
Prepare Top Huawei H12-723-ENU Exam Study Guide Practice Questions Edition
Go to H12-723-ENU Questions - Try H12-723-ENU dumps pdf
NEW QUESTION 63
The free mobility is a special access control method. According to the user's access point, access time, access method and user terminal specified permission is granted. From the physical connection, the access method can be divided into 3 categories, which of the following access methods not include?
- A. VPN access
- B. Wireless access
- C. Wired access
- D. 802.1X access
Answer: D
NEW QUESTION 64
MAC authentication means that in 802.1X authentication environment, when the terminal does not respond to 802.1X authentication request from the access control device after accessing the network, the access control device automatically obtains MAC address of the terminal and sends it to RADIUS server as a certificate for accessing the network.
- A. True
- B. False
Answer: B
NEW QUESTION 65
Configuring WLAN device detection can realize the monitoring of the entire network, but you need to set the working mode of the AP first, which of the following options are.
What is the working mode of AP? (multiple choice)
- A. Normal mode
- B. Mixed mode
- C. Monitoring mode
- D. access mode
Answer: A,C
NEW QUESTION 66
Which device is usually used as the hardware SACG in Agile Controller-Campus solution?
- A. IPS
- B. Switch
- C. Firewall
- D. Router
Answer: C
NEW QUESTION 67
The SACG query right-manager information as follows, which are correct? (Multiple choices)
[USG] display right-manager server-group
17:35:21 2017/7/14
Server group state: Enable
Server number:1
Server ip address Port State Master
1.1.1.2 3288 active Y
2.1.1.1 3288 active N
- A. The linkage between SACG and the controller is successful.
- B. The main controller IP address is 2.1.1.1.
- C. The collaboration between SACG and IP address 2.1.1.1 was unsuccessful.
- D. The main controller IP address is 1.1.1.2.
Answer: A,D
NEW QUESTION 68
In WPA2, because of the more secure encryption technology-TKIP/MIC, WPA2 is more secure than WPA.
- A. right
- B. wrong
Answer: B
NEW QUESTION 69
Regarding the principle of MAC authentication, which of the following descriptions is wrong?
- A. MAC Certification required Portal Server cooperation.
- B. NAS Device Configuration MAC After authentication, the terminal's MAC The address is used as the username and password.
- C. MAC Authentication requires obtaining the terminal's MAC The address is stored in AAA server.
- D. MAC Certification is passed 802.1X Implementation of the agreement.
Answer: A
NEW QUESTION 70
An enterprise use the hardware SACG access mode to perform admission control. The configuration commands are as follows: Admin@123
[USG] right-manager server-group
[USG-rightm] local ip 10.1.10.2
[USG-rightm] server ip 10.1.31.78 shared-key Adnln@123
[USG2100-rightm] right-manager server-group enable
Assuming other configurations are correct, based on the above configuration, which of the following options is correct?
- A. After the configuration is complete, SACG can associate with Agile Controller-Campus successfully.
- B. The pre-authentication domain ACL can be delivered.
- C. The association fails but the terminal can access the pre-authentication domain server.
- D. After the configuration is complete, the SACG can't associate with Agile Controller-Campus successfully.
Answer: D
NEW QUESTION 71
When deploy wired 802.1X authentication, if the admission control device is deployed at the convergence layer, this deployment method has features such as high security performance, multiple management devices and complicated management.
- A. True
- B. False
Answer: B
NEW QUESTION 72
Which of the following options is not a challenge brought by mobile office?
- A. Unified terminal management and fine control.
- B. Users can access the network safely and quickly.
- C. The mobile office platform is safe and reliable and goes online quickly.
- D. Network gateway deployment
Answer: D
NEW QUESTION 73
Regarding the way SACG devices connect to the network, which of the following descriptions are correct?
(multiple choice)
- A. SACG It is usually connected to the core switch equipment and uses policy routing to divert traffic.
- B. SACG Equipment requirements and Agile Controller-Campus Interoperability on the second floor.
- C. SACG The equipment requires Layer 3 intercommunication with the terminal.
