Huawei H12-731-ENU Exam Syllabus Topics:
| Section | Weight | Objectives |
|---|---|---|
| Threat Defense & Intrusion Prevention | 20% | - IPS/IDS deployment and signature management - Vulnerability management and threat intelligence - DDoS defense, single-packet attack protection |
| Security Architecture & Standards | 20% | - Risk management and compliance requirements - Enterprise security architecture design principles - Information security standards and frameworks |
| Cloud & Data Security | 12% | - Data security, encryption, and leakage prevention - Virtual firewall and cloud security solutions |
| Firewall & Traffic Security Technologies | 25% | - Virtual systems and multi-tenant security - Advanced firewall features and high availability - NAT, bandwidth management, and security policies |
| VPN & Encryption Technologies | 15% | - PKI, certificate management, and encryption algorithms - IPsec VPN, SSL VPN, and GRE over IPsec - VPN high reliability and troubleshooting |
| Security O&M & Incident Response | 8% | - Incident response procedures and emergency handling - Security log analysis and monitoring |
Huawei HCIE-Security (Huawei Certified Internetwork Expert-Security) Sample Questions:
Question #1
For some large IP data packets, in order to meet the requirements of the MTU (Maximum Transmission Unit) of the link layer, it needs to be fragmented and divided into several IP packets during the transmission process. In each IP header there is an offset field and a split flag (MF), where the offset field indicates the location of the fragment in the entire IP packet. If the attacker sets the offset field to an incorrect value after intercepting the IP data packet, the receiver cannot correctly combine the values of the offset field in the data packet after receiving the split data packets. In this way, the receiver will keep trying, and the operating system will crash due to resource exhaustion.
What is this attack method?
A. TCP packet flag attack
B. WinNuke Attack
C. Teardrop Attack
D. Ip Fragmented Packet Attack
Question #2
When the Linux host passes through the tracert of the USG firewall for a certain destination IP address, it is found that * is displayed from the hop of the firewall, but the network is confirmed to be no problem. In order to make the firewall itself and the devices behind the firewall truly display the IP address , Which of the following must be configured on the firewall?
A. undo firewall defend tracert enable
B. Packet filtering policy that allows udp packets to be forwarded through the firewall
C. Packet filtering policy that allows icmp packets to be forwarded through the firewall
D. undo ip ttl-expires enable
Question #3
Intranet users can access the Internet normally, and dual links are used for master and backup backup.
For Internet users, the FTP server can be accessed through the public network address. Two public network addresses are announced, 200.1.1.200 and 202.1.1.200.
Which of the following configuration is correct?
A. USG] ip-link check enable [USG] ip-link 1 destination 200.1.1.2 interface GigabitEthernet 0/0/2 mode icmp [USG] ip route-static 0.0.0.0 0.0.0.0 200.1.1.2 track ip- link 1 [USG] ip route-static 0.0.0.0 0.0.0.0 200.1.1.2 preference 70
B. [USG] nat server s1 zone untrust1 protocol global 200.1.1.200 ftp inside 192.168.1.254 ftp [USG] nat server s2 zone untrust2 protocol global 202.1.1.200 ftp inside 192.168.1.254 ftp
C. [USG] nat server s1 protocol tcp global 200.1.1.200 ftp inside 192.168.1.254 ftp [USG] nat server s2 protocol tcp global 202.1.1.200 ftp inside 192.168.1.254 ftp
D. [USG] ip-link check enable [USG] ip-link 1 destination 202.1.1.2 interface GigabitEthernet 0/0/2 mode icmp [USG] ip route-static 0.0.0.0 0.0.0.0 200.1.1.2 [USG ] ip route-static 0.0.0.0 0.0.0.0 200.1.1.2 preference 70 track ip-link 1
Question #4
Which of the following statements is true about the life cycle of an IPsec tunnel:
A. The soft timeout is the expiration time of the SA life cycle, and the hard timeout is the time to start negotiating a new SA before the expiration of the life cycle.
B. The lifecycle configuration of both ends must be the same.
C. The IPsec tunnel will renegotiate a new tunnel when it reaches its lifetime.
D. IPsec SA lifetime can be calculated in traffic.
Question #5
Which fields in the packet need to be analyzed in the firewall's IP packet fragmentation and reassembly?
A. Flags
B. Identifier
C. Lifetime TTL
D. Fragment Offset
E. Total Length
Solutions:
| Question #1 Correct Answer: C | Question #2 Correct Answer: A,B | Question #3 Correct Answer: A,B | Question #4 Correct Answer: C,D | Question #5 Correct Answer: A,B,D |














989 Customer Reviews
Quality and ValueITCertKing Practice Exams are written to the highest standards of technical accuracy, using only certified subject matter experts and published authors for development - no all study materials.
Tested and ApprovedWe are committed to the process of vendor and third party approvals. We believe professionals and executives alike deserve the confidence of quality coverage these authorizations provide.
Easy to PassIf you prepare for the exams using our ITCertKing testing engine, It is easy to succeed for all certifications in the first attempt. You don't have to deal with all dumps or any free torrent / rapidshare all stuff.
Try Before BuyITCertKing offers free demo of each product. You can check out the interface, question quality and usability of our practice exams before you decide to buy.
