GB0-283-LAB Real Exam Answers

GB0-283-LAB Exam Description
Questions and Answers:6 Q&As

Updated: 2009-10-11
Exam Number/Code: GB0-283-LAB
Exam Name: Constructing Enterprise-level Routing Networks

Certinside professional IT Q&A vendors, we provide well after-sale service. To all the customers buy the Q&As, we provide track service. when you buy the Q&As with in 3 months. you can enjoy the upgrade Q&As service for free. If in this period, the certified test center change the H3C GB0-283-LAB Q&As, we will update the Q&A in the first time, and provide you the download update for free

GB0-283-LAB Free Demo Download

Certinside offers free demo for GB0-283-LAB 6 Q & As with Expert Explanations). You can check out the interface, question quality and usability of our practice exams before you decide to buy it.


Download GB0-283-LAB Exam Pdf Demo

Download GB0-283-LAB Exam iEngine Demo

  • Share/Bookmark
Posted in H3C. Comments Off »

GB0-540 Real Exam Answers

GB0-540 Exam Description
Questions and Answers:177 Q&As

Updated: 2009-09-14
Exam Number/Code: GB0-540
Exam Name: Advanced Intrusion Prevention System Configuration

Certinside professional IT Q&A vendors, we provide well after-sale service. To all the customers buy the Q&As, we provide track service. when you buy the Q&As with in 3 months. you can enjoy the upgrade Q&As service for free. If in this period, the certified test center change the H3C Others GB0-540 Q&As, we will update the Q&A in the first time, and provide you the download update for free

 
 
Exam : H3C GB0-540
Title : H3C Certified Senior Engineer for Security – IPS

1. TippingPoint对BT下载进行限流,依靠的是TippingPoint的哪种保护功能?
A. 应用层保护
B. 基础设施保护
C. 性能保护
Answer: C

2. 在CLI操作中,显示TippingPoint配置的命令是( )。
A. show config
B. dis config
C. dis configuration
D. show configurarion
Answer: D

3. 下列选项中,属于DoS攻击的有( )。
A. TFN
B. Syn Flood
C. Land
D. ICMP Flood
Answer: ABCD

4. 对报文的源地址反查路由表,入接口与以该地址为目的地址的最佳出接口不同的IP报文被视为( )攻击。
A. IP Spoofing
B. Land
C. Fraggle
D. ICMP Redirect
Answer: A

5. Notification Contacts包括的组合有( )。
A. SMS + Remote system log + LSM
B. Remote System Log + Management Console
C. Management Console + SMS
D. LSM + Management Console + SMS
Answer: AB

6. TippingPoint设备支持的网管设备只有SMS,其它网管设备不支持。
A. True
B. False
Answer: B

7. 攻击者向目标主机发送源地址和目的地址均为该主机地址的TCP SYN报文,并以此来达到攻击目的,这种攻击的名称是( )。
A. Smurf
B. Land
C. Fraggle
D. IP Spoofing
Answer: B

8. 网络钓鱼的危害表现在( )。
A. 盗取用户的银行卡或者信用卡的帐户的密码,使用户遭受经济上的损失。
B. 产生大量的TCP办连接,使网络资源被大量消耗。
C. 大量占用网络带宽,使其他用户无法正常浏览网页。
D. 传播大量的病毒到网络上,造成其它设备无法正常使用。
Answer: A

9. TippingPoint支持单设备管理LSM和企业级集中管理SMS两种管理架构。
A. True
B. False
Answer: A

10. TippingPoint IPS对应用保护的过滤器分为哪几类?
A. Attack Pretection, Reconnaissance, Security Policy, Informational
B. Attack Pretection, Scan, Security Policy, Informational
C. Attack Pretection, Reconnaissance, Misuser&Abuse, Informational
D. Attack Pretectio, Scan, Security Policy, Misuser&Abuse
Answer: A

11. 使用Web方式登陆TippingPoint,每次最多只能同时登录一个用户。
A. True
B. False
Answer: B

12. TippingPoint的优势在于( )。
A. 对第二层到第七层实行全部的检查
B. 对存在的漏洞提供保护
C. 实现零时差攻击保护
D. 防止应用程序和操作系统损坏或宕机
E. 不必紧急实施为危险漏洞打补丁
Answer: ABCDE

13. 下面属于泛洪攻击的是( )。
A. ICMP-flood
B. UDP-flood
C. TCP-flood
D. SYN-flood
Answer: ABD

14. 在SMS操作中,当TippingPoint检测到接入客户端的非法活动时,SMS进行基于策略的门限控制,SMS发送Trap到NMS或者根据配置执行相应的动作。
A. True
B. False
Answer: A

15. Smurf攻击为了达到攻击的目的,采用的攻击手段是( )。
A. 伪造一个SYN报文,其源地址是伪造的不存在的地址,向受害主机发起连接。
B. 向同一个子网的主机发送ICMP重定向报文,请求主机改变路由。
C. 发送ICMP应答请求报文,该请求的目的地址设置为受害网络的广播地址。
D. 利用那些在TCP/IP堆栈实现中信任IP碎片中的报文头所包含的信息来实现自己的攻击。
Answer: C

16. 客户想下载最新的数字疫苗,可以从下列哪个网站获取?
A. www.huawei-3com.com
B. www.3com.com
C. www.huawei.com
D. www.tippingpoint.com
Answer: D

  • Share/Bookmark
Posted in H3C. Comments Off »

GB0-520 Real Exam Answers

GB0-520 Exam Description
Questions and Answers:319 Q&As

Updated: 2009-09-17
Exam Number/Code: GB0-520
Exam Name: Building Secure Virtual Private Networks

