H12-725_V4.0 Exam Questions
518 real H12-725_V4.0 exam questions with expert-verified answers and explanations. Page 8 of 11.
- Question #354VPN Technologies
In the IPSec intelligent routing scenario, Huawei firewall supports link switching based on link quality detection.
IPSec intelligent routinglink quality detectionlink switchingWAN redundancy - Question #355Firewall Technologies and Deployment
Firewall bandwidth management can limit the number of service connections, which helps reduce the bandwidth occupied by the service and saves device session resources.
bandwidth managementconnection limitingsession resourcesQoS - Question #356Network Security Solution Design
Link-Group improves link reliability by binding multiple physical interfaces. When one interface fails, traffic is forwarded from other interfaces.
Link-Grouplink aggregationinterface bindinglink reliability - Question #357Advanced Security Features
When deploying Portal authentication, you need to configure an authentication-free template to ensure that the authentication terminal can open the Portal page normally. To achieve...
Portal authenticationauthentication-free policyDNS resolutionRADIUS - Question #358Security O&M and Management
Process troubleshooting is mainly used to check whether there are abnormal processes and determine whether the business host has been invaded, implanted with Trojans or backdoor pr...
process troubleshootingintrusion detectionTrojan detectionsecurity O&M - Question #359Advanced Security Features
Constructing wrong query statements and obtaining key information from the error prompts returned by the database is a common method for implementing SQL injection attacks.
SQL injectionerror-based injectiondatabase securityweb attack - Question #360Security O&M and Management
Habits such as keeping the browser version updated, paying attention to browser pop-ups and not actively visiting unknown websites can effectively prevent phishing attacks.
phishing preventionbrowser securitysocial engineeringsecurity awareness - Question #361Advanced Security Features
WAF can protect HTTPS traffic. Its implementation principle is to decrypt, filter, and re-encrypt messages through the public key, private key, and certificate chain uploaded to th...
WAFHTTPS inspectionSSL decryptioncertificate chain - Question #362Intrusion Prevention System (IPS) and Anti-DDoS
Special control message attack is a potential attack behavior that does not have direct destructive behavior. The attacker detects the network structure by sending special control...
special control message attackreconnaissancenetwork scanningattack preparation - Question #363VPN Technologies
The security association is uniquely identified by a triplet, including the security parameter index SPI, source IP address and security protocol number.
security associationSPIIPSec SAdestination IP address - Question #364VPN Technologies
The protocol number of AH protocol is 50.
AH protocolprotocol numbersIPSec headersESP vs AH - Question #365Network Security Solution Design
In order to improve the reliability of traffic forwarding, the ISP routing function can be used together with the health check function to ensure that traffic is not forwarded to f...
ISP routinghealth checklink reliabilitytraffic forwarding - Question #366Network Security Solution Design
In addition to detecting link connectivity, health check can also detect link delay, jitter and packet loss rate in real time. Reference health check and link quality indicators in...
health checklink qualityintelligent routingjitter and packet loss - Question #367Firewall Technologies and Deployment
Firewall virtual system allocates resources
virtual systemresource allocationfirewall virtualization - Question #368Advanced Security Features
AD domain authentication is an implementation method of LDAP authentication.
AD domain authenticationLDAPuser authenticationidentity management - Question #369Advanced Security Features
A Word document file.doc can be renamed to file.exe, but the firewall's file filtering mechanism can still identify the true type of the file.
file filteringcontent inspectionfile type identificationevasion detection - Question #370Intrusion Prevention System (IPS) and Anti-DDoS
BGP traffic diversion only supports manual traffic diversion.
BGP traffic diversionanti-DDoStraffic scrubbingautomatic diversion - Question #371Intrusion Prevention System (IPS) and Anti-DDoS
The difference between DoS attacks and DDoS attacks is that DoS attacks are usually initiated directly by the attacker, while DDoS attacks are usually initiated by the attacker con...
DoS attackDDoS attackbotnetattack classification - Question #372VPN Technologies
Endpoint security is SSL A method in VPN to check whether the terminal is safe, including host check when the user accesses the virtual gateway and cache clearing when the user exi...
SSL VPNendpoint securityhost checkcache clearing - Question #373VPN Technologies
When configuring the SSLVPN port forwarding function, the security policy only needs to allow traffic between Untrust and Trust.
SSL VPNport forwardingsecurity policyzone configuration - Question #374VPN Technologies
IPSec VPN does not support the encapsulation of non-IP unicast packets.
IPSec VPNnon-IP trafficunicast encapsulationGRE over IPSec - Question #375VPN Technologies
IPSec uses an asymmetric encryption algorithm to encrypt transmitted data.
IPSec encryptionsymmetric encryptionasymmetric encryptionIKE vs ESP - Question #376VPN Technologies
As shown in the figure, in this scenario, NAT traversal is enabled, and the security policy configuration of firewall B regarding NAT traversal is as follows. If other configuratio...
NAT traversalIPSec VPNsecurity policyUDP 4500 - Question #377VPN Technologies
In scenarios that require high reliability of IPSec services, it is recommended to enable the DPD detection function on the devices at both ends of the tunnel at the same time to e...
