Latest Mar-2023 Huawei H12-731-ENU Dumps Updated 205 Questions
PDF Download Free of H12-731-ENU Valid Practice Test Questions
NEW QUESTION 107
Which fields in the packet need to be analyzed in the firewall's IP packet fragmentation and reassembly?
- A. Flags
- B. Identifier
- C. Lifetime TTL
- D. Fragment Offset
- E. Total Length
Answer: A,B,D
NEW QUESTION 108
In the scenario of dual-system hot backup, what is wrong about the description of the main firewall device and the standby device?
- A. When the dual-system hot backup works in the active/standby state, the command prompt of the active device displays HRPA, and the command prompt of the standby device displays HRP_S.
- B. Configure the master device to define HRP_A, configure the slave device to define HRP_S, and it does not change with the priority.
- C. Only the master device can perform command configuration, and the standby device command cannot be configured.
- D. By default, the configuration of the active device will be backed up to the standby device immediately.
Answer: B,C
NEW QUESTION 109
The networking of a network is as follows: PC----ADSL router-----USG-----LAN
The key configurations of the USG are as follows:
l2tp enable
interface Virtual-Template1
ppp authentication-mode pap
ip address 4.1.1.1 255.255.255.0
remote address pool 1
l2tp-group 1
mandatory-Icp
allow 12tp virtual-template 1
#
user-ma page user pc1
password admin@123
aaa
domain default
ip pool 1 4.1.1.1 4.1.1.99
Assuming that other configurations are complete and correct, what is the problem with this configuration in actual work?
- A. Disconnect immediately after successful dialing.
- B. Failed to dial successfully.
- C. You can dial successfully, and you can also access the intranet server.
- D. The dial-up is successful, but the intranet server cannot be accessed.
Answer: B
NEW QUESTION 110
In NGFW, to use the RBL blacklist, which of the following key options need to be configured by the network administrator?
- A. SMTP server IP address
- B. Reply Code
- C. RBL server IP address
- D. DNS server
Answer: B,D
NEW QUESTION 111
Determine which QoS technology the USG device uses according to the following status information:
[USG_A] display qos policy interface tunnel 1
Interface: GigabitEthernet0/0/1
Direction: Outbound
Policy: dscp
Classifier: default-class
Matched: 0/0
(Packets/Bytes)
Rule(s): if-match any
Behavior: be
-none-
Classifier: server
Matched: 480154/41293244
(Packets/Bytes)
Offered rate: 7244746 bps, drop
rate: 242352 bps
Operator: AND
Rule(s): if-match acl 2001
Behavior: server
Assured Forwarding:
Bandwidth 40000
(Kbps)
Matched:
713659/71365900 (Packets/Bytes)
Enqueued:
36606/3660600 (Packets/Bytes)
Discarded:
677053/67705300 (Packets/Bytes)
Classifier: pc
Matched: 478498/41150828
(Packets/Bytes)
Offered rate: 7344746 bps, drop
rate: 342352
Operator: AND
Rule(s): if-match acl 2002
Assured Forwarding:
Bandwidth 40000 (Kbps)
Matched:
765394/76539400 (Packets/Bytes)
Enqueued:
39235/3923500 (Packets/Bytes)
Discarded:
726159/72615900 (Packets/Bytes)
Classifier: telephone
Matched: 550057/47304902
(Packets/Bytes)
Offered rate: 8244746 bps, drop
rate: 252352 bps
Operator: AND
Rule(s): if-match acl 2003
Behavior: telephone
Expedited Forwarding:
Bandwidth 240000
(Kbps), CBS 600000 (Bytes)
Matched:
765644/76564400 (Packets/Bytes)
Enqueued:
70553/7055300 (Packets/Bytes)
Discarded:
695091/69509100 (Packets/Bytes)
- A. CAR
- B. WRED
- C. CBWFQ
- D. GTS
Answer: C
NEW QUESTION 112
A network uses Agile Controller for 802.1X authentication, in which the S switch GigabitEthernet 0/0/9 is connected to the terminal host and the printer, the printer passes MAC authentication, and the terminal host needs to pass the Agent to pass the authentication. What is the correct configuration of the switch?
