System (IPS) and Anti-DDoS
The signature filter of IPS is a set of conditions for a series of signatures. Any signature that meets one of the filter conditions can match the signature filter.
IPS signature filtersignature matchingfilter conditionsIPS configuration - Question #338Firewall Technologies and Deployment
Even if the firewall is configured with content filtering, if it is not referenced correctly in the security policy, content that should be blocked can still be transmitted normall...
content filteringsecurity policyfirewall configurationpolicy reference - Question #339Advanced Security Features
The remote query server provides larger URL classification information. If the URL classification cannot be queried in the predefined URL classification cache, you can continue the...
URL filteringURL classificationremote query serverpredefined cache - Question #340Advanced Security Features
Turn on the email filtering function to detect viruses carried in emails.
email filteringantiviruscontent inspectionsecurity feature scope - Question #341Intrusion Prevention System (IPS) and Anti-DDoS
DDoS attack is a distributed DoS attack.
DDoSdistributed denial of serviceDoS attack typesattack classification - Question #342Intrusion Prevention System (IPS) and Anti-DDoS
When deploying an Anti-DDoS defense system in a straight line, reliability needs to be considered to prevent single points of failure.
Anti-DDoS deploymentinline deploymentsingle point of failurehigh availability - Question #343Intrusion Prevention System (IPS) and Anti-DDoS
UDP Flood attack initiates large traffic access and occupies protocol stack resources, thereby achieving the purpose of the server refusing to provide services to normal users.
UDP FloodDoS attackprotocol stack resourcesservice denial - Question #344Intrusion Prevention System (IPS) and Anti-DDoS
When configuring DDoS attack defense, you need to configure defense thresholds for various attacks. This threshold can be regarded as the upper limit of normal traffic in the netwo...
DDoS defenseattack thresholdtraffic anomaly detectionfirewall configuration - Question #345VPN Technologies
SSLVPN users can support login without authentication.
SSL VPNuser authenticationaccess control - Question #346VPN Technologies
As shown in the figure, in this scenario, both communicating parties (ie, firewall A and firewall B) need to enable NAT traversal.
NAT traversalIPSec VPNNAT-Tsite-to-site VPN - Question #347Firewall Technologies and Deployment
Administrators need to make reasonable calculations when allocating resources to the firewall virtual system. This avoids the situation where a virtual system occupies too many res...
virtual systemresource allocationfirewall virtualization - Question #348Intrusion Prevention System (IPS) and Anti-DDoS
If IPS equipment adopts Layer 2 bypass detection deployment method, it can only monitor business traffic and cannot achieve real-time protection.
IPS deploymentLayer 2 bypassinline vs bypassreal-time protection - Question #349Advanced Security Features
URL filtering can perform better access control than DNS filtering, effectively reducing the traffic of HTTP messages on the entire network.
URL filteringDNS filteringHTTP trafficaccess control comparison - Question #350Advanced Security Features
Email content filtering can not only filter out anonymous emails, but also control the permissions of intranet users to send or receive emails by checking the email content.
email content filteringanonymous emailintranet email control - Question #351Advanced Security Features
In addition to affecting normal email reading, spam may also contain viruses and other harmful information.
spamemail securitymalwarevirus - Question #352Intrusion Prevention System (IPS) and Anti-DDoS
Single packet attacks, DoS and DDoS attacks can all cause denial of service.
single packet attackDoSDDoSdenial of service - Question #353VPN Technologies
Relative to IPSec network layer control, SSL All VPN access control is based on the application layer, and its level of subdivision can reach the URL or file level, which can great...
SSL VPNIPSec VPNapplication layer controlURL-level access