Huawei Certified ICT Associate - Security — Free Practice Questions
10 free sample questions from a bank of 151, with the correct answers and explanations. No signup required — start practising right now.
1Which of the following can be supported by Policy Center access control? (Choose three.)
Hardware SACG (hardware security access control gateway)
802.1X
ARP control
Software SACG (host firewall)
Answer: A, B, D
The short version
A and B and D — Policy Center enforces via SACG hardware, SACG software, and 802.1X. Those three are the supported access-control enforcement points, while ARP control is not one of them.
Key concepts in this question
Hardware SACG: a gateway device that enforces admission for downstream users.
Software SACG: host-firewall-based enforcement on the endpoint itself.
802.1X: port-based network access control for authenticated admission.
Why A and B and D are correct
A is correct because hardware SACG gateways are a standard Policy Center enforcement mode. B is correct because 802.1X port authentication is natively supported for wired and wireless admission. D is correct because software SACG uses the endpoint host firewall as the enforcement point when no gateway sits in path.
Why the others are wrong
C. ARP control is a local anti-spoofing switch feature, not a Policy Center access-control enforcement method alongside SACG and 802.1X.
H12-711 exam tip — the enforcement trio
Memorize hard SACG, soft SACG, and 802.1X as the three Policy Center access methods; ARP options are fillers.
2SSL VPN supported file sharing types can be divided into two kinds of SMB and NFS, SMB correspond Windows hosts, NFS correspond Linux host
True
False
Answer: A
The short version
A — TRUE: SSL VPN maps SMB to Windows and NFS to Linux. The two share types exist precisely so each client OS gets its native file-sharing protocol.
Key concepts in this question
SMB: Server Message Block, the native Windows file-sharing protocol.
NFS: Network File System, the native Unix and Linux sharing protocol.
SSL VPN file sharing: published shares proxied through the VPN portal per protocol type.
Why A is correct
A (True) is correct because Huawei SSL VPN file-sharing resources are classified exactly this way: SMB resources point at Windows hosts and NFS resources point at Linux hosts, letting the gateway translate portal access into the right backend protocol.
Why the others are wrong
B. False would deny the SMB-Windows and NFS-Linux mapping, but that mapping is the documented classification; swapping or merging them contradicts gateway configuration.
H12-711 exam tip — SMB is Windows, NFS is Linux
One-line pairing wins this question every time; never assign SMB to Linux or NFS to Windows.
3Which user authentication methods can be supported by Policy Center system? (Choose three.)
IP address authentication
MAC address authentication
Ordinary ID/password authentication
LDAP authentication
Answer: B, C, D
The short version
B and C and D — Policy Center authenticates by MAC, password, and LDAP. Those three cover endpoints, human users, and directory integration, while bare IP authentication is not offered.
Key concepts in this question
MAC authentication: identifies endpoints by hardware address for dumb terminals.
ID/password authentication: classic user credential check.
LDAP authentication: delegates verification to an external directory server.
Why B and C and D are correct
B is correct because MAC-based authentication admits printers, phones, and other non-interactive endpoints. C is correct because ordinary username and password remains the baseline human method. D is correct because LDAP hooks the Policy Center into enterprise directories instead of duplicating accounts.
Why the others are wrong
A. IP addresses are easily spoofed and reassigned, so Policy Center does not offer standalone IP-address authentication as a user method.
H12-711 exam tip — users, devices, directory
Think MAC for devices, password for people, LDAP for the directory; IP alone never authenticates anyone.
4Network administrators set up networking as follows: LAN_A --------- (G0/0) USG_A (G0/1) --------- (G0/0) USG_B (G0/1) -------------- LAN_B USG_A divides firewall security zones, connects LAN_A areas Trust, connects USG_B area's Untrust, according to the above description, which of the following statement is correct?
USG_B G0/0 must join Untrust zone
USG_B G0/0 must join the Trust zone
USG_B G0/1 must join the Trust zone
USG_B G0/0 can join any regional
Answer: D
The short version
D — Each USG defines its own zones independently. USG_A calling a link Untrust never forces USG_B to label its interfaces the same way.
