H12-731-ENU Exam PDF [2023] Tests Free Updated Today with Correct 205 Questions
Huawei H12-731-ENU Exam Preparation Guide and PDF Download
NEW QUESTION # 123
Which of the following commands are the interface loopback commands needed to handle E1/CE1 problems
- A. loopback check
- B. loopback
- C. loopback remote
- D. loopback local
- E. test loopback
Answer: C,D,E
NEW QUESTION # 124
When using the SSL VPN network extension function, the virtual IP address pool can be set to the same network segment as the IP address of the internal network interface of the device.
If the virtual IP address pool and the IP address of the intranet interface are not in the same network segment, manually configure the route to the address pool on the device, the outgoing interface is the intranet interface, and the next hop is the next hop of the intranet interface.
- A. TRUE
- B. FALSE
Answer: A
NEW QUESTION # 125
The centralized networking scheme of three servers, as shown in the figure, the administrator found that only one of the three Agile Controllers in the resource pool was alive.
In this case, which of the following statements is correct?
- A. All three database servers cannot work normally, and only one of the three Agile Controllers in the resource pool is alive. In this case, all Agile Controller services are transferred to the surviving Agile Controller and can operate normally, and terminal identity authentication, access control, software distribution, patch installation, and asset management will not be affected.
- B. After the Agile Controller is started, each Agile Controller will immediately read the database and save it on the local hard disk in a cached manner. If all databases become unavailable due to a failure, the Agile Controller will continue to maintain the operation of the Agile Controller business with the cache saved at that time as the data source.
- C. At this point, you can try to restart the surviving Agile Controller, and repair the database server while restarting.
- D. At this point, the escape channel on the firewall has been opened.
Answer: A,B
NEW QUESTION # 126
Which of the following functional blocks can be used in conjunction with the IP-Link function?
- A. OSPF
- B. Routing Policy
- C. DHCP
- D. VRRP
Answer: C,D
NEW QUESTION # 127
In the networking shown in the figure, the default gateway for accessing the external network is not configured on the Web server. To ensure that users on the external network can normally access the Web server through the NAT Server, which one of the following configuration plans for the firewall is correct:
- A. It is necessary to configure the source NAT from Untrust to the DMZ on the firewall to translate the source address of the data packets from the external network users accessing the Web server to 192.168.1.1.
- B. It is necessary to configure destination-nat for external network users on the firewall to convert the public network address of the accessed web server into the internal network address
- C. It is necessary to configure the source NAT in the direction from DMZ to Untrust on the firewall, so that the web server can access the external network, so that the response message of the web server can be returned to the external network user.
- D. It is necessary to configure nat server on the firewall to ensure that external network users can access the Web server by accessing 202.20.1.5.
Answer: A,D
NEW QUESTION # 128
Huawei USG firewall, in the dual-system hot-standby network (as shown in the figure), the PC cannot log in to the real IP address of the external network port of the standby firewall FW2 through SSH. Check the corresponding sessions on the active and standby firewalls as follows, and analyze the following statements about this fault. is it right ?
HRP_A <E1000-1> display firewall session table verbose source inside 192.168.22.151
tcp VPN: public ->
public
Zone: trust -> local TTL: 00:00:05 Left: timeout
Interface: G0/0/1 Nexthop: 192.168.22.122 MAC: 00-22-a1-06-b3-cb
<-- packets: 1
bytes: 48 -> packets: 0 bytes: 0
192.168.22.122:22 <-- 192.168.22.151:4354
HRP_S <-E1000-2>display firewall session table verbose source inside 192.168.22.151
tcp VPN: public -> public
Zone: trust -> local TTL: 00:00:05 Left: timeout
Interface: I0 Nexthop: 127.0.0.1 MAC: 00-00-00-00-00-00
<-- packets: 1
bytes: 48 -> packets: 1 bytes: 44
192.168.22.122:22 <-- 192.168.22.151:4354
- A. The problem may be caused by turning off hrp mirror session enable.
- B. When the PC logs in to the standby firewall FW2, the round-trip path is inconsistent.
- C. Because the SSH client supports packet retransmission during the login process.
- D. The problem is caused by disabling the indo firewall session link-state check function of the chromium road state check function.
Answer: B,D
NEW QUESTION # 129
In the Remote Access VPN scenario, the remote PC uses the Secoway VPN Client and the firewall to establish a VPN. Which of the following statements is correct?
- A. Default use transfer mode
- B. use l2tp over ipsec dial by default
- C. Tunnel mode is used by default
- D. use l2tp dialing by default
Answer: C,D
NEW QUESTION # 130
In the L2TP Over IPsec scenario, the central node uses the IPsec template, how to configure the IPsec Security ACL on the LNS at this time?
