Which of the following statements are true about traffic encryption on SD-WAN links?
You can specify whether to encrypt traffic of a VN. If encryption is enabled for a VN, traffic on all WAN links in that VN is encrypted.
You can specify whether to encrypt traffic between specific devices. If encryption is enabled between specific devices, traffic transmitted between those devices is encrypted.
You can specify whether to encrypt specific data. If encryption is enabled for specific application data, only the specified data is encrypted.
You can specify whether to encrypt traffic of a TN. If encryption is enabled for a TN, traffic transmitted in the TN is encrypted.
Huawei SD-WAN allows encryption to be controlled by virtual network and by specific device relationships. When encryption is enabled for a VN, the overlay data channels carrying that VN’s traffic use IPsec protection across the relevant WAN links. This provides consistent isolation and confidentiality for the department or service represented by that VN.
Encryption can also be enabled between selected devices or sites. In that case, secure data channels are established for traffic exchanged between those specified endpoints, while other device relationships can continue using GRE without IPsec according to their policies.
Application-specific encryption, as described in option C, is not the supported control granularity. Application identification can influence intelligent traffic steering, QoS, and security-policy selection, but it does not mean that only the payload of a selected application is independently encrypted inside an otherwise unencrypted SD-WAN tunnel.
A transport network is an underlay WAN such as MPLS or the Internet. Enabling encryption is an overlay tunnel policy rather than a mechanism that encrypts all traffic belonging to an entire TN. Huawei distinguishes TNs as underlay networks and GRE or IPsec VPNs as overlay data channels. Therefore, only A and B are correct.
What are the two IPsec data encapsulation modes?
AH mode
ESP mode
Transport mode
Tunnel mode
The two IPsec encapsulation modes are transport mode and tunnel mode. In transport mode, IPsec protects the upper-layer payload of the original IP packet while retaining the original IP header as the packet’s outer header. It is commonly associated with end-to-end host communication, although it can also protect a GRE packet between tunnel endpoints.
In tunnel mode, IPsec protects the complete original IP packet and adds a new outer IP header containing the addresses of the IPsec peers. This mode is commonly used between security gateways, routers, or site-to-site VPN endpoints because the original source and destination information can be protected within the encrypted inner packet. RFC 4301 formally defines transport and tunnel as the two IPsec security-association modes.
AH and ESP are not encapsulation modes. They are IPsec security protocols. Authentication Header provides integrity and source authentication but not encryption. Encapsulating Security Payload can provide encryption, integrity, authentication, and anti-replay protection. Either protocol can conceptually operate in transport or tunnel mode, although ESP is overwhelmingly used for encrypted enterprise VPN and SD-WAN data channels.
==================
What are the objectives of the next-generation advanced industrial network with an open architecture?
Network-security integration
Networked devices
Network intelligence
IP-based connections
All four options represent objectives of a next-generation advanced industrial network. IP-based connections establish a standardized communications foundation, allowing production systems, controllers, sensors, machines, and management platforms to communicate through scalable Ethernet and IP technologies instead of isolated proprietary field networks.
Networked devices extend connectivity across operational technology assets so that equipment status, production data, and control information can be shared across production lines, plants, data centers, and cloud platforms. Network intelligence introduces automated provisioning, telemetry, analytics, fault prediction, policy optimization, and closed-loop operations. These capabilities reduce manual configuration and improve production availability.
Network-security integration is equally essential because greater openness and interconnection increase the potential attack surface. Security must therefore be integrated into access control, segmentation, device identification, encrypted communication, anomaly detection, and policy enforcement rather than added as an isolated external system. Huawei’s broader CloudCampus architecture similarly emphasizes automated provisioning, intelligent O & M, secure interconnection, integrated wired and wireless management, and open network capabilities. The four objectives collectively create an open, connected, intelligent, and secure industrial communications architecture.
==================
Which of the following deployment modes are supported by APs?
Barcode scanning–based deployment with CloudCampus APP
Email-based deployment
DHCP Option 148–based deployment
Registration query center–based deployment
APs support barcode scanning through the CloudCampus APP, DHCP Option 148–based deployment, and deployment through Huawei’s registration query center. With barcode scanning, the installer scans the AP’s label using the CloudCampus APP. The application obtains information such as the electronic serial number and MAC address, associates the AP with the correct tenant and site, and allows the AP to register with iMaster NCE.
