Get ready to pass the H12-711_V3.0 Exam right now using our HCIA-Security Exam Package [Q228-Q248]

Share

Get ready to pass the H12-711_V3.0 Exam right now using our HCIA-Security Exam Package

A fully updated 2022 H12-711_V3.0 Exam Dumps exam guide from training expert Real4dumps

NEW QUESTION 228
Security technology has different methods in different technical levels and fields. Which of the following devices can be used for network layer security? (multiple choice)

  • A. firewall
  • B. Vulnerability Scanning Device
  • C. Anti-DDoSequipment
  • D. IPS/IDSequipment

Answer: A,C,D

 

NEW QUESTION 229
When the FW is deployed at the network egress, if a fault occurs, it will affect the Zaonet service. to enhance the network Reliability, need to deploy two FWs and form ______[fill in the blank]*

Answer:

Explanation:
hot standby

 

NEW QUESTION 230
Which of the following options belong to international organizations related to the standardization of information security? (multiple choice)

  • A. International Electrotechnical Commission(IEC) International Electrotechnical Commission
  • B. International Telecommunication Union(ITU)ITU
  • C. International Organization for Standardization(ISO)International Organization for Standardization
  • D. Wi-Fi Alliance Wi-Fialliance organization

Answer: A,B,C

 

NEW QUESTION 231
aboutVRRP/VGMP/HRPWhich of the following statements is correct? (multiple choice)

  • A. HRPResponsible for data backup during dual-system hot standby operation
  • B. VGMPResponsible for monitoring equipment failures and controlling rapid switching of equipment
  • C. inActivestateVGMPGroups may containStandbystateVRRPGroup
  • D. VRRPResponsible for sending free messages during active/standby switchoverARPDirect traffic to the new master

Answer: A,B,D

 

NEW QUESTION 232
When the firewall upgrades the signature database and virus database online through the security service center, the firewall must first be able to connect to the Internet, and secondly, the correct DNS address must be configured.

  • A. False
  • B. True

Answer: B

 

NEW QUESTION 233
If there is a practical change in the company structure, it is necessary to re-test whether the business continuity plan is feasible.

  • A. False
  • B. True

Answer: B

 

NEW QUESTION 234
In order to obtain criminal evidence, it is necessary to master the intrusion tracking technology. Which of the following description of the tracking technology is correct? (Multiple choice)

  • A. Link detection technology determines the source of the attack information by testing the network connection between routers
  • B. Shallow mail behavior analysis can realize the analysis of sending IP address, sending time, sending frequency, number of recipients, shallow email headers and other information
  • C. Data packet marking technology records data packets on the router, and then uses data drilling technology to extract information about the source of the attack
  • D. The packet recording technology inserts tracking data into the tracked IP packet, thereby marking the packet on each router mentioned.

Answer: A,B

 

NEW QUESTION 235
Which of the following options is not a hash algorithm?

  • A. SM1
  • B. SHA1
  • C. MD5
  • D. SHA2

Answer: A

 

NEW QUESTION 236
When the user uses the session authentication method to trigger the firewall's built-in Portal authentication, the user does not actively perform identity authentication, first performs business access, and the device pushes "redirect" to the authentication page.

  • A. False
  • B. True

Answer: B

 

NEW QUESTION 237
Security policy conditions can be divided into multiple fields, such as source address, destination address, source port, destination port, etc. These fields have an "and" relationship, that is, only the information in the message matches all fields It is considered that this strategy has been hit by the above.

  • A. False
  • B. True

Answer: B

 

NEW QUESTION 238
Which of the following is not the business scope of the National Internet Emergency Response Center?

  • A. Early warning and notification of security incidents
  • B. Provide security evaluation services for government departments, enterprises and institutions
  • C. Emergency handling of security incidents
  • D. Cooperate with other organizations to provide training services

Answer: D

 

NEW QUESTION 239
Which of the following VPNs cannot be used in Site to-Site scenarios?

  • A. IPSEC VPN
  • B. GRE VPN
  • C. SSL VPN
  • D. L2TP VPN

Answer: C

 

NEW QUESTION 240
The key used by DES encryption is bits, while the key used by 3DES encryption is bits.

  • A. 0
  • B. 1
  • C. 2
  • D. 3

Answer: C

 

NEW QUESTION 241
ASPF (Application specific Packet Filter)It is a packet filtering technology based on the application layer, andserver-mapTables implement special security mechanisms. aboutASPFandserver-mapWhich of the following statements is correct? (multiple choice)

  • A. Quintupleserver-mapThe table entry implements a similar function to the session table
  • B. ASPFpass throughserver-mapTable implementation dynamically allows multi-channel protocol data to pass through
  • C. ASPFcan be created dynamicallyserver-map
  • D. ASPFMonitor messages during communication

Answer: B,C,D

 

NEW QUESTION 242
In the USG series firewall, which of the following commands can be used to query the NAT conversion result?

  • A. display current nat
  • B. display firewall nat translation
  • C. display firewall session table
  • D. display nat translation

Answer: C

 

NEW QUESTION 243
Which of the following SSLVPN functions can and can only access all TCP resources?

  • A. Network expansion
  • B. Port Forwarding
  • C. file sharing
  • D. web proxy

Answer: D

 

NEW QUESTION 244
In digital signature technology, we usually encrypt the digital fingerprint with the sender's ( ). (fill in the blank)

Answer:

Explanation:
Private key

 

NEW QUESTION 245
Which of the following is the action to be taken in the eradication phase in cybersecurity emergency response? (Multiple choice)

  • A. Look for trojan horses, illegal authorizations, and system loopholes, and deal with them in time
  • B. Revise the security policy based on the security incidents that occur, and enable security auditing
  • C. Confirm the degree of damage caused by the security incident and report the security incident
  • D. Block the attacking behavior and reduce the scope of influence

Answer: A,B

 

NEW QUESTION 246
When configuring user single sign-on, the mode of receiving PC messages is adopted, and the authentication process has the following steps:
1. The visitor's PC executes the login script and sends the user login information to the AD monitor
2. The firewall extracts the corresponding relationship between the user and IP from the login information and adds it to the online user table
3. The AD monitor connects to the AD server to query login user information, and forwards the queried user information to the firewall
4. The visitor logs in to the AD domain, and the AD server returns a login success message to the user and delivers the login script. Which of the following is the correct order?

  • A. 1-2-3-4
  • B. 1-4-3-2
  • C. 4-1-3-2
  • D. 3-2-1-4

Answer: C

 

NEW QUESTION 247
An employee of a company accesses the internal web server of the company through the firewall. The web page of the website can be opened by using a browser, but the reachability of the web server is tested by using the Ping command, and it shows that it is unreachable. What are the possible reasons?

  • A. The interface of the firewall connecting to the server is not added to the security zone
  • B. The security policy deployed on the firewall allows the TCP protocol, but not the ICMP protocol
  • C. The security policy deployed on the firewall allows the HTTP protocol, but not the ICMP protocol
  • D. The web server is down

Answer: C

 

NEW QUESTION 248
......

Master 2022 Latest The Questions HCIA-Security and Pass H12-711_V3.0 Real Exam!: https://www.real4dumps.com/H12-711_V3.0_examcollection.html