
[Oct-2021] Dumps Brief Outline Of The H12-723-ENU Exam - Exam4PDF
H12-723-ENU Training & Certification Get Latest HCNP-Security
NEW QUESTION 98
When all services are allocated according to the user group, account number and terminal IP address range, if the same service is assigned to the user group, account number and terminal IP address range (except the announcement service), the business assigned by the highest priority will take effect.
About the order of priorities, which of the following is correct?
- A. User Group> Terminal IP Address Range> Account
- B. Account> User Group> Terminal IP Address Range
- C. Terminal IP Address Range> Account> User Group
- D. Account> Terminal IP Address Range> User Group
Answer: D
NEW QUESTION 99
In some scenarios, anonymous accounts can be used for authentication. Which are correct for anonymous account? (Multiple choices)
- A. By default, anonymous account access control, policy/patching template invocation and software distribution can't be performed.
- B. The administrator can't delete the anonymous account "~anonymous".
- C. The "~anonymous" account needs to be manually created on Agile Controller-Campus.
- D. Use anonymous account for authentication is based on the belief that the certification authority does not require the other party to provide identity information and provide services to the other party.
Answer: B,D
NEW QUESTION 100
In Agile Controller-Campus admission control scenario, which of the following is correct about RADIUS server/client role?
- A. The authentication device (such as 802.1X switch) serves as RADIUS server and the user terminal serves as RADIUS client.
- B. Agile Controller-Campus acts as RADIUS server and the authentication device (such as 802.1X switch) acts as RADIUS client.
- C. Agile Controller-Campus serves as RADIUS server and the user terminal serves as RADIUS client.
- D. Agile Controller-Campus integrates all the functions of RADIUS server and client.
Answer: B
NEW QUESTION 101
For the convenience of visitors, different authentication and registration pages can be pushed for different visitors. When configuring push page policy, you need to define different matching conditions. Which of the following can be used as qualified matching conditions? (Multiple selection)
- A. Access device location information
- B. SSID of access network
- C. Terminal IP address
- D. Guest account priority
Answer: B,C
NEW QUESTION 102
The administrator issues notices to users through the form of announcements, such as the latest software and patch installation notices, etc. Which of the following options is wrong?
- A. The endpoint must have proxy client installed to receive announcements.
- B. You can issue an announcement by department.
- C. You can issue an announcement by account number.
- D. If the system issues an announcement and the proxy client is not online, it will not receive the announcement information after going online.
Answer: D
NEW QUESTION 103
Use the command on the switch to view the free deployment status of the service. The command is as follows:
<SW>display group-policy status
Controller IP address: 10.1.31.78
Controller port: 5222
Backup controller IP address: -
Backup controller port: -
Source IP address: 10.1.10.34
State: working
Connected controller: master
Device protocol version: 2
Controller protocol version: 2
For the above command, which of the following descriptions is correct?
- A. The address of the authentication device is 10.1.31.78
- B. The status is "working" indicating that the association between the switch and the controller is successful.
- C. The control server address is 10.1.10.34
- D. The current Controller server is backup
Answer: B
NEW QUESTION 104
Which of the following are correct of SACG equipment accesses the network? (Multiple choices)
- A. SACG support hanging on non-Huawei equipment.
- B. SACG is usually hung on the core switch equipment and use policy routing to divert traffic.
- C. SACG equipment requires interworking with the terminal at Layer 2.
- D. SACG equipment requires interworking with Agile Controller-Campus Layer 2.
Answer: A,B
NEW QUESTION 105
Which of the following is the main function of SC component in Agile Controller-Campus?
- A. As security server of Agile Controller-Campus, it is responsible for analyzing and calculating the security events reported by iRadar.
- B. As the management center of Agile Controller-Campus, it is responsible for formulating the overall strategy.
- C. Integrate standard RADIUS servers, Porta servers, etc., it is responsible for implementing user-based network access control policy in conjunction with network access devices.
- D. As the management interface of Agile Controller-Campus, configure and monitor the system.
Answer: C
NEW QUESTION 106
Which of the following descriptions is correct regarding the strategy for checking screen saver settings?
- A. You can check whether the terminal has screen saver enabled.
- B. Screensaver settings do not automatically repair
- C. Only Windows operating systems are supported.
- D. You can check whether the screen saver password is enabled
Answer: A,D
NEW QUESTION 107
Which of the following descriptions are correct regarding the strategy of checking account security? (Multiple choices)
- A. Can't repaired automatically.
- B. You can check whether the account has joined a specific group.
- C. Can't check whether the password length meets the requirements.
- D. You can check if there is a weak password.
Answer: B,D
NEW QUESTION 108
Which of the following statements is true about the description of ACL used by SACG devices and TSM systems?
- A. The default ACL rule group number can only be 3999.
