Sign In
Home/Huawei/Datacom Campus Network Planning and Deployment/Free questions

Huawei Certified ICT Professional - Datacom Campus Network Planning and Deployment — Free Practice Questions

10 free sample questions from a bank of 154, with the correct answers and explanations. No signup required — start practising right now.

1In an MPLS VPN network, when a data packet is forwarded from the PE device to the CE device, which of the following operations will the PE device perform to process the tag?
  • Retain the outer public network label, only strip the inner VPN label.
  • Strip the outer public network label, retain the inner VPN label, and forward it to CE.
  • Simultaneously strip the outer public network label and the inner VPN label, and forward the data to CE according to the IP address.
  • Retain the double-layer label and forward it directly to the CE device.
Answer: C

The short version

C — The PE strips both labels toward the CE. The CE speaks plain IP, so the egress PE removes the transport and VPN labels and forwards by destination address.

Key concepts in this question

  • Label stack: outer transport label plus inner VPN label inside the MPLS backbone.
  • Penultimate hop popping: the outer label is usually already gone when the packet reaches the PE.
  • Egress PE role: pops the VPN label to identify the VRF and next hop.
  • PE-CE link: a plain IP link with no MPLS awareness on the CE side.

Why C is correct

Across the backbone the packet carries two labels, but the CE cannot process any label. The egress PE therefore removes the remaining stack — the outer label if still present and always the inner VPN label — looks up the exposed IP packet in the correct VPN instance, and forwards it to the CE. Option C describes exactly this double pop with IP-based forwarding.

Why the others are wrong

  • A. Keeping the outer label would deliver an MPLS frame the CE cannot parse.
  • B. Keeping the inner VPN label would likewise deliver a labeled packet to a label-unaware CE.
  • D. Forwarding both labels to the CE fails for the same reason: the CE expects native IP.

H12-841 exam tip

Memory hook: labels die at the PE — the CE only ever receives plain IP packets.

2In a wide area network (WAN) IPv6 transition scenario, if "an enterprise needs to publish IPv6 services to the outside world, and the outside world only supports IPv4 access", which of the following technologies should be adopted?
  • IPv4/IPv6 dual-stack technology (requires external IPv6 support)
  • IPv6 over IPv4 tunnel (only allows access from IPv6 terminals)
  • DNS64+NAT64 (only enables internal IPv6 to access external IPv4)
  • NAT46 (translates external IPv4 addresses into internal IPv6 addresses to enable access)
Answer: D

The short version

D — NAT46 publishes IPv6 services to IPv4-only clients. It translates the outside IPv4 request into the internal IPv6 service address and back.

Key concepts in this question

  • Publishing direction: outside IPv4 users must reach an inside IPv6 server.
  • NAT46: stateless or stateful translation from IPv4 to IPv6 for server access.
  • Dual stack: needs IPv6 support on the outside, which the scenario rules out.
  • Tunnels and NAT64: serve the opposite direction or dual-capable clients.

Why D is correct

The requirement is one-directional publishing: the service lives on IPv6, visitors speak only IPv4. NAT46 on the border maps the public IPv4 address and port to the internal IPv6 server address, translating headers in both directions for the session. No outside IPv6 capability is needed, which fits the scenario precisely and makes D correct.

Why the others are wrong

  • A. Dual stack explicitly requires outside IPv6 support, contradicting the scenario.
  • B. IPv6-over-IPv4 tunnels help IPv6 endpoints talk across IPv4, not IPv4-only visitors.
  • C. NAT64 with DNS64 lets inside IPv6 clients reach outside IPv4 servers — the reverse direction.

H12-841 exam tip

Memory hook: read the arrow first — outside v4 into inside v6 spells NAT46.

