[Q173-Q194] Master 2023 Latest The Questions HCNA-Security and Pass H12-711 Real Exam!

Share

Master 2023 Latest The Questions HCNA-Security and Pass H12-711 Real Exam!

Penetration testers simulate H12-711 exam PDF

NEW QUESTION # 173
As shown in the figure, a NAT server application scenario isconfigured when the web configuration mode is used

Which of the following statements are correct"? (Multiple choice)

  • A. When configuring an interzone secunty policy, set the source security zone to DMZ and the target secunty zone to Untrust.
  • B. When configuring an interzone secunty policy, set the source security zone to Untrust and the target security zone to DMZ
  • C. When configuring NAT Server, the internal address is 200.10.10.1 and the external address is 10.1.1.2.
  • D. When configuring NAT Server, the internal address is 10 1.1 2 and the external address is 200.10.10.1.

Answer: B,D


NEW QUESTION # 174
Data analysis technology is to find and -natch keywords or key ohrases in the acquired data stream or information flow, and analyze: he correlation of time. Which of the following is not an evidence analysis technique?

  • A. Techniques for discovering the connections between different evidences
  • B. Password deciphering, data decryption technology
  • C. Spam tracking technology
  • D. Document Digital Abstract Analysis Technology

Answer: C


NEW QUESTION # 175
The single-point login function of the online user, the user authenticates directly to the AD server, and the device does not interfere with the user authentication process. The AD monitoring service needs to be deployed on the USG device to monitor the authentication information of the AD server.

  • A. True
  • B. False

Answer: B


NEW QUESTION # 176
When Firewall does dual-system hot backup networking, in order to achieve the overall status of the backup group switching, which of the following protocol technology need to be used?

  • A. VRRP
  • B. VGMP
  • C. HRP
  • D. OSPF

Answer: B


NEW QUESTION # 177
In o der to obtain evidence of crime, it is necessary to master the technology ofintrusion tracking Which of the following descriptions are correct about the tracking technology? (Multiple Choice)

  • A. Link test technology determines the source of the attack by testing the network link between the routers
  • B. Packet Recording Technology marks packets on each passing router by inserting trace data into the tracked IP packets
  • C. Packet tagging technology extracts information from attack sources by recording packets on the router and then using data drilling techniques
  • D. Snallow mail behavior analysis can analyze the information such as sending IF address, sending time, sending frequency, number of recipients, shallow email heacers and so on.

Answer: A,B,D


NEW QUESTION # 178
Which of the following statements is wrong about VPN?

  • A. The generation of VPN technology enables employees on business trips toremotely access internal corporate servers.
  • B. VPN technology necessarily involves encryption technology
  • C. Virtual private network ischeaper than dedicated line
  • D. VPN technology is a technology that multiplexes logica channels on actual physical lines.

Answer: B


NEW QUESTION # 179
In IPSEC VPN, which of the following scenarios can be applied by tunnel mode?

  • A. between hosts and security gateways
  • B. between security gateways
  • C. between tunnel mode and transport mode
  • D. between the host and the host

Answer: B


NEW QUESTION # 180
Fire Trust domain FTP client wants to access an Um.rust server FTP service has allowed the client: to access the server TCP 21 port, the client in the Windows command line window can log into the FTP server, but can not download the file, what are the following solutions? (Multiple choice)

  • A. The ^TP works with the port mode modify the Untru3t Trust domain to allow the inbound direction between the default access strategy
  • B. Trust Untrust domain configuration is enabled detect ftp
  • C. Take the Trust between Un:rust domain to allow two-way default access strategy
  • D. FTP works with Passive mode modify the domain inbound direction betv/een the Untrust Trust default access policy to allow

Answer: A,B,C


NEW QUESTION # 181
To implement the " anti-virus function " in the security policy, you must perform a License activation

  • A. True
  • B. False

Answer: A


NEW QUESTION # 182
HRP (Huawei Redundancy Protocol) Protocol to backup the connection state of data includes:

  • A. The dynamic blacklist
  • B. TCP/UDP sessions table
  • C. Server Map table
  • D. The routing table

Answer: A,B,C


NEW QUESTION # 183
Regarding the description of the packet in the iptables transmission process, which of the following option is wrong?

  • A. If the destination address of the packet is local, the packet will be sent to the INPUT chain.
  • B. If the destination address of the packet is not local, the system sends the packet to the OUTPUT chain.
  • C. If the destination address of the packet is not local, the system sends the packet to the FORWARD chain.
  • D. When a packet enters the network card, it first matches the PREROUTING chain.

Answer: B


NEW QUESTION # 184
Which of the following options does not belong to the log type of the Windows operating system?

  • A. Application log
  • B. Business log
  • C. System log
  • D. Security log

Answer: B


NEW QUESTION # 185
Which of the following is an action to be taken during the summary phase of the cybersecurity emergency response? (Multiple Choice)

  • A. Determine the effectiveness of the isolation measures
  • B. Evaluate the implementation of the contingency plan and propose a follow-up improvement plan
  • C. Evaluation of members of the emergency response organization
  • D. Establish a defense system and specify control measures

Answer: B,C


NEW QUESTION # 186
Which of the following is not included in the Corporate Impact Analysis (BIA)?

  • A. Business priority
  • B. Impact assessment
  • C. Accident handling priority
  • D. Risk identification

Answer: B


NEW QUESTION # 187
Which of the following is not part of the method used in the Detection section of the P2DR model?

  • A. Shut down the service
  • B. Alarm
  • C. Real-time monitoring
  • D. Testing

Answer: B


NEW QUESTION # 188
Which of the following statement about the L2TP VPN ofClient-initialized is wrong?

  • A. LNS assign a private IP address for remote users
  • B. remote users do not need to install VPN client software
  • C. After the remote user access to internet, can initiate L2TP tunneling request to the remote LNS directly through the client software
  • D. LNS device receives user L2TPconnection request, can verify based on user name and password.

Answer: B


NEW QUESTION # 189
Regarding the relationship and role of VRRP/VGMP/HRP, which of the following statements are correct? (Multiple choice)

  • A. VGMP group in the active state may include the VRRP group in the standby state.
  • B. VRRP is responsible for sending free ARP to direct traffic to the new primary device during active/standby switchover.
  • C. VGMP is responsible for monitoring equipment failures and controlling fast switching of equipment.
  • D. HRP is responsible for data backup during hot standby operation.

Answer: B,C,D


NEW QUESTION # 190
Electronic evidence preservation is directly related to the legal effect of evidence, in line with the preservation of legal procedures, and its authenticity and reliability are guaranteed. Which of the following is not anevidence preservation technology?

  • A. Message tag tracking technology
  • B. Digital signature technology
  • C. Encryption technology
  • D. Digital certificate technology

Answer: A


NEW QUESTION # 191
Which of the following are the same features of Windows and LINUX systems? (MultipleChoice)

  • A. Support graphical interface operations
  • B. Support multitasking
  • C. Open source system
  • D. Support multiple terminal platforms

Answer: A,B,D


NEW QUESTION # 192
In the digital signature process, which of the following is the HASH algorithm to verify the integrity of the data transmission?

  • A. Receiver public key
  • B. Symmetric key
  • C. Receiver private key
  • D. User data

Answer: D


NEW QUESTION # 193
Which of the following protection levels are included in the TCSEC standard? (Multiple Choice)

  • A. Verify protection level
  • B. Independent protection level
  • C. Passive protection level
  • D. Forced protection level

Answer: A,B,D


NEW QUESTION # 194
......

Penetration testers simulate H12-711 exam: https://braindumps.exam4docs.com/H12-711-study-questions.html