To all, the current version of Huawei HCIP-Security certification is V3.0. Candidates are required to pass three exams to complete the HCIP-Security V3.0 certification:

  • H12-721_V3.0-ENU HCIP-Security-CISN V3.0
  • H12-722_V3.0-ENU HCIP-Security-CSSN V3.0
  • H12-723_V3.0-ENU HCIP-Security-CTSS V3.0

To all, the current version of Huawei HCIP-Security certification is V3.0. Candidates are required to pass three exams to complete the HCIP-Security V3.0 certification.

1. Which of the following is not a parameter of intelligent routing link quality detection?

2. Session persistence refers to a mechanism on the load balancer that can identify the relevance of the interaction process between the client and the server. When creating a four-layer protocol listener, which of the following algorithms is selected for the allocation policy type, and the session retention time can be configured?

3. Huawei UMA unified operation and maintenance audit product can effectively reduce the internal operation and maintenance risks of network equipment, servers, databases, business systems and other resources by centrally managing, monitoring and auditing the operation behavior of all operation and maintenance personnel in the enterprise.
Which of the following descriptions about Huawei UMA products is wrong?

4. Which of the following is not an action type of policy routing?

5. By default, what is the interval for sending VGMP Hello packets?

6. The firewall provides a wealth of health check mechanisms, which can improve the quality of links and services, and improve the user experience.
Which of the following options can a health check probe for?

7. Which of the following supports multiple hotlink identification algorithms and can effectively solve information theft such as single-source hotlinking, distributed hotlinking, and malicious website data theft, so as to ensure that website resources can only be obtained through this site access?

8. Which of the following descriptions about HWTACACS protocol and RADIUS protocol is wrong?

9. How many messages need to be exchanged in the savage mode of IPSec VPN to complete the establishment of IKE SA?

10. Regarding the characteristics of the firewall's dual-system hot-standby synchronization data, which of the following options is incorrect?

11. Regarding the characteristics of digital certificates, which of the following descriptions is false?

12. Which of the following descriptions about the USG firewall bandwidth policy is wrong?

13. Which of the following BFD states indicates that it has been able to communicate with the peer system, and the local end wants the session to enter the Up state?

14. Which of the following descriptions about the output information of the USG firewall diversion table is wrong?
<FW> display firewall import-flow public
Import Flow Tables:
Source Instance Destination Address Destination Instance
public vsysa Total: 1

15. Regarding L2TP over IPSec VPN, which of the following statements is correct? (Multiple Choice)

16. One FW device can create multiple virtual gateways, and each virtual gateway has an independent administrator.

17. SSL VPN is basically not restricted by the access location, and can access network resources from many Internet access devices and any remote location.

18. The USG firewall bandwidth policy can match both traffic from source-zone to destination-zone and traffic from destination-zone to source-zone

19. The LAN address spaces under different virtual systems of the same firewall cannot overlap.

20. There are three L2TP authentication methods: proxy authentication, mandatory CHAP authentication and LCP renegotiation. Among them, LCP renegotiation has the lowest priority, and proxy authentication has the highest priority.

21. BFD supports asynchronous detection mode and synchronous detection mode.

22. The overload protection threshold can be configured for the intelligent route selection interface, which may cause the user's Internet traffic to select the interface link before the interface link is overloaded, and the newly established session traffic (such as opening a new web page) is because the original interface link is overloaded. However, it is forwarded from other interfaces by the firewall, so that the logged-in website needs to log in again after being refreshed.

23. The following output information indicates that the packet type of the health check is TCP.
[FW1] display slb group Group
Group Information (Total 1)
Group Name: slb
Group ID: 0
Metric: weight-roundrobin
Health Check Type: TCP
Virtual Server ID:0
Virtual Server VIP List:
Real Server Number: 1
RserverlD IP Address weight Status 32 status inactive

24. When GRE over IPSec is used to connect between gateways, the IPSec encapsulation mode can only be tunnel mode.

25. When configuring the time for the IP-Link group to send detection packets, the smaller the interval value is, the more the burden on the device CPU can be reduced, and the sensitivity of link detection is improved.