3In Huawei's WAN solution, regarding the issue of "echoes in cross-regional voice services (VoIP)," which of the following troubleshooting steps should be performed first?
  • Check if the MPLS LSP of the PE device is established.
  • Check if the routing table of the CE device includes the VoIP server network segment.
  • Check if the link bandwidth is sufficient.
  • Check if echo cancellation is enabled on the VoIP gateway.
Answer: D

The short version

D — Check echo cancellation on the gateway first. Echo in VoIP is a voice-path symptom, so the voice endpoint setting outranks transport checks.

Key concepts in this question

  • Echo source: hybrid mismatch and delay in the voice path, fixed by cancellers.
  • VoIP gateway: hosts the echo canceller facing the PSTN or analog side.
  • Troubleshooting order: start with the most symptom-specific cause before generic links.
  • Transport red herrings: LSP, routing, and bandwidth rarely create classic echo.

Why D is correct

Cross-region delay makes any existing echo more audible, but the direct control is the echo canceller on the VoIP gateway. If it is disabled or misconfigured, echo persists regardless of a healthy LSP, correct routes, or ample bandwidth. Verifying that feature first isolates the voice-specific cause before spending effort on the transport layers, so D is the correct first step.

Why the others are wrong

  • A. A broken LSP would cause loss or outage, not classic voice echo.
  • B. A missing VoIP route would break calls entirely rather than echoing them.
  • C. Tight bandwidth causes choppiness or delay, but cancellation state is the echo-specific check.

H12-841 exam tip

Memory hook: symptom-specific before generic — echo means look at the canceller first.

4In Huawei's WAN solution, for the scenario where " WAN link bandwidth fluctuations cause file transfers to be sometimes fast and sometimes slow," which of the following technologies can"smooth the impact of bandwidth fluctuations and stabilize file transfer rates"?
  • Ignore bandwidth fluctuations and transfer files directly.
  • Transfer files only during peak bandwidth periods, pausing at other times.
  • Lower the priority of file transfers and prioritize other services.
  • Token bucket-based traffic smoothing technology (controlling file sending rate to avoid sudden rate fluctuations)
Answer: D

The short version

D — Shape the flow with a token bucket. Smoothing caps bursts and evens the sending rate so transfers survive bandwidth swings.

Key concepts in this question

  • Token bucket: tokens accrue at a set rate and each byte needs a token to send.
  • Traffic shaping: buffers excess instead of dropping it, flattening peaks.
  • Rate stability: the receiver sees a steadier stream despite link fluctuation.
  • Do-nothing options: ignoring or pausing transfers never smooths anything.

Why D is correct

Flapping bandwidth punishes bursty sends: bursts hit the troughs and stall. A token-bucket shaper paces file traffic to a configured rate, queuing surplus during peaks and releasing it evenly, which absorbs the fluctuation and stabilizes throughput. Option D is the only choice naming a real smoothing mechanism, so it is correct.

Why the others are wrong

  • A. Ignoring fluctuations leaves bursts exposed to every trough.
  • B. Transferring only at peaks wastes capacity and guarantees stalls elsewhere.
  • C. Deprioritizing files may protect other services but does nothing to steady the file rate.

H12-841 exam tip

Memory hook: “smooth the rate” always points at shaping — think token bucket on sight.

5In Huawei's SD-WAN solution, which of the following functions can "classify branch service traffic and allocate different bandwidth ratios to different services (such as ERP and video)"?
  • Business Traffic Classification and Bandwidth Allocation
  • IPsec encrypted tunnel
  • Automatic link switching
  • Link Quality Detection (LQM)
Answer: A

The short version

A — Traffic classification with bandwidth allocation does this. It sorts flows like ERP and video, then guarantees each class its share.

Key concepts in this question

  • Service classification: identifies applications by port, DSCP, or DPI signatures.
  • Bandwidth allocation: assigns ratios or minimum guarantees per class.
  • SD-WAN policy: pushes the same application treatment to all branches.
  • Transport features: encryption, failover, and probing protect delivery but do not divide bandwidth.

Why A is correct

The requirement has two halves: tell services apart, then split bandwidth between them. That is precisely application-aware classification plus per-class bandwidth ratios, which SD-WAN applies at branch edges so ERP stays responsive while video gets its provisioned share. Option A names that combined function, making it correct.

