{"id":21121,"date":"2026-09-24T11:03:28","date_gmt":"2026-09-24T11:03:28","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=21121"},"modified":"2026-09-24T11:03:28","modified_gmt":"2026-09-24T11:03:28","slug":"huawei-h12-821-practice-test-questions-and-exam-dumps-part14-q261-280","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/huawei-h12-821-practice-test-questions-and-exam-dumps-part14-q261-280\/","title":{"rendered":"Huawei H12-821 Practice Test Questions and Exam Dumps Part14 Q261-280"},"content":{"rendered":"<p><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/h12-821-exam-dumps\"><b>Huawei H12-821 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/p>\n<p><b><br \/>\n<\/b><b>Question 261. What is the PRIMARY purpose of Unicast Reverse Path Forwarding (uRPF)?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> To encrypt routed packets<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To detect packets with potentially spoofed source IP addresses by checking reverse-path information<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To allocate IPv6 addresses dynamically<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To establish BGP sessions<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. To detect packets with potentially spoofed source IP addresses by checking reverse-path information<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Unicast Reverse Path Forwarding helps defend against packets that use forged source IP addresses. Instead of checking only the destination route, the device performs a FIB lookup using the packet&#8217;s source address. Depending on the configured uRPF mode, it verifies whether the source is reachable and potentially whether the packet arrived through the expected interface. Packets that fail the check can be discarded. Huawei identifies uRPF as especially useful for reducing source-spoofing and certain denial-of-service attacks. It is therefore a data-plane security mechanism rather than an encryption, addressing, or routing-session protocol.<\/span><\/p>\n<p><b>Question 262. What does strict uRPF normally verify?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only that the destination address exists in the routing table<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> That the packet contains an MPLS label<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> That the source uses a private address<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> That the best reverse route toward the source points through the interface on which the packet arrived<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. That the best reverse route toward the source points through the interface on which the packet arrived<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Strict uRPF performs a relatively restrictive source validation check. The device looks up the packet&#8217;s source IP address in the FIB and compares the resulting reverse-path interface with the interface on which the packet was received. If those interfaces do not match, the packet may be treated as spoofed and discarded. This is effective on networks where traffic paths are symmetric and predictable. However, Huawei notes that strict uRPF may be unsuitable in some ECMP or asymmetric-routing environments because a valid packet may legitimately arrive through an interface different from the preferred reverse path.<\/span><\/p>\n<p><b>Question 263. In which environment is strict uRPF MOST likely to cause false packet drops?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> A network with asymmetric routing paths<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A single-path stub network<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A network using only directly connected routes<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A network with no IP routing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. A network with asymmetric routing paths<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Strict uRPF assumes that the interface used to reach a packet&#8217;s source should match the interface on which the packet arrived. In an asymmetric network, legitimate traffic can enter through one path while the best route back to the source uses another. Strict uRPF can therefore classify valid traffic as suspicious and discard it. Huawei also documents platform and ECMP considerations for strict uRPF. Network designers should evaluate actual path symmetry before deploying strict source validation broadly. Where asymmetry is expected, a less restrictive validation method or another source-security control may be more appropriate.<\/span><\/p>\n<p><b>Question 264. What is the PRIMARY purpose of IP Source Guard (IPSG)?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> To prevent Ethernet loops<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To encrypt host traffic<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To prevent IP address spoofing by validating source information against binding entries<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To assign addresses to DHCP clients<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. To prevent IP address spoofing by validating source information against binding entries<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">IP Source Guard protects an access network from hosts that attempt to use forged source IP information. Huawei IPSG maintains or uses binding information containing details such as IP address, MAC address, VLAN, and inbound interface. Packets received on IPSG-protected interfaces are compared with those bindings, and traffic that does not match can be discarded. This helps prevent an attacker from impersonating an authorized endpoint simply by configuring its IP address. IPSG is typically deployed at the access layer and can use manually configured static bindings or dynamically learned DHCP snooping bindings.<\/span><\/p>\n<p><b>Question 265. Which information can be included in an IPSG binding entry?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Source IP address, source MAC address, VLAN ID, and inbound interface<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> BGP AS_Path, MED, and Origin<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> OSPF router ID and DR priority only<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> MPLS label stack only<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Source IP address, source MAC address, VLAN ID, and inbound interface<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Huawei IPSG binding entries can associate an endpoint&#8217;s IP address, MAC address, VLAN, and inbound interface. The switch compares received packets against the configured or dynamically learned binding information. Depending on the selected IPSG check method, one or several of these fields can be validated. Using multiple fields provides stronger protection because an attacker would need to impersonate more than just an IP address. Dynamic bindings are commonly built from DHCP snooping information, while static entries can be manually configured for hosts that use fixed addresses.