Huawei Certified ICT Professional - Security — Free Practice Questions
10 free sample questions from a bank of 90, with the correct answers and explanations. No signup required — start practising right now.
1Which of the following statement is correct about VRRP packet?
The destination address of VRRP packet is 224.0.0.18
VRRP packets are unicast packets
VRRP uses UDP packets
VRRP uses TCP packets
Answer: A
The short version
A — VRRP packets go to multicast 224.0.0.18. That group address lets all candidate routers hear advertisements without any unicast or transport-layer setup.
Key concepts in this question
VRRP: gateway redundancy protocol where master and backups exchange advertisements.
Destination 224.0.0.18: the reserved multicast group every VRRP router joins.
IP protocol 112: VRRP rides directly on IP, not on UDP or TCP.
Why A is correct
A is correct because RFC 3768 and Huawei VRP implementations send VRRP advertisements to the reserved multicast address 224.0.0.18, so every backup on the LAN receives master announcements and can detect failure by timeout.
Why the others are wrong
B. VRRP advertisements are multicast to the whole redundancy group, never point-to-point unicast.
C. VRRP uses IP protocol number 112 directly, not UDP datagrams.
D. VRRP likewise never uses TCP connections or ports.
H12-721 exam tip — 18 is VRRP
Burn in 224.0.0.18 equals VRRP the way 224.0.0.5 equals OSPF; UDP and TCP options are instant rejects.
2In the networking environment of dual-system hot backup and IP-Link linkage (as shown in the following figure), in the configuration of the active firewall, which of the following is the configuration for the linkage between IP-Link and hot standby?
IP-Link check enable
hrp track IP-Link 1
hrp track IP-Link 1 enable
hrp mirror IP-Link 1
Answer: B
The short version
B — Bind the probe with hrp track ip-link 1. That command links uplink detection to hot standby so a failed path triggers firewall switchover.
Key concepts in this question
Dual-system hot backup (HRP): active and standby firewalls syncing sessions and state.
IP-Link: a probe tracking uplink reachability beyond the local interface.
hrp track: the command associating a track object with HRP priority adjustment.
Why B is correct
B is correct because on the active firewall the documented linkage syntax is hrp track ip-link 1: it registers IP-Link instance 1 with HRP, so when the probe fails the active device lowers its priority and the standby takes over gateway duties.
Why the others are wrong
A. Enabling IP-Link alone only starts probing; without the hrp track binding, HRP never reacts to the result.
C. Appending enable is not the VRP syntax for this binding and the extra keyword invalidates the command.
D. Mirroring synchronizes configuration or session data, it does not bind a track object to HRP election.
H12-721 exam tip — probe, then track, then switch
Sequence it as ip-link watches the uplink while hrp track watches ip-link; a missing track link means no failover.
3About the configuration command in the smart routing, which statement of the following is correct? (Multiple Choice)#multi-interfacemode priority-of-link-qualitypriority-of-link-quality parameter delay jitter losspriority-of-link-quality protocol tcp-simpleadd interface GigabitEthernet1/0/1add interface GigabitEthernet1/0/2
Parameter of link quality detection has the delay, jitter, and packet loss rate
Use the TCP protocol to detect
Selected 3 links for sharing
Use the way of bandwidth-based load sharing
Answer: A, B
The short version
A and B — The policy probes delay, jitter, and loss over TCP. Those three link-quality metrics plus the tcp-simple probe define exactly how the two member links are measured.
Key concepts in this question
Link-quality priority mode: egress selection driven by measured path quality.
delay jitter loss: the three probe parameters quantifying responsiveness and reliability.
tcp-simple: a TCP-based detection method for path probing.
Why A and B are correct
A is correct because the priority-of-link-quality parameter line explicitly lists delay, jitter, and loss as the detection inputs. B is correct because the priority-of-link-quality protocol tcp-simple line selects TCP as the probe transport used to sample those metrics.
Why the others are wrong
C. Only GigabitEthernet1/0/1 and 1/0/2 are added, so two links share load, not three.
D. The mode is link-quality priority, not bandwidth-based sharing; bandwidth weighting would need a different multi-interface mode.
H12-721 exam tip — read the config lines literally
Map each CLI line to one option: parameter line equals metrics, protocol line equals probe type, add lines count the links.