Certinside professional IT Q&A vendors, we provide well after-sale service. To all the customers buy the Q&As, we provide track service. when you buy the Q&As with in 3 months. you can enjoy the upgrade Q&As service for free. If in this period, the certified test center change the H3C Others GB0-520 Q&As, we will update the Q&A in the first time, and provide you the download update for free

 
 
Exam : H3C GB0-520
Title : Building Secure Virtual Private Networks

1. 为保证每个安全联盟所使用的密钥互不相关,每次建立安全联盟都要经过 DH 交换过程。
T. True
F. False
Answer: T

2. 可提供数据加密功能的 IPSec 协议有( )。
A. AH
B. ESP
C. IKE
D. ISAKMP
Answer: B

3. 在 SSL 协议中,一个加密套件包括( )。
A.密钥交换算法
B.加密算法
C. HMAC 算法
D. SHA 算法
Answer: ABC

4. SecPath防火墙产品的 HT 加密卡不可以热插拔。
T. True
F. False
Answer: T

5. DVPN 支持全动态地址,即使两个 Client 的 IP 地址都不是静态的,而是动态分配的,也可以自动建立 DVPN 隧道。
T. True
F. False
Answer: F

6. PFS 之所以更安全,是因为每次协商出的 SPI 均不相同。
T. True
F. False
Answer: F

7. 下面不属于 SSL 握手消息的是( )。
A. ClientHello
B. Alert
C. ChangeCipherSpec
D. ApplicationData
Answer: BCD

8. 若L2TP VPN接入方式形如"移动员工-PSTN-LAC-Internet-LNS-总部内网",对这种接入方式,正确的说法有( )。
A. LAC 设备多由 ISP 提供; LNS 设备多由总部提供
B. 用户接入的 AAA 服务由 LAC 设备完成
C. 用户的最终授权和验证工作由 LNS 完成
D. L2TP 隧道由 LAC 发起,由 LNS 终结
E. PPP 通道最终建立在移动员工和 LAC 之间
Answer: ABCD

9. IPSec 的配置中规定,一个接口上只能应用一个安全策略组,一个安全策略组中可包括多条策略。
T. True
F. False
Answer: T

10. SecPath系列安全网关支持多种 VPN 业务,其中能提供数据机密性的是( )。
A. L2TP VPN
B. IPSec VPN
C. SSL VPN
D. GRE VPN
Answer: BC

11. SSL 版本正确的是( )。
A. SSL 1.0
B. SSL 2.0
C. SSL 3.0
D. TLS 3.0
Answer: ABC

12. 密钥长一倍,安全强度就提高一倍。
T. True
F. False
Answer: F

13. 只有将报文加密才能保证不被篡改,除此之外其他办法均无效。
T. True
F. False
Answer: F

14. AH 和 ESP 均可以穿越 NAT 。
T. True
F. False
Answer: F

15. 网络通信对安全性的要求包括( )。
A. 一致性
B. 私密性
C. 完整性
D. 身份验证
Answer: BCD

16. L2TP 隧道的建立是一个三次握手的过程,而 L2TP 会话的建立是一个四次握手的过程。
T. True
F. False
Answer: F

  • Share/Bookmark
Posted in H3C. Comments Off »

GB0-500 Real Exam Answers

GB0-500 Exam Description
Questions and Answers:224 Q&As

Updated: 2009-09-16
Exam Number/Code: GB0-500
Exam Name: Implementing Secure Firewalls

Certinside professional IT Q&A vendors, we provide well after-sale service. To all the customers buy the Q&As, we provide track service. when you buy the Q&As with in 3 months. you can enjoy the upgrade Q&As service for free. If in this period, the certified test center change the H3C Others GB0-500 Q&As, we will update the Q&A in the first time, and provide you the download update for free

 
 
Exam : H3C GB0-500
Title : Implementing Secure Firewalls

1. IP Spoofing攻击的手段是( )。
A. 伪造IP地址
B. 窃取密码
C. 窃听IP通信
D. 攻击IP协议栈
Answer: A

2. 邮件的收件人过滤可配置的收件人地址长度最大值为( )。
A. 64
B. 128
C. 256
D. 512
Answer: B

3. 下列哪些属于防火墙的必备技术?
A. 网络隔离及访问控制
B. 攻击防范
C. 地址转换
D. 应用层状态检测
E. 身份认证
F. 内容过滤
G.安全管理
Answer: ABCDEFG

4. 在SYN Flood攻击防范命令中可以设置( )。
A. enable
B. ip
C. zone
D. blacklist
E. max-rate
F. tcp-proxy
Answer: ABCEF

5. 以下哪些攻击需要配置域统计。
A. ICMP Flood
B. SYN Flood
C. UDP Flood
D. ARP Flood
Answer: ABC

6. TACL主要用于匹配一个会话中的所有返回的报文,可以为某一应用返回的报文在防火墙的外部接口上建立一个临时的返回通道。
T. True
F. False
Answer: T

7. 随着网络技术的普及,网络攻击行为出现得越来越频繁。目前,Internet上常见的安全威胁分为以下几类:非法使用,拒绝服务,信息盗窃,数据篡改等。
T. True
F. False
Answer: T

8. 防火墙主要关注边界安全,提供防止常见网络层攻击的特性。SecPath防火墙发现下列哪些网络攻击行为后,可能不会丢弃其报文?
A. IP Spoofing
B. WinNuke
C. IP-Sweep
D. TearDorp
Answer: C

