Which of the following statements is true about MACsec?
It always requires complex manual configuration.
It commonly uses hardware-based encryption.
It removes the requirement for Layer 2 connectivity between MACsec peers.
All of the above.
Hardware-based encryption is the unambiguously correct statement. MACsec protects Ethernet frames at Layer 2 using AES-GCM-based authenticated encryption. On enterprise switches and routers, the encryption and integrity operations are commonly implemented in forwarding ASICs or dedicated hardware so that frames can be protected at high throughput with low latency.
Option A is incorrect because complex manual configuration is not an inherent requirement. MACsec can use manually configured connectivity-association keys, but IEEE 802.1X MACsec Key Agreement can automate peer authentication, secure-channel establishment, key distribution, and rekeying. The operational complexity therefore depends on the deployment model and management platform.
Option C is also inaccurate. MACsec is media-independent, meaning it can operate over supported copper or fiber Ethernet; however, it does not eliminate the requirement for appropriate Layer 2 connectivity between participating MACsec entities. Standard hop-by-hop MACsec protects Ethernet links or LAN connectivity between peers and is not a general Layer 3 tunneling mechanism.
MACsec supplies Layer 2 confidentiality, integrity, origin authentication, and replay protection. Its encryption can be performed directly in network-device hardware, enabling substantially better forwarding performance than software-only encryption implementations.
Which 5G-Advanced capabilities does the AR5710-S8T1XWE-NRGL support?
NR 3GPP Release 16
Carrier aggregation: downlink 3CC and uplink 2CC
Eight APNs
Global frequency bands
The AR5710-S8T1XWE-NRGL supports all four listed 5G-Advanced capabilities. Support for 3GPP Release 16 enables enhanced 5G New Radio functions and provides the standards foundation for improved mobile-WAN capacity, reliability, and service performance.
Carrier aggregation combines multiple component carriers to increase available throughput. Downlink 3CC allows three component carriers to be aggregated for received traffic, while uplink 2CC combines two carriers for transmitted traffic. This is valuable for high-bandwidth branch access, video backhaul, and mobile private-network scenarios.
Support for eight APNs permits multiple logically separated mobile services or provider profiles to be configured. Different APNs can represent enterprise services, management traffic, production systems, backup connectivity, or isolated customer networks. Global-frequency-band support improves deployment flexibility across countries and carrier networks, subject to local spectrum regulation and the supported modem variant.
Huawei SD-WAN can use 5G as a primary, secondary, or bypass link and supports combinations such as dual 5G and 5G plus wired connectivity for service assurance. Therefore, NR Release 16, carrier aggregation, eight APNs, and global frequency bands are all supported.
==================
Which of the following deployment modes are supported by APs?
Barcode scanning–based deployment with CloudCampus APP
Email-based deployment
DHCP Option 148–based deployment
Registration query center–based deployment
APs support barcode scanning through the CloudCampus APP, DHCP Option 148–based deployment, and deployment through Huawei’s registration query center. With barcode scanning, the installer scans the AP’s label using the CloudCampus APP. The application obtains information such as the electronic serial number and MAC address, associates the AP with the correct tenant and site, and allows the AP to register with iMaster NCE.
With DHCP Option 148, the DHCP server supplies the AP with its IP configuration and the IP address and port number of iMaster NCE. The AP changes to cloud-management mode and automatically initiates registration. Huawei lists AR routers, switches, and APs as supported devices for this mode.
The registration query center can also provide the controller address after the AP contacts Huawei’s query service. It supports APs together with ARs, firewalls, and switches. Email-based deployment is primarily an SD-WAN CPE or AR-router ZTP method, not an AP deployment mode. Therefore, A, C, and D are correct.
==================
In hierarchical networking, which of the following devices is used for communication between different areas?
Edge device
Border device
Any device
Any specified device
A border device, or more precisely a device at a border site, provides communication between different areas in a hierarchical SD-WAN topology. The hierarchical model divides a large WAN into multiple areas. Each area can independently use a hub-spoke or full-mesh topology, while selected border sites connect the local area to a centralized backbone area.
When a non-border site receives a route originating in another area, the route’s next-hop site ID is changed to the border site in its own area. The local border device then forwards traffic toward the border site in the destination area or toward an interconnected hub site. Ordinary edge devices provide connectivity for their own sites but do not automatically perform cross-area transit.
Huawei describes border sites as members of both the level-2 area network and the level-1 backbone network. These sites collectively implement interconnection between areas. Huawei further explains that inter-area routes point to border sites and recommends two border sites operating in active/standby mode for reliability. Therefore, the correct answer is B.
==================
Which of the following WLAN networking solutions is recommended when there are 15,000 wireless terminals on the customer network?
Core switch + access switch + native WAC + AP
Core switch + aggregation switch + access switch + native WAC + AP
Core switch + aggregation/access switch + standalone WAC + AP
All of the above
A network serving 15,000 wireless terminals is a large-scale WLAN and should use a standalone WAC solution. A dedicated WAC provides independent controller resources, scalable AP and user management, centralized WLAN policy control, and the ability to deploy controller redundancy without tying wireless-control capacity directly to a specific core-switch service card.
