Sign In
Home/Huawei/WLAN Written/Free questions

Huawei Certified ICT Expert - WLAN Written — Free Practice Questions

10 free sample questions from a bank of 83, with the correct answers and explanations. No signup required — start practising right now.

1On a campus network, which of the following problems may occur when you manually create a static VXLAN tunnel? (Select All that Apply)
  • Although the static VXLAN tunnel mode supports the distributed gateway scenario, the configuration involves a heavy workload and is complex to adjust.
  • A static VXLAN tunnel uses related protocols on the control plane, consuming device resources.
  • If N devices need to establish VXLAN tunnels, you need to manually configure the ingress replication list up to N x (N-l)/2 times.
  • Remote MAC addresses can be learned only through data flooding.
Answer: A, C

The short version

A and C — Static VXLAN tunnels scale poorly by hand. Manual peer and replication-list configuration grows quadratically, so large campuses prefer dynamic EVPN control planes.

Key concepts in this question

  • Static VXLAN tunnel: manually configured VTEP peer list with no control-plane protocol for MAC/VNI advertisement.
  • Ingress replication: BUM traffic is unicast-copied to every peer in the replication list.
  • Distributed gateway: each VTEP can act as Layer 3 gateway, multiplying the manual entries needed.

Why A and C are correct

A is correct because even where a static tunnel can support a distributed gateway, every VTEP peer must be hand-configured, which is labor-intensive and error-prone to change. C is correct because a full mesh of N VTEPs needs N x (N-1)/2 tunnel relationships, so the administrator must maintain the ingress replication entries that many times, which explodes as sites are added.

Why the others are wrong

  • B. Static tunnels by definition use no control-plane protocol; protocol resource consumption is a property of dynamic EVPN/BGP, not static mode.
  • D. Flood-based learning of remote MAC addresses is the designed data-plane behavior of static VXLAN, not one of the scaling problems the question targets; the tested problems are workload and replication-list growth.

H12-351 exam tip — static means hand-built mesh

If you see N x (N-1)/2 or heavy manual workload, think static VXLAN; if you see automatic MAC advertisement, think BGP EVPN.

2Inter-WAC roaming and intra-WLAN roaming are supported in dual-link HSB scenarios.
  • FALSE
  • TRUE
Answer: B

The short version

B — TRUE: dual-link HSB keeps both roaming types working. Hot standby preserves user state so clients can roam within one WAC domain and across WACs without re-authentication.

Key concepts in this question

  • HSB (hot standby): two WACs synchronize service state so failover is hitless.
  • Dual-link HSB: APs hold links to both active and standby WACs for fast switchover.
  • Inter-WAC vs intra-WLAN roaming: roaming across controllers versus roaming between APs under one controller.

Why B is correct

B (TRUE) is correct because dual-link HSB synchronizes STA entries, keys, and roaming state between the active and standby WACs. A client roaming between APs on the same WAC (intra-WLAN) is unaffected, and a client moving across WACs (inter-WAC) can continue its session because the standby already holds the user context and takes over cleanly.

Why the others are wrong

  • A. FALSE would mean HSB breaks one of the roaming types, but state backup exists precisely to preserve roaming; nothing in dual-link HSB disables inter-WAC or intra-WLAN handover.

H12-351 exam tip — HSB preserves, never removes, roaming

Associate HSB with state sync: if state is synced, roaming survives; FALSE answers usually describe broken sync, not normal HSB.

3When an 802.IX client uses MDS encryption, the user authentication mode can be set to EAP or CHAP on the device. When an 802. IX client uses PEAP authenticatwn, the user authentication mode can be set to______on the device. (Enter the acronym in uppercase letters.)
  • MSCHAPV2
  • EAP
  • CHAP
  • PAP
Answer: A

The short version

Answer: A – MSCHAPV2 is the user authentication mode for PEAP clients.

Key concepts in this question

802.1X, MDS encryption, PEAP inner authentication, EAP/CHAP/MSCHAPV2 modes.

Why A is correct

PEAP tunnels the inner user authentication, and Huawei devices set the user authentication mode to MSCHAPV2 for PEAP; MDS clients instead use EAP or CHAP.

Why the others are wrong

EAP and CHAP apply to MDS clients, not PEAP inner auth; PAP is not the banked PEAP user-auth mode.

H12-351 exam tip

H12-351 fill-style stems expect exact uppercase acronyms; memorize EAP/CHAP for MDS and MSCHAPV2 for PEAP.

4Multicast addresses are Class D addresses, and can be used only as destination addresses but not source addresses of data packets.
  • FALSE
  • TRUE
Answer: B

The short version

B — TRUE: multicast means Class D and destination-only. Addresses 224.0.0.0-239.255.255.255 identify groups, so they never appear as a packet source.

