Verified H12-721 exam dumps Q&As with Correct 180 Questions and Answers [Q62-Q87]

Share

Verified H12-721 exam dumps Q&As with Correct 180 Questions and Answers

Huawei H12-721 Test Engine PDF - All Free Dumps from Prep4King


Huawei H12-721 Exam Syllabus Topics:

TopicDetails
Topic 1
  • Firewall Intelligent Routing
  • VPN Technology And Application
  • Intelligent Routing Application Analysis
Topic 2
  • Ipsec VPN Technology And Application
  • SSL VPN Technology And Application
  • Firewall High Availability
Topic 3
  • Server Load Balancing
  • IP-Link Technology
  • SLB Deployment
  • Network Security
  • BFD Technology
Topic 4
  • Principle Of Firewall Bandwidth Management
  • Principles Of Intelligent Routing
  • Network Security Device Management
Topic 5
  • Network Security Device Management, Device Log Analysis
  • Principles Of SLB Technology
Topic 6
  • Firewall High Availability, VPN Technology And Application, Firewall Bandwidth Management And Virtual Firewall Technology
Topic 7
  • Firewall Bandwidth Management Troubleshooting
  • Firewall Bandwidth Management Deployment
  • Firewall Virtual System

 

NEW QUESTION 62
What is the correct statement about the Eth-trunk function?

  • A. Improve data security
  • B. traffic load sharing
  • C. Improve the reliability of the link
  • D. Improve the communication bandwidth of the link

Answer: B,C,D

 

NEW QUESTION 63
If the IP address of one of the parties establishing the IPSec VPN tunnel is not fixed, which of the following configuration methods cannot be applied in this scenario?

  • A. Name authentication in aggressive mode
  • B. Specify the peer address when configuring IKE
  • C. Strategy template
  • D. Pre-share key authentication in aggressive mode

Answer: B

 

NEW QUESTION 64
Which of the following statements is true for virtual service technology?

  • A. For multiple real servers, the real servers need to be in the same network segment and in the same security zone.
  • B. For multiple real servers, the real server may not be in the same security zone, but must be in the same network segment
  • C. For multiple real servers, the real servers may not be in the same network segment, but they must be in the same security zone.
  • D. For multiple real servers, the network segment and security zone where the real server is located does not affect the load balancing function.

Answer: A

 

NEW QUESTION 65
As shown below, for the L2TP over IPsec scenarios, the following configuration shows how to protect data on the IPsec flow. Which one is correct?

  • A. [LNS] acl number 3001
    [LNS-acl-adv-3001] rule permit tcp source-port 1701
  • B. [LNS] acl number 3001
    [LNS-acl-adv-3001] rule permit udp source-port eq 1701
  • C. [LNS] acl number 2001
    [LNS-acl-basic-2001] rule permit udp source 10.10.1.0 0.0.0.255
  • D. [LNS] acl number 3001
    [LNS-acl-adv-3001] rule permit source 10.10.1.0 0.0.0.255 destination 10.10.2.0 0.0.0.255

Answer: B

 

NEW QUESTION 66
USG device can be factory reset by holding down the Reset button for 1-3 seconds to recover the console password.

  • A. FALSE
  • B. TRUE

Answer: A

 

NEW QUESTION 67
IPsec VPN using digital certificates for authentication has the following steps:
1 . Certificate signature verification
2 . Find the certificate serial number in the CRL
3 . Both devices share their entity certificate
4 . Verify the certificate is valid
5 . Establish a VPN tunnel
Which of the following is the correct pattern?

  • A. 1-3-2-4-5
  • B. 3-1-4-2-5
  • C. 2-4-3-1-5
  • D. 3-2-1-4-5

Answer: B

 

NEW QUESTION 68
After enabled session retention, the traffic is intelligently routed for the first time. After an interface link is selected, the Huawei USG6000 firewall generates a corresponding session retention entry. If new traffic matches the session retention entry, then forward traffic according to the outbound interface recorded in the entry. So that the user's traffic is always forwarded using the same interface link. Which of the following options does not include the parameters recorded in the session retention entry?

  • A. Outbound interface
  • B. Destination address
  • C. Source address
  • D. Next hop address

Answer: D

 

NEW QUESTION 69
Regarding the Radius authentication process, refer to the following steps:
1. Network device Radius client (network access server) receives the user name and password, and sends an authentication request to the Radius server.
2. When a user logs into the USG access servers and other network devices, the user name and password will be sent to the network access server.
3. After the Radius server receives a valid request to complete the request and the required user authorization information is sent back to the client.
Which of the following is a correct sequence?

