DON'T WANT TO MISS A THING?

Certification Exam Passing Tips

Latest exam news and discount info

Curated and up-to-date by our experts

Yes, send me the newsletter

Free Huawei H12-711 Practice Questions & Answers 2026 Part2 | HCIA-Security

Are you preparing for the Huawei H12-711 certification exam? SPOTO offers the Huawei H12-711 Premium File; all questions are aligned with the latest exam content and come with expert-provided answers. Our question banks cover the latest question types, core concepts, and detailed explanations, helping you familiarize yourself with the exam format and difficulty level. Whether you are reviewing core concepts or simulating a real exam environment, these resources will rapidly boost your confidence and readiness.
For over two decades, SPOTO has successfully helped numerous IT professionals secure their ideal positions at Fortune 500 companies. Download now to start practicing efficiently and ensure a high score on the actual exam. Don't miss this opportunity to pass your certification exam with ease!
Take other online exams

Question #1
at HuaweiUSGOn the series firewalls, the default security policy does not support modification.
A. rue
B. alse
View answer
Correct Answer: B
Question #2
Among the various aspects of the risk assessment of IS027001, which of the following does not belong to the system design and release process?
A. Hold a summary meeting of the project in the information security management stage
B. Determine risk disposal measures and implement rectification plans
C. Determine risk tolerance and risk appetite
D. System integration and information security management system document preparation
View answer
Correct Answer: A
Question #3
SSL VPN is a VPN technology that realizes remote secure access through SSL protocol. Which of thefollowing software must be installed when using SSL VPN?
A. rowser
B. irewall
C. lient
D. ntivirus
View answer
Correct Answer: C
Question #4
SSL VPN supported file sharing types can be divided into two kinds of SMB and NFS, SMB correspond Windows hosts, NFS correspond Linux host
A. True
B. False
View answer
Correct Answer: A
Question #5
Which of the following types of malicious code on your computer includes?
A. Oral virus
B. Trojan horses
C. Port SQL injection
D. Oral spyware
View answer
Correct Answer: ABCD
Question #6
Which of the following statements is incorrect about DoS attacks?
A. oS attacks stop services or resource access on the target server
B. oS attacks use IP spoofing to prevent authorized users from connecting to the target server
C. oS attack forces the target server's buffer to be full and does not receive new requests
D. oS attacks cause unrecoverable physical damage to the target server
View answer
Correct Answer: D
Question #7
A Web server is deployed in an enterprise intranet to provide Web access services to Internet users, and in order to protect the access security of the server, it should be divided into the _____ area of the firewall.
A. DMZ
B. DMY
View answer
Correct Answer: A
Question #8
What is the security level of the Untrust zone in Huawei firewalls?
A. 10
B. 20
C. 5
D. 15
View answer
Correct Answer: C
Question #9
Which of the following attack methods is to construct special SQL statements and submit sensitive information to exploit program vulnerabilities
A. Buffer overflow attack
B. SQL injection attacks
C. Worm attack
D. Phishing attacks
View answer
Correct Answer: B
Question #10
At what layer does packet filtering technology in the firewall filter packets?
A. Transport layer
B. Network layer
C. Physical layer
D. Data link layer
View answer
Correct Answer: B
Question #11
For which of the following parameters can the packet filtering firewall filter?
A. Port packet payload
B. IP address of the port source destination
C. The MAC address of the source destination
D. Port number and protocol number of the port source
View answer
Correct Answer: BD
Question #12
For which of the following parameters can the packet filtering firewall filter?
A. Port packet payload
B. IP address of the port source destination
C. The MAC address of the source destination
D. Port number and protocol number of the port source
View answer
Correct Answer: BD
Question #13
When the Layer 2 switch receives a unicast frame and the MAC address table entry of the switch is empty, the switch discards the unicast frame.
A. TRUE
B. FALSE
View answer
Correct Answer: B
Question #14
Which layer of the protocol stack does SSL provide end-to-end encrypted transmission services?
A. Application layer
B. Data link layer
C. Network layer
D. Transport layer
View answer
Correct Answer: D
