Verified H12-723-ENU dumps Q&As 100% Pass in First Attempt Guaranteed Updated Dump from Exam4PDF [Q75-Q100]

Share

Verified H12-723-ENU dumps Q&As 100% Pass in First Attempt Guaranteed Updated Dump from Exam4PDF

Pass HCNP-Security H12-723-ENU Exam With  200 Questions

NEW QUESTION 75
According to different reliability requirements, centralized networking can provide different reliability networking solutions. Which of the following are correct about these solutions? (Multiple choices)

  • A. The basic networking includes deploy one SM server, one SC server, one DB and one AE server.
  • B. In addition to deploying basic networking components, AE reliability networking requires the deployment of one more standby SC server.
  • C. In addition to deploying basic networking components, DB reliability networking requires the deployment of one more standby DB.
  • D. In addition to deploying basic networking components, SC reliability networking requires the deployment of one more standby SM server.

Answer: A,C

 

NEW QUESTION 76
In Portal authentication, after enter the account password authentication through web browser, prompt "Authenticating..." The status continues for a long time before the authentication is successful.
This phenomenon is caused by which of the following reasons?

  • A. Multiple Agile Controller servers simultaneously add the same terminal IP address to Portal "access terminal IP address list", and some of Agile Controller servers and terminals can't communicate normally.
  • B. The portal template is configured with wrong password.
  • C. There are too many authorization rules on Agile Controller-Campus and it takes a lot of time to find them.
  • D. The lack of curtains in the terminal equipment leads to large delay.

Answer: A

 

NEW QUESTION 77
Webmail filter support Intranet users receive mail filtering.

  • A. TRUE
  • B. FALSE

Answer: A

 

NEW QUESTION 78
Which of the following descriptions is wrong for the basic principle of user access security?

  • A. The terminal device selects the resource to be accessed according to the result of the status check
  • B. The terminal device directly interacts with the security policy server. The terminal reports its own status information, including the virus database version, operating system version and patch version installed on the terminal.
  • C. When terminal device accesses the network, it first authenticates the user through the access device, and the access device cooperates with the authentication server to complete the user identity authentication.
  • D. The security policy server checks the terminal status information. For terminal devices that do not meet enterprise security standards, the security policy server re-issues authorization information to the access device.

Answer: A

 

NEW QUESTION 79
Regarding uninstalling the Agile Controller-Campus in Windows and Linux systems, which of the following descriptions is correct?

  • A. On the Windows platform, select "Start>All Programs>Huawei>Agile Controller>Server Startup config".
  • B. Use a common account to execute sh uninstall.sh in the Agile Controller/Uninstall directory to start the uninstallation program.
  • C. On the Windows platform, select "Start>All Programs> Huawei> Agile Controller>Uninstall
  • D. Use the root account to execute sh uninstall.sh in the Agile Controller directory to start the uninstallation program. :

Answer: C

 

NEW QUESTION 80
Mobile smartphone, tablet PC users through Any Office Client and AE Establish IPSec Encrypted tunnel, After passing the certification and compliance check, visit the enterprise business.

  • A. right
  • B. wrong

Answer: B

 

NEW QUESTION 81
Security domain division refers to dividing the intranet into several logically appropriate logical areas based on intranet service types and security requirements in order to better secure the intranet.
Which of the following options does not belong to the security domain in Agile Controller-Campus?

  • A. Business Domain
  • B. Network domain
  • C. Attack domain
  • D. User domain

Answer: C

 

NEW QUESTION 82
Which three steps involved in the free mobility deployment? (Multiple choices)

  • A. Define the security group
  • B. Define user groups
  • C. The system runs automatically
  • D. System report security group
  • E. Define and deploy group policy

Answer: A,C,E

 

NEW QUESTION 83
Which of the following statement is correct IDS and IPS?

