Question No : 1

Check firewall HRP status information as follows:
HRP_S [USG_B] display hrp
The firewall's config state is: Standby
Current state of virtual routers configured as standby
GigabitEthernet1/0/0 vrid 1: standby
GigabitEthernet1/0/1 vrid 2: standby
Which of the following description is correct?
A. the firewall VGMP group status is Active
B. the firewall G1/0/0 and G1/0/1 interface of VRRP group status is Standby
C. the firewall of HRP heartbeats interface is G1/0/0 and G1/0/1
D. the firewall must be in a state of preemption
Answer: B

Question No : 2

Terminal security system supports Bluetooth, SD card and other computer peripherals monitoring function, and support configuration peripheral equipment prohibited.
Answer: A

Question No : 3

When ARP address resolution, ARP-REPLY packets sent by means of broadcast, hosts are able to receive on the same Layer 2 network , and thus learn the corresponding relations between the IP and MAC address.
Answer: B

Question No : 4

USG state detecting firewall to view Session information as follows:
<USG > display firewall session table verbose
Current total sessions: 1
icmp VPN: public -- > public
Zone: trust -- > untrust Slot: 8 CPU: 0 TTL: 00:00:20 Left: 00:00:19
Interface: GigabitEthernet6/0/0 Nexthop:
<--packets: 134 bytes: 8040-- > packets: 134 bytes: 8040 1280-- >
Which of the following statement about above information are correct ? ( multiple choice)
A. In Trust area host is visiting or have visited Untrust
B. the packet is VPN packet
C. the follow-up to the firewall packat,need to match the session table and firewall security policy
D. the outbound interface of forward direction flow is GigabitEthernet6/0/0
Answer: AD

Question No : 5

Huawei USG firewall VRRP HELLO packets for multicast packets, it requires each router in the backup group must be able to achieve directly two layer interflow.
Answer: A

Question No : 6

The address range of rule permit ip source is :
Answer: B

Question No : 7

Wildcard mask and subnet mask formats are similar, but values have different meanings, in wildcard mask, 1 indicates that the corresponding IP address bits need to compare, 0 indicates that the corresponding IP address bits to ignore comparisons.
Answer: B

Question No : 8

Which of the following does not belong to the AES secret key length?
A. 64
B. 128
C. 192
D. 256
Answer: A

Question No : 9

CA (Certificate Authority) certificate used for verifying the user's identity of virtual gateway when SSL communication connection is established, saved in the device side, issued by the CA institution.
Answer: A

Question No : 10

Which of following problems can use IPsec-IKE aggressive mode to solve ? (multiple choice)
A. negotiate slow problem on both ends of the tunnel
B. the security problems in the process of negotiation
C. NAT traversal problem
D. originator source address uncertainty problem
Answer: CD

Question No : 11

ASPF technology enables the firewall to support multi-channel protocols such as FTP, at the same time can also formulate the corresponding security strategy for complex applications.
Answer: A

Question No : 12

Use NAT technology, can only switch the network layer information (IP address) in the data packet .
Answer: B

Question No : 13

About NAT £¬ which statement is correct?
A. NAT with port translation NAT address pool can be configured to achieve
B. NAT compatible with all IPsec security protocol
C. Because the FTP protocol is a multi-channel protocol, so it does not support NAT
D. NAT support TCP/IP two, three, four conversion
Answer: A

Question No : 14

SVN products extend the network function, the need to implement the user can only access the remote enterprise Intranet, cannot access to the local LAN and the Internet, you need to use the client routing is:
A. Full Tunnel
B. Split Tunnel
C. Route Tunnel
D. Manual Tunnel
Answer: A

Question No : 15

When you configure source NAT strategy, the configuration of destination area can be used to replace configuration flow outbound interface information .
Answer: A
