Huawei HCIE-Security (Huawei Certified Internetwork Expert-Security) (H12-731中文版) Sample Questions:
1. 在双机热备的场景,关于防火墙主设备和备设备描述错误的是 ?
A) 默认情况下,主用设备的配置会立刻备份到备用设备上。
B) 配置主设备界示 HRP_A ,配置从设备界示 HRP_S ,而且不随优先级变化而变化。
C) 只有主设备才能进行命令配置,备用设备命令不能进行配置。
D) 当双机热备工作在主备状态下,主用设备的命令提示符显示 HRPA ,备用设备的命令提示符显示 HRP_S 。
2. 防火墙的双机热备份的命令备份功能中不可以备份以下哪些命令 ?
A) IP 地址配置
B) 路由表
C) IPS 命令
D) 转发策略命令
3. 根据以下状态信息判断, USG 设备使用了哪项 QoS 技术:
[USG_A] display qos policy interface tunnel 1
Interface: GigabitEthernet0/0/1
Direction: Outbound
Policy: dscp
Classifier: default-class
Matched: 0/0
(Packets/Bytes)
Rule(s): if-match any
Behavior: be
-none-
Classifier: server
Matched: 480154/41293244
(Packets/Bytes)
Offered rate: 7244746 bps, drop
rate: 242352 bps
Operator: AND
Rule(s): if-match acl 2001
Behavior: server
Assured Forwarding:
Bandwidth 40000
(Kbps)
Matched:
713659/71365900 (Packets/Bytes)
Enqueued:
36606/3660600 (Packets/Bytes)
Discarded:
677053/67705300 (Packets/Bytes)
Classifier: pc
Matched: 478498/41150828
(Packets/Bytes)
Offered rate: 7344746 bps, drop
rate: 342352
Operator: AND
Rule(s): if-match acl 2002
Assured Forwarding:
Bandwidth 40000 (Kbps)
Matched:
765394/76539400 (Packets/Bytes)
Enqueued:
39235/3923500 (Packets/Bytes)
Discarded:
726159/72615900 (Packets/Bytes)
Classifier: telephone
Matched: 550057/47304902
(Packets/Bytes)
Offered rate: 8244746 bps, drop
rate: 252352 bps
Operator: AND
Rule(s): if-match acl 2003
Behavior: telephone
Expedited Forwarding:
Bandwidth 240000
(Kbps), CBS 600000 (Bytes)
Matched:
765644/76564400 (Packets/Bytes)
Enqueued:
70553/7055300 (Packets/Bytes)
Discarded:
695091/69509100 (Packets/Bytes)
A) GTS
B) WRED
C) CBWFQ
D) CAR
4. IPS (入侵防御)故障需要排查哪几方面 ?
A) 是否配置 IPS 策略,并应用到域间。
B) 是否使能 IPS 全局开关。
C) 查看是否配置 IPS 黑名单。
D) 是否配置了覆盖签名。
E) 配置的策略是否提交编译。
5. 终端用 Agent 进行 802.1x 认证, SC 和 Radius 服务器 IP 地址为 172.18.10.68 ,认证时总是提示网络通信失败;
查看 Radius 认证日志显示 Radius 认证成功,并且授权为 ACL3001 ,交换机配置如下:
dot1x enable
dot1x authentication-method eap
radius-server template lzy
radius-server shared-key simple 123456
radius-server authentication 172.18.10.68 1812
radius-server accounting1 72.1 3.10.63 1813
radius-server authorization 172.18.10.68 shared-key simple 123456
aaa
authentication-scheme default
authentication-scheme auth
authentication-mode radius
accounting-scheme acco
accounting-mode radius
accounting realtime 3
domain default
authentication-scheme auth
accounting-scheme acco
radius-server lzy
interface GigabitEthernet0/0/14
description connect 222
port hybrid pvid vlan 105
port hybrid untagged vlan 105
dot1x enable
acl number 3001
rule 1 permit ip destination 172.18.100.235 0
rule 2 permit ip destination 172.18.100.237 0
rule 10 deny ip
网络通信失败的原因可能是 ?
A) 计费配置可能错误
B) GigabitEthernet0/0/14 端口配置错误
C) 授权规则 ACL 配置错误
D) AAA 配置错误
Solutions:
| Question # 1 Answer: B,C | Question # 2 Answer: A,B | Question # 3 Answer: C | Question # 4 Answer: A,B,E | Question # 5 Answer: C |
We're so confident of our products that we provide no hassle product exchange.


By Meredith