- A. rule permit udp destination-port eq 1701
- B. rule permit tcp destination-port eq 1701
- C. rule permit udp source-port eq 1701
- D. rule permit tcp source-port eq 1701
Answer: C
NEW QUESTION # 131
View the session table information on the network egress firewall as follows:
[USG] display firewall session table verbose
15:11:25 2013/12/18
Current Total
Sessions: 40
http VPN: public --> public
Zone: trust --> untrust TTL: 00:10:00 Left: 00:08:59
Interface: GigabitEthernet0/0/1 NextHop: 58.251.159.1 MAC: 00-0f-e2-a2-a2-61
<-- packets: 144 bytes: 6340 --> packets: 74 bytes: 3951
192.168.100.28:1036 [58.251.159.112:2048] --> 111.206.79.100:80
Which of the following descriptions is incorrect:
- A. Firewall interface GigabitEthernet0/0/1 belongs to the untrust zone.
- B. The host on the internal network 192.168.100.28 establishes an http connection with the external network 111.206.79.100.
- C. The MAC address of the outgoing interface of the firewall is 00-0f-e2-a2-a2-61.
- D. The NAT-translated address is 58.251.159.112.
Answer: C
NEW QUESTION # 132
What aspects need to be checked for IPS (Intrusion Prevention) failures?
- A. Whether the configured policy is submitted for compilation.
- B. Check whether the IPS blacklist is configured.
- C. Whether to enable IPS global switch.
- D. Whether to configure the IPS policy and apply it to the interzone.
- E. Whether the overlay signature is configured.
Answer: A,C,D
NEW QUESTION # 133
A PC receives a fragmented package as shown in the figure below. According to the following package information, which of the following options is correct?
- A. offset bit is 0
- B. The protocol number in the IP header is 2
- C. There are subsequent IP fragments
- D. The flag bit in the Layer 3 IP header is 1
Answer: A,C
NEW QUESTION # 134
The firewall single sign-on authentication process as shown in the figure includes the following main links:
a. Find user group information on AD server
b. The device has created an online user list, and the user directly accesses external resources
c. Send information such as username and group to the device
d. User requests authentication
e. Actively send a message to the AD monitoring service (username, user IP address)
f . Server authentication passed
Please select the correct correspondence between letters and numbers ?
- A. ① -> d ② -> e ③ -> f ④ -> a ⑤ -> C ⑥ -> b
- B. ① -> d ② -> f ③ -> d ④ -> e ⑤ -> C ⑥ -> b
- C. ① -> d ② -> f ③ -> e ④ -> d ⑤ -> C ⑥ -> b
- D. ① -> d ② -> e ③ -> d ④ -> f ⑤ -> C ⑥ -> b
Answer: C
NEW QUESTION # 135
A customer network topology is shown in the figure.
An LZTP tunnel is established between the PC and the FW, with the PC as the client and the FW as the LNS side. After the administrator completes the configuration, it is found that the L2TP tunnel cannot be established successfully.
Execute the command debug l2tp packet in the user view to enable the debug switch, and see the following debug information:
USG %%01L2TP/8/L2TDBG (d): L2TP::Check SCCRQ MSG Type 1
USG %%01L2TP/8/L2TDBG (d): L2TP::Parse AVP Protocol version: 100
USG %%01L2TP/8/L2TDBG (d): L2TP::Parse AVP Framing capability: 1
USG %%01L2TP/8/L2TDBG (d): L2TP::Parse AVP Bearer capability, value: 0
USG %%01L2TP/8/L2TDBG (d): L2TP::Parse AVP Firmware revision, value: 1200
USG %%01L2TP/8/L2TDBG (d): L2TP::Parse AVP Host name, value: maple-54b160e59
USG %%01L2TP/8/L2TDBG (d): L2TP::requested Host isn't in the define l2tp group, refuse the requested
USG %%01L2TP/8/L2TDBG (d): L2TP::Clear Calls On Tunnel ID=1 Reason=1
Based on the above information, which failure analysis option is correct?
- A. Client LNS IP address configuration error
- B. L2TP Group tunnel authentication failed
- C. The Virtual Template interface is not added to the security domain
- D. LNS remote tunnel name configuration is incorrect
Answer: D
NEW QUESTION # 136
Which of the following is a correct description of the stateful inspection firewall forwarding principle:
- A. The firewall does not support the stateful inspection mechanism when deployed as a Layer 2 device.
- B. Session state detection based on TCP connection three-way handshake.
- C. Establish a connection for this UDP data stream when processing UDP protocol packets.
- D. The non-first packet forwarding is based on the session table, which can only be forwarded if it matches the session table.
- E. ICMP packets will not be checked for status.