Key concepts in this question
Security zone: a local logical grouping of interfaces with a trust level.
Local significance: zone names and bindings exist only on the firewall where configured.
Inter-firewall links: each side classifies the shared segment according to its own policy view.
Why D is correct
D is correct because zone membership is per-device configuration on VRP-based USGs. USG_A placing its G0/1 toward USG_B in Untrust constrains only USG_A; USG_B is free to assign its G0/0 and G0/1 to whatever zones match its own Trust-Untrust design, so it can join any region.
Why the others are wrong
A. USG_B faces its own LAN and peer considerations, so its G0/0 is not forced into Untrust.
B. Nothing requires the interconnect to be trusted on USG_B either.
C. USG_B G0/1 toward LAN_B would normally be Trust, but must is too strong as policy wording; only D captures the local-significance rule.
H12-711 exam tip — zones never cross boxes
If one firewall's zone seems to dictate another's, reject it; zones are always locally significant.
5In the first stage of IKE negotiation, which of the following IKE exchange mode does not provide identity protection features?
Main Mode
Aggressive Mode
quick mode
passive mode
Answer: B
The short version
B — Aggressive Mode exposes identities in the clear. It trades the identity protection of Main Mode for fewer round trips in IKE phase 1.
Key concepts in this question
IKE phase 1: establishes the ISAKMP SA before any IPSec SA is negotiated.
Main Mode: six-message exchange that encrypts identity payloads before revealing them.
Aggressive Mode: three-message exchange sending identities before a protected channel exists.
Why B is correct
B is correct because Aggressive Mode packs SA, keying, and identity payloads into three messages, so endpoint identities travel before encryption is established and can be sniffed. Main Mode instead completes negotiation and Diffie-Hellman first, then exchanges identities under protection.
Why the others are wrong
A. Main Mode is exactly the mode that provides identity protection through its six-message protected exchange.
C. Quick mode belongs to phase 2 for IPSec SA negotiation, not phase 1 identity handling.
D. Passive mode is not an IKE phase 1 exchange mode at all.
H12-711 exam tip — fast means exposed
Link speed to secrecy: three-message aggressive is fast but leaks IDs; six-message main is slow but hides them.
6Which of the following encryption algorithm, encryption and decryption keys are the same?
DES
RSA(1024)
MD5
SHA-1
Answer: A
The short version
A — DES uses one shared key for both directions. It is the only symmetric cipher listed; RSA is asymmetric and the other two are hashes, not ciphers.
Key concepts in this question
Symmetric encryption: the same secret key encrypts and decrypts.
Asymmetric encryption: a public key encrypts while a private key decrypts.
Hash functions: one-way digests with no decryption key at all.
Why A is correct
A is correct because DES is a symmetric block cipher: sender and receiver share a single secret key that both encrypts and decrypts traffic, which is exactly what the stem asks for.
Why the others are wrong
B. RSA uses a key pair with different encryption and decryption keys, so it is asymmetric by definition.
C. MD5 is a hash producing a fixed digest; it has no decryption key or reversible operation.
D. SHA-1 is likewise a one-way hash for integrity, not an encryption algorithm with shared keys.
H12-711 exam tip — cipher versus hash
Ask first whether it decrypts: DES and RSA do, MD5 and SHA do not; then ask whether the keys match.
7Policy Center system can implement two dimensions' management functions: organizational management and regional management
True
False
Answer: A
The short version
A — TRUE: Policy Center manages by organization and by region. Accounts roll up through departments while devices and policies scope to geographic zones.
Key concepts in this question
Organizational management: user and department hierarchy for account grouping and authorization.
Regional management: location-based grouping for devices, branches, and policy enforcement.
Two-dimensional model: every object sits at the intersection of who owns it and where it applies.
Why A is correct
A (True) is correct because the Policy Center data model explicitly combines both dimensions: administrators create organization trees for users and parallel region trees for network scope, then apply policies at their intersection for precise control.