9. SecPath防火墙的ASPF作为改进的状态检测安全技术,支持以下哪些应用协议检测?
A. PPTP
B. HTTP
C. TFTP
D. FTP
Answer: ABD

10. SecPath500F防火墙可以实现( )个MIM接口扩展。
A. 0
B. 1
C. 2
D. 3
Answer: C

11. 以下关于安全区域描述不正确的是( )。
A. 不同安全区域的安全级别可以相同
B. 一个接口可以添加到多个安全区域中
C. 一个安全区域中可以添加无限个接口
D. Inloopback0接口可以添加到任何安全区域中
Answer: ABCD

12. 利用HWTACACS协议认证与授权分离的特性,可以使用RADIUS进行认证,而使用HWTACACS进行授权。
T. True
F. False
Answer: T

13. SecPath系列防火墙可以工作在多种模式下, 在( )下, 防火墙通过二层对外连接,所有接口无IP地址。
A. 路由模式
B. 透明模式
C. 混合模式
D. 攻击防范模式
Answer: B

14. 下列哪些功能是无法通过Web网管进行配置的?
A. GRE 相关配置
B. L2TP相关配置
C. PPPoE相关配置
D. 网页过滤相关配置
Answer: AC

15. 下列防火墙技术中,能够实现单向访问控制的有( )。
A. 应用层状态检测
B. 内容过滤
C. 地址转换
D. 攻击防范
Answer: AC

16. ACL可以应用于整机或指定接口上,过滤数据包。除此之外,ACL还可以用于( ) 。
A. QoS中,对数据流量进行分类;
B. DCC中,用来规定触发拨号的条件;
C. NAT中;
D. 报文转发,提高转发速度。
Answer: ABC

  • Share/Bookmark
Posted in H3C. Comments Off »

GB0-323English Real Exam Answers

GB0-323English Exam Description
Questions and Answers:300 Q&As

Updated: 2009-08-06
Exam Number/Code: GB0-323English
Exam Name: Constructing Enterprise-level Switching Networks

Certinside professional IT Q&A vendors, we provide well after-sale service. To all the customers buy the Q&As, we provide track service. when you buy the Q&As with in 3 months. you can enjoy the upgrade Q&As service for free. If in this period, the certified test center change the H3C HCSE GB0-323English Q&As, we will update the Q&A in the first time, and provide you the download update for free

GB0-323English Free Demo Download

Certinside offers free demo for GB0-323English 300 Q & As with Expert Explanations). You can check out the interface, question quality and usability of our practice exams before you decide to buy it.


Download GB0-323English Exam Pdf Demo

Download GB0-323English Exam iEngine Demo

 
 
Exam : HuaWei GB0-323English
Title : Constructing Enterprise-level Switching Networks

1. STP is a routing protocol.
A. True
B. False
Answer: B

2. The reason why RSTP can implement fast restoration of the network is that ( ).
A. RSTP reduces the delay from the Blocking state to the Forwarding state.
B. The port will enter the Forwarding state immediately if the old Root port turn in the Blocking state and the remote end of the new Root port is in the Forwarding state.
C. A non-edge Designated port needs only one handshake with the downstream bridge to transfer from the Blocking state to the Forwarding state quickly.
D. Soon after the bridge is started, the edge port enters the Forwarding state without delay.
Answer: ABCD

3. Which of the following statements is right about 802.1x ports? ( )
A. 802.1x supports the port-based authentication only.
B. The ports of authenticator fall into controlled ports and uncontrolled ports.
C. Uncontrolled ports always forward bi-directionally whether the authentication is passed or not.
D. Controlled ports transmit EAPOL protocol packets only.
Answer: BC

4. Which of the following is right about the GARP application? ( )
A. The switches in a network domain automatically share the VLAN information and multicast group configuration information.
B. The whole switching network can be monitored precisely through a switch.
C. The changed VLAN or multicast group configuration will be advertised to the whole switching network dynamically, thus reducing the maintenance cost and improving the reliability.
D. Plug-and-play of VLANs and multicast groups are implemented.
Answer: ABCD

5. On the H3C switch, VRRP can be used to implement ( ).
A. Gateway backup of the LAN
B. Gateway backup of the WAN
C. Load balance
D. Port monitoring for improving network reliability
Answer: ACD

6. Which of the following statements is correct? ( )
A. igmp timer query seconds is used to set the interval of the query packet sending on the switch.
B. igmp timer query seconds is used to set the maximum response time in the query packet.
C. igmp max-response-time seconds is used to set the maximum response time in the query packet.
D. igmp timer other-querier-present seconds is used to set the timeout time of the snooping querier on the switch.
Answer: ACD

7. Which of the following is correct about the PIM Hello message? ( ):
A. The Hello message is sent periodically to all PIM routers in multicast group 224.0.0.13 to establish PIM neighbourship.
B. The Hello message is used to select the DR on the multi-access network.
C. As the IGMP message, the Hello message is used to maintain the relationship between interfaces and host members.
D. When IGMP V1 is adopted on the interface, the Hello message is used to select the DR as the IGMP V1 querier.
Answer: ABD

8. Multicast protocols fall into group member management protocols and multicast routing protocols. Which of the following is a group member management protocol? ( )
A. GVRP
B. GMRP
C. IGMP
D. PIM
Answer: C

9. IGMP is a signaling protocol between hosts and the router, which defines the mechanism to establish and maintain the multicast membership between hosts and the router. ( )
A. True
B. False
Answer: A

10. VLAN can be defined based on ( ).
A. IP addresses
B. Network layers
C. MAC addresses
D. Ports
Answer: ACD

11. The length of PAUSE MAC control frame defined in IEEE802.3x is ( ).
A. 16 bytes
B. 32 bytes
C. 64 bytes
D. 96 bytes
Answer: C

