2021 Valid H12-711 Real Exam Questions (Updated) 100% Dumps & Practice Exam
[UPDATED 2021] Huawei H12-711 Questions Prepare with Free Demo of PDF
NEW QUESTION 72
There ere various security threats in the use of the server. Which of the following options is not a server securitythreat?
- A. DDos attack
- B. Malicious programs
- C. Hacking
- D. Natural disasters
Answer: D
NEW QUESTION 73
Which of the following is true about the description of the TCP/IP protocol stack packet encapsulation?
(Multiple choice)
- A. After receiving the data packet, the network layer is stripped after parsing, and the upper layer processing protocol is known according to the parsing information, such as HTTP
- B. After the transport layer (TCP) receives the data packet, the transport layer information is stripped after parsing, and the upper layer processing protocol, such as UDP, is known according to the parsing information
- C. After the application layer receives the data packet, the application layer information is stripped after parsing, and the user data displayed at the end is exactly the same as the data sent by the sender host.
- D. The data packet is firsttransmitted to the data link layer. After parsing, the data link layer information is stripped, and the network layer information is known according to the parsing information, such as IP.
Answer: C,D
NEW QUESTION 74
Which of the following is not included in the steps of the safety assessment method?
- A. Manual audit
- B. Penetration test
- C. Questionnaire survey
- D. Data analysis
Answer: D
NEW QUESTION 75
In the information security system construction management cycle, which of the following actions is required to be implemented in the "check' link?
- A. Safety managementsystem operation monitoring
- B. Implementation of the safety management system
- C. Safety management system design
- D. Risk assessment
Answer: D
NEW QUESTION 76
Which of the following is correct about the description of SSL VPN?
- A. may IP encrypt layer
- B. There is a NAT traversal problem
- C. Can be used without a client
- D. No authentication required
Answer: C
NEW QUESTION 77
Both A and B communicate data. If an asymmetric encryption algorithm is used for encryption, when A sends data to B, which of the following keys will be used for data encryption?
- A. A public key
- B. B public key
- C. B private key
- D. A private key
Answer: B
NEW QUESTION 78
Firewall update signature database and Virus database online throjgh security servicecenter, requires the firewall can connect to the Internet first, and then need to configure the correct DNS addresses.
- A. FALSE
- B. TRUE
Answer: B
NEW QUESTION 79
What are the main security capability of encryption service? (Choose three.)
- A. Confidentiality
- B. Non-repudiation
- C. Scalability
- D. Integrity
Answer: A,B,D
NEW QUESTION 80
For the occurrence of network security incidents, the remote emergency response is generally adopted first. If the problem cannot be solved for the customer through remote access, after the customer confirms, it is transferred to the local emergency response process.
- A. False
- B. True
Answer: B
NEW QUESTION 81
Which of the following attacks is not a malformed packet attack?
- A. Teardrop attack
- B. TCP fragmentation attack
- C. ICMP unreachable packet attack
- D. Smurf attack
Answer: C
NEW QUESTION 82
Information security levelprotection is the basic system of national information security work
- A. False
- B. True
Answer: B
NEW QUESTION 83
The following security policy command, representatives of the meaning:
- A. banned from trust region access to untrust region and the source address is 10.2.10.10 host to all the hosts ICMP message
- B. banned from trust region access to untrust region and the destination address is 10.1.0.0/16 segment all hosts ICMP message
- C. banned from trust region access to untrust region and the destination address is 10.1.10.10 host ICMP message
- D. banned from trust region access to untrust region and the source address is 10.1.0.0/16 segment all the hosts ICMP message
Answer: D
NEW QUESTION 84
Security policy conditions can be divided into multiple fields, such as source address, destination address, source port, destination port, etc. These fields are "and " , that is, only information in the message and all fields If you match, you can hit this strategy
- A. False
- B. True
Answer: A
NEW QUESTION 85
The attacker by sending ICMP response request, and will request packet destination address set to suffer Internet radio address. Which kind of attack does this behavior belong to9
- A. IP spoofing attack
- B. Smurf attack
- C. SYN flood attack
- D. ICMP redirect attack
Answer: B
NEW QUESTION 86
Regarding the AH and ESP security protocols, which ofthe following options is correct? (Multiple Choice)
- A. The agreement number of AH is 51.
- B. ESP can provide encryption and verification functions
- C. The agreement number of ESP is51.
- D. AH can provide encryption and verification functions
Answer: A,B
NEW QUESTION 87
Fire Trust domain FTP client wants to access an Um.rust server FTP service has allowed the client: to access the server TCP 21 port, the client in the Windows command line window can log into the FTP server, but can not download the file, what are the following solutions? (Multiple choice)
- A. Trust Untrust domain configuration is enabled detect ftp
- B. The ^TP works with the port mode modify the Untru3t Trust domain to allow the inbound direction between the default access strategy
- C. FTP works with Passive mode modify the domain inbound direction betv/een the Untrust Trust default access policy to allow
- D. Take the Trust between Un:rust domain to allow two-way default access strategy
Answer: A,B,D
NEW QUESTION 88
Which of the following are core elements of the IATF (Information Assurance Technology Framework) model? (Multiple choice)
- A. person
- B. Technology
- C. Operation
- D. Environment
Answer: A,B,C
NEW QUESTION 89
If the administrator uses the default authentication domain to authenticate a user, you only need to enter a user name when the user logs, if administrators use the newly created authentication domain to authenticate the user, the user will need to enter login "username @ Certified domain name"
- A. False
- B. True
Answer: B
NEW QUESTION 90
Which of the following is the core part of the P2DR model?
- A. Response
- B. Protection
- C. Detection
- D. Policy Strategy
Answer: D
NEW QUESTION 91
......
H12-711 Deluxe Study Guide with Online Test Engine: https://www.trainingquiz.com/H12-711-practice-quiz.html
NEW 2021 Certification Sample Questions H12-711 Dumps & Practice Exam: https://drive.google.com/open?id=1vBOevax2P89BPHMZ4gQGnThqmVo66kS-

