HCSE-Presales-Campus Network Planning and Design V1.0 Questions and Answers
On a campus fabric network, which of the following methods can be used for non-authenticated terminals to access a VN?
Options:
Dynamically authorizing VLANs
Authorizing VLANs in wired mode
Authorizing VLANs in wireless mode
Configuring static VLANs
Answer:
DExplanation:
Non-authenticated terminals can access a virtual network by using statically configured VLANs. Such terminals may include printers, cameras, sensors, industrial devices, and other dumb terminals that cannot perform 802.1X, Portal, or comparable interactive authentication. Their access interfaces and service VLANs are therefore configured in advance and mapped to the required VN.
Dynamic VLAN authorization requires a completed authentication or identification process. Normally, an authentication server returns a VLAN or other authorization attribute after validating the user or terminal. Because the question specifically refers to non-authenticated terminals, dynamically authorizing a VLAN is not the applicable mechanism. The wired-mode and wireless-mode authorization options are likewise associated with authentication-based policy delivery rather than unconditional VN access.
Huawei’s VN design guidance states that LAN-side physical interfaces and VLANs are assigned to the appropriate departments or services and then associated with corresponding VRFs or VNs. It also explains that a department may use an independent physical interface or share an interface while maintaining isolation through VLANs. Therefore, configuring a static VLAN is the correct method.
==================
Which of the following statements is false about GRE over IPsec?
Options:
IPsec supports encapsulation in both tunnel and transport modes.
Compared with tunnel mode, transport mode adds an additional outer IP header. As a result, the packet is longer and more likely to be fragmented. Therefore, GRE over IPsec in tunnel mode is recommended.
IPsec protects data flows between the GRE tunnel source and GRE tunnel destination.
GRE over IPsec first encapsulates packets using GRE and then protects the GRE packets using IPsec.
Answer:
BExplanation:
Option B is false because it reverses the encapsulation behavior. In IPsec transport mode, the IPsec security header is inserted after the existing IP header; a new outer IP header is not normally added. In tunnel mode, the complete original IP packet is encapsulated and a new outer IP header is added. Tunnel mode therefore generally introduces greater overhead and produces a longer packet than transport mode, not the reverse.
The remaining statements are correct. IPsec supports both transport and tunnel modes. GRE over IPsec performs GRE encapsulation first, allowing GRE to transport the original payload, and then applies IPsec protection to the resulting GRE packet. The IPsec security association is established between the GRE tunnel endpoints, protecting the GRE-encapsulated traffic as it traverses an untrusted transport network.
Huawei SD-WAN data channels can use either GRE or GRE over IPsec. GRE provides flexible overlay encapsulation, while IPsec adds confidentiality, integrity, origin authentication, and anti-replay protection for site-to-site traffic. Huawei specifically identifies IPsec encryption as the mechanism securing site-to-site SD-WAN services.
==================
Which of the following models supports IPS, antivirus, and URL filtering at the same time?
Options:
AR5710-SE
AR5710-S
AR631
AR610
Answer:
AExplanation:
The AR5710-SE is the security-enhanced model that supports intrusion prevention, antivirus, and URL filtering concurrently. The “SE” variant is designed for branch scenarios requiring integrated routing and advanced security processing instead of only basic WAN connectivity and packet forwarding.
IPS examines network traffic for attack signatures and abnormal behavior and can block detected intrusions. Antivirus inspection identifies malicious files or content using security-signature databases. URL filtering controls access to websites based on categories, reputation, or explicitly configured allowlists and blocklists. Supporting all three functions simultaneously allows the AR5710-SE to operate as both an SD-WAN CPE and a secure branch egress gateway, reducing the requirement for an additional branch firewall.
Huawei’s SD-WAN security architecture identifies firewall protection, antivirus, IPS, and URL filtering as its principal service-traffic security functions. Huawei also recommends advanced security functions such as URL filtering, IPS, and antivirus for branch scenarios requiring stronger Internet-egress protection. Among the listed models, the AR5710-SE provides the combined feature set. Therefore, option A is correct.
==================
Traffic can be forwarded directly between the two PRP ports of a PRP RedBox.