- A. [Quidway] dotlx enable [Quidway] dot1X authentication-method eap [Quidway] interface GigabitEthernet 0/0/9 [Quidway-GigabitEthernet 0/0/9] port link-type a [Quidway-GigabitEthernet 0/0/ 9] port default vlan 105 [Quidway-GigabitEthernet 0/0/9] dot1x enable [Quidway-GigabitEthernet 0/0/9] dot1x port-method MAC
- B. [Quidway] dot1x enable [Quidway] dot1X authentication-method eap [Quidway] interface GigabitEthernet 0/0/9 [Quidway-GigabitEthernet 0/0/9] port link-type trunk
- C. [Quidway] dot1X authentication-method eap [Quidway] interface GigabitEthernet 0/0/9 [Quidway-GigabitEthernet 0/0/9] port link-type a [Quidway-GigabitEthernet 0/0/9] dot1x port- method MAC
- D. [Quidway] dot1X authentication-method eap [Quidway] interface GigabitEthernet 0/0/9 [Quidway-GigabitEthernet 0/0/9] port link-type a [Quidway-GigabitEthernet 0/0/9] port default vlan 105 [Quidway-GigabitEthernet 0/0/9] dot1x port-method MAC
Answer: A
NEW QUESTION 113
For the description of NAT Server, which is correct?
- A. If the public network address of the NAT Server and the corresponding public network interface address are not in the same network segment, you do not need to configure black hole routing.
- B. NAT Server cannot be configured on the virtual firewall for users of the root firewall.
- C. If the public network address of the NAT Server is the interface address, if the black hole route of this address is configured, the service access to the firewall itself will be abnormal.
- D. If the public network address of the NAT Server and the corresponding public network interface address are in the same network segment, you do not need to configure black hole routing.
Answer: D
NEW QUESTION 114
Which statement is false about client-side troubleshooting when using Agile Controller to protect endpoints?
- A. Failure to connect to the SC server may be a server failure
- B. If you can't connect to the SC server, the server address may be wrong.
- C. The failure to connect to the SC server may be a network failure
- D. The failure to connect to the SC server may be a security check failure
Answer: D
NEW QUESTION 115
The IPsecVPN tunnel is successfully established, but the speed of accessing the peer's private network web page is slow or the access is intermittent. The influence of the Internet network quality has been ruled out. The following possible faults are:
- A. Packet filtering policy is not enabled
- B. The problem of packet fragmentation
- C. The CPU usage of the egress gateway is too high
- D. There is a NAT device in the middle of the network
Answer: B,C
NEW QUESTION 116
The following HWTACACS configuration has been made on the firewall:
<sysname> system-view
[sysname] hwtacacs-server template server1
[sysname-hwtacacs-server1] hwtacacs-server authentication 3.3.3.3 10000
[sysname-hwtacacs-server1] hwtacacs-server accounting 3.3.3.3 10010
Please point out the problem in this configuration:
- A. The authorization server is not configured.
- B. The port number used by the configured authentication server is incorrect.
- C. Authentication and accounting servers should not use the same IP address.
- D. The port number used to configure the accounting server is incorrect.
Answer: A
NEW QUESTION 117
Configure the firewall as follows:
[USG-policy-security] rule name Trust Local
[USG-policy-security-rule-Untrust Local] source-zone trust
[USG-policy-security-rule-Untrust Local] destination-zone local
[USG-policy-security-rule-Untrust Local] source-address 192.168.5.2 32
[USG-policy-security-rule-Untrust Local] destination-address 192.168.5.1 32
[USG-policy-security-rule-Untrust Local] service http
[USG-policy-security-rule-Untrust Local] service telnet
[USG-policy-security-rule-Untrust Local] action permit
Please select the correct description below:
- A. Allow the 192.168.5.2/24 address segment to log in to the firewall via Web.
- B. Allow the IP address 192.168.5.2/24 to log in to the firewall through Telnet.
- C. Allow the firewall to log in to the device at 192.168.5.1 through the Web.
- D. Allow the firewall to log in to the device at 192.168.5.1 through Telnet.
Answer: A,B
NEW QUESTION 118
In Agile Controller, what is the correct statement about the screen saver check policy ?
