HCSE-Presales-Campus Network Planning and Design V1.0 Questions and Answers
iMaster NCE-Campus can identify terminals. Which of the following services can be provided after terminal identification?
Options:
Spoofing detection: Terminal type changes are checked to provide a basis for spoofing detection.
Wired authentication: Terminals are identified through wired authentication.
Traffic statistics: Traffic statistics are collected based on different terminal types, and reports are generated.
Authentication and authorization: Different network access permissions are assigned to different types of terminals.
Answer:
A, C, DExplanation:
After identifying a terminal, iMaster NCE-Campus can use the identification result for security monitoring, visibility, and policy automation. Spoofing detection is supported because the platform can compare a terminal’s current type and traffic behavior with its previously identified characteristics. For example, if a device originally identified as an IP phone suddenly behaves like a PC, the system can generate a spoofing alarm or apply an isolation policy.
Terminal identification also supports statistics and reporting by vendor, operating system, device category, access port, and policy status. Huawei explicitly describes terminal-type statistics, report export, and visibility of access policies.
In addition, iMaster NCE-Campus can automatically deliver VLAN, security-group, QoS, authentication, and access-permission policies according to the identified terminal type. Option B is incorrect because wired authentication is an admission process, not a service produced after terminal identification. Therefore, A, C, and D are correct.
==================
A label stack is an ordered set of labels. MPLS supports a maximum of three layers of nested labels.
Options:
True
False
Answer:
BExplanation:
The statement is false. An MPLS label stack is an ordered sequence of label-stack entries, with the top label processed first and the bottom identified by the Bottom-of-Stack bit. However, the MPLS architecture does not define a universal maximum of three nested labels. An MPLS forwarding operation may replace the top label, remove it, or push one or more additional labels onto the stack.
Practical label depth is constrained by device implementation, forwarding ASIC capabilities, packet size, and the number of network functions being encoded. A conventional MPLS VPN may use two labels: a transport label and a VPN label. More advanced deployments can add labels for traffic engineering, segment routing, entropy, service chaining, or hierarchical transport. This can produce stacks deeper than three entries.
Therefore, “three layers” may describe a limitation of a particular platform, software version, or deployment design, but it is not an MPLS protocol maximum. RFC 3032 defines the stack as a sequence of four-byte entries and explicitly allows one or more entries to be pushed without specifying a three-label ceiling.
==================
Which of the following are Target Wake Time (TWT) technologies?
Options:
Broadcast TWT
Implicit TWT
Individual TWT
Multicast TWT
Answer:
A, B, CExplanation:
Broadcast TWT, Individual TWT, and Implicit TWT are valid Target Wake Time concepts. Individual TWT establishes a wake schedule between an AP and a specific station. Broadcast TWT advertises scheduling information that multiple stations can use, reducing individual negotiation overhead and coordinating groups of devices. An implicit TWT agreement defines a repeating schedule in which subsequent wake times are calculated from the agreed wake interval instead of being renegotiated for every service period.
These mechanisms allow stations, particularly battery-powered IoT devices, to sleep for predictable periods and wake only when transmission or reception is scheduled. TWT consequently reduces power consumption, channel contention, collisions, and unnecessary medium access in dense WLAN environments. Research describing IEEE 802.11ax TWT confirms that the mechanism schedules station transmission periods and allows stations to remain asleep outside their negotiated service periods.
“Multicast TWT” is not one of the standard TWT concepts represented by this question. Broadcast scheduling can cover multiple stations, but that does not create a separate mechanism formally identified here as Multicast TWT. Therefore, the correct answers are A, B, and C.
==================
Which experience-assurance technologies does Huawei SD-WAN provide?
Options:
Per-packet/per-flow load balancing
Multi-fed and selective receiving
A-FEC
Intelligent traffic steering
Answer:
A, B, C, DExplanation:
Huawei SD-WAN provides all four technologies. Per-flow load balancing distributes separate application flows among multiple links that have the same priority and satisfy the required SLA. Per-packet load balancing can transmit packets from one flow across multiple eligible links, improving aggregate bandwidth utilization for large file transfers, backups, and replication.
Multi-fed and selective receiving duplicates critical traffic across different links. The receiving device selects valid packets, removes duplicates, and preserves packet order. Packet loss or failure on one path therefore does not interrupt the service, enabling zero-millisecond link switchover in applicable deployments.
