H12-711 HCIA-Security V4.0 Practice Questions
Prepare for H12-711 with more than an answer.
- Exam fee
- $200 USD
- Level
- Associate
- Valid for
- 3 years
Domains covered on the exam 11
- Network Security Concepts and Specifications5%
- Network Basics10%
- Common Network Security Threats and Threat Prevention5%
- Firewall Security Policy10%
- Firewall NAT Technologies10%
- Firewall Hot Standby Technologies10%
- Firewall User Management Technologies10%
- Firewall Intrusion Prevention Technologies10%
- Fundamentals of Encryption Technologies10%
- PKI Certificate System5%
- Encryption Technology Applications15%
- 1
A security analyst is reviewing firewall logs and notices a large volume of TCP SYN packets from various source IPs directed at a single web server in the DMZ, but the corresponding SYN-ACKs are never acknowledged. This has caused the server's connection table to fill up, making it unresponsive to legitimate users. What type of attack is occurring?
Show answer details
Correct answer: C
This scenario describes a classic TCP SYN Flood attack. The attacker sends a succession of SYN requests to a target's system in an attempt to consume enough server resources to make the system unresponsive to legitimate traffic. The attacker does not complete the three-way handshake, leaving the server with a large number of half-open connections.
- 2
A network engineer is configuring a Huawei USG firewall. They need to ensure that traffic from the internal 'Trust' zone to the 'DMZ' zone is allowed only for SSH (TCP port 22) and RDP (TCP port 3389). All other traffic between these two zones should be denied. What is the best practice for creating the security policy to achieve this?
Show answer details
Correct answer: B
The best practice is to follow the principle of least privilege. This involves creating a specific rule to permit only the required traffic (SSH and RDP) from the Trust zone to the DMZ zone. The firewall's default security policy for inter-zone traffic is 'deny', which will automatically block all other traffic that doesn't match this specific permit rule. Creating broad permit rules is insecure.
- 3
Which of the following OSI model layers is primarily concerned with logical addressing, routing, and path determination?
Show answer details
Correct answer: B
Layer 3, the Network Layer, is responsible for providing logical addressing (like IP addresses) and determining the best path for data packets to travel from a source to a destination across different networks. This process is known as routing.
- 4
When comparing IPSec Transport mode and Tunnel mode, which statement is correct?
Show answer details
Correct answer: C
Tunnel mode protects the entire original IP packet by encapsulating it within a new IP packet. It adds a new outer IP header. This mode is used for site-to-site VPNs where gateways are involved. Transport mode, in contrast, only encrypts the payload (data) of the original IP packet and leaves the original IP header intact, typically used for host-to-host communication.
- 5
A financial institution is setting up a highly available firewall solution using two Huawei USG firewalls in an active/standby cluster. They are using HRP to synchronize session and configuration data. To ensure the standby firewall can detect a failure of the active firewall promptly, a dedicated link is established between them. What is this dedicated link primarily used for?
Show answer details
Correct answer: B
The dedicated link between firewalls in an HRP cluster is known as the heartbeat link or state channel. Its primary purposes are to transmit heartbeat messages to monitor the health of the peer firewall and to carry the state synchronization data (like session tables and configuration changes) from the active to the standby unit.
- 6
True or False: Asymmetric encryption algorithms like RSA are generally faster and more computationally efficient than symmetric encryption algorithms like AES, making them suitable for encrypting large volumes of data.
Show answer details
Correct answer: B
This statement is false. Symmetric encryption algorithms (like AES) are significantly faster and less computationally intensive than asymmetric algorithms (like RSA). Therefore, a common practice is to use asymmetric encryption to securely exchange a symmetric key, and then use that faster symmetric key to encrypt the actual bulk data.
- 7
Case Study:
A medium-sized e-commerce company, 'ShopFast', is deploying a new web application. The architecture consists of public-facing web servers and internal database servers. The CISO has mandated a strict security posture based on the principle of least privilege.
Current Setup:
- A single Huawei USG6000 firewall is at the perimeter.
- Web Servers are in the 192.168.10.0/24 subnet.
- Database Servers are in the 192.168.20.0/24 subnet.
- Corporate user workstations are in the 172.16.0.0/16 subnet.
Requirements:
- Web servers must be accessible from the Internet on TCP ports 80 and 443.
- Web servers must be able to initiate connections to the database servers on TCP port 3306.
- Database servers must NOT be able to initiate any connections to the web servers or the Internet.
- Corporate users must be able to access the web servers for testing but should not have access to the database servers.
Which security zone and policy design best fulfills all requirements?
graph TD Internet((Internet)) --> FW[USG Firewall] FW --> WebServers[Web Servers] FW --> CorpUsers[Corporate Users] WebServers --> DBServers[Database Servers]Show answer details
Correct answer: B
This design correctly isolates the systems. Placing web servers in a DMZ protects the internal network. Placing databases in the highly protected Trust zone is appropriate. Creating specific, unidirectional policies (Untrust->DMZ, DMZ->Trust, Corp->DMZ) enforces the principle of least privilege and meets all stated requirements, including preventing the database servers from initiating outbound connections.
- 8
A security administrator is tasked with configuring a remote access solution for employees who travel frequently. The primary requirements are that the solution must be accessible from any standard web browser without requiring pre-installed client software, and it should provide access to internal web applications and file shares (SMB/CIFS). Which Huawei firewall feature is the most appropriate choice to meet these specific requirements?
Show answer details
Correct answer: C
SSL VPN in Web Proxy mode (clientless mode) is the best solution as it allows users to access internal web-based resources and file shares through a standard web browser without needing to install any client software. This directly addresses the core requirements. IPSec and L2TP VPNs typically require client software installation. SSL VPN in Network Extension mode also requires a client-side component.
- 9
A company is implementing a policy where employees in the 'Sales' department can only access the internet during business hours (9 AM to 5 PM, Monday to Friday). An administrator has created a user group for the Sales team and a time range object for the specified business hours. Which component of a Huawei USG firewall security policy must be configured to enforce this rule?
Show answer details
Correct answer: C
To enforce a rule based on a specific department and time of day, the administrator must configure the 'User' condition (by selecting the 'Sales' user group) and the 'Schedule' condition (by applying the pre-configured time range object) within the security policy.
- 10
Which of the following statements about the Huawei Redundancy Protocol (HRP) are correct? (Select TWO)
Show answer details
Correct answer: B, C