12. On the H3C S middle-end/low-end switches, STP is enabled by default. ( )
A. True
B. False
Answer: B

13. SwitchA is an H3C S Layer-2 switch. PC1, PC2 and PC3 connect to E0/1, E0/2 and E0/3 of SwitchA. The three ports belong to VLAN 10, VLAN 20 and VLAN 30 respectively. A server connects to port G1/1 of the switch, which belongs to VLAN100. The PCs are required to isolate from each other, and the PCs shall be able to access the server. After completing the configuration, which of the following statements is right about the switch ports? ( )
A. E0/1 is an access port, with the PVID VLAN 10.
B. E0/2 is a hybrid port, with the Untagged VLAN ID 100, and the Tagged VLAN ID 10.
C. E0/2 is a Hybrid port, with the Untagged VLAN IDs 20 and100, and the Tagged VLAN ID none.
D. G1/1 is a Hybrid port, with the Untagged VLAN IDs 10, 20, and 30, and the Tagged VLAN ID 100.
Answer: C

14. In STP, it is suggested to modify the value of Max Age indirectly through setting the network diameter. ( )
A. True
B. False
Answer: A

15. Which of the following methods cannot be used to configure H3C middle-end and low-end switches? ( )
A. Console
B. Xmodem
C. Telnet
D. Dial-up with Modems
Answer: B

16. 802.1D defines the Disabled state of STP. Which of the following is correct about the port in the Disabled state? ( )
A. It does not receive/send any packet.
B. It does not receive/forward data. It receives but does not send BPDUs, and does not learn addresses.
C. It does not receive/forward data. It receives and forwards BPDUs, and does not learn addresses.
D. It does not receive/forward data. It receives and forwards BPDUs. It begins to learn addresses.
E. It receives or forwards data. It receives and forwards BPDUs. It begins to learn addresses.
Answer: A

  • Share/Bookmark
Posted in H3C. Comments Off »

GB0-363English Real Exam Answers

GB0-363English Exam Description
Questions and Answers:317 Q&As

Updated: 2009-08-06
Exam Number/Code: GB0-363English
Exam Name: Designing Enterprise-level Networks

Certinside professional IT Q&A vendors, we provide well after-sale service. To all the customers buy the Q&As, we provide track service. when you buy the Q&As with in 3 months. you can enjoy the upgrade Q&As service for free. If in this period, the certified test center change the H3C HCSE GB0-363English Q&As, we will update the Q&A in the first time, and provide you the download update for free

GB0-363English Free Demo Download

Certinside offers free demo for GB0-363English 317 Q & As with Expert Explanations). You can check out the interface, question quality and usability of our practice exams before you decide to buy it.


Download GB0-363English Exam Pdf Demo

Download GB0-363English Exam iEngine Demo

 
 
Exam : HuaWei GB0-363English
Title : Designing Enterprise-level Networks

1. To transit a SOHO network to IPv6, we should ( ).
A. Choose an appropriate tunnel technology to access the IPv6 Internet according to the access mode provided by the ISP
B. Use the dual-stack technology to enable all the hosts to access IPv6 and IPv4 network concurrently
C. Use 6to4 technology to access the IPv6 Internet if the ISP does not provide any IPv6 access
D. Use the 6PE technology to access the IPv6 Internet if the ISP provides 6PE access
Answer: AC

2. Which of the following descriptions about dynamic routing protocol is correct? ( )
A. The fundamentals of RIPng are the same as those of RIP, but RIPng speeds up convergence compared with RIP.
B. The packet format of OSPFv3 is the same as that of OSPF, but OSPFv3 can support IPv6.
C. MBGP is the unique EGP routing protocol in the IPv6 network.
D. IS-IS supports multiple protocols so that it can support IPv6 without any modification.
Answer: C

3. In a Layer 2 switching network, if only IGMP Snooping is enabled on the switch, what will happen? ( )
A. Multicast fails.
B. Multicast works properly, but IGMP Snooping cannot correctly record the member port information.
C. Multicast works properly, and IGMP Snooping can correctly record the member port information.
D. IGMP Snooping will work properly if IGMP Spoofing is enabled.
Answer: A

4. Which of the following descriptions about QoS is/are correct? ( )
A. Traffic policing can be applied on the inbound or outbound interfaces.
B. Traffic shaping can be applied on the inbound or outbound interfaces.
C. Congestion management and queue scheduling can be applied on the inbound or outbound interfaces.
D. RED and WRED are used to avoid TCP global synchronization.
Answer: AD

5. In an MSTP region, all switches must support the MSTP. There is not such a switch that supports RSTP or STP only.
A. True
B. False
Answer: A

6. Which of the following is/are correct about data link layer backup? ( )
A. The PPP MP can provide automatic backup and load balancing among the links in a bundle.
B. The dial-watch continuously sends ICMP packets to detect whether the peer is reachable.
C. IEEE 802.3ad can provide automatic backup and load balancing among the links in a bundle.
D. The RPR uses the probe packet at the data link layer to realize self-healing in case of link failure.
Answer: AD

7. The superiority of OSPF to RIP includes ( ).
A. Variable long subnet mask
B. Multicasting update
C. Protocol packet authentication
D. No routing loop
E. Fast convergence
Answer: DE

8. The security services in the Open System Interconnection security architecture include ( ) and anti-DoS.
1) Authentication
2) Access control
3) Data privacy service
4) Data integrity service
A. 1) and 2)
B. 1), 2) and 3)
C. 2) and 4)
D. 1), 2), 3) and 4)
Answer: D