A-FEC dynamically generates redundant packets and adjusts the redundancy ratio according to measured packet loss. The receiving device reconstructs lost packets, reducing video freezing and voice-quality deterioration. Huawei describes both adaptive FEC and multi-fed selective receiving as WAN-optimization mechanisms for key traffic.
Intelligent traffic steering selects links according to application identity, quality, bandwidth, priority, and load. Therefore, A, B, C, and D are all correct.
==================
Which of the following deployment modes are supported by AR routers?
Options:
Registration query center–based deployment
Barcode scanning–based deployment with CloudCampus APP
Email-based deployment
DHCP Option 148–based deployment
Answer:
A, C, DExplanation:
AR routers support registration query center–based deployment, email-based deployment, and DHCP Option 148–based deployment. In registration query center deployment, the router obtains basic network connectivity, resolves or contacts Huawei’s registration service, retrieves the address and port of iMaster NCE, and then initiates registration. Huawei identifies AR routers, firewalls, switches, and APs as applicable devices for this method.
Email-based deployment is a major SD-WAN ZTP method for AR routers operating as CPEs. An administrator creates the site and ZTP configuration on iMaster NCE and sends a deployment URL to the onsite engineer. After the URL is opened and the parameters are written to the router, the device connects to the WAN and automatically registers with the controller.
DHCP Option 148 can provide the controller’s southbound IP address and port number to an IPv4 AR router, enabling automatic registration. Barcode scanning through the CloudCampus APP is specifically presented as an AP onboarding method, not an AR-router deployment method. Therefore, A, C, and D are correct.
Which of the following statements are true about predefined security zones on a firewall?
Options:
The local zone is the highest-security zone, with a priority of 100.
The demilitarized zone (DMZ) is a medium-security zone, with a priority of 50.
The trust zone is a high-security zone, with a priority of 95.
The untrust zone is a low-security zone, with a priority of 5.
Answer:
A, B, DExplanation:
Huawei firewalls provide four commonly predefined security zones: Local, Trust, DMZ, and Untrust. The Local zone represents the firewall itself, including traffic generated by or destined for the device, and has the highest default security priority of 100. The Trust zone normally represents an organization’s protected internal network and has a default priority of 85, not 95. Therefore, option C is false.
The DMZ typically hosts public-facing or semi-trusted resources, such as web, email, and application servers. Its default priority is 50, placing it between the trusted internal network and the external untrusted network. The Untrust zone normally represents the Internet or another uncontrolled network and has the lowest predefined priority of 5.
Zone priority expresses the relative security level used to classify inbound and outbound traffic direction; it does not independently permit traffic. Security policies still determine whether matched traffic is allowed or denied. Huawei’s SD-WAN design uses Trust and Untrust zones on CPEs, and iMaster NCE can orchestrate the corresponding zones and firewall policies for Internet-access protection.
==================
Which of the following functions is supported by the AR6177?
Options:
IPS, antivirus, and URL filtering
Wi-Fi
VDSL
PoE
Answer:
CExplanation:
The distinguishing function supported by the AR6177 is VDSL. VDSL, or Very-high-bit-rate Digital Subscriber Line, enables a branch router to obtain WAN connectivity over existing copper telephone infrastructure. It is appropriate for small branches and distributed sites where Ethernet private lines, fiber, or mobile connections are unavailable or commercially impractical.
The AR6177 can terminate the VDSL access circuit and provide routing, NAT, DHCP, VPN, and other branch-gateway functions for the connected LAN. In this single-answer question, Wi-Fi and PoE are not the defining integrated capabilities of the AR6177 model. Similarly, the complete combination of IPS, antivirus, and URL filtering belongs to a security-enhanced product profile rather than the function used to distinguish the AR6177.
Huawei’s campus design material recognizes DSL links as a specific WAN-access category and notes that deployments involving complex or low-speed links, including DSL, may require an appropriate branch-device deployment method. The model is therefore selected when direct VDSL-based WAN access is required. Consequently, VDSL is the supported capability intended by this question, and option C is correct.
==================
Which of the following models supports IPS, antivirus, and URL filtering at the same time?
Options:
AR5710-SE
AR5710-S
AR631
AR610
Answer:
AExplanation:
The AR5710-SE is the security-enhanced model that supports intrusion prevention, antivirus, and URL filtering concurrently. The “SE” variant is designed for branch scenarios requiring integrated routing and advanced security processing instead of only basic WAN connectivity and packet forwarding.
