Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Testing44

Total questions: 60

Worksheet time: 30mins

Name
Class
Date
1.

When firewalls are deployed in hot standby mode, which of the following protocols is used to switch the status of the entire VRRP group?

a)

VRRP

b)

VGMP

c)

ICMP

d)

IGMP

2.

Which of the following statements is correct about the function of lateral movement in network penetration?

a)

An attacker obtains the IP address, domain name, active port, and communication information of the target network through scanning and network monitoring to lay a foundation for subsequent attacks.

b)

After accessing the target system, the attacker cannot perform lateral movement due to a lack of privileges. Therefore, the attacker may try to elevate privileges.

c)

Lateral movement is to penetrate other devices that may have vulnerabilities on the network through controlled hosts or servers.

d)

Communicate with the customer to understand the target of the penetration test, such as the system, server, and IP address.

3.

Which of the following is a private IP address?

a)

192.200.1.1

b)

172.32.1.1

c)

192.1.1.1

d)

172.20.2.1

4.

Which of the following statements is correct about the characteristics of a DDoS attack?

a)

An attacker intrudes into the target system through a backdoor program.

b)

The purpose of such an attack is to steal confidential information from the target system.

c)

The attack behavior can prevent the target system from processing the requests of authorized users.

d)

If the target system has no vulnerability, the remote attack cannot succeed.

5.

Network penetration simulates hackers’ intrusion behaviors and thought patterns to perform non-destructive security tests on customer systems. Which of the following is the correct sequence of the network penetration process?

a)

Confirm the target → Collect information → Implement penetration → Perform lateral movement → Elevate privileges → Clear traces

b)

Collect information → Confirm the target → Implement penetration → Perform lateral movement → Elevate privileges → Clear traces

c)

Confirm the target → Collect information → Perform lateral movement → Implement penetration → Elevate privileges → Clear traces

d)

Confirm the target → Implement penetration → Collect information → Perform lateral movement → Elevate privileges → Clear traces

6.

Which of the following statements is incorrect about TTL in IP packets?

a)

TTL is the maximum number of hops that an IP packet can be forwarded on a computer network.

b)

The main function of TTL is to prevent IP packets from being circulated over a network infinitely, thereby saving network resources.

c)

The TTL value decrements by 1 every time a packet is forwarded to a Layer 3 node.

d)

The TTL value of a packet ranges from 0 to 4095.

7.

In tunnel mode of IPsec, to authenticate a new IP header, which of the following IPsec protocols needs to be used?

a)

MD5

b)

SHA1

c)

ESP

d)

AH

8.

Which of the following attacks is not a network-layer attack?

a)

Smurf attack

b)

IP sweep

c)

IP spoofing attack

d)

Port scanning

9.

Which of the following statements is correct about a firewall’s interzone security policies?

a)

Interzone security policies are matched sequentially from the one with the smallest ID.

b)

Interzone security policies are matched sequentially from the top down.

c)

Interzone security policies are matched sequentially from the one with the largest ID.

d)

Interzone security policies are automatically sorted by ID. If the position of a policy changes, the ID of the policy changes accordingly.

10.

Which of the following statements is incorrect about the RADIUS protocol?

a)

By default, UDP is used, and the authentication and authorization port numbers are 1812 and 1813 or 1645 and 1646, respectively.

b)

It encrypts only the password field in an authentication packet.

c)

Authentication and authorization are processed together.

d)

It supports authorization of configuration commands.

11.

Hot Standby Redundancy Protocol (HRP) is used to synchronize data such as the key configurations and connection status of the active firewall to the standby firewall. Which of the following data is beyond the synchronization scope?

a)

Routing rules

b)

Security policies

c)

SSL policies

d)

NAT policies

12.

Which of the following messages can provide error information and IP packet processing information for source ends?

a)

IGMP

b)

TCP

c)

UDP

d)

ICMP

13.

If packet loss occurs when hosts A and B communicate with each other through TCP, how does TCP ensure reliability?

a)

Host B sends ICMP packets to host A to notify data loss.

b)

The sliding window mechanism is used between the two hosts to ensure reliability.

c)

Host B uses the ACK field to instruct host A to retransmit packets.

d)

The Option field in TCP packets is used to ensure reliability of host A and host B.

14.

Which one of the following parts is not included in a digital certificate?

a)

Name of the certificate holder

b)

Certificate validity period

c)

Certificate private key

d)

Certificate public key

15.