Why the others are wrong

  • B. IPsec tunnels encrypt traffic but allocate no per-service ratios.
  • C. Automatic link switching changes paths on failure without classifying services.
  • D. Link quality detection measures loss, delay, and jitter but assigns no bandwidth shares.

H12-841 exam tip

Memory hook: “classify plus share” is always the QoS answer — tunnels, failover, and probes are distractors.

6In an MPLS VPN network, which of the following descriptions conforms to the allocation logic of"VPN label (inner label)"?
  • Assigned by the CE device based on local routing, used to identify the service type.
  • Assigned by the PE device based on the VPN instance, used to identify the VPN to which the data packet belongs.
  • Assigned by the P device according to the backbone network topology, used to identify the forwarding path.
  • Fixed to a default value, not changing with VPN instance.
Answer: B

The short version

B — The egress PE assigns the VPN label per instance. That inner label tells the far PE which VRF the packet belongs to.

Key concepts in this question

  • Inner label: identifies the VPN or forwarding entry, not the transport path.
  • PE allocation: the egress PE binds the label to a VRF route and signals it via MP-BGP.
  • Outer label: built hop by hop by LDP or RSVP for transport to the egress PE.
  • CE and P roles: neither assigns VPN labels in this architecture.

Why B is correct

When the ingress PE forwards VPN traffic, it pushes the inner label advertised by the egress PE for that prefix or VRF. The egress PE allocated it from its own label space precisely to demultiplex the VPN on arrival. Option B captures the allocator (PE), the scope (per VPN instance), and the purpose (identify the VPN), so it is correct.

Why the others are wrong

  • A. The CE runs plain IP and VRF-unaware routing; it assigns no MPLS labels.
  • C. The P device only swaps transport labels; it never sees VPN membership.
  • D. VPN labels vary per instance and prefix, so no fixed default value exists.

H12-841 exam tip

Memory hook: inner means VPN and comes from the far PE — outer is transport, inner is identity.

7In the OSPF protocol for wide area networks, which of the following is the core information contained in Type 2 LSA (Network LSA)?
  • Prefix and metric of inter-area summary route
  • Prefix and next hop of external routes to the AS
  • The DR router ID that generated this LSA and the IDs of all routers in the network.
  • Prefixes and metrics for external routes within the NSSA area
Answer: C

The short version

C — Type 2 describes the multi-access network membership. It lists the DR plus every router attached to that segment.

Key concepts in this question

  • Network LSA: generated by the DR for each broadcast or NBMA segment.
  • DR field: identifies the router that originated the LSA.
  • Attached routers: the link-state ID set of all neighbors on the segment.
  • Other LSA roles: summaries and externals live in Types 3, 5, and 7, not Type 2.

Why C is correct

On a segment with two or more routers, the DR originates a Type 2 LSA that enumerates the DR itself and all attached routers, letting every router reconstruct the star topology of the segment. Option C states exactly that content — DR identity plus member list — so it is correct.

Why the others are wrong

  • A. Inter-area prefixes and metrics belong to Type 3 summary LSAs.
  • B. AS-external prefixes and next hops belong to Type 5 LSAs.
  • D. NSSA external content belongs to Type 7 LSAs, not Type 2.

H12-841 exam tip

Memory hook: Type 2 equals the DR’s attendance sheet — members of the segment, nothing about other areas.

8In Huawei's SD-WAN solution, which of the following technologies can "enable branch devices to dynamically obtain IP addresses (e.g., via DHCP) without manually configuring static IPs"?
  • Disable IP address configuration on branch devices and rely on remote allocation from headquarters.
  • SD-WAN devices support DHCP client functionality (automatic IP address acquisition).
  • Manually configure static IP addresses for branch devices.
  • All branch devices use the same fixed IP address, distinguished by port number.
Answer: B

The short version

B — Branch devices act as DHCP clients. They request addresses automatically instead of needing static configuration.