IPS examines network traffic for attack signatures and abnormal behavior and can block detected intrusions. Antivirus inspection identifies malicious files or content using security-signature databases. URL filtering controls access to websites based on categories, reputation, or explicitly configured allowlists and blocklists. Supporting all three functions simultaneously allows the AR5710-SE to operate as both an SD-WAN CPE and a secure branch egress gateway, reducing the requirement for an additional branch firewall.
Huawei’s SD-WAN security architecture identifies firewall protection, antivirus, IPS, and URL filtering as its principal service-traffic security functions. Huawei also recommends advanced security functions such as URL filtering, IPS, and antivirus for branch scenarios requiring stronger Internet-egress protection. Among the listed models, the AR5710-SE provides the combined feature set. Therefore, option A is correct.
==================
What are the modes of the HSR RedBox?
Options:
HSR-SAN
HSR-PRP
PRP-PRP
HSR-HSR
Answer:
A, B, C, DExplanation:
An industrial RedBox can provide all four listed interconnection modes. In HSR-SAN mode, it connects a singly attached node that does not natively support High-availability Seamless Redundancy to an HSR network. The RedBox duplicates frames entering the HSR domain and removes duplicate frames before delivering traffic to the SAN.
HSR-PRP mode interconnects an HSR ring with a Parallel Redundancy Protocol network while preserving seamless redundancy. PRP-PRP mode couples two PRP network domains, while HSR-HSR mode connects separate HSR rings. Depending on the implementation, the HSR-HSR interconnection function may also be described as a QuadBox function because four HSR-facing ports can be involved.
The essential RedBox responsibilities are frame conversion, duplication, duplicate elimination, sequence-number handling, and prevention of unintended forwarding loops between redundancy domains. HSR and PRP use compatible duplicate-identification principles, enabling controlled interconnection between these network types without introducing a single point of failure. RedBoxes also provide redundant connectivity for devices that have only one ordinary Ethernet interface.
==================
In the energy-saving solution based on AI traffic prediction, IoT APs are recommended to operate in non-energy-saving mode by default.
Options:
True
False
Answer:
AExplanation:
The statement is true. AI-based energy-saving systems analyze historical traffic and usage patterns to predict periods of low network demand. Ordinary AP radios or access devices can then enter an energy-saving state when their capacity is not required, while surrounding devices maintain sufficient coverage and service availability.
IoT APs, however, may host continuously operating IoT cards, sensors, electronic shelf-label services, Bluetooth location functions, RFID services, healthcare devices, or asset-tracking terminals. Placing such an AP into an energy-saving or hibernation state could interrupt more than ordinary Wi-Fi connectivity. It could also disable an IoT module’s power supply, management channel, data backhaul, or persistent sensing function. Huawei’s Wi-Fi and IoT convergence architecture uses APs as shared locations, power sources, and communication channels for IoT services.
Huawei also applies intelligent technologies to analyze AP load trends and perform predictive network optimization. The safer default is therefore to exclude IoT APs from automatic energy-saving actions unless the administrator confirms that their attached IoT services tolerate interruption. Accordingly, the answer is True.
==================
Which of the following statements is false about Layer 3 roaming?
Options:
When Layer 3 roaming occurs for a STA, the STA’s traffic is diverted to the HAP.
The IP address of a STA changes after Layer 3 roaming.
The HAP is determined when the STA accesses the network for the first time.
Before and after Layer 3 roaming, the SSID remains the same, but the service VLANs are different.
Answer:
BExplanation:
Option B is false because a station retains its original IP address during Layer 3 roaming. Preserving the IP address is essential for maintaining active application sessions when the station moves between APs associated with different service VLANs, Layer 2 domains, and gateways. Huawei’s training diagram shows the same station IP address before and after roaming, while the service VLAN changes.
When the STA initially accesses the WLAN, a Home AP or HAP is selected for it. After the STA roams to a Foreign AP, the new AP obtains the station information and establishes the required forwarding relationship with the HAP. In direct-forwarding implementations, the STA’s traffic is encapsulated and forwarded to the HAP, which preserves access through the original network and gateway.
Therefore, A and C accurately describe HAP-based Layer 3 roaming. Option D is also correct: the APs use the same SSID and authentication mode but different service VLANs. The station’s IP address does not change, so B is the false statement.