<\/span><\/p>\n<p><b>Question 266. Which technology commonly supplies dynamic binding entries that IPSG can use for hosts obtaining addresses automatically?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> BGP<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> OSPF<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> LLDP<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> DHCP snooping<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. DHCP snooping<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">When hosts obtain addresses through DHCP, DHCP snooping can dynamically create trusted binding entries based on legitimate DHCP exchanges. These entries contain host information such as the assigned IP address, MAC address, VLAN, and access interface. IPSG can then use the binding table to validate subsequent user traffic. This avoids manually configuring every endpoint while still providing source-address protection. Huawei identifies DHCP snooping dynamic bindings as particularly suitable for access networks containing many hosts whose addressing is assigned by DHCP. Static IPSG entries remain useful for smaller environments with fixed-address endpoints.<\/span><\/p>\n<p><b>Question 267. What problem does Dynamic ARP Inspection (DAI) primarily address?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> BGP route hijacking<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> ARP spoofing and man-in-the-middle attacks<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> OSPF adjacency failures<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> MPLS label exhaustion<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. ARP spoofing and man-in-the-middle attacks<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Dynamic ARP Inspection protects Ethernet access networks against forged ARP information. In an ARP spoofing attack, a malicious host sends false ARP mappings so other devices associate a legitimate IP address with the attacker&#8217;s MAC address. This can redirect traffic through the attacker and enable a man-in-the-middle attack. Huawei describes DAI as a defense that validates ARP packets using trusted binding information before accepting them. DAI complements IPSG: IPSG validates IP packets against source bindings, while DAI focuses specifically on malicious ARP behavior and address-resolution attacks.<\/span><\/p>\n<p><b>Question 268. Why might an enterprise deploy both IPSG and DAI on an access switch?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Both technologies perform exactly the same check<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> DAI provides routing while IPSG provides switching<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> IPSG protects against forged IP source traffic, while DAI additionally protects against malicious ARP spoofing and related conflicts<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> IPSG replaces DHCP and DAI replaces DNS<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. IPSG protects against forged IP source traffic, while DAI additionally protects against malicious ARP spoofing and related conflicts<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">IPSG and DAI are complementary security controls. IPSG validates IP traffic against trusted bindings and helps stop a malicious device from using a forged source IP address. However, Huawei notes that IPSG alone does not address every ARP-related problem, including cases where an attacker creates conflicts or redirects traffic through forged ARP messages. DAI examines ARP packets and helps prevent those spoofing attacks. Deploying DHCP snooping, IPSG, and DAI together can therefore provide layered protection for dynamically addressed access-layer endpoints.<\/span><\/p>\n<p><b>Question 269. What is the PRIMARY purpose of port security on a Huawei access switch?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> To dynamically select OSPF routes<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To create MPLS labels<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To provide DHCP relay<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To restrict endpoint access based on secure MAC addresses and limit how many MAC addresses a port may learn<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. To restrict endpoint access based on secure MAC addresses and limit how many MAC addresses a port may learn<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Port security controls access based on MAC addresses learned or configured on a switch interface. Huawei port security can convert learned dynamic MAC addresses into secure MAC addresses and limit the number of secure MAC addresses that an interface may learn. Traffic sourced from addresses outside the secure list can then trigger a protective action. This helps prevent unauthorized devices from connecting through a protected port and can reduce the risk of MAC-address-table exhaustion attacks. Port security is especially useful on user-facing access interfaces where the expected number of connected endpoints is known.<\/span><\/p>\n<p><b>Question 270. What happens when the number of secure MAC addresses on a port reaches its configured maximum and an unknown source MAC appears?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The switch takes the configured port-security protective action<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The maximum value automatically doubles<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> OSPF recalculates its SPF tree<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The source MAC automatically becomes trusted<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. The switch takes the configured port-security protective action<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">After the secure MAC-address limit is reached, additional unknown source MAC addresses are treated as unauthorized. Huawei supports protective actions such as restrict, protect, and shutdown. Restrict discards the offending traffic and reports an alarm, protect discards it without generating the same alarm behavior, and shutdown can place the interface into an error-down state. This allows administrators to choose the response appropriate to the risk of the environment. The port does not simply expand its secure MAC limit or trust the new endpoint automatically.