H12-821 Hcip-Datacom-Core Technology V1.0 Practice Questions
Prepare for H12-821 with more than an answer.
- Exam fee
- $180 USD
- Level
- Professional
- Valid for
- 3 years
Domains covered on the exam 13
- Routing Basics3%
- OSPF Core Knowledge16%
- IS-IS Core Knowledge8%
- BGP Core Knowledge17%
- Routing and Traffic Control10%
- Switching Core Knowledge7%
- Multicast Basics9%
- IPv6 Core Knowledge3%
- Network Security Basics9%
- Network Reliability Basics8%
- Network Service and Management2%
- Large-scale WLAN Architecture6%
- Network Solution2%
- 1
In an OSPF Not-So-Stubby Area (NSSA), how are external routes from a directly connected, redistributed protocol handled within the area and propagated to the backbone area?
graph LR subgraph Area 1 (NSSA) ASBR1 -- OSPF --> R1 R1 -- OSPF --> ABR1 end subgraph Area 0 (Backbone) ABR1 -- OSPF --> R2 end External((External Routes)) -- RIP --> ASBR1Show answer details
Correct answer: B
NSSAs are designed to block Type 5 External LSAs but still allow for the redistribution of external routes from within the area. The ASBR within the NSSA generates a special Type 7 LSA to advertise these external routes. Type 7 LSAs are only flooded within the NSSA. When the NSSA's ABR receives a Type 7 LSA, it translates it into a standard Type 5 LSA and floods it into Area 0 and subsequently to other areas. This allows the rest of the OSPF domain to learn about the external routes originated in the NSSA.
- 2
A company has two BGP routers, R1 and R2, in the same AS. R1 learns an external route from an eBGP peer. R1 then advertises this route to R2 via iBGP. By default, what will R2 use as the next-hop address for this route, and what is the potential issue with this behavior?
Show answer details
Correct answer: B
A fundamental BGP rule is that when a route is advertised to an iBGP peer, the NEXT_HOP attribute is not changed by default. Therefore, R1 will advertise the route to R2 with the next-hop still set to the IP address of the external eBGP peer. The potential problem is that R2, being an internal router, likely does not have a route in its IGP to reach the external peer's IP address directly. This makes the BGP route unusable. The solution is to configure
peer next-hop-selfon R1, which forces R1 to substitute its own IP address as the next-hop when advertising to R2. - 3
When comparing IS-IS and OSPF, which statement accurately describes a key difference in their design and operation?
Show answer details
Correct answer: A
This is a fundamental difference. OSPF is built around the concept of a mandatory backbone area (Area 0), and all other areas must connect to it. IS-IS uses a two-level hierarchy (Level-1 for intra-area, Level-2 for inter-area/backbone), but the backbone is simply the collection of all Level-2 capable routers, not a specific area. This makes the IS-IS design potentially more flexible. Also, IS-IS runs directly over Layer 2, making it transport-agnostic, whereas OSPF runs over IP.
- 4
A network engineer wants to apply a routing policy to filter routes being imported from BGP into OSPF. The policy should only permit routes that have a specific BGP community tag (e.g., 100:123). Which tools would be used in the
if-matchclause of aroute-policyon a Huawei router to achieve this?Show answer details
Correct answer: C
To match routes based on their BGP community attribute, a
community-filtermust be created first. This filter defines the community value(s) to match. Then, within theroute-policy, theif-match community-filtercommand is used to reference this filter. This allows the policy to selectively apply actions (like permit or deny) to routes carrying the specified community tag during the redistribution process. - 5
Case Study: E-Commerce Co. WLAN Security
E-Commerce Co. is implementing a secure wireless network for its corporate employees. The requirements are stringent: each user must authenticate with their unique corporate credentials (username and password), all wireless traffic must be strongly encrypted, and the solution must be scalable for a growing number of users and devices.
The network team has deployed a Huawei Fit AP solution with a central AC. A RADIUS server has been installed to manage user credentials. The security team has mandated the use of the most secure, standards-based authentication and encryption methods available.
An intern suggests using WPA2-PSK, where all employees share a common pre-shared key for simplicity. A senior engineer immediately rejects this, citing security risks and lack of individual accountability.
