Limited-Time Offer: Enjoy 50% Savings! Ends in 00h 00m 00s Coupon code: 50OFF
Skip to content

Free Huawei HCIE-Datacom V1.0 H12-891_V1.0 Exam Questions

Page: 1 / 22 Total 322 questions

Want more questions? Get Premium Access.

Question 1

To prevent hackers from attacking user devices or networks using MAC addresses, you can configure MAC addresses of untrusted users as blackhole MAC addresses to filter out such invalid MAC addresses. When receiving a packet whose source or destination MAC address is a blackhole MAC address on a device, the device discards the packet.

Correct Answer: A. TRUE
Explanation:

Comprehensive and Detailed In-Depth

Blackhole MAC address configuration is a security feature that helps protect a network from MAC address spoofing or attacks involving untrusted MAC addresses. When you configure a MAC address as a blackhole MAC address, any packet received with that address as the source or destination will be immediately discarded by the device.

This feature is useful in scenarios where certain MAC addresses are identified as malicious or untrusted. By adding these MAC addresses to the blackhole list, the device effectively blocks communication involving these addresses, thereby mitigating security risks.


Huawei HCIE Datacom Official Certification Guide

Huawei Ethernet Switching and Security Configuration Guide

Question 2

MPLS implements data forwarding based on two different planes. Which of the following statements regarding the forwarding mechanism are correct?

Correct Answer: C. The system automatically assigns an ID to the upper-layer application that uses a tunnel. This ID is also called the tunnel ID.
Explanation:

Understanding MPLS Forwarding Mechanism

MPLS (Multiprotocol Label Switching) is a high-performance forwarding mechanism that operates on two planes:

1 Control Plane:

Establishes Label Switched Paths (LSPs) using protocols like LDP (Label Distribution Protocol), RSVP-TE (Resource Reservation Protocol - Traffic Engineering), or BGP-LU (BGP Label Unicast).

Assigns labels to packets based on routing policies.

2 Data Plane (Forwarding Plane):

Uses a Label Forwarding Information Base (LFIB) instead of traditional IP routing.

Packets are forwarded based on labels, not IP addresses.

Analysis of the Answer Choices

C. The system automatically assigns an ID to the upper-layer application that uses a tunnel. This ID is also called the tunnel ID.

Correct: MPLS assigns a Tunnel ID to applications that utilize tunnels (e.g., VPNs, MPLS-TE, or L2/L3 services).

This ID helps differentiate between various tunnel applications, ensuring traffic follows the correct LSP.

A. After an IP packet enters an MPLS domain, the MPLS device forwards the packet based on FIB table queries.

Incorrect: MPLS routers do NOT use the FIB (Forwarding Information Base) for forwarding once labels are assigned.

Instead, they use LFIB (Label Forwarding Information Base) to switch packets based on labels.

B. If the tunnel ID is 0x0, the MPLS forwarding process starts.

Incorrect: If the Tunnel ID is 0x0, MPLS does NOT start; it means no label is assigned, and traditional IP forwarding occurs.

D. If the tunnel ID is not 0x0, the normal IP forwarding process starts.

Incorrect: If the Tunnel ID is not 0x0, MPLS forwards traffic using label switching, not IP forwarding.


Question 3

In the Huawei CloudCampus Solution, which of the following devices can go online through the registration query center?

Correct Answer: A. Switch; B. AR; C. AP; D. Firewall
Explanation:

Comprehensive and Detailed

The Huawei Registration Query Center allows devices to register and go online automatically in a cloud-managed environment.

Supported Devices:

Switches

Access Routers (AR)

Access Points (APs)

Firewalls

How It Works:

Devices obtain their registration information via DHCP Option 148 or pre-configured credentials.

The devices then connect to the registration query center to retrieve configuration and authentication details.

Once authenticated, they go online and become manageable via iMaster NCE-Campus.

