Font size
Worksheetstesting4
Total questions: 60
Worksheet time: 30mins
When firewalls are deployed in hot standby mode, which of the following protocols is used to switch the status of the entire VRRP group?
IGMP
VRRP
ICMP
VGMP
Which of the following statements is correct about the function of lateral movement in network penetration?
After accessing the target system, the attacker cannot perform lateral movement without privileges.
Lateral movement is to penetrate other devices that may have vulnerabilities through controlled hosts or servers.
An attacker obtains target network details through scanning and monitoring.
Communicate with the customer to understand the penetration test targets and IP addresses.
Which of the following is a private IP address?
172.20.2.1
192.1.1.1
172.32.1.1
192.200.1.1
Which of the following statements is correct about the characteristics of a DDoS attack?
The attack behavior can prevent the target system from processing the requests of authorized users.
An attacker intrudes into the target system through a backdoor program.
If the target system has no vulnerability, the remote attack cannot succeed.
The purpose of such an attack is to steal confidential information from the target system.
Network penetration simulates hackers' intrusion behaviors and thought patterns to perform non-destructive security tests on customer systems. Which of the following is the correct sequence of the network penetration process?
Confirm the target → Collect information → Implement penetration → Perform lateral movement → Clear traces → Elevate privileges
Confirm the target → Collect information → Implement penetration → Elevate privileges → Clear traces → Perform lateral movement
Confirm the target → Collect information → Implement penetration → Perform lateral movement → Elevate privileges → Clear traces
Collect information → Confirm the target → Implement penetration → Perform lateral movement → Elevate privileges → Clear traces
Which of the following statements is incorrect about TTL in IP packets?
The TTL value decrements by 1 every time a packet is forwarded to a Layer 3 node.
TTL is the maximum number of hops that an IP packet can be forwarded on a computer network.
The main function of TTL is to prevent IP packets from being circulated over a network infinitely, thereby saving network resources.
The TTL value of a packet ranges from 0 to 4095.
In tunnel mode of IPsec, to authenticate a new IP header, which of the following IPsec protocols needs to be used?
MD5
SHA1
AH
ESP
Which of the following attacks is not a network-layer attack?
IP sweep
IP spoofing attack
Smurf attack
Port scanning
Which statement is correct about a firewall’s interzone security policies?
Matched sequentially from the one with the smallest ID
Matched sequentially from the top down
Matched sequentially from the one with the largest ID
Automatically sorted by ID and IDs change with position
Which of the following statements is incorrect about the RADIUS protocol?
It supports authorization of configuration commands
By default, UDP is used with ports 1812 and 1813 or 1645 and 1646
Authentication and authorization are processed together
It encrypts only the password field in an authentication packet
Huawei Redundancy Protocol (HRP) synchronizes data from an active firewall to a standby firewall. Which data is beyond the synchronization scope?
Security policies
NAT policies
Session states
Routing information
Which messages provide error information and IP packet processing information for source hosts?
UDP datagram headers
IGMP control messages
TCP segment flags
ICMP control messages
During TCP communication, if packet loss occurs between two hosts, how is reliability ensured?
A sliding window is used between the two hosts
Host B sends ICMP packets to notify host A
Host B uses ACKs to request retransmission
TCP Options field guarantees end-host reliability
Which part is not included in a standard digital certificate?
Name of the certificate holder
Certificate public key
Certificate validity period
Certificate private key
To configure a USG firewall through the console port using PuTTY, which serial settings should be used?
4800 bps, 8 data bits, 1 stop bit, odd parity, no flow control
9600 bps, 8 data bits, 1 stop bit, even parity, hardware flow control
9600 bps, 8 data bits, 1 stop bit, no parity, no flow control
19200 bps, 8 data bits, 1 stop bit, no parity, no flow control
On a USG firewall, which of the following commands is used to view current session entries?
display firewall statistic
display firewall fib session
display firewall routing table
display firewall session table
Which of the following values is the default security level of the Trust zone on a Huawei USG firewall?
85
100
5
50
Which of the following statements is correct about firewall security zones?
An interface on a firewall can belong to multiple security zones
Different interfaces on a firewall can belong to the same security zone
Different security zones can have the same security level
The default security zones cannot be deleted from a firewall
Which of the following steps is optional for configuring intrusion prevention?
Creating an IPS profile
Configuring a signature filter
Configuring signature exceptions
Referencing an IPS profile in a security policy
Which of the following values is the default port number of the SSH protocol?
22
21
23
20
The digital certification technology addresses the problem from the digital signature technology that the owner of a public key cannot be determined. Which of the following are types of digital certificates?
Local device certificate
Local certificate
CA certificate
Self-signed certificate
Which ports are the default RADIUS authentication and accounting ports?
1812 and 1813
1813 and 1815
1811 and 1814
1810 and 1812
An administrator enabled Telnet on a firewall, but a user still cannot connect remotely. Which cause is most likely?
Telnet user level misconfigured
Too many online Telnet users
User typed an incorrect password
Network path to firewall unreachable
Which methods can implement an SSL VPN web proxy?
Reverse proxy automatic tunneling
Web forwarding only
Web transparent transmission only
Web link and web rewriting
Which components are part of a PKI system?
NTP masters and clients
DNS and DHCP servers
End entities and CAs
SNMP agents and traps
In IPsec, which security functions are provided by AH?