What is the most appropriate and secure WLAN authentication method to implement that meets all of E-Commerce Co.'s requirements?
Show answer details
Correct answer: D
WPA2-Enterprise (or its successor, WPA3-Enterprise) combined with 802.1X is the industry standard for secure corporate wireless. This method meets all requirements: 1) 802.1X forces each user to authenticate with their individual credentials, which are validated by the RADIUS server. 2) It uses strong encryption (AES). 3) It is highly scalable, as user management is centralized on the RADIUS server, making it easy to add, remove, or modify user access without changing the wireless infrastructure configuration. It provides individual accountability, which is impossible with a shared key.
- 6
A network administrator at a financial services firm is configuring OSPF between two routers, R1 and R2. After configuration, the OSPF adjacency fails to establish and remains stuck in the ExStart state. A packet capture reveals that R1 and R2 are successfully exchanging Hello packets and agree on all parameters, but they continuously retransmit Database Description (DD) packets to each other. What is the most likely cause of this issue?
Show answer details
Correct answer: C
When OSPF routers are in the ExStart/Exchange state, they exchange Database Description (DD) packets to synchronize their Link-State Databases (LSDBs). If the Maximum Transmission Unit (MTU) on their interconnected interfaces is different, the router with the larger MTU might send a DD packet that is too large for the other router to receive. This causes the negotiation to fail and the routers to get stuck in this state, continuously retransmitting DD packets. Mismatched area types or duplicate router IDs would typically prevent the neighbor relationship from forming at all (stuck in 2-Way or earlier).
- 7
A network engineer is designing a BGP solution for an enterprise with two connections to the same ISP. The goal is to use one connection as the primary path for all outbound traffic and the other as a backup. Which BGP attribute should be configured on the enterprise edge routers to influence the ISP's routing decision for inbound traffic, ensuring the ISP prefers one link over the other?
Show answer details
Correct answer: B
The Multi-Exit Discriminator (MED) is an optional non-transitive attribute used to influence how a neighboring AS selects an entry point into your AS when multiple entry points exist. A lower MED value is preferred. By setting a lower MED on the routes advertised over the primary link and a higher MED on the backup link, you suggest to the ISP which path to prefer for inbound traffic. Local Preference is used to influence outbound traffic decisions within your own AS. AS_Path prepending is another method, but MED is specifically designed for this purpose.
- 8
A large-scale enterprise network uses IS-IS as its IGP. The network is divided into multiple Level-1 areas connected to a Level-2 backbone. To improve scalability, the lead architect wants to prevent Level-1 routers from receiving specific Level-2 routes while still allowing them to reach those destinations via a default route. Which IS-IS feature should be implemented on the Level-1-2 border routers?
Show answer details
Correct answer: B
By default, a Level-1-2 router sets the Attached (ATT) bit in its Level-1 LSP. This signals to other Level-1 routers within the same area that it has a connection to the Level-2 backbone. The Level-1 routers will then install a default route pointing to the L1/L2 router. This mechanism allows Level-1 routers to reach destinations outside their area (including other L1 areas and external routes) without needing to hold all the specific Level-2 routes in their routing tables, thus improving scalability.
- 9
An administrator is implementing Policy-Based Routing (PBR) on a Huawei router to redirect HTTP traffic from a specific subnet (192.168.10.0/24) to a dedicated proxy server (10.10.10.1). Which of the following components are required for this configuration? (Select THREE)
Show answer details
Correct answer: A, B, C
- 10
True or False: In a multi-area OSPF network, a Type 4 Summary-ASBR LSA is generated by an Area Border Router (ABR) to advertise the location of an Autonomous System Boundary Router (ASBR) to other areas.
Show answer details
Correct answer: A
This statement is true. A Type 5 External LSA, which advertises an external route, is flooded throughout the OSPF domain. However, the next-hop for this external route is the ASBR. Routers in other areas need to know how to reach the ASBR. The ABR in the ASBR's area generates a Type 4 LSA to advertise the ASBR's router ID and the cost to reach it into other areas, enabling proper routing to external destinations.
