Spring Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70percent

Huawei H12-841_V1.5 HCIP-Datacom-Campus Network Planning and Deployment V1.5 Exam Practice Test

Demo: 31 questions
Total 104 questions

HCIP-Datacom-Campus Network Planning and Deployment V1.5 Questions and Answers

Question 1

(To isolate communication between wired terminals, you can enable port isolation on the access switches. However, APs cannot implement wireless user isolation.)

Options:

A.

TRUE

B.

FALSE

Question 2

Network admission control (NAC) needs to be deployed on the network shown in the figure. Drag a proper authentication mode to each authentication point.

Options:

Question 3

(Which of the following statements about the fabric global resource pool isfalse?)

Options:

A.

A bridge domain is a Layer 2 broadcast domain used to forward data packets on a VXLAN.

B.

VLANs for connecting to external networks, VLANs for connecting to network service resources, and VLANs for connecting underlay devices are allocated from the VLAN resource pool.

C.

A VXLAN network identifier identifies a VXLAN.

D.

Configure a service VLAN pool when you need to configure external gateway interconnection VLANs, network service resource interconnection VLANs, management VLANs for policy association, and VN access VLANs.

Question 4

(The following figure shows the MAC address table of a Layer 2 VXLAN gateway. Which of the following statements are true?Choose all that apply.)

Options:

A.

Both 0000-0000-0010 and 5489-9893-48a3 belong to BD 10 and are in the same Layer 2 broadcast domain.

B.

The outbound interface corresponding to 5489-982d-77e2 is GE1/0/1.20. Because this interface belongs to BD 20, the host with 5489-982d-77e2 can directly communicate with the host with 5489-9893-48a3 at Layer 2.

C.

The MAC address entry with the outbound interface 10.3.3.3 is learned from the remote VTEP through the VXLAN tunnel.

D.

The outbound interface corresponding to 5489-9893-48a3 is GE1/0/1.10, which belongs to BD 10.

Question 5

(iMaster NCE-Campus has multiple networking planes. The single-plane networking is optional only in single-node system deployment.)

Options:

A.

TRUE

B.

FALSE

Question 6

(DHCP dynamically configures and centrally manages IP addresses of hosts. Which of the following statements about DHCP is false?)

Options:

A.

If only the gateway and DNS server information needs to be delivered to a DHCP client, the DHCP Offer message sent by the DHCP server to the client does not carry the Options field.

B.

The Options field in DHCP messages uses the type-length-value (TLV) structure and can carry parameters such as the NTP server address, AC address, and log server address.

C.

DHCP supports static IP address allocation, in which it assigns fixed IP addresses to specified terminals.

D.

When a DHCP client and a DHCP server are located on different Layer 3 networks, a DHCP relay agent is needed for forwarding packets between the DHCP client and server.

Question 7

(Refer to the figure.

Which of the following steps aremandatoryto enable 802.1X authentication on GE0/0/2 and GE0/0/3 of SW3 and configure a RADIUS server to authenticate and deliver network access rights to users?Choose all that apply.)

Options:

A.

Configure an authentication domain.

B.

Configure an authentication profile.

C.

Configure an 802.1X access profile.

D.

Configure an AAA scheme.

Question 8

(On a small- or medium-sized campus network deployed based on the Huawei CloudCampus Solution, an AR functioning as the egress gateway supports web-based network management, registration center query, and DHCP Option 148-based deployment, but does not support CLI-based deployment.)

Options:

A.

TRUE

B.

FALSE

Question 9

(Which of the following fields in the ESP protocol is used to prevent replay attacks?)

Options:

A.

Sequence Number

B.

Next Header

C.

SPI

D.

Authentication Data

Question 10

(Which of the following statements isfalseabout sites on a virtualized network deployed using iMaster NCE-Campus?)

Options:

A.

iMaster NCE-Campus does not support batch site creation.

B.

Tenants configure and manage devices by site.

C.

iMaster NCE-Campus allows administrators to create sites one by one.