DPD detectionIPSec reliabilitytunnel failure detectiondead peer detection - Question #378Network Security Solution Design
After completing the configuration of policy routing intelligent routing, subsequent traffic passing through the firewall will be forwarded according to the routing policy. Some of...
policy routingintelligent routingsession agingtraffic forwarding - Question #379Network Security Solution Design
The smart DNS function needs to be used together with the NAT Server function and the source- in- source-out function.
smart DNSNAT Serversource-in-source-outDNS load balancing - Question #380Firewall Technologies and Deployment
When assigning interfaces to a virtual system, the management port cannot be assigned to the virtual system.
virtual systeminterface assignmentmanagement portVSYS - Question #381Firewall Technologies and Deployment
When allocating resources to a virtual system, some resources are a fixed number of resources that are automatically allocated according to system specifications and do not support...
virtual systemresource allocationsystem specificationsfixed resources - Question #382VPN Technologies
The figure shows the load balancing network. Firewall A and firewall B establish IPSec VPN tunnels with firewall C respectively. When a link failure occurs between firewall A and f...
IPSec VPNVRRPload balancinglink failover - Question #383Firewall Technologies and Deployment
When administrators create a firewall virtual system, they also need to create a VPN instance with the same name to isolate routes.
virtual systemVPN instanceroute isolationVSYS creation - Question #384Firewall Technologies and Deployment
Huawei firewall only supports bandwidth limitation in the outbound direction of the interface.
bandwidth limitationinterface directionQoStraffic shaping - Question #385Network Security Solution Design
In a multi-exit scenario, when there are multiple equal-cost routes or default routes to the destination network, the global route selection policy is matched. The firewall can dyn...
multi-exit routingequal-cost routesglobal route selectiontraffic steering - Question #386Network Security Solution Design
Policy routing is a mechanism that modifies entries in the routing table according to user-defined policies and then selects routes after the routing table has been generated.
policy routingrouting tablePBRroute selection - Question #387VPN Technologies
As shown in the figure, the firewalls at both ends establish GRE over IPSec. The original packet is first encapsulated by IPSec and then GRE encapsulated.
GRE over IPSecpacket encapsulationtunnel modeVPN encapsulation order - Question #388VPN Technologies
SSL VPN is based on B/S architecture and does not require client installation.
SSL VPNB/S architectureclientless VPNweb-based access - Question #389Intrusion Prevention System (IPS) and Anti-DDoS
The key to DDoS attack defense configuration is the reasonable configuration of the threshold. If the defense threshold is set too low, the system will activate the attack defense...
DDoS defensethreshold configurationattack detectiontraffic baseline - Question #390Intrusion Prevention System (IPS) and Anti-DDoS
If the attack frequency of ICMP Flood attacks does not exceed the reading value, the security device will not activate preventive measures.
ICMP Floodattack thresholdrate limitingDDoS prevention - Question #391Advanced Security Features
In firewall content filtering, keyword recognition can perform corresponding actions based on weight values.
content filteringkeyword recognitionweight-based filteringpolicy actions - Question #392Advanced Security Features
Content filtering includes file content filtering and application content filtering.
content filteringfile content filteringapplication content filteringDPI - Question #393Advanced Security Features
URL filtering is more granular than DNS filtering and can be controlled to the directory and file levels.
URL filteringDNS filteringweb filtering granularityaccess control - Question #394Advanced Security Features
When a POP3 or HAP message is detected, if it is determined to be an illegal email, the firewall's response action can only be to block the email.
email filteringPOP3IMAPresponse actions - Question #395Intrusion Prevention System (IPS) and Anti-DDoS
Port scanning technology is a technology that scans and detects the running status of the host. Through port scanning, you can determine what services are enabled on the target hos...
port scanningnetwork reconnaissanceservice enumerationattack preparation - Question #396Advanced Security Features
The security sandbox detects unknown malicious files by restoring the network traffic mirrored by switches or traditional security devices and detecting files transmitted on the ne...
security sandboxmalware detectionnetwork traffic mirroringunknown file analysis - Question #397Advanced Security Features
Since no corresponding patch has been released for zero-day vulnerabilities, there is currently no method that can effectively resist zero-day attacks.
zero-day vulnerabilitiesthreat mitigationsandbox defenseadvanced threats - Question #398Security O&M and Management
iMaster NCE Campus supports serving as a RADIUS server, but does not support serving as a RADIUS relay device.
iMaster NCE-CampusRADIUS serverAAAnetwork access control - Question #399Security O&M and Management
The second-party access device added to iMaster NCE-Campus supports connection using the TACACS protocol.
iMaster NCE-CampusTACACSthird-party device integrationAAA protocol - Question #400Network Security Solution Design
BFD control packets are encapsulated in TCP packets and transmitted, and their destination port number is 3784.
BFDUDP encapsulationcontrol plane protocolslink detection - Question #401Security O&M and Management
When configuring Portal page push policy on iMaster NCE-Campus, support using operating system and browser information as matching conditions. In order to implement iMaster NCE- Ca...
iMaster NCE-Campusportal authenticationURL templateOS browser identification - Question #402Security O&M and Management
Nmap is a commonly used network scanning and sniffing tool. It can scan and discover the open UDP or TCP ports of the target host, but it cannot determine what operating system the...
NmapOS fingerprintingport scanningnetwork reconnaissance - Question #403Intrusion Prevention System (IPS) and Anti-DDoS
Ping scanning is the most basic method of network scanning. Its advantages are simple operation, fast scanning, and support by most systems; its disadvantage is that it is easily r...
ping scanningICMPnetwork discoveryfirewall restriction