[Mar 12, 2023] Free Huawei Specialist H12-731-ENU Exam Question
H12-731-ENU dumps & Huawei Specialist sure practice dumps
NEW QUESTION 64
There are multiple real servers in an enterprise network that provide FTP services to the outside world, and the load balancing function is configured to ensure the load balancing of traffic flowing through the USG.
The administrator hopes that by detecting the real server status, the load ratio of each server is the same as the weight ratio. The following suitable configurations are:
- A. # Configure the real server to join the negative balance group. [USG-slb] group test [USG-slb-group-test] metric weightrr [USG-slb-group-test] addrserver 1 [USG-slb-group-test] addrserver 2 [USG-slb-group-test] addrserver 3 [USG-slb-group-test] quit
- B. # Configure the real server to join the negative balance group. [USG-slb] group test [USG-slb-group-test] metric roundrobin [USG-slb-group-test] addrserver 1 [USG-slb-group-test] addrserver 2 [USG-slb-group-test] addrserver 3 [USG-slb-group-test] quit
- C. # Configure the real server to join the negative balance group. [USG-slb] group test [USG-slb-group-test] metric least-connection [USG-slb-group-test] addrserver 1 [USG-slb-group-test] addrserver 2 [USG-slb-group-test] ] addrserver 3 [USG-slb-group-test] quit
- D. # Configure the real server to join the negative balance group. [USG-slb] group test [USG-slb-group-test] metric srchash [USG-slb-group-test] addrserver 1 [USG-slb-group-test] addrserver 2 [USG-slb-group-test] addrserver 3 [USG-slb-group-test] quit
Answer: A
NEW QUESTION 65
When using the UTM function, the link state detection function can be disabled to prevent packet loss due to failure of the firewall state detection when network packets are inconsistent with the round-trip paths.
- A. FALSE
- B. TRUE
Answer: A
NEW QUESTION 66
Which of the following statements about URL filtering is false?
- A. URL matching method supports blacklist and whitelist
- B. Prefix and suffix matching only supports black and white lists but not custom classifications
- C. The order of URL filtering is whitelist>blacklist>custom URL>predefined URL
- D. Cannot associate time objects when applying URL profiles to security policies
Answer: B,D
NEW QUESTION 67
Regarding the authentication mode of 802.1X, which of the following descriptions are correct?
- A. Under the same interface, port-based and MAC-based modes can be enabled at the same time.
- B. From the point of view of the authentication requirements for all access users, the port-based mode is more secure than the MAC-based mode.
- C. 802.1X authentication mode is divided into interface-based and MAC-based.
- D. From the point of view of the authentication requirements for all access users, the MAC-based mode is more secure than the port-based mode.
Answer: C,D
NEW QUESTION 68
For the networking shown in the figure, one end of the IPsec tunnel uses two devices for dual-system hot backup. When the master-slave switchover occurs, which of the following descriptions is correct?
- A. The IPsec tunnel does not require renegotiation.
- B. The Keepalive mechanism consumes less CPU resources than the DPD mechanism.
- C. Packets from USG_C to HQ will trigger renegotiation, and services will not be affected.
- D. Configure the dpd mechanism on USG_A, USG_B, and USG_C to increase the reliability of IPsec dual-system hot backup.
Answer: A,D
NEW QUESTION 69
Regarding the firewall IP-Link feature, the following description is incorrect:
- A. The firewall continuously sends ICMP packets to the specified destination address, and if no ICMP echo reply is received for 3 seconds (default), the link is considered to be faulty.
- B. The firewall continuously sends ARP request packets to the target network segment, and when it receives ARP response packets, it considers the link to be normal.
- C. ARP detection mode only supports detection of direct links.
- D. The ICMP detection method can be used to detect the reliability of chromium paths across network segments.
Answer: B
NEW QUESTION 70
What are the methods for firewalls to diagnose forwarding faults?
- A. Debug IP Packet
- B. Statistics of detailed packet loss classification
- C. Packet loss statistics based on 5-tuple
- D. message missing
- E. View session table
Answer: A,C,D
NEW QUESTION 71
In order to ensure the normal operation of the device and prevent security threats, it is necessary to strengthen the security of the device. The correct consideration is:
- A. Use Telnet protocol for device management.
- B. Set the console password, and set the login timeout and authentication times limit of the administrator interface.
- C. SNMPv2 version and network management communication.
- D. The security policy from Untrust, Trust, DMZ zone to Local zone only opens ports that allow ICMP, SSH login, SNMP, etc.
