Summer Sale Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: s2p65

Easiest Solution 2 Pass Your Certification Exams

H12-721 Huawei Certified ICT Professional - Constructing Infrastructure of Security Network Free Practice Exam Questions (2025 Updated)

Prepare effectively for your Huawei H12-721 Huawei Certified ICT Professional - Constructing Infrastructure of Security Network certification with our extensive collection of free, high-quality practice questions. Each question is designed to mirror the actual exam format and objectives, complete with comprehensive answers and detailed explanations. Our materials are regularly updated for 2025, ensuring you have the most current resources to build confidence and succeed on your first attempt.

Page: 3 / 4
Total 217 questions

In the IPSec active/standby link backup application scenario, gateway B uses IPSec tunneling technology and gateway A to establish an IPSec VPN.

A.

TRUE

B.

FALSE

In the active/standby mode of the USG dual-system hot standby, the service interface works at Layer 3, and the upstream and downstream routers are connected to the router. The administrator can view: USG_A status is HRP_M[USG_A], USG_B status is HRP_S[USG_B], current 15000+ session Table, every time a switchover occurs, all traffic is interrupted for a period of time, and seamless switching is impossible.

A.

Execute the command hrp preempt delay 64 to lengthen the delay of preemption.

B.

Check connectivity between heartbeat lines

C.

does not configure session fast backup

D.

no hrp enable

The following figure shows the data packet of the pre-shared key mode main mode exchange process in the first phase of IKE V1. What is captured below?

A.

exchange D-H public value and various auxiliary data

B.

SA suggested strategy

C.

authentication

D.

encryption transformation strategy

When the firewall works in the dual-system hot backup load balancing environment, if the upstream and downstream routers are working in the routing mode, you need to adjust the OSPF cost based on HRP.

A.

TRUE

B.

FALSE

The management control information and service information of the out-of-band management interface are sent on the same channel.

A.

TRUE

B.

FALSE

USG dual-machine hot standby must meet certain conditions and can be used below. What are the following statements correct?

A.

major and backup equipment must have the same product model

B.

The software version of the active and standby devices must be the same.

C.

The interface IP of the active and standby devices must be the same.

D.

The primary device must be configured, and the standby device does not require any configuration.

The IPSec establishment of a device is unsuccessful. The debug print information is as follows. What are the possible causes of the fault?

? %%01IKE/4/WARING(1):phase2:proposal mismatch,please check ipsec proposal configuration 0 34476900 %%01IKE/7/DEBUG(d) dropped message from 3.3.3.1 due to notification type NO_PROPOSAL_CHOSEN

A.

IKE proposal parameters are inconsistent

B.

IPSec proposal parameters are inconsistent

C.

ike peer configuration error

D.

Security acl configuration error

By default, GigabitEthernet0/0/0 can be used as an out-of-band management interface in the USG2200 series.

A.

TRUE

B.

FALSE

What type of message is the VRRP hello message?

A.

unicast message

B.

broadcast message

C.

multicast packet

D.

UDP packet

Accessing the headquarters server through the IPSec VPN from the branch computer. The IPSec tunnel can be established normally, but the service is unreachable. What are the possible reasons?

A.

packet is fragmented, and fragmented packets are discarded on the link.

B.

There is load sharing or dual-machine link, which may be inconsistent with the back and forth path.

C.

route oscillating

D.

DPD detection parameters are inconsistent at both ends

An administrator can view the status of the device components by the following command: The status of the Slot3 board is Abnormal. What are the possible causes of the following faults?

A.

This slot is not supported in this slot of device A.

B.

interface card is damaged

C.

The pin on the backplane or motherboard is damaged. If the incorrect board is installed, the pin is tilted.

D.

ADSL telephone line failure

The following scan snoop attacks are:

A.

SIP Flood attack

B.

HTTP Flood attack

C.

IP address scanning attack

D.

ICMP redirect packet attack

The interaction process of the firewall linkage NIP intrusion detection device is: 1. record the intrusion process, alarm log record; 2. NIP for attack detection; 3. reconfigure the firewall; 4 terminate the intrusion Which of the following correct interaction sequences is the same?

A.

1 2 3 4

B.

2 1 3 4

C.

3 1 2 4

D.

1 2 4 3

In the IPSec VPN, the digital certificate is used for identity authentication. If the IKE main mode is used for negotiation, the certificate verification is completed in message 5 and message 6.

A.

TRUE

B.

FALSE

As shown in the figure, the Eth-trunk function is required to bind the interface. On this basis, if you need to implement the load balancing function of each interface, you need to add the following configuration command?

A.

[USG] load-balance interface eth-trunk 1 packet-all

B.

[USG]interface eth-trunk 1 [USG-eth-trunk 1] load-balance packet-all

C.

[USG] load-balance interface eth-trunk 1 src-dst-ip

D.

[USG]interface eth-trunk 1 [USG-eth-trunk 1] load-balance src-dst-ip

What are the scenarios in which the USG series firewall service port sends gratuitous ARPs when the following configurations are performed?

A.

routing mode + switch

B.

routing mode + router

C.

exchange mode + switch

D.

exchange mode + router

Which of the following protocols does the USG firewall hot standby not include?

A.

HRP

B.

VRRP

C.

VGMP

D.

IGMP

Which of the following is not a message sent during ip-link detection?

A.

ARP packet

B.

IGMP message

C.

ICMP message

D.

Hello message

An intranet has made a network, the old equipment is offline, the new network equipment is brought online, and after the service test, it is found that most of the original service traffic cannot work normally. What is the quickest way to restore the business?

A.

layering method

B.

segmentation method

C.

replacement method

D.

block method

Which is incorrect about the IKE DPD statement?

A.

is used for detection of IKE neighbor status

B.

PDUs are sent periodically between B IKE PEERs.

C.

After the DPD function is enabled, the IPSec packet is not received within the interval specified by the interval, and the DPD sends a DPD request to the peer and waits for the response. Text

D.

DPD sends the query only before the encrypted message is sent and the timer expires.

Page: 3 / 4
Total 217 questions
Copyright © 2014-2025 Solution2Pass. All Rights Reserved