[Jan 15, 2022] Free HCIA-Security H12-711_V3.0-ENU Exam Question H12-711_V3.0-ENU dumps HCIA-Security sure practice dumps NEW QUESTION 109 Regarding the description of firewall dual-system hot backup, which of the following options are correct? (Multiple Choice) A. The firewall dual-system hot backup needs to synchronize the backup of the session table, MAC table, routing table and other information [...]

[Jan 15, 2022] Free HCIA-Security H12-711_V3.0-ENU Exam Question [Q109-Q128]

Share

[Jan 15, 2022] Free HCIA-Security H12-711_V3.0-ENU Exam Question

H12-711_V3.0-ENU dumps & HCIA-Security sure practice dumps

NEW QUESTION 109
Regarding the description of firewall dual-system hot backup, which of the following options are correct? (Multiple Choice)

  • A. The firewall dual-system hot backup needs to synchronize the backup of the session table, MAC table, routing table and other information between the master device and the slave device
  • B. The state of all VRRP backup groups of the same VGMP management group on the same firewall is required to be consistent
  • C. VGMP is used to ensure the consistency of all VRRP backup group switching
  • D. When multiple areas on the firewall need to provide dual-system backup, multiple VRRP backup groups need to be configured on the firewall

Answer: B,C,D

 

NEW QUESTION 110
Equipment sabotage attacks are generally not easy to cause information leakage, but usually cause the interruption of network communication services.

  • A. True
  • B. False

Answer: A

 

NEW QUESTION 111
Which of the following is not a requirement for firewall dual-machine hot backup?

  • A. The firewall hardware models are consistent
  • B. The firewall interface IP addresses are consistent
  • C. The firewall software version is consistent
  • D. The interface type and number used are consistent

Answer: B

 

NEW QUESTION 112
Regarding the control actions permit and deny of the firewall inter-domain forwarding security policy, which of the following options are correct? (Multiple choice)

  • A. No matter whether the packet is a permit action or a deny action that matches the security policy, it will be transferred to the UTM module for processing
  • B. Even if the data packet matches the permit action of the security policy, it will not necessarily be forwarded by the firewall
  • C. After the packet matches the deny action of the inter-domain security policy, the packet is immediately discarded, and other inter-domain security policies will not continue to be executed
  • D. The default security policy action of the firewall is denied

Answer: B,C,D

 

NEW QUESTION 113
When configuring a security policy, a security policy can reference the address set or configure multiple destination IP addresses.

  • A. True
  • B. False

Answer: A

 

NEW QUESTION 114
When configuring NAT Server on the USG Series Firewall, a Server-Map table is generated. Which item below does not belong to content in this performance?

  • A. Source IP
  • B. Destination IP
  • C. Destination port number
  • D. Agreement number

Answer: A

 

NEW QUESTION 115
Which attack below is not a malformated packet attack?

  • A. TEARDROP attack
  • B. ICMP unreachable message attack
  • C. Smurf attack
  • D. TCP shard attack

Answer: B

 

NEW QUESTION 116
Digital certificate technology solves the problem that the owner of the public key cannot be determined in digital signature technology

  • A. True
  • B. False

Answer: A

 

NEW QUESTION 117
Please sort the following project implementation steps from the start of the project.

Answer:

Explanation:

 

NEW QUESTION 118
After the firewall detects the virus, which of the following will release the virus?

  • A. Protocol not supported by firewall
  • B. Hit application exception
  • C. Hit virus exception
  • D. Source IP hits the whitelist

Answer: C

 

NEW QUESTION 119
According to the logical structure of the HiSec solution, please drag the hierarchy of HiSec solutions on the left to the box on the right and arrange them in order from top to bottom.

Answer:

Explanation:

 

NEW QUESTION 120
Regarding the description of the risk assessment, which of the following options is wrong?

  • A. Risk assessment needs to identify threats, vulnerabilities, and scan for security vulnerabilities.
  • B. Risk assessment requires operation of monitoring system.
  • C. Risk assessment requires training in asset collection and risk assessment methods.
  • D. Risk assessment requires assessment of risks and classification of risk levels.

Answer: B

 

NEW QUESTION 121
Regarding single sign on, which of the following statements are correct? (Multiple Choice)

  • A. The device can identify users who have passed the authentication by the identity authentication system
  • B. AD domain single sign on can be synchronized to the firewall by mirroring the login data stream
  • C. There is only one deployment mode for AD domain single sign on
  • D. Although there is no need to enter the user password, the authentication server needs to interact with the user password and the device to ensure that the authentication is passed

Answer: A,B

 

NEW QUESTION 122
Which of the following options belong to the same characteristics of windows system and LINUX system? (Multiple choice)

  • A. Support multitasking
  • B. Open-source system
  • C. Support multiple terminal platforms
  • D. Support graphical interface operation

Answer: A,C,D

 

NEW QUESTION 123
If internal employees access the Internet through a firewall and find that they cannot connect to the Internet normally, which view commands can be used on the firewall to troubleshoot the interface state security zone, security policy, and routing table? (Write any view command, require: command line The words must be complete and correct to score, and cannot be omitted or abbreviated)

  • A. display ip routing-table display zone

Answer: A

 

NEW QUESTION 124
Which of the following options belongs to the Layer 2 VPN technology?

  • A. IPSec VPN
  • B. SSL VPN
  • C. GRE VPN
  • D. L2TP VPN

Answer: D

 

NEW QUESTION 125
Regarding the description of IP Spoofing, which of the following is wrong?

  • A. IP spoofing attacks are launched by using the normal IP address-based trust relationship between hosts
  • B. The attacker needs to disguise the source IP address as a trusted host and send a data segment marked with SYN to request a connection
  • C. Hosts in a trust relationship based on IP addresses can log in directly without entering password verification
  • D. After an IP spoofing attack is successful, the attacker can use any forged IP address to imitate a legitimate host to access key information

Answer: B

 

NEW QUESTION 126
The matching principle of the security policy is: first search for the manually configured inter-domain security policy, if it does not match, then directly discard the data packet.

  • A. True
  • B. False

Answer: A

 

NEW QUESTION 127
Regarding the description of the advanced settings of the windows firewall, which of the following options are wrong? (Multiple choice)

  • A. When setting the popstack rules, only the local port can be restricted, but the remote port cannot be restricted
  • B. When setting the popstack rules, both the local port and the remote port can be restricted
  • C. When setting the pushstack rules, only the local port can be restricted, but the remote port cannot be restricted
  • D. When setting the pushstack rules, both the local port and the remote port can be restricted

Answer: B,D

 

NEW QUESTION 128
......

Huawei H12-711_V3.0-ENU Actual Questions and Braindumps: https://www.braindumpsvce.com/H12-711_V3.0-ENU_exam-dumps-torrent.html