H12-711 Questions Pass on Your First Attempt Dumps for HCNA-Security Certified [Q121-Q140]

Share

H12-711 Questions Pass on Your First Attempt Dumps for HCNA-Security Certified

H12-711 Practice Test Pdf Exam Material

NEW QUESTION # 121
Check the firewall HRP status information as follows:
HRP_S [USG_ B] display hrp state 16:90: 13 2010/11/29 The firewall's config state is : SLAVE Current state of virtual routers configured as slave GigabitEthernet0/0/0 vird 1 : slave GigabitEthernet0/0/1 vied 2 : slave Which of the following description is correct?

  • A. The firewall ofHRP heartbeats interface is G0/0/0 and G0/0/1
  • B. The firewall VGMP group status is Master
  • C. The firewall G0/0/0 and 0/1 GO / interface of VRRP group status is Slave
  • D. The firewall must be in a state of preemption

Answer: C


NEW QUESTION # 122
Except built-in Portal authentication, firewall also supports custom Portal authentication, when using a custom Portalauthentication, no need to deploy a separate external Portal sever.

  • A. True
  • B. False

Answer: B


NEW QUESTION # 123
Which of the following options does not include the respondents in the questionnaire for safety assessment?

  • A. HR
  • B. Security administrator
  • C. Network System Administrator
  • D. Technical leader

Answer: A


NEW QUESTION # 124
Except built-in Portal authentication, firewall also supports custom Portal authentication, when using a custom Portal authentication, no need to deploy a separate external Portal server.

  • A. True
  • B. False

Answer: B


NEW QUESTION # 125
Digital signature is to achieve the integrity of data transmission by using a hash algorithm to generate digital fingerprints.

  • A. True
  • B. False

Answer: A


NEW QUESTION # 126
Regarding the HRP master and backup configuration consistency check content, which of the following is not included?

  • A. NAT policy
  • B. Next hop and outbound interface of static route
  • C. Is the heartbeat interface configured with the sameserial number?
  • D. Authentication Policy

Answer: B


NEW QUESTION # 127
The SIP protocol establishes a session using an SDP message, and the SDP message contains a remote address ora multicast address

  • A. True
  • B. False

Answer: A


NEW QUESTION # 128
Which of the following protection levels are included in the TCSEC standard? (Multiple Choice)

  • A. Verify protection level
  • B. Forced protection level
  • C. Independent protection level
  • D. Passive protection level

Answer: A,B,C


NEW QUESTION # 129
Which of the following are key elements of information securityprevention? (Multiple choice)

  • A. Security products and technologies
  • B. Asset management
  • C. Security operation and management
  • D. Personnel

Answer: A,B,C,D


NEW QUESTION # 130
In the digital signature process, which of the following is the HASH algorithm to verify the integrity of the data transmission?

  • A. User data
  • B. Symmetric key
  • C. Receiver private key
  • D. Receiver public key

Answer: A


NEW QUESTION # 131
Against Buffer overflow attacks, which description is correct?(Multiple choice)

  • A. Buffer overflow attack has nothing to do with operating system's vulnerabilities and architecture
  • B. Buffer overflow attack is the most common method of attack software system's behaviors
  • C. Buffer overflow attack belongs to the application layer attack behavior
  • D. Buffer overflow attack is use of the software system on memory operating defects, by using high operating permission to run attack code

Answer: B,C,D


NEW QUESTION # 132
Digital certificate technology solves the problem that public key owners cannot determine in digital signature technology.

  • A. True
  • B. False

Answer: A


NEW QUESTION # 133
The following security policy command, representatives of the meaning:

  • A. banned from trust region access to untrust region and the destination address is 10.1.10.10 host ICMP message
  • B. banned from trust region access to untrust region and the source address is 10.2.10.10 host to all the hosts ICMP message
  • C. banned from trust region access to untrust region and the destination address is 10.1.0.0/16 segment all hosts ICMP message
  • D. banned from trust region access to untrust region and the source address is 10.1.0.0/16 segment all the hosts ICMP message

Answer: D


NEW QUESTION # 134
Which of the following attacks can DHCP Snooping prevent? (Multiple Choice)

  • A. Intermediaries and IP/MAC spoofing attacks
  • B. IP spoofing attack
  • C. DHCP Server counterfeiter attack
  • D. Counterfeit DHCP lease renewal packet attack using option82 field

Answer: A,B,C,D


NEW QUESTION # 135
Which of the following options can be used in the advanced settings of Windows Firewall? (Multiple choice)

  • A. Restore defaults
  • B. Set out inbound rules
  • C. Change notification rules
  • D. Set connection security rules

Answer: A,B,C,D


NEW QUESTION # 136
Which of the following is not the scope of business of the National Internet Emergency Center?

  • A. Providing security evaluation services for government departments, enterprises and institutions
  • B. Cooperate with other agencies to provide training services
  • C. Early warning rotification of security incidents
  • D. Emergency handling of security incidents

Answer: B


NEW QUESTION # 137
Regarding the problem that the two-way binding user of the authentication-free method cannot access the network resources, which of the following options are possible reasons? (Multiple choice)

  • A. The authentication action in the authentication policy is set to "No credit / free authentication"
  • B. The authentication-free user does not use the PC with the specified IP/MAC address.
  • C. The authentication-free user and the authenticated user are in the same security zone.
  • D. Online users have reached a large value

Answer: B,D


NEW QUESTION # 138
Both the GE1/0/1 and GE1/0/2 ports of the firewall belong to the DMZ. If the area connected to GE1/0/1 can access the area connected to GE1/0/2, which of the following is correct?

  • A. Need to configure an interzone security policy
  • B. Need to configure the security policy from Local to DMZ
  • C. No need to do any configuration
  • D. Need to configure security policy from DMZ to local

Answer: C


NEW QUESTION # 139
Which of the following are the hazards of traffic attacks? (Multiple choice)

  • A. Data is stolen
  • B. Server downtime
  • C. Network paralysis
  • D. The page has been tampered with

Answer: B,C


NEW QUESTION # 140
......

H12-711 [Feb-2024] Newly Released] Exam Questions For You To Pass: https://certlibrary.itpassleader.com/Huawei/H12-711-dumps-pass-exam.html

0
0
0
0