Huawei H12-731-ENU 試験概要:
| 認定ベンダー: | Huawei |
| 試験名: | HCIE-Security 筆記試験 |
| 試験番号: | H12-731-ENU |
| 関連資格: | Huawei Certified Network Professional (HCNP) Security Huawei Certified Network Associate (HCNA) Security |
| 対応言語: | English |
| 試験形式: | 単一選択式, 複数選択式 |
| 推奨トレーニング: | Huawei HCIE-Securityトレーニングリソース |
| 受験申し込み: | Huawei Talentオンライン認定プラットフォーム |
| サンプル問題: | Huawei H12-731-ENU サンプル問題 |
| 受験方法: | 認定されたHuawei試験センターでのコンピュータベースの試験、またはオンライン監督試験(地域によって異なります) |
| 前提条件: | HCNP Securityと同等の事前知識、または同等のネットワーク/セキュリティ経験があることが推奨されます。 |
| 公式シラバスのURL: | https://e.huawei.com/en/talent/ |
Huawei H12-731-ENU 試験シラバストピック:
| セクション | 目標 |
|---|---|
| トピック 1: 境界セキュリティ技術 | - ファイアウォール技術と導入 - VPN技術 (IPSec / SSL VPN) |
| トピック 2: ネットワークセキュリティの基礎 | - 一般的な攻撃タイプと防御メカニズム - セキュリティ原則とモデル |
| トピック 3: セキュリティ運用と保守 | - セキュリティポリシーとログ - セキュリティ監視とインシデント対応 |
| トピック 4: セキュアネットワークアクセス制御 | - AAAおよびRADIUSシステム - 802.1X認証 |
| トピック 5: ネットワーク防御と侵入防止 | - Anti-DDoS技術 - IDS/IPSシステム |
Huawei HCIE-Security (Huawei Certified Internetwork Expert-Security) 認定 H12-731-ENU 試験問題:
1. The terminal uses Agent for 802.1x authentication, the IP address of SC and Radius server is 172.18.10.68, and it always prompts network communication failure during authentication;
Viewing the Radius authentication log shows that the Radius authentication is successful and the authorization is ACL3001. The switch configuration is as follows:
dot1x enable
dot1x authentication-method eap
radius-server template lzy
radius-server shared-key simple 123456
radius-server authentication 172.18.10.68 1812
radius-server accounting1 72.1 3.10.63 1813
radius-server authorization 172.18.10.68 shared-key simple 123456
aaa
authentication-scheme default
authentication-scheme auth
authentication-mode radius
accounting-scheme acco
accounting-mode radius
accounting realtime 3
domain default
authentication-scheme auth
accounting-scheme acco
radius-server lzy
interface GigabitEthernet0/0/14
description connect 222
port hybrid pvid vlan 105
port hybrid untagged vlan 105
dot1x enable
acl number 3001
rule 1 permit ip destination 172.18.100.235 0
rule 2 permit ip destination 172.18.100.237 0
rule 10 deny ip
What could be the reason for the failure of network communication?
A) AAA configuration error
B) GigabitEthernet0/0/14 port configuration error
C) Authorization rule ACL configuration error
D) Billing configuration may be wrong
2. When the firewall runs GRE, which three parameters must be configured on the tunnel interface?
A) source IP address of the tunnel
B) The protocol number of the tunnel is GRE
C) Destination IP address of the tunnel
D) Checksum enable for GRE
E) key
3. Which of the following statements about hot standby is correct?
A) The preemption operation is always started only after the failure recovery or the restart of the primary USG is completed.
B) hrp auto-sync config , which will manually back up the commands configured on the primary USG to the secondary USG.
C) If the preemption time is set too long, the switch operation will not be performed immediately when the USG fails.
D) The vrrp vrids of the interfaces corresponding to the heartbeat lines on the two USGs may be different.
4. The Trust zone of the USG firewall of a certain network is connected to the terminal host, and the Untrust zone is connected to the security controller. If the security controller can issue rules to the USG, which of the following security policies must be configured?
A) security-policy rule name untrust_to_local source-zone untrust destination-zone local action permit rule name local_to_trust source-zone local destination-zone trust action permit
B) security-policy rule name to_local source-zone untrust trust destination-zone local action permit
C) security-policy rule name local_to_trust source-zone local destination-zone trust action permit
D) security-policy rule name untrust_to_local source-zone untrust destination-zone local action permit
5. A company has the following requirements:
The intranet users in the Trust area are on the 192.160.1.0/24 network segment and can access the Internet.
Which of the following configurations are correct:
traffic-policy
profile trust_tountrust
bandwidth downstream
maximum-bandwidth 400000
bandwidth downstream
guaranteed-bandwidth 50000
bandwidth ip-car downstream
maximum-bandwidth per-ip 2000
rule name trust_to_untrust
source-zone trust
destination-zone untrust
source-address 192.160.1.0 24
action qos profile
trust_to_untrust
#
A) This configuration will implement the download traffic in the direction from Trust to Untrust, and the maximum bandwidth per IP is 2M.
B) This configuration will implement speed limit for Internet addresses to actively access the intranet segment.
C) This configuration will enable Trust intranet users to actively access the Internet outside the Internet and limit the total maximum download bandwidth to 400M.
D) This configuration will achieve an overall upload bandwidth of 50M for intranet 192.168.1.0/24 users.
質問と回答:
| 質問 # 1 正解: C | 質問 # 2 正解: A、B、C | 質問 # 3 正解: A | 質問 # 4 正解: D | 質問 # 5 正解: A、C |














911 お客様のコメント
品質保証JPexamはIT認定試験のシラバスに従って、試験問題の範囲を正確に絞って、的中率が99%の最新問題集を捧げます。
1年間の無料更新サービスJPexamは1年以内に問題集の無料更新サービスを提供し、お客様がいつでも最新版の問題集を持つことを保証いたします。もし試験の内容が変更されたら、弊社は直ちにお客様にお知らせします。それに、弊社の問題集が更新されたら、早速メールで最新バージョンを送付いたします。
全額返金JPexamの問題集を利用すると、短時間で勉強しても試験に合格できるのを保証いたします。試験に不合格になってしまった場合、弊社は全額返金いたします。(
ご購入前のお試しJPexamは問題集のサンプルを無料で提供いたします。ご購入前にサンプルを試用して製品の品質を確認することができます。ご遠慮なく利用してください。
