H12-725_V4.0 Exam Questions
518 real H12-725_V4.0 exam questions with expert-verified answers and explanations. Page 8 of 11.
- Question #354
In the IPSec intelligent routing scenario, Huawei firewall supports link switching based on link quality detection.
- Question #355
Firewall bandwidth management can limit the number of service connections, which helps reduce the bandwidth occupied by the service and saves device session resources.
- Question #356
Link-Group improves link reliability by binding multiple physical interfaces. When one interface fails, traffic is forwarded from other interfaces.
- Question #357
When deploying Portal authentication, you need to configure an authentication-free template to ensure that the authentication terminal can open the Portal page normally. To achieve...
- Question #358
Process troubleshooting is mainly used to check whether there are abnormal processes and determine whether the business host has been invaded, implanted with Trojans or backdoor pr...
- Question #359
Constructing wrong query statements and obtaining key information from the error prompts returned by the database is a common method for implementing SQL injection attacks.
- Question #360
Habits such as keeping the browser version updated, paying attention to browser pop-ups and not actively visiting unknown websites can effectively prevent phishing attacks.
- Question #361
WAF can protect HTTPS traffic. Its implementation principle is to decrypt, filter, and re-encrypt messages through the public key, private key, and certificate chain uploaded to th...
- Question #362
Special control message attack is a potential attack behavior that does not have direct destructive behavior. The attacker detects the network structure by sending special control...
- Question #363
The security association is uniquely identified by a triplet, including the security parameter index SPI, source IP address and security protocol number.
- Question #364
The protocol number of AH protocol is 50.
- Question #365
In order to improve the reliability of traffic forwarding, the ISP routing function can be used together with the health check function to ensure that traffic is not forwarded to f...
- Question #366
In addition to detecting link connectivity, health check can also detect link delay, jitter and packet loss rate in real time. Reference health check and link quality indicators in...
- Question #367
Firewall virtual system allocates resources
- Question #368
AD domain authentication is an implementation method of LDAP authentication.
- Question #369
A Word document file.doc can be renamed to file.exe, but the firewall's file filtering mechanism can still identify the true type of the file.
- Question #370
BGP traffic diversion only supports manual traffic diversion.
- Question #371
The difference between DoS attacks and DDoS attacks is that DoS attacks are usually initiated directly by the attacker, while DDoS attacks are usually initiated by the attacker con...
- Question #372
Endpoint security is SSL A method in VPN to check whether the terminal is safe, including host check when the user accesses the virtual gateway and cache clearing when the user exi...
- Question #373
When configuring the SSLVPN port forwarding function, the security policy only needs to allow traffic between Untrust and Trust.
- Question #374
IPSec VPN does not support the encapsulation of non-IP unicast packets.
- Question #375
IPSec uses an asymmetric encryption algorithm to encrypt transmitted data.
- Question #376
As shown in the figure, in this scenario, NAT traversal is enabled, and the security policy configuration of firewall B regarding NAT traversal is as follows. If other configuratio...
- Question #377
In scenarios that require high reliability of IPSec services, it is recommended to enable the DPD detection function on the devices at both ends of the tunnel at the same time to e...
- Question #378
After completing the configuration of policy routing intelligent routing, subsequent traffic passing through the firewall will be forwarded according to the routing policy. Some of...
- Question #379
The smart DNS function needs to be used together with the NAT Server function and the source- in- source-out function.
- Question #380
When assigning interfaces to a virtual system, the management port cannot be assigned to the virtual system.
- Question #381
When allocating resources to a virtual system, some resources are a fixed number of resources that are automatically allocated according to system specifications and do not support...
- Question #382
The figure shows the load balancing network. Firewall A and firewall B establish IPSec VPN tunnels with firewall C respectively. When a link failure occurs between firewall A and f...
- Question #383
When administrators create a firewall virtual system, they also need to create a VPN instance with the same name to isolate routes.
- Question #384
Huawei firewall only supports bandwidth limitation in the outbound direction of the interface.
- Question #385
In a multi-exit scenario, when there are multiple equal-cost routes or default routes to the destination network, the global route selection policy is matched. The firewall can dyn...
- Question #386
Policy routing is a mechanism that modifies entries in the routing table according to user-defined policies and then selects routes after the routing table has been generated.
- Question #387
As shown in the figure, the firewalls at both ends establish GRE over IPSec. The original packet is first encapsulated by IPSec and then GRE encapsulated.
- Question #388
SSL VPN is based on B/S architecture and does not require client installation.
- Question #389
The key to DDoS attack defense configuration is the reasonable configuration of the threshold. If the defense threshold is set too low, the system will activate the attack defense...
- Question #390
If the attack frequency of ICMP Flood attacks does not exceed the reading value, the security device will not activate preventive measures.
- Question #391
In firewall content filtering, keyword recognition can perform corresponding actions based on weight values.
- Question #392
Content filtering includes file content filtering and application content filtering.
- Question #393
URL filtering is more granular than DNS filtering and can be controlled to the directory and file levels.
- Question #394
When a POP3 or HAP message is detected, if it is determined to be an illegal email, the firewall's response action can only be to block the email.
- Question #395
Port scanning technology is a technology that scans and detects the running status of the host. Through port scanning, you can determine what services are enabled on the target hos...
- Question #396
The security sandbox detects unknown malicious files by restoring the network traffic mirrored by switches or traditional security devices and detecting files transmitted on the ne...
- Question #397
Since no corresponding patch has been released for zero-day vulnerabilities, there is currently no method that can effectively resist zero-day attacks.
- Question #398
iMaster NCE Campus supports serving as a RADIUS server, but does not support serving as a RADIUS relay device.
- Question #399
The second-party access device added to iMaster NCE-Campus supports connection using the TACACS protocol.
- Question #400
BFD control packets are encapsulated in TCP packets and transmitted, and their destination port number is 3784.
- Question #401
When configuring Portal page push policy on iMaster NCE-Campus, support using operating system and browser information as matching conditions. In order to implement iMaster NCE- Ca...
- Question #402
Nmap is a commonly used network scanning and sniffing tool. It can scan and discover the open UDP or TCP ports of the target host, but it cannot determine what operating system the...
- Question #403
Ping scanning is the most basic method of network scanning. Its advantages are simple operation, fast scanning, and support by most systems; its disadvantage is that it is easily r...