Reference: Huawei HCIE Datacom -- CloudCampus Device Registration


Question 4

In Huawei's NAC solution, which of the following cannot be used for Portal authentication?

Correct Answer: D. User's MAC address
Explanation:

Huawei's Network Access Control (NAC) Portal authentication supports various identity authentication methods for user login via a web page. These include:

Username and password --- standard method.

Passcode --- one-time password or PIN.

SMS verification code --- users receive a dynamic code via SMS for identity verification.

However:

MAC address authentication is used in MAC-based authentication, not Portal. MAC authentication allows a device to be authenticated using its MAC address without user interaction (i.e., not via a Portal page).

Correct answer: D. User's MAC address


Question 5

What is the router ID length supported by OSPFv3?

Correct Answer: D. 32 bits
Explanation:

Comprehensive and Detailed In-Depth

OSPFv3, which supports IPv6, uses a router ID that is 32 bits in length, similar to OSPFv2. The router ID in OSPF is always a 32-bit number, typically represented in an IPv4 address format (dotted decimal). Although OSPFv3 is designed to support IPv6, it still relies on a 32-bit router ID for identification, which must be unique within an OSPF domain. The router ID does not change even though the protocol itself supports IPv6 addresses (128 bits).


Huawei HCIE Datacom Official Certification Guide

Huawei OSPFv3 Configuration and Implementation Guide

Question 6

Based on the configuration in the following figure, how many interfaces on R4 are advertised into IS-IS?

plaintext

CopyEdit

display isis interface

Interface information for ISIS(1)

Interface Id IPV4.State IPV6.State MTU Type DIS

GE0/0/0 001 Up Down 1497 L1/L2 No/No

GE0/0/1 002 Up Down 1497 L1/L2 No/No

Loop0 001 Up Down 1500 L1/L2 -

Correct Answer: A. 2
Explanation:

The Loopback interface is not advertised by default in IS-IS, unless a specific command is used (like network entity with loopback settings or enabling it manually). In this case, the GE0/0/0 and GE0/0/1 interfaces are both UP, and have IS-IS L1/L2 enabled. These two interfaces qualify to advertise IS-IS routes.

Exact Extract - Huawei HCIE-Datacom V1.0 IS-IS Chapter

''By default, only physical interfaces in UP state and configured with IS-IS (L1, L2, or L1/L2) participate in IS-IS. Loopback interfaces must be explicitly advertised using route import policies.''


Huawei HCIE-Datacom Courseware -- IS-IS Interface Types

Datacom Certification Guide -- IS-IS Interface Advertisement Logic

Question 7

On the network shown in the following figure, a remote LDP session needs to be established between SWA and SWC. Which of the following statements is correct?

[SWA] mpls lsr-id 1.1.1.1

[SWA] mpls

[SWA-mpls] mpls ldp

[SWC] mpls lsr-id 33.3.3.3

[SWC] mpls

[SWC-mpls] mpls ldp

SWA ---- SWB ---- SWC

<------ Remote LDP Session ------>

Correct Answer: D, D
Explanation:

In MPLS LDP, there are two types of sessions:

Direct LDP sessions: Established between directly connected LSRs using LDP Hellos over a link.

Remote LDP sessions (also called targeted LDP sessions): Established between non-directly connected LSRs. These require manual configuration of the remote peer.

In this scenario, SWA and SWC are not directly connected, so a remote (targeted) LDP session must be set up.

For a remote LDP session:

You must configure the remote peer using the command:

[SWA-MPLS-LDP] targeted-peer x.x.x.x

Where x.x.x.x is the LSR ID of SWC (33.3.3.3 in this case).

The current configuration does not include this required step.

Thus, the correct statement is:


Question 8

In the Huawei SD-WAN Solution, the topologies of different VNs must be the same.

Correct Answer: B. FALSE
Explanation:

Understanding Huawei SD-WAN VN (Virtual Network) Topologies

Huawei SD-WAN uses Virtual Networks (VNs) to provide traffic isolation and policy-based routing for different services, branches, and applications.

