WorksheetsTesting44
Total questions: 60
Worksheet time: 30mins
When firewalls are deployed in hot standby mode, which of the following protocols is used to switch the status of the entire VRRP group?
VRRP
VGMP
ICMP
IGMP
Which of the following statements is correct about the function of lateral movement in network penetration?
An attacker obtains the IP address, domain name, active port, and communication information of the target network through scanning and network monitoring to lay a foundation for subsequent attacks.
After accessing the target system, the attacker cannot perform lateral movement due to a lack of privileges. Therefore, the attacker may try to elevate privileges.
Lateral movement is to penetrate other devices that may have vulnerabilities on the network through controlled hosts or servers.
Communicate with the customer to understand the target of the penetration test, such as the system, server, and IP address.
Which of the following is a private IP address?
192.200.1.1
172.32.1.1
192.1.1.1
172.20.2.1
Which of the following statements is correct about the characteristics of a DDoS attack?
An attacker intrudes into the target system through a backdoor program.
The purpose of such an attack is to steal confidential information from the target system.
The attack behavior can prevent the target system from processing the requests of authorized users.
If the target system has no vulnerability, the remote attack cannot succeed.
Network penetration simulates hackers’ intrusion behaviors and thought patterns to perform non-destructive security tests on customer systems. Which of the following is the correct sequence of the network penetration process?
Confirm the target → Collect information → Implement penetration → Perform lateral movement → Elevate privileges → Clear traces
Collect information → Confirm the target → Implement penetration → Perform lateral movement → Elevate privileges → Clear traces
Confirm the target → Collect information → Perform lateral movement → Implement penetration → Elevate privileges → Clear traces
Confirm the target → Implement penetration → Collect information → Perform lateral movement → Elevate privileges → Clear traces
Which of the following statements is incorrect about TTL in IP packets?
TTL is the maximum number of hops that an IP packet can be forwarded on a computer network.
The main function of TTL is to prevent IP packets from being circulated over a network infinitely, thereby saving network resources.
The TTL value decrements by 1 every time a packet is forwarded to a Layer 3 node.
The TTL value of a packet ranges from 0 to 4095.
In tunnel mode of IPsec, to authenticate a new IP header, which of the following IPsec protocols needs to be used?
MD5
SHA1
ESP
AH
Which of the following attacks is not a network-layer attack?
Smurf attack
IP sweep
IP spoofing attack
Port scanning
Which of the following statements is correct about a firewall’s interzone security policies?
Interzone security policies are matched sequentially from the one with the smallest ID.
Interzone security policies are matched sequentially from the top down.
Interzone security policies are matched sequentially from the one with the largest ID.
Interzone security policies are automatically sorted by ID. If the position of a policy changes, the ID of the policy changes accordingly.
Which of the following statements is incorrect about the RADIUS protocol?
By default, UDP is used, and the authentication and authorization port numbers are 1812 and 1813 or 1645 and 1646, respectively.
It encrypts only the password field in an authentication packet.
Authentication and authorization are processed together.
It supports authorization of configuration commands.
Hot Standby Redundancy Protocol (HRP) is used to synchronize data such as the key configurations and connection status of the active firewall to the standby firewall. Which of the following data is beyond the synchronization scope?
Routing rules
Security policies
SSL policies
NAT policies
Which of the following messages can provide error information and IP packet processing information for source ends?
IGMP
TCP
UDP
ICMP
If packet loss occurs when hosts A and B communicate with each other through TCP, how does TCP ensure reliability?
Host B sends ICMP packets to host A to notify data loss.
The sliding window mechanism is used between the two hosts to ensure reliability.
Host B uses the ACK field to instruct host A to retransmit packets.
The Option field in TCP packets is used to ensure reliability of host A and host B.
Which one of the following parts is not included in a digital certificate?
Name of the certificate holder
Certificate validity period
Certificate private key
Certificate public key
When an administrator wants to configure a USG series firewall through the console port, which of the following configurations should be made in the putty?