Options:
True
False
Answer:
BExplanation:
The statement is false. In Parallel Redundancy Protocol, LAN A and LAN B must remain two separate, failure-independent networks. A PRP RedBox connects a singly attached node or conventional network to both parallel LANs and behaves toward the PRP network like a doubly attached node. It duplicates outgoing frames and transmits one copy through each PRP port. For incoming traffic, it accepts the first valid copy and discards the later duplicate before forwarding the frame through its interlink port.
The RedBox must not operate as a normal bridge that directly forwards frames from its LAN A port to its LAN B port. Doing so would connect the two redundant LANs, potentially creating loops, duplicate propagation, broadcast amplification, and a common failure path. That would defeat the fundamental PRP requirement that failure or disruption in one LAN must not affect the other.
The original video contains the typing error “PPR RedBox”; the correct term is PRP RedBox , meaning Parallel Redundancy Protocol Redundancy Box. PRP topology requires two separate networks with no direct links between them, while the RedBox provides controlled redundant attachment for non-PRP devices.
==================
On which public clouds can vCPEs be deployed in SD-WAN scenarios?
Options:
AWS
Alibaba Cloud
Microsoft Azure
Huawei Cloud
Answer:
A, B, CExplanation:
In the product and course version covered by this examination, SD-WAN virtual CPEs can be deployed on AWS, Alibaba Cloud, and Microsoft Azure. A vCPE such as Huawei AR1000V provides SD-WAN routing functions as a virtual machine within a supported public-cloud infrastructure. It can connect enterprise branches to workloads hosted in the cloud and bring the cloud environment under the same controller-based management and policy-orchestration framework as physical CPEs.
This deployment provides one-hop cloud access, avoids unnecessarily routing cloud-bound traffic through a remote headquarters, and enables unified overlay networking between branches, data centers, and cloud virtual networks. Huawei states that the AR1000V virtual SD-WAN router can be deployed in public clouds to implement branch-to-cloud interconnection and unified policy orchestration. Huawei also describes flexible deployment of physical CPEs and vCPEs for cloud-access and PoP-based acceleration scenarios.
Huawei Cloud is not included in the supported public-cloud list represented by this specific H19-404 question. Product compatibility is version-dependent, so the correct examination answer is A, B, and C.
==================
Which of the following is not part of an IFIT measurement model?
Options:
Measurement point
NMS
Measurement flow
Measurement direction
Answer:
BExplanation:
The Network Management System is not an element of the IFIT measurement model. An IFIT measurement definition identifies the traffic to be measured, the locations where measurement actions occur, and the direction in which the flow is evaluated. The measurement flow specifies the target packets, usually through flow-identification fields. Measurement points define where packets are marked, counted, timestamped, or reported, such as ingress, transit, and egress nodes. Measurement direction distinguishes forward and reverse monitoring so that packet loss, delay, and path behavior can be analyzed correctly for each direction.
An NMS or controller remains operationally important because it creates measurement tasks, distributes configurations, receives telemetry data, correlates the results, and presents fault-location information. However, it is the management and analysis system surrounding the measurement model, not one of the model’s constituent measurement parameters.
Huawei positions IFIT as a high-precision telemetry mechanism used to delimit and locate application-quality faults. The training material highlights IFIT’s capability to locate faults rapidly and detect packet loss with extremely high reliability. Therefore, the component that is not part of the measurement model is the NMS.
==================
Which of the following are WAN interconnection models for multi-branch campus networks?
Options:
Full-mesh
Hub-spoke
Partial-spoke
Partial-mesh
Answer:
A, B, DExplanation:
Huawei SD-WAN supports full-mesh, hub-spoke, and partial-mesh interconnection models. In a full-mesh topology, every site can communicate directly with the other sites. This model minimizes intermediate forwarding and is appropriate when branches frequently exchange latency-sensitive traffic such as voice, video, or collaborative application data.
In a hub-spoke topology, branch sites communicate with a central headquarters or data-center hub. Branch-to-branch traffic normally traverses that hub. The model is simple, scalable, and suitable for enterprises whose applications and shared resources are concentrated at headquarters.
Partial-mesh is used when most sites can communicate directly but some sites lack direct underlay connectivity or do not require direct tunnels. Those sites can communicate through a redirect or intermediate site. Huawei describes full-mesh, hub-spoke, and partial-mesh as supported topology designs and explains the role of a redirect site in partial-mesh networking.
“Partial-spoke” is not a defined SD-WAN topology model. A spoke is a role within hub-spoke networking rather than an independent partial-spoke topology. Therefore, A, B, and D are correct.
