ExamGecko
Home / Huawei / H12-821_V1.0 / List of questions
Ask Question

Huawei H12-821_V1.0 Practice Test - Questions Answers, Page 11

List of questions

Question 101

Report Export Collapse

What parameters can a DHCP6 server assign to a DHCPv6 client?

Gateway address

Gateway address

DNS server address

DNS server address

IPV6 address/prefix

IPV6 address/prefix

SNTP server address

SNTP server address

Suggested answer: B, C, D
Explanation:

Understanding DHCPv6:

DHCPv6 (Dynamic Host Configuration Protocol for IPv6) is used to assign configuration parameters to IPv6 clients.

It supports both stateful and stateless modes:

Stateful: Assigns IPv6 addresses and other configuration parameters.

Stateless: Assigns only configuration parameters (e.g., DNS server) without providing IPv6 addresses.

Analysis of Parameters:

A . Gateway address:

False. DHCPv6 does not assign the default gateway. Instead, the default gateway is advertised by routers using Router Advertisement (RA) messages in IPv6.

B . DNS server address:

True. DHCPv6 can assign the IPv6 address of DNS servers to the client.

C . IPv6 address/prefix:

True. In stateful mode, DHCPv6 assigns IPv6 addresses and prefixes to clients.

D . SNTP server address:

True. DHCPv6 can assign the address of an SNTP (Simple Network Time Protocol) server to synchronize time on the client.

Conclusion:

The correct parameters that a DHCPv6 server can assign to a client are: B. DNS server address, C. IPv6 address/prefix, D. SNTP server address.

asked 02/12/2024
Maria Kniess
42 questions

Question 102

Report Export Collapse

Which of the following statements about multicast packet forwarding is true?

If a multicast data packet fails the RPF check, the packet must have been received through a sub-optimal interface. However, this interface still receives and forwards the multicast traffic downstream.

If a multicast data packet fails the RPF check, the packet must have been received through a sub-optimal interface. However, this interface still receives and forwards the multicast traffic downstream.

IGMP snooping cannot control the scope of multicast traffic flooding on a Layer 2 network.

IGMP snooping cannot control the scope of multicast traffic flooding on a Layer 2 network.

The source address of a multicast packet is a unicast address.

The source address of a multicast packet is a unicast address.

In multicast transmission, the destination address of a packet can be the unicast address of a host.

In multicast transmission, the destination address of a packet can be the unicast address of a host.

Suggested answer: C
Explanation:

A stateful inspection firewall tracks the state of network connections and only matches the initial packet against its rule set. Subsequent packets in the same connection are matched in the state table. Contrary to this, UDP packets can be inspected by correlating them with connection states, and packets in a single connection are always correlated .

asked 02/12/2024
Donald VIRMOND
36 questions

Question 103

Report Export Collapse

Which of the following statements regarding the stateful inspection firewall is true?

When the stateful inspection firewall checks packets, packets of one same connection are not correlated.

When the stateful inspection firewall checks packets, packets of one same connection are not correlated.

Because UDP is a connectionless protocol, so the stateful inspection firewall cannot match UDP packets with the status table.

Because UDP is a connectionless protocol, so the stateful inspection firewall cannot match UDP packets with the status table.

The stateful inspection firewall only needs to match the first data packet against a rule, and the subsequent packets of the connection are matched directly in the state table.

The stateful inspection firewall only needs to match the first data packet against a rule, and the subsequent packets of the connection are matched directly in the state table.

The stateful inspection firewall needs to match the rules for each incoming packet.

The stateful inspection firewall needs to match the rules for each incoming packet.

Suggested answer: C
Explanation:

A stateful inspection firewall tracks the state of network connections and only matches the initial packet against its rule set. Subsequent packets in the same connection are matched in the state table. Contrary to this, UDP packets can be inspected by correlating them with connection states, and packets in a single connection are always correlated .

asked 02/12/2024
patricia rosales
37 questions

Question 104

Report Export Collapse

Fill in the blanks

Compress the 2001:0DBB:B8:0000:C030:0000:0000:09A0:CDEF address.___________(if the answer contains letters, capitalize them.)