Question #15
Which of the following can be supported by Policy Center access control? (Choose three.)
A. Hardware SACG (hardware security access control gateway)
B. 802
C. ARP control
D. Software SACG (host firewall)
View answer
Correct Answer: ABD
Question #16
What is the security level of the Untrust zone in Huawei firewalls?
A. 10
B. 20
C. 5
D. 15
View answer
Correct Answer: C
Question #17
Among the various aspects of the risk assessment of IS027001, which of the following does notbelong to the system design and release process?
A. old a summary meeting of the project in the information security management stage
B. etermine risk disposal measures and implement rectification plans
C. etermine risk tolerance and risk appetite
D. ystem integration and information security management system document preparation
View answer
Correct Answer: A
Question #18
Which layer of the protocol stack does SSL provide end-to-end encrypted transmission services?
A. Application layer
B. Data link layer
C. Network layer
D. Transport layer
View answer
Correct Answer: D
Question #19
For which of the following parameters can the packet filtering firewall filter?
A. Port packet payload
B. IP address of the port source destination
C. The MAC address of the source destination
D. Port number and protocol number of the port source
View answer
Correct Answer: BD
Question #20
Which of the following types of malicious code on your computer includes?
A. Oral virus
B. Trojan horses
C. Port SQL injection
D. Oral spyware
View answer
Correct Answer: ABCD
Question #21
Which of the following types of malicious code on your computer includes?
A. Oral virus
B. Trojan horses
C. Port SQL injection
D. Oral spyware
View answer
Correct Answer: ABCD
Question #22
For which of the following parameters can the packet filtering firewall filter?
A. ort packet payload
B. P address of the port source destination
C. he MAC address of the source destination
D. ort number and protocol number of the port source
View answer
Correct Answer: BD
Question #23
As shown in the figure, the administrator needs to test the network quality of the 20.0.0/24 CIDR block to the 40.0.0/24 CIDR block on Device B, and the device needs to send large packets for a long time to test the network connectivity and stability.
A. tracert -a 20
B. ping -a 20
C. ping -s 20
D. tracert -a 20
View answer
Correct Answer: B
Question #24
For which of the following parameters can the packet filtering firewall filter?
A. Port packet payload
B. IP address of the port source destination
C. The MAC address of the source destination
D. Port number and protocol number of the port source
View answer
Correct Answer: BD
Question #25
Digital envelope technology means that the sender uses the receiver's public key to encrypt the data, and then sends the ciphertext to the receiver ( )[Multiple choice]*
A. TRUE
B. FALSE
View answer
Correct Answer: B
Question #26
Which of the following attack methods is to construct special SQL statements and submit sensitive information to exploit program vulnerabilities
A. Buffer overflow attack
B. SQL injection attacks
C. Worm attack
D. Phishing attacks
View answer
Correct Answer: B
Question #27
A Web server is deployed in an enterprise intranet to provide Web access services to Internet users, and in order to protect the access security of the server, it should be divided into the _____ area of the firewall.
A. DMZ
B. DMY
View answer
Correct Answer: A
Question #28
Which user authentication methods can be supported by Policy Center system? (Choose three.)
A. IP address authentication
B. MAC address authentication
C. Ordinary ID/password authentication
D. LDAP authentication
View answer
Correct Answer: BCD
Question #29
WAF can accurately control and manage users' online behavior and user traffic.
A. TRUE
B. FALSE
View answer
Correct Answer: A
Question #30
Which of the following is true about the description of the firewall?
A. n order to avoid single point of failure, the firewall only supports side-by-side deployment
B. dding a firewall to the network will inevitably change the topology of the network
C. epending on the usage scenario, the firewall can be deployed in transparent mode or deployed in a three-bedroom mode
D. he firewall cannot transparently access the network
View answer
Correct Answer: C
Question #31
Which of the following types of malicious code on your computer includes?
A. ral virus
B. rojan horses
C. ort SQL injection
D. ral spyware
View answer
Correct Answer: ABCD
Question #32
In the process of digital signature, which of the following is mainly carried outHASHAlgorithms thereby verifying the integrity of data transmissions?