==================
Which of the following deployment modes are supported by AR routers?
Options:
Registration query center–based deployment
Barcode scanning–based deployment with CloudCampus APP
Email-based deployment
DHCP Option 148–based deployment
Answer:
A, C, DExplanation:
AR routers support registration query center–based deployment, email-based deployment, and DHCP Option 148–based deployment. In registration query center deployment, the router obtains basic network connectivity, resolves or contacts Huawei’s registration service, retrieves the address and port of iMaster NCE, and then initiates registration. Huawei identifies AR routers, firewalls, switches, and APs as applicable devices for this method.
Email-based deployment is a major SD-WAN ZTP method for AR routers operating as CPEs. An administrator creates the site and ZTP configuration on iMaster NCE and sends a deployment URL to the onsite engineer. After the URL is opened and the parameters are written to the router, the device connects to the WAN and automatically registers with the controller.
DHCP Option 148 can provide the controller’s southbound IP address and port number to an IPv4 AR router, enabling automatic registration. Barcode scanning through the CloudCampus APP is specifically presented as an AP onboarding method, not an AR-router deployment method. Therefore, A, C, and D are correct.
What are the modes of the HSR RedBox?
Options:
HSR-SAN
HSR-PRP
PRP-PRP
HSR-HSR
Answer:
A, B, C, DExplanation:
An industrial RedBox can provide all four listed interconnection modes. In HSR-SAN mode, it connects a singly attached node that does not natively support High-availability Seamless Redundancy to an HSR network. The RedBox duplicates frames entering the HSR domain and removes duplicate frames before delivering traffic to the SAN.
HSR-PRP mode interconnects an HSR ring with a Parallel Redundancy Protocol network while preserving seamless redundancy. PRP-PRP mode couples two PRP network domains, while HSR-HSR mode connects separate HSR rings. Depending on the implementation, the HSR-HSR interconnection function may also be described as a QuadBox function because four HSR-facing ports can be involved.
The essential RedBox responsibilities are frame conversion, duplication, duplicate elimination, sequence-number handling, and prevention of unintended forwarding loops between redundancy domains. HSR and PRP use compatible duplicate-identification principles, enabling controlled interconnection between these network types without introducing a single point of failure. RedBoxes also provide redundant connectivity for devices that have only one ordinary Ethernet interface.
==================
Which of the following SM-series cryptographic algorithms is supported?
Options:
SM2
SM4
SM1
SM5
Answer:
BExplanation:
SM4 is the supported SM-series cryptographic algorithm intended by this question. SM4 is a standardized symmetric block cipher that uses a 128-bit block size and a 128-bit key. It is suitable for high-volume data encryption because symmetric cryptography can process service traffic efficiently compared with public-key algorithms.
Within an SD-WAN or IPsec context, the bulk traffic carried through secure data channels requires a symmetric encryption algorithm. SM4 can therefore be used as the encryption component of an approved cryptographic suite where compliance with Chinese commercial cryptography requirements is necessary.
SM2 is an asymmetric public-key cryptographic suite used for functions such as digital signatures, key exchange, and public-key encryption. It is not the bulk data-encryption algorithm requested in this item. SM1 is a restricted proprietary algorithm whose implementation details are not publicly standardized in the same manner, while SM5 is not the supported option represented by the Huawei course question.
Huawei’s SD-WAN architecture uses IPsec to protect site-to-site services and supports secure GRE-over-IPsec data channels between edge devices. In the SM-series selection presented here, the correct supported traffic-encryption algorithm is SM4.
==================
Huawei provides an innovative technology that can maintain smooth video when traffic packet loss between enterprise branches reaches up to 20%. Which technology provides this capability?
Options:
IFIT
IPCA
A-FEC
FEC
Answer:
CExplanation:
A-FEC, or Adaptive Forward Error Correction, is the correct technology. It protects delay-sensitive traffic by adding calculated redundant packets to the original packet stream. If some original packets are lost during WAN transmission, the receiving edge device can reconstruct them using the surviving original and redundant packets rather than waiting for end-to-end retransmission.
The key distinction between ordinary FEC and A-FEC is adaptation. With A-FEC, the receiving device reports real-time packet-loss and continuous-loss information to the transmitting device through FEC acknowledgement messages. The transmitting edge then dynamically increases or decreases the redundancy ratio according to actual network conditions. This provides stronger recovery during severe loss while avoiding unnecessary bandwidth overhead when link quality improves. Huawei describes this feedback-controlled adjustment as a mechanism that can alleviate or eliminate the impact of packet loss.
