
H12-711-ENU Training & Certification Get Latest HCNA-Security Updated on Jul 15, 2021
Certification Training for H12-711-ENU Exam Dumps Test Engine
NEW QUESTION 28
Caesar Code is primarily used to encrypt data by using a stick of a specific specification.
- A. False
- B. True
Answer: A
NEW QUESTION 29
Which of the following descriptions about the action and security profile of the security policy are correct? (Multiple choice)
- A. If the action of the security policy is "prohibited", the device will discard this traffic, and then no content security check will be performed.
- B. If the security policy action is "Allow", the traffic will not match the security profile.
- C. The security profile may not be applied to the security policy that the action is allowed and take effect.
- D. The security profile must be applied to the security policy that is allowed to take effect.
Answer: A,D
NEW QUESTION 30
Encryption technology can transform readable information into unreadable information in a certain way.
- A. True
- B. False
Answer: A
NEW QUESTION 31
In information security prevention, commonly used security products are firewalls, Anti-DDos devices and IPS/IDS devices.
- A. True
- B. False
Answer: A
NEW QUESTION 32
About the description of firewall active-standby, which of the following is correct? (Multiple Choice)
- A. When a plurality of regions on the firewall need to provide dual-machine backup function, you need to configure multiple VRRP backup groups on the firewall.
- B. The firewall active-standby requires the information such as the session table, MAC table, routing table and so on synchronous backup between primary devices and slave devices.
- C. VGMP is to ensure all VRRP backup groups' consistency of switching
- D. It requires the state of all the VRRP backup groups in the same VGMP management group on the same firewall should be consistent.
Answer: A,C,D
NEW QUESTION 33
Which of the following statements are correct about the business continuity plan? (Multiple Choice)
- A. Business continuity plan does not require high-level participation of the company in determining the project scope phase
- B. Not all security incidents must be reported to company executives
- C. Business continuity plan does not require high-level participation of the company before forming a formal document
- D. BCP needs flexibility because it cannot predict all possible accidents
Answer: B,D
NEW QUESTION 34
IPSec VPN uses an asymmetric encryption algorithm to encrypt the transmitted data.
- A. False
- B. True
Answer: A
NEW QUESTION 35
Which of the following is true about the description of SSL VPN?
- A. Can be used without a client
- B. No authentication required
- C. There is a NAT traversal problem
- D. May encrypt to IP layer
Answer: A
NEW QUESTION 36
W hich of the following are the characteristics of a symmetric encryption algorithm? (Multiple choice)
- A. Key distribution security is high
- B. Key distribution is not secure
- C. Confidential speed is slow
- D. Fast encryption
Answer: B,D
NEW QUESTION 37
In the USG series firewall, you can use the ______ function to provide well-known application services for non-known ports.
- A. Port mapping
- B. MAC and IP address binding
- C. Long connection
- D. Packet filtering
Answer: A
NEW QUESTION 38
Which of the following attacks is not a cyber-attack?
- A. Smurf attack
- B. MAC address spoofing attack
- C. IP spoofing attack
- D. ICMP attack
Answer: B
NEW QUESTION 39
Check the firewall HRP status information as follows:
HRP_S [USG_ B] display hrp state
16 : 90 : 13 2010/11/29
The firewall's config state is : SLAVE
Current state of virtual routers configured as slave
GigabitEthernet0/0/0 vird 1 : slave
GigabitEthernet0/0/1 vied 2 : slave
Which of the following description is correct?
- A. the firewall must be in a state of preemption
- B. the firewall VGMP group status is Master
- C. the firewall of HRP heartbeats interface is G0/0/0 and G0/0/1
- D. the firewall G0/0/0 and 0/1 G0 / interface of VRRP group status is Slave
Answer: D
NEW QUESTION 40
"Being good at observation" and "keeping suspicion" can help us better identify security threats in the online world.
- A. True
- B. False
Answer: A
NEW QUESTION 41
A company employee account authority expires, but can still use the account to access the company server.
What are the security risks of the above scenarios? (Multiple Choice)
- A. Managing security risk
- B. System security risk
- C. Physical security risk
- D. Access security risk
Answer: A,B,D
NEW QUESTION 42
During the configuration of NAT, which of the following will the device generate a Server-map entry? (Multiple Choice)?
- A. After the NAT server is configured successfully, the device automatically generates a server map entry.
- B. A server-map entry is generated when easy-ip is configured.
- C. Automatically generate server-map entries when configuring source NAT.
- D. After configuring NAT No-PAT, the device will create a server-map table for the configured multi-channel protocol data stream.
Answer: A,D
NEW QUESTION 43
In the information security system construction management cycle, which of the following actions is required to be implemented in the "check" link?
- A. Implementation of the safety management system
- B. Safety management system operation monitoring
- C. Safety management system design
- D. Risk assessment
Answer: D
NEW QUESTION 44
Which of the following is not part of the method used in the Detection section of the P2DR model?
- A. Shut down the service
- B. Testing
- C. Alarm
- D. Real-time monitoring
Answer: C
NEW QUESTION 45
Which of the following attacks is not a special packet attack?
- A. ICMP unreachable packet attack
- B. Large ICMP packet attack
- C. IP address scanning attack
- D. ICMP redirect packet attack
Answer: C
NEW QUESTION 46
......
Step by Step Guide to Prepare for H12-711-ENU Exam: https://www.easy4engine.com/H12-711-ENU-test-engine.html