A. ser data
B. eceiver's public key
C. ymmetric key
D. eceiver's private key
View answer
Correct Answer: A
Question #33
When the following conditions occur in the VGMP group, the VGMP message will not be sent to the peer end actively?
A. anually switch the active and standby status of the firewall
B. ession table entry changes
C. irewall service interface failure
D. ual hot backup function enabled
View answer
Correct Answer: B
Question #34
Which of the following is correct about firewall IPSec policy?
A. y default, IPSec policy can control multicast
B. y default, IPSec policy can control unicast packets and broadcast packets
C. y default, IPSec policy only controls unicast packets
D. y default, IPSec policy can control unicast packets, broadcast packets, and multicast packets 。
View answer
Correct Answer: C
Question #35
According to the protection object, the firewall is divided. Windows Firewall belongs to ________.
A. etwork firewall
B. tand-alone firewall
C. oftware firewall
D. ardware firewall
View answer
Correct Answer: B
Question #36
Among the various aspects of the risk assessment of IS027001, which of the following does not belong to the system design and release process?
A. Hold a summary meeting of the project in the information security management stage
B. Determine risk disposal measures and implement rectification plans
C. Determine risk tolerance and risk appetite
D. System integration and information security management system document preparation
View answer
Correct Answer: A
Question #37
Policy Center system can implement two dimensions’ management functions: organizational management and regional management
A. True
B. False
View answer
Correct Answer: A
Question #38
Which layer of the protocol stack does SSL provide end-to-end encrypted transmission services?
A. Application layer
B. Data link layer
C. Network layer
D. Transport layer
View answer
Correct Answer: D
Question #39
SSL VPN supported file sharing types can be divided into two kinds of SMB and NFS, SMB correspond Windows hosts, NFS correspond Linux host
A. True
B. False
View answer
Correct Answer: A
Question #40
Which of the following packets is controlled by a firewall's security policy by default?
A. ulticast
B. nicast
C. nycast
D. roadcast
View answer
Correct Answer: B
Question #41
ARP man-in-the-middle attacks are a type of spoofing attack technique.
A. TRUE
B. FALSE
View answer
Correct Answer: A
Question #42
Which layer of the protocol stack does SSL provide end-to-end encrypted transmission services?
A. Application layer
B. Data link layer
C. Network layer
D. Transport layer
View answer
Correct Answer: D
Question #43
What is the security level of the Untrust zone in Huawei firewalls?
A. 10
B. 20
C. 5
D. 15
View answer
Correct Answer: C
Question #44
Which of the following options are correct regarding the description of Windows log event types? (multiple choice)
A. Warning events are events that refer to the successful operation of an application, driver, or service
B. False events generally refer to loss of functionality and data
C. When the disk space is insufficient, it will be recorded as an "information event"
D. Failed audit events refer to failed audit security logon attempts, such as failure to access a network drive from a user's view, will be logged as a failed audit event
View answer
Correct Answer: BD
Question #45
Which of the following is not a rating in the network security incident?
A. pecial network security incidents
B. eneral network security incidents
C. ajor network security incidents
D. arger network security incidents
View answer
Correct Answer: A
Question #46
Which layer of the protocol stack does SSL provide end-to-end encrypted transmission services?
A. Application layer
B. Data link layer
C. Network layer
D. Transport layer
View answer
Correct Answer: D
Question #47
For which of the following parameters can the packet filtering firewall filter?
A. Port packet payload
B. IP address of the port source destination
C. The MAC address of the source destination
D. Port number and protocol number of the port source
View answer
Correct Answer: BD
Question #48
A Trojan horse can operate autonomously. Once it is planted on a user's device, the Trojan horse starts to replicate itself and can be activated without user operations.
A. RUE
B. ALSE
View answer
Correct Answer: B

View Answers after Submission

Please submit your email and WhatsApp to get the answers of questions.

Note: Please make sure your email ID and Whatsapp are valid so that you can get the correct exam results.

Email:
Whatsapp/phone number:
Contact Us