[Nov 25, 2021] Step by Step Guide to Prepare for H12-711_V3.0 Exam BrainDumps [Q87-Q108]

Share

Nov 25, 2021 Step by Step Guide to Prepare for H12-711_V3.0 Exam BrainDumps

HCIA-Security H12-711_V3.0 Real Exam Questions and Answers FREE Updated on 2021

NEW QUESTION 87
According to the management regulations, regular inspections of network security systems and equipment, patch upgrades, and network security emergency response drills are organized. Which aspects of the MPDRR network security model are the above actions belong to? (Multiple choice)

  • A. Protection link
  • B. Response link
  • C. Testing link
  • D. Management link

Answer: A,B,C

 

NEW QUESTION 88
ASPF (Application specific Packet Filter) is a packet filtering technology based on the application layer and implements a special security mechanism through the server-map table. Regarding ASPF and server-map tables, which of the following are correct? (Multiple choice)

  • A. ASPF can dynamically create server-map
  • B. ASPF dynamically allows multi-channel protocol data to pass through the server-map table
  • C. The five-tuple server-map table entry implements a function similar to the session table
  • D. ASPF monitors the packets in the communication process

Answer: A,B,D

 

NEW QUESTION 89
In response to network security incidents, remote emergency response is generally taken first. If the problem cannot be solved for the customer through remote access, after the customer confirms, it will be transferred to the local emergency response process.

  • A. True
  • B. False

Answer: A

 

NEW QUESTION 90
When deploying IPSec VPN, which of the following is the main application scenario of tunnel mode?

  • A. Between host and host
  • B. Between security gateways
  • C. Between the host and the security gateway
  • D. Between host and server

Answer: B

 

NEW QUESTION 91
About AH and ESP security protocols, which of the following statements are correct? (Multiple Choice)

  • A. ESP can provide the functions of encryption and verification
  • B. AH can provide the functions of encryption and verification
  • C. AH's protocol number is 51
  • D. ESP's protocol number is 51

Answer: A,C

 

NEW QUESTION 92
According to the requirements of level protection, which of the following behaviors belong to the scope of information security operation and maintenance management? (Multiple choice)

  • A. Develop an emergency response plan
  • B. Harden the security of the host
  • C. Back up or restore data
  • D. Participate in information security training

Answer: A,B,C,D

 

NEW QUESTION 93
Which of the following protocols does not belong to the protocol type that ASPF can detect?

  • A. MSTP
  • B. PPTP
  • C. DNS
  • D. FTP

Answer: A

 

NEW QUESTION 94
Which of the following is the encryption technology used in the digital envelope?

  • A. Asymmetric encryption algorithm
  • B. Hashing algorithm
  • C. Stream encryption algorithm
  • D. Symmetric encryption algorithm

Answer: A

 

NEW QUESTION 95
The attacker sends a SYN packet with the same source address and destination address, or the source address is the loopback address, to the target host (the source port and the destination port are the same), causing the attacked to send a SYN-AKY message to his own address. Which kind of attack is is this behavior?

  • A. SYN Flood attack
  • B. Smurf attack
  • C. TCP spoofing attack
  • D. Land attack

Answer: D

 

NEW QUESTION 96
Manual audit is a supplement to tool assessment. It does not require any software to be installed on the target system being assessed, and has no effect on the operation and status of the target system. Which of the following is not included in the manual audit?

  • A. Manual detection of the host operating system
  • B. Manual inspection of network equipment
  • C. Manual inspection of the process of the administrator operating the equipment
  • D. Manual inspection of the database

Answer: C

 

NEW QUESTION 97
Which of the following is the status information that can be backed up by the HRP (Huawei Redundancy Protocol) protocol? (Multiple choice)

  • A. Dynamic blacklist
  • B. Routing table
  • C. Session table
  • D. ServerMap table entries

Answer: A,C,D

 

NEW QUESTION 98
_______ is a defect in the specific implementation of hardware, software, and protocol or system security strategy, which can enable an attacker to access or destroy the system without authorization.