2001:DBB:B8:0:C030::9A0:CDEF

2001:DBB:B8:0:C030::9A0:CDEF

Suggested answer: A
Explanation:

The IPv6 address 2001:0DBB:B8:0000:C030:0000:0000:09A0:CDEF can be compressed by removing leading zeros in each segment and collapsing consecutive zero groups into ::. The result is 2001:DBB:B8:0:C030::9A0:CDEF .

asked 02/12/2024
Jonathan Marboux
38 questions

Question 105

Report Export Collapse

Fill in the blanks

A Huawei firewall by default creates security zones named untrust, dmz, _________ and local. (Use Lowercase letters.)

TRUST

TRUST

Suggested answer: A
Explanation:

By default, Huawei firewalls create security zones named untrust, dmz, trust, and local. These zones facilitate security policies for inbound, outbound, and inter-zone traffic control .

asked 02/12/2024
Aleph Ventures
36 questions

Question 106

Report Export Collapse

Which of the following attacks is not the network layer attack?

IP spoofing attack

IP spoofing attack

ICMP attack

ICMP attack

Smurf attack

Smurf attack

ARP spoofing attack

ARP spoofing attack

Suggested answer: D
Explanation:

ARP spoofing is a Layer 2 attack, as it targets ARP tables in switches or end devices. All other attacks, including IP spoofing, ICMP attacks, and Smurf attacks, are network layer (Layer 3) attacks .

asked 02/12/2024
frederic dohen
40 questions

Question 107

Report Export Collapse

Which of the following statements regarding the firewall zone security level is false?

The configured security level cannot be changed.

The configured security level cannot be changed.

Two zones cannot be configured with the same security level.

Two zones cannot be configured with the same security level.

The default security level of the new zone is 1.

The default security level of the new zone is 1.

Only the security level of the user-defined zone can be configured.

Only the security level of the user-defined zone can be configured.

Suggested answer: A
Explanation:

In Huawei firewalls, the security level of a zone can be reconfigured by an administrator, making the statement that it cannot be changed false. Other statements accurately describe security level restrictions or defaults .

asked 02/12/2024
ajay jaiswal
41 questions

Question 108

Report Export Collapse

ON a stateful inspection Firewall where there is no session table, when the status detection mechanism is enabled and the second packet (CYN+ACK) of 3-way hadshakes reaches the firewall. Which of the following statements is true?

If the firewall security policy permits packets to pass, the session table is created.

If the firewall security policy permits packets to pass, the session table is created.

By default, when status detection is disabled and the permit policy is configured packets can pass.

By default, when status detection is disabled and the permit policy is configured packets can pass.

Packets must pass the firewall, and a session table is established.

Packets must pass the firewall, and a session table is established.

If the firewall security policy permits packets to pass, the packets can pass the firewall.

If the firewall security policy permits packets to pass, the packets can pass the firewall.

Suggested answer: D
Explanation:

In a stateful inspection firewall, if the status detection mechanism is enabled, it tracks and validates the state of connections using the session table. If there is no session table and a SYN+ACK packet reaches the firewall, it checks the security policy. If the policy explicitly permits the packet, it will pass through the firewall, but no session table will be created without the initial SYN packet. The other options are either incorrect or misrepresent the behavior of stateful inspection .

asked 02/12/2024
Sharankumar Nadarajah
41 questions

Question 109

Report Export Collapse

Which of the following configurations are not mandatory when an administrator configures VRRP?

Become a Premium Member for full access
  Unlock Premium Member

Question 110

Report Export Collapse

DRAG DROP

Drag the following VRRP states to the corresponding working mechanisms.


Become a Premium Member for full access
  Unlock Premium Member
Total 219 questions
Go to page: of 22

Related questions