9. The common security equipment includes the Firewall, Intrusion Detection System (IDS) and Intrusion Prevention System (IPS). The IDS serves as the gateway and is deployed on the path of main service traffic, while the Firewall and IPS are deployed on the bypass.
A. True
B. False
Answer: B

10. Which of the following descriptions about the BGP route aggregation is correct? ( )
A. It advertises the aggregation route only.
B. It cannot aggregate routes and advertises the original routes only.
C. It can advertise the aggregation route and the original routes.
D. The original AS-Path attribute is changed during route aggregation.
Answer: C

11. On the basis of the port-based dynamic NAT, GRE can work properly after NAT traversal.
A. True
B. False
Answer: B

12. To prevent route spoofing, it is preferred to set the OSPF enabled interface that is connected to the users intranet to the Silent state and enable MD5 authentication.
A. True
B. False
Answer: B

13. PIM-SM may not need RP.
A. True
B. False
Answer: B

14. if the data link layer protocol in the OSPF P2P network is PPP, two OSPF routers whose interface addresses are in different subnets can still establish adjacency and learn the routing information correctly.
A. True
B. False
Answer: A

15. Which is the encapsulation format used in ADSL dial-up access initiated from PC? ( )
A. IPoA
B. IPoEoA
C. PPPoA
D. PPPoEoA
Answer: D

16. Which of the following port states is/are defined in both STP and RSTP? ( )
A. Disabled
B. Blocking
C. Listening
D. Learning
E. Forwarding
Answer: DE

  • Share/Bookmark
Posted in H3C. Comments Off »

GB0-283English Real Exam Answers

GB0-283English Exam Description
Questions and Answers:300 Q&As

Updated: 2009-08-06
Exam Number/Code: GB0-283English
Exam Name: Constructing Enterprise-level Routing Networks

Certinside professional IT Q&A vendors, we provide well after-sale service. To all the customers buy the Q&As, we provide track service. when you buy the Q&As with in 3 months. you can enjoy the upgrade Q&As service for free. If in this period, the certified test center change the H3C HCSE GB0-283English Q&As, we will update the Q&A in the first time, and provide you the download update for free

GB0-283English Free Demo Download

Certinside offers free demo for GB0-283English 300 Q & As with Expert Explanations). You can check out the interface, question quality and usability of our practice exams before you decide to buy it.


Download GB0-283English Exam Pdf Demo

Download GB0-283English Exam iEngine Demo

 
 
Exam : HuaWei GB0-283English
Title : Constructing Enterprise-level Routing Networks

1. Which of the following descriptions about BGP route aggregation is/are correct? ( )
A. Route aggregation is to aggregate routes of all segments into one or more aggregation routes so as to reduce the size of routing table.
B. If the keyword detail-suppressed is added to the BGP summary command, only the aggregation routes are advertised.
C. BGP route aggregation takes effect on the route imported through the network command only.
D. BGP route aggregation takes effect on the route imported through the import command only.
Answer: AB

2. CAR is realized at the IP layer so that it can only limit the traffic of IP packets. Compared with CAR, LR can limit all the traffic passing through the physical interface.
A. True
B. False
Answer: A

3. 0.0/24, 192.168.1.0/24, 192.168.2.0/24 and 192.168.3.0/24. These routes are aggregated to one route 192.168.0.0/22 by the ABR. Which routes will the ABR redistribute to the other areas? ( )
A. One aggregation route
B. The four original routes
C. One aggregation route and the four original routes
D. None
Answer: B
4. Which of the following descriptions about the IPSec Security Association (SA) is/are correct? ( )
A. The data security service provided by IPSec is realized through SAs.
B. One SA is a unidirectional logical connection between two IPSec peers.
C. The inbound data flow and outbound data flow are respectively processed by the inbound SA and outbound SA.
D. SAs can be set up by the means of manual configuration or automatic negotiation.
Answer: A

4. Which of the following descriptions about route import is/are correct? ( )
A. A routing protocol can import the routes discovered by other routing protocols to enrich its routing information.
B. While importing routes from a routing protocol to another, we can define a route-policy to filter out the unexpected routes.
C. In the process of route importing, it is necessary to specify a metric for the imported route if the target routing protocol cannot directly use the metric of the source routing protocol.
D. Bi-directional importing indicates that two routing protocols import the routes from each other. It may cause routing loop.
Answer: ABCD

5. 45.0.0 0.0.0.255
nssa default-route-advertise
#
area 0.0.0.0
network 4.4.4.4 0.0.0.0
network 10.34.0.0 0.0.0.255
Which of the following descriptions about the above network diagram and configuration is correct? ( )
A. RouterD redistributes a Type 7 LSA for a default route in Area 1. RouterE and RouterF can receive this LSA.
B. RouterD redistributes a Type 5 LSA for a default route in Area 1. RouterE and RouterF can receive this LSA.
C. RouterC can receive a Type 5 LSA for a default route redistributed by RouterD.
D. None of the above
Answer: A
10. Which of the following descriptions about OSPF STUB area is wrong? ( )
A. A backbone area cannot be configured as STUB area and a virtual link cannot pass through a STUB area.
B. It is unnecessary to configure this attribute on all routers in a STUB area.
C. There is no ASBR in a STUB area.
D. After an area is configured as STUB area, the Type 3 LSA of other areas can be propagated in this area.
Answer: B

6. What is the meaning of the BGP command aggregate 10.110.0.0 255.255.0.0 suppress-policy test ? ( )
A. Advertise the aggregation route only
B. Advertise the aggregation route and all the aggregated routes
C. Advertise the aggregation route and some aggregated routes that meet the filtering conditions
D. Advertise the aggregated routes only,
Answer: C

