wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

testing4

Total questions: 60

Worksheet time: 30mins

Name
Class
Date
1.

When firewalls are deployed in hot standby mode, which of the following protocols is used to switch the status of the entire VRRP group?

a)

IGMP

b)

VRRP

c)

ICMP

d)

VGMP

2.

Which of the following statements is correct about the function of lateral movement in network penetration?

a)

After accessing the target system, the attacker cannot perform lateral movement without privileges.

b)

Lateral movement is to penetrate other devices that may have vulnerabilities through controlled hosts or servers.

c)

An attacker obtains target network details through scanning and monitoring.

d)

Communicate with the customer to understand the penetration test targets and IP addresses.

3.

Which of the following is a private IP address?

a)

172.20.2.1

b)

192.1.1.1

c)

172.32.1.1

d)

192.200.1.1

4.

Which of the following statements is correct about the characteristics of a DDoS attack?

a)

The attack behavior can prevent the target system from processing the requests of authorized users.

b)

An attacker intrudes into the target system through a backdoor program.

c)

If the target system has no vulnerability, the remote attack cannot succeed.

d)

The purpose of such an attack is to steal confidential information from the target system.

5.

Network penetration simulates hackers' intrusion behaviors and thought patterns to perform non-destructive security tests on customer systems. Which of the following is the correct sequence of the network penetration process?

a)

Confirm the target → Collect information → Implement penetration → Perform lateral movement → Clear traces → Elevate privileges

b)

Confirm the target → Collect information → Implement penetration → Elevate privileges → Clear traces → Perform lateral movement

c)

Confirm the target → Collect information → Implement penetration → Perform lateral movement → Elevate privileges → Clear traces

d)

Collect information → Confirm the target → Implement penetration → Perform lateral movement → Elevate privileges → Clear traces

6.

Which of the following statements is incorrect about TTL in IP packets?

a)

The TTL value decrements by 1 every time a packet is forwarded to a Layer 3 node.

b)

TTL is the maximum number of hops that an IP packet can be forwarded on a computer network.

c)

The main function of TTL is to prevent IP packets from being circulated over a network infinitely, thereby saving network resources.

d)

The TTL value of a packet ranges from 0 to 4095.

7.

In tunnel mode of IPsec, to authenticate a new IP header, which of the following IPsec protocols needs to be used?

a)

MD5

b)

SHA1

c)

AH

d)

ESP

8.

Which of the following attacks is not a network-layer attack?

a)

IP sweep

b)

IP spoofing attack

c)

Smurf attack

d)

Port scanning

9.

Which statement is correct about a firewall’s interzone security policies?

a)

Matched sequentially from the one with the smallest ID

b)

Matched sequentially from the top down

c)

Matched sequentially from the one with the largest ID

d)

Automatically sorted by ID and IDs change with position

10.

Which of the following statements is incorrect about the RADIUS protocol?

a)

It supports authorization of configuration commands

b)

By default, UDP is used with ports 1812 and 1813 or 1645 and 1646

c)

Authentication and authorization are processed together

d)

It encrypts only the password field in an authentication packet

11.

Huawei Redundancy Protocol (HRP) synchronizes data from an active firewall to a standby firewall. Which data is beyond the synchronization scope?

a)

Security policies

b)

NAT policies

c)

Session states

d)

Routing information

12.

Which messages provide error information and IP packet processing information for source hosts?

a)

UDP datagram headers

b)

IGMP control messages

c)

TCP segment flags

d)

ICMP control messages

13.

During TCP communication, if packet loss occurs between two hosts, how is reliability ensured?

a)

A sliding window is used between the two hosts

b)

Host B sends ICMP packets to notify host A

c)

Host B uses ACKs to request retransmission

d)

TCP Options field guarantees end-host reliability

14.

Which part is not included in a standard digital certificate?

a)

Name of the certificate holder

b)

Certificate public key

c)

Certificate validity period

d)

Certificate private key

15.

To configure a USG firewall through the console port using PuTTY, which serial settings should be used?

a)

4800 bps, 8 data bits, 1 stop bit, odd parity, no flow control

b)

9600 bps, 8 data bits, 1 stop bit, even parity, hardware flow control

c)

9600 bps, 8 data bits, 1 stop bit, no parity, no flow control

d)

19200 bps, 8 data bits, 1 stop bit, no parity, no flow control

16.

