Exit demo H12-721 HCIP-Security-CISN V3.0 PDF format · free preview

Huawei H12-721 - Questions & Answers

Free preview · every answer includes a full explanation

Product page: https://prepkeys.com/h12-721.html

Question 1
Single choice

In IPsec standby backup scenarios shown below, the gateway B is using IPsec tunneling technology and gateway A build IPsec VPN.

A.

TRUE

B.

FALSE

Question 2
Single choice

Virtual firewall technology can be implemented using IP address overlap.

A.

TRUE

B.

FALSE

Question 3
Single choice

Virtual firewall technology does not include which of the following characteristics?

A.

Provides multi-instance routing, security, multi-instance, multi-instance configuration, NAT multi-
instance, VPN multi-instance application flexibility to meet a variety of networking needs.

B.

Each virtual firewalls can support four separate security zones TRUST, UNTRUST, DMZ, etc., flexible interface partitioning and allocation.

C.

It guarantee that every virtual system and a separate firewall instance, and can be safely implement
access between each virtual system.

D.

Each virtual system provides independent administrator privileges.

Question 4
Single choice

As shown in Figure Eth-Trunk functionality with binding, if the need is to implement each interface-by-packet load balancing feature, you need to run which of the following configuration commands?

A.

[USG] load-balance interface eth-trunk 1 packet-all

B.

[USG] interface eth-trunk 1
[USG-Eth-Trunk 1] load-balance packet-all

C.

[USG] load-balance interface eth-trunk 1 src-dst-ip

D.

[USG] interface eth-trunk 1
[USG-Eth-Trunk 1] load-balance src-dst-ip

Question 5
Single choice

Which of the following is the role of Message5 and Message6 with the main mode IKE negotiation process?

A.

Runs the DH algorithm

B.

negotiate set of proposals

C.

mutual authentication

D.

negotiate IPsec SA

Question 6
Single choice

With regard to the firewall configuration interface binding VPN instance, which configuration is correct?

A.

ip binding vpn-instance vpn-id

B.

ip binding vpn-instance vpn-instance-name

C.

ip binding vpn-id

D.

ip binding vpn-id vpn-instance-name

Question 7
Multiple choice

In the dual-system hot backup networking environment as shown in the standby firewall also need to configure NAT function, assuming that the external address of the VRRP backup group. NAT address pool and NAT Server in the same network segment.

Which of the following configuration needs to be on the Server? (choose two answers)

A.

HRP_M [USG_A] nat address-group 1 2.2.2.5 2.2.2.6 vrrp 1

B.

HRP_M [USG_A] nat address-group 1 2.2.2.5 2.2.2.6 vrrp 2

C.

HRP_M [USG_A] nat server global 2.2.2.10 inside 10.100.10.3 vrrp 2

D.

HRP_M [USG_A] nat server global 2.2.2.10 inside 10.100.10.3 vrrp 1

Question 8
Single choice

In IP-link, how many successive packets must not be recived for it to be considered a failure, by default?

A.

1 times

B.

2 times

C.

3 times

D.

5 times

Question 9
Single choice

In IKE V1 stage 1 pre-shared key with Main Mode exchange process, the SA is established after which messages?

A.

message 1 and message 2

B.

message 3 and message 4

C.

message 5 and message 6

D.

message 7 and message 8

Question 10
Single choice

Through the configuration of the Bypass interface, you can avoid network communication interruption caused by equipment failure and improve reliability. The power Bypass function can use any network interfaces to configure the Bypass GE parameters to achieve the Bypass function.

A.

TRUE

B.

FALSE

Showing 10 of 245 questions · Unlock the full set