Huawei Certified ICT Professional - Security - CTSS — Free Practice Questions
10 free sample questions from a bank of 85, with the correct answers and explanations. No signup required — start practising right now.
1Which of the following options is Agile Controller-Campus middle SC The main function of the component?
As Agile Controller-Campus The management interface is used to configure and monitor the system.
As Agile Controller-Campus The management center is responsible for formulating the overallstrategy.
As Agile Controller-Campus 'S security assistance server, responsible for iRadar Analysis and calculation of reported security incidents.
Integrated with standards RADIUS server,Porta Server, etc., responsible for linking with network access equipment to realize user-based networkaccess control Strategy.
Answer: D
The short version
D — The SC integrates RADIUS and Portal functions for user access control. It links with NAD devices to enforce user-based policies.
Key concepts in this question
Service controller (SC): policy enforcement point for campus admission and authorization.
RADIUS and Portal integration: standard authentication services embedded in the SC role.
NAD linkage: coordination with network access devices for access control and mobility.
Why D is correct
In the Agile Controller-Campus architecture the SC acts as the service enforcement component with built-in RADIUS and Portal server behavior, linking admission devices to apply user-based access policies. Options A through C describe management, strategy, or security-analysis roles belonging to other components, so D is the SC function and the banked answer is retained.
Why the others are wrong
A. The management interface for configuration and monitoring belongs to the management center role, not the SC.
B. Formulating the overall management strategy is the management center function, not the SC.
C. Security-incident analysis and iRadar computation belong to the security assistance and analysis role, not the SC.
H12-723 exam tip
Map MC to manage, SM to business, SC to enforce access with RADIUS and Portal.
2A network adopts 802. 1X To authenticate access users, the access control equipment is deployed at the convergence layer, and after the deployment is completed, it is used on the access control equipment t-aa The command test is successful, but the user cannot access the network. The failure may be caused by the following reasons? (Multiple choice)
Connect to the terminal on the device to open 802.1X Function.
The aggregation layer device is not configured RADIUS Certification template.
Agile Controller-Campus The switch is not added on NAS equipment.
The Layer 2 link is used between the access device and the aggregation device, and it is not turned on802 Instrument transparent transmission function
Answer: A, D
The short version
A and D — Success on the AAA test but user failure points to the client or path. The terminal lacks 802.1X and the Layer 2 path lacks transparent transmission.
Key concepts in this question
t-aa test: validates the aggregation device to RADIUS path, not the end-to-end client path.
Terminal 802.1X supplicant: client software required for EAP exchanges.
802.1X transparent transmission: access-layer pass-through of EAP frames toward an upstream authenticator.
Why A and D are correct
A passing AAA test proves the aggregation device reaches the server, so the remaining breakage lies with EAP delivery: the terminal must enable its 802.1X supplicant and the access-to-aggregation Layer 2 path must transparently forward EAP frames to the upstream authentication point. Those are options A and D, so the banked answer is retained.
Why the others are wrong
B. A missing RADIUS template would fail the AAA test itself, which here succeeded.
C. A missing NAS entry on the controller would likewise break server-side authentication rather than leave the AAA test passing.
H12-723 exam tip
When the AAA test passes but users fail, look downstream at the supplicant and the EAP pass-through path.
3Agile Controller-Campus The department includes four parts of the management center(MC)Business manager(SM)And business controller(SC)And client network access equipment (NAD)As a component of the solution, it is linked with the service controller to realize user access control and free mobility.
True
False
Answer: A
The short version
A — True: MC, SM, SC, and NAD are the four solution parts. NAD links with the SC for access control and mobility.
Key concepts in this question
Management center (MC): system management and monitoring plane.
Service manager (SM) and service controller (SC): business policy versus enforcement roles.
NAD: access devices that authenticate users together with the SC.
Why A is correct
The Agile Controller-Campus department structure is defined as management center, service manager, service controller, and network access devices, with NAD equipment cooperating with the SC to deliver user admission and free mobility. The statement matches that composition exactly, so it is true and the banked answer A is retained.
Why the others are wrong
B. False would deny the documented four-part model and the NAD and SC linkage, which are standard solution elements.
H12-723 exam tip
Count four every time: manage, business, control, access device; NAD plus SC delivers mobility.