7. Which of the following descriptions about route aggregation in OSPF is/are wrong? ( )
A. The ABR can automatically summarize routes without manual configuration.
B. Aggregation can be made only on the ABR.
C. The router serving as the ABR and the ASBR concurrently cannot summarize routes.
D. The ASBR can summarize all external routes.
Answer: ABCD

8. When a BGP Speaker advertises the imported IGP routes to the IBGP neighbor, the AS-Path value is the local AS number.
A. True
B. False
Answer: B

9. 0.0.5
B. 224.0.0.6
C. 224.0.0.9
D. 224.0.0.10
Answer: AB
2. Which of the following descriptions about route aggregation in OSPF is/are wrong? ( )
A. The ABR can automatically summarize routes without manual configuration.
B. Aggregation can be made only on the ABR.
C. The router serving as the ABR and the ASBR concurrently cannot summarize routes.
D. The ASBR can summarize all external routes.
Answer: ABCD

10. The multicast address used by OSPF is ( ).
A. 224.0.0.5
B. 224.0.0.6
C. 224.0.0.9
D. 224.0.0.10
Answer: AB

11. A BGP router receives a new route from its EBGP peer, which of the following descriptions is correct? ( )
A. The router will immediately send the route to its BGP peers.
B. The router will look up this route in its routing table. If the route is not recorded in the routing table, it will send the route to its BGP peers.
C. The router will check the sent routes information. If it never sends such a route, it will send the route to its BGP peers.
D. The router will check the sent routes information. If it has sent such a route, it will not send the route to its BGP peers.
Answer: C

12. Which of the following descriptions about queue is correct? ( )
A. WFQ discarding mechanism is Tail Drop on each queue, the same as CQ.
B. WFQ classifies data flow by using ACL.
C. CBWFQ is an improvement of WFQ using the same basic scheduling as WFQ.
D. LLQ will first check the low-latency queue and take packets from the queue. Only when there is no packet in the low-delay queue, it will take the packets from other queues. In addition, it uses other mechanisms to avoid starving to death of the queues.
Answer: D

13. The BGP mandatory attributes include ( ).
A. Origin
B. AS-Path
C. Next-hop
D. MED
E. Local-preference
F. Community
Answer: ABC

14. As shown in the figure, Area 1 is an NSSA area and RouterD is the ABR of the area. The configuration on RouterD is as follows:
ospf 1
area 0.0.0.1
network 10.45.0.0 0.0.0.255
nssa default-route-advertise
#
area 0.0.0.0
network 4.4.4.4 0.0.0.0
network 10.34.0.0 0.0.0.255
Which of the following descriptions about the above network diagram and configuration is correct? ( )
A. RouterD redistributes a Type 7 LSA for a default route in Area 1. RouterE and RouterF can receive this LSA.
B. RouterD redistributes a Type 5 LSA for a default route in Area 1. RouterE and RouterF can receive this LSA.
C. RouterC can receive a Type 5 LSA for a default route redistributed by RouterD.
D. None of the above
Answer: A

15. The ASBR imports four external routes, 192.168.0.0/24, 192.168.1.0/24, 192.168.2.0/24 and 192.168.3.0/24. These routes are aggregated to one route 192.168.0.0/22 by the ABR. Which routes will the ABR redistribute to the other areas? ( )
A. One aggregation route
B. The four original routes
C. One aggregation route and the four original routes
D. None
Answer: B

16. Which of the following descriptions about QoS at the access, convergence and core layers is/are correct? ( )
A. QoS is implemented identically in the access, convergence and core layers.
B. Packets are classified and marked in the access layer.
C. No QoS mechanism should be configured in the access layer.
D. Usually, the queuing mechanism (such as CBQ) and the congestion avoidance mechanism (such as WRED) should be used in the convergence layer.
Answer: BD

  • Share/Bookmark
Posted in H3C. Comments Off »

GB0-190 Real Exam Answers

GB0-190 Exam Description
Questions and Answers:198 Q&As

Updated: 2009-08-22
Exam Number/Code: GB0-190
Exam Name: Construction Small-and Medium-Sized Enterprise Network

Certinside professional IT Q&A vendors, we provide well after-sale service. To all the customers buy the Q&As, we provide track service. when you buy the Q&As with in 3 months. you can enjoy the upgrade Q&As service for free. If in this period, the certified test center change the H3C Others GB0-190 Q&As, we will update the Q&A in the first time, and provide you the download update for free

  • Share/Bookmark
Posted in H3C. Comments Off »

GB0-190Chinese Real Exam Answers

GB0-190Chinese Exam Description
Questions and Answers:446 Q&As

Updated: 2009-08-25
Exam Number/Code: GB0-190Chinese
Exam Name: Construction Small-and Medium-Sized Enterprise Network

Certinside professional IT Q&A vendors, we provide well after-sale service. To all the customers buy the Q&As, we provide track service. when you buy the Q&As with in 3 months. you can enjoy the upgrade Q&As service for free. If in this period, the certified test center change the H3C Others GB0-190Chinese Q&As, we will update the Q&A in the first time, and provide you the download update for free

GB0-190Chinese Free Demo Download

Certinside offers free demo for GB0-190Chinese 446 Q & As with Expert Explanations). You can check out the interface, question quality and usability of our practice exams before you decide to buy it.