When an administrator wants to configure a USG series firewall through the console port, which of the following configurations should be made in the putty?

a)

4800 bps, 8 data bits, 1 stop bit, odd parity check, and no flow control

b)

9600 bps, 8 data bits, 1 stop bit, even parity check, and hardware-based flow control

c)

9600 bps, 8 data bits, 1 stop bit, no parity check, and no flow control

d)

19200 bps, 8 data bits, 1 stop bit, no parity check, and no flow control

16.

On a USG firewall, which of the following commands is used to view current session entries?

a)

display firewall statistic

b)

display firewall routing table

c)

display firewall session table

d)

display firewall fib session

17.

Which of the following values is the default security level of the Trust zone on a Huawei USG firewall?

a)

5

b)

50

c)

85

d)

100

18.

Which of the following statements is correct about firewall security zones?

a)

The default security zones cannot be deleted from a firewall.

b)

An interface on a firewall can belong to multiple security zones.

c)

Different interfaces on a firewall can belong to the same security zone.

d)

Different security zones can have the same security level.

19.

Which of the following steps is optional for configuring intrusion prevention?

a)

Creating an IPS profile

b)

Configuring a signature filter

c)

Configuring signature exceptions

d)

Referencing an IPS profile in a security policy

20.

Which of the following values is the default port number of the SSH protocol?

a)

20

b)

21

c)

22

d)

23

21.

The digital certificate technology addresses the problem from the digital signature technology that the owner of a public key cannot be determined. Which of the following are types of digital certificates?

a)

Self-signed certificate

b)

CA certificate

c)

Local certificate

d)

Local device certificate

22.

Which of the following ports are used as the default authentication and accounting ports of the RADIUS protocol?

a)

1811

b)

1812

c)

1813

d)

1814

23.

If the administrator has configured the Telnet service on the firewall but a user still cannot access the firewall remotely, which of the following are possible causes of the access failure?

a)

The network between the user and the firewall is unreachable.

b)

The user enters an incorrect password.

c)

The Telnet user level is incorrectly configured.

d)

The number of online Telnet users reaches the upper limit.

24.

Select all that apply: Which of the following methods can be used to implement the SSL VPN web proxy?

a)

Web link

b)

Web transparent transmission

c)

Web forwarding

d)

Web rewriting

25.

Select all that apply: Which of the following are components of a PKI system?

a)

End entity

b)

Certificate authority

c)

Certificate registration authority

d)

Certificate/CRL database

26.

Select all that apply: Which of the following security functions can be provided by the AH protocol in IPsec?

a)

Data origin authentication

b)

Data confidentiality

c)

Data integrity verification

d)

Anti-replay

27.

Select all that apply: Which of the following algorithms are symmetric encryption algorithms?

a)

DES

b)

3DES

c)

MD5

d)

SHA1

28.

Select all that apply: Which of the following are common network topologies?

a)

Bus topology

b)

Tree topology

c)

Star topology

d)

Ring topology

29.

Select all that apply: Which of the following statements are correct about the decapsulation of data packets in the TCP/IP protocol stack?

a)

The physical network layer receives frames, calculates the CRC of the frames, and then sends the frames to the data link layer.

b)

The data link layer checks whether the CRC of the frames is correct, deletes the frame header and CRC, and then sends the frames to the network layer.

c)

After the network layer receives and parses data packets, network layer information is removed, and the upper-layer protocol is obtained based on the parsing result.

d)

After the transport layer (TCP) receives and parses data packets, transport layer information is removed, and the upper-layer protocol is obtained based on the parsing result.

30.

Select all that apply: Which of the following VPNs are suitable for employees on business trips to access the enterprise intranet from the public network?

a)

L2TP VPN

b)

GRE VPN

c)

L2TP over IPsec

d)

SSL VPN

31.

Select all that apply: Which of the following principles must be adhered to when you configure the security levels of the firewall security zones?

a)

The security level cannot be changed once it is configured.

b)

Two security zones in the same system cannot be configured with the same security level.

c)

The default security level of a new security zone is 100.

d)

Security levels can be set only for user-defined security zones.

32.

Select all that apply: Users are network access subjects and basic units for network behavior control and network permission assignment by firewalls. Which of the following are involved in the user organizational structure?

a)

Authentication domain

b)

User group/user

c)

Security group

d)

Isolation group

33.

Select all that apply: Which of the following TCP ports are used by the FTP service by default?

a)

20

b)

21

c)

22

d)

23

34.

Select all that apply: Which of the following backup modes are supported by the HRP mechanism?

a)

Scheduled backup

b)

Real-time backup

c)

Batch backup

d)

Quick backup

35.