VN Topologies Can Be Different

Each VN (Virtual Network) can have its own topology.

Some VNs may use full-mesh, while others may use hub-and-spoke or star topology.

Different VNs can have different routing and security policies.

Example:

Corporate traffic (VN1) Full-mesh topology for efficient inter-branch communication.

Guest Wi-Fi traffic (VN2) Hub-and-spoke topology to restrict inter-site communication.

Why is the Answer FALSE?

All VNs do not have to use the same topology.

Each VN can be configured independently with a unique topology, routing policy, and security settings.

Reference: Huawei HCIE-Datacom Guide -- SD-WAN VN Topologies and Segmentation


Question 9

In Huawei SD-WAN Solution, which of the following tunneling technologies is used to establish data channels?

Correct Answer: B. GRE over IPsec
Explanation:

Huawei SD-WAN establishes secure tunnels between SD-WAN edge devices (CPEs, AR routers, and controllers) using tunneling protocols.

B. GRE over IPsec (Correct Answer)

GRE (Generic Routing Encapsulation) over IPsec is the primary tunneling method used in Huawei SD-WAN.

GRE provides multi-protocol encapsulation, while IPsec ensures encryption and security.

Used for secure communication over public WAN links (e.g., the internet, LTE, MPLS, etc.).


Question 10

The BGP ORF function can be used to control the maximum number of routes that can be sent by a BGP peer. To achieve this, which of the following tools is used to send such a route list to BGP peers?

Correct Answer: D. IP prefix-list
Explanation:

Comprehensive and Detailed In-Depth

The Outbound Route Filtering (ORF) function in BGP allows a BGP speaker to inform its peer about the prefixes that it wants to receive, thereby reducing unnecessary route advertisements.

IP Prefix-List (D) is the correct answer because it is used to define the list of prefixes that are sent to the BGP peer during the ORF capability negotiation.

Filter-policy (A) and Route-policy (B) are used for controlling routing information locally or filtering incoming/outgoing routes but do not directly control the number of routes sent using ORF.

ACL (C) is primarily used for packet filtering and is not related to BGP route filtering.


Huawei HCIE Datacom Official Certification Guide

Huawei BGP Configuration and Maintenance Guide

RFC 5291: Outbound Route Filtering Capability for BGP-4

Question 11

Which of the following statements is incorrect about MP-BGP?

Correct Answer: B. When PEs and CEs exchange routes through BGP, you need to create a BGP process for each VPN instance in the CE.
Explanation:

MP-BGP is an extension of BGP-4 that supports multi-protocol address families such as IPv6, VPNv4, etc. When PE and CE exchange BGP routes, there is no need to create a BGP process per VPN on the CE. The CE typically runs a standard BGP process, while the PE maintains separate VPN routing tables (VRFs).

Exact Extract - Huawei HCIE-Datacom MP-BGP Chapter:

''CE devices use standard BGP, and multiple VPNs can share the same BGP process on the CE. The PE handles VPN route separation through VRFs and MP-BGP.''


Huawei HCIE-Datacom Guide -- MPLS VPN and MP-BGP

Huawei Datacom Training -- MP-BGP and VPN Route Management

Question 12

Man-in-the-middle attacks (MITM) or IP/MAC Spoofing attacks are common on intranets and can cause information leakage.

Which configuration method can prevent these attacks?

Correct Answer: D. Configure association between DHCP snooping and IPSG or DAI on the switch.
Explanation:

Comprehensive and Detailed

The Best Protection Against MITM and Spoofing Attacks:

(D) Associating DHCP Snooping with IPSG (IP Source Guard) and DAI (Dynamic ARP Inspection) provides complete protection by:

Blocking rogue DHCP servers.

Preventing MAC/IP spoofing.

Ensuring only valid clients access the network.

Why Not Other Options?

