Question No : 1

What is the maximum bits of a Class C address can be used for subnet?
Answer: A

Question No : 2

Which of the following statements are correct regarding the function of VRRP?
A. VRRP can improve the reliability of default gateway.
B. VRRP increase the convergence speed of routing protocol.
C. VRRP is mainly used for traffic balance.
D. VRRP can provide one default gateway for different network segments, it simplifies the gateway configuration for PC.
Answer: A

Question No : 3

Which following BGP attribute can used to define a set of prefixes with the same characteristics?
A. Origin
B. Nexthop
C. Community
Answer: C

Question No : 4

Which of the following statements about the zone priorities of the Eudemon are true?
A. The priority of the Local zone is 100.
B. The priority of the Trust zone is 80.
C. The priority of the Untrust zone is 5.
D. The priority of the DMZ is 50.
Answer: ACD

Question No : 5

Assume that the trace route test is used to detect the packet forwarding path and tracert packets have passed through the firewall.
Which of the following attack protection functions needs to be disabled to normally display the tracert result?
A. ICMP-redirect
B. ICMP-unreachable
C. Tracert
D. Smurf
Answer: C

Question No : 6

Which of the following statements about the security policies for the Eudemon are true9
A. By default, a user in the Local zone can access other zones.
B. By default, a user in the Trust zone can access the DMZ.
C. By default, a user in the Untrust zone cannot access the Trust zone.
D. By default, a user in a zone of the firewall cannot access any other zone of the firewall.
Answer: CD

Question No : 7

Which of the following NAT functions are supported by the Eudemon?
C. Bidirectional NAT
D. NAT server
Answer: ABCD

Question No : 8

Which of the following data traffic is incoming data traffic on the Eudemon?
A. Data traffic from a Trust zone to a demilitarized zone (DMZ)
B. Data traffic from an Untrust zone to a DMZ
C. Data traffic from a Local zone to a Trust zone
D. Data traffic from an Untrust zone to a Local zone
Answer: BD

Question No : 9

Which of the following options are performance parameters of the firewall?
A. Throughput
B. Maximum number of connections
C. Number of new connections per second
D. Process delay
Answer: ABCD

Question No : 10

The firewall does not use security rules to filter packets exchanged between interfaces in the same zone.
A. True
B. False
Answer: A

Question No : 11

The Eudemon that is working in transparent mode detects processes data at Layer 2. Its interfaces are not configured with lP addresses.
A. True
B. False
Answer: A

Question No : 12

TRUE/FALSE: On an MPLS VPN network, CEs and PEs can use the same routing protocol or different routing protocols to exchange routing information. The routing protocols are independent from one another.
A. True
B. False
Answer: A

Question No : 13

Which of the following commands is used to display the detailed information about the Eudemon?
A. display firewall statistic system
B. display firewall session table raw both-direction
C. display firewall session table verbose
D. display firewall session table detail
Answer: C

Question No : 14

In a Land attack, the source address and destination address of an SYN packet are both the IP address of the attacked object or a loopback address.
A. True
B. False
Answer: A

Question No : 15

How many default zones does the Eudemon supporting multi-instance have?
A. Two
B. Three
C. Four
D. Five
Answer: D