Huawei recommends a standalone WAC when the wireless network scale is large or when the wireless network is deployed independently over an existing wired campus. The WAC is typically connected to the aggregation or core layer in off-path mode, and VRRP hot standby can be used to improve reliability.
Native WAC solutions are valuable for unified wired and wireless management, authentication, forwarding, and policy enforcement. However, for a very large number of wireless terminals, the controller platform must be selected according to user, AP, traffic, and forwarding-capacity specifications. A standalone WAC allows the wireless control plane to be sized and expanded independently.
Option C provides the dedicated WAC together with the required core and aggregation or access infrastructure. Therefore, it is the recommended architecture for 15,000 wireless terminals.
Which of the following Wi-Fi 7 APs offers PCIe card-based IoT functions?
AirEngine 6776I-X6TH
AirEngine 6776-58TI
AirEngine 8771-X1T
AirEngine 5773-25HW
The AirEngine 6776I-X6TH is the model designed to provide PCIe card-based IoT expansion. The PCIe interface enables an appropriate IoT expansion card to be installed so that the AP can support additional wireless or sensing technologies according to the deployment requirement. This allows the same physical access infrastructure to deliver enterprise Wi-Fi and IoT connectivity.
The capability is useful in retail, healthcare, education, manufacturing, and asset-management environments, where technologies such as Bluetooth, RFID, Zigbee, electronic shelf labels, location services, or specialized sensing systems may need to coexist with the WLAN. A modular card design is preferable when an organization requires selectable or upgradeable IoT functions rather than only fixed integrated capabilities.
Huawei’s Wi-Fi and IoT convergence architecture reduces repeated cabling, separate power systems, and independently managed wireless networks. It enables an IoT-capable AP to provide the installation position, power, management connectivity, and uplink data channel required by IoT modules. Among the models listed, the AirEngine 6776I-X6TH is the PCIe card-based IoT model. Therefore, option A is correct.
==================
Which of the following technologies is used for wireless attack detection?
Mesh
Spectrum analysis
PMF
WIPS
WIPS is the correct technology because it provides wireless intrusion prevention capabilities, including detecting and containing rogue access points, rogue stations, ad hoc devices, spoofing attempts, flood attacks, and other malicious activity on the radio interface. Huawei’s security-design material groups WIDS and WIPS with wireless attack detection and rogue-device containment. It recommends attack detection in public areas and primary or secondary education environments with high security requirements.
WIDS primarily detects and reports suspicious behavior, while WIPS adds active prevention or containment actions according to the configured policy. The other options serve different purposes. Mesh is a wireless networking architecture used to provide backhaul connectivity or extend coverage between APs; it is not an attack-detection mechanism. Spectrum analysis identifies non-Wi-Fi interference sources and evaluates radio-frequency utilization, but does not provide complete security attack detection and containment. Protected Management Frames protects selected 802.11 management frames against forgery, deauthentication, and disassociation attacks, but it is a protection mechanism rather than the comprehensive detection system requested. Therefore, WIPS is the correct answer.
==================
Which of the following encryption algorithms is used by WPA3?
AES-128
AES-256
AES-512
RC4
The intended answer is AES-256. In certification material, this question normally refers to the enhanced WPA3-Enterprise 192-bit security suite, which uses the GCMP-256 data-protection algorithm based on AES-256, together with stronger integrity and key-management components. AES-512 is not a standardized AES variant, and RC4 is the obsolete stream cipher associated with legacy WEP and TKIP-era protection rather than WPA3.
There is an important technical qualification: WPA3 is a family of certification modes, not one universal cipher suite. WPA3-Personal commonly uses Simultaneous Authentication of Equals for password-authenticated key establishment and requires CCMP-128, which is based on AES-128. WPA3-Enterprise 192-bit mode, however, uses AES-256 in GCM mode. Therefore, the original wording is broader than it should be. A technically precise version would ask which algorithm is associated with the WPA3-Enterprise 192-bit security suite. Under the intended Huawei examination scope and the supplied single-choice options, option B is correct. That distinction is crucial when interpreting this simplified examination item.
==================
The AirEngine 8771-X1T has dynamic-zoom smart antennas that can switch between omnidirectional and high-density modes.
True
False
The statement is true. The AirEngine 8771-X1T uses dynamic-zoom smart-antenna technology that can adapt its radiation characteristics according to the deployment environment. In omnidirectional mode, the antenna pattern is optimized to provide broad and balanced coverage, making it appropriate for ordinary offices, corridors, classrooms, and other environments where users are distributed over a relatively large area.
In high-density mode, the antenna pattern is adjusted to concentrate radio energy more effectively within the intended service area. This reduces unnecessary signal leakage, limits interference between neighboring APs, and improves concurrent-user performance in lecture halls, conference rooms, auditoriums, and similar high-density environments.