With DHCP Option 148, the DHCP server supplies the AP with its IP configuration and the IP address and port number of iMaster NCE. The AP changes to cloud-management mode and automatically initiates registration. Huawei lists AR routers, switches, and APs as supported devices for this mode.
The registration query center can also provide the controller address after the AP contacts Huawei’s query service. It supports APs together with ARs, firewalls, and switches. Email-based deployment is primarily an SD-WAN CPE or AR-router ZTP method, not an AP deployment mode. Therefore, A, C, and D are correct.
==================
Which of the following Wi-Fi 7 APs offers PCIe card-based IoT functions?
AirEngine 6776I-X6TH
AirEngine 6776-58TI
AirEngine 8771-X1T
AirEngine 5773-25HW
The AirEngine 6776I-X6TH is the model designed to provide PCIe card-based IoT expansion. The PCIe interface enables an appropriate IoT expansion card to be installed so that the AP can support additional wireless or sensing technologies according to the deployment requirement. This allows the same physical access infrastructure to deliver enterprise Wi-Fi and IoT connectivity.
The capability is useful in retail, healthcare, education, manufacturing, and asset-management environments, where technologies such as Bluetooth, RFID, Zigbee, electronic shelf labels, location services, or specialized sensing systems may need to coexist with the WLAN. A modular card design is preferable when an organization requires selectable or upgradeable IoT functions rather than only fixed integrated capabilities.
Huawei’s Wi-Fi and IoT convergence architecture reduces repeated cabling, separate power systems, and independently managed wireless networks. It enables an IoT-capable AP to provide the installation position, power, management connectivity, and uplink data channel required by IoT modules. Among the models listed, the AirEngine 6776I-X6TH is the PCIe card-based IoT model. Therefore, option A is correct.
==================
A label stack is an ordered set of labels. MPLS supports a maximum of three layers of nested labels.
True
False
The statement is false. An MPLS label stack is an ordered sequence of label-stack entries, with the top label processed first and the bottom identified by the Bottom-of-Stack bit. However, the MPLS architecture does not define a universal maximum of three nested labels. An MPLS forwarding operation may replace the top label, remove it, or push one or more additional labels onto the stack.
Practical label depth is constrained by device implementation, forwarding ASIC capabilities, packet size, and the number of network functions being encoded. A conventional MPLS VPN may use two labels: a transport label and a VPN label. More advanced deployments can add labels for traffic engineering, segment routing, entropy, service chaining, or hierarchical transport. This can produce stacks deeper than three entries.
Therefore, “three layers†may describe a limitation of a particular platform, software version, or deployment design, but it is not an MPLS protocol maximum. RFC 3032 defines the stack as a sequence of four-byte entries and explicitly allows one or more entries to be pushed without specifying a three-label ceiling.
==================
Which of the following functions is supported by the AR6177?
IPS, antivirus, and URL filtering
Wi-Fi
VDSL
PoE
The distinguishing function supported by the AR6177 is VDSL. VDSL, or Very-high-bit-rate Digital Subscriber Line, enables a branch router to obtain WAN connectivity over existing copper telephone infrastructure. It is appropriate for small branches and distributed sites where Ethernet private lines, fiber, or mobile connections are unavailable or commercially impractical.
The AR6177 can terminate the VDSL access circuit and provide routing, NAT, DHCP, VPN, and other branch-gateway functions for the connected LAN. In this single-answer question, Wi-Fi and PoE are not the defining integrated capabilities of the AR6177 model. Similarly, the complete combination of IPS, antivirus, and URL filtering belongs to a security-enhanced product profile rather than the function used to distinguish the AR6177.
Huawei’s campus design material recognizes DSL links as a specific WAN-access category and notes that deployments involving complex or low-speed links, including DSL, may require an appropriate branch-device deployment method. The model is therefore selected when direct VDSL-based WAN access is required. Consequently, VDSL is the supported capability intended by this question, and option C is correct.
==================
Which of the following are WAN interconnection models for multi-branch campus networks?
Full-mesh
Hub-spoke
Partial-spoke
Partial-mesh
Huawei SD-WAN supports full-mesh, hub-spoke, and partial-mesh interconnection models. In a full-mesh topology, every site can communicate directly with the other sites. This model minimizes intermediate forwarding and is appropriate when branches frequently exchange latency-sensitive traffic such as voice, video, or collaborative application data.