On a USG firewall, which of the following commands is used to view current session entries?

a)

display firewall statistic

b)

display firewall fib session

c)

display firewall routing table

d)

display firewall session table

17.

Which of the following values is the default security level of the Trust zone on a Huawei USG firewall?

a)

85

b)

100

c)

5

d)

50

18.

Which of the following statements is correct about firewall security zones?

a)

An interface on a firewall can belong to multiple security zones

b)

Different interfaces on a firewall can belong to the same security zone

c)

Different security zones can have the same security level

d)

The default security zones cannot be deleted from a firewall

19.

Which of the following steps is optional for configuring intrusion prevention?

a)

Creating an IPS profile

b)

Configuring a signature filter

c)

Configuring signature exceptions

d)

Referencing an IPS profile in a security policy

20.

Which of the following values is the default port number of the SSH protocol?

a)

22

b)

21

c)

23

d)

20

21.

The digital certification technology addresses the problem from the digital signature technology that the owner of a public key cannot be determined. Which of the following are types of digital certificates?

a)

Local device certificate

b)

Local certificate

c)

CA certificate

d)

Self-signed certificate

22.

Which ports are the default RADIUS authentication and accounting ports?

a)

1812 and 1813

b)

1813 and 1815

c)

1811 and 1814

d)

1810 and 1812

23.

An administrator enabled Telnet on a firewall, but a user still cannot connect remotely. Which cause is most likely?

a)

Telnet user level misconfigured

b)

Too many online Telnet users

c)

User typed an incorrect password

d)

Network path to firewall unreachable

24.

Which methods can implement an SSL VPN web proxy?

a)

Reverse proxy automatic tunneling

b)

Web forwarding only

c)

Web transparent transmission only

d)

Web link and web rewriting

25.

Which components are part of a PKI system?

a)

NTP masters and clients

b)

DNS and DHCP servers

c)

End entities and CAs

d)

SNMP agents and traps

26.

In IPsec, which security functions are provided by AH?

a)

Integrity verification and anti-replay

b)

Key exchange and encryption

c)

Data confidentiality only

d)

Data origin authentication only

27.

Which algorithms are symmetric encryption algorithms?

a)

Diffie–Hellman and ElGamal

b)

RSA and ECC

c)

MD5 and SHA1

d)

DES and 3DES

28.

Which of the following are common network topologies?

a)

Bus topology

b)

Tree topology

c)

Star topology

d)

Ring topology

29.

Which statements correctly describe decapsulation of data packets in the TCP/IP stack?

a)

Network layer removes its header and identifies upper-layer protocol

b)

Data link layer checks CRC and removes frame header

c)

Physical layer receives frames and calculates CRC

d)

Transport layer removes its header and identifies upper-layer protocol

30.

Which VPNs are suitable for employees on business trips to access an intranet from the public network?

a)

L2TP over IPsec

b)

GRE VPN

c)

L2TP VPN

d)

SSL VPN

31.

Which principles must be followed when configuring firewall security zone levels?

a)

Default level of a new zone is 100

b)

Level cannot be changed once configured

c)

Two zones in the same system cannot share the same level

d)

Levels can be set only for user-defined zones

32.

Users are network access subjects and basic units for firewall control and permission assignment. Which are involved in the user organizational structure?

a)

Authentication domain

b)

User group

c)

Security group

d)

Location group

33.

Which TCP ports are used by FTP service by default?

a)

23

b)

20

c)

21

d)

22

34.

Which backup modes are supported by the HRP mechanism?

a)

Quick backup

b)

Scheduled backup

c)

Real-time backup

d)

Batch backup

35.

Which of the following can be used to implement AAA on Huawei devices?

a)

RADIUS

b)

AD

c)

HWTACACS

d)

LDAP

36.

Which of the following VPNs are Layer 3 VPNs?

a)

GRE VPN

b)

L2TP VPN

c)

SSL VPN

d)

IPsec VPN

37.

Which of the following protocol technologies are used when firewalls are deployed in hot standby mode?

a)

IGMP

b)

VGMP

c)

VRRP

d)

HRP

38.