The switching capability is more effective than using a permanently fixed antenna pattern because WLAN conditions can change as users move and traffic density increases or decreases. Huawei’s training material states that dynamic-zoom smart antennas dynamically switch between omnidirectional and high-density modes, improving coverage in omnidirectional mode while strengthening the user experience in high-density scenarios. Therefore, option A is correct.
==================
Which of the following wireless security standards was proposed by China?
WPA
WAPI
WPA2
WPA3
WAPI, or WLAN Authentication and Privacy Infrastructure, is the wireless LAN security standard proposed by China. It provides wireless link authentication and data-protection mechanisms and was developed as an alternative security framework for WLAN environments. Huawei’s training material explicitly identifies WAPI as a WLAN security standard proposed in China and states that it provides stronger protection than legacy WEP and WPA mechanisms.
WPA, WPA2, and WPA3 belong to the Wi-Fi Protected Access family maintained through Wi-Fi industry certification. WPA was introduced as an interim improvement over WEP. WPA2 adopted stronger IEEE 802.11i security mechanisms, including AES-based CCMP. WPA3 later introduced stronger password-authentication and enterprise-security options.
WAPI incorporates authentication and encryption as part of an integrated wireless security architecture. Its deployment depends on regional requirements, terminal compatibility, AP support, and the organization’s regulatory or cryptographic-policy obligations. The question asks which standard originated as a Chinese wireless security standard, not which standard is most widely deployed internationally. Therefore, WAPI is the only correct choice, making option B the verified answer.
==================
Which of the following are common terminal identification methods?
SNMP query
DHCP option
MAC OUI
Nmap
All four options are recognized terminal identification methods. MAC OUI examines the first three bytes of a device’s MAC address to determine its manufacturer, although it generally cannot identify the exact model or operating system. DHCP option identification analyzes fields such as DHCP options 12, 55, and 60, which can reveal the hostname, parameter-request list, vendor class, and other terminal characteristics. SNMP query is an active identification method that retrieves device details from relevant MIB objects and is particularly useful for printers, network devices, and other SNMP-capable equipment.
Nmap is also an active scanning method. It analyzes open ports, service responses, protocol behavior, and operating-system fingerprints to estimate a terminal’s device type and OS. Huawei distinguishes information-reporting methods from proactive scanning methods: MAC OUI and DHCP options generally use information observed in traffic, whereas SNMP and Nmap actively query or scan the endpoint. iMaster NCE-Campus can correlate multiple fingerprints to improve identification accuracy and automatically apply terminal-specific access policies.
==================
On a campus fabric network, which of the following methods can be used for non-authenticated terminals to access a VN?
Dynamically authorizing VLANs
Authorizing VLANs in wired mode
Authorizing VLANs in wireless mode
Configuring static VLANs
Non-authenticated terminals can access a virtual network by using statically configured VLANs. Such terminals may include printers, cameras, sensors, industrial devices, and other dumb terminals that cannot perform 802.1X, Portal, or comparable interactive authentication. Their access interfaces and service VLANs are therefore configured in advance and mapped to the required VN.
Dynamic VLAN authorization requires a completed authentication or identification process. Normally, an authentication server returns a VLAN or other authorization attribute after validating the user or terminal. Because the question specifically refers to non-authenticated terminals, dynamically authorizing a VLAN is not the applicable mechanism. The wired-mode and wireless-mode authorization options are likewise associated with authentication-based policy delivery rather than unconditional VN access.
Huawei’s VN design guidance states that LAN-side physical interfaces and VLANs are assigned to the appropriate departments or services and then associated with corresponding VRFs or VNs. It also explains that a department may use an independent physical interface or share an interface while maintaining isolation through VLANs. Therefore, configuring a static VLAN is the correct method.
==================
Which of the following statements are true about selecting network access authentication points?
Centralized authentication points provide higher performance.
APs are recommended as authentication points for wireless users.
Access switches are recommended as authentication points for wired users.
Authentication points should be deployed closer to terminals to provide stronger security control.
Authentication points should generally be placed on access devices close to the terminals. For wireless users, the AP or WLAN access device is the natural admission point because it directly controls the station’s wireless association and service access. For wired users, the access switch directly connects the endpoint and can enforce 802.1X, MAC-address authentication, VLAN authorization, ACLs, and security-group policies.
Huawei recommends access devices as authentication points for employees and specifically recommends access switches as authentication points for wired dumb terminals using MAC-address authentication. Deploying enforcement close to endpoints prevents unauthenticated or unauthorized traffic from traversing deeper into the campus network. It also improves fault isolation, policy granularity, and scalability because admission processing is distributed across access devices.
Option A is incorrect. A centralized authentication point can simplify configuration and policy management, but it does not inherently provide higher performance. It can create concentrated processing pressure, enlarge the Layer 2 scope, and allow unauthenticated traffic to travel farther before being evaluated. Therefore, the recommended principles are represented by B, C, and D.
==================
TESTED 02 Sep 2026
Copyright © 2014-2026 DumpsTool. All Rights Reserved