Verified H12-731-ENU dumps Q&As 100% Pass in First Attempt Guaranteed Updated Dump from ExamTorrent
Pass Huawei Specialist H12-731-ENU Exam With 205 Questions
The Huawei H12-731-ENU exam tests the knowledge and skills of IT professionals in areas such as network security technologies, network security protocols, network security products and solutions, and network security design and implementation. The exam is designed to assess the ability of IT professionals to analyze complex security problems, design and implement security solutions, and manage and maintain secure network environments.
The Huawei H12-731-ENU certification exam is an excellent choice for IT professionals who are looking to advance their careers in the field of network security. This certification is highly respected in the industry and is recognized globally. Candidates who pass the exam will have the skills and knowledge necessary to design and implement effective security solutions for complex network environments.
NEW QUESTION # 115
The customer has a USG6000, and the remote PC wants to access the intranet through l2tp over ipsec, but the dial-up through the vpn client software is unsuccessful.
1 View ike sa during dialing:
<USG6000>dis ike sa
20:54:36 2013/06/19
current ike sa number: 2
-------------------------------------------------- -----------------------------
conn-id peer flag phase vpn
-------------------------------------------------- ------------------------------
40051 <unnamed> NONE v1:2 public
40050 2.2.2.2:12485 NONE v1:1 public
2 debugging ipsec error:
2013-06-19 20:54:21 USG2100 %%01IKE/4/WARNING (I): phase2: security acl mismatch.
*0.46319980 USG IKE/7/DEBUG: Get IPsec policy: get IPsec policy failed
*0.46319930 USG IKE/7/DEBUG: validate_prop: no IPsec policy found
*0.46319980 USG IKE/7/DEBUG: dropped message from 2.2.2.2 due to notification type
INVALID ID INFORMATION
Which statement about this problem is correct?
- A. HASH algorithm mismatch
- B. ACL configuration error
- C. IKE Phase 1 policy for IPsec is misconfigured
- D. No IPsec policy configured
Answer: B
NEW QUESTION # 116
When the firewall uses WEB redirection password authentication, the user does not take the initiative to authenticate, but first accesses the business, and the firewall redirects the page to the "authentication page". After successful authentication, it automatically jumps to the page the user visited before.
- A. FALSE
- B. TRUE
Answer: B
NEW QUESTION # 117
The USG serves as the gateway of the headquarters. Users on business trips need to use the Internet to establish a VPN tunnel to access the resources of the headquarters, and users on business trips do not need to install any dial-up software. Which of the following VPN technologies is most suitable:
- A. IPsec VPN
- B. L2TP
- C. GRE
- D. SSL VPN
Answer: D
NEW QUESTION # 118
Which fields in the packet need to be analyzed in the firewall's IP packet fragmentation and reassembly?
- A. Fragment Offset
- B. Flags
- C. Lifetime TTL
- D. Total Length
- E. Identifier
Answer: A,B,E
NEW QUESTION # 119
NGFW_A and NGFW_B, NGFW_A and NGFW_C configure static routes respectively. NGFW_A -> NGFW_B is the primary link, NGFW_A -> NGFW_C is the backup link. It is required that the traffic can be quickly switched to the backup link when the primary link fails; the traffic can be switched to the primary chromium road after the primary link is restored.
Which of the following configurations is correct?
- A. [USG_A] bfd
[USG_A] bfd ab bind peer-ip 10.1.1.2
[USG_A-bfd-session-ab] discriminator local 10
[USG_A-bfd-session-ab] discriminator remote 20
[USG_A-bfd-session-ab] commit
[USG_A] ip route-static 0.0.0.0 0 10.1.1.2
[USG_A] ip route-static 0.0.0.0 0 20.1.1.2 preference 100 track bfd-session ab - B. [USG_B] bfd
[BSG_B] bfd ab bind peer-ip 10.1.1.1
[USG_B-bfd-session-ab] discriminator local 20
[USG_B-bfd-session-ab] discriminator remote 10
[USG_B-bfd-session-ab] commit - C. [USG_A] bfd
[USG_A] bfd ab bind peer-ip 10.1.1.2
[USG_A-bfd-session-ab] discriminator local 10
[USG_A-bfd-session-ab] discriminator remote 20
[USG_A-bfd-session-ab] commit
[USG_A] ip route-static 0.0.0.0 0 10.1.1.2 track bfd-session ab
[USG_A] ip route-static 0.0.0.0 0 20.1.1.2 preference 100 - D. [USG_B] bfd
[BSG_B] bfd ab bind peer-ip 10.1.1.1
[USG_B-bfd-session-ab] discriminator local 10
[USG_B-bfd-session-ab] discriminator remote 20
[USG_B-bfd-session-ab] commit
Answer: B,C
NEW QUESTION # 120
Which of the following commands cannot be backed up in the command backup function of the firewall's dual-system hot backup?
- A. Forwarding Policy Commands
- B. IPS command
- C. IP address configuration
- D. routing table
Answer: C,D
NEW QUESTION # 121
The Trust zone of the USG firewall of a certain network is connected to the terminal host, and the Untrust zone is connected to the security controller. If the security controller can issue rules to the USG, which of the following security policies must be configured?