==================
Which of the following WLAN networking solutions is recommended when there are 15,000 wireless terminals on the customer network?
Options:
Core switch + access switch + native WAC + AP
Core switch + aggregation switch + access switch + native WAC + AP
Core switch + aggregation/access switch + standalone WAC + AP
All of the above
Answer:
CExplanation:
A network serving 15,000 wireless terminals is a large-scale WLAN and should use a standalone WAC solution. A dedicated WAC provides independent controller resources, scalable AP and user management, centralized WLAN policy control, and the ability to deploy controller redundancy without tying wireless-control capacity directly to a specific core-switch service card.
Huawei recommends a standalone WAC when the wireless network scale is large or when the wireless network is deployed independently over an existing wired campus. The WAC is typically connected to the aggregation or core layer in off-path mode, and VRRP hot standby can be used to improve reliability.
Native WAC solutions are valuable for unified wired and wireless management, authentication, forwarding, and policy enforcement. However, for a very large number of wireless terminals, the controller platform must be selected according to user, AP, traffic, and forwarding-capacity specifications. A standalone WAC allows the wireless control plane to be sized and expanded independently.
Option C provides the dedicated WAC together with the required core and aggregation or access infrastructure. Therefore, it is the recommended architecture for 15,000 wireless terminals.
Which of the following statements are true about selecting network access authentication points?
Options:
Centralized authentication points provide higher performance.
APs are recommended as authentication points for wireless users.
Access switches are recommended as authentication points for wired users.
Authentication points should be deployed closer to terminals to provide stronger security control.
Answer:
B, C, DExplanation:
Authentication points should generally be placed on access devices close to the terminals. For wireless users, the AP or WLAN access device is the natural admission point because it directly controls the station’s wireless association and service access. For wired users, the access switch directly connects the endpoint and can enforce 802.1X, MAC-address authentication, VLAN authorization, ACLs, and security-group policies.
Huawei recommends access devices as authentication points for employees and specifically recommends access switches as authentication points for wired dumb terminals using MAC-address authentication. Deploying enforcement close to endpoints prevents unauthenticated or unauthorized traffic from traversing deeper into the campus network. It also improves fault isolation, policy granularity, and scalability because admission processing is distributed across access devices.
Option A is incorrect. A centralized authentication point can simplify configuration and policy management, but it does not inherently provide higher performance. It can create concentrated processing pressure, enlarge the Layer 2 scope, and allow unauthenticated traffic to travel farther before being evaluated. Therefore, the recommended principles are represented by B, C, and D.
==================
Which of the following statements is true about an AP’s transmit power?
Options:
The higher the AP’s transmit power, the better.
The AP’s transmit power must be within a proper range to avoid interference between APs.
The transmit power of an AP does not matter.
The lower the AP’s transmit power, the better.
Answer:
BExplanation:
An AP’s transmit power must be maintained within an appropriate range. Excessive power does not automatically improve service quality. A high-power AP can enlarge its interference domain, create co-channel or adjacent-channel interference, produce asymmetric uplink and downlink coverage, and cause sticky-client behavior because a station continues hearing an AP even when its weaker transmission cannot reliably reach that AP. Huawei states that high-power APs can interfere with adjacent APs and that radio calibration dynamically adjusts AP channels, power, and frequency bands to ensure coverage while minimizing interference.
Conversely, power that is too low creates coverage holes, weak received signal strength, low modulation rates, retransmissions, and roaming instability. When a new AP is added, neighboring APs may reduce their transmit power to limit interference. When an AP goes offline, neighboring APs may increase power to compensate for the missing coverage. The engineering objective is therefore neither maximum nor minimum power, but sufficient coverage with controlled overlap and minimum interference. Accordingly, option B is correct.
==================
The AirEngine 8771-X1T has dynamic-zoom smart antennas that can switch between omnidirectional and high-density modes.
Options:
True
False
Answer:
AExplanation:
The statement is true. The AirEngine 8771-X1T uses dynamic-zoom smart-antenna technology that can adapt its radiation characteristics according to the deployment environment. In omnidirectional mode, the antenna pattern is optimized to provide broad and balanced coverage, making it appropriate for ordinary offices, corridors, classrooms, and other environments where users are distributed over a relatively large area.