IFIT and IPCA are primarily measurement and service-quality analysis technologies; they do not reconstruct lost video packets. Fixed FEC does not adapt its redundancy level as effectively to changing loss conditions. Therefore, the technology intended for smooth video under packet loss of up to 20% is A-FEC.
==================
In hierarchical networking, which of the following devices is used for communication between different areas?
Options:
Edge device
Border device
Any device
Any specified device
Answer:
BExplanation:
A border device, or more precisely a device at a border site, provides communication between different areas in a hierarchical SD-WAN topology. The hierarchical model divides a large WAN into multiple areas. Each area can independently use a hub-spoke or full-mesh topology, while selected border sites connect the local area to a centralized backbone area.
When a non-border site receives a route originating in another area, the route’s next-hop site ID is changed to the border site in its own area. The local border device then forwards traffic toward the border site in the destination area or toward an interconnected hub site. Ordinary edge devices provide connectivity for their own sites but do not automatically perform cross-area transit.
Huawei describes border sites as members of both the level-2 area network and the level-1 backbone network. These sites collectively implement interconnection between areas. Huawei further explains that inter-area routes point to border sites and recommends two border sites operating in active/standby mode for reliability. Therefore, the correct answer is B.
==================
On which public cloud can the AR6700V-L running R024C10 not be deployed?
Options:
AWS
GCP
Oracle Cloud
Microsoft Azure
Answer:
BExplanation:
For the R024C10 software release specified in the question, the AR6700V-L cannot be deployed on Google Cloud Platform. The supported environments represented by this release and question are Amazon Web Services, Oracle Cloud, and Microsoft Azure.
Public-cloud support for a virtual CPE is release-specific. A virtual router requires more than generic virtual-machine compatibility. Huawei must provide or validate the appropriate cloud image, virtual network-interface drivers, deployment template, bootstrap mechanism, licensing integration, resource specifications, and controller-registration process for each cloud platform. Therefore, support for one KVM- or VMware-based environment does not automatically mean that every public-cloud provider is supported.
A cloud-hosted virtual CPE enables branches to establish overlay connectivity directly with cloud workloads and allows the controller to provide unified management and policy orchestration for physical and virtual edge devices. Huawei describes this model as deploying a virtual SD-WAN router on a public cloud to implement branch-to-cloud interconnection and unified policy orchestration. Under the R024C10 compatibility matrix tested by this question, GCP is excluded. Therefore, option B is correct.
==================
Which of the following protocol data packets can be encapsulated in a VPN using GRE?
Options:
IPv6 data packets
IP multicast data packets
IP unicast data packets
IP broadcast data packets
Answer:
A, B, C, DExplanation:
GRE is a multiprotocol encapsulation mechanism and can carry all the listed packet types. It inserts a GRE header around the original payload and then places the resulting GRE packet inside a delivery-protocol packet. Because the GRE header contains a Protocol Type field identifying the encapsulated payload, GRE is not restricted to ordinary IPv4 unicast traffic.
IPv6 packets can be transported as GRE payloads when supported by the tunnel endpoints. IP unicast traffic is the most common use case. GRE can also carry IP multicast and broadcast packets, which is one of its major advantages over basic IPsec tunnel selectors that traditionally focus on IP unicast traffic. This enables routing protocols, multicast applications, discovery traffic, and other non-unicast services to operate across a logical point-to-point tunnel.
RFC 2784 defines GRE as a general mechanism for encapsulating an arbitrary network-layer protocol over another network-layer protocol. It also defines the Protocol Type field used to identify the carried payload. Huawei uses GRE as an SD-WAN overlay data-channel option and can additionally secure it using IPsec when confidentiality and integrity are required.
==================
Which of the following statements is false about the energy-saving function of the digital map?
Options:
It displays the energy consumption of network-wide devices.
It automatically powers off some wireless APs during energy-saving periods.
It automatically powers off switches.
It automatically recommends energy-saving periods.
Answer:
CExplanation:
Option C is false. The digital-map energy-saving function provides network-wide energy visibility, identifies periods of low wireless demand, and recommends appropriate energy-saving time windows. During an approved energy-saving period, selected wireless APs or radio resources can be placed into an energy-saving state after the system evaluates coverage, traffic, and capacity requirements.