Key concepts in this question

  • Class D addresses: the 224.0.0.0/4 range reserved for multicast group identifiers.
  • Destination-only semantics: a multicast address names a group of receivers, not a single sender.
  • Source address rule: every IP packet source must be a unicast address of the actual sender.

Why B is correct

B (TRUE) is correct on both claims. Multicast addresses are drawn from Class D (224.0.0.0 through 239.255.255.255), and because they denote a group rather than an interface, standards require them to appear only in the destination field; a host can never legitimately source a packet from a group address.

Why the others are wrong

  • A. FALSE would deny either the Class D mapping or the destination-only rule, but both are textbook facts: Class D is reserved for multicast and group addresses cannot be source addresses.

H12-351 exam tip — group in destination, host in source

Memorize the pair: Class D equals multicast equals never-a-source; any source-address multicast option is automatically wrong.

5After the HTTP domain name is entered in a browser, the user Is not redirected to the Portal URL. Which of the followings is the possible cause for this failure? (Select All that Apply)
  • The DNS server IP address is not added to the authentication-free rule.
  • The URL template is incorrectly configured.
  • HTTPS redirection is disabled.
  • The web server is incorrectly configured.
Answer: A, B, D

The short version

A and B and D — Portal redirect fails on DNS, template, or server errors. Each breaks one link in the resolve, redirect-to-URL, or page-serve chain before the user ever sees login.

Key concepts in this question

  • Authentication-free rule: permits DNS and Portal traffic before the user passes authentication.
  • URL template: defines the Portal redirect address pushed to unauthenticated HTTP users.
  • Portal web server: serves the actual login page after redirection.

Why A and B and D are correct

A is correct because without the DNS server in the free rule, the browser cannot resolve the typed domain and no HTTP request is ever built. B is correct because a wrong URL template redirects to a bad Portal address, so login never displays. D is correct because a misconfigured web server cannot serve the Portal page even when redirection succeeds.

Why the others are wrong

  • C. The user typed an HTTP domain, and HTTP redirection handles that case; disabled HTTPS redirection only breaks direct HTTPS visits, so it cannot explain this HTTP failure.

H12-351 exam tip — trace the three links

Debug Portal as DNS, then redirect URL, then page server; match each failure option to exactly one link.

6Which of the following statements about attack defense is true?
  • Defense against flood attacks can be used to defend against Ping of Death attacks.
  • Attack defense allows APs to analyze the contents and behaviors of incoming packets on ports to determine whether packets have attack characteristics. The APs then take defense measures on the packets that have attack characteristics.
  • Attack defense can defend against spoofing packet attacks, malformed packet attacks, fragmentation attacks, and flood attacks.
  • Fragmentation attack defense enables a device to detect packet fragments in real time and discard or rate-limit them to protect the device.
Answer: B

The short version

B — Attack defense means APs inspect and act on hostile packets. The defining behavior is content and behavior analysis at the AP followed by countermeasures such as discarding.

Key concepts in this question

  • Attack defense: WLAN feature that profiles incoming packets for attack signatures and abnormal behavior.
  • AP enforcement point: APs apply detection and defense actions on access-facing traffic.
  • Attack categories: spoofing, malformed, fragmentation, and flood families handled by specific sub-features.

Why B is correct

B is correct because it states the mechanism Huawei tests: APs analyze packet contents and behaviors on ports, identify characteristics such as spoofing or flooding, and apply defenses to offending packets. It is the only option describing how the feature works rather than asserting a narrow capability mapping.

Why the others are wrong

  • A. Flood defense covers traffic surges, not the crafted oversized packets of Ping of Death, which belong to malformed-packet defense.
  • C. It overclaims a single switch covering every attack family; Huawei implements separate defenses per family.
  • D. It misstates fragmentation defense as generic fragment rate-limiting instead of the specific attack-pattern detection.

H12-351 exam tip — mechanism beats coverage claims

Pick the option describing analyze-then-act on the AP; broad covers-everything options are usually distractors.

7AD authentication integrates Kerberos authentication into LDAP authentication. The basic AD architecture consists of the user, AD client, and AD server. Which of the following are components of an A3 server?
  • Authorization server
  • LDAP server
  • Accounting server
  • Key distribution center
Answer: B, D

The short version

B and D — An AD server is LDAP plus a Kerberos KDC. Directory lookups come from LDAP while tickets and authentication come from the key distribution center.

Key concepts in this question

  • AD authentication: Kerberos authentication layered over LDAP directory services.
  • LDAP server: stores users, groups, and attributes for directory queries.
  • Key distribution center (KDC): Kerberos AS plus TGS that issues ticket-granting and service tickets.

Why B and D are correct

B is correct because the LDAP server provides the directory side of AD: user objects and attribute lookups. D is correct because the KDC provides the Kerberos side: it authenticates principals and issues tickets, which is exactly the Kerberos-into-LDAP integration the stem describes.