D.

A site is a tenant network created by a tenant administrator.

Question 11

(Which of the following are iMaster NCE-Campus license business models?Choose all that apply.)

Options:

A.

Global perpetual license (N1 mode)

B.

Tenant Subscription license (SaaS Mode)

C.

Global perpetual license (a-la-carte mode)

D.

Global subscription license (IaaS Mode)

Question 12

(O&M personnel for a large-scale event center receive feedback about Wi-Fi access failures. iMaster NCE-CampusInsight provides the function for personnel to view packet exchange processes and locate the root cause. It is found that IP addresses in the DHCP address pool are exhausted, preventing IP addresses from being assigned to mobile terminals. Which of the following functions is used by O&M personnel in this scenario?)

Options:

A.

Protocol trace

B.

Simulation feedback

C.

Issue analysis

D.

Client journey

Question 13

Complete the following static VXLAN tunnel configurations by dragging the configurations to the corresponding areas.

Options:

Question 14

(When access authentication is deployed on a network, which of the following servers typically reside in the pre-authentication domain?)

Options:

A.

FTP server

B.

Antivirus server

C.

DHCP server

D.

DNS server

Question 15

(On a campus network, iMaster NCE-Campus is used to deploy two VNs: R&D VN and marketing VN, users in these two VNs belong to two security groups, respectively. The campus network requires R&D personnel and sales personnel to communicate with each other. To meet this requirement, which of the following tasks does a network administrator need to perform?)

Options:

A.

Deploy a policy control matrix.

B.

Deploy an external network.

C.

Configure access management.

D.

Configure inter-VN communication.

Question 16

(The egress zone is the boundary between a campus network and external networks, including the Internet and WAN. It bridges the intranet and extranet and protects the security of the campus network. Which of the following are requirements for egress zone design?)

Options:

A.

Service control capability

B.

Various and flexible access modes

C.

Network connectivity

D.

Network secure ensurance

Question 17

(If the number of MAC addresses learned on an interface enabled with port security reaches the upper limit, which of the following actions may the switch take?)

Options:

A.

Sets the interface state to error-down and generates an alarm.

B.

Sets the interface state to error-down without generating any alarm.

C.

Discards packets with unknown source MAC addresses without generating any alarm.

D.

Discards packets with unknown source MAC addresses and generates an alarm.

Question 18

(APs in the Agile Distributed Wi-Fi Solution include central APs and RUs. A central AP can manage multiple RUs, so no AC is needed in the Agile Distributed Wi-Fi Solution.)

Options:

A.

TRUE

B.

FALSE

Question 19

(The Huawei CloudCampus Solution supports various rate limiting modes for wireless users in small- and medium-sized campus scenarios. Which of the following modes is suitable for refined traffic control of each user?)

Options:

A.

User-based rate limiting

B.

SSID-based rate limiting

C.

ACL-based rate limiting

D.

Radio-based rate limiting

Question 20

(Huawei iMaster NCE-Campus provides the financial SD-WAN SRv6 solution to help the financial industry implement end-to-end scheduling. To use this function, you need to obtain the SRv6 function package license.)

Options:

A.

TRUE

B.

FALSE

Question 21

(Fabric nodes need to be planned during fabric design on a CloudCampus virtualized campus network. Which of the following statements about node planning on a fabric is false?)

Options:

A.

It is recommended that core devices be deployed as border nodes, and access or aggregation devices be deployed as edge nodes.

B.

It is recommended that access devices be deployed as edge nodes to implement end-to-end automatic VXLAN deployment.

C.

When the fabric needs to connect to two external networks located in different physical locations, two border nodes need to be deployed.

D.

If a BGP EVPN RR is required on a VXLAN network, BGP peer relationships need to be established between edge nodes and border nodes and between edge nodes.

Question 22

(As shown in the figure,

SW1 and SW2 use asymmetric IRB forwarding, and PC1 and PC2 communicate with each other. Which of the following is the destination MAC address of the original data frame in the packet sent from VTEP1 to VTEP2?)