4800 bps, 8 data bits, 1 stop bit, odd parity check, and no flow control
9600 bps, 8 data bits, 1 stop bit, even parity check, and hardware-based flow control
9600 bps, 8 data bits, 1 stop bit, no parity check, and no flow control
19200 bps, 8 data bits, 1 stop bit, no parity check, and no flow control
On a USG firewall, which of the following commands is used to view current session entries?
display firewall statistic
display firewall routing table
display firewall session table
display firewall fib session
Which of the following values is the default security level of the Trust zone on a Huawei USG firewall?
5
50
85
100
Which of the following statements is correct about firewall security zones?
The default security zones cannot be deleted from a firewall.
An interface on a firewall can belong to multiple security zones.
Different interfaces on a firewall can belong to the same security zone.
Different security zones can have the same security level.
Which of the following steps is optional for configuring intrusion prevention?
Creating an IPS profile
Configuring a signature filter
Configuring signature exceptions
Referencing an IPS profile in a security policy
Which of the following values is the default port number of the SSH protocol?
20
21
22
23
The digital certificate technology addresses the problem from the digital signature technology that the owner of a public key cannot be determined. Which of the following are types of digital certificates?
Self-signed certificate
CA certificate
Local certificate
Local device certificate
Which of the following ports are used as the default authentication and accounting ports of the RADIUS protocol?
1811
1812
1813
1814
If the administrator has configured the Telnet service on the firewall but a user still cannot access the firewall remotely, which of the following are possible causes of the access failure?
The network between the user and the firewall is unreachable.
The user enters an incorrect password.
The Telnet user level is incorrectly configured.
The number of online Telnet users reaches the upper limit.
Select all that apply: Which of the following methods can be used to implement the SSL VPN web proxy?
Web link
Web transparent transmission
Web forwarding
Web rewriting
Select all that apply: Which of the following are components of a PKI system?
End entity
Certificate authority
Certificate registration authority
Certificate/CRL database
Select all that apply: Which of the following security functions can be provided by the AH protocol in IPsec?
Data origin authentication
Data confidentiality
Data integrity verification
Anti-replay
Select all that apply: Which of the following algorithms are symmetric encryption algorithms?
DES
3DES
MD5
SHA1
Select all that apply: Which of the following are common network topologies?
Bus topology
Tree topology
Star topology
Ring topology
Select all that apply: Which of the following statements are correct about the decapsulation of data packets in the TCP/IP protocol stack?
The physical network layer receives frames, calculates the CRC of the frames, and then sends the frames to the data link layer.
The data link layer checks whether the CRC of the frames is correct, deletes the frame header and CRC, and then sends the frames to the network layer.
After the network layer receives and parses data packets, network layer information is removed, and the upper-layer protocol is obtained based on the parsing result.
After the transport layer (TCP) receives and parses data packets, transport layer information is removed, and the upper-layer protocol is obtained based on the parsing result.
Select all that apply: Which of the following VPNs are suitable for employees on business trips to access the enterprise intranet from the public network?
L2TP VPN
GRE VPN
L2TP over IPsec
SSL VPN
Select all that apply: Which of the following principles must be adhered to when you configure the security levels of the firewall security zones?
The security level cannot be changed once it is configured.
Two security zones in the same system cannot be configured with the same security level.
The default security level of a new security zone is 100.
Security levels can be set only for user-defined security zones.
Select all that apply: Users are network access subjects and basic units for network behavior control and network permission assignment by firewalls. Which of the following are involved in the user organizational structure?
Authentication domain
User group/user
Security group
Isolation group
Select all that apply: Which of the following TCP ports are used by the FTP service by default?
20
21
22
23
Select all that apply: Which of the following backup modes are supported by the HRP mechanism?
Scheduled backup
Real-time backup
Batch backup
Quick backup
Which of the following can be used to implement AAA on Huawei devices?