In a hub-spoke topology, branch sites communicate with a central headquarters or data-center hub. Branch-to-branch traffic normally traverses that hub. The model is simple, scalable, and suitable for enterprises whose applications and shared resources are concentrated at headquarters.
Partial-mesh is used when most sites can communicate directly but some sites lack direct underlay connectivity or do not require direct tunnels. Those sites can communicate through a redirect or intermediate site. Huawei describes full-mesh, hub-spoke, and partial-mesh as supported topology designs and explains the role of a redirect site in partial-mesh networking.
“Partial-spoke†is not a defined SD-WAN topology model. A spoke is a role within hub-spoke networking rather than an independent partial-spoke topology. Therefore, A, B, and D are correct.
==================
Which of the following slicing modes are supported?
Based on a 5-tuple or application
Based on a VPN
Based on a user group
Based on a VLAN or port
All four listed classification dimensions are supported slicing approaches in the relevant campus and SD-WAN context. A slice can be created from traffic characteristics, including a 5-tuple or an identified application, so selected flows receive dedicated forwarding, bandwidth, security, or quality policies. Huawei supports customized application identification using URLs and IP 5-tuple information, as well as application- and 5-tuple-based traffic steering and QoS.
VPN- or VN-based slicing provides logical Layer 3 isolation. Huawei’s SD-WAN design maps each VN to an independent VPN instance or VRF and permits different overlay topologies, routing configurations, and policies. User-group-based slicing associates network treatment with identity or security-group membership rather than a permanently assigned IP address, supporting free mobility and consistent policy when users move. Huawei’s campus architecture applies different permissions to different user groups inside a VN.
VLAN- or port-based slicing classifies traffic by the local access attachment and is useful for fixed terminals or environments without identity authentication. Therefore, A, B, C, and D are all correct.
iMaster NCE-Campus can identify terminals. Which of the following services can be provided after terminal identification?
Spoofing detection: Terminal type changes are checked to provide a basis for spoofing detection.
Wired authentication: Terminals are identified through wired authentication.
Traffic statistics: Traffic statistics are collected based on different terminal types, and reports are generated.
Authentication and authorization: Different network access permissions are assigned to different types of terminals.
After identifying a terminal, iMaster NCE-Campus can use the identification result for security monitoring, visibility, and policy automation. Spoofing detection is supported because the platform can compare a terminal’s current type and traffic behavior with its previously identified characteristics. For example, if a device originally identified as an IP phone suddenly behaves like a PC, the system can generate a spoofing alarm or apply an isolation policy.
Terminal identification also supports statistics and reporting by vendor, operating system, device category, access port, and policy status. Huawei explicitly describes terminal-type statistics, report export, and visibility of access policies.
In addition, iMaster NCE-Campus can automatically deliver VLAN, security-group, QoS, authentication, and access-permission policies according to the identified terminal type. Option B is incorrect because wired authentication is an admission process, not a service produced after terminal identification. Therefore, A, C, and D are correct.
==================
Which of the following statements is true about an AP’s transmit power?
The higher the AP’s transmit power, the better.
The AP’s transmit power must be within a proper range to avoid interference between APs.
The transmit power of an AP does not matter.
The lower the AP’s transmit power, the better.
An AP’s transmit power must be maintained within an appropriate range. Excessive power does not automatically improve service quality. A high-power AP can enlarge its interference domain, create co-channel or adjacent-channel interference, produce asymmetric uplink and downlink coverage, and cause sticky-client behavior because a station continues hearing an AP even when its weaker transmission cannot reliably reach that AP. Huawei states that high-power APs can interfere with adjacent APs and that radio calibration dynamically adjusts AP channels, power, and frequency bands to ensure coverage while minimizing interference.
Conversely, power that is too low creates coverage holes, weak received signal strength, low modulation rates, retransmissions, and roaming instability. When a new AP is added, neighboring APs may reduce their transmit power to limit interference. When an AP goes offline, neighboring APs may increase power to compensate for the missing coverage. The engineering objective is therefore neither maximum nor minimum power, but sufficient coverage with controlled overlap and minimum interference. Accordingly, option B is correct.