- A. You can check if the screen saver is enabled on the terminal
- B. Screen saver settings cannot be fixed automatically
- C. Only supports Windows OS
- D. Can check if the screen saver password is enabled
Answer: A,C,D
NEW QUESTION 119
A network expects to use URPF technology to improve network security. Which mode of URPF is used in the following networking scenarios:
- A. loose mode
- B. strict mode or loose mode
- C. strict mode
- D. According to the stem information, the corresponding mode cannot be judged
Answer: A
NEW QUESTION 120
Which of the following functional blocks can be used in conjunction with the IP-Link function?
- A. DHCP
- B. VRRP
- C. Routing Policy
- D. OSPF
Answer: A,B
NEW QUESTION 121
Which of the following options can be used as conditions for Portal push ?
- A. MAC address of the access AP
- B. Endpoint IP address range
- C. SSID of the access AP
- D. MAC address of the connected AC
- E. Terminal device type
- F. Terminal browser type
Answer: A,B,C,E
NEW QUESTION 122
Which authentication methods does L2TP over IPsec dial-up support?
- A. PEAP authentication
- B. Radius
- C. Support local authentication
- D. LDAP
- E. TSM Certified
Answer: B,C,D
NEW QUESTION 123
In a new campus network of an enterprise, there is a requirement for ordinary PC users and dumb terminal users to connect to the Internet at the same time under an access switch.
Which authentication method is recommended to be deployed on this switch?
- A. Portal Authentication
- B. MAC bypass authentication
- C. 802.1X Authentication
- D. MAC Authentication
Answer: B
NEW QUESTION 124
In the abnormal traffic cleaning solution, automatic drainage means that the detection device reports abnormal traffic to the management center, and the management center automatically generates drainage tasks and automatically sends drainage tasks to the cleaning device.
Which specific drainage technology is generally required to achieve automatic drainage?
- A. BGP drainage
- B. Policy routing diversion
- C. Static route diversion
- D. GRE Drainage
Answer: A
NEW QUESTION 125
The anti-spam function of Huawei firewall uses the RBL method. What are the requirements for the DNS server?
- A. This DNS must be a server that is not hijacked by DNS.
- B. When no DNS server is specified, the DNS server configured in system mode is used.
- C. This DNS must be a server using an iterative algorithm.
- D. This DNS must be a server using a recursive algorithm.
Answer: A,D
NEW QUESTION 126
In the networking shown in the figure, the default gateway for accessing the external network is not configured on the Web server. To ensure that users on the external network can normally access the Web server through the NAT Server, which one of the following configuration plans for the firewall is correct:
- A. It is necessary to configure the source NAT in the direction from DMZ to Untrust on the firewall, so that the web server can access the external network, so that the response message of the web server can be returned to the external network user.
- B. It is necessary to configure the source NAT from Untrust to the DMZ on the firewall to translate the source address of the data packets from the external network users accessing the Web server to 192.168.1.1.
- C. It is necessary to configure nat server on the firewall to ensure that external network users can access the Web server by accessing 202.20.1.5.
- D. It is necessary to configure destination-nat for external network users on the firewall to convert the public network address of the accessed web server into the internal network address
Answer: B,C
NEW QUESTION 127
Mobile employees access the headquarters through an L2TP over IPsec tunnel. The correct statement about planning and deployment is:
- A. The security ACL of the USG gateway at the headquarters should be [USG] acl 3000 [USG-acl-adv-3000] rule permit udp source-port eq 1701
- B. L2TP generally uses NAS-Initialized mode.
- C. Since IKE V1 cannot assign addresses to remote users, address assignment must be achieved through L2TP.
- D. The NAT traversal function cannot be used.
Answer: A,C
NEW QUESTION 128
According to the following networking, a customer uses the BGP traffic diversion policy route back injection method. Which of the following configurations must be configured on the cleaning device?
- A. ip route-static 0.0.0.0 0 10.1.3.1
- B. firewall ddos bgp-next-hop fib-filter
- C. interface GigabitEthernet2/0/2 anti-ddos flow-statistic enable
- D. firewall ddos bgp-next-hop 10.1.3.1
Answer: D
NEW QUESTION 129
......
H12-731-ENU Test Engine files, H12-731-ENU Dumps PDF: https://www.itcertmagic.com/Huawei/real-H12-731-ENU-exam-prep-dumps.html
Latest Huawei H12-731-ENU PDF and Dumps (2023) Free Exam Questions Answers: https://drive.google.com/open?id=1RPJrDE2E1Bh3_1Hhs-9TSS73JZvYvSlX