H12-821 Sample Questions

H12-821 Sample Questions & Answers

BGP fundamentals carry the biggest weight, alongside IP routing basics, OSPF and IS-IS, controlling traffic through routing policy, switching at the Ethernet layer, IP multicast, IPv6, network security and reliability, large-scale WLAN design, and enterprise solutions.

Launch the full H12-821 simulator →

Showing 10 of 20 free samples.

  1. Question 1Advanced

    BGP Core Knowledge · BGP Route Aggregation

    Case Study: Global Logistics Inc. Network Redesign

    Global Logistics Inc. is redesigning its core network, which uses BGP for external connectivity and OSPF as the IGP. The company has a large number of internal routes that are currently being redistributed into BGP. This practice has led to instability in the BGP routing table, as every internal OSPF flap (a link going down or up) causes BGP updates to be sent to their upstream ISPs. This instability is causing performance issues and has violated their SLA with the providers.

    The network architecture team has been tasked with resolving this instability. The primary requirement is to advertise a stable summary of the company's internal address space to the internet while preventing IGP instability from affecting the external BGP sessions. The solution must ensure that internal subnets remain reachable from the internet via the advertised summary route. Any solution that requires manual intervention for every internal network change is unacceptable.

    The current configuration on the edge routers involves a redistribute ospf command under the BGP process, which is the source of the problem. The company's allocated public IP space is 203.0.113.0/24, which is currently broken down into multiple /26 and /27 subnets used internally and advertised via OSPF.

    Which approach best meets the requirements to stabilize BGP while maintaining reachability?

    Show answer & explanation

    Correct answer: D

    This is the best practice for BGP stability. By advertising only a single, stable aggregate route, the external BGP peers are shielded from any instability within the internal OSPF domain. The aggregate route will only be withdrawn if all contributing specific routes disappear, which is a much more significant event than a single link flap. This solves the instability problem while ensuring reachability and avoiding the high administrative overhead of static routes. Route dampening punishes flapping routes but doesn't solve the core issue of over-advertisement. Filtering after redistribution is less efficient and doesn't stop the BGP process from reacting to IGP churn.

  2. Question 2Intermediate

    Network Security Basics · Switch Security

    A network administrator is securing the access layer of a campus network using Huawei switches. To prevent common attacks like DHCP starvation and rogue DHCP servers, DHCP Snooping has been enabled. Which additional feature must be configured to validate ARP packets against the DHCP Snooping binding database, preventing ARP spoofing attacks?

    Show answer & explanation

    Correct answer: C

    Dynamic ARP Inspection (DAI) is a security feature that works in conjunction with DHCP Snooping. It intercepts all ARP requests and replies on untrusted ports and validates them against the IP-to-MAC address bindings stored in the DHCP Snooping database. If an ARP packet does not have a valid binding, it is dropped. This effectively prevents ARP spoofing and man-in-the-middle attacks.

  3. Question 3Intermediate

    Network Reliability Basics · BFD (Bidirectional Forwarding Detection)

    To ensure rapid failure detection for a critical link carrying BGP traffic between two routers, an engineer configures BFD. The desired detection time is less than one second. Which BFD parameters are most directly configured to achieve this goal?

    Show answer & explanation

    Correct answer: D

    The speed of BFD failure detection is determined by the negotiated transmission interval and the detection multiplier. The min-tx-interval specifies the minimum interval at which the local system wants to transmit BFD packets, min-rx-interval is the minimum interval at which it can receive them, and the detect-multiplier is the number of consecutive packets that can be missed before the session is declared down. The actual detection time is the negotiated transmit interval multiplied by the neighbor's detect-multiplier. Configuring these values aggressively (e.g., 50ms intervals with a multiplier of 3) achieves sub-second detection.

  4. Question 4IntermediateSelect 2

    Large-scale WLAN Architecture · CAPWAP Protocol

    A university is deploying a large-scale campus WLAN using Huawei's Fit AP architecture. The network consists of one Access Controller (AC) and hundreds of Access Points (APs). How do the APs discover the location of the AC to establish a CAPWAP tunnel? (Select TWO methods)

    Show answer & explanation

    Correct answers: A, C

  5. Question 5IntermediateSelect 3

    Switching Core Knowledge · Spanning Tree Protocols

    An engineer is configuring MSTP on a set of interconnected Huawei switches. To ensure that switches are part of the same MSTP region, which three parameters must match exactly on all switches within that region?