  • A. IPS deployed as a bypass mode is similar to the function of ID
  • B. With the IPS does not need to deploy a firewall and IDS
  • C. IDS only supports Inline online deployment
  • D. the core technology of IPS is deep packet inspection and bypass inspection

Answer: A

 

NEW QUESTION 84
Regarding MAC authentication and MAC bypass authentication, which of the following descriptions are correct? (multiple choice)

  • A. The biggest difference between the two is MAC Bypass authentication belongs to 802 1X Certification, while MAC Certification does not belong to 802 1X Certification.
  • B. MAC Authentication MAC One more bypass authentication 802 In the instrument certification process, the open time is longer than MAC The bypass authentication time is long.
  • C. If a network can connect to dumb terminals(printer,IP telephone), The text may be connected to a portable computer, please use MAC Bypass authentication:First try 802 1X Authentication, try again if authentication fails MAC Certification
  • D. If a network will only connect to dumb terminals(printer,IP telephone),please use MAC Certification in order to shorten the certification time.

Answer: A,C,D

 

NEW QUESTION 85
The admission control server is the implementer of the enterprise security policy and is responsible for implementing the corresponding admission control (allow, deny, quarantine, or restrict) according to the security policy formulated by the customer network.

  • A. False
  • B. True

Answer: A

 

NEW QUESTION 86
Agile Controller-Campus Which deployment mode is not supported?

  • A. Centralized deployment
  • B. Hierarchical deployment
  • C. Two-machine deployment
  • D. Distributed deployment

Answer: C

 

NEW QUESTION 87
Which of the following correct for MAC authentication and MAC bypass authentication? (Multiple choices)

  • A. MAC address is not used as the user name and password to automatically access the network during MAC bypass authentication.
  • B. MAC authentication is an authentication method that controls the user's network access rights based on the interface and MAC address. It does not require the user to install any client software.
  • C. MAC bypass authentication first 802.1X authentication is performed on the device that accesses the device. If the device does not respond to 802.1X authentication, the device uses MAC to authenticate the device.
  • D. During the MAC authentication process, the user needs to manually enter the user name or password.

Answer: B,C

 

NEW QUESTION 88
Portal The second-level authentication method of authentication refers to the direct connection between the client and the access device(Or only layer devices exist in between),The device can learn the user's MAC Address and can be used IP with MAC Address to identify the user.

  • A. right
  • B. wrong

Answer: A

 

NEW QUESTION 89
Regarding the basic principles of user access security, it is wrong not to list any description?

  • A. The terminal device selects the answer to the resource to be accessed according to the result of the status check.
  • B. When a terminal device accesses the network, it first authenticates the user's identity through the access device, and the access device cooperates with the authentication server to complete the user Authentication.
  • C. The terminal device directly interacts with the security policy server, and the terminal reports its own status information, including virus database version, operating system version, and terminal Information such as the patch version installed on the device.
  • D. The security policy server checks the status information of the terminal, and for terminal devices that do not meet the corporate security standards, the security policy server reissues. The authorization information is given to the access device.

Answer: A

 

NEW QUESTION 90
In agile network, before the user is authenticated, users may need to access servers such as DNS, DHCP and Portal. When the traffic from the user access the server pass through the firewall, the firewall queries the Agile controller-campus server for the agile security group information corresponding to the traffic. Because the user is not authenticated at this time, the Agile controller-campus server informs the firewall that the user belongs to the "unknown agile security group (Unknown)". This will cause the user's traffic to match the "unknown agile security group" before the firewall refreshes the user identity.
After the user passes the authentication, the right authority can't be obtained immediately. How to solve the problem?

  • A. Configure TSM on FW.
  • B. Release traffic to the server on FW.
  • C. Set the security pre-domain. When an unauthenticated user accesses a server in the pre-security domain, FW directly forwards the traffic.
  • D. Turn off state detection on FW.

Answer: C

 

NEW QUESTION 91
Which of the following is correct of the accompanying logical architecture of the business?

  • A. Points of concern for the network device plane include user terminals and static resources.
  • B. The business management plane focuses on administrators, authentication servers and policy servers.
  • C. The free-to-play logical architecture include management subsystem, authentication and authorization subsystem and business strategy subsystem.
  • D. The user plane focuses on the authentication point and the policy enforcement point.

