
290 Q&As in UPDATED H12-711 Exam Questions Certification Test Engine to PDF
Get The Important Preparation Guide With H12-711 Dumps
NEW QUESTION # 126
Apply for emergency response special funds, which stage work content does procurement emergency responsesoftware and hardware equipment belong to in the network full emergency response?
- A. Inhibition phase
- B. Recovery phase
- C. Preparation stage
- D. Response phase
Answer: C
NEW QUESTION # 127
Which of the following is not the scope of business of the National Internet Emergency Center?
- A. Providing security evaluation services for government departments, enterprises and institutions
- B. Cooperate with other agencies to provide training services
- C. Early warning rotification of security incidents
- D. Emergency handling of security incidents
Answer: B
NEW QUESTION # 128
What are the main security capability of encryption service? (Choose three.)
- A. Integrity
- B. Non-repudiation
- C. Confidentiality
- D. Scalability
Answer: A,B,C
NEW QUESTION # 129
Which of the following are international organizations related to information security standardization? (Multiple Choice)
- A. International Electrotechnical Commission (IEC)
- B. International Organization for Standardization (ISO)
- C. Wi-Fi Alliance
- D. International Telecommunication Union (ITU)
Answer: A,B,D
NEW QUESTION # 130
What is the nature cf information security in "Implementation of security monitoring and management of information and information systems to prevent the illegal use of information and information systems"?
- A. Integrity
- B. Controllability
- C. Confidentiality
- D. Non-repudiation
Answer: B
NEW QUESTION # 131
The administrator wants to know the current session table. Which of the following commands is correct?
- A. Reset firewall session table
- B. Display firewall session table
- C. Displaysession table
- D. Clear firewall session table
Answer: A
NEW QUESTION # 132
During the configuration of NAT, which of the following will the device generate a Server-map entry? (Multiple Choice)?
- A. After configuring NAT No-PAT, the device will create a server-map table for the configured multi-channel protocol data stream.
- B. A server-map entry is generated when easy-ip is configured.
- C. After the NAT server is configured successfully, the device automatically generates a server map entry.
- D. Automatically generate server-map entries when configuring source NAT.
Answer: A,C
NEW QUESTION # 133
Which of the following is not in the quintuple range?
- A. Source IP
- B. Destination port
- C. Source MAC
- D. Destination IP
Answer: C
NEW QUESTION # 134
Regarding the relationship and role of VRRP/VGMP/HRP, which of the following statements are correct? (Multiple choice)
- A. VGMP group in the active state may include the VRRP group in the standby state.
- B. VGMP is responsible for monitoring equipment failures and controlling fast switching of equipment.
- C. HRP is responsible for data backup during hot standby operation.
- D. VRRP is responsible for sending free ARP to direct traffic to the new primary device during active/standby switchover.
Answer: B,C,D
NEW QUESTION # 135
Which of the following encryption algorithm, encryption and decryption keys are the same?
- A. MD5
- B. RSA(1024)
- C. SHA-1
- D. DES
Answer: D
NEW QUESTION # 136
Which of the following is an action to be taken during the eradication phase of the cyber security emergency response? (Multiple Choice)
- A. Confirm the damage caused by security incidents and report security incidents
- B. Find sick Trojans, illegal authorization, systemvulnerabilities, and deal with it in time
- C. Revise the security policy based on the security incident that occurred, enable security auditing
- D. Block the behavior ofthe attack, reduce the scope of influence
Answer: B,C
NEW QUESTION # 137
Typical remote authentication modes are: (Multiple Choice)
- A. HWTACACS
- B. LLDP
- C. RADIUS
- D. Local
Answer: A,C
NEW QUESTION # 138
Which of the following statements about IPSec SA is true?
- A. IPSec SA is two-way
- B. Used to generate a secret algorithm
- C. used to generate anencryption key
- D. IPSec SA is one-way
Answer: D
NEW QUESTION # 139
UDP port scanning means that the attacker sends a zero-byte UDP packet to a specific port of the target host.
If the port is open, it will return an ICMP port reachable data packet
- A. True
- B. False
Answer: B
NEW QUESTION # 140
In the IPSec VPN transmission mode, which part ofthe data packe: is encrypted?
- A. Network layer and upper layer data packet
- B. Original IP packet header
- C. Transport layer and upper layer data packet
- D. New IP packet header
Answer: C
NEW QUESTION # 141
Which VPN access modes are suitable for mobile office workers? (Choose three.)
- A. GRE VPN
- B. L2TP over IPsec
- C. L2TP VPN
- D. SSL VPN
Answer: B,C,D
NEW QUESTION # 142
The content of intrusion detection covers authorized and unauthorized intrusions. Which of the following is not in the scope of intrusion detection?
- A. Administrator mistakenly delete configuration
- B. Planting worms and Trojans
- C. Pretending to be another user
- D. Leaking data information
Answer: A
NEW QUESTION # 143
To implement the " anti-virus function " in the security policy, you must perform a License activation
- A. False
- B. True
Answer: B
NEW QUESTION # 144
Which of the following belongs to the devices at the execution layer in the Huawei SDSec solution? 'Multiple Choice)
- A. Fierhunter
- B. Router
- C. AntiDDoS
- D. cis
Answer: A,B,C
NEW QUESTION # 145
When configuring NAT Server on the USG series firewall, the server-map table will be generated. Which of the following does not belong in the table?
- A. Destination port number
- B. Source IP
- C. Agreement number
- D. Destination IP
Answer: B
NEW QUESTION # 146
Firewall update signature database and Virus database online throjgh security servicecenter, requires the firewall can connect to the Internet first, and then need to configure the correct DNS addresses.
- A. FALSE
- B. TRUE
Answer: B
NEW QUESTION # 147
Which of the following descriptions is wrong about IKE SA?
- A. IKE SA is two-way
- B. IKE is a UDP-based application layer protocol
- C. The encryption algorithm used by user data packets is determined by IKE SA.
- D. IKE SA for IPSec SA services
Answer: C
NEW QUESTION # 148
IPSEC VPN technology does not support NAT traversal when encapsulated in ESP security protocol because ESP encrypts the packet header.
- A. True
- B. False
Answer: B
NEW QUESTION # 149
......
Prepare With Top Rated High-quality H12-711 Dumps For Success in Exam: https://examcollection.prep4sureguide.com/H12-711-prep4sure-exam-guide.html