<\/span><\/p>\n<p><b>Question 271. What is the main characteristic of a sticky MAC address learned through port security?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> It is used only for multicast traffic<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> It cannot be associated with a VLAN<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> It can preserve the learned secure MAC binding across a saved device restart<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> It is automatically advertised through BGP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. It can preserve the learned secure MAC binding across a saved device restart<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Sticky MAC functionality allows a switch to learn endpoint MAC addresses dynamically and convert them into persistent secure bindings. Huawei notes that sticky MAC addresses are useful when endpoints rarely change location because the learned port\/MAC\/VLAN relationship can be retained when the configuration is saved and the device restarts. This differs from secure dynamic MAC addresses, which may need to be relearned after a restart. Sticky learning therefore reduces manual configuration while providing more persistence than ordinary dynamic secure learning.<\/span><\/p>\n<p><b>Question 272. Which port-security action discards unauthorized packets and generates an alarm without putting the interface into error-down state?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Shutdown<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Restrict<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Protect<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Forward<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Restrict<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Huawei defines restrict as the recommended port-security protective action in many situations. When unauthorized traffic arrives after the secure MAC limit has been reached, the switch discards the packets and reports an alarm while keeping the interface operational for legitimate secure MAC addresses. The protect action discards unauthorized traffic but does not report the same alarm, whereas shutdown places the interface into an error-down state and reports an alarm. Restrict therefore offers a useful balance between maintaining service for legitimate users and making administrators aware of the security violation.<\/span><\/p>\n<p><b>Question 273. What security services does MACsec provide on an Ethernet LAN link?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Authentication, encryption, integrity protection, and replay protection<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only IP routing<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only DHCP address assignment<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> BGP route filtering<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Authentication, encryption, integrity protection, and replay protection<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">MACsec protects Ethernet communications at the data-link layer. Huawei describes MACsec as providing identity authentication, data encryption, integrity checking, and replay protection. Encryption prevents an observer on the LAN link from reading protected frame contents, integrity checking detects tampering, and replay protection helps prevent captured frames from simply being retransmitted as valid traffic. Because MACsec operates directly on Ethernet frames, it protects communication differently from IPsec, which operates at the IP layer. MACsec is particularly useful on point-to-point Ethernet links where sensitive LAN traffic needs protection.<\/span><\/p>\n<p><b>Question 274. At which OSI layer does MACsec primarily protect traffic?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Layer 7<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Layer 4<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Layer 3<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Layer 2**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Layer 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">MACsec operates at Layer 2, the data-link layer. It directly protects Ethernet frames transmitted across a LAN link before higher-layer protocols process them. This differs from IPsec, which protects traffic at the network layer and can operate across routed paths. Huawei identifies MACsec as an IEEE 802.1AE-based security technology for Ethernet networks. Because the protection is applied at Layer 2, protocols carried inside the Ethernet frame can benefit from confidentiality and integrity without each application requiring its own encryption mechanism.<\/span><\/p>\n<p><b>Question 275. What is the PRIMARY function of MKA in a MACsec deployment?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> To calculate OSPF routes<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To negotiate MACsec security associations and manage keys used for protected communication<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To provide DHCP snooping<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To create VLAN trunks<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. To negotiate MACsec security associations and manage keys used for protected communication<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">MACsec Key Agreement, or MKA, handles key negotiation and secure-session establishment for MACsec. Huawei explains that participating devices use MKA to exchange capabilities and security parameters and to elect a key server. The key server derives a Secure Association Key used to encrypt protected data and distributes the required keying information to the peer. MKA also supports keepalive behavior for the secure session. It therefore provides the control mechanisms required for MACsec encryption to function reliably, rather than performing IP routing or address assignment.<\/span><\/p>\n<p><b>Question 276. Why is SSH preferred over Telnet for remote administration of Huawei network devices?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> SSH requires no authentication<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Telnet provides stronger encryption than SSH<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> SSH authenticates endpoints and encrypts management traffic instead of sending it in cleartext<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> SSH works only on local console ports<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. SSH authenticates endpoints and encrypts management traffic instead of sending it in cleartext<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Telnet transmits management information in cleartext, which can expose usernames, passwords, and configuration commands to anyone capable of intercepting the session. SSH addresses these weaknesses by authenticating participants and encrypting the communication channel. Huawei recommends secure SSH-based management, including STelnet V2 rather than the older version. SSH normally uses TCP port 22. Using encrypted management protocols is especially important because compromise of an administrative session can provide direct control of routers and switches even if user data traffic is otherwise well protected.