Huawei HCIP-5G-Security Solution (H35-665) Certification Sample Questions
Getting knowledge of the Huawei H35-665 exam structure and question format is vital in preparing for the Huawei Certified ICT Professional-5G-Security Solution certification exam. Our Huawei HCIP-5G-Security Solution sample questions offer you information regarding the question types and level of difficulty you will face in the real exam. The benefit of using these Huawei H35-665 sample questions is that you will get to check your preparation level or enhance your knowledge by learning the unknown questions. You will also get a clear idea of the exam environment and exam pattern you will face in the actual exam with the Huawei Certified ICT Professional-5G-Security Solution Sample Practice Test. Therefore, solve the Huawei HCIP-5G-Security Solution sample questions to stay one step forward in grabbing the Huawei Certified ICT Professional-5G-Security Solution credential.
These Huawei H35-665 sample questions are simple and basic questions similar to the actual Huawei HCIP-5G-Security Solution questions. If you want to evaluate your preparation level, we suggest taking our Huawei Certified ICT Professional-5G-Security Solution Premium Practice Test. You might face difficulties while solving the real-exam-like questions. But, you can work hard and build your confidence on the syllabus topics through unlimited practice attempts.
Huawei H35-665 Sample Questions:
01. An operator is building a slice for a bank's payment terminals beside its consumer slices on a shared RAN. The bank requires that PDU session management and user-plane traffic for its terminals are handled only by functions dedicated to its slice. It accepts sharing the RAN and the functions that handle registration and mobility, and the operator wants the lowest-cost design that meets the requirement.
Which configuration should the operator choose?
a) A dedicated SMF and UPF for the bank's slice, with a shared AMF and RAN
b) A dedicated AMF for the bank's slice, with a shared SMF, UPF and RAN
c) A shared AMF, SMF, UPF and RAN, with a separate S-NSSAI for the bank
d) A dedicated AMF, SMF and UPF for the bank's slice, with a shared RAN
02. A security architect is ranking the impact of compromise for components of an operator's virtualized core. The candidates are a single UPF instance, one gNB, one subscriber's USIM, and the NFV orchestrator that instantiates, scales and terminates all core NFs.
Which compromise has the broadest impact?
a) The UPF instance, because it forwards user traffic for every slice in the network
b) The orchestrator, because it controls every NF's lifecycle
c) The USIM, because its long-term key lets an attacker act for all subscribers
d) The gNB, because it holds the long-term keys of every attached subscriber
03. An operator's incident response team has confirmed that a MEC application server is compromised. It has isolated the server from the network and captured forensic images of its memory and disk.
Which incident response activity should the team carry out next?
a) Recovery: return the server to production service immediately
b) Preparation: write and test the team's playbooks
c) Eradication: remove the attacker's malware and access
d) Detection: confirm once more that an incident has occurred
04. A car-parts factory connects its own programmable logic controllers and a supplier-built monitoring application to an operator-provided private 5G network. A penetration test finds an unauthenticated remote-control function in the monitoring application, reachable from the factory's devices over the 5G network.
Under the shared responsibility model, who owns remediation of this finding?
a) The operator, because the vulnerable application is reachable across its 5G network
b) The national regulator, because the factory counts as critical industrial infrastructure
c) The network equipment vendor, because its gNBs and UPF carry the application's traffic
d) The factory, because it owns that connected application
05. A utility deploys thousands of 5G smart-meter modules in unattended street cabinets. Its risk assessment notes that a thief could remove a module's USIM and insert it into attacker-controlled equipment to reach the network as that meter.
Controls inside the module that lock the USIM so it works only with its authorized mobile equipment belong to which security domain?
a) User domain security, because it protects access between the USIM and the mobile equipment
b) Network domain security, because the equipment connects through operator transport
c) Application domain security, because the meter application runs on the module
d) Network access security, because the network authenticates the subscription held in the USIM
06. An operator's security architects are mapping where each protection for a UE's traffic terminates on the network side.
Which protections terminate at the gNB?
(Choose two.)
a) De-concealment of the UE's SUCI
b) Ciphering of NAS signaling
c) Verification of the UE's authentication response
d) Integrity protection of RRC signaling
e) PDCP ciphering of user-plane data on radio bearers
07. A power grid operator connects legacy substation devices that have no 5G modem. Each substation uses an industrial 5G router whose SIM authenticates to the operator, with the devices plugged into the router's Ethernet ports. An audit finds that any laptop plugged into a spare port gets the same access as the devices.
Which control closes this gap?
a) Switching the router's primary authentication from 5G AKA to EAP-AKA'
b) Secondary authentication of the router's PDU sessions by the grid operator's AAA server
c) Authenticating wired devices at the router's ports before they use its 5G session
d) Allowing only the router's subscription onto the substation DNN and slice at the UDM
08. An operator splits its gNB-CU into a central CU-CP and CU-UP instances placed at edge sites near a stadium and a university campus. A design review asks which link carries the user-plane security keys from the CU-CP to the CU-UP.
Which interface is it?
a) E1, between the CU-CP and each CU-UP instance
b) N2, between the CU-CP and the AMF
c) N3, between each CU-UP and the UPF
d) F1-C, between the CU-CP and each gNB-DU
09. A wind farm operator moves from a design where turbine data crossed the operator's central core to one with a UPF and edge server at the substation, linked to the operator core over the wind farm's own transport network, which the operator does not manage. The change keeps turbine data local and cuts latency.
Which risk does the new design introduce that the central design largely avoided?
a) Exposure of the turbines' long-term keys held in the UDM
b) Interception of N3 and N4 on the site transport
c) Loss of NAS protection between turbines and the AMF
d) Abuse of roaming signaling across the N32 interface
10. On a port's private 5G network, analysis of registrations from several UEs near one quay shows that the network selected weaker algorithms for them than it assigns to identical UEs elsewhere. A rogue relay device was later found near the quay.
Which threat class was being attempted?
a) A replay of previously captured authentication vectors from the home network
b) A signaling storm caused by UEs repeating their registration attempts
c) A bidding-down attack
d) An extraction of the long-term key stored in each UE's USIM
Answers:
|
Question: 01 Answer: a |
Question: 02 Answer: b |
Question: 03 Answer: c |
Question: 04 Answer: d |
Question: 05 Answer: a |
|
Question: 06 Answer: d, e |
Question: 07 Answer: c |
Question: 08 Answer: a |
Question: 09 Answer: b |
Question: 10 Answer: c |
Note: For any error in Huawei Certified ICT Professional-5G-Security Solution (H35-665) certification exam sample questions, please update us by writing an email on feedback@certfun.com.
- H35-665 Questions |
- H35-665 Quiz |
- H35-665 |
- Huawei HCIP-5G-Security Solution Certification |
- Huawei H35-665 Question Bank |
- HCIP-5G-Security Solution Mock Exam |
- HCIP-5G-Security Solution |
- HCIP-5G-Security Solution Sample Questions |
- Huawei H35-665 Practice Test Free |
- HCIP-5G-Security Solution Certification Sample Questions