Options:

A.

MAC D

B.

MAC A

C.

MAC B

D.

MAC C

Question 23

(On a virtualized network deployed using iMaster NCE-Campus, after an administrator performs an operation, iMaster NCE-Campus delivers the following configuration to devices. Which operation did the administrator perform?

ip vpn-instance MKT

ipv4-family

route-distinguisher 3:6

vpn-target 0:6 export-extcommunity

vpn-target 0:6 export-extcommunity evpn

vpn-target 0:6 import-extcommunity

vpn-target 0:6 import-extcommunity evpn

vxlan vni 6

Options:

A.

Create a network service resource named MKT.

B.

Create a fabric named MKT.

C.

Create an external network named MKT.

D.

Create a VN named MKT.

Question 24

(Which of the following advantages are provided by Telemetry compared with SNMP?Choose all that apply.)

Options:

A.

Telemetry supports various data types based on the YANG model.

B.

Telemetry establishes sessions based on SSH, ensuring security.

C.

Telemetry configures and manages different databases of managed devices.

D.

Telemetry supports second-level data collection with higher precision.

Question 25

(DHCP snooping is a security feature of DHCP that prevents DHCP servers and clients from being attacked. Which of the following statements about DHCP snooping are true?Choose all that apply.)

Options:

A.

A DHCP snooping-enabled device listens to DHCP messages and records client information obtained from DHCP Offer messages.

B.

After DHCP snooping is enabled on a switch, you need to configure the interface that receives DHCP messages from a DHCP server as a trusted interface.

C.

The device discards messages, such as DHCP ACK and DHCP Offer messages, received on untrusted interfaces from a DHCP server.

D.

When the interface directly connected to a DHCP client goes Down, the corresponding DHCP snooping entry does not disappear until the IP address lease of the DHCP client expires.

Question 26

(When a BGP EVPN route is transmitted between VTEPs, the BGP EVPN route is discarded only when the RT carried in the route is different from both the EVPN IRT and IP VPN IRT.)

Options:

A.

TRUE

B.

FALSE

Question 27

(Which of the following commands needs to be run in the BGP view to enable a VPN instance to advertise IP routes to the BGP-EVPN address family?)

Options:

A.

advertise vpnv4

B.

advertise irbv6

C.

advertise irb

D.

advertise l2vpn evpn

Question 28

(Which of the following is used to implement inter-subnet communication on a VXLAN network and allow access from a VXLAN network to an external non-VXLAN network?)

Options:

A.

Layer 3 VXLAN gateway

B.

VLANIF interface

C.

NVE interface

D.

Layer 2 VXLAN gateway

Question 29

(As shown in the following figure, R1 and R2 establish an IPsec VPN in ISAKMP mode for communication. For IPsec proposals on R1 and R2, ESP is used, the encapsulation mode is set to tunnel mode, SHA1 is configured as the authentication algorithm, and AES-256 is configured as the encryption algorithm. In addition, IKEv1 is configured for IKE peers, the main mode is configured for IKEv1 negotiation phase 1, and the PSK Huawei@123 is configured for PSK authentication between IKE peers. For IKE proposals on R1 and R2, SHA1 is configured as the authentication algorithm, AES-256 is configured as the encryption algorithm, and DH group 1 is configured for IKE negotiation. Based on these configurations on R1 and R2, drag the configuration items on the left to the correct locations on the right.)

Options:

Question 30

(Which of the following information types are transmitted through enhanced BGP EVPN in Huawei SD-WAN Interconnection Solution?)

Options:

A.

GRE configuration

B.

TNP route

C.

IPsec SA information

D.

Service route

Question 31

(In the Huawei CloudCampus Solution, which of the following provisioning modes isnot supportedby firewalls?)

Options:

A.

Web interface

B.

Registration center query

C.

DHCP Option 148

D.

CLI

Demo: 31 questions
Total 104 questions