[Q61-Q86] Best Quality Huawei H12-723-ENU Exam Questions ValidBraindumps Realistic Practice Exams [2021]

Share

Best Quality Huawei H12-723-ENU Exam Questions ValidBraindumps Realistic Practice Exams [2021]

Critical Information To HCIP-Security-CTSS(Huawei Certified ICT Professional -Constructing Terminal Security System) Pass the First Time

NEW QUESTION 61
The AD/LDAP account can be synchronized to Agile Controller-Campus or not to Agile Controller-Campus. The synchronization to Agile Controller-Campus can only be authorized by the user group. If it is not synchronized to Agile Controller-Campus, it can be based on account authorization.

  • A. False
  • B. True

Answer: A

 

NEW QUESTION 62
The visitor management process includes page customization, account application, user authentication, auditing and logout. After the user successfully applies for an account, the user needs to distribute the account to the user. Which stage of the account distribution?

  • A. Page customization phase
  • B. Account application stage
  • C. User authentication stage
  • D. Audit and cancellation stages

Answer: B

 

NEW QUESTION 63
In some scenarios, anonymous accounts can be used for authentication. Which are correct for anonymous account? (Multiple choices)

  • A. By default, anonymous account access control, policy/patching template invocation and software distribution can't be performed.
  • B. The administrator can't delete the anonymous account "~anonymous".
  • C. The "~anonymous" account needs to be manually created on Agile Controller-Campus.
  • D. Use anonymous account for authentication is based on the belief that the certification authority does not require the other party to provide identity information and provide services to the other party.

Answer: B,D

 

NEW QUESTION 64
Security authentication mainly implements security checks on access users through security policy. Terminal host security management is mainly implemented by check-type policy. End-user behavior management is mainly implemented by monitoring policy. If the user needs to formulate strategy according to his own custom strategy.

  • A. True
  • B. False

Answer: A

 

NEW QUESTION 65
Which of the following is correct for the roles of Portal authentication system?

  • A. The role of the admission control device is to complete the user's authentication, authorization and accounting.
  • B. The role of RADIUS server is to redirect all HTTP requests from users in the authentication network segment to the Portal server.
  • C. The role of portal server is to receive the client authentication request, provide free portal service and authentication interface and interact with the access device to authenticate the client.
  • D. The client is Any Office software.

Answer: C

 

NEW QUESTION 66
BYOD solution provide products and systems cover terminals, networks, security, application and management, include serialized BYOD devices, wireless network systems, network access security, VPN gateways, terminal security client software, authentication systems, mobile device management (MDM), mobile eSpace UC, etc.

  • A. True
  • B. False

Answer: A

 

NEW QUESTION 67
Which of the following series of devices does not support the free mobility feature?

  • A. SVN5600 series
  • B. S5720HI Series Switches
  • C. AR Series Routers
  • D. USG6000 Series Firewalls

Answer: C

 

NEW QUESTION 68
Which of the following options can't trigger MAC authentication?

  • A. DHCP packets
  • B. ICMP packets
  • C. ARP packets
  • D. DHCPv6 packets

Answer: B

 

NEW QUESTION 69
Which of the following statements is wrong about use MAC authentication to access network in WLAN networking environment?

  • A. MAC authentication does not require the user to install any client software.
  • B. MAC bypass authentication resolves both 802.1X client authentication and MAC authentication in the same network environment.
  • C. MAC authentication actually use 802.1X authentication method.
  • D. User name format used for MAC authentication there is only one MAC address user name format.

Answer: D

 

NEW QUESTION 70
In Agile Controller-Campus admission control scenario, which of the following is correct about RADIUS server/client role?

  • A. The authentication device (such as 802.1X switch) serves as RADIUS server and the user terminal serves as RADIUS client.
  • B. Agile Controller-Campus acts as RADIUS server and the authentication device (such as 802.1X switch) acts as RADIUS client.
  • C. Agile Controller-Campus serves as RADIUS server and the user terminal serves as RADIUS client.
  • D. Agile Controller-Campus integrates all the functions of RADIUS server and client.

Answer: B

 

NEW QUESTION 71
A Layer 3 forwarding device exists between the authentication client and the admission control device. In this case, if the Layer 3 authentication mode of Portal authentication is adopted, the device can also obtain the MAC address of the authentication client. Therefore, the IP address and MAC address can be used as the same to identify the user's information.

  • A. False
  • B. True

Answer: A

 

NEW QUESTION 72
Location refers to the terminal environment when terminal user use AC-Campus to access controlled network.
Which of the following about the location is correct?

  • A. Different locations can have different security strategy.
  • B. There is no relationship between locations.
  • C. There can only be one location in the company.
  • D. There is no relationship between location and safety.

Answer: A

 

NEW QUESTION 73
The free mobility is a special access control method. According to the user's access point, access time, access method and user terminal specified permission is granted. From the physical connection, the access method can be divided into 3 categories, which of the following access methods not include?

