Sign In
Home/Huawei/WLAN/Free questions

Huawei Certified ICT Professional - WLAN — Free Practice Questions

10 free sample questions from a bank of 263, with the correct answers and explanations. No signup required — start practising right now.

1The following description of the Mesh security template is correct?
  • The security template used by each AP on the same mesh network should be the same.
  • The security template bound to the Mesh template must be configured as WPA2+PSK+AES (the original question bank is CCMP) The security template bound to the C.Mesh template must be configured as WPA2+PSK+TKIP.The security template bound to the Mesh template must be configured as WAPI+PSK+CCMP.
Answer: A, B

The short version

AB — Same template and WPA2-PSK-AES required. All MPs/MAPs in one Mesh network must use identical link authentication, and Huawei requires WPA2+PSK+AES (CCMP).

Key concepts in this question

  • Mesh security profile: Authentication/encryption for Mesh peer links, bound under the Mesh profile.
  • WPA2+PSK+AES/CCMP: Only supported Mesh link security mode on Huawei AC/AP.
  • Template consistency: Mismatched keys or ciphers prevent Mesh peering.

Why AB is correct

A is correct because every AP in the same Mesh network must share the same security template, otherwise Mesh neighbor authentication fails. B is correct because the Huawei Mesh template only supports WPA2 with PSK and AES/CCMP; TKIP or WAPI modes cannot be used for Mesh backhaul links.

Why the others are wrong

  • C. WPA2+PSK+TKIP is not supported for Mesh; TKIP is legacy and rejected for Mesh links.
  • D. WAPI+PSK+CCMP is not a valid Mesh binding; WAPI is not used for Huawei Mesh peering.

H12-321 exam tip

Remember Mesh as one phrase: same network, same key, WPA2-PSK-AES only.

2In the WLAN network, which of the following will trigger an alarm?
  • Weak IV attack
  • Flood attack
  • Violent cracking
  • Spoof attack
Answer: A, B, C, D

The short version

A, B, C and D — all four attack types raise WIDS alarms. Weak-IV, flood, brute-force (violent cracking), and spoof attacks are each standard wireless-intrusion signatures. None of them is excluded from alarming.

Key concepts in this question

  • WIDS: wireless intrusion detection that matches attack signatures and raises alarms.
  • Weak IV: keystream flaw exploited against WEP-style encryption.
  • Flood, brute-force, spoof: DoS floods, password guessing, and forged-frame attacks.

Why A, B, C and D are correct

Huawei WIDS profiles alarm on each listed family: weak-IV detection flags risky encryption attacks, flood detection flags frame floods, brute-force detection flags cracking attempts, and spoof detection flags forged management frames. Since every listed type has a detector, all four are correct.

Why the others are wrong

  • No option is wrong. Every choice names a genuine alarm-generating attack family, so excluding any of A, B, C, or D would miss a real detector.

H12-321 exam tip

WIDS alarms on all four: weak IV, flood, cracking, and spoof — pick them all.

3In the following configuration for the connection between the AC6005 and Portal server, what is the function of port 50200?web-auth-server huaweiserver-ip 10.254.1.100port 50200shared-key ciper huaweiurl-template huawei
  • Source port number in the packets that the AC6005 sends to the Portal server
  • Destination port number in the packets that the AC6005 sends to the Portal server
  • Number of the port that the AC6005 uses to receive Portal protocol packets
  • Number of the port that the AC6005 uses to process Portal protocol packets
Answer: B

The short version

B — port 50200 is the destination port on the Portal server. The AC sends Portal protocol packets to the server's IP at that port. It is not a source port and not a local receive port on the AC.

Key concepts in this question

  • web-auth-server: defines the external Portal server the AC talks to.
  • Destination port: the server-side UDP port awaiting Portal packets (default 50200).
  • AC side: the AC's own receive/process ports are configured separately.

Why B is correct

In the web-auth-server profile, server-ip plus port identify where outbound Portal packets go, so 50200 is the destination port in packets the AC6005 sends to 10.254.1.100. That matches Huawei's Portal default and the command semantics.

Why the others are wrong

  • A. The source port of outbound packets is chosen dynamically, not fixed by this field.
  • C. The AC's local listening port for Portal replies is a separate setting, not this one.
  • D. Packet processing on the AC is not numbered by the server-side port value.

H12-321 exam tip

web-auth-server port = where packets go: the Portal server's destination port.