4There are three physical interfaces in the Link-Group group. When any of these interfaces fails, which of the following statements is correct? (Multiple Choice)
If any interface in the group fails, the status of other interfaces in the group does not change.
After all the interfaces in the group are restored to normal, the interface status in the entire group is set to Up again.
After some interfaces in the group are restored to normal, the interface status in the entire group is set to Up again.
If any interface in the group fails, the system sets the status of other interfaces in the group to Down.
Answer: B, D
The short version
B and D — One failed member downs the group until all recover. Link-Group fate-shares its interfaces so connected devices detect the outage together.
Key concepts in this question
Link-Group: Huawei interface-bundling feature linking the line status of member ports.
Fate sharing: any member failure forces the remaining members Down.
Group recovery: the group returns Up only after every member is healthy again.
Why B and D are correct
D is correct because Link-Group semantics propagate failure: when any physical interface fails, the system sets the other members Down so both ends of the path converge. B is correct because recovery is equally strict: only after all members return to normal does the whole group come Up, preventing partial black holes.
Why the others are wrong
A. Independent member status contradicts fate sharing; unaffected interfaces would hide the failure from the peer.
C. Partial recovery bringing the group Up would forward traffic into still-dead members, which the design forbids.
H12-721 exam tip — all for one in Link-Group
Think musketeers: one falls, all fall; all stand, all stand; any partial-recovery option is wrong.
5Which of the following VPN encapsulation protocols that do not provide encryption? (Multiple choices)
L2TP
ESP
GRE
AH
Answer: A, C, D
The short version
A and C and D — L2TP, GRE, and AH alone give no encryption. Only ESP among the choices provides confidentiality; the rest tunnel or authenticate without hiding payloads.
Key concepts in this question
L2TP: Layer 2 tunneling protocol carrying PPP with no native encryption.
GRE: generic encapsulation for tunneling, cleartext by itself.
AH vs ESP: authentication header proves integrity while encapsulating security payload encrypts content.
Why A and C and D are correct
A is correct because L2TP supplies tunneling and is paired with IPSec only when encryption is wanted. C is correct because GRE only encapsulates packets for transport and leaves contents readable. D is correct because AH authenticates headers and payloads but explicitly provides no confidentiality.
Why the others are wrong
B. ESP is the IPSec protocol that encrypts payloads, so it is the one choice that does provide encryption and must be excluded.
H12-721 exam tip — only ESP encrypts
Sort by function: ESP hides, AH signs, GRE carries, L2TP tunnels; encryption questions always isolate ESP.
6When configuring the IPSec VPN certificate authentication mode, if you select "RSA signature" authentication, need to configure which of the following steps?
Create local and public private key pair
Upload local certificate
Upload CA certificate
Upload the peer device certificate
Answer: B, C, D
The short version
B and C and D — RSA-signature certificates need all three uploads. The local certificate, the CA certificate, and the peer certificate together complete the trust chain.
Key concepts in this question
RSA signature auth: IKE peers prove identity with certificates instead of pre-shared keys.
Local certificate: the firewall's own identity issued by the CA.
CA and peer certificates: the trust anchor plus the remote party credential for verification.
Why B and C and D are correct
B is correct because the device must present its own CA-issued certificate during IKE authentication. C is correct because the CA certificate anchors trust for validating any certificate in the chain. D is correct because the peer device certificate (or its CA path) must be available to verify the remote signature.
Why the others are wrong
A. Manually creating a local public-private key pair is the RSA public-key (non-certificate) flow; the certificate flow obtains keys through enrollment and centers on uploading the three certificates.
H12-721 exam tip — cert auth is a three-upload checklist
Count local, CA, and peer: miss any one and the chain breaks; key-pair creation belongs to a different auth method.
7On the main panel of the Huawei USG6300 firewall, there is a fixed management interface GigabitEthernet 0/0/0 for device management.
True
False
Answer: A
The short version
A — TRUE: GE0/0/0 is the fixed management interface on the USG6300. The front-panel port is reserved for out-of-band device administration.
Key concepts in this question
USG6300 series: Huawei next-generation firewall with a dedicated panel interface.
GigabitEthernet 0/0/0: the fixed port wired for management access.
Management plane separation: admin traffic stays off service interfaces.
