Pass the Huawei Huawei Certified Network Professional HCNP H12-721 Questions and answers with CertsForce

Viewing page 3 out of 7 pages
Viewing questions 21-30 out of questions
Questions # 21:

What are the scenarios in which the USG series firewall service port sends gratuitous ARPs when the following configurations are performed?

Options:

A.

routing mode + switch


B.

routing mode + router


C.

exchange mode + switch


D.

exchange mode + router


Expert Solution
Questions # 22:

In the DDoS attack defense, if the service learning function is used to find that there is no service or traffic of a certain service in normal traffic, you can use the blocking or traffic limiting method to defend against attacks on the Anti-DDoS device. .

Options:

A.

TRUE


B.

FALSE


Expert Solution
Questions # 23:

The traffic limiting policy feature only supports the number of connections initiated by the specified IP or the number of connections received.

Options:

A.

TRUE


B.

FALSE


Expert Solution
Questions # 24:

The main function of URPF is to prevent network attack behavior based on destination address spoofing.

Options:

A.

TRUE


B.

FALSE


Expert Solution
Questions # 25:

In the active/standby mode of the USG dual-system hot standby, the service interface works at Layer 3, and the upstream and downstream routers are connected to the router. The administrator can view: USG_A status is HRP_M[USG_A], USG_B status is HRP_S[USG_B], current 15000+ session Table, every time a switchover occurs, all traffic is interrupted for a period of time, and seamless switching is impossible.

Question # 25

Options:

A.

Execute the command hrp preempt delay 64 to lengthen the delay of preemption.


B.

Check connectivity between heartbeat lines


C.

does not configure session fast backup


D.

no hrp enable


Expert Solution
Questions # 26:

Which is the correct packet encapsulation order for L2TP over IPSec?

Options:

A.

The order from the first package to the post package is PPP-->UDP-->L2TP-->IPSec


B.

The order from the first package to the back package is PPP--> L2TP-->UDP--> IPSec


C.

The order of C from pre-package to post-encapsulation is IPSec --> L2TP-->UDP--> PPP


D.

The order of D from pre-package to post-encapsulation is IPSec --> PPP --> L2TP-->UDP


Expert Solution
Questions # 27:

As shown in the figure, the firewall is dual-system hot standby. In this networking environment, all service interfaces of the firewall work in routing mode, and OSPF is configured on the upper and lower routers. Assume that the convergence time of OSPF is 30s after the fault is rectified. What is the best configuration for HRP preemption management?

Question # 27

Options:

A.

hrp preempt delay 20


B.

hrp preempt delay 40


C.

hrp preempt delay 30


D.

undo hrp preempt delay


Expert Solution
Questions # 28:

By default, GigabitEthernet0/0/0 can be used as an out-of-band management interface in the USG2200 series.

Options:

A.

TRUE


B.

FALSE


Expert Solution
Questions # 29:

In the IPSec VPN, the digital certificate is used for identity authentication. If the IKE main mode is used for negotiation, the certificate verification is completed in message 5 and message 6.

Options:

A.

TRUE


B.

FALSE


Expert Solution
Questions # 30:

Two USG firewalls failed to establish an IPSec VPN tunnel through the NAT traversal mode. Run the display ike sa command to view the session without any UDP 500 session. What are the possible reasons?

Options:

A.

public network route is unreachable


B.

Intermediate line device disables UDP port 500


C.

Intermediate line device disables UDP 4500 port


D.

Intermediate line device disables ESP packets


Expert Solution
Viewing page 3 out of 7 pages
Viewing questions 21-30 out of questions