4When deploying the Agile Controller-Campus, the high-reliability solution of the Windows+SQL Server platform is adopted. Which of the following components is not supported for deployment?
Deploy MC and SM dual machine backup
Deploy the main DB
Deploy witness DB
Deployimage DBO
Answer: A
The short version
A — MC plus SM dual-machine backup is the unsupported option here. The Windows plus SQL Server HA model centers on database redundancy.
Key concepts in this question
Windows plus SQL Server HA: database-level redundancy with primary, mirror, and witness roles.
Primary DB, mirror DB, and witness DB: SQL Server mirroring trio for failover decisions.
MC and SM redundancy: controller-level backup, distinct from database HA.
Why A is correct
The described high-reliability scheme provides database protection through primary, mirror, and witness database deployment, while MC and SM dual-machine backup is not the component this database-HA option supports. Option A is therefore the not-supported deployment, and the banked answer is retained.
Why the others are wrong
B. Deploying the primary database is a required member of the mirroring set.
C. Deploying the witness database is required for quorum and automatic failover.
D. Deploying the mirror database is the standby copy in the HA trio.
H12-723 exam tip
For database HA questions, look for the primary, mirror, and witness trio; controller backup is a different scheme.
5Traditional network single--The strategy is difficult to cope with the current complex situations such as diversified users, diversified locations, diversified terminals, diversified applications, and insecure experience.
True
False
Answer: A
The short version
A — True: single static policies cannot handle diverse users, places, terminals, and apps. Matrixed policy is the stated answer.
Key concepts in this question
Traditional single-dimensional policy: rules tied mainly to IP address or port.
Diversified campus: varied users, locations, terminals, applications, and experience demands.
Policy-driven matrix: user, device, application, and location-aware access control.
Why A is correct
Static one-dimensional strategies break down when access depends on who, where, with what device, and for which application under experience guarantees. Huawei campus positioning states exactly that traditional policy cannot cope with this multidimensional complexity, so the statement is true and the banked answer A is retained.
Why the others are wrong
B. False would claim a single static policy still suffices, contradicting the multidimensional campus problem the solution addresses.
H12-723 exam tip
Link the word diversified to multidimensional policy: one interest per dimension, one static rule cannot cover them.
6Security zone division means to better protect the internal network security,Based on the business type and security requirements of the intranet, divide the intranet into several granularities.Logical area. Which of the following options does not belong Agile Controller-Campus Security domain?
Business domain:
Network domain
User domain
Attack domain
Answer: D
The short version
D — Attack domain is not an Agile Controller-Campus security domain. The model uses business, network, and user views.
Key concepts in this question
Security zone division: grouping the intranet by business type and protection needs.
Business, network, and user domains: the campus classification dimensions.
Attack domain: a threat concept, not a campus zoning category.
Why D is correct
Campus security domains partition users and resources into business, network, and user domains for differentiated policy, while attack domain describes adversary activity rather than a zoning class. Option D is therefore the item outside the model, and the banked answer is retained.
Why the others are wrong
A. Business domain grouping by service type is a standard zoning dimension.
B. Network domain grouping by network region and role is a standard zoning dimension.
C. User domain grouping by identity and role is a standard zoning dimension.
H12-723 exam tip
Recall three zoning lenses: what service, what network, what user; attack is a threat, not a zone.
7802.1X During the authentication, if the authentication point is at the aggregation switch, in addition to RADIUS,AAA,802.1X In addition to theconventional configuration, what special configuration is needed?
No special configuration required
Access layer switch needs to be configured 802. 1X Transparent transmission of messages.
Both the aggregation layer and the access layer switches need to be turned on 802.1X Function.
The aggregation switch needs to be configured 802 1X Transparent transmission of messages.
Answer: B
The short version
B — With authentication upstream, the access switch must pass EAP through. Transparent transmission delivers client frames to the aggregation authenticator.
Key concepts in this question
Authentication point at aggregation: the upstream switch terminates 802.1X exchanges.
EAP transparent transmission: Layer 2 pass-through of EAPOL frames without local termination.
Conventional AAA, RADIUS, and 802.1X setup: baseline config assumed on the authenticator.