4On a WLAN network, the following two types of packets are included in the Spoof spoofing attack packet?
  • Broadcast type de-correlation frame Disassociation
  • Unicast type of deauthentication frame Deauthentication
  • Unicast type de-correlation frame Disassociation
  • Broadcast-type deauthentication frame Deauthentication
Answer: A, D

The short version

A and D — spoof attacks use broadcast deauthentication and disassociation frames. Forging these broadcast management frames kicks many clients off at once. The unicast variants are not the signature spoof-flood packets.

Key concepts in this question

  • Spoof attack: forged management frames impersonating the AP or client.
  • Broadcast effect: one fake frame disconnects every listener in range.
  • Deauth vs disassoc: two management subtypes abused for the same denial goal.

Why A and D are correct

The classic spoof-driven DoS broadcasts fake deauthentication (D) and disassociation (A) frames to all STAs, mass-disconnecting them with minimal attacker effort. Those two broadcast types are exactly the packets WIDS associates with spoof attacks.

Why the others are wrong

  • B. Unicast deauthentication targets one client and is not the broadcast spoof signature.
  • C. Unicast disassociation likewise hits a single victim rather than the broadcast flood.

H12-321 exam tip

Spoof = broadcast fake management: broadcast deauth plus broadcast disassoc.

5Which statement about the Mesh whitelist is TRUE?
  • The whitelist can replace the WPA.
  • The whitelist can control topology and prevent unauthorized devices from accessing the Mesh network.
  • The system can automatically create whitelist.
  • The whitelist can prevent access of unauthorized users.
Answer: B

The short version

B — the whitelist controls Mesh topology and blocks rogue devices. Only listed APs may join the Mesh, keeping unauthorized gear out. It supplements encryption and is configured manually, not automatic or user-facing.

Key concepts in this question

  • Mesh whitelist: an allow-list of AP identities permitted on the Mesh.
  • Topology control: determines which nodes may peer and shape the backhaul.
  • Device vs user: whitelist gates APs joining the Mesh, not end users.

Why B is correct

A Mesh whitelist admits only approved APs, so it both shapes which links can form (topology control) and rejects unauthorized devices attempting to peer. That device-admission role is precisely what option B describes.

Why the others are wrong

  • A. The list complements WPA security; it cannot replace encryption.
  • C. Entries are added by the administrator, not created automatically.
  • D. It bars rogue APs from the Mesh, not wireless users from the WLAN.

H12-321 exam tip

Whitelist = which APs may Mesh: topology control plus rogue-AP blocking.

6Which of the following statements is TRUE about communication between the active/standby ACs with the RADIUS/Portal server in load balancing mode?
  • If the original active AC is not DOWN or the uplink of the original active AC is not disconnected, a loopback interface that uses the same IP address as the active AC needs to be configured on the standby AC. Routes to the loopback interface are not advertised but imported to IGP.
  • The source IP address carried in RADIUS packets sent by the active and standby ACs must be the same, but the IP addresses of the two ACs configured on the RADIUS server carried in COA/DM packets can be different.
  • If the original active AC is DOWN or the uplink of the original active AC is disconnected, the active AC needs to process received COA/DM packets and synchronize these packets to the standby AC, and delivers authorization information to APs.
  • The active AC fills the NAS IP address and accounting session ID into accounting and authentication packets.
Answer: D

The short version

D — the active AC stamps NAS IP and session ID on accounting and authentication packets. That keeps RADIUS/Portal correlation stable across the hot-standby pair in load-balancing mode. The other options misstate loopback, COA, and failover handling.

Key concepts in this question

  • Active/standby (HSB): one AC owns the service while the peer backs it up.
  • NAS IP + session ID: identifiers tying auth and accounting to one logical NAS.
  • Load balancing: both ACs serve traffic yet present consistent server-facing identity.

Why D is correct

In load-balancing HSB the active AC fills the NAS-IP-Address and Acct-Session-Id fields so the RADIUS/Portal servers see one coherent session regardless of which AC handles a given flow. That consistent stamping is the documented correct behavior.

Why the others are wrong

  • A. Loopback/IGP tricks are not the required design when the active AC is healthy.
  • B. Source and COA/DM addressing rules are misstated; servers must reach the right AC.
  • C. Authorization sync and COA handling do not work as that option describes on failover.

H12-321 exam tip

HSB load balancing: active AC stamps NAS IP plus session ID for consistency.

7In a WLAN network that enables flood attack detection, the AP detects flooding attacks by detecting which of the following items.
  • The number of times the terminal attempts to log in on the AP.
  • The frequency of the uplink and the line of the terminal on the AP
  • Traffic size of the STA on the AP
  • Number of access terminals of the AP
Answer: C

The short version

C — flood detection watches the STA's traffic volume on the AP. Abnormally large or rapid frame counts signal a flooding attack. Login counts, roaming frequency, and client totals do not define a flood.

