Huawei HCIE-Security (Huawei Certified Internetwork Expert-Security) - H12-731-ENU Exam Practice Test
Which of the following is correct for the functional comparison of NIP5000 and NIP5000D:
Correct Answer: A,B,D
For the admission control of the existing wired network, the SACG authentication scheme is recommended. What are the advantages?
Correct Answer: C,D
The following HWTACACS configuration has been made on the firewall:
<sysname> system-view
[sysname] hwtacacs-server template server1
[sysname-hwtacacs-server1] hwtacacs-server authentication 3.3.3.3 10000
[sysname-hwtacacs-server1] hwtacacs-server accounting 3.3.3.3 10010
Please point out the problem in this configuration:
<sysname> system-view
[sysname] hwtacacs-server template server1
[sysname-hwtacacs-server1] hwtacacs-server authentication 3.3.3.3 10000
[sysname-hwtacacs-server1] hwtacacs-server accounting 3.3.3.3 10010
Please point out the problem in this configuration:
Correct Answer: A
Which of the following options fall under the scope of visitor management?
Correct Answer: B,C,E,F
Use NGFW for SSL VPN connection, use certificate authentication, certificate can be selected, but after clicking login, you cannot log in to the resource page. After using debug check on NGFW, it prompts that the certificate is wrong.
<NGFW>debugging ssl error
<NGFW>terminal debugging
<NGFW>terminal monitor
*0.10012266 USG2130 SSL/7/error:
SSL 3.0, Alert, write, fatal bad certificate
But check that the certificate is complete and the contents of the certificate are correct.
What are the possible reasons for this certificate validation error?
<NGFW>debugging ssl error
<NGFW>terminal debugging
<NGFW>terminal monitor
*0.10012266 USG2130 SSL/7/error:
SSL 3.0, Alert, write, fatal bad certificate
But check that the certificate is complete and the contents of the certificate are correct.
What are the possible reasons for this certificate validation error?
Correct Answer: B,D
Regarding the authentication mode of 802.1X, which of the following descriptions are correct?
Correct Answer: A,B
Regarding SACG's built-in ACL, which of the following statements are correct?
Correct Answer: B,C
A company has the following requirements:
The intranet users in the Trust area are on the 192.160.1.0/24 network segment and can access the Internet.
Which of the following configurations are correct:
traffic-policy
profile trust_tountrust
bandwidth downstream
maximum-bandwidth 400000
bandwidth downstream
guaranteed-bandwidth 50000
bandwidth ip-car downstream
maximum-bandwidth per-ip 2000
rule name trust_to_untrust
source-zone trust
destination-zone untrust
source-address 192.160.1.0 24
action qos profile
trust_to_untrust
#

The intranet users in the Trust area are on the 192.160.1.0/24 network segment and can access the Internet.
Which of the following configurations are correct:
traffic-policy
profile trust_tountrust
bandwidth downstream
maximum-bandwidth 400000
bandwidth downstream
guaranteed-bandwidth 50000
bandwidth ip-car downstream
maximum-bandwidth per-ip 2000
rule name trust_to_untrust
source-zone trust
destination-zone untrust
source-address 192.160.1.0 24
action qos profile
trust_to_untrust
#

Correct Answer: A,B
Which statement about MTU and PMTU is correct?
Correct Answer: A,B
Intranet users can access the Internet normally, and dual links are used for master and backup backup.
For Internet users, the FTP server can be accessed through the public network address. Two public network addresses are announced, 200.1.1.200 and 202.1.1.200.
Which of the following configuration is correct?

For Internet users, the FTP server can be accessed through the public network address. Two public network addresses are announced, 200.1.1.200 and 202.1.1.200.
Which of the following configuration is correct?

Correct Answer: A,D
When the firewall runs GRE, which three parameters must be configured on the tunnel interface?
Correct Answer: B,C,E
Configure the firewall as follows:
[USG-policy-security] rule name Trust Local
[USG-policy-security-rule-Untrust Local] source-zone trust
[USG-policy-security-rule-Untrust Local] destination-zone local
[USG-policy-security-rule-Untrust Local] source-address 192.168.5.2 32
[USG-policy-security-rule-Untrust Local] destination-address 192.168.5.1 32
[USG-policy-security-rule-Untrust Local] service http
[USG-policy-security-rule-Untrust Local] service telnet
[USG-policy-security-rule-Untrust Local] action permit
Please select the correct description below:
[USG-policy-security] rule name Trust Local
[USG-policy-security-rule-Untrust Local] source-zone trust
[USG-policy-security-rule-Untrust Local] destination-zone local
[USG-policy-security-rule-Untrust Local] source-address 192.168.5.2 32
[USG-policy-security-rule-Untrust Local] destination-address 192.168.5.1 32
[USG-policy-security-rule-Untrust Local] service http
[USG-policy-security-rule-Untrust Local] service telnet
[USG-policy-security-rule-Untrust Local] action permit
Please select the correct description below:
Correct Answer: A,D
Which of the following networking is not included in the common networking modes of the NIP5000?
Correct Answer: D
A network deploys the AntiDdos cleaning equipment at the network nodes in a bypass mode, and conducts bidirectional drainage and cleaning for the traffic drawn to the cleaning equipment.
The following networking is correct:
The following networking is correct:
Correct Answer: A
The following configuration, when the physical state of interface G0/0/1 goes down, what will happen to the switch switch?
PC ----------------- (G0/0/1) FW (G0/0/2) ---------------- Switch
#
interface GigabitEthernet0/0/1
link-group 1
interface GigabitEthernet0/0/2
link-group 1
#
PC ----------------- (G0/0/1) FW (G0/0/2) ---------------- Switch
#
interface GigabitEthernet0/0/1
link-group 1
interface GigabitEthernet0/0/2
link-group 1
#
Correct Answer: B