Download GB0-190Chinese Exam Pdf Demo

Download GB0-190Chinese Exam iEngine Demo

 
 
Exam : H3C GB0-190Chinese
Title : Construction Small-and Medium-Sized Enterprise Network

1. 在Windows操作系统中,哪一条命令能够显示ARP表项信息?
A. display arp
B. arp -a
C. arp -d
D. show arp
Answer: B

2. 111.77对应的自然分类网段的广播地址为________________。
Answer: 202.135.111.255
4. 在如图所示的TCP连接的建立过程中,SYN中的Z部分应该填入________。
A. a
B. b
C. a+1
D. b+1
Answer: D
5. FTP默认使用的控制协议端口是______。
A. 20
B. 21
C. 23
D. 22
Answer: B

3. 以下工作于OSI参考模型数据链路层的设备是______。 (选择一项或多项)
A. 广域网交换机
B. 路由器
C. 中继器
D. 集线器
Answer: A

4. 如下哪种路由协议只关心到达目的网段的距离和方向?(选择一项或多项)
A. IGP
B. OSPF
C. RIPv1
D. RIPv2
Answer: CD

5. 通常情况下,路由器会对长度大于接口MTU的报文分片。为了检测线路MTU,可以带______参数ping目的地址。
A. -a
B. -d
C. -f
D. -c
Answer: C

6. 下列有关光纤的说法中哪些是错误的?
A. 多模光纤可传输不同波长不同入射角度的光
B. 多模光纤的纤芯较细
C. 采用多模光纤时,信号的最大传输距离比单模光纤长
D. 多模光纤的成本比单模光纤低
Answer: BC

7. 在如图所示的TCP连接的建立过程中,SYN中的Z部分应该填入________。
A. a
B. b
C. a+1
D. b+1
Answer: D

8. IP地址132.119.100.200的子网掩码是255.255.255.240,哪么它所在子网的广播地址是______。
A. 132.119.100.207
B. 132.119.100.255
C. 132.119.100.193
D. 132.119.100.223
Answer: A

9. 配置交换机SWA的桥优先级为0的命令为______。
A. [SWA] stp priority 0
B. [SWA-Ethernet1/0/1] stp priority 0
C. [SWA] stp root priority 0
D. [SWA-Ethernet1/0/1] stp root priority 0
Answer: A

10. TFTP采用的传输层知名端口号为______。
A. 67
B. 68
C. 69
D. 53
Answer: C

11. 如果以太网交换机中某个运行STP的端口不接收或转发数据,接收并发送BPDU,不进行地址学习,那么该端口应该处于______状态。
A. Blocking
B. Listening
C. Learning
D. Forwarding
E. Waiting
F. Disable
Answer: B

12. 在如图所示的交换网络中,所有交换机都启用了STP协议。SWA被选为了根桥。根据图中的信息来看,_______端口应该被置为Blocking状态。(选择一项或多项)
A. SWC的P1
B. SWC的P2
C. SWD的P1
D. SWD的P2
E. 信息不足,无法判断
Answer: BD

13. 客户的网络连接形如:
HostA—-GE0/0–MSR-1–S1/0—–WAN—–S1/0–MSR-2–GE0/0—-HostB
两台MSR路由器通过广域网实现互连,目前物理连接已经正常。MSR-1的接口S1/0地址为3.3.3.1/30,MSR-2的接口S1/0地址为3.3.3.2/30,现在在MSR-1上配置了如下三条静态路由:
ip route-static 192.168.1.0 255.255.255.0 3.3.3.2
ip route-static 192.168.2.0 255.255.255.0 3.3.3.2
ip route-static 192.168.0.0 255.255.255.0 3.3.3.2
其中192.168.0.0/22子网是主机HostB所在的局域网段。那么如下描述哪些是正确的?(选择一项或多项)
A. 这三条路由都会被写入MSR-1的路由表
B. 只有第三条路由会被写入MSR-1的路由表
C. 这三条路由可以被一条路由ip route-static 192.168.0.0 255.255.252.0 3.3.3.2代替
D. 只有第一条路由会被写入MSR-1的路由表
Answer: AC

14. 77对应的自然分类网段的广播地址为________________。
Answer: 202.135.111.255
4. 在如图所示的TCP连接的建立过程中,SYN中的Z部分应该填入________。
A. a
B. b
C. a+1
D. b+1
Answer: D
5. FTP默认使用的控制协议端口是______。
A. 20
B. 21
C. 23
D. 22
Answer: B

15. IP地址202.135.111.77对应的自然分类网段的广播地址为________________。
Answer: 202.135.111.255

16. 用______命令可指定下次启动使用的操作系统软件。
A. startup
B. boot-loader
C. bootfile
D. boot startup
Answer: B

  • Share/Bookmark
Posted in H3C. Comments Off »

GB0-800 Real Exam Answers

GB0-800 Exam Description
Questions and Answers:866 Q&As

Updated: 2009-09-07
Exam Number/Code: GB0-800
Exam Name: Huawei-3Com Certified internet Expert:Routing and Switching

Certinside professional IT Q&A vendors, we provide well after-sale service. To all the customers buy the Q&As, we provide track service. when you buy the Q&As with in 3 months. you can enjoy the upgrade Q&As service for free. If in this period, the certified test center change the H3C Others GB0-800 Q&As, we will update the Q&A in the first time, and provide you the download update for free

GB0-800 Free Demo Download

Certinside offers free demo for GB0-800 866 Q & As with Expert Explanations). You can check out the interface, question quality and usability of our practice exams before you decide to buy it.


