Font size
WorksheetsHuawei Security
Total questions: 15
Worksheet time: 9mins
With a large number of network users, large enterprises usually use a hierarchical structure to support network expansion and growing number of users.
True
False
During the ARP process, ARP reply packets are sent in broadcast mode. All hosts on the same Layer 2 network can receive these packets and learn the mapping between IP and MAC addresses.
True
False
The persistent connection function of the firewall allows you to set a long aging time for specific TCP and UDP data flows, ensuring that the session information does not age out for a long time.
True
False
NAT in Easy IP mode translates only private IP addresses. It cannot translate port numbers.
True
False
When the stateful inspection function is disabled, the firewall creates a session for subsequent packets.
True
False
Which of the following values is the default security level of the Trust zone on a Huawei USG firewall?
5
50
85
100
Which of the following values is the default port number of the SSH protocol?
20
21
22
23
Which of the following is a private IP address?
192.200.1.1
172.32.1.1
192.1.1.1
172.20.2.1
Which of the following TCP ports are used by the FTP service by default?
20
23
22
21
A session-based stateful inspection firewall processes the first packet and subsequent packets differently. Which of the following statements are correct?
When receiving a packet, the firewall searches for a matching entry in the session table. If a matching entry is found, the firewall processes the packet as a subsequent packet.
When receiving a packet, the firewall searches for a matching entry in the session table. If no match is found, the firewall processes the packet as the first packet.
When stateful inspection is enabled, subsequent packets also need to be checked based on security policies.
When stateful inspection is enabled and the firewall processes TCP packets, a session can be established only for SYN packets.
Which of the following statements is correct about firewall security zones?
The default security zones cannot be deleted from a firewall.
An interface on a firewall can belong to multiple security zones.
Different security zones can have the same security level.
Different interfaces on a firewall can belong to the same security zone.
FTP is used for long-distance file transfer between two hosts and can ensure the reliability and confidentiality of data transmission.
True
False
On the CLI, users can view the running status and statistics in the user view, but not in the system view.
True
False
Which of the following principles must be adhered to when you configure the security levels of the firewall security zones
Two security zones in the same system cannot be configured with the same security level.
The security level cannot be changed once it is configured.
The default security level of a new security zone is 100
Security levels can be set only for user-defined security zones
On a USG firewall, which of the following commands is used to view current session entries
display firewall statistic
display firewall session table
display firewall routing table
display firewall fib session