Key concepts in this question

  • DHCP client: obtains IP, mask, gateway, and DNS from a server on plugging in.
  • Zero-touch onboarding: branches come up without manual per-site addressing.
  • Static addressing: the manual alternative the requirement explicitly avoids.
  • Address reuse fallacies: sharing one address across branches breaks routing.

Why B is correct

The requirement is dynamic address acquisition without static entries. SD-WAN edge devices support DHCP client mode on their WAN or uplink interfaces, pulling all parameters from the local access network at boot. Option B is the only choice describing automatic acquisition, so it is correct.

Why the others are wrong

  • A. Disabling address configuration leaves the device unreachable; headquarters cannot remotely number an unaddressed WAN.
  • C. Manual static addresses are exactly what the scenario rules out.
  • D. Reusing one fixed address everywhere creates conflicts and unroutable branches.

H12-841 exam tip

Memory hook: “no static IP” always resolves to DHCP client — pick the automatic option.

9In a wide area network (WAN) OSPF deployment, when a non-backbone area (such as Area 1) is not directly connected to the backbone area (Area 0), which of the following technologies needs to be deployed to solve the routing connectivity problem?
  • OSPF Certification
  • OSPF route aggregation
  • OSPF Virtual Link
  • OSPF NSSA area
Answer: C

The short version

C — Build an OSPF virtual link. It logically stitches the detached area to the backbone through a transit area.

Key concepts in this question

  • Backbone rule: every OSPF area must touch Area 0 directly or logically.
  • Virtual link: an Area 0 extension across a transit area between two ABRs.
  • Discontiguous area: Area 1 here has no ABR on Area 0, breaking inter-area routes.
  • Unrelated fixes: authentication, aggregation, and NSSA solve other problems.

Why C is correct

OSPF requires contiguous backbone connectivity: inter-area traffic must pass through Area 0. A non-backbone area isolated from Area 0 cannot exchange summary LSAs correctly. A virtual link configured between ABRs across the transit area restores the logical adjacency to Area 0, repairing route computation. Option C names that repair mechanism, so it is correct.

Why the others are wrong

  • A. Authentication secures adjacencies but creates no path to the backbone.
  • B. Aggregation shrinks advertisements yet still needs backbone reachability first.
  • D. An NSSA controls external import; it does not reconnect an isolated area.

H12-841 exam tip

Memory hook: detached area means virtual link — it is the only option that extends Area 0.

10In the Huawei WAN management platform, which of the following functions can "set up device configuration change alarms (such as routing policy modifications) to promptly detect unauthorized configurations"?
  • Network topology visualization
  • Equipment hardware resource monitoring
  • Batch distribution of configuration templates
  • Configuration change monitoring and alarms
Answer: D

The short version

D — Configuration-change monitoring with alarms does this. It watches for edits like routing-policy changes and raises unauthorized-change alerts.

Key concepts in this question

  • Change detection: baselines configs and flags any diff on managed devices.
  • Alarm linkage: turns a detected edit into an actionable notification.
  • Policy edits: routing-policy changes are exactly the high-risk edits to catch.
  • Adjacent features: topology, inventory, and templates serve other purposes.

Why D is correct

The requirement pairs two functions: notice the configuration change, then alert on it. Change-monitoring continuously compares device configs and emits an alarm when an unplanned edit such as a routing-policy modification appears, enabling fast rollback or audit. Option D is the only choice combining detection with alarming, so it is correct.

Why the others are wrong

  • A. Topology visualization draws links and status but does not alarm on config edits.
  • B. Hardware monitoring tracks CPU, memory, and boards, not configuration text.
  • C. Template distribution pushes intended configs but does not detect rogue changes.

H12-841 exam tip

Memory hook: “detect unauthorized edits” means change monitor plus alarm — visualization and templates never alarm.

Want the full bank of 154 questions for Huawei Certified ICT Professional - Datacom Campus Network Planning and Deployment? See all practice exams.