  • A. Wired access
  • B. Wireless access
  • C. 802.1X access
  • D. VPN access

Answer: C

 

NEW QUESTION 74
Which of the following devices is suitable for MAC authentication access network?

  • A. Network printer
  • B. Mobile clients, such as smart phones, etc.
  • C. Linux system host for testing
  • D. Windows System Host for Office

Answer: A

 

NEW QUESTION 75
Identity authentication determines whether to allow access by identifying the access device or user.

  • A. True
  • B. False

Answer: A

 

NEW QUESTION 76
Mobile smart phone and tablet users establish IPSec encryption tunnel with AE through Any Office client. After passing authentication and compliance checks, they access enterprise services.

  • A. False
  • B. True

Answer: A

 

NEW QUESTION 77
In 802.1X authentication, if the authentication point is at the aggregation layer switch, which special configurations are required in addition to the conventional configurations such as RADIUS, AAA and 802.1X?

  • A. The access layer switch needs to configure transparent transmission of 802.1X packets.
  • B. The aggregation layer switch needs to configure transparent transmission of 802.1X packets.
  • C. The 802.1X function needs to be enabled on both aggregation layer and access layer switch.
  • D. No special configuration is required.

Answer: A

 

NEW QUESTION 78
Which of the following correct for MAC authentication and MAC bypass authentication? (Multiple choices)

  • A. MAC bypass authentication first 802.1X authentication is performed on the device that accesses the device. If the device does not respond to 802.1X authentication, the device uses MAC to authenticate the device.
  • B. MAC address is not used as the user name and password to automatically access the network during MAC bypass authentication.
  • C. MAC authentication is an authentication method that controls the user's network access rights based on the interface and MAC address. It does not require the user to install any client software.
  • D. During the MAC authentication process, the user needs to manually enter the user name or password.

Answer: A,C

 

NEW QUESTION 79
The Portal server can be an independent entity (external Portal server) outside the access device, or it can be an embedded entity (built-in Portal server) that exists in the access device.

  • A. True
  • B. False

Answer: A

 

NEW QUESTION 80
If automatic account lockout function is enabled on Agile Controller-Campus and the account IP/MAC address is bound, if the number of wrong passwords entered during the end user authentication exceeds the limit within limited time, which of the following descriptions are correct? (Multiple choices)

  • A. When the account is locked, only the account can't be authenticated on the bound terminal device. Normal authentication can be performed on other terminal devices.
  • B. After the lockout time expires, the account lockout is automatically released.
  • C. If you want to unlock the account, only the administrator can delete the account from the list.
  • D. This account is locked on all terminal devices and can't be authenticated.

Answer: A,B

 

NEW QUESTION 81
Regarding the definition of WIPS/WIDS, which of the following statements is correct?

  • A. WIDS is a wireless intrusion prevention system
  • B. WIPS is wireless intrusion detection system
  • C. WIPS is wireless intrusion prevention system
  • D. WIDS is wireless intrusion countermeasure system

Answer: C

 

NEW QUESTION 82
When hardware SACG is used for authentication, after SACG configuration is complete, you can see that the association between SACG and Agile Controller-Campus succeeds, but the user authentication fails. This phenomenon may be caused by which of the following reasons? (Multi-selection)

  • A. There is no shutdown state detection on SACG.
  • B. User traffic did not pass SACG.
  • C. The key configuration error on Agile Controller-Campus is related to SACG.
  • D. User traffic is not released on SACG.

Answer: A,D

 

NEW QUESTION 83
Which of the following is not supported by the business?

  • A. Teamwork office.
  • B. Implement communication between devices.
  • C. When traveling user accesses the intranet resources, the traveling user accesses the intranet through VPN.
  • D. Intranet users access the data center/Internet.

Answer: B

 

NEW QUESTION 84
Which of the following options are correct for guest management descriptions? (Multiple choices)

  • A. Guest account approval information can notify visitors via SMS
  • B. Guest authentication page cannot be used for anonymous account authentication
  • C. Guest registration accounts can be configured for approval
  • D. Guest login can only be configured as a web page

Answer: A,C

 

NEW QUESTION 85
Which of the following statements is true about the description of ACL used by SACG devices and TSM systems?

  • A. The default ACL rule group number can only be 3999.
  • B. Because SACG needs to use ACL 3099 to 3999 to receive the rules delivered by TSM system, you must first ensure that these ACL are not referenced by other functions before configuring TSM linkage.
  • C. TSM linkage can be successfully enabled even if ACL with the original group number 3099 to 3999 is occupied.
  • D. The default ACL rule group number can be arbitrarily specified.

Answer: B

 

NEW QUESTION 86
......

H12-723-ENU EXAM DUMPS WITH GUARANTEED SUCCESS: https://www.validbraindumps.com/H12-723-ENU-exam-prep.html