Free H12-821_V1.0 Exam Braindumps (page: 13)

Page 12 of 56

GRE is a VPN encapsulation technology that is widely used to transmit packets across heterogeneous networks.
Which of the following statements is false about GRE?

  1. GRE supports encryption and authentication.
  2. GRE supports multicast transmission.
  3. GRE is a Layer 3 VPN encapsulation technology.
  4. GRE can work with other VPN protocols to better ensure data security.

Answer(s): A

Explanation:

GRE Characteristics

GRE does not inherently support encryption or authentication. It is a tunneling protocol for encapsulating packets, and data security features must be implemented using other protocols such as IPsec.

Other correct attributes of GRE include:

B . Supports multicast transmission.

C . Acts as a Layer 3 VPN encapsulation technology.

D . Can work with VPN protocols like IPsec for better security.

HCIP-Datacom-Core Reference

GRE features and limitations are discussed in VPN encapsulation technology chapters.



By default, some security zones are created when Huawei firewalls are enabled.
Which of the following security zones is created by users?

  1. DMZ
  2. ISP
  3. Trust
  4. Local

Answer(s): A

Explanation:

By default, Huawei firewalls create security zones such as Trust, Untrust, and Local. The DMZ (Demilitarized Zone) is a security zone explicitly created by users. A DMZ is used to isolate an internal network from the external one, providing an additional layer of security by placing public-facing services (e.g., web servers) in this intermediary zone. This setup ensures that if a public-facing service is compromised, the internal network remains secure. Huawei Firewall configuration steps confirm this zoning principle, making DMZ creation an explicit user-driven action .



When receiving a packet that does not match any session table entry, the firewall discards the packet to prevent external attacks and ensure internal information security.

  1. TRUE
  2. FALSE

Answer(s): A

Explanation:

When a Huawei firewall receives a packet that does not match any existing session table entry, it discards the packet. This is part of the default firewall policy, which ensures that unrecognized traffic is treated as a potential security risk and blocked. This behavior is vital for preventing unauthorized access and mitigating external attacks. The feature aligns with Huawei's default security strategies as detailed in their firewall operation manuals .



GRE is a Layer 2 VPN encapsulation technology that encapsulates packets of certain data link layer protocols so that the encapsulated packets can be transmitted over an IP network.

  1. TRUE
  2. FALSE

Answer(s): B

Explanation:

GRE (Generic Routing Encapsulation) is not a Layer 2 VPN technology. Instead, it is a Layer 3 tunneling protocol used to encapsulate a wide variety of network layer protocols inside point-to- point connections. GRE is commonly used for creating VPN tunnels across IP networks, allowing for the transport of various types of payloads. This misunderstanding about GRE being a Layer 2 technology contradicts its definition and typical application .






Post your Comments and Discuss Huawei H12-821_V1.0 exam with other Community members:

H12-821_V1.0 Exam Discussions & Posts