==================
In the energy-saving solution based on AI traffic prediction, IoT APs are recommended to operate in non-energy-saving mode by default.
True
False
The statement is true. AI-based energy-saving systems analyze historical traffic and usage patterns to predict periods of low network demand. Ordinary AP radios or access devices can then enter an energy-saving state when their capacity is not required, while surrounding devices maintain sufficient coverage and service availability.
IoT APs, however, may host continuously operating IoT cards, sensors, electronic shelf-label services, Bluetooth location functions, RFID services, healthcare devices, or asset-tracking terminals. Placing such an AP into an energy-saving or hibernation state could interrupt more than ordinary Wi-Fi connectivity. It could also disable an IoT module’s power supply, management channel, data backhaul, or persistent sensing function. Huawei’s Wi-Fi and IoT convergence architecture uses APs as shared locations, power sources, and communication channels for IoT services.
Huawei also applies intelligent technologies to analyze AP load trends and perform predictive network optimization. The safer default is therefore to exclude IoT APs from automatic energy-saving actions unless the administrator confirms that their attached IoT services tolerate interruption. Accordingly, the answer is True.
==================
The CNN-based application identification technology can identify both known and unknown applications.
True
False
The statement is true in the context of Huawei’s AI-assisted application-identification architecture. Conventional identification depends mainly on predefined signatures, fixed destination addresses, port numbers, protocol fields, DNS correlation, or deep packet inspection. Huawei’s standard SD-WAN process uses Service Awareness and First-Packet Identification signature databases to identify and group application traffic. These mechanisms are effective for known applications but become less reliable when traffic is encrypted, applications change versions, or previously unseen applications appear.
A CNN-based classifier learns multidimensional traffic characteristics such as packet-length sequences, timing, direction, and flow behavior. It can classify traffic matching learned application patterns and, when implemented with open-set detection, recognize flows outside known classes as unknown or zero-day applications. Commercial-grade deep-learning traffic classification research demonstrates identification of known encrypted applications together with the handling of unknown zero-day applications.
This does not mean the system automatically assigns an exact commercial name to every unseen application. It detects that the traffic does not match established classes so that it can be investigated, labelled, and incorporated into later model updates. Therefore, the statement is True.
==================
Which of the following technologies is used for wireless attack detection?
Mesh
Spectrum analysis
PMF
WIPS
WIPS is the correct technology because it provides wireless intrusion prevention capabilities, including detecting and containing rogue access points, rogue stations, ad hoc devices, spoofing attempts, flood attacks, and other malicious activity on the radio interface. Huawei’s security-design material groups WIDS and WIPS with wireless attack detection and rogue-device containment. It recommends attack detection in public areas and primary or secondary education environments with high security requirements.
WIDS primarily detects and reports suspicious behavior, while WIPS adds active prevention or containment actions according to the configured policy. The other options serve different purposes. Mesh is a wireless networking architecture used to provide backhaul connectivity or extend coverage between APs; it is not an attack-detection mechanism. Spectrum analysis identifies non-Wi-Fi interference sources and evaluates radio-frequency utilization, but does not provide complete security attack detection and containment. Protected Management Frames protects selected 802.11 management frames against forgery, deauthentication, and disassociation attacks, but it is a protection mechanism rather than the comprehensive detection system requested. Therefore, WIPS is the correct answer.
==================
An AP cannot work independently. Instead, it must be configured by a WAC or iMaster NCE-Campus.
True
False
The statement is false because “AP†is a generic term covering several operating architectures. A Fit AP requires a WAC, and a cloud-managed AP is centrally managed through iMaster NCE-Campus. However, a Fat AP is autonomous: it can operate and be configured independently without a centralized controller. Huawei also describes the leader AP architecture, in which a capable AP integrates part of the WAC functionality, operates independently, and manages a limited number of Fit APs.
Therefore, the absolute claim that an AP cannot work independently is technically incorrect. The correct interpretation depends on the AP mode. Fit APs depend on a WAC or leader AP for centralized configuration and CAPWAP-based management, whereas Fat APs provide local control and forwarding. Huawei explicitly states that the Fat AP architecture is autonomous and requires no additional centralized control device. Because at least one recognized AP architecture operates independently, the correct answer is False.
==================
TESTED 02 Sep 2026