Integrity verification and anti-replay
Key exchange and encryption
Data confidentiality only
Data origin authentication only
Which algorithms are symmetric encryption algorithms?
Diffie–Hellman and ElGamal
RSA and ECC
MD5 and SHA1
DES and 3DES
Which of the following are common network topologies?
Bus topology
Tree topology
Star topology
Ring topology
Which statements correctly describe decapsulation of data packets in the TCP/IP stack?
Network layer removes its header and identifies upper-layer protocol
Data link layer checks CRC and removes frame header
Physical layer receives frames and calculates CRC
Transport layer removes its header and identifies upper-layer protocol
Which VPNs are suitable for employees on business trips to access an intranet from the public network?
L2TP over IPsec
GRE VPN
L2TP VPN
SSL VPN
Which principles must be followed when configuring firewall security zone levels?
Default level of a new zone is 100
Level cannot be changed once configured
Two zones in the same system cannot share the same level
Levels can be set only for user-defined zones
Users are network access subjects and basic units for firewall control and permission assignment. Which are involved in the user organizational structure?
Authentication domain
User group
Security group
Location group
Which TCP ports are used by FTP service by default?
23
20
21
22
Which backup modes are supported by the HRP mechanism?
Quick backup
Scheduled backup
Real-time backup
Batch backup
Which of the following can be used to implement AAA on Huawei devices?
RADIUS
AD
HWTACACS
LDAP
Which of the following VPNs are Layer 3 VPNs?
GRE VPN
L2TP VPN
SSL VPN
IPsec VPN
Which of the following protocol technologies are used when firewalls are deployed in hot standby mode?
IGMP
VGMP
VRRP
HRP
Which of the following authentication modes are available for Internet access users?
User-defined Portal authentication
User authentication exemption
Built-in Portal authentication
SSO
Which of the following parameters comprise an IPsec SA?
Security protocol number
Destination IP address
Source IP address
SPI
A session-based stateful inspection firewall processes the first packet and subsequent packets differently. Which of the following statements are correct?
When stateful inspection is enabled, subsequent packets also need to be checked based on security policies.
When stateful inspection is enabled and the firewall processes TCP packets, a session can be established only for SYN packets.
When receiving a packet, the firewall searches for a matching entry in the session table. If a matching entry is found, the firewall processes the packet as a subsequent packet.
When receiving a packet, the firewall searches for a matching entry in the session table. If no match is found, the firewall processes the packet as the first packet.
The web redirection password authentication function of a USG firewall enables a user to access services without being proactively authenticated, and the device pushes the authentication page to the user.
True
False
In an IP sweep attack, an attacker sends ICMP packets to probe the IP addresses of the target network and obtain the topology of the target network and active devices. Choose the correct option.
True
False
When a USG firewall serves as an out-of-path detection device, the detection interface must be configured as a Layer 3 interface. Choose the correct option.
True
False
The intrusion prevention function of a firewall detects and terminates intrusions such as buffer overflow attacks, Trojan horses, and worms in real time to protect enterprise information systems and network architectures. Choose the correct option.
True
False
During the ARP process, ARP reply packets are sent in broadcast mode so all hosts on the same Layer 2 network can receive them and learn the mapping between IP and MAC addresses. Choose the correct option.
True
False
When the stateful inspection function is disabled, the firewall creates a session for subsequent packets. Choose the correct option.
True
False
If the IKE negotiation mode of an IPsec VPN is the main mode, the ID type must be an IP address. Choose the correct option.
False
True
With a large number of network users, large enterprises usually use a hierarchical structure to support network expansion and the growing number of users. Choose the correct option.
True
False
The heartbeat link is a channel through which two firewalls exchange messages to learn each other's status and back up configuration commands and entries; the MGMT interface can be used as the heartbeat interface. Choose the correct option.
True
False
SSL is a security protocol that provides secure connections for TCP-based application layer protocols such as HTTP. Choose the correct option.
False
True
FTP is used for long-distance file transfer between two hosts and can ensure the reliability and confidentiality of data transmission.
False
True
Huawei Redundancy Protocol (HRP) is used to synchronize information such as key configurations, connection status, routing tables, and interface addresses between the active and standby firewalls.
True
False
On the CLI, users can view the running status and statistics in the user view, but not in the system view.
True
False
After receiving a packet, the LNS checks whether the TCP destination port number is 1701. If so, the LNS sends the packet to the L2TP processing module for further processing. If not, the LNS processes the packet as a normal IP packet.
True
False
A USG firewall is usually deployed between the external network and the network to be protected. It generates threat logs when detecting viruses, intrusions, botnets, Trojan horses, or worms.
False
True
A network device searches the routing table according to the destination IP address field in the IP packet header, and then forwards the data based on the search result.
False
True
IKEv1 negotiation phase 1 aims to establish an IKE SA, and supports two negotiation modes: main mode and aggressive mode.
True
False
The persistent connection function of the firewall allows you to set a long aging time for specific TCP and UDP data flows, ensuring that the session information does not age out for a long time.
False
True
NAT in Easy IP mode translates only private IP addresses. It cannot translate port numbers.
False
True
Proactive preemption is a process in which the active firewall takes over services when it recovers from a fault. Proactive preemption is enabled by default.
True
False