Answer: B,C,D
NEW QUESTION # 137
For the networking shown in the figure, one end of the IPsec tunnel uses two devices for dual-system hot backup. When the master-slave switchover occurs, which of the following descriptions is correct?
- A. Packets from USG_C to HQ will trigger renegotiation, and services will not be affected.
- B. Configure the dpd mechanism on USG_A, USG_B, and USG_C to increase the reliability of IPsec dual-system hot backup.
- C. The Keepalive mechanism consumes less CPU resources than the DPD mechanism.
- D. The IPsec tunnel does not require renegotiation.
Answer: B,D
NEW QUESTION # 138
When the firewall runs GRE, which three parameters must be configured on the tunnel interface?
- A. Destination IP address of the tunnel
- B. Checksum enable for GRE
- C. key
- D. source IP address of the tunnel
- E. The protocol number of the tunnel is GRE
Answer: A,D,E
NEW QUESTION # 139
In the scenario of dual-system hot backup, what is wrong about the description of the main firewall device and the standby device?
- A. Configure the master device to define HRP_A, configure the slave device to define HRP_S, and it does not change with the priority.
- B. When the dual-system hot backup works in the active/standby state, the command prompt of the active device displays HRPA, and the command prompt of the standby device displays HRP_S.
- C. Only the master device can perform command configuration, and the standby device command cannot be configured.
- D. By default, the configuration of the active device will be backed up to the standby device immediately.
Answer: A,C
NEW QUESTION # 140
USGA G0/0/2 (30.1.1.2) ----------------------------- (30.1.1.1) G0/0/2 USGB
A network adopts the above topology and establishes BFD with USGA and USGB, but it is found that the BFD session cannot be Up. The most probable cause is:
<USGA> display bfd session all
-------------------------------------------------- -------------------------------------------------- -------------
Local Remote Peer IP Address Interface Name State Type
-------------------------------------------------- -------------------------------------------------- ------------
60 20 30.1.1.1 GigabitEthernet0/0/2 Down Static
-------------------------------------------------- -------------------------------------------------- ------------
<USGB> display bfd session all
-------------------------------------------------- -------------------------------------------------- -------------
Local Remote Peer IP Address Interface Name State Type
-------------------------------------------------- -------------------------------------------------- ------------
60 20 30.1.1.2 GigabitEthernet0/0/2 Down Static
-------------------------------------------------- -------------------------------------------------- ------------
- A. BFD session with unbound outbound interface
- B. The shutdown command is configured on one side of the BFC session
- C. Identifiers at both ends of the BFC session do not correspond
- D. BFC session configuration not committed
Answer: C
NEW QUESTION # 141
Regarding the trigger mechanism of 802.1X authentication, which of the following descriptions are correct?
- A. The 802.1X client can trigger authentication by multicast or broadcast.
- B. 802.1X authentication can only be initiated by an authentication device (such as an 802.1X switch).
- C. The authentication device can trigger authentication in multicast or unicast.
- D. The 802.1X authentication trigger can only be initiated by the client.
Answer: A,C
NEW QUESTION # 142
When the firewall uses WEB redirection password authentication, the user does not take the initiative to authenticate, but first accesses the business, and the firewall redirects the page to the "authentication page". After successful authentication, it automatically jumps to the page the user visited before.
- A. TRUE
- B. FALSE
Answer: A
NEW QUESTION # 143
When configuring the firewall security policy, which of the following configuration commands is correct to match the data packets sent from the 192.168.10.0 network segment?
- A. destination-address 192.168.10.0 0.0.0.255
- B. source-address 192.168.10.0 255.255.255.0
- C. destination-address 192.168.10.0 255.255.255.0
- D. source-address 192.168.10.0 0.0.0.255
Answer: D
NEW QUESTION # 144
Due to the network upgrade of the new USG_A and USG_B software versions, how to upgrade without affecting services:
USG_A is Active device, USG B is Standby device
① Log in to USG_B through Telnet or SSH. The operations are as follows:
[USG-B] hrp enable
② Log in to USG_A through Telnet or SSH. The operations are as follows:
HRP_M [USG_A] undo hrp enable
③ Execute the undo hrp enable command on USG_B, then upgrade the software version of USG_B, and restart the USG_B device.
④ Upgrade the software version of USG_A and restart the USG_A device.
⑤ Test whether the USG_B service is normal.
- A. ②③①④⑤
- B. ③②①⑤④
- C. ③②④①⑤
- D. ①⑤③②④
Answer: B
NEW QUESTION # 145
......
Verified & Correct H12-731-ENU Practice Test Reliable Source Jul 16, 2023 Updated: https://pass4sure.dumptorrent.com/H12-731-ENU-braindumps-torrent.html