  • A. 3-2-1
  • B. 1-2-3
  • C. 2-3-1
  • D. 2-1-3

Answer: D

 

NEW QUESTION 70
In Hot standby, the backup channel must be the primary interface to the interface board.
Which type is not supported?

  • A. GigabitEthernet
  • B. vlan-if
  • C. E1
  • D. Ethernet

Answer: C

 

NEW QUESTION 71
The following figure shows the data packets captured during the pre-shared key mode master mode exchange process in the first phase of IKE V1. Which packet is captured below?

  • A. IKE seventh message or eighth message
  • B. IKE first message or second message
  • C. IKE third message or fourth message
  • D. IKE fifth message or sixth message

Answer: B

 

NEW QUESTION 72
In Defense gate FIN / RST Flood attack method, conversation is checked. The workflow is that when the door FIN / RST packet rate exceeds the threshold; it discards packets, and then starts the conversation check.

  • A. FALSE
  • B. TRUE

Answer: B

 

NEW QUESTION 73
With HRP technology, all configuration information of the standby firewall can be synchronized by the main firewall through HRP. No configuration is required, and configuration information is not lost after the restart.

  • A. True
  • B. False

Answer: B

 

NEW QUESTION 74
In the system view of the USG, you need to delete the sslconfig.cfg file in the hda1:/ directory. Which of the following commands can complete this operation?

  • A. cd: hda1:/ mkdir sslconfig.cfg
  • B. cd: hda1:/ remove sslconfig.cfg
  • C. cd: hda1:/ delete sslconfig.cfg
  • D. cd: hda1:/ rmdir sslconfig.cfg

Answer: C

 

NEW QUESTION 75
Which of the following statements are true about Link-group? (Choose two answers)

  • A. The support interface state management across the interface board
  • B. It supports hot-swappable interface board
  • C. It provides support for remote management interface status
  • D. The cross-switch interface supports state management

Answer: A,B

 

NEW QUESTION 76
In the Enterprise netowrk shown below, Server A and Server B can not access Web services. Troubleshooting has found that there is firewall routing module and that there is a problem with the routing table in USG_A.
An enterprise network follows, then Server A Server B can not access Web services, administrators troubleshoot and found no firewall routing module A problem has been to establish the appropriate routing table, but Firewall A firewall module is provided with wrong.

What troubleshooting method should be used?

  • A. substitution method
  • B. Break Law
  • C. Block Method
  • D. stratification

Answer: C

 

NEW QUESTION 77
71. Which option is incorrect about the HTTP Flood defense principle?

  • A. fingerprint learning
  • B. HTTP Flood source authentication
  • C. load check
  • D. URI detection of destination IP

Answer: C

 

NEW QUESTION 78
When the firewall works in the dual-system hot backup load balancing environment, if the upstream and downstream routers are working in the routing mode, you need to adjust the OSPF cost based on HRP.

  • A. FALSE
  • B. TRUE

Answer: A

Explanation:
Explanation
Note: When dual-system hot backup load balancing is configured, the upstream and downstream routers are configured with equal-cost routes, and no HRP OSPF cost is required. When the dual-system hot standby network is deployed, the standby firewall automatically adds a COST value when it routes routes to the outside (the default is 65500).

 

NEW QUESTION 79
As shown in the following figure, the BFD for OSPF network is as follows: 1. OSPF is running between the three devices: FW_A, FW_B, and FW_C. The neighbors are in the FULL state. The association between BFD and OSPF is complete. BFD is complete. To establish a BFD session, the following instructions are correct?

  • A. link switching is switched in seconds
  • B. When link a finds a fault, OSPF automatically converges and notifies BFD.
  • C. When link a fails, BFD first senses, and FWA and FWB will converge immediately.
  • D. FWA processes the neighbor Down event and recalculates the route. The new route is link b.

Answer: C,D

 

NEW QUESTION 80
Virtual firewall technology can be implemented using IP address overlap.

  • A. FALSE
  • B. TRUE

Answer: B

 

NEW QUESTION 81
Which of the following IKE Negotiation Phase 1 main mode negotiation processes is the role of Message 5 and Message 6?

