
[2021] H12-723 PDF Questions - Perfect Prospect To Go With TestBraindump Practice Exam
Huawei H12-723 Pdf Questions - Outstanding Practice To your Exam
NEW QUESTION 23
Which of the following are correct when deploy BYOD system adopt distributed deployment? (Multiple selection)
- A. The database, SM server and SC server are all installed on one server.
- B. Any Office server is deployed in Trust zone.
- C. AE server needs to provide external interfaces. Therefore, it is recommended that deploy in Untrust zone of the egress firewall.
- D. In the distributed networking, the database and SM server are only installed in the corporate headquarters, SC server and AE server are installed in the corporate headquarters and branches.
Answer: B,D
NEW QUESTION 24
Agile Controller-Campus product architecture includes three levels. Which of the following does not belong to product architecture hierarchy?
- A. Server layer
- B. Network device layer
- C. User access layer
- D. Admission control layer
Answer: D
NEW QUESTION 25
When all services are allocated according to the user group, account number and terminal IP address range, if the same service is assigned to the user group, account number and terminal IP address range (except the announcement service), the business assigned by the highest priority will take effect.
About the order of priorities, which of the following is correct?
- A. User Group> Terminal IP Address Range> Account
- B. Account> User Group> Terminal IP Address Range
- C. Terminal IP Address Range> Account> User Group
- D. Account> Terminal IP Address Range> User Group
Answer: D
NEW QUESTION 26
After successful installed Agile Controller-Campus in Windows environment, how to manually start the Management Center (MC)?
- A. Select "Start> All Programs> Huawei> Agile Controller> Server Startup Config" to manually start the required components.
- B. Double-click "Start Server" shortcut on the desktop to start it.
- C. Select "Start> All Programs> Huawei> MCServer> Server Startup Config" to manually start the required components.
- D. Select "Start> All Programs> Huawei> MCServer> Start Server".
Answer: B,D
NEW QUESTION 27
The admission control server is the implementer of the enterprise security policy and is responsible for implementing the corresponding admission control (allow, deny, quarantine, or restrict) according to the security policy formulated by the customer network.
- A. False
- B. True
Answer: A
NEW QUESTION 28
Business entourage is a special access control method. According to the user's access point, access time, access method and user terminal specified permission is granted. As long as the user access conditions remain unchanged, the permissions and network experience after accessing the network are the same.
- A. True
- B. False
Answer: A
NEW QUESTION 29
Which of the following descriptions is wrong for the basic principle of user access security?
- A. The terminal device selects the resource to be accessed according to the result of the status check
- B. The terminal device directly interacts with the security policy server. The terminal reports its own status information, including the virus database version, operating system version and patch version installed on the terminal.
- C. The security policy server checks the terminal status information. For terminal devices that do not meet enterprise security standards, the security policy server re-issues authorization information to the access device.
- D. When terminal device accesses the network, it first authenticates the user through the access device, and the access device cooperates with the authentication server to complete the user identity authentication.
Answer: A
NEW QUESTION 30
In the terminal host check class policy, you can control the access of the terminal host by checking whether the important subkeys and keys of the registry meet the requirements. Which of the following check results are recorded as violations? (Multiple choices)
- A. The registry contains the "subkeys and key values" enforced by this policy.
- B. The registry does not include the "subkeys and key values" enforced by this policy.
- C. The registry does not "subkeys and key values" prohibited by this policy.
- D. The registry contains "subkeys and key values" prohibited by this policy.
Answer: B,D
NEW QUESTION 31
A network use Portal authentication, when the user accesses, he finds that the user name/password is not entered in the pushed Web page.
This fault may be caused by which reason?
- A. Push page error on portal server.
- B. Switch AAA configured wrong.
- C. There is no corresponding user on Agile Controller-Campus.
- D. The switch does not enable Portal function.
Answer: A
NEW QUESTION 32
Which of the following descriptions is correct for distributed deployment scenario for an authentication server?
- A. Scenarios where the number of users in branches is less than 2,000 and the network between the headquarters and branches is relatively stable.
- B. The terminal security management services between the branches and the headquarters are relatively independent, and the headquarters provides monitoring and recommendation scenarios for the terminal security management services of the branches.
- C. The quality of the network between the branch office and the headquarters is difficult to guarantee. The network between the headquarters and the branch office may be interrupted, making the terminal of the branch office unable to connect to the data center of the headquarters.
- D. The enterprise network is relatively decentralized. There are multiple branches and the users of the branches are large.
Answer: C,D
NEW QUESTION 33
A company with relatively strict end-host access control management, the administrator wants to bind the terminal host and account so as to avoid end users from access the controlled network from non-authorized terminal hosts.
Which of the following is correct of the bound terminal host and account?
- A. When other accounts need to be authenticated on the bound terminal host, they do not need to find the owner of the asset bound for the first time to authorize themselves.
- B. The bound terminal host and account are only applicable to the scenario where the terminal user authenticates through Any Office. The authentication through Web Agent plug-in and Web client is not applicable.
- C. When AnyOffice logs in use an account for the first time, the terminal host automatically binds the current account, but the automatic binding process requires administrator approval.
- D. There is only one terminal host bound to the account and can't be configured by the administrator.
Answer: B
NEW QUESTION 34
Which of the following is correct about the authentication method and authentication type?
- A. Users can use the web method to support both local authentication and digital certificate authentication.
- B. Users can use the web agent mode to support both digital certificate authentication and system authentication.