Answer: B

 

NEW QUESTION 92
In enterprises where terminal host access control management is relatively strict, administrators hope to bind terminal hosts and accounts to prevent terminal users from accessing the controlled network from unauthorized terminal hosts at will. Regarding the description of binding the terminal host and account, which of the following is correct?

  • A. Binding terminal hosts and accounts is only applicable to terminal users through Any Office Scenarios for authentication, Not applicable Web Agent Plugins and Web The scenario where the client authenticates.
  • B. When other accounts need to be authenticated on the bound terminal host, there is no need to find the asset owner who is bound for the first time to authorize themselves.
  • C. exist Any Office When logging in with an account for the first time, the terminal host is automatically bound to the current account, but the automatic binding process requires administrator approval
  • D. There are only consoles in the account binding terminal host, which cannot be configured by the administrator.

Answer: A

 

NEW QUESTION 93
In the terminal host check strategy, you can check whether the important subkeys and key values of the registry meet the requirements to control the terminal host's Access, which of the following check results will be recorded as violations? (multiple choice)

  • A. The registry contains the prohibited"Subkeys and key values"W
  • B. The registry does not contain the mandatory requirements of the policy"Subkeys and key values".
  • C. The registry contains the mandatory requirements of the policy"Subkeys and key values",
  • D. The registry does not contain any prohibited by this policy"Subkeys and key values"

Answer: A,B

 

NEW QUESTION 94
IPS custom signature in UTM supports you to set direction and protocol type.

  • A. TRUE
  • B. FALSE

Answer: A

 

NEW QUESTION 95
There are two types of accounts on the Agile Controller-Campus: one is a local account and the other is an external account.
Which of the following is not a local account?

  • A. Ordinary account
  • B. Mobile certificate account
  • C. Anonymous account
  • D. Guest account

Answer: B

 

NEW QUESTION 96
Regarding the application scenarios of Agile Controller-Campus centralized deployment and distributed deployment, which of the following options are correct? (Multiple select)

  • A. If most end users are concentrated on--Offices in several regions, and a small number of end users work in branches. Distributed deployment is recommended.
  • B. If end users are scattered in different geographical locations, a distributed deployment solution is recommended.
  • C. If end users are scattered in different regions, a centralized deployment solution is recommended.
  • D. If most end users work in one area and a few end users work in branch offices, centralized deployment is recommended.

Answer: B,D

 

NEW QUESTION 97
In the campus network, employees can use 802.1X, Portal,MAC Address or SACG Way to access. Use different access methods according to different needs to achieve the purpose of user access control.

  • A. right
  • B. wrong

Answer: A

 

NEW QUESTION 98
Deploying on Windows platform, using SQL Server database About the HA function of Agile Cotoller-Campus, which of the following descriptions Is it correct? (multiple choice)

  • A. Deploy Business Manager SM Time, support HA, Provide based on Keepalived Technical HA Active/standby switchover.
  • B. Deployment Management Center MC Time, support HA, Provide based on Keepalived Technical HA Active/standby switchover.
  • C. Deploy the database DB Time, support HA use SQL Server Database mirroring technology requires the deployment of master DB+Mirroring DB+witness DB.
  • D. Deploy business controller 3SC Time, support HA, Provide a backup solution in resource pool mode, which needs to be deployed N+1 indivual SC

Answer: C,D

 

NEW QUESTION 99
Which of the following descriptions are correct regarding the strategy of checking account security? (Multiple choices)

  • A. You can check if there is a weak password.
  • B. Can't repaired automatically.
  • C. Can't check whether the password length meets the requirements.
  • D. You can check whether the account has joined a specific group.

Answer: A,D

 

NEW QUESTION 100
......

Pass H12-723-ENU Tests Engine pdf - All Free Dumps: https://www.exam4pdf.com/H12-723-ENU-dumps-torrent.html