Which of the following can be used to implement AAA on Huawei devices?

a)

RADIUS

b)

HWTACACS

c)

LDAP

d)

AD

36.

Which of the following VPNs are Layer 3 VPNs?

a)

L2TP VPN

b)

GRE VPN

c)

IPsec VPN

d)

SSL VPN

37.

Which of the following protocol technologies are used when firewalls are deployed in hot standby mode?

a)

VRRP

b)

IGMP

c)

VGMP

d)

HRP

38.

Which of the following authentication modes are available for Internet access users?

a)

SSO

b)

Built-in Portal authentication

c)

User-defined Portal authentication

d)

User authentication exemption

39.

Which of the following parameters comprise an IPsec SA?

a)

SPI

b)

Source IP address

c)

Destination IP address

d)

Security protocol number

40.

A session-based stateful inspection firewall processes the first packet and subsequent packets differently. Which of the following statements are correct?

a)

When receiving a packet, the firewall searches for a matching entry in the session table. If no match is found, the firewall processes the packet as the first packet.

b)

When receiving a packet, the firewall searches for a matching entry in the session table. If a matching entry is found, the firewall processes the packet as a subsequent packet.

c)

When stateful inspection is enabled, subsequent packets also need to be checked based on security policies.

d)

When stateful inspection is enabled and the firewall processes TCP packets, a session can be established only for SYN packets.

41.

The web redirection password authentication function of a USG firewall enables a user to access services without being proactively authenticated, and the device pushes the authentication page to the user.

a)

True

b)

False

42.

In an IP sweep attack, an attacker sends ICMP packets to probe the IP address of the target network and obtain the topology of the target network and active devices.

a)

True

b)

False

43.

When a USG firewall serves as an out-of-path detection device, you need to configure the detection interface as a Layer 3 interface.

a)

True

b)

False

44.

The intrusion prevention function of the firewall detects and terminates intrusions (such as buffer overflow attacks, Trojan horses, and worms) in real time to protect enterprises' information systems and network architectures.

a)

True

b)

False

45.

During the ARP process, ARP reply packets are sent in broadcast mode. All hosts on the same Layer 2 network can receive these packets and learn the mapping between IP and MAC addresses.

a)

True

b)

False

46.

When the stateful inspection function is disabled, the firewall creates a session for subsequent packets.

a)

True

b)

False

47.

If the IKE negotiation mode of the IPsec VPN is the main mode, the ID type must be an IP address.

a)

True

b)

False

48.

True or False: With a large number of network users, large enterprises usually use a hierarchical structure to support network expansion and growing number of users.

a)

True

b)

False

49.

True or False: The heartbeat link is a channel through which two firewalls exchange messages to learn about each other’s status and back up configuration commands and entries. The MGMT interface can be used as the heartbeat interface.

a)

True

b)

False

50.

True or False: SSL is a security protocol that provides secure connections for TCP-based application layer protocols like HTTP.

a)

True

b)

False

51.

True or False: FTP is used for long-distance file transfer between two hosts and can ensure the reliability and confidentiality of data transmission.

a)

True

b)

False

52.

True or False: Huawei Redundancy Protocol (HRP) is used to synchronize information such as key configurations, connection status, routing tables, and interface addresses between the active and standby firewalls.

a)

True

b)

False

53.

True or False: On the CLI, users can view the running status and statistics in the user view, but not in the system view.

a)

True

b)

False

54.

True or False: After receiving a packet, the LNS checks whether the TCP destination port number is 1701. If so, the LNS sends the packet to the L2TP processing module for further processing. If not, the LNS processes the packet as a normal IP packet.

a)

True

b)

False

55.

True or False: A USG firewall is usually deployed between the external network and the network to be protected. It generates threat logs when detecting viruses, intrusions, botnets, Trojan horses, or worms.

a)

True

b)

False

56.

True or False: A network device searches the routing table according to the destination IP address field in the IP packet header, and then forwards the data based on the search result.

a)

True

b)

False

57.

True or False: IKEv1 negotiation phase 1 aims to establish an IKE SA, and supports two negotiation modes: main mode and aggressive mode.

a)

True

b)

False

58.

True or False: The persistent connection function of the firewall allows you to set a long aging time for specific TCP and UDP data flows, ensuring that the session information does not age out for a long time.

a)

True

b)

False

59.

True or False: NAT in Easy IP mode translates only private IP addresses. It cannot translate port numbers.

a)

True

b)

False

60.

True or False: Proactive preemption is a process in which the active firewall takes over services when it recovers from a fault. Proactive preemption is enabled by default.

a)

True

b)

False