Official Bank 0/217

HCNP-Security-CISN (Huawei Certified Network Professional – Constructing Infrastructure of Security Network) (H12-721) - Huawei Exam Questions

Last updated on June 20, 2026

97% Exam Compliance
217 Total Questions
1
Question
The topology of the BFD-bound static route is as follows: The administrator has configured the following on firewall A: [USG9000_A] bfd [USG9000_A-bfd] quit [USG9000_A] bfd aa bind peer-ip 1.1.1.2 [USG9000_A- Bfd session-aa] discriminator local 10 [USG9000_A-bfd session-aa] discriminator remote 20 Which of the following configurations can be added to the firewall to implement BFD-bound static routes?

Exhibit
Select 2
Options
A [USG9000_A]ip route-static 0.0.0.0 0 1.1.1.2 track bfd-session aa
B [USG9000_A]bfd aa bind local-ip 1.1.1.1
C [USG9000_A-bfd session-aa] commit
D [USG9000_A] ip route-static 0.0.0.0 0 1.1.1.2 bfd-session aa
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

2
Question
What is the correct statement about the Eth-trunk function?
Select 3
Options
A Improve data security
B traffic load sharing
C Improve the communication bandwidth of the link
D Improve the reliability of the link
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

3
Question
What are the load balancing algorithms supported by the USG firewall?
Select 3
Options
A simple polling algorithm (roundrobin)
B weighted rounding algorithm (weightff)
C source address hash algorithm
D ratio (Ratio)
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

4
Question
The PC A in the Trust zone is 192.168.3.1. You cannot access the Internet server in the Untrust zone. The configuration between the Trust zone and the Untrust zone is as follows. What are the most likely causes of the following faults?

Exhibit
Options
A Since the firewall default packet-filter is deny is executed first, the subsequent policies are not executed.
B security policy application direction configuration error, should be outbound
C policy source 192.168.3.0 0.0.0.255 configuration error, need to be modified to policy source 192.168.3.0 0.0.255.255
D policy destination any configuration error, a clear destination IP address must be established
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

5
Question
A certain network is as follows: LAN----G0/0/0 USG G0/0/1 ----Server. After the administrator
analyzes the Attarcker on the LAN network connected to G0/0/0, if you want to prevent ARP flood attacks, limit the ARP traffic to 100 packets/minute. Which is the correct configuration?
Options
A firewall defend arp-flood enable firewall defend arp-flood interface GigabitEthernet 0/0/0 max- rate 6000
B firewall defend arp-flood enable firewall defend arp-flood interface GigabitEthernet 0/0/1 max- rate 6000
C firewall defend arp-flood enable firewall defend arp-flood interface GigabitEthernet 0/0/1 max- rate 100
D firewall defend arp-flood enable firewall defend arp-flood interface GigabitEthernet 0/0/0 max- rate 100
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

Finish Practice?

Are you sure you want to finish? This will end your practice session.