Which of the following authentication modes are available for Internet access users?

a)

User-defined Portal authentication

b)

User authentication exemption

c)

Built-in Portal authentication

d)

SSO

39.

Which of the following parameters comprise an IPsec SA?

a)

Security protocol number

b)

Destination IP address

c)

Source IP address

d)

SPI

40.

A session-based stateful inspection firewall processes the first packet and subsequent packets differently. Which of the following statements are correct?

a)

When stateful inspection is enabled, subsequent packets also need to be checked based on security policies.

b)

When stateful inspection is enabled and the firewall processes TCP packets, a session can be established only for SYN packets.

c)

When receiving a packet, the firewall searches for a matching entry in the session table. If a matching entry is found, the firewall processes the packet as a subsequent packet.

d)

When receiving a packet, the firewall searches for a matching entry in the session table. If no match is found, the firewall processes the packet as the first packet.

41.

The web redirection password authentication function of a USG firewall enables a user to access services without being proactively authenticated, and the device pushes the authentication page to the user.

a)

True

b)

False

42.

In an IP sweep attack, an attacker sends ICMP packets to probe the IP addresses of the target network and obtain the topology of the target network and active devices. Choose the correct option.

a)

True

b)

False

43.

When a USG firewall serves as an out-of-path detection device, the detection interface must be configured as a Layer 3 interface. Choose the correct option.

a)

True

b)

False

44.

The intrusion prevention function of a firewall detects and terminates intrusions such as buffer overflow attacks, Trojan horses, and worms in real time to protect enterprise information systems and network architectures. Choose the correct option.

a)

True

b)

False

45.

During the ARP process, ARP reply packets are sent in broadcast mode so all hosts on the same Layer 2 network can receive them and learn the mapping between IP and MAC addresses. Choose the correct option.

a)

True

b)

False

46.

When the stateful inspection function is disabled, the firewall creates a session for subsequent packets. Choose the correct option.

a)

True

b)

False

47.

If the IKE negotiation mode of an IPsec VPN is the main mode, the ID type must be an IP address. Choose the correct option.

a)

False

b)

True

48.

With a large number of network users, large enterprises usually use a hierarchical structure to support network expansion and the growing number of users. Choose the correct option.

a)

True

b)

False

49.

The heartbeat link is a channel through which two firewalls exchange messages to learn each other's status and back up configuration commands and entries; the MGMT interface can be used as the heartbeat interface. Choose the correct option.

a)

True

b)

False

50.

SSL is a security protocol that provides secure connections for TCP-based application layer protocols such as HTTP. Choose the correct option.

a)

False

b)

True

51.

FTP is used for long-distance file transfer between two hosts and can ensure the reliability and confidentiality of data transmission.

a)

False

b)

True

52.

Huawei Redundancy Protocol (HRP) is used to synchronize information such as key configurations, connection status, routing tables, and interface addresses between the active and standby firewalls.

a)

True

b)

False

53.

On the CLI, users can view the running status and statistics in the user view, but not in the system view.

a)

True

b)

False

54.

After receiving a packet, the LNS checks whether the TCP destination port number is 1701. If so, the LNS sends the packet to the L2TP processing module for further processing. If not, the LNS processes the packet as a normal IP packet.

a)

True

b)

False

55.

A USG firewall is usually deployed between the external network and the network to be protected. It generates threat logs when detecting viruses, intrusions, botnets, Trojan horses, or worms.

a)

False

b)

True

56.

A network device searches the routing table according to the destination IP address field in the IP packet header, and then forwards the data based on the search result.

a)

False

b)

True

57.

IKEv1 negotiation phase 1 aims to establish an IKE SA, and supports two negotiation modes: main mode and aggressive mode.

a)

True

b)

False

58.

The persistent connection function of the firewall allows you to set a long aging time for specific TCP and UDP data flows, ensuring that the session information does not age out for a long time.

a)

False

b)

True

59.

NAT in Easy IP mode translates only private IP addresses. It cannot translate port numbers.

a)

False

b)

True

60.

Proactive preemption is a process in which the active firewall takes over services when it recovers from a fault. Proactive preemption is enabled by default.

a)

True

b)

False