  • A. Vulnerabilities

Answer: A

 

NEW QUESTION 99
After a network intrusion event occurs, according to the plan to obtain the identity of the intrusion, the source of the attack and other information, and block the intrusion behavior, which links in the PDRR network security model do the above actions belong to? (Multiple choice)

  • A. Protection link
  • B. Response link
  • C. Testing link
  • D. Recovery link

Answer: B,C

 

NEW QUESTION 100
Which of the following options is not a passive means of obtaining information?

  • A. Collect logs
  • B. Port mirroring
  • C. Port scan
  • D. Capture

Answer: D

 

NEW QUESTION 101
In the IPSec VPN transmission mode, which part of the data message is encrypted?

  • A. New IP header
  • B. Network layer and upper layer data packets
  • C. Original IP header
  • D. Transport layer and upper layer data messages

Answer: D

 

NEW QUESTION 102
Regarding the business continuity plan, which of the following statements is correct? (Multiple choice)

  • A. The business continuity plan does not require the participation of the company's senior management before it is formally documented
  • B. Not all safety incidents must be reported to the company's senior management
  • C. All possible accidents are thought not to be predicted, so BCP needs to be flexible
  • D. The business continuity plan does not require the participation of the company's senior management during the project scope stage

Answer: A,B,C

 

NEW QUESTION 103
The online scenario of internal users in the enterprise is shown in the figure. The user online process is as follows:
1. After the authentication is passed, the USG allows the connection to be established
2. The user accesses the internet and enters http://1.1.1.1
3. USG push authentication interface
4. The user successfully accesses http://1.1.1.1, and the device creates a session table
5. The user enters the correct user name and password
Which of the following is the correct process sequence?

  • A. 2->5->3->1->4
  • B. 2->1->3->5->4
  • C. 2->3->1->5->4
  • D. 2->3->5->1->4

Answer: D

 

NEW QUESTION 104
Regarding the actions of the security policy and the description of the security configuration file, which of the following options are correct? (Multiple choice)

  • A. If the security policy action is "allow", the traffic will not match the security profile
  • B. If the action of the security policy is "Forbidden", the device will discard this traffic, and no further content security checks will be performed.
  • C. The security configuration file must be applied to the security policy where the action is allowed to take effect
  • D. The security configuration file can take effect without being applied to the security policy where the action is allowed

Answer: B,C

 

NEW QUESTION 105
In the _______ view of the firewall, you can use the reboot command to restart the firewall.

Answer:

Explanation:
User

 

NEW QUESTION 106
As shown in the figure, the nat server global 202.106.1.1 inside 10.10.1.1 is configured on the firewall. Which of the following configuration is correct for inter-domain rules?

  • A. rule named, source-zone untrust, destination-zone trust, destination-address 10.10.1.1 32, action permit
  • B. rule name c, source-zone untrust, destination-zone trust, destination-address 202.106.1.1 32, action permit
  • C. rule name b, source-zone untrust, destination-zone trust, source-address 10.10.1.1 32, action permit
  • D. rule name b, source-zone untrust, destination-zone trust, source-address 202.106.1.1 32, action permit

Answer: A

 

NEW QUESTION 107
When configuring user single sign-on, the mode of receiving PC messages is adopted, and the authentication process has the following steps:
1. The visitor's PC executes the login script and sends the user login information to the AD monitor
2. The firewall extracts the corresponding relationship between the user and IP from the login information and adds it to the online user table
3. The AD monitor connects to the AD server to query login user information, and forwards the queried user information to the firewall
4. The visitor logs in to the AD domain, and the AD server returns a login success message to the user and delivers the login script. Which of the following is the correct order?

  • A. 1-2-3-4
  • B. 3-2-1-4
  • C. 1-4-3-2
  • D. 4-1-3-2

Answer: D

 

NEW QUESTION 108
......

Ultimate Guide to Prepare H12-711_V3.0 Certification Exam for HCIA-Security: https://www.real4dumps.com/H12-711_V3.0_examcollection.html