
(Dec-2023) H12-711 Exam Dumps Contains FREE Real Quesions from the Actual Exam
Free Test Engine Verified By HCNA-Security Certified Experts
Huawei H12-711 (HCIA-Security V3.0) Exam is a certification exam that tests the knowledge and skills of candidates in the field of network security. H12-711 exam is designed to validate the ability of individuals to design, deploy, and manage secure and reliable network systems using Huawei technologies. The HCIA-Security certification is an essential requirement for professionals who want to advance their careers in network security and become certified Huawei engineers.
The Huawei H12-711 exam consists of multiple choice questions and scenarios that require candidates to apply their knowledge and skills to real-world situations. H12-711 exam covers a wide range of topics, including network security fundamentals, firewall technology, VPN technologies, intrusion prevention and detection systems, and network security management.
NEW QUESTION # 24
The process of electronic forensics includes: protecting the site, obtaining evidence, preserving evidence,identifying evidence, analyzing evidence, tracking and presenting evidence
- A. False
- B. True
Answer: B
NEW QUESTION # 25
Which of the following description is wrong about the Internet users and VPN access user authentication?
- A. After the VPN access user passes the authentication, it will be online on the user online list.
- B. The local authentication or server authentication process is basically the same for the Internet users. The authentication is performed on the user through the authentication domain.
- C. After the VPN user accesses the network, it can access the network resources of the enterprise headquarters. The firewall can control the accessible network resources based on theuser name.
- D. The Internet user andthe VPN access user share data, and the users attribute check (user status, account expiration time, etc.) also takes effect on the VPN access.
Answer: A
NEW QUESTION # 26
Regarding the firewall security policy, which of the following options are wrong?
- A. When configuring the security policy name, you cannot reuse the samename.
- B. The number of security policy entries of Huawei USG series firewalls cannot exceed 128.
- C. Adjust the order of security policies without saving the configuration file.
- D. If the security policy is permit, the discarded message will not accumulate the number of hits.
Answer: D
NEW QUESTION # 27
Which of the following statements about IPSec SA is true?
- A. Used to generate a secret algorithm
- B. IPSec SA is two-way
- C. used to generate anencryption key
- D. IPSec SA is one-way
Answer: D
NEW QUESTION # 28
The vulnerability that has not been discovered is the 0 day vulnerability
- A. True
- B. False
Answer: B
NEW QUESTION # 29
Which VPN access modes are suitable for mobile office workers? (Choose three.)
- A. L2TP VPN
- B. L2TP over IPsec
- C. SSL VPN
- D. GRE VPN
Answer: A,B,C
NEW QUESTION # 30
Which of the following is not the scope of business of the National Internet Emergency Center?
- A. Providing security evaluation services for government departments, enterprises and institutions
- B. Cooperate with other agencies to provide training services
- C. Emergency handling of security incidents
- D. Early warning notification of security incidents
Answer: B
NEW QUESTION # 31
Which of the following options is not the part of the quintet?
- A. Destination Port
- B. Destination IP
- C. Source MAC
- D. Source IP
Answer: C
NEW QUESTION # 32
When configuring security policy, a security policy can reference an address set or configure multiple destination IP addresses.
- A. False
- B. True
Answer: B
NEW QUESTION # 33
After the firewall uses the hrp standby config enable command to enable the standby device configuration function, all the information that can be backed up can bedirectly configured on the standby device, and the configuration on the standby device can be synchronized to the active device.
- A. False
- B. True
Answer: B
NEW QUESTION # 34
When the sesson authentication mode is used to trigger the firewall's built-in Portal aithentication. the user does not actively perform identity authentication, advanced service access, and device push "redirect" to the authentication page? .. ' * '
- A. False
- B. True
Answer: B
NEW QUESTION # 35
Which of the following is not a rating in the network security incident?
- A. Special network security incidents
- B. Major network security incidents
- C. General network security incidents
Answer: A
NEW QUESTION # 36
Which of the following are correct about configuring the firewall security zone?(Multiple Choice)
- A. The firewall has four security zones by default, and the four security zone priorities do not support modification.
- B. The firewall can create two security zones of the same priority
- C. When data flows between different security zones, the device security check is triggered and the corresponding security policy is implemented
- D. Firewall can have 12 security zones at most.
Answer: A,C
NEW QUESTION # 37
Which of the following statement about the NAT is wrong?
- A. Address Translation can follow the needs of users, providing FTP, WWW, Telnet and other services outside the LAN
- B. NAT technology can effectively hide the hosts of the LAN, it is an effective network security protection technology
- C. Some application layer protocols carry IP address information in the data, but also modify the IP address information in the data of the upper layer when they are as NAT
- D. For some non-TCP, UDP protocols (such as ICMP, PPTP), unable to do the NAT translation
Answer: D
NEW QUESTION # 38
The host firewall is mainly used to protect the host from attacks and intrusions from the network
- A. False
- B. True
Answer: B
NEW QUESTION # 39
Which of the following is the analysis layer device inthe Huawei SDSec solution? r a.
- A. switch
- B. Firehunter
- C. Agile Controller
- D. cis
Answer: B
NEW QUESTION # 40
What are the advantages of address translation techniques included? (Multiple choice)
- A. Address conversion that can handle the IP header of encryption
- B. Address conversion can make internal network users (private IPaddress) easy access to the Internet
- C. Many host address conversion can make the internal LAN to share an IP address on the Internet
- D. Address conversion can block internal network users,improve the safety of internal network
Answer: B,C,D
NEW QUESTION # 41
What port numbers may be used by FTP protocol? (Choose two.)
- A. 0
- B. 1
- C. 2
- D. 3
Answer: B,D
NEW QUESTION # 42
When the USG series firewall hard disk is in place, which of the following logs can be viewed? (Multiple Choice)
- A. Alarm information
- B. Operation log
- C. Threat log
- D. Business log
Answer: A,B,C,D
NEW QUESTION # 43
HTTP packets are carried by UDP. and the HTTPS protocol is based on TCP three-way handshake. Therefore.
HTTPS is relatively secure, and HTTPS is recommended.
- A. True
- B. False
Answer: B
NEW QUESTION # 44
Using a computer to store information about criminal activity is not a comouter crime
- A. True
- B. False
Answer: B
NEW QUESTION # 45
Security technology has different methods at different technical levels and areas. Which of the following devices can be used for network layer security protection? (Multiple choice)
- A. Anti-DDoS device
- B. Firewall
- C. IPS/IDS device
- D. Vulnerability scanning device
Answer: A,B,C
NEW QUESTION # 46
......
Use Real Huawei Achieve the H12-711 Dumps - 100% Exam Passing Guarantee: https://examtorrent.vce4dumps.com/H12-711-latest-dumps.html