Answer: B,D
NEW QUESTION 72
In the scenario of dual-system hot backup of firewalls, IPsec VPN does not support real-time backup of tunnels.
- A. FALSE
- B. TRUE
Answer: A
NEW QUESTION 73
The following HWTACACS configuration has been made on the firewall:
<sysname> system-view
[sysname] hwtacacs-server template server1
[sysname-hwtacacs-server1] hwtacacs-server authentication 3.3.3.3 10000
[sysname-hwtacacs-server1] hwtacacs-server accounting 3.3.3.3 10010
Please point out the problem in this configuration:
- A. The port number used to configure the accounting server is incorrect.
- B. Authentication and accounting servers should not use the same IP address.
- C. The port number used by the configured authentication server is incorrect.
- D. The authorization server is not configured.
Answer: D
NEW QUESTION 74
The IPsecVPN tunnel is successfully established, but the speed of accessing the peer's private network web page is slow or the access is intermittent. The influence of the Internet network quality has been ruled out. The following possible faults are:
- A. There is a NAT device in the middle of the network
- B. The CPU usage of the egress gateway is too high
- C. The problem of packet fragmentation
- D. Packet filtering policy is not enabled
Answer: B,C
NEW QUESTION 75
As shown in the figure, the routing example between the virtual firewall vpn1 and the root firewall needs to be configured.
Which of the following is correct:
- A. [USG-vpn1] ip route-static 202.168.10.0 255.255.255.0 202.168.20.3 vpn-instance vpn1 [USG] ip route-static 10.1.1.0 255.255.255.0 vpn-instance vpn1 10.1.2.2.2
- B. [USG-vpn1] ip route-static 202.168.10.0 255.255.255.0 202.168.20.3 public [USG] ip route-static 10.1.1.0 255.255.255.0 10.1.2.2.2
- C. [USG-vpn1] ip route-static 202.168.10.0 255.255.255.0 202.168.20.3 [USG] ip route-static 10.1.1.0 255.255.255.0 vpn-instance vpn1 10.1.2.2.2
- D. [USG-vpn1] ip route-static 202.168.10.0 255.255.255.0 public [USG] ip route-static 10.1.1.0 255.255.255.0 vpn-instance vpn1 10.1.2.2.2 [USG] ip route-static 202.168 .10.0 255.255.255.0 250.168.20.3
Answer: D
NEW QUESTION 76
The firewall is deployed between the mobile terminal of the wireless user and the WAP gateway, the mobile terminal is in the trust zone, and the WAP gateway is in the untrust zone, and the following configurations are made:
[USG] ad 3000
[USG-acl-adv-3000] rule permit ip destination 202.10.10.2 0
[USG-acl-adv-3000] quit
[USG] fir-all zone trust
[USG-zone-trust] destination-nat 3000 address 200.10.10.2
[USG-zone-trust] quit
The following descriptions are correct:
- A. The firewall translates the destination address of the packet accessing the gateway address of 202.10.10.2 to 200.10.10.2
- B. The command firewall zone trust should be changed to firewall interzone trust untrust outbound
- C. The command firewall zone trust should be changed to firewall interzone untrust trust
- D. This configuration can also be applied to server address mapping scenarios
Answer: A
NEW QUESTION 77
VGMP unified management of VRRP backup group status, the priority of VGMP management group Active is 65001, and the priority of Standby is 65000. When the VGMP management group monitors the interface Down through the VRRP backup group or directly, the priority of the VGMP management group will be recalculated. When each interface is Down, the priority of the VGMP management group decreases by 2.
- A. FALSE
- B. TRUE
Answer: B
NEW QUESTION 78
What are the advantages of PortaI authentication compared to 802.1X authentication?
- A. Portal authentication does not require installation of client software.
- B. Portal authentication is more suitable for casual visitors to the network.
- C. Portal can be used in dumb terminal access scenarios.
- D. Portal authentication is compatible with MAC authentication.
Answer: A,B
NEW QUESTION 79
For border network security, which of the following options are recommended for planning and deployment priorities?
- A. Security Domain Isolation
- B. Enable DDoS function
- C. IPS Real-Time Intrusion Prevention
- D. Deploy VPN
- E. Enable device virtualization
Answer: A,B,C
NEW QUESTION 80
......
Huawei H12-731-ENU Actual Questions and Braindumps: https://www.examtorrent.com/H12-731-ENU-valid-vce-dumps.html
Pass H12-731-ENU Exam with Updated H12-731-ENU Exam Dumps PDF 2023: https://drive.google.com/open?id=1GOTs2SnMEo18cPJbidg-05Yu7hHVOjMY