Automatically powering off switches is not the intended function. Campus switches may carry essential wired services, provide uplinks for other network devices, and supply PoE power to APs, cameras, phones, sensors, and access-control systems. Automatically shutting down a complete switch could therefore interrupt many unrelated services and potentially disconnect downstream network segments.
Huawei identifies low-carbon and energy-saving operation as a characteristic of cloud campus networks and combines this objective with AI-based intelligent O & M and proactive optimization. Its intelligent O & M architecture analyzes AP load trends and performs predictive wireless-network optimization, providing the analytical foundation for selecting safe energy-saving periods and resources.
Therefore, A, B, and D describe supported digital-map energy-saving capabilities. Automatic switch power-off is the false statement, making C correct.
What is the maximum number of access units supported by a central switch on a passive Ethernet network (PEN)?
Options:
96
72
48
64
Answer:
CExplanation:
A central switch in the relevant passive Ethernet network architecture supports a maximum of 48 access units. The architecture replaces a conventional multi-layer access design with a centralized switch and distributed remote or access units. The access units function as extensions of the central switch’s ports, simplifying device management, configuration, and topology maintenance.
Huawei’s CloudEngine S5731-H fixed central-switch specification provides models with 24 or 48 hybrid optical-electrical downlink ports. The 48-port model can therefore directly manage up to 48 associated access or remote units under the design limits represented by this question. The same hybrid links can provide data transmission and remote PoE power, enabling access units to be installed closer to terminals without requiring conventional active aggregation equipment at every location.
The central switch automatically discovers the topology, while remote units behave as extended ports rather than independently managed switches. This reduces management nodes and simplifies a traditional three-layer network into a two-layer architecture. The larger values of 64, 72, and 96 exceed the supported maximum for the specified central-switch implementation. Therefore, option C is correct.
==================
Which of the following WLAN networking solutions is recommended when there are 15,000 wireless terminals on the customer network?
Options:
Core switch + access switch + native WAC + AP
Core switch + aggregation switch + access switch + native WAC + AP
Core switch + aggregation/access switch + standalone WAC + AP
All of the above
Answer:
CExplanation:
A network serving 15,000 wireless terminals is a large-scale WLAN and should use a standalone WAC solution. A dedicated WAC provides independent controller resources, scalable AP and user management, centralized WLAN policy control, and the ability to deploy controller redundancy without tying wireless-control capacity directly to a specific core-switch service card.
Huawei recommends a standalone WAC when the wireless network scale is large or when the wireless network is deployed independently over an existing wired campus. The WAC is typically connected to the aggregation or core layer in off-path mode, and VRRP hot standby can be used to improve reliability.
Native WAC solutions are valuable for unified wired and wireless management, authentication, forwarding, and policy enforcement. However, for a very large number of wireless terminals, the controller platform must be selected according to user, AP, traffic, and forwarding-capacity specifications. A standalone WAC allows the wireless control plane to be sized and expanded independently.
Option C provides the dedicated WAC together with the required core and aggregation or access infrastructure. Therefore, it is the recommended architecture for 15,000 wireless terminals.
What are the two IPsec data encapsulation modes?
Options:
AH mode
ESP mode
Transport mode
Tunnel mode
Answer:
C, DExplanation:
The two IPsec encapsulation modes are transport mode and tunnel mode. In transport mode, IPsec protects the upper-layer payload of the original IP packet while retaining the original IP header as the packet’s outer header. It is commonly associated with end-to-end host communication, although it can also protect a GRE packet between tunnel endpoints.
In tunnel mode, IPsec protects the complete original IP packet and adds a new outer IP header containing the addresses of the IPsec peers. This mode is commonly used between security gateways, routers, or site-to-site VPN endpoints because the original source and destination information can be protected within the encrypted inner packet. RFC 4301 formally defines transport and tunnel as the two IPsec security-association modes.
AH and ESP are not encapsulation modes. They are IPsec security protocols. Authentication Header provides integrity and source authentication but not encryption. Encapsulating Security Payload can provide encryption, integrity, authentication, and anti-replay protection. Either protocol can conceptually operate in transport or tunnel mode, although ESP is overwhelmingly used for encrypted enterprise VPN and SD-WAN data channels.
==================