Huawei H12-731-ENU Exam Overview:
| Certification Vendor: | Huawei |
|---|---|
| Exam Name: | HCIE-Security Written Exam |
| Exam Number: | H12-731-ENU |
| Exam Format: | Multiple choice, Multiple response |
| Related Certifications: | Huawei Certified Network Professional (HCNP) Security Huawei Certified Network Associate (HCNA) Security |
| Available Languages: | English |
| Recommended Training: | Huawei HCIE-Security Training Resources |
| Exam Registration: | Huawei Talent Online Certification Platform |
| Sample Questions: | Huawei H12-731-ENU Sample Questions |
| Exam Way: | Computer-based testing at authorized Huawei testing centers or online proctored exam (varies by region) |
| Pre Condition: | It is recommended to have prior knowledge equivalent to HCNP Security or equivalent networking/security experience. |
| Official Syllabus URL: | https://e.huawei.com/en/talent/ |
Huawei H12-731-ENU Exam Syllabus Topics:
| Section | Objectives |
|---|---|
| Topic 1: Security Operations and Maintenance | - Security policies and logs - Security monitoring and incident response |
| Topic 2: Secure Network Access Control | - AAA and RADIUS systems - 802.1X authentication |
| Topic 3: Network Security Fundamentals | - Security principles and models - Common attack types and defense mechanisms |
| Topic 4: Perimeter Security Technologies | - Firewall technologies and deployment - VPN technologies (IPSec / SSL VPN) |
| Topic 5: Network Defense and Intrusion Prevention | - Anti-DDoS technologies - IDS/IPS systems |
Huawei HCIE-Security (Huawei Certified Internetwork Expert-Security) Sample Questions:
A Web Server deployed in the DMZ area of an enterprise has an intranet IP address of 10.1.1.3 and a port of 8080. The public network address announced to the outside world is 1.1.1.2, and the external port number is 80.
Configure the following commands on the firewall:
[USG6600] security-policy
[[USG6600-policy-security] rule name untrust_to_mz
[USG6600-policy-security-rule-untrust_to_mz] source-zone untrust
[USG6600-policy-security-rule-untrust_to_mz] destination-zone dmz
[USG6600-policy-security-rule-untrust_to_mz] destination-address 1.1.1.2 32
[USG6600-policy-security-rule-untrust_to_mz] service http
[USG6600-policy-security-rule-untrust_to_mz] action permit
[USG6600] nat server webserver protocol tcp global 1.1.1.2 www inside 10.1.1.3 8080
The external network PC cannot access the Web Server of 10.1.1.3 within the enterprise. Please analyze the most likely reasons for this:
- A. Firewall should be configured as nat server webserver protocol tcp global 1.1.1.2 80 inside 10.1.1.3 8080
- B. Firewall untrust to DMZ zone security policy should be configured as destination-address 10.1.1.3 32
- C. Firewall untrust to DMZ zone security policy should be configured as service 8080
- D. The firewall does not open the default packet filtering policy from the untmut zone to the dmz zone
Correct Answer: B π³οΈ
Intranet users can access the Internet normally, and dual links are used for master and backup backup.
For Internet users, the FTP server can be accessed through the public network address. Two public network addresses are announced, 200.1.1.200 and 202.1.1.200.
Which of the following configuration is correct?
- A. [USG] ip-link check enable [USG] ip-link 1 destination 202.1.1.2 interface GigabitEthernet 0/0/2 mode icmp [USG] ip route-static 0.0.0.0 0.0.0.0 200.1.1.2 [USG ] ip route-static 0.0.0.0 0.0.0.0 200.1.1.2 preference 70 track ip-link 1
- B. USG] ip-link check enable [USG] ip-link 1 destination 200.1.1.2 interface GigabitEthernet 0/0/2 mode icmp [USG] ip route-static 0.0.0.0 0.0.0.0 200.1.1.2 track ip- link 1 [USG] ip route-static 0.0.0.0 0.0.0.0 200.1.1.2 preference 70
- C. [USG] nat server s1 protocol tcp global 200.1.1.200 ftp inside 192.168.1.254 ftp [USG] nat server s2 protocol tcp global 202.1.1.200 ftp inside 192.168.1.254 ftp
- D. [USG] nat server s1 zone untrust1 protocol global 200.1.1.200 ftp inside 192.168.1.254 ftp [USG] nat server s2 zone untrust2 protocol global 202.1.1.200 ftp inside 192.168.1.254 ftp
Correct Answer: B,D π³οΈ
As shown in the figure below, a company uses the USG6600 firewall as the egress. The company has two egresses. Carrier A and carrier B share the egress load. When an engineer deploys the firewall, two egresses are added to the untrust zone at the same time. The user has joined the trust zone and made source NAT mapping. After the deployment, it is found that some users have normal access to the Internet, while some users have very slow access to the Internet, and even sometimes cannot access the Internet.
[USG] display firewall session table verbose
http VPN: public --> public
Zone: trust --> untrust TTL: 00:00:10 Left: 00:00:08
Interface: GigabitEthernet0/0/0 Nexthop: 41.134.5.49 MAC: F0-DE-F1-69-26-91
<--packets: 9 bytes: 364 -->packets: 9 bytes: 364
10.16.1.20:5246 [41.134.5.52:5246] --> 16.8.3.8:80
http VPN: public --> public
Zone: trust --> untrust TTL: 00:10:00 Left: 00:09:59
Interface: GigabitEthernet0/0/1 Nexthop: 41.160.30.65 MAC: 00-21-97-cf-22-38
<--packets: 4 bytes: 238 -->packets: 14 bytes: 1640
10.16.1.122:3745 [41.134.5.52:3745] --> 2.2.2.2:80
[USG] display ip routing-table
20:56:07 2012/09/30
Route Flags: R - relay, D - download to fib
Routing Tables: Public
Destinations: 5 Routes: 5
Destination/Mask Proto Pre Cost Flags NextHop
0.0.0.0/0
Static 60
0
RD 41.134.5.49
0.0.0.0/0
Static
60
0
RD 41.160.30.65
10.16.1.1/24
Direct
0
0
D 127.0.0.1
127.0.0.0/8
Direct
0
0D 127.0.0.1
127.0.0.1/32
Direct
0
0
D 127.0.0.1
Based on the above information, please determine which of the following descriptions is correct?
- A. The issue is related to carrier network stability.
- B. The problem is caused by an equal-cost route.
- C. The problem is caused by the user's PC.
- D. It can be inferred that the source NAT configuration is correct.
Correct Answer: B,D π³οΈ
Which of the following options fall under the scope of visitor management?
- A. Visitor page customization
- B. Guest Account Creation
- C. Visitors register on the registration page
- D. The guest uses the account to authenticate
- E. Guest Account Approval
- F. Visitor online behavior audit
Correct Answer: A,B,E,F π³οΈ
After the USG enables the HRP backup function, key configuration commands and session table status information will be synchronously backed up to the standby device in real time. What configuration commands and status information can be backed up?
- A. Forwarding Policy Commands
- B. interface configuration command
- C. Attack Defense Command
- D. session table
- E. Virtual Firewall Command
Correct Answer: A,C,D π³οΈ
We're so confident of our products that we provide no hassle product exchange.


By Stephanie