- B. Because SACG needs to use ACL 3099 to 3999 to receive the rules delivered by TSM system, you must first ensure that these ACL are not referenced by other functions before configuring TSM linkage.
- C. TSM linkage can be successfully enabled even if ACL with the original group number 3099 to 3999 is occupied.
- D. The default ACL rule group number can be arbitrarily specified.
Answer: B
NEW QUESTION 109
The traditional network single strategy is difficult to deal with complex situations such as diverse users, diversified locations, diversified terminals, diversified applications and inexperienced experiences.
- A. True
- B. False
Answer: A
NEW QUESTION 110
A network use Portal authentication, when the user accesses, he finds that the user name/password is not entered in the pushed Web page.
This fault may be caused by which reason?
- A. Push page error on portal server.
- B. Switch AAA configured wrong.
- C. There is no corresponding user on Agile Controller-Campus.
- D. The switch does not enable Portal function.
Answer: A
NEW QUESTION 111
Use hardware SACG access control, the result of viewing the session table on hardware SACG is as follows:
<FW>display firewall session table verbose:
tcpVPN: public-->public
Zone: untrust-->trust TTL: 00:10:00 Left: 00:05:27
Interface: GigabitEthernet0/0/1 NextHop:192.168.200.11 MAC:00-0c-29-d4-47-d2
<--packets: 316ytes:9516-->packets:33bytes:17277
192.168.0.119:1574-->192.168.200.11:15080
tcpVPN: public-->public
Zone: untrust-->trust TTL: 00:10:00 Left: 00:02:20
Interface: GigabitEthernet0/0/1 NextHop:192.168.100.1 MAC: 00-0c-29-a4-37-c2
<--packets:31bytes:9516-->packets:336ytes:17277
192.168.0.119:1671-->192.168.100.1:8443
Which of the following statements are correct? (Multiple choices)
- A. If 192.168.200.11 is the server in the post-authentication domain, then the terminal with the IP address 192.168.0.119 may access the server if it is not authenticated.
- B. If the session 192.168.0.119:1574-->192.168.200.11:15080 is not refreshed within 6 minutes, the IP address is 192.168.0.119. If the device wants to communicate with the device whose IP address is 192.168.200.11, must must reestablish the session.
- C. 192.168.100.1 must be the controller IP address of Agile Controller-Campus.
- D. 192.168.100.1 must be the manager IP address of Agile Controller-Campus.
Answer: A,B,D
NEW QUESTION 112
After the announcement is configured, Agile Controller-Campus system can't assign the announcement to which of the following objects?
- A. Assigned to the terminal IP address range
- B. Assigned to the account
- C. Assigned to the user
- D. Assign to a place
Answer: D
NEW QUESTION 113
The service will determine the access right and QoS policy according to 5W1H condition of user access. Which of the following statements is correct for 5W1H? (Multiple choices)
- A. What, determine the access device (PC, iOS, etc.)
- B. Who, determine the attribution of access equipment (company standard, BYOD, etc.)
- C. Whose, determine the identity of the access person (employees, visitors, etc.)
- D. How to determine the access method (wired, wireless, etc.).
Answer: A,D
NEW QUESTION 114
Which of the following options can't trigger MAC authentication?
- A. DHCP packets
- B. ICMP packets
- C. ARP packets
- D. DHCPv6 packets
Answer: B
NEW QUESTION 115
Portal authentication on Agile Controller-Campus has been configured and it is correct.
Configure the following command on admission control switch:
[S5720] authentication free-rule 1 destination ip 10.1.31.78 mask 255.255.255.255 Which of the following options are correct? (Multiple choices)
- A. After the configuration is complete, the switch will automatically release the data flow to access the security controller without the administrator manually configuring it.
- B. After the configuration is complete, the administrator still needs to manually configure the release network segment.
- C. This configuration allows users to access the network resources before authentication.
- D. The terminal can access the 10.1.31.78 host only after the authentication is passed.
Answer: A,C
NEW QUESTION 116
The free mobility is a special access control method. According to the user's access point, access time, access method and user terminal specified permission is granted. From the physical connection, the access method can be divided into 3 categories, which of the following access methods not include?
- A. Wired access
- B. Wireless access
- C. 802.1X access
- D. VPN access
Answer: C
NEW QUESTION 117
Agile Controller-Campus product architecture includes three levels. Which of the following does not belong to product architecture hierarchy?
- A. Server layer
- B. Network device layer
- C. User access layer
- D. Admission control layer
Answer: D
NEW QUESTION 118
Which of the following is not supported by the business?
- A. Teamwork office.
- B. Implement communication between devices.
- C. When traveling user accesses the intranet resources, the traveling user accesses the intranet through VPN.
- D. Intranet users access the data center/Internet.
Answer: B
NEW QUESTION 119
......
Certification Training for H12-723-ENU Exam Dumps Test Engine: https://www.exam4pdf.com/H12-723-ENU-dumps-torrent.html

