Spring Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code = getmirror

Pass the Huawei Certified Network Professional HCNP H12-721 Questions and answers with ExamsMirror

Practice at least 50% of the questions to maximize your chances of passing.
Exam H12-721 Premium Access

View all detail and faqs for the H12-721 exam


746 Students Passed

86% Average Score

95% Same Questions
Viewing page 3 out of 7 pages
Viewing questions 21-30 out of questions
Questions # 21:

The firewall device defends against the SYN Flood attack by using the technology of source legality verification. The device receives the SYN packet and sends the SYN-ACK probe packet to the source IP address host in the SYN packet. If the host exists, it will Which message is sent?

Options:

A.

RST message

B.

FIN message

C.

ACK message

D.

SYN message

Questions # 22:

What are the HRP backup methods supported by the USG?

Options:

A.

automatic backup

B.

manual batch backup

C.

fast backup

D.

real-time backup

Questions # 23:

In the firewall DDoS attack defense technology, the data packet of the session table is not defended. If the data packet of the session has been established, it is directly released.

Options:

A.

TRUE

B.

FALSE

Questions # 24:

The SSL VPN authentication login is unsuccessful and the message "Bad username or password" is displayed. Which one is wrong?

Options:

A.

username and password are entered incorrectly

B.

user or group filter field configuration error

C.

certificate filter field configuration error

D.

administrator configured a policy to limit the source IP address of the terminal

Questions # 25:

Connecting the internal network interface address from the firewall By pinging the internal network address of the peer, the IPSec tunnel can be successfully triggered. The internal PC cannot trigger the tunnel establishment. What are the possible reasons?

Options:

A.

IKE proposal configuration problem

B.

IPSec proposal configuration problem

C.

interested traffic ACL source network segment does not include the PC

D.

packet filtering (inter-domain policy) configuration problem

Questions # 26:

The USG_B status is HRP_M[USG_A], and the USG_B status is HRP_S[USG_B]. The status of the USG_A is HRP_M[USG_A]. However, all traffic did not pass USG_A completely, and half of the traffic also passed USG_B.

Options:

A.

[USG_A]hrp ospf-cost adjust-enable [USG_B]hrp ospf-cost adjust-enable

B.

[USG_B]interface GigabitEthernet 0/0/1 [USG_B- GigabitEthernet 0/0/1]hrp track master

   [USG_B]interface GigabitEthernet 0/0/3 [USG_B- GigabitEthernet 0/0/3]hrp track master

C.

hrp preempt delay 60

D.

The address of the heartbeat is not released to OSPF.

Questions # 27:

The figure shows the data flow direction of the Bypass interface in the Bypass working mode and the non-Bypass working mode. What are the following statements about the working flow of the electrical Bypass interface?

Question # 27

Options:

A.

When the interface is in the non-bypass state, the traffic flows from the GE0 interface to the USG through Router_a. After the USG processes, the traffic flows from the GE1 interface to Router_B.

B.

When the interface is working in the Bypass state, the traffic is forwarded from the GE0 interface to the USG. The USG does not pass any processing and flows directly from the GE1 interface to Router_B.

C.

When the firewall is configured to implement the security priority, the uplink and downlink services are not interrupted when the interface works in the bypass state. Therefore, the device can be kept in the Bypass state.

D.

The electrical bypass interface can only work in Layer 2 mode and has circuit bypass function.

Questions # 28:

In Huawei's abnormal traffic cleaning solution, the characteristics of the straight-line deployment mode and the bypass deployment mode are correct.

Options:

A.

straight path deployment method requires separate deployment of detection equipment

B.

side deployment mode requires separate deployment of detection equipment

C.

bypass deployment mode is more flexible than the direct route deployment mode. You can use static drainage or dynamic drainage.

D.

Straight-line deployment mode Anti-DDoS device performs real-time drainage on all traffic passing through

Questions # 29:

Which of the following technologies can enhance the security of mobile users accessing the company's intranet VPN solution?

Options:

A.

SSL

B.

PPPoE

C.

GRE

D.

L2TP

Questions # 30:

When an attack occurs, the result of packet capture on the attacked host (1.1.1.1) is as shown in the figure. What kind of attack is this attack?

Question # 30

Options:

A.

Smurf attack

B.

Land attack

C.

WinNuke attack

D.

Ping of Death attack

Viewing page 3 out of 7 pages
Viewing questions 21-30 out of questions
TOP CODES

TOP CODES

Top selling exam codes in the certification world, popular, in demand and updated to help you pass on the first try.