H12-711 Questions Pass on Your First Attempt Dumps for HCNA-Security Certified
H12-711 Practice Test Pdf Exam Material
NEW QUESTION # 121
Check the firewall HRP status information as follows:
HRP_S [USG_ B] display hrp state 16:90: 13 2010/11/29 The firewall's config state is : SLAVE Current state of virtual routers configured as slave GigabitEthernet0/0/0 vird 1 : slave GigabitEthernet0/0/1 vied 2 : slave Which of the following description is correct?
- A. The firewall ofHRP heartbeats interface is G0/0/0 and G0/0/1
- B. The firewall VGMP group status is Master
- C. The firewall G0/0/0 and 0/1 GO / interface of VRRP group status is Slave
- D. The firewall must be in a state of preemption
Answer: C
NEW QUESTION # 122
Except built-in Portal authentication, firewall also supports custom Portal authentication, when using a custom Portalauthentication, no need to deploy a separate external Portal sever.
- A. True
- B. False
Answer: B
NEW QUESTION # 123
Which of the following options does not include the respondents in the questionnaire for safety assessment?
- A. HR
- B. Security administrator
- C. Network System Administrator
- D. Technical leader
Answer: A
NEW QUESTION # 124
Except built-in Portal authentication, firewall also supports custom Portal authentication, when using a custom Portal authentication, no need to deploy a separate external Portal server.
- A. True
- B. False
Answer: B
NEW QUESTION # 125
Digital signature is to achieve the integrity of data transmission by using a hash algorithm to generate digital fingerprints.
- A. True
- B. False
Answer: A
NEW QUESTION # 126
Regarding the HRP master and backup configuration consistency check content, which of the following is not included?
- A. NAT policy
- B. Next hop and outbound interface of static route
- C. Is the heartbeat interface configured with the sameserial number?
- D. Authentication Policy
Answer: B
NEW QUESTION # 127
The SIP protocol establishes a session using an SDP message, and the SDP message contains a remote address ora multicast address
- A. True
- B. False
Answer: A
NEW QUESTION # 128
Which of the following protection levels are included in the TCSEC standard? (Multiple Choice)
- A. Verify protection level
- B. Forced protection level
- C. Independent protection level
- D. Passive protection level
Answer: A,B,C
NEW QUESTION # 129
Which of the following are key elements of information securityprevention? (Multiple choice)
- A. Security products and technologies
- B. Asset management
- C. Security operation and management
- D. Personnel
Answer: A,B,C,D
NEW QUESTION # 130
In the digital signature process, which of the following is the HASH algorithm to verify the integrity of the data transmission?
- A. User data
- B. Symmetric key
- C. Receiver private key
- D. Receiver public key
Answer: A
NEW QUESTION # 131
Against Buffer overflow attacks, which description is correct?(Multiple choice)
- A. Buffer overflow attack has nothing to do with operating system's vulnerabilities and architecture
- B. Buffer overflow attack is the most common method of attack software system's behaviors
- C. Buffer overflow attack belongs to the application layer attack behavior
- D. Buffer overflow attack is use of the software system on memory operating defects, by using high operating permission to run attack code
Answer: B,C,D
NEW QUESTION # 132
Digital certificate technology solves the problem that public key owners cannot determine in digital signature technology.
- A. True
- B. False
Answer: A
NEW QUESTION # 133
The following security policy command, representatives of the meaning:
- A. banned from trust region access to untrust region and the destination address is 10.1.10.10 host ICMP message
- B. banned from trust region access to untrust region and the source address is 10.2.10.10 host to all the hosts ICMP message
- C. banned from trust region access to untrust region and the destination address is 10.1.0.0/16 segment all hosts ICMP message
- D. banned from trust region access to untrust region and the source address is 10.1.0.0/16 segment all the hosts ICMP message
Answer: D
NEW QUESTION # 134
Which of the following attacks can DHCP Snooping prevent? (Multiple Choice)
- A. Intermediaries and IP/MAC spoofing attacks
- B. IP spoofing attack
- C. DHCP Server counterfeiter attack
- D. Counterfeit DHCP lease renewal packet attack using option82 field
Answer: A,B,C,D
NEW QUESTION # 135
Which of the following options can be used in the advanced settings of Windows Firewall? (Multiple choice)
- A. Restore defaults
- B. Set out inbound rules
- C. Change notification rules
- D. Set connection security rules
Answer: A,B,C,D
NEW QUESTION # 136
Which of the following is not the scope of business of the National Internet Emergency Center?
- A. Providing security evaluation services for government departments, enterprises and institutions
- B. Cooperate with other agencies to provide training services
- C. Early warning rotification of security incidents
- D. Emergency handling of security incidents
Answer: B
NEW QUESTION # 137
Regarding the problem that the two-way binding user of the authentication-free method cannot access the network resources, which of the following options are possible reasons? (Multiple choice)
- A. The authentication action in the authentication policy is set to "No credit / free authentication"
- B. The authentication-free user does not use the PC with the specified IP/MAC address.
- C. The authentication-free user and the authenticated user are in the same security zone.
- D. Online users have reached a large value
Answer: B,D
NEW QUESTION # 138
Both the GE1/0/1 and GE1/0/2 ports of the firewall belong to the DMZ. If the area connected to GE1/0/1 can access the area connected to GE1/0/2, which of the following is correct?
- A. Need to configure an interzone security policy
- B. Need to configure the security policy from Local to DMZ
- C. No need to do any configuration
- D. Need to configure security policy from DMZ to local
Answer: C
NEW QUESTION # 139
Which of the following are the hazards of traffic attacks? (Multiple choice)
- A. Data is stolen
- B. Server downtime
- C. Network paralysis
- D. The page has been tampered with
Answer: B,C
NEW QUESTION # 140
......
H12-711 [Feb-2024] Newly Released] Exam Questions For You To Pass: https://certlibrary.itpassleader.com/Huawei/H12-711-dumps-pass-exam.html