- C. Users can use the Agent mode to support three authentication types: local authentication, digital certificate authentication and system authentication.
- D. Users can use the web agent method to support both digital certificate authentication and local authentication.
Answer: C
NEW QUESTION 35
Which of the following is true about uninstall Agile Controller-Campus on Windows and Linux systems?
- A. Run sh uninstall.sh to start uninstall program use the common account in Agile Controller/Uninstall directory.
- B. Windows platform, select Start> All Programs> Huawei> Agile Controller> Uninstall.
- C. Windows platform, select Start> All Programs> Huawei> Agile Controller> Server Startup config.
- D. Run sh uninstall.sh to start uninstall process use the root account in Agile Controller directory.
Answer: B
NEW QUESTION 36
Which of the following belong to the third-party server account? (Multiple choices)
- A. Mobile certificate account
- B. AD account
- C. Guest account
- D. Anonymous account
Answer: A,B
NEW QUESTION 37
On the campus network, employees can use 802.1X, Portal, MAC address, or SACG. According to different needs, different methods are used to access and achieve the purpose of user access control.
- A. True
- B. False
Answer: A
NEW QUESTION 38
In some scenarios, anonymous accounts can be used for authentication. Which are correct for anonymous account? (Multiple choices)
- A. By default, anonymous account access control, policy/patching template invocation and software distribution can't be performed.
- B. The administrator can't delete the anonymous account "~anonymous".
- C. The "~anonymous" account needs to be manually created on Agile Controller-Campus.
- D. Use anonymous account for authentication is based on the belief that the certification authority does not require the other party to provide identity information and provide services to the other party.
Answer: B,D
NEW QUESTION 39
Which of the following are correct about 802.1X access process? (Multiple choices)
- A. Use MD5 algorithm to verify the information.
- B. Throughout the authentication process, the terminal exchanges information through the server and EAP packets.
- C. The terminal exchanges EAP packets with the 802.1X switch. The 802.1X switch and the server use Radius packets exchange information.
- D. 802.1X authentication does not require security policy checks.
Answer: A,C
NEW QUESTION 40
Use hardware SACG access control, the result of viewing the session table on hardware SACG is as follows:
<FW>display firewall session table verbose:
tcpVPN: public-->public
Zone: untrust-->trust TTL: 00:10:00 Left: 00:05:27
Interface: GigabitEthernet0/0/1 NextHop:192.168.200.11 MAC:00-0c-29-d4-47-d2
<--packets: 316ytes:9516-->packets:33bytes:17277
192.168.0.119:1574-->192.168.200.11:15080
tcpVPN: public-->public
Zone: untrust-->trust TTL: 00:10:00 Left: 00:02:20
Interface: GigabitEthernet0/0/1 NextHop:192.168.100.1 MAC: 00-0c-29-a4-37-c2
<--packets:31bytes:9516-->packets:336ytes:17277
192.168.0.119:1671-->192.168.100.1:8443
Which of the following statements are correct? (Multiple choices)
- A. If 192.168.200.11 is the server in the post-authentication domain, then the terminal with the IP address 192.168.0.119 may access the server if it is not authenticated.
- B. If the session 192.168.0.119:1574-->192.168.200.11:15080 is not refreshed within 6 minutes, the IP address is 192.168.0.119. If the device wants to communicate with the device whose IP address is 192.168.200.11, must must reestablish the session.
- C. 192.168.100.1 must be the controller IP address of Agile Controller-Campus.
- D. 192.168.100.1 must be the manager IP address of Agile Controller-Campus.
Answer: A,B,D
NEW QUESTION 41
Portal authentication is used on the terminal to access the network. However, it is not possible to jump to the authentication page. The possible reasons do not include which of the following options?
- A. When the page is customized, the preset template is used.
- B. SC did not start.
- C. Portal authentication parameters configured on Agile Controller-Campus are inconsistent with the access control devices.
- D. The authentication port number configured on the access device Portal profile is 50100, default on Agile Controller-Campus.
Answer: A
NEW QUESTION 42
Visitors refer to users who need temporary access to the network in a specific location.
- A. True
- B. False
Answer: A
NEW QUESTION 43
According to the format and content of the user name used by the access device to verify the identity of the user, the user name format used for MAC authentication can be divided into three types. Which of the following formats is not included?
- A. ARP option format
- B. DHCP option format
- C. MAC address format
- D. Fixed username form
Answer: A
NEW QUESTION 44
Which deployment mode does Agile Controller-Campus not support?
- A. Distributed deployment
- B. Two-machine deployment
- C. Centralized deployment
- D. Hierarchical deployment
Answer: B
NEW QUESTION 45
Which of the following are correct for Any Office solution content? (Multiple choices)
- A. Application rapid integration can be extended.
- B. Provide a unified security portal for enterprise mobility applications on mobile devices.
- C. The tunnel is dedicated and viruses can't intrude.
- D. Quickly integrate and interface with enterprise application cloud platform.
Answer: A,B,C,D
NEW QUESTION 46
Which of the following is true about software SACG and hardware SACG?
- A. Software SACG use Any Office for admission control.
- B. Hardware SACG use Any Office for admission control.
- C. Hardware SACG save costs compared to software SACG.
- D. Hardware SACG is more secure.
Answer: A
NEW QUESTION 47
......
Online Questions - Outstanding Practice To your H12-723 Exam: https://www.testbraindump.com/H12-723-exam-prep.html