  • A. Negotiate IPSec SA
  • B. mutual authentication
  • C. Negotiation proposal set
  • D. running DH algorithm

Answer: B

Explanation:
Explanation
Note: The main mode requires a total of 6 messages in three steps to complete the first phase of negotiation, and finally establishes an IKE SA: these three steps are mode negotiation, Diffle-Hellman exchange and nonce exchange, and the identity of both parties. verification. Features of the main mode include identity protection and full utilization of ISAKMP negotiation capabilities. Among them, identity protection is particularly important when the other party wants to hide their identity. Before the messages 1, 2 are sent, the negotiation initiator and the responder must calculate and generate their own cookies, which are used to uniquely identify each individual negotiation exchange. The cookie uses the source/destination IP address, random number, date, and time to perform the MD5 operation. And put into the ISAKMP of Message 1 to identify a separate negotiated exchange. In the first exchange, the two parties need to exchange the cookie and the SA payload.
The SA load carries the parameters of the IKE SA to be negotiated, including the IKE hash type, the encryption algorithm, the authentication algorithm, and the negotiation time of the IKE SA. Limits, etc. Before the second exchange after the first exchange, the communicating parties need to generate a DH value for generating a Diffle-Hellman shared key. The generation method is that each party generates a random number, and the random number is processed by the DH algorithm to obtain a DH value Xa (initiator's DH value) and Xb (responder's DH value), and then both sides calculate according to the DH algorithm. A temporary value of Ni and Nr is given. For the second exchange, the two parties exchange their respective key exchange payloads (Diffle- Hellman exchange, including Xa and Xb) and temporary value payloads (nonce exchanges containing Ni and Nr). After the two parties exchange the temporary value loads Ni and Nr, the pre-shared key is pre-prepared, and then a pseudo-random function operation can generate a key SKEYID, which is the basis of all subsequent key generation. Then, by calculating the DH value calculated by itself, the DH value obtained by the exchange, and the SKEYID, a shared key SKEYID_d that only the two parties know is generated. This shared key is not transmitted, only the DH value and the temporary value are transmitted, so even if the third party gets these materials, the shared key cannot be calculated. After the second exchange is completed, the calculation materials required by both parties have been exchanged. At this time, both parties can calculate all the keys and use the key to provide security for subsequent IKE messages. These keys include DKEYID_a and DKEYID_e. DKEYID_a is used to provide security services such as integrity and data source authentication for IKE messages. DKEYID_e is used to encrypt IKE messages. The third exchange is the exchange of the identification load and the hash load. The identifier payload contains the identifier information, IP address or host name of the initiator; the hash payload contains the values obtained by HASH operation of the three sets of keys generated in the previous process. These two payloads are encrypted by DKEYID_e. If the payloads of both parties are the same, the authentication is successful. The IKE first-stage master mode pre-shared key exchange is complete.

 

NEW QUESTION 82
To establish IPsec VPN Security, ACL rules should mirror each other. This is the general requirement at both ends in Huawei firewall environment.

  • A. FALSE
  • B. TRUE

Answer: B

 

NEW QUESTION 83
What algorithm can be used for session maintenance?

  • A. The minimum connection algorithm
  • B. Source IP hash algorithm
  • C. Simple Round-Robin algorithm
  • D. Weighted Round-Robin algorithm

Answer: B

 

NEW QUESTION 84
After the NAT server is configured (no-reverse parameter is added), the firewall automatically generates static Server-Map entries. The first packet matches the Server-Map entry and does not match the session table.

  • A. FALSE
  • B. TRUE

Answer: B

 

NEW QUESTION 85
When using the SSL VPN client, it initiates network expansion "Connect gateway mate lost", what are the causes of this failure? (Choose three answers)

  • A. PC and virtual gateway routing between unreachable TCP
  • B. If you are using a proxy server, network extension client proxy server settings wrong.
  • C. network expansion between the client and the virtual gateway connection is blocked by the firewall.
  • D. Username and password configuration errors.

Answer: A,B,C

 

NEW QUESTION 86
The following are traffic-type attacks.

  • A. ICMP redirect packet attack
  • B. IP Flood attack
  • C. IP address scanning attack
  • D. HTTP Flood attack

Answer: B,D

Explanation:
Explanation
Note: Traffic-type attack: refers to a flood attack caused by a large number of packets causing link congestion or system processing, that is, flood attacks. Main representatives: SYN Flood, UDP Flood, and ICMP Flood.
In recent years, it has developed into a flood attack for common services, mainly including connection flood (connection exhaustion), HTTP flood (the most obvious attack effect such as CC attack), DNS Query Flood, DNS Reply Flood, and SIP Flood (sending a large number of SIP ports). UDP spam).

 

NEW QUESTION 87
......

100% Passing Guarantee - Brilliant H12-721 Exam Questions PDF: https://www.prep4king.com/H12-721-exam-prep-material.html