Winter Special Sale Limited Time 60% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 2493360325

Good News !!! H12-721 Huawei Certified ICT Professional - Constructing Infrastructure of Security Network is now Stable and With Pass Result

H12-721 Practice Exam Questions and Answers

Huawei Certified ICT Professional - Constructing Infrastructure of Security Network

Last Update 18 hours ago
Total Questions : 217

Huawei Certified ICT Professional - Constructing Infrastructure of Security Network is stable now with all latest exam questions are added 18 hours ago. Incorporating H12-721 practice exam questions into your study plan is more than just a preparation strategy.

H12-721 exam questions often include scenarios and problem-solving exercises that mirror real-world challenges. Working through H12-721 dumps allows you to practice pacing yourself, ensuring that you can complete all Huawei Certified ICT Professional - Constructing Infrastructure of Security Network practice test within the allotted time frame.

H12-721 PDF

H12-721 PDF (Printable)
$48
$119.99

H12-721 Testing Engine

H12-721 PDF (Printable)
$56
$139.99

H12-721 PDF + Testing Engine

H12-721 PDF (Printable)
$70.8
$176.99
Question # 1

Which of the following protocol messages cannot be propagated in an IPSec tunnel by default?

Options:

A.  

TCP

B.  

UDP

C.  

ICMP

D.  

IGMP

Discussion 0
Question # 2

The following are traffic-type attacks.

Options:

A.  

IP Flood attack

B.  

HTTP Flood attack

C.  

IP address scanning attack

D.  

ICMP redirect packet attack

Discussion 0
Question # 3

87. The SSL VPN scenario under dual-system hot standby is shown in the following figure. The administrator has enabled the SSL network extension function. The following is about the configuration of the SSL VPN function.

Question # 3

Options:

A.  

virtual gateway created on the master side will not be synchronized to the slave side.

B.  

Bind the address pool to VRRP backup group 2 when configuring network extensions.

C.  

The virtual gateway IP address of the SSL VPN in C USG_A must use 202.38.10.2

D.  

The virtual gateway IP address of the SSL VPN in D USG_B must use 10.100.10.2.

Discussion 0
Question # 4

The following figure shows the L2TP over IPSec application scenario. The client uses the pre-shared-key command to perform IPSec authentication. How should the IPSec security policy be configured on the LNS?

Options:

A.  

uses IKE master mode for negotiation

B.  

Negotiate in IKE aggressive mode

C.  

IPSec security policy

D.  

Configuring an IPSec Policy Template

Discussion 0
Question # 5

Three physical interfaces have been added to the link-group group. When any one of the interfaces fails, what are the following descriptions correct?

Options:

A.  

If any interface in group A fails, the system sets the status of other interfaces in the group to down.

B.  

Any interface in group B fails, and the status of other interfaces in the group does not change.

C.  

After the interfaces in the group are restored to normal, the interfaces in the entire group are reset to up.

D.  

After all the interfaces in the group are restored, the interfaces in the entire group are reset to up.

Discussion 0
Question # 6

The Haiwei Secoway VPN client initiates an L2TP connection. The source port of the L2TP packet is 1710 and the port 1710 of the destination port.

Options:

A.  

TRUE

B.  

FALSE

Discussion 0
Question # 7

When the ip-link link health check is performed, if it is unable to receive the message several times in the absence of the link, it will be considered as a link failure.

Options:

A.  

1 time

B.  

2 times

C.  

3 times

D.  

5 times

Discussion 0
Question # 8

134. Which of the following is the connection status data to be backed up in the HRP function?

Options:

A.  

ServerMap entry

B.  

port mapping table

C.  

dynamic blacklist

D.  

Session entry

Discussion 0
Question # 9

Which of the following statements is correct about the IKE main mode and the aggressive mode?

Options:

A.  

All negotiation packets in the first phase of the aggressive mode are encrypted.

B.  

All the negotiation packets of the first phase in the main mode are encrypted.

C.  

barbarian mode uses DH algorithm

D.  

will enter the fast mode regardless of whether the negotiation is successful or not.

Discussion 0
Question # 10

IPSec NAT traversal does not support IKE main mode, aggressive mode IP address + pre-shared key mode authentication, because pre-shared key mode authentication needs to extract the source IP address in the IP address to find the pre-shared key corresponding to this address. . The address change caused by the presence of NAT prevents the device from finding the pre-shared key.

Options:

A.  

TRUE

B.  

FALSE

Discussion 0
Get H12-721 dumps and pass your exam in 24 hours!

Free Exams Sample Questions