Why the others are wrong

  • A. An authorization server belongs to AAA/RADIUS-style policy enforcement, not to the AD server composition tested here.
  • C. An accounting server tracks usage records in AAA architectures; AD authentication relies on directory plus Kerberos, not accounting.

H12-351 exam tip — AD equals directory plus tickets

Remember LDAP holds who users are and the KDC proves it with tickets; authorization and accounting servers are AAA, not AD.

8When planning WLAN outdoor coverage using external 2.4 GHz omnidirectional antennas with 3 dBi gain, what is the recommended coverage radius?
  • 30-50 m
  • 80-100 m
  • 150-200 m
  • 200-250 m
Answer: B

The short version

B — Plan 80-100 m for 2.4 GHz outdoor omni coverage at 3 dBi. That radius balances the band's range against realistic outdoor interference and client power limits.

Key concepts in this question

  • 2.4 GHz propagation: longer range but noisier band than 5 GHz, suited to wide outdoor cells.
  • 3 dBi omnidirectional antenna: modest gain with 360-degree horizontal pattern for open areas.
  • Coverage radius planning: Huawei guideline value used for AP placement and overlap design.

Why B is correct

B is correct because Huawei's WLAN planning guidance gives roughly 80-100 m as the recommended outdoor coverage radius for 2.4 GHz omnidirectional antennas with about 3 dBi gain. It reflects practical throughput at the cell edge rather than theoretical maximum reach.

Why the others are wrong

  • A. 30-50 m is an indoor or 5 GHz small-cell figure, far too conservative for outdoor 2.4 GHz omni coverage.
  • C. 150-200 m exceeds the reliable edge for 3 dBi omni clients and belongs to higher-gain directional designs.
  • D. 200-250 m is only reachable with directional or high-gain antennas, not a 3 dBi omnidirectional.

H12-351 exam tip — pair band, antenna, and distance

Lock the triple: outdoor 2.4 GHz plus 3 dBi omni equals 80-100 m; shrink it for 5 GHz or indoor walls.

9In on-demand routing mode on a mesh network, which of the fallowing types of frames is broadcast by the source node to establish a route to the destination node?
  • PREQ
  • DHCP
  • DNS
  • PREP
Answer: A

The short version

A — The source broadcasts PREQ to discover the mesh path. Path Request frames flood outward, and the destination answers to build the on-demand route.

Key concepts in this question

  • On-demand (reactive) routing: routes are discovered only when traffic needs them, as in HWMP/AODV-style mesh.
  • PREQ: Path Request frame broadcast by the source seeking the destination.
  • PREP: Path Reply frame unicast back to confirm the selected route.

Why A is correct

A is correct because in on-demand mesh routing the source has no prebuilt path, so it broadcasts a PREQ that propagates through neighbors until it reaches the destination (or a node with a fresh route), which then returns a reply and establishes forwarding entries along the way.

Why the others are wrong

  • B. DHCP assigns addresses and has no role in mesh path discovery.
  • C. DNS resolves names to addresses and is never the route-discovery frame.
  • D. PREP is the reply, sent after discovery toward the source, not the broadcast that starts it.

H12-351 exam tip — Q broadcasts, P answers

Mnemonic: PREQ equals question flooded everywhere, PREP equals private reply back to the source.

10Which of the following statements are true about Huawei ' s smart roaming solution?
  • In common coverage scenarios, STAs with poor signal strength are steered to APs with better signal strength, improving service experience for users and overall channel performance.
  • The smart roaming solution resolves the sticky STA problem and enables STAs to proactively roam to the optimal AP.
  • Smart roaming enables each STA to associate with the nearest AP.
  • In high-density coverage scenarios, STAs generally have good signals. Smart roaming can enable STAs to associate with APs that have better signals, significantly improving channel performance.
Answer: A, B

The short version

A and B — Smart roaming cures sticky clients by steering them. Weak-signal STAs are guided to better APs so they roam proactively instead of clinging to a bad cell.

Key concepts in this question

  • Sticky STA problem: clients cling to their original AP even after a better AP is available.
  • Smart roaming steering: the network nudges eligible STAs toward the optimal AP.
  • Channel performance: moving poor-signal clients away raises overall airtime efficiency.

Why A and B are correct

A is correct because in overlapping coverage the solution steers low-signal STAs to stronger APs, lifting both user experience and channel utilization. B is correct because that steering is precisely the fix for stickiness: instead of waiting for the client to decide, the network enables proactive roaming to the optimal AP.

Why the others are wrong

  • C. Association targets the optimal AP by signal, load, and capability, not strictly the geographically nearest one.
  • D. In high-density areas signals are already good, so gains come from load and band balancing rather than simply chasing better signal.

H12-351 exam tip — sticky means steer

Any option about fixing stickiness or steering weak clients to better APs is core smart roaming; nearest-AP wording is the trap.

Want the full bank of 83 questions for Huawei Certified ICT Expert - WLAN Written? See all practice exams.