- A. security-policy rule name untrust_to_local source-zone untrust destination-zone local action permit
- B. security-policy rule name local_to_trust source-zone local destination-zone trust action permit
- C. security-policy rule name untrust_to_local source-zone untrust destination-zone local action permit rule name local_to_trust source-zone local destination-zone trust action permit
- D. security-policy rule name to_local source-zone untrust trust destination-zone local action permit
Answer: A
NEW QUESTION # 122
For the description of NAT Server, which is correct?
- A. If the public network address of the NAT Server and the corresponding public network interface address are not in the same network segment, you do not need to configure black hole routing.
- B. If the public network address of the NAT Server and the corresponding public network interface address are in the same network segment, you do not need to configure black hole routing.
- C. NAT Server cannot be configured on the virtual firewall for users of the root firewall.
- D. If the public network address of the NAT Server is the interface address, if the black hole route of this address is configured, the service access to the firewall itself will be abnormal.
Answer: B
NEW QUESTION # 123
The firewall uses display diagnostic-information to collect system diagnostic information in the diagnosis view, but cannot obtain the information output by which of the following commands?
- A. display version
- B. debug ip packet
- C. display current-configuration
- D. display history-command
Answer: B
NEW QUESTION # 124
The packet encapsulation of L2TP Over IPsec is:
- A. IP header+ESP header+L2TP header+PPP header+encrypted PPP payload+ESP trailer+Auth trailer
- B. IP header+ESP header+UDP header+L2TP header+PPP header+encrypted PPP payload+ESP trailer+Auth trailer
- C. IP header+UDP header+ESP header+L2TP header+PPP header+encrypted PPP payload+Auth trailer+ESP trailer
- D. ESP header+IP header+UDP header+L2TP header+PPP header+encrypted PPP payload+Auth trailer+ESP trailer
Answer: B
NEW QUESTION # 125
A network expects to use URPF technology to improve network security. Which mode of URPF is used in the following networking scenarios:
- A. loose mode
- B. strict mode or loose mode
- C. strict mode
- D. According to the stem information, the corresponding mode cannot be judged
Answer: A
NEW QUESTION # 126
Configure the firewall as follows:
[USG-policy-security] rule name Trust Local
[USG-policy-security-rule-Untrust Local] source-zone trust
[USG-policy-security-rule-Untrust Local] destination-zone local
[USG-policy-security-rule-Untrust Local] source-address 192.168.5.2 32
[USG-policy-security-rule-Untrust Local] destination-address 192.168.5.1 32
[USG-policy-security-rule-Untrust Local] service http
[USG-policy-security-rule-Untrust Local] service telnet
[USG-policy-security-rule-Untrust Local] action permit
Please select the correct description below:
- A. Allow the firewall to log in to the device at 192.168.5.1 through the Web.
- B. Allow the firewall to log in to the device at 192.168.5.1 through Telnet.
- C. Allow the 192.168.5.2/24 address segment to log in to the firewall via Web.
- D. Allow the IP address 192.168.5.2/24 to log in to the firewall through Telnet.
Answer: C,D
NEW QUESTION # 127
The main differences between the RADIUS and HWTACACS protocols include:
- A. HWTACACS encrypts the entire body of the message, and RADIUS only encrypts the password field in the authentication message.
- B. RADIUS authentication and authorization are separated, and HWTACACS authentication and authorization are processed together.
- C. RADIUS uses TCP protocol, network transmission is more reliable, HWTACACS uses UDP protocol.
- D. HWTACACS supports authorization of configuration commands, RADIUS does not support authorization of configuration commands.
Answer: A,D
NEW QUESTION # 128
In the process of IPsec negotiation failure, turn on the debug switch of IKE and display the following information: got NOTIFY of type NO_PROPOSAL CHOSEN or drop message from ABCD due to notification type NO_PROPOSAL CHOSEN , what should I do?
- A. If the negotiation is not successful in the first phase, the pre-share-key may be configured incorrectly.
- B. If the negotiation is not successful in the first stage, it may be that the ike proposal does not match.
- C. If the negotiation is not successful in the second phase, it may be that the ipsec proposal does not match.
- D. If the negotiation is not successful in the second phase, it may be that the ACL does not match.
Answer: B,C
NEW QUESTION # 129
Comparing the two technologies of mail content filtering and RBL filtering, the correct statement is:
- A. RBL filtering only filters messages sent by male POP3.
- B. RBL filtering is based on the destination IP address of the SMTP connection.
- C. Mail content filtering Filters the mail content.
- D. Mail Content Filtering supports filtering of webmail or mail transmitted via SMTP/POP3.
Answer: C,D
NEW QUESTION # 130
The firewall single sign-on authentication process as shown in the figure includes the following main links:
a. Find user group information on AD server
b. The device has created an online user list, and the user directly accesses external resources
c. Send information such as username and group to the device
d. User requests authentication
e. Actively send a message to the AD monitoring service (username, user IP address)
f . Server authentication passed
Please select the correct correspondence between letters and numbers ?