Download GB0-800 Exam Pdf Demo

Download GB0-800 Exam iEngine Demo

 
 
Exam : HuaWei GB0-800
Title : Huawei-3Com Certified internet Expert:Routing and Switching

1. 在LACP中,形成一个链路聚合组ID所必须的元素包括:( )
A. Actor系统ID
B. Actor操作KEY
C. Actor系统优先级
D. Partner系统ID
E. Partner操作KEY
F. Partner系统优先级
Answer: BDE

2. 在OSI七层模型中,两台主机之间进行通信时,其中一台主机的会话层通常只和对端的( )进行通信。
A. 物理层
B. 网络层
C. 传输层
D. 表示层
E. 会话层
F. 数据链路层
Answer: E

3. STP发送配置消息的目的地址是( )
A. 01-80-C1-00-00-00
B. 01-80-C2-00-00-00
C. 01-80-C3-00-00-00
D. 01-80-C4-00-00-00
Answer: B

4. 下列关于多链路帧中继说法错误的有( )
A. 多链路帧中继(Multilink Frame Relay,简写为MFR)基于帧中继论坛的FRF.16协议
B.多链路帧中继特性提供一种逻辑接口:MFR接口,由多个帧中继物理链路捆绑而成,从而可以在帧中继网络上提供高速率、大带宽的链路
C. 对同一个MFR接口必须捆绑速率一致的物理接口,否则将无法绑定成功
D. 一个MFR接口对应一个捆绑,一个捆绑中可以包含多个捆绑链路,一个捆绑链路对应着一个物理接口或者子接口
Answer: CD

5. 以太网帧(数据链路层)最后4byte为数据链路层CRC校验值,当一个数据帧尾没有形成一个完整的Byte时被称为:( )
A. 普通CRC校验错误
B. Runt错误
C. Oversize错误
D. Fragment (碎片)
E. alignment错误
F. Jabber
Answer: E

6. FTP的常用端口号为: ( )
A. 20,21
B. 21,22
C. 20,22
D. 21,23
Answer: A

7. 关于冲突域和广播域,下列说法正确的有:( )
A. Hub的所有端口都属于同一个冲突域
B. 以太网交换机的一个VLAN是一个广播域
C. 以太网交换机上的端口都分别属于不同的冲突域
D. 以太网交换机的上VLAN实际上是一个冲突域
Answer: ABC

8. 分层PE跨域部署时,假如骨干网划为一个自治系统,城域网划为另外一个自治系统,那么下列说法正确的是:( )
A. 骨干网设置SPE,城域网设置UPE
B. UPE将城域网全部路由发送给SPE,SPE只发送VRF默认路由给UPE
C. 城域网只维护内部的VPN SITE和远端相同VPN的所有路由,骨干网维护全局所有VPN SITE的路由
D. 在跨AS方案中,SPE-UPE采用MP-EBGP或者Multi-hopEBGP方式,实现灵活的部署
Answer: ABD

9. 下面关于HVPLS接入方式的说法,正确的是( )
A. UPE与NPE之间运行LDP会话时,可以根据LDP会话的活动状态来判断主PW是否失效来设计MTU/UPE与PE/NPE设备之间链路的备份
B. 对于QinQ接入的HVPLS,没有办法判断主、从PW的状态,所以QINQ方式的接入无法实现MTU/UPE与PE/NPE设备之间链路的备份
C. HVPLS可以减少UPE路由器之间的全连接
D. HVPLS可以大大减少网络中被复制的广播报文数目
E. HVPLS接入方式转发到VPN对端的数据包中的私网标签由UPE分配的
Answer: AC

10. 关于Isolate-user-vlan和Super VLAN,下列描述中哪项是不正确的( )
A. 建立Isolate-user-vlan的主要目的是减少上行交换机需要配置的VLAN数
B. Isolate-user-vlan的主VLAN可以包含具体的物理端口,但Super VLAN的主VLAN不能包含具体物理端口
C. 建立Super VLAN的主要目的是避免IP地址的浪费
D. 默认情况下,Isolate-user-vlan不同Secondary VLAN下的主机是不能互通的,但Super VLAN不同 Sub VLAN下的主机是可以互通的
Answer: D

11. 在标签转发过程中,MPLS报文头中的TTL减一,IP报文头中的TTL同时也会减一。
T. True
F. False
Answer: F

12. 快速以太网技术中包含了众多成员,下列关于这些成员的描述正确的有( )
A. 100Base-TX采用五类双绞线传输数据,最大距离可以达到100米
B. 100Base-T4采用三类双绞线传输数据,但是传输距离小于100米
C. 100Base-T4与100Base-TX不同的是,100Base-T4需要4对双绞线进行数据传输,而100Base-TX只需要2对
D. 100Base-T2同100Base-TX一样也只需要2对双绞线传输数据,但它采用了不同于其它快速以太网的编码方式
E. 100Base-F采用的是光纤传输介质,目前传输距离可以达到100千米
Answer: ACDE

13. 下列关于HOPE的说法正确的是( )
A. HOPE解决了作为下层PE的BGP连接数量大的问题
B. HOPE解决了作为下层PE的VPN路由数量大的问题
C. SPE可以同时作为UPE
D. HOPE支持嵌套
Answer: ABCD

14. 扩展后的IS-IS协议使用________传递TE相关属性信息:( )
A. Type 21 TLVs
B. Type 22 TLVs
C. Type 23 TLVs
D. Type 24 TLVs
Answer: B

15. 以太网报头中的以太网帧类型字段为0 x 8035时,表示后面数据的类型可能为:( )
A. ARP请求
B. ARP应答
C. RARP请求
D. RARP应答
Answer: CD

16. 在L2TP组网中,假设LAC与LNS都已在公共网上,并实现正确连通的情况下,如果Tunnel建立失败,那么可能的原因有( )
A. 在LAC端,LNS的地址设置不正确
B. LAC端设置的用户名与密码有误
C. Tunnel验证不通过
D. LNS(通常为路由器)端没有设置可以接收该隧道对端的L2TP组
Answer: ACD

  • Share/Bookmark
Posted in H3C. Comments Off »