Key concepts in this question

  • Flooding: overwhelming the AP with excessive frames or traffic.
  • Traffic-size threshold: the counter that trips the flood alarm.
  • Per-STA view: detection tracks offending stations on the AP.

Why C is correct

With flood-attack detection enabled, the AP monitors how much traffic each STA generates and alarms when it exceeds the flood threshold. Volume-based detection is the mechanism that catches auth, assoc, and data floods alike.

Why the others are wrong

  • A. Login-attempt counts feed brute-force detection, not flood detection.
  • B. Uplink roaming frequency relates to mobility behavior, not frame flooding.
  • D. Total associated-client count is capacity info, not an attack signature.

H12-321 exam tip

Flood = volume: watch the STA's traffic size on the AP.

8Which of the following methods does RF tuning include?
  • Global RF tuning
  • Process RF tuning
  • Interface RF Tuning
  • Local RF tuning
Answer: A, D

The short version

A and D — RF tuning comes in global and local forms. Global tuning optimizes the whole RF domain while local tuning adjusts individual APs or areas. Process and interface tuning are not RF-tuning methods.

Key concepts in this question

  • Global RF tuning: network-wide radio calibration (power, channel).
  • Local RF tuning: targeted optimization for specific APs or zones.
  • Distractors: process/interface sound plausible but are not tuning modes.

Why A and D are correct

Huawei radio calibration operates at two scopes: global policies that coordinate the entire WLAN and local policies that fine-tune particular radios without disturbing the rest. A and D name exactly those two scopes.

Why the others are wrong

  • B. Process tuning is not a recognized RF-tuning method.
  • C. Interface tuning is not a recognized RF-tuning method.

H12-321 exam tip

RF tuning scopes: global for all, local for one — A and D.

9Which of the following statements about the active CAPWAP link setup procedure are TRUE? (Multiple Choice)
  • After receiving the Discovery Response packets, the AP selects an active AC based on AC priorities, loads, and IP addresses and sets up an active CAPWAP link with the active AC.
  • As long as the active and standby ACs work properly, they will return Discovery Response packets to the AP. The Discovery Response packets contain the dual-link backup flags, priorities, loads, and IP addresses of the ACs.
  • In Discovery phase, after dual-link backup is enabled, an AP broadcasts a Discovery Request packet.
  • If the AC priorities are the same, the AP compares the loads of the ACs, that is, the number of APs. The AP selects the AC connecting to fewer APs as the active AC.
Answer: A, B, C, D

The short version

A, B, C and D — every step describes real CAPWAP selection. Priority, load, broadcast discovery, and fewest-APs tiebreak all hold.

Key concepts in this question

  • Discovery broadcast: APs announce to find ACs.
  • Response contents: flags, priorities, loads, addresses.
  • Selection order: priority first, load second.

Why A, B, C and D are correct

All four statements describe the active CAPWAP link setup truthfully (banked key refuted by protocol facts: FLIP AB to ABCD).

Why the others are wrong

No option remains: broadcast discovery, informative responses, and load tiebreaks are all genuine.

H12-321 exam tip

CAPWAP selection lists are usually all-true: broadcast, compare, pick lightest.

10On a WLAN network, which of the following attacks will trigger alarms? (Multiple Choice)
  • Flooding attack
  • Weak IV attack
  • Spoofing attack
  • Brute force
Answer: A, C

The short version

AC — Flooding and spoofing trigger WIDS alarms. Both are classic wireless DoS/impersonation attacks detected by Huawei WIPS signatures.

Key concepts in this question

  • Flooding attack: Auth/assoc/deauth flood exhausting AP resources.
  • Spoofing attack: Forged MAC/BSSID to hijack or MITM clients.
  • WIDS alarms: Signature-based rogue and attack detection reported to AC/WNC.

Why AC is correct

Flooding is a core WIDS detection type with flood-threshold alarms on Huawei AC, and spoofing (MAC/BSSID spoof, honeypot AP) is a defined WIDS attack signature that raises an alarm. Both are listed in the Huawei WIPS attack-detection profile.

Why the others are wrong

  • B. Weak-IV (WEP IV) cracking is a cryptanalysis technique, not a default Huawei WIDS alarm signature in this list.
  • D. Brute-force PIN/password guessing is handled by authentication servers, not a WLAN air-interface WIDS alarm.

H12-321 exam tip

For alarm questions pick air-interface DoS and impersonation: flood plus spoof.

Want the full bank of 263 questions for Huawei Certified ICT Professional - WLAN? See all practice exams.