Question 1:

In the dual-system hot backup networking environment as shown in the standby firewall also need to configure NAT function, assuming that the external address of the VRRP backup group. NAT address pool and NAT Server in the same network segment. Which of the following configuration needs to be on the Server? (choose two answers)

A. HRP_M [USG_A] nat address-group 1 vrrp 1

B. HRP_M [USG_A] nat address-group 1 vrrp 2

C. HRP_M [USG_A] nat server global inside vrrp 2

D. HRP_M [USG_A] nat server global inside vrrp 1

Correct Answer: BC

Question 2:

In IP-link, how many successive packets must not be recived for it to be considered a failure, by default?

A. 1 times

B. 2 times

C. 3 times

D. 5 times

Correct Answer: C

Question 3:

Through the configuration of the Bypass interface, you can avoid network communication interruption caused by equipment failure and improve reliability. The power Bypass function can use any network interfaces to configure the Bypass GE parameters to achieve the Bypass function.



Correct Answer: B

Question 4:

As shown below, the trust area has two PC machines, PC1, PC2 and the Untrust zone has one server

PC1 can not access, and PC2 actively access each other. Through configuration analysis, how will you fix the following problems?

A. image075

B. image077

C. image079

D. image081

Correct Answer: A

Question 5:

With the USG firewall, which two commands can be used to view equipment components (control board, fans, power supplies, etc.) run state and memory / CPU usage? (Choose two answers)

A. display device

B. display environment

C. display version

D. dir

Correct Answer: AB

Question 6:

Which of the following is a drawback of an L2TP VPN?

A. It cannot be routed in two layers

B. You must use L2TP Over IPsec

C. No authentication

D. No encryption

Correct Answer: D

Question 7:

If a data stream has been established in the firewall session and you modify the data corresponding packet filtering policy, how will the firewall perform?

A. When a new packet reaches the firewall, filtering is performed immediately according to the latest strategies and refreshes the session table

B. Immediately perform filtering according to the latest strategy session table is not refreshed.

C. session before aging, not to implement the new strategy, in accordance with previously established session match

D. modification will fail to modify the need to clear the session.

Correct Answer: A

Question 8:

About BFD detection mechanism, the following statement is correct? (Choose two answers)

A. BFD control packets are encapsulated in TCP packets

B. BFD provides two detection modes: asynchronous and synchronous mode

C. After the establishment of a BFD session, both systems periodically send BFD control packets

D. At the beginning of the session, the two sides negotiate through the control system carried in the packet parameters

Correct Answer: CD

Question 9:

Shown below is an IPSec standby scenario, with main link A and backup link B. Assuming that on link B the next-hop IP address is and, and we want to ensure that the primary and redundant backup link via IP-Link is configured.

Which of the following is the correct cstatic routeonfiguration from the headquarters to the branch office?

A. [USG] ip route-static [USG] ip route-static

B. [USG] ip route-static ip-link 1 [USG] ip route-static ip-link 2

C. [USG] ip route-static track ip-link 1 [USG] ip route-static preference 70 track ip-link 2

D. [USG] ip route-static preference 70 track ip-link 1 [USG] ip route-static track ip-link 2

Correct Answer: C

Question 10:

URPF main function is to prevent network attacks based on the destination address spoofing.



Correct Answer: B

Question 11:

The USG supported HRP backup options are awhich of the follwoing? (Choose three answers)

A. Automatic Backup

B. Manual batch backup

C. Quick Backup

D. Real-time backup

Correct Answer: ABC

Question 12:

After the firewall creates a new security instance, the firewall does not have any security zones assigned to the new instance and the administrator needs to configure them.



Correct Answer: B

Question 13:

Which of the following statements about VRRP and VGMP packets are correct? (Choose 2 answers)

A. VGMP groups use VGMP Hello packets to communicate with VRRP groups.

B. VGMP groups use VGMP Hello packets for mutual communication.

C. VGMP groups use VRRP packets for mutual communication.

D. VGMP groups use VGMP packets to communicate with VRRP groups.

Correct Answer: BD

Question 14:

USG5000A has an IPSEC connection to USG5000B and the “display ike sa” command was performed on USG5000A:

Based on the output shown, which of the following is correct?

A. USG5000A Firewall is a secure channel initiator IKE negotiation

B. USG5000B is the initiator of IKE negotiation of safe passage

C. The SA has been successfully established between the firewalls

D. The SA has not been established between the firewalls successfully.

Correct Answer: AC

Question 15:

Which of the following protocol packets can not be sent by default in an IPsec tunnel?





Correct Answer: D

