H12-711 Sample Questions

H12-711 Sample Questions & Answers

Applying cryptographic technologies carries the biggest weight, alongside security standards, writing firewall policies, failing over with VRRP hot standby, translating addresses through NAT, authenticating users, preventing intrusions, and PKI basics.

Launch the full H12-711 simulator →

Showing 10 of 20 free samples.

  1. Question 1Intermediate

    Firewall NAT technologies · NAT Server

    A network administrator needs to provide secure access to an internal web server (192.168.1.10) for external users. The Huawei USG firewall has a public IP address of 203.0.113.5 on its Untrust interface. The administrator wants external users to access the web server by browsing to https://203.0.113.5. Which type of NAT configuration is required on the USG firewall?

    Show answer & explanation

    Correct answer: B

    NAT Server, also known as port forwarding or destination NAT, is used to publish internal services to an external network. It maps a combination of a public IP address and a port to an internal private IP address and port. This allows inbound traffic from the internet to reach the internal server. Static NAT creates a one-to-one mapping of entire IP addresses, which is not what is required here. Dynamic NAT and PAT are for outbound connections.

  2. Question 2Beginner

    Encryption technology applications · IPSec VPN

    A company has two data centers, each with a Huawei USG firewall. They need to establish a secure and resilient connection between them over the public internet. The primary goal is to ensure data confidentiality and integrity for all traffic between the two sites. Which technology should be implemented?

    graph TD subgraph Data Center A FWA[USG Firewall A] LANA[LAN A] end subgraph Data Center B FWB[USG Firewall B] LANB[LAN B] end FWA --- LANA FWB --- LANB FWA |Internet| FWB

    Show answer & explanation

    Correct answer: B

    IPSec VPN is the industry standard for creating secure site-to-site connections over untrusted networks like the internet. It operates at the network layer (Layer 3) and can protect all IP traffic between the two locations, ensuring both confidentiality (through encryption with ESP) and integrity (through hashing with ESP or AH). SSL VPN is primarily used for remote user access, not for connecting entire sites.

  3. Question 3Intermediate

    Fundamentals of Encryption Technologies · Asymmetric Encryption

    What is the primary function of the Diffie-Hellman (DH) algorithm within the IKE protocol used by IPSec?

    Show answer & explanation

    Correct answer: C

    The Diffie-Hellman algorithm is a key exchange protocol. Its purpose in IKE is to allow two parties, without any prior shared secret, to jointly establish a shared secret key over an insecure communication channel. This shared secret is then used to derive the symmetric keys for encrypting the subsequent IKE and IPSec communication. It does not perform payload encryption or peer authentication itself.

  4. Question 4IntermediateSelect 3

    Firewall intrusion prevention · IPS Configuration and Management

    A security administrator is deploying a Huawei USG firewall and wants to implement an Intrusion Prevention System (IPS). Which of the following are valid actions that can be configured for a signature in an IPS profile? (Select THREE)

    Show answer & explanation

    Correct answers: A, B, D

  5. Question 5Intermediate

    Firewall user management · User Authentication Methods

    A company wants to implement 802.1X authentication for all devices connecting to its campus network. The goal is to ensure that only authorized and authenticated users and devices can gain network access. In this architecture, what is the role of the Huawei switch to which the end-user devices connect?

    Show answer & explanation

    Correct answer: C

    In an 802.1X architecture, there are three main components. The Supplicant is the client software on the end-user device. The Authentication Server (typically a RADIUS server) validates the user's credentials. The Authenticator is the network access device, such as a switch or wireless access point, that controls physical access to the network and acts as a proxy between the supplicant and the authentication server.

  6. Question 6Beginner

    Common network security threats and prevention · Network Attacks

    What is the term for a type of network attack where the attacker secretly relays and possibly alters the communications between two parties who believe they are directly communicating with each other?

    Show answer & explanation

    Correct answer: B

    A Man-in-the-Middle (MitM) attack is an active eavesdropping attack where the attacker intercepts a communication channel between two systems. The attacker can then read, insert, and modify data in the intercepted communication without either of the two parties knowing that the channel has been compromised.

  7. Question 7Intermediate

    Firewall hot standby technologies · VRRP (Virtual Router Redundancy Protocol)

    When configuring VRRP for gateway redundancy, two routers are configured in the same VRRP group. Router A has a priority of 120 and Router B has a priority of 100. Preemption is enabled on both routers. If Router A is currently the Master and it fails, Router B becomes the Master. What happens when Router A comes back online?

    Show answer & explanation

    Correct answer: B

    Because preemption is enabled, a router with a higher priority will always attempt to become the Master. Router A has a higher priority (120) than Router B (100). When Router A comes back online, it will detect that the current Master (Router B) has a lower priority. Due to preemption being enabled, Router A will take over the Master role.

  8. Question 8Beginner

    PKI certificate system · PKI Components

    Which PKI component is responsible for verifying the identity of an entity requesting a digital certificate before the certificate is issued?

    Show answer & explanation

    Correct answer: B

    The Registration Authority (RA) is the component of a PKI that is responsible for identity verification of individuals or entities requesting certificates. The RA vets the request and, upon successful verification, instructs the Certificate Authority (CA) to issue the certificate. The CA is responsible for digitally signing and issuing the certificate itself.

  9. Question 9Intermediate

    Common network security threats and prevention · Network Attacks

    A security analyst is reviewing firewall logs and notices a large volume of TCP SYN packets from various source IPs directed at a single web server in the DMZ, but the corresponding SYN-ACKs are never acknowledged. This has caused the server's connection table to fill up, making it unresponsive to legitimate users. What type of attack is occurring?

    Show answer & explanation

    Correct answer: C

    This scenario describes a classic TCP SYN Flood attack. The attacker sends a succession of SYN requests to a target's system in an attempt to consume enough server resources to make the system unresponsive to legitimate traffic. The attacker does not complete the three-way handshake, leaving the server with a large number of half-open connections.

  10. Question 10Intermediate

    Firewall security policy · Security Policy Configuration

    A network engineer is configuring a Huawei USG firewall. They need to ensure that traffic from the internal 'Trust' zone to the 'DMZ' zone is allowed only for SSH (TCP port 22) and RDP (TCP port 3389). All other traffic between these two zones should be denied. What is the best practice for creating the security policy to achieve this?

    Show answer & explanation

    Correct answer: B

    The best practice is to follow the principle of least privilege. This involves creating a specific rule to permit only the required traffic (SSH and RDP) from the Trust zone to the DMZ zone. The firewall's default security policy for inter-zone traffic is 'deny', which will automatically block all other traffic that doesn't match this specific permit rule. Creating broad permit rules is insecure.

Ready for the real thing?

The full H12-711 simulator has every exam-style question, timed mode, and instant scoring.