    Show answer & explanation

    Correct answers: A, B, C

  6. Question 6Intermediate

    Multicast Basics · IP Multicast Fundamentals

    A router running PIM-SM has received a multicast packet on an interface. What is the first and most critical check it performs to determine whether to accept and forward the packet?

    Show answer & explanation

    Correct answer: B

    The Reverse Path Forwarding (RPF) check is a fundamental loop-prevention mechanism in multicast routing. When a multicast packet arrives on an interface, the router looks up the source IP address in its unicast routing table. If the interface on which the packet was received is the same interface the router would use to send unicast traffic back to the source, the RPF check passes. If it fails, the packet is dropped. This ensures that multicast traffic follows a loop-free path from the source.

  7. Question 7Beginner

    IPv6 Core Knowledge · IPv6 Address Configuration

    Which IPv6 address autoconfiguration method allows a host to derive its own IP address using the prefix advertised by a local router via Router Advertisement (RA) messages, without the need for a central server to track address assignments?

    Show answer & explanation

    Correct answer: C

    SLAAC is the method where an IPv6 host configures its own address. It listens for Router Advertisement (RA) messages from a local router, which contain the network prefix. The host then combines this prefix with an interface identifier (often derived from its MAC address using the EUI-64 format or generated randomly) to create a unique global unicast address. This process is 'stateless' because no server needs to maintain a lease database of assigned addresses.

  8. Question 8Advanced

    BGP Core Knowledge · BGP Route Reflectors

    True or False: A BGP route reflector is permitted to modify the NEXT_HOP attribute of a route it reflects from one iBGP peer to another iBGP peer within the same cluster.

    Show answer & explanation

    Correct answer: B

    This statement is false. According to BGP rules, when a route reflector reflects a route learned from an iBGP peer to another iBGP peer (a client), it MUST NOT modify the NEXT_HOP, LOCAL_PREF, or MED attributes. The primary function of a route reflector is to relax the iBGP full-mesh requirement by reflecting routes, not by altering path attributes between internal peers. The next-hop-self command is used when advertising routes to iBGP peers, but it is typically applied on the edge router in its peering with the route reflector, not by the reflector during reflection to other clients.

  9. Question 9Advanced

    Network Reliability Basics · Gateway Redundancy

    Case Study: HealthNet Hospital Network Upgrade

    HealthNet, a large hospital, is upgrading its campus network for higher reliability. The current design has a single core router acting as the default gateway for all VLANs. A failure of this router would cause a complete network outage. The network team is implementing a pair of new, high-capacity core switches (CSW1 and CSW2) to provide gateway redundancy.

    The primary goals are: 1) Provide a resilient default gateway for all client devices. 2) Ensure failover is automatic and sub-second if possible. 3) Both core switches should actively forward traffic to utilize their capacity efficiently. 4) The solution must integrate with the existing OSPF routing environment to advertise the virtual gateway's reachability to the rest of the network.

    CSW1 and CSW2 are directly connected via a 10GbE Eth-Trunk link for control plane and data traffic. They both have connections to the access layer and the upstream firewall. The hospital uses VLAN 10 for medical devices, with a gateway IP of 172.16.10.1.

    Which combination of technologies provides the most effective solution to meet all of HealthNet's requirements?

    Show answer & explanation

    Correct answer: C

    This solution meets all requirements. VRRP provides the resilient virtual gateway. Enabling VRRP load balancing (where both master and backup forward traffic for the virtual IP) ensures both switches are used efficiently. Configuring BFD to track the VRRP peer provides the fastest possible failure detection (sub-second), which is critical in a hospital environment. The virtual IP can then be advertised into OSPF. The active/standby option does not meet the active-active forwarding requirement. Manual load balancing is complex to manage and less efficient than the built-in load balancing feature. Using only Eth-Trunk and OSPF does not provide gateway IP redundancy.

  10. Question 10Beginner

    Network Security Basics · Access Control Lists (ACLs)

    A Huawei router is configured with the following ACL rule: rule 5 permit ip source 192.168.1.0 0.0.0.255. Which of the following IP addresses will be matched by this rule?

    Show answer & explanation

    Correct answer: B

    The wildcard mask 0.0.0.255 specifies that the first three octets of the source IP address must match 192.168.1 exactly (where the mask bit is 0), and the last octet can be any value (where the mask bit is 1). Therefore, this rule matches any IP address in the 192.168.1.0/24 subnet. The IP address 192.168.1.55 falls within this range.

Ready for the real thing?

The full H12-821 simulator has every exam-style question, timed mode, and instant scoring.