<\/span><\/p>\n<p><b>Question 277. Which TCP port does an SSH server use by default?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> TCP 23<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> TCP 80<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> TCP 179<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> TCP 22**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. TCP 22<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">SSH servers use TCP port 22 by default. Before an SSH client can securely manage a network device, IP reachability must exist and the server must be enabled and configured with suitable authentication parameters. Huawei describes SSH as a secure alternative to protocols such as Telnet because it authenticates communicating parties and encrypts exchanged information. Telnet traditionally uses TCP port 23 and does not offer comparable confidentiality. Firewall and ACL policies protecting the management plane should therefore permit TCP 22 only from authorized administration networks where possible.<\/span><\/p>\n<p><b>Question 278. What is the PRIMARY purpose of NetStream?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> To collect per-flow traffic statistics for monitoring, accounting, and network optimization<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To encrypt Ethernet frames<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To create OSPF neighbors<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To assign VLAN IDs<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. To collect per-flow traffic statistics for monitoring, accounting, and network optimization<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">NetStream analyzes network traffic as flows based on packet fields such as source and destination IP addresses, ports, and protocol information. A NetStream-enabled device collects flow statistics and exports them to a collector, where the information can be stored and analyzed. Huawei identifies accounting, network monitoring, and network optimization as common applications. Administrators can determine which hosts or applications consume bandwidth, where traffic is going, and how network usage changes over time. NetStream provides traffic visibility rather than encryption, routing adjacency establishment, or VLAN assignment.<\/span><\/p>\n<p><b>Question 279. In a NetStream architecture, which component collects flow statistics from network devices and stores them for analysis?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> NetStream Collector (NSC)<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> NDE only<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> OSPF ASBR<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> VRRP Master<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. NetStream Collector (NSC)<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A Huawei NetStream system includes the NetStream Data Exporter (NDE), NetStream Collector (NSC), and NetStream Data Analyzer (NDA). The NDE is usually the network device that collects and exports flow information. The NSC receives flow records from one or more NDEs and stores or processes the statistics. The NDA then analyzes that information and produces reports for applications such as accounting, traffic engineering, and network optimization. In practice, the collector and analyzer may be integrated into the same server platform, but their logical roles remain distinct.<\/span><\/p>\n<p><b>Question 280. An enterprise wants to prevent spoofed source addresses, restrict unauthorized access devices, encrypt sensitive Ethernet links, securely administer switches, and analyze application bandwidth consumption. Which combination BEST addresses these requirements?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Use only STP and OSPF<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Use BGP, VRRP, and DHCP relay only<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Use IPSG\/uRPF for source validation, port security for MAC-based access control, MACsec for Ethernet link protection, SSH for administration, and NetStream for traffic analysis<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Use only VLANs and static routes<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Use IPSG\/uRPF for source validation, port security for MAC-based access control, MACsec for Ethernet link protection, SSH for administration, and NetStream for traffic analysis<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Each requirement calls for a different security or operations capability. IPSG and uRPF help detect or block traffic using invalid source addressing. Port security controls which MAC addresses may use a switch interface and limits learned endpoints. MACsec provides Layer 2 authentication, encryption, integrity, and replay protection on sensitive Ethernet links. SSH protects remote device-management sessions from cleartext exposure. Finally, NetStream provides per-flow statistics that help identify bandwidth consumers and support monitoring, accounting, and optimization. Combining these tools provides layered protection and visibility across the access, forwarding, management, and operational planes.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Huawei H12-821 Exam Dumps and Practice Test Dumps. Question 261. What is the PRIMARY purpose of Unicast Reverse Path Forwarding (uRPF)? To encrypt routed packets To detect packets with potentially spoofed source IP addresses by checking reverse-path information To allocate IPv6 addresses dynamically To establish BGP sessions Correct Answer: 2. To detect packets [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/21121"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=21121"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/21121\/revisions"}],"predecessor-version":[{"id":21122,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/21121\/revisions\/21122"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=21121"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=21121"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=21121"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}