- D. SACG Support hanging on non-Huawei devices.
Answer: A,D
NEW QUESTION 74
Which of the following options is for Portal The statement of the gateway access process is correct?
- A. Portal gateway initiates Radius Challenge request message, including user name and password information
- B. The ACL issued by the server to the access gateway is carried in the Portal protocol message
- C. Issue policies while performing identity authentication
- D. The Portal server needs to pass the security check result to the access gateway device
Answer: D
NEW QUESTION 75
WEB filtering technology is a kind of in-depth testing for WEB loophole, WEB classification and access control security management technology on the Internet.
- A. TRUE
- B. FALSE
Answer: A
NEW QUESTION 76
The use of 802.1X authentication scheme generally requires the terminal install specific client software. For large-scale deployment of client software, which of the following can use?
- A. Copy the installation packages from each other through U disk.
- B. Enable Guest VLAN so that users can obtain the installation package in Guest VLAN.
- C. Configure free-rule and web push functions on switch to push installation packages to users.
- D. Installed by the administrator for each user.
Answer: B,C
NEW QUESTION 77
Deployed by an enterprise network managerAgile Controller-Campus withSACG Later;Identity authentication is successful but cannot access the post-authentication domain, This phenomenon may be caused by any reason? (Multiple choice)
- A. The access control list of the post-authentication domain has not been delivered SACG.
- B. A serious violation will prohibit access to the post-authentication domain.
- C. Agile Controller-Campus Wrong post-authentication domain resources are configured on the server.
- D. ALC The number of rules issued is too many, and a lot of time is required to match, causing interruption of access services.
Answer: A,B,C
NEW QUESTION 78
Which of the following are correct of SACG equipment accesses the network? (Multiple choices)
- A. SACG equipment requires interworking with the terminal at Layer 2.
- B. SACG equipment requires interworking with Agile Controller-Campus Layer 2.
- C. SACG is usually hung on the core switch equipment and use policy routing to divert traffic.
- D. SACG support hanging on non-Huawei equipment.
Answer: C,D
NEW QUESTION 79
When the account assigned by the administrator for the guest is connected to the network, the audit action that the administrator can perform on the guest does not include which of the following options?
- A. Visitor online and offline records
- B. Account deactivation 1 reset Password
- C. Force users to go offline
- D. Send a warning message to the user
Answer: D
NEW QUESTION 80
Regarding CAPWAP encryption, which of the following statements is wrong?
- A. Use the certificate method to carry out DTLS Negotiation, the certificate is only used to generate the key, not right AP Perform authentication.
- B. DTLS Encryption can guarantee AC The issued control messages will not be eavesdropped on.
- C. DTLS Support two authentication methods:Certificate authentication(out AC,AP Already brought)with PSK Password authentication.
- D. CAPWAP The data tunnel can be used DTLS Encrypted.
Answer: D
NEW QUESTION 81
When performing terminal access control, the authentication technology that can be used does not include which of the following options?
- A. Bypass authentication
- B. Portal Certification
- C. 8021X Certification
- D. SACG Certification p2-
Answer: A
NEW QUESTION 82
User access authentication technology does not include which of the following options?
- A. Isolation repair'
- B. Authentication
- C. Security check
- D. Access control
Answer: A
NEW QUESTION 83
Regarding the basic principles of user access security, it is wrong not to list any description?
- A. When a terminal device accesses the network, it first authenticates the user's identity through the access device, and the access device cooperates with the authentication server to complete the user Authentication.
- B. The terminal device directly interacts with the security policy server, and the terminal reports its own status information, including virus database version, operating system version, and terminal Information such as the patch version installed on the device.
- C. The terminal device selects the answer to the resource to be accessed according to the result of the status check.
- D. The security policy server checks the status information of the terminal, and for terminal devices that do not meet the corporate security standards, the security policy server reissues. The authorization information is given to the access device.
Answer: C
NEW QUESTION 84
......
Free HCNP-Security H12-723-ENU Exam Question: https://www.test4cram.com/H12-723-ENU_real-exam-dumps.html