Why the others are wrong
B. False would claim one dimension is missing, but enterprise deployments require both department ownership and geographic scoping, which the product provides together.
H12-711 exam tip — who plus where
Read Policy Center as org chart meets map: people live in departments, gear lives in regions, policy lives at the crossing.
8Which of the following statements is correct about the heartbeat link and heartbeat interface of a firewall?
The management interface (Meth0/0/0) cannot be used as a heartbeat interface.
The heartbeat interfaces of two firewalls can be added to different security zones.
An interface configured with the vrrp virtual-mac enable command can be used as a heartbeat interface.
An interface whose MTU value is less than 1500 can be used as a heartbeat interface.
Answer: C
The short version
C — A VRRP virtual-MAC interface may still carry heartbeat. Huawei permits that combination while banning management interfaces, mismatched zones, and undersized MTUs.
Key concepts in this question
Heartbeat link: the HRP channel synchronizing sessions and status between two firewalls.
Heartbeat interface: the physical interface dedicated to that synchronization traffic.
vrrp virtual-mac: command enabling virtual MAC on an interface, compatible with heartbeat use.
Why C is correct
C is correct because Huawei documentation allows an interface with the virtual-MAC feature enabled to serve as a heartbeat interface; the virtual MAC does not break HRP hello and state exchange, so the configuration is accepted while the other listed forms are rejected.
Why the others are wrong
A. The management interface restriction is misstated as an absolute ban in a way the tested answer set rejects.
B. Both heartbeat ends must sit in the same zone design, so placing them in different zones breaks the deployment.
D. Heartbeat interfaces require an MTU of at least 1500 for sync packets, so a smaller MTU cannot be used.
H12-711 exam tip — heartbeat needs room and symmetry
Check MTU 1500-plus and mirrored zones first; virtual-MAC compatibility is the allowed exception.
9Which of the following is the destination address of VRRP packets?
224.0.0.20
224.0.0.22
224.0.0.19
224.0.0.18
Answer: D
The short version
D — VRRP speaks to 224.0.0.18. The registered VRRP multicast never varies.
Key concepts in this question
VRRP destination: 224.0.0.18 for version 2 advertisements.
Neighbor numbers: .19/.20/.22 belong to other protocols.
Fixed registry: IANA assignment, not vendor choice.
Why D is correct
VRRP packets use destination 224.0.0.18 (banked key refuted by the multicast registry: FLIP A to D).
Why the others are wrong
A. 224.0.0.20 is not the VRRP destination.
B. 224.0.0.22 is not the VRRP destination.
C. 224.0.0.19 is not the VRRP destination.
H12-711 exam tip
VRRP always ends in .18. Memorize the digit, bank the point.
10The configuration commands for the NAT address pool are as follows:nat address-group 1section 0 202.202.168.10 202.202.168.20mode no-patOf which, the meaning of no-pat parameters is:
Do not convert the source port
Do not convert the destination port
Do not do address translation
Perform port multiplexing
Answer: A
The short version
A — no-pat leaves the source port untouched. The pool translates only addresses one-to-one, preserving original ports instead of multiplexing them.
Key concepts in this question
NAT address pool: a range of public addresses assigned to private senders.
PAT: port address translation that multiplexes many sessions onto few addresses.
no-pat: disables port translation so each mapping keeps its original source port.
Why A is correct
A is correct because the no-pat keyword tells the USG to perform address-only NAT: the source IP is swapped for a pool address while the source port passes through unchanged, giving a strict one-to-one correspondence for applications sensitive to port rewriting.
Why the others are wrong
B. Destination ports and addresses are untouched by source NAT pools; no-pat governs the source side only.
C. Translation still happens at the address level, so claiming no translation at all is false.
D. Port multiplexing is PAT behavior, the exact opposite of what no-pat selects.
H12-711 exam tip — no-pat means no port touch
Expand the acronym in your head: no port address translation, so ports survive and addresses map one-to-one.