RADIUS
HWTACACS
LDAP
AD
Which of the following VPNs are Layer 3 VPNs?
L2TP VPN
GRE VPN
IPsec VPN
SSL VPN
Which of the following protocol technologies are used when firewalls are deployed in hot standby mode?
VRRP
IGMP
VGMP
HRP
Which of the following authentication modes are available for Internet access users?
SSO
Built-in Portal authentication
User-defined Portal authentication
User authentication exemption
Which of the following parameters comprise an IPsec SA?
SPI
Source IP address
Destination IP address
Security protocol number
A session-based stateful inspection firewall processes the first packet and subsequent packets differently. Which of the following statements are correct?
When receiving a packet, the firewall searches for a matching entry in the session table. If no match is found, the firewall processes the packet as the first packet.
When receiving a packet, the firewall searches for a matching entry in the session table. If a matching entry is found, the firewall processes the packet as a subsequent packet.
When stateful inspection is enabled, subsequent packets also need to be checked based on security policies.
When stateful inspection is enabled and the firewall processes TCP packets, a session can be established only for SYN packets.
The web redirection password authentication function of a USG firewall enables a user to access services without being proactively authenticated, and the device pushes the authentication page to the user.
True
False
In an IP sweep attack, an attacker sends ICMP packets to probe the IP address of the target network and obtain the topology of the target network and active devices.
True
False
When a USG firewall serves as an out-of-path detection device, you need to configure the detection interface as a Layer 3 interface.
True
False
The intrusion prevention function of the firewall detects and terminates intrusions (such as buffer overflow attacks, Trojan horses, and worms) in real time to protect enterprises' information systems and network architectures.
True
False
During the ARP process, ARP reply packets are sent in broadcast mode. All hosts on the same Layer 2 network can receive these packets and learn the mapping between IP and MAC addresses.
True
False
When the stateful inspection function is disabled, the firewall creates a session for subsequent packets.
True
False
If the IKE negotiation mode of the IPsec VPN is the main mode, the ID type must be an IP address.
True
False
True or False: With a large number of network users, large enterprises usually use a hierarchical structure to support network expansion and growing number of users.
True
False
True or False: The heartbeat link is a channel through which two firewalls exchange messages to learn about each other’s status and back up configuration commands and entries. The MGMT interface can be used as the heartbeat interface.
True
False
True or False: SSL is a security protocol that provides secure connections for TCP-based application layer protocols like HTTP.
True
False
True or False: FTP is used for long-distance file transfer between two hosts and can ensure the reliability and confidentiality of data transmission.
True
False
True or False: Huawei Redundancy Protocol (HRP) is used to synchronize information such as key configurations, connection status, routing tables, and interface addresses between the active and standby firewalls.
True
False
True or False: On the CLI, users can view the running status and statistics in the user view, but not in the system view.
True
False
True or False: After receiving a packet, the LNS checks whether the TCP destination port number is 1701. If so, the LNS sends the packet to the L2TP processing module for further processing. If not, the LNS processes the packet as a normal IP packet.
True
False
True or False: A USG firewall is usually deployed between the external network and the network to be protected. It generates threat logs when detecting viruses, intrusions, botnets, Trojan horses, or worms.
True
False
True or False: A network device searches the routing table according to the destination IP address field in the IP packet header, and then forwards the data based on the search result.
True
False
True or False: IKEv1 negotiation phase 1 aims to establish an IKE SA, and supports two negotiation modes: main mode and aggressive mode.
True
False
True or False: The persistent connection function of the firewall allows you to set a long aging time for specific TCP and UDP data flows, ensuring that the session information does not age out for a long time.
True
False
True or False: NAT in Easy IP mode translates only private IP addresses. It cannot translate port numbers.
True
False
True or False: Proactive preemption is a process in which the active firewall takes over services when it recovers from a fault. Proactive preemption is enabled by default.
True
False
