Huawei HCIE-Security (Huawei Certified Internetwork Expert-Security) 認定 H12-731-ENU 試験問題:
1. As shown in the figure, the corresponding defense methods are:
A) Authenticate the user through the associated TCP protocol
B) Fingerprint Learning Defense
C) Method defense through source authentication
D) Payload Check Defense
E) Defense by TTL checking
2. Which of the following statements about Unified Threat Management is true?
A) Solve the problem of current serial device deployment, such as firewall devices, IPS devices, AV devices, etc. are connected in series on a link.
B) With the development of UTM technology, UTM devices gradually begin to completely replace traditional firewalls.
C) In the use of users, the management and investment of network equipment is reduced, and network management personnel only need to master the use and management skills of a single device.
D) The unified threat management device integrates firewall, IPS, AV, AS, Internet behavior management and other functions.
3. When using the SSL VPN network extension function, the virtual IP address pool can be set to the same network segment as the IP address of the internal network interface of the device.
If the virtual IP address pool and the IP address of the intranet interface are not in the same network segment, manually configure the route to the address pool on the device, the outgoing interface is the intranet interface, and the next hop is the next hop of the intranet interface.
A) TRUE
B) FALSE
4. In the L2TP Over IPsec scenario, the central node uses the IPsec template, how to configure the IPsec Security ACL on the LNS at this time?
A) rule permit udp destination-port eq 1701
B) rule permit tcp source-port eq 1701
C) rule permit tcp destination-port eq 1701
D) rule permit udp source-port eq 1701
5. The WeChat voice (TCP) service of a site experienced a large delay, and the delay reached 3 seconds. As its egress NAT gateway, the firewall is configured with easy-ip nat mode (single egress), with link state detection disabled, TCP aging time of 30 seconds, small business traffic, and nearly 50,000 sessions to the voice server. Through the session, you can see a large number of packets of one-way access to the voice server.
What is the correct cause and solution for this failure?
A) If there is no inconsistency between the round-trip paths on the link, you can enable the link status detection function, and the aging time is default, which can solve this problem.
B) The solution could increase the TCP aging time to 600 seconds.
C) The aging time of the TCF session is too short, and it takes time for the firewall to create a new session.
D) After the firewall session is aging, the port after the NAT of the new connection is inconsistent with the port used to establish the connection with the server, resulting in no response from the server. The client needs to re-establish the connection after timeout before sending data.
質問と回答:
| 質問 # 1 正解: A、B、D | 質問 # 2 正解: A、C、D | 質問 # 3 正解: A | 質問 # 4 正解: D | 質問 # 5 正解: A、D |














1091 お客様のコメント
品質保証JPexamはIT認定試験のシラバスに従って、試験問題の範囲を正確に絞って、的中率が99%の最新問題集を捧げます。
1年間の無料更新サービスJPexamは1年以内に問題集の無料更新サービスを提供し、お客様がいつでも最新版の問題集を持つことを保証いたします。もし試験の内容が変更されたら、弊社は直ちにお客様にお知らせします。それに、弊社の問題集が更新されたら、早速メールで最新バージョンを送付いたします。
全額返金JPexamの問題集を利用すると、短時間で勉強しても試験に合格できるのを保証いたします。試験に不合格になってしまった場合、弊社は全額返金いたします。(
ご購入前のお試しJPexamは問題集のサンプルを無料で提供いたします。ご購入前にサンプルを試用して製品の品質を確認することができます。ご遠慮なく利用してください。