(A) Configuring trusted/untrusted interfaces only helps block rogue DHCP servers, but does not prevent spoofing.

(B) Limiting MAC address learning prevents MAC flooding, but does not stop MITM attacks.

(C) Checking the CHADDR field in DHCP Snooping helps detect spoofed requests, but does not block all MITM scenarios.

Reference: Huawei HCIE Datacom -- Security Mechanisms for Intranet Protection


Question 13

The IS-IS Level-1 neighbor relationship is not established between R3 and R4. Referring to the following information, what is the possible cause?

Correct Answer: D. The area IDs of R3 and R4 are different.
Explanation:

From the IS-IS error output, the key error is:

Mismatched Area Addr(L1): 13

This clearly indicates that the area addresses are different, which prevents the Level-1 adjacency from forming.

Why is Option D Correct?

IS-IS Level-1 routers must have the same area ID to form an adjacency.

Since the log shows a mismatched area address, the adjacency fails at Level-1.

If R3 and R4 were Level-2 routers, they could form an adjacency even with different area IDs.

Why Are the Other Options Incorrect?

Option A: No authentication failure is reported.

Option B: No 'Mismatched Level' errors appear, so their levels are compatible.

Option C: No 'Bad Circuit Type' errors indicate mismatched circuit types.

Thus, the correct answer is D.

Reference: Huawei HCIE Datacom -- IS-IS Neighbor Troubleshooting


Question 14

BFD can implement millisecond-level link status detection.

Correct Answer: A. TRUE
Explanation:

Understanding BFD (Bidirectional Forwarding Detection)

BFD is a high-speed fault detection protocol used to monitor link failures in milliseconds.

It operates at Layer 2 (Data Link Layer) and Layer 3 (Network Layer) to provide fast convergence.

Why Can BFD Detect Failures in Milliseconds?

Uses lightweight control packets that are exchanged between routers.

Works with OSPF, IS-IS, BGP, and MPLS to trigger fast convergence.

Detection time = (Transmit Interval) (Detect Multiplier)

Example: If the interval is 3ms and the multiplier is 3, failure detection takes 9ms.

Why is the Answer TRUE?

BFD achieves millisecond-level detection by sending rapid probe packets.

Used in high-availability networks where link failures must be detected in real-time.

Real-World Application

Service Provider Networks: BFD improves network resilience by detecting link failures faster than traditional routing timers.

Enterprise WANs: Used in SD-WANs to switch paths dynamically.

MPLS Fast Reroute (FRR): Works with MPLS Traffic Engineering for near-instantaneous failover.

Reference: Huawei HCIE-Datacom Guide -- BFD for Fast Link Failure Detection


Question 15

Which of the following are carried in an HTTP/1.1 response?

Correct Answer: A. Status line; B. Response body; C. Response header; D. Empty line
Explanation:

Understanding HTTP/1.1 Response Structure

What is an HTTP Response?

The response is sent from the server to the client after processing an HTTP request.

The structure follows a standardized format:

Elements of an HTTP/1.1 Response:

A. Status Line Contains protocol version, status code, and reason phrase.

B. Response Body Contains HTML, JSON, XML, or other content.

C. Response Header Provides metadata about the response (e.g., Content-Type, Server).

D. Empty Line A blank line separates headers from the response body.

Example of an HTTP/1.1 Response:

HTTP/1.1 200 OK

Date: Sat, 08 Mar 2025 14:00:00 GMT

Server: Apache/2.4.41 (Ubuntu)

Content-Type: text/html; charset=UTF-8

<html>

<body>

<h1>Welcome to Huawei Datacom</h1>

</body>

</html>

Why is the Answer A, B, C, D?

An HTTP response includes a status line, headers, an empty line, and a response body.

Real-World Application:

Web Application Debugging: Helps developers analyze server responses.

API Security: Validates response headers to prevent injection attacks.

Reference: Huawei HCIE-Datacom Guide -- HTTP Protocol and Response Headers