H12-711-ENU Training & Certification Get Latest HCNA-Security Updated on Jul 15, 2021 [Q28-Q46]

Share

H12-711-ENU Training & Certification Get Latest HCNA-Security Updated on Jul 15, 2021

Certification Training for H12-711-ENU Exam Dumps Test Engine

NEW QUESTION 28
Caesar Code is primarily used to encrypt data by using a stick of a specific specification.

  • A. False
  • B. True

Answer: A

 

NEW QUESTION 29
Which of the following descriptions about the action and security profile of the security policy are correct? (Multiple choice)

  • A. If the action of the security policy is "prohibited", the device will discard this traffic, and then no content security check will be performed.
  • B. If the security policy action is "Allow", the traffic will not match the security profile.
  • C. The security profile may not be applied to the security policy that the action is allowed and take effect.
  • D. The security profile must be applied to the security policy that is allowed to take effect.

Answer: A,D

 

NEW QUESTION 30
Encryption technology can transform readable information into unreadable information in a certain way.

  • A. True
  • B. False

Answer: A

 

NEW QUESTION 31
In information security prevention, commonly used security products are firewalls, Anti-DDos devices and IPS/IDS devices.

  • A. True
  • B. False

Answer: A

 

NEW QUESTION 32
About the description of firewall active-standby, which of the following is correct? (Multiple Choice)

  • A. When a plurality of regions on the firewall need to provide dual-machine backup function, you need to configure multiple VRRP backup groups on the firewall.
  • B. The firewall active-standby requires the information such as the session table, MAC table, routing table and so on synchronous backup between primary devices and slave devices.
  • C. VGMP is to ensure all VRRP backup groups' consistency of switching
  • D. It requires the state of all the VRRP backup groups in the same VGMP management group on the same firewall should be consistent.

Answer: A,C,D

 

NEW QUESTION 33
Which of the following statements are correct about the business continuity plan? (Multiple Choice)

  • A. Business continuity plan does not require high-level participation of the company in determining the project scope phase
  • B. Not all security incidents must be reported to company executives
  • C. Business continuity plan does not require high-level participation of the company before forming a formal document
  • D. BCP needs flexibility because it cannot predict all possible accidents

Answer: B,D

 

NEW QUESTION 34
IPSec VPN uses an asymmetric encryption algorithm to encrypt the transmitted data.

  • A. False
  • B. True

Answer: A

 

NEW QUESTION 35
Which of the following is true about the description of SSL VPN?

  • A. Can be used without a client
  • B. No authentication required
  • C. There is a NAT traversal problem
  • D. May encrypt to IP layer

Answer: A

 

NEW QUESTION 36
W hich of the following are the characteristics of a symmetric encryption algorithm? (Multiple choice)

  • A. Key distribution security is high
  • B. Key distribution is not secure
  • C. Confidential speed is slow
  • D. Fast encryption

Answer: B,D

 

NEW QUESTION 37
In the USG series firewall, you can use the ______ function to provide well-known application services for non-known ports.

  • A. Port mapping
  • B. MAC and IP address binding
  • C. Long connection
  • D. Packet filtering

Answer: A

 

NEW QUESTION 38
Which of the following attacks is not a cyber-attack?

  • A. Smurf attack
  • B. MAC address spoofing attack
  • C. IP spoofing attack
  • D. ICMP attack

Answer: B

 

NEW QUESTION 39
Check the firewall HRP status information as follows:
HRP_S [USG_ B] display hrp state
16 : 90 : 13 2010/11/29
The firewall's config state is : SLAVE
Current state of virtual routers configured as slave
GigabitEthernet0/0/0 vird 1 : slave
GigabitEthernet0/0/1 vied 2 : slave
Which of the following description is correct?

  • A. the firewall must be in a state of preemption
  • B. the firewall VGMP group status is Master
  • C. the firewall of HRP heartbeats interface is G0/0/0 and G0/0/1
  • D. the firewall G0/0/0 and 0/1 G0 / interface of VRRP group status is Slave

Answer: D

 

NEW QUESTION 40
"Being good at observation" and "keeping suspicion" can help us better identify security threats in the online world.

  • A. True
  • B. False

Answer: A

 

NEW QUESTION 41
A company employee account authority expires, but can still use the account to access the company server.
What are the security risks of the above scenarios? (Multiple Choice)

  • A. Managing security risk
  • B. System security risk
  • C. Physical security risk
  • D. Access security risk

Answer: A,B,D

 

NEW QUESTION 42
During the configuration of NAT, which of the following will the device generate a Server-map entry? (Multiple Choice)?

  • A. After the NAT server is configured successfully, the device automatically generates a server map entry.
  • B. A server-map entry is generated when easy-ip is configured.
  • C. Automatically generate server-map entries when configuring source NAT.
  • D. After configuring NAT No-PAT, the device will create a server-map table for the configured multi-channel protocol data stream.

Answer: A,D

 

NEW QUESTION 43
In the information security system construction management cycle, which of the following actions is required to be implemented in the "check" link?

  • A. Implementation of the safety management system
  • B. Safety management system operation monitoring
  • C. Safety management system design
  • D. Risk assessment

Answer: D

 

NEW QUESTION 44
Which of the following is not part of the method used in the Detection section of the P2DR model?

  • A. Shut down the service
  • B. Testing
  • C. Alarm
  • D. Real-time monitoring

Answer: C

 

NEW QUESTION 45
Which of the following attacks is not a special packet attack?

  • A. ICMP unreachable packet attack
  • B. Large ICMP packet attack
  • C. IP address scanning attack
  • D. ICMP redirect packet attack

Answer: C

 

NEW QUESTION 46
......

Step by Step Guide to Prepare for H12-711-ENU Exam: https://www.easy4engine.com/H12-711-ENU-test-engine.html