Spring Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: Board70

H12-711_V4.0 Exam Dumps - Huawei HCIA-Security Questions and Answers

Question # 14

Which of the following statements are correct about firewall security zones?

Options:

A.

Security policies do not have to permit mutual access between users in the same zone.

B.

A security policy can permit traffic in one direction.

C.

By default, firewalls have only three security zones: Trust, Untrust, and DMZ.

D.

A firewall interface can be added to multiple security zones.

Buy Now
Question # 15

Which of the following descriptions about the main implementation of single sign-on is wrong?

Options:

A.

Accept PC message mode

B.

Query the AD server security log mode

C.

Query the syslog server mode

D.

Firewall monitors AD authentication packets

Buy Now
Question # 16

Which of the following statements is incorrect about Portal authentication?

Options:

A.

In Portal authentication, users can be authenticated only on the firewall authentication page.

B.

In session authentication, users do not initiate identity authentication. Instead, they access the HTTP service first and are authenticated during the access. Service access is allowed only after authentication.

C.

In user-initiated authentication, users proactively initiate authentication and can access network resources only after authentication.

D.

The built-in Portal authentication triggering modes include session authentication and user-initiated authentication.

Buy Now
Question # 17

Match the following user categories and authentication modes.

Options:

Buy Now
Question # 18

An engineer needs to back up the firewall configuration. Now he wants to use a command to view all the current configurations of the firewall. May I ask the command he uses is ____[fill in the blank]*

Options:

Buy Now
Question # 19

HTTPS introduces the TLS layer based on HTTP to provide identity authentication, encryption, and integrity check for data transmission.

Options:

A.

TRUE

B.

FALSE

Buy Now
Question # 20

Which of the following attacks can be detected through intrusion prevention?

Options:

A.

Injection attack

B.

Directory traversal

C.

Trojan horse

D.

Buffer overflow attack

Buy Now
Question # 21

Which of the following descriptions about the heartbeat interface is wrong ( )?

Options:

A.

It is recommended to configure at least two heartbeat interfaces. - One heartbeat interface is used as the master, and the other heartbeat interface is used as the backup.

B.

The interface MTU value is greater than 1500 and cannot be used as a heartbeat interface

C.

The connection method of the heartbeat interface can be directly connected, or it can be connected through a switch or router

D.

MGMT interface (Gigabi tEtherneto/0/0) cannot be used as heartbeat interface

Buy Now
Question # 22

Regarding the characteristics of the routing table, which of the following items is described correctly

Options:

A.

Port When a packet matches multiple entries in the routing table, it is forwarded based on the route entry with the largest metric.

B.

Port In the global routing table, there is at most one next hop to the same destination CIDR block.

C.

There may be multiple next hops in the global routing table to the same destination.

D.

Port When a packet matches multiple entries in the routing table, it is forwarded according to the longest mask.

Buy Now
Question # 23

Arrange the following processes in the correct order based on the PKI lifecycle.

Options:

Buy Now
Exam Code: H12-711_V4.0
Exam Name: HCIA-Security V4.0 Exam
Last Update: Apr 3, 2026
Questions: 153
H12-711_V4.0 pdf

H12-711_V4.0 PDF

$25.5  $84.99
H12-711_V4.0 Engine

H12-711_V4.0 Testing Engine

$28.5  $94.99
H12-711_V4.0 PDF + Engine

H12-711_V4.0 PDF + Testing Engine

$40.5  $134.99