- A. ① -> d ② -> f ③ -> e ④ -> d ⑤ -> C ⑥ -> b
- B. ① -> d ② -> e ③ -> f ④ -> a ⑤ -> C ⑥ -> b
- C. ① -> d ② -> f ③ -> d ④ -> e ⑤ -> C ⑥ -> b
- D. ① -> d ② -> e ③ -> d ④ -> f ⑤ -> C ⑥ -> b
Answer: A
NEW QUESTION # 131
What are the mechanisms for implementing intrusion prevention?
- A. Response handling
- B. feature matching
- C. Protocol identification and protocol resolution
- D. Blacklist match
Answer: A,B,C
NEW QUESTION # 132
When the link state detection function of the USG firewall is enabled, when the interval between sending the first fragmented packet and the second fragmented packet of a TCP session is greater than the aging time of the session table, the session table will be deleted, and the subsequent packets will be deleted. The text will recreate the session table.
- A. TRUE
- B. FALSE
Answer: B
NEW QUESTION # 133
Using the SSL function of the USG gateway, the administrator can quickly and securely access all resources in the enterprise intranet, not only Web resources, and ensure that the communication between the client and the virtual gateway adopts the SSL security protocol, and the SSL client must ensure that the Without affecting access to other network resources, you can directly access Internet resources.
- A. port forwarding
- B. Network expansion in full routing mode
- C. Network extension in manual mode
- D. Network extension in split mode
Answer: C
NEW QUESTION # 134
The correct deployment recommendations for the abnormal traffic cleaning system are:
- A. Side-by-side deployment or in-line deployment at the network egress.
- B. The management server sends policies to network devices through SNMP protocol.
- C. The management server uses Telnet to monitor network devices.
- D. The testing center and cleaning center report logs to the collector.
Answer: A,D
NEW QUESTION # 135
The terminal uses Agent for 802.1x authentication, the IP address of SC and Radius server is 172.18.10.68, and it always prompts network communication failure during authentication;
Viewing the Radius authentication log shows that the Radius authentication is successful and the authorization is ACL3001. The switch configuration is as follows:
dot1x enable
dot1x authentication-method eap
radius-server template lzy
radius-server shared-key simple 123456
radius-server authentication 172.18.10.68 1812
radius-server accounting1 72.1 3.10.63 1813
radius-server authorization 172.18.10.68 shared-key simple 123456
aaa
authentication-scheme default
authentication-scheme auth
authentication-mode radius
accounting-scheme acco
accounting-mode radius
accounting realtime 3
domain default
authentication-scheme auth
accounting-scheme acco
radius-server lzy
interface GigabitEthernet0/0/14
description connect 222
port hybrid pvid vlan 105
port hybrid untagged vlan 105
dot1x enable
acl number 3001
rule 1 permit ip destination 172.18.100.235 0
rule 2 permit ip destination 172.18.100.237 0
rule 10 deny ip
What could be the reason for the failure of network communication?
- A. GigabitEthernet0/0/14 port configuration error
- B. Billing configuration may be wrong
- C. Authorization rule ACL configuration error
- D. AAA configuration error
Answer: C
NEW QUESTION # 136
A company has the following requirements:
The intranet users in the Trust area are on the 192.160.1.0/24 network segment and can access the Internet.
Which of the following configurations are correct:
traffic-policy
profile trust_tountrust
bandwidth downstream
maximum-bandwidth 400000
bandwidth downstream
guaranteed-bandwidth 50000
bandwidth ip-car downstream
maximum-bandwidth per-ip 2000
rule name trust_to_untrust
source-zone trust
destination-zone untrust
source-address 192.160.1.0 24
action qos profile
trust_to_untrust
#
- A. This configuration will achieve an overall upload bandwidth of 50M for intranet 192.168.1.0/24 users.
- B. This configuration will enable Trust intranet users to actively access the Internet outside the Internet and limit the total maximum download bandwidth to 400M.
- C. This configuration will implement the download traffic in the direction from Trust to Untrust, and the maximum bandwidth per IP is 2M.
- D. This configuration will implement speed limit for Internet addresses to actively access the intranet segment.
Answer: B,C
NEW QUESTION # 137
The attacker sends a TCMP request message to the broadcast address in the network with the attacker's IP address, so that all hosts in the network respond to the attacked ICMP response message, causing the victim's system to be busy and link congestion.
Why is this attack attacked?
- A. Land Attack
- B. Smurf Attack
- C. Fraggle Attack
- D. IP Spoofing Attack
Answer: B
NEW QUESTION # 138
......
Ultimate Guide to Prepare Free H12-731-ENU Exam Questions and Answer: https://drive.google.com/open?id=1GOTs2SnMEo18cPJbidg-05Yu7hHVOjMY
Pass H12-731-ENU Tests Engine pdf - All Free Dumps: https://www.examtorrent.com/H12-731-ENU-valid-vce-dumps.html