Why A is correct
A (True) is correct because Huawei designates GigabitEthernet 0/0/0 on the USG6300 main panel as the fixed management interface, used for initial login, software upgrades, and routine monitoring without consuming any service port.
Why the others are wrong
B. False would deny the dedicated management port, but panel diagrams and commissioning guides consistently identify GE0/0/0 in that role.
H12-721 exam tip — slot zero port zero manages
Default to GE0/0/0 as management on fixed-port USGs unless the stem explicitly reassigns it.
8Which of the following options is not required when configuring server load balancing?
Virtual server address
Load balancing algorithm
Service health check
Real server address
Answer: C
The short version
C — Health checks are optional in a minimal SLB build. A virtual address, real servers, and an algorithm forward traffic; probing only adds reliability.
Key concepts in this question
Virtual server address: the single VIP clients target.
Real server addresses: the backend pool members receiving dispatched flows.
Load balancing algorithm: the rule such as round-robin or least-connection picking members.
Why C is correct
C is correct because service health checks monitor backend liveness but are not mandatory to create the SLB instance: forwarding works once the VIP, server pool, and scheduling algorithm exist, and checks can be added later for failover intelligence.
Why the others are wrong
A. Without a virtual server address clients have no single destination to reach the service.
B. Without an algorithm the device cannot choose among backends.
D. Without real server addresses there is no pool to balance across.
H12-721 exam tip — VIP plus pool plus algorithm
Build SLB as where (VIP), who (real servers), how (algorithm); health checks are the optional when, not the core.
9If you use SSL VPN to provide file sharing, all files in the shared directory are visible to end users.Which of the following descriptions is correct for the configuration of the file share path?
The format of the NFS type resource is: //IP address (host name)/dir1/dir2/shared folder. The NFS type resource path can only have one-level shared folder directory.
The format of the SMB type resource is: //IP address (host name)/shared folder. The SMB type resource path can be a multi-level shared folder directory.
Select SMB for file sharing resources under Linux.
Select SMB for file sharing resources under Windows.
Answer: D
The short version
D — Windows shares use SMB. The gateway must match the backend OS, so SMB pairs with Windows while NFS pairs with Linux.
Key concepts in this question
SMB resources: file shares hosted on Windows systems.
NFS resources: file shares hosted on Linux and Unix systems.
Share path format: each type has its own syntax and directory-level rules.
Why D is correct
D is correct because SSL VPN file-sharing configuration selects the resource type by server OS: Windows-hosted folders are published as SMB resources, which is the only statement among the options that pairs type and platform correctly.
Why the others are wrong
A. It garbles the NFS path format and invents a one-level-only restriction that the configuration does not impose.
B. It garbles the SMB path format and invents multi-level permission the same way.
C. Linux shares use NFS, so assigning SMB to Linux reverses the required pairing.
H12-721 exam tip — OS picks the protocol
Decide by server OS first: Windows equals SMB, Linux equals NFS; path-format options are usually the traps.
10Which of the following is the role of Message5 and Message6 in the primary mode negotiation of IKE v1?
Negotiating IPSec SA
Negotiation proposal set
Run the DH algorithm
Doing mutual authentication
Answer: D
The short version
D — Messages 5 and 6 authenticate the peers. After proposals and Diffie-Hellman, the final pair exchanges protected identities to prove who is who.
Key concepts in this question
IKEv1 Main Mode: six-message phase 1 exchange building the ISAKMP SA.
Messages 1-2: SA proposal negotiation; messages 3-4 run Diffie-Hellman.
Messages 5-6: identity exchange and authentication under the new protection.
Why D is correct
D is correct because by message 5 the peers share encryption from the DH exchange, so they can safely send identities and authentication hashes (pre-shared key or signatures) to mutually verify each other before any phase 2 negotiation begins.
Why the others are wrong
A. IPSec SA negotiation happens later in Quick Mode phase 2, not in Main Mode messages 5-6.
B. Proposal-set negotiation is the job of messages 1-2 at the start of phase 1.
C. The Diffie-Hellman exchange occupies messages 3-4, already complete before authentication.
H12-721 exam tip — 1-2 propose, 3-4 mix, 5-6 prove
Chunk Main Mode into pairs by number; authentication always lands on the final protected pair.