Why B is correct
When the aggregation switch is the authenticator, client EAP frames arriving at the access switch must be forwarded unchanged upstream instead of being consumed locally. Configuring 802.1X transparent transmission on the access layer provides that path, so option B is the extra requirement and the banked answer is retained.
Why the others are wrong
A. No special configuration is wrong because direct access-layer termination would swallow client EAP frames.
C. Enabling full 802.1X on both layers creates competing authenticators rather than a pass-through path.
D. Transparent transmission on the authenticator itself is misplaced; the pass-through belongs downstream.
H12-723 exam tip
Upstream authenticator means downstream forwarder: access passes through, aggregation authenticates.
8When using local guest account authentication, usually use(Portal The authentication method pushes the authentication page to the visitor. Before the user is authenticated, when the admission control device receives the HTTP The requested resource is not Portal Server authentication URL When, how to deal with the access control equipment.
URL Address redirected to Portal Authentication page
Discard message
Direct travel
Send authentication information to authentication server
Answer: A
The short version
A — Before authentication, non-Portal HTTP requests are redirected to the Portal page. The device forces guest login first.
Key concepts in this question
Local guest account with Portal: visitor login through a pushed web page.
Pre-authentication HTTP interception: admission device inspects unauthenticated web requests.
URL redirection: rewriting the request destination to the Portal authentication URL.
Why A is correct
An unauthenticated guest requesting any non-Portal resource has not yet proven identity, so the admission device redirects that HTTP request to the Portal authentication page to start login. Direct pass, silent drop, or premature server authentication would bypass or break the guest flow, so option A is correct and the banked answer is retained.
Why the others are wrong
B. Dropping the message strands the guest without ever presenting the login page.
C. Passing the request directly grants network access before authentication.
D. The admission device does not complete authentication itself; the Portal server interaction follows redirection.
H12-723 exam tip
Pre-auth web equals redirect to login: anything not Portal becomes Portal until the guest signs in.
9VIP Experience guarantee, from which two aspects are the main guaranteesVIP User experience? (Multiple choice)
Authority
bandwidth
Forwarding priority
Strategy
Answer: B, C
The short version
B and C — VIP experience rests on bandwidth and forwarding priority. Reserved capacity plus preferred scheduling protects key users.
Key concepts in this question
Bandwidth assurance: guaranteed or reserved throughput for VIP traffic.
Forwarding priority: scheduling preference so VIP packets go first under contention.
Rights and policy: authorization inputs, not the two experience mechanisms named here.
Why B and C are correct
Experience assurance means VIP flows keep speed and responsiveness when the network is busy, which requires both enough bandwidth and scheduling preference in the forwarding path. Options B and C name exactly those two mechanisms, while authority and generic policy describe admission rather than quality, so the banked answer is retained.
Why the others are wrong
A. Authority decides what a user may access, not how smooth the forwarding feels.
D. Policy is the container for rules; the concrete experience levers in this question are bandwidth and priority.
H12-723 exam tip
VIP experience equals pipe plus preference: reserve the bandwidth, prioritize the forwarding.
10SACG Inquire right-manager The information is as follows, which options are correct? (Multiple choice)
main controller IP address is 1.1.1.2.
SACG and IP Address is 2.1.1.1 The server linkage is unsuccessful.
SACG Thelinkage with the controller is successful.
main controller IP address is 2.1.1.1.
Answer: A, C
The short version
AC — Controller is 1.1.1.2 and the SACG linkage is successful. The reconstructed right-manager output shows 1.1.1.2 with State Success.
Key concepts in this question
Right-manager: SACG query showing main controller IP and linkage state.
Main controller IP: the Policy Center address the SACG registers to.
Linkage state: Success versus failure flag in the output.
Why AC is correct
The reconstructed inquiry output lists Main Controller 1.1.1.2 with Linkage Success, so A correctly reports the controller address and C correctly reports the successful linkage.
Why the others are wrong
B. Combines the wrong address 2.1.1.1 with unsuccessful, contradicting the Success flag.
D. Reports 2.1.1.1, which is the SACG-side address in the reconstruction, not the controller.
H12-723 exam tip
Read controller IP and Success flag as a pair; 1.1.1.2 plus Success equals AC.