[Jan-2022] H12-711 Certification with Actual Questions from Exam4Labs [Q84-Q102]

Share

[Jan-2022] H12-711  Certification with Actual Questions from Exam4Labs

Updated H12-711 Dumps PDF - H12-711 Real Valid Brain Dumps With 290 Questions!

NEW QUESTION 84
Which of the followingdescription about the VGMP protocol is wrong?

  • A. By default, when three HELLO packet cycle of Standby end does not receive HELLO packets which are sent from the opposite end, the opposite end will be considered a failure, which will switch itself to the Active state
  • B. VGMP ensure that all VRRP backup groups state are the same througha unified control of the switching of each VRRP backup group state
  • C. VGMP add multiple VRRP backup groups on the same firewall to a management group, uniformly manage all the VRRP group by management group.
  • D. State of VGMP group is active, which will periodically send HELLO packets to the opposite end.
    Stdandby end only monitors the HELLO packets, which will not respond

Answer: D

 

NEW QUESTION 85
On Huawei USG series devices, the administrator wants to erase the configuration file. Which of thefollowing commands is correct?

  • A. reset current-configuration
  • B. reset running-configuration
  • C. clear saved-configuration
  • D. reset saved-configuration

Answer: D

 

NEW QUESTION 86
Policy Center system can implement two dimensions' management functions: organizational management and regional management

  • A. False
  • B. True

Answer: B

 

NEW QUESTION 87
Which of the following is not the certificate save file format supported by the USG6000 series?

  • A. PEM
  • B. DER
  • C. PKCS#
  • D. PKCS#12

Answer: C

 

NEW QUESTION 88
Which of the following is correct for the command to view the number of security pclicy matches?

  • A. display firewall sesstiontable
  • B. display security-policy count
  • C. display security-policy all
  • D. count security-policy hit

Answer: C

 

NEW QUESTION 89
Use iptables to write a rule that does not allow the network segment of 172.16.0.0/16 to access the device. Which of the following rules is correct?

  • A. iptables -t filter -A INPUT -s 172.16.0.0/16 -p all -j DROP
  • B. iptables -t filter -P INPUT -s 172.16.0.0/16 -p all -j ACCEPT
  • C. iptables -t filter -P INPUT -s 172.16.0.0/16 -p all -j DROP
  • D. iptables -t filter -P INPUT -d 172.16.0.0/16 -p all -j ACCEPT

Answer: A

 

NEW QUESTION 90
ASPF (Application Specific Packet Filter) is a packet filtering technology based on the application layer, and implements a special security mechanism through the server-map table.
Which of the following statements about the ASPF and server-map tables are correct? (Multiple Choice)

  • A. The quintuple server-map entry implements a similar function to the session table.
  • B. ASPF monitors messages during communication
  • C. ASPF can dynamically create a server-map
  • D. ASPF dynamically allows multi-channel protocol data to pass through the server-map table.

Answer: B,C,D

 

NEW QUESTION 91
The Huawei Redundancy Protocol (HRP) is used to synchronize the main firewall configuration and connection status and other data on the backup firewall to synchronize . Whichof the following options is not in the scope of synchronization?

  • A. NAT policy
  • B. Blacklist
  • C. Security policy
  • D. IPS signature set

Answer: D

 

NEW QUESTION 92
In the security assessment method, the purpose ofthe security scan is to scan the target system with a scan analysis evaluation tool to discover related vulnerabilities and prepare for the attack.

  • A. False
  • B. True

Answer: A

 

NEW QUESTION 93
Which of the following options are suppoied by VPNtechnology to encrypt data messages? (Multiple choice)

  • A. IPSec VPN
  • B. SSL VPN
  • C. L2TP VPN
  • D. GRE VPN

Answer: A,B

 

NEW QUESTION 94
Which of the following descriptions of the firewall fragment cache function are correct? (Multiple choice)

  • A. After the fragmented packet is directly forwarded, the firewall forwards the fragment according to the interzone security policy if it is not the fragmented packet of the first packet.
  • B. For fragmented packets, NAT ALG does not support the processing of SIP fragmented packets.
  • C. By default, the number of large fragment caches of an IPV4 packet is 32, and the number of large fragmentation buffers of an IPV6 packet is 255.
  • D. By default, the firewall caches fragmented packets.

Answer: B,C,D

 

NEW QUESTION 95
What port numbers may be used by FTP protocol? (Choose two.)

  • A. 0
  • B. 1
  • C. 2
  • D. 3

Answer: B,D

 

NEW QUESTION 96
Which of the following description is correct about the sort of the call setup process for L2TP corridors?
1. L2TP tunnel
2. PPP connection
3. LNS authenticates users
4. Users access intranet resources
5. Establish an L2TP session

  • A. 1->5->3->2->4
  • B. 2->1->5->3->4
  • C. 1->2->3->5->4
  • D. 2->3->1->5->4

Answer: A

 

NEW QUESTION 97
In the first stage of IKE negotiation, which of the following IKE exchange mode does not provide identity protection features?

  • A. quick mode
  • B. Aggressive Mode
  • C. Main Mode
  • D. passive mode

Answer: B

 

NEW QUESTION 98
Which of the following description are correct about the security policy action and security configuration file? (Multiple Choice)

  • A. If the action of the security policy is "prohibited", the device will discard this traffic and will not perform content security check later.
  • B. The security configuration file can be applied without being applied to the security policy allowed by the action.
  • C. The security configuration file must be applied to the security policy that is allowed to take effect.
  • D. If the security policy action is "Allow", the traffic will not match the security configuration file.

Answer: A,C

 

NEW QUESTION 99
Which of the following can be supported by Policy Center access control? (Choose three.)

  • A. 802.1X
  • B. Hardware SACG (hardware security access control gateway)
  • C. Software SACG (host firewall)
  • D. ARP control

Answer: A,B,C

 

NEW QUESTION 100
IPSec VPN technology does not support NAT traversal when encapsulating with ESP security protocol, because ESP encrypts the packet header

  • A. False
  • B. True

Answer: A

 

NEW QUESTION 101
In the IPSec VPN transmission mode, which part of the data packet is encrypted?

  • A. New IP packet header
  • B. Transport layer and upper layer data packet
  • C. Network layer and upper layer data packet
  • D. Original IP packet header

Answer: B

 

NEW QUESTION 102
......

Pass Your H12-711 Exam Easily With 100% Exam Passing Guarantee: https://www.exam4labs.com/H12-711-practice-torrent.html