Huawei HCIA-5G-Security Solution (H35-664) Certification Sample Questions
Getting knowledge of the Huawei H35-664 exam structure and question format is vital in preparing for the HCIA-5G-Security Solution certification exam. Our Huawei HCIA-5G-Security Solution sample questions offer you information regarding the question types and level of difficulty you will face in the real exam. The benefit of using these Huawei H35-664 sample questions is that you will get to check your preparation level or enhance your knowledge by learning the unknown questions. You will also get a clear idea of the exam environment and exam pattern you will face in the actual exam with the HCIA-5G-Security Solution Sample Practice Test. Therefore, solve the Huawei HCIA-5G-Security Solution sample questions to stay one step forward in grabbing the HCIA-5G-Security Solution credential.
These Huawei H35-664 sample questions are simple and basic questions similar to the actual Huawei HCIA-5G-Security Solution questions. If you want to evaluate your preparation level, we suggest taking our HCIA-5G-Security Solution Premium Practice Test. You might face difficulties while solving the real-exam-like questions. But, you can work hard and build your confidence on the syllabus topics through unlimited practice attempts.
Huawei H35-664 Sample Questions:
01. An operator's gNBs at cell sites connect to its core data center over leased backhaul that the operator does not control. All core functions, including the SMF and the UPF, sit in that data center. Neighboring gNBs also exchange traffic with each other over the same backhaul.
Which traffic could an attacker with access to that backhaul observe or alter if it is left unprotected?
(Choose two.)
a) N4 session rules sent from the SMF down to the UPF.
b) The subscriber's long-term key, sent to the gNB during registration.
c) N2 signaling to the AMF and N3 user data to the UPF.
d) Over-the-air traffic between UEs and their serving gNB.
e) Xn signaling exchanged between neighboring gNBs.
02. A defense contractor's policy states that its production traffic must never run on equipment that also carries other organizations' traffic. An operator offers the contractor a slice with dedicated core NFs, reserved radio resources and its own transport VPN.
Does the offer satisfy the policy?
a) No, since only a network on dedicated equipment meets that policy.
b) Yes, since dedicated core NFs, reserved radio resources and a transport VPN make the slice physically separate.
c) Yes, provided the slice's traffic is also encrypted end to end, since encryption removes the need for separate equipment.
d) No, since a slice can have dedicated core NFs only when it also has dedicated cell sites, which this offer lacks.
03. A vendor has completed the process assessment part of NESAS and now needs its new gNB release evaluated. Its product manager asks who performs the evaluation and what the product is evaluated against.
Which statement is correct?
a) An accredited test laboratory evaluates the gNB against the vendor's own security target.
b) An accredited test laboratory evaluates the gNB against the operator's acceptance criteria.
c) An accredited test laboratory evaluates the gNB against ISO/IEC 27001 controls.
d) An accredited test laboratory evaluates the gNB using the applicable 3GPP SCAS as the test basis.
04. An operator is splitting its gNBs into a CU and DUs. The DUs will sit in street cabinets beside the antennas, and the planners must decide where the CUs go. The security team wants the point where user data leaves radio-interface protection to be in a physically secured site.
Which placement decision meets this requirement?
a) Place the DUs in a secured site, because radio protection terminates in the physical layer that they host.
b) Place the CUs in a secured site, because PDCP runs there and radio protection terminates in it.
c) Place the CUs beside the DUs to shorten the midhaul, simplify cabling and reduce latency.
d) Place the CUs in the cabinets too, because the transport link to the core is where radio protection ends.
05. At 02:10 an edge site raises a cabinet-door-open alarm, although no maintenance visit is scheduled. At 02:25 the edge UPF at that site restarts without any planned change, comes back up and starts carrying traffic again.
What should the security O&M engineer do?
a) Treat it as possible tampering and verify the node's software integrity before it carries traffic.
b) Clear both alarms once the UPF has recovered and traffic is flowing normally.
c) Raise a transport ticket for the N4 link between the UPF and the SMF.
d) Record both alarms in the shift log and review them at the next scheduled security audit of the site.
06. A hospital buys a slice for remote patient monitoring on an operator's shared infrastructure. Its risk assessment lists one concern: during a major public event, consumer traffic on the operator's broadband slice could consume capacity that the monitoring devices need. A reviewer states that slice isolation is a confidentiality control and so does not address this concern.
How should the reviewer's statement be evaluated?
a) It is correct, since isolation exists to stop one slice's traffic being read by another slice's tenant.
b) It is correct, since capacity during public events is set by the radio scheduler, which slicing cannot influence.
c) It is wrong, since isolation encrypts each slice's traffic so the broadband slice cannot see monitoring data.
d) It is wrong, since resource isolation also protects availability.
07. An operator downloads CNF images from a vendor's repository. Today its deployment pipeline compares each image with a checksum file published in the same repository. A review warns that an attacker who gains write access to the repository could replace an image with a modified one.
Which change to the pipeline defends against that attack?
a) Download the image and its checksum file over an encrypted connection.
b) Verify the vendor's signature on each image before deployment.
c) Compare the checksum twice, once at download and again just before deployment.
d) Scan each running container for known vulnerabilities once it is deployed.
08. Security monitoring shows that a small number of UEs each day report an authentication synchronization failure, after which authentication succeeds on the next attempt. A new analyst proposes opening a security incident for every such event.
What is the correct view of these events?
a) Each shows that a false base station has captured the UE.
b) They reveal that the UDM holds a corrupted long-term key.
c) On its own, this is routine resynchronization.
d) They prove an attacker has de-concealed the UE's SUCI.
09. An attacker gains full read access to an AMF in a visited network, including the security contexts it holds for roaming subscribers. The home operator is assessing what the breach exposes.
Which of those subscribers' keys can the attacker still not obtain from this breach?
a) The long-term key held in the USIM and the ARPF.
b) The anchor key the serving network received once primary authentication completed.
c) The NAS keys that protect signaling between these subscribers' UEs and the AMF.
d) The key the AMF passed to the gNB, from which the radio-link keys are derived.
10. A regional operator buys a core network product that has a NESAS evaluation report. A manager proposes closing the network's security review because "the product is already NESAS-evaluated".
Which two responsibilities does the operator still own after the purchase?
(Choose two.)
a) The accredited laboratory's evaluation of the product's own security functions.
b) The audit of the vendor's development and product lifecycle processes.
c) Fixing design flaws in the product's software, which the operator patches into the source code itself.
d) Operation, patching and monitoring of the product.
e) Secure configuration of the product and its integration into the network.
Answers:
|
Question: 01 Answer: c, e |
Question: 02 Answer: a |
Question: 03 Answer: d |
Question: 04 Answer: b |
Question: 05 Answer: a |
|
Question: 06 Answer: d |
Question: 07 Answer: b |
Question: 08 Answer: c |
Question: 09 Answer: a |
Question: 10 Answer: d, e |
Note: For any error in HCIA-5G-Security Solution (H35-664) certification exam sample questions, please update us by writing an email on feedback@certfun.com.
- HCIA-5G-Security Solution |
- H35-664 Questions |
- H35-664 Quiz |
- H35-664 |
- Huawei HCIA-5G-Security Solution Certification |
- Huawei H35-664 Question Bank |
- HCIA-5G-Security Solution Mock Exam |
- HCIA-5G-Security Solution Sample Questions |
- Huawei H35-664 Practice Test Free |
- HCIA-5G-Security Solution Certification Sample Questions