In high-density mode, the antenna pattern is adjusted to concentrate radio energy more effectively within the intended service area. This reduces unnecessary signal leakage, limits interference between neighboring APs, and improves concurrent-user performance in lecture halls, conference rooms, auditoriums, and similar high-density environments.
The switching capability is more effective than using a permanently fixed antenna pattern because WLAN conditions can change as users move and traffic density increases or decreases. Huawei’s training material states that dynamic-zoom smart antennas dynamically switch between omnidirectional and high-density modes, improving coverage in omnidirectional mode while strengthening the user experience in high-density scenarios. Therefore, option A is correct.
==================
Traffic can be forwarded directly between the two PRP ports of a PRP RedBox.
Options:
True
False
Answer:
BExplanation:
The statement is false. In Parallel Redundancy Protocol, LAN A and LAN B must remain two separate, failure-independent networks. A PRP RedBox connects a singly attached node or conventional network to both parallel LANs and behaves toward the PRP network like a doubly attached node. It duplicates outgoing frames and transmits one copy through each PRP port. For incoming traffic, it accepts the first valid copy and discards the later duplicate before forwarding the frame through its interlink port.
The RedBox must not operate as a normal bridge that directly forwards frames from its LAN A port to its LAN B port. Doing so would connect the two redundant LANs, potentially creating loops, duplicate propagation, broadcast amplification, and a common failure path. That would defeat the fundamental PRP requirement that failure or disruption in one LAN must not affect the other.
The original video contains the typing error “PPR RedBox”; the correct term is PRP RedBox , meaning Parallel Redundancy Protocol Redundancy Box. PRP topology requires two separate networks with no direct links between them, while the RedBox provides controlled redundant attachment for non-PRP devices.
==================
Which of the following BGP NLRI address-family combinations is used to transmit SD-WAN tunnel encapsulation information?
Options:
AFI: 1, SAFI: 74
AFI: 1, SAFI: 1
AFI: 25, SAFI: 70
AFI: 1, SAFI: 2
Answer:
AExplanation:
AFI 1 with SAFI 74 is the correct combination. In Multiprotocol BGP, the Address Family Identifier defines the basic network-layer address family, while the Subsequent Address Family Identifier specifies how the associated NLRI is interpreted. AFI 1 represents IPv4. SAFI 74 is assigned for SD-WAN capabilities and is used to distribute information required for SD-WAN edge discovery and tunnel establishment, including transport and encapsulation-related attributes.
The other combinations represent different forms of reachability information. AFI 1/SAFI 1 is ordinary IPv4 unicast NLRI. AFI 1/SAFI 2 represents IPv4 multicast reachability. AFI 25 represents Layer 2 VPN information, while SAFI 70 represents Ethernet VPN routes; that combination is associated with EVPN rather than the specific SD-WAN capability NLRI requested.
Huawei’s architecture uses BGP-based control channels to exchange transport network port information, IPsec security-association information, and service routes. These parameters allow edge devices to determine peer endpoints and create GRE or GRE-over-IPsec data channels after the relevant service routes trigger tunnel establishment.
==================
Which 5G-Advanced capabilities does the AR5710-S8T1XWE-NRGL support?
Options:
NR 3GPP Release 16
Carrier aggregation: downlink 3CC and uplink 2CC
Eight APNs
Global frequency bands
Answer:
A, B, C, DExplanation:
The AR5710-S8T1XWE-NRGL supports all four listed 5G-Advanced capabilities. Support for 3GPP Release 16 enables enhanced 5G New Radio functions and provides the standards foundation for improved mobile-WAN capacity, reliability, and service performance.
Carrier aggregation combines multiple component carriers to increase available throughput. Downlink 3CC allows three component carriers to be aggregated for received traffic, while uplink 2CC combines two carriers for transmitted traffic. This is valuable for high-bandwidth branch access, video backhaul, and mobile private-network scenarios.
Support for eight APNs permits multiple logically separated mobile services or provider profiles to be configured. Different APNs can represent enterprise services, management traffic, production systems, backup connectivity, or isolated customer networks. Global-frequency-band support improves deployment flexibility across countries and carrier networks, subject to local spectrum regulation and the supported modem variant.
Huawei SD-WAN can use 5G as a primary, secondary, or bypass link and supports combinations such as dual 5G and 5G plus wired connectivity for service assurance. Therefore, NR Release 16, carrier aggregation, eight APNs, and global frequency bands are all supported.
==================