Weekend Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: xmas50

Juniper JN0-636 - Security, Professional (JNCIP-SEC)

Page: 4 / 4
Total 115 questions

Exhibit

You are asked to establish an IBGP peering between the SRX Series device and the router, but the session is not being established. In the security flow trace on the SRX device, packet drops are observed as shown in the exhibit.

What is the correct action to solve the problem on the SRX device?

A.

Create a firewall filter to accept the BGP traffic

B.

Configure destination NAT for BGP traffic.

C.

Add BGP to the Allowed host-inbound-traffic for the interface

D.

Modify the security policy to allow the BGP traffic.

Exhibit

Which two statements are correct about the output shown in the exhibit? (Choose two.)

A.

The packet is silently discarded.

B.

The packet is part of an existing session.

C.

The packet is part of a new session.

D.

The packet is explicitly rejected.

Which statement is true about persistent NAT types?

A.

The target-host-port parameter cannot be used with IPv4 addresses in NAT46.

B.

The target-host parameter cannot be used with IPv6 addressee in NAT64.

C.

The target-host parameter cannot be used with IPv4 addresses in NAT46

D.

The target-host-port parameter cannot be used with IPv6 addresses in NAT64

Exhibit

Referring to the exhibit, which two statements are true? (Choose two.)

A.

The data that traverses the ge-0/070 interface is secured by a secure association key.

B.

The data that traverses the ge-070/0 interface can be intercepted and read by anyone.

C.

The data that traverses the ge-070/0 interface cannot be intercepted and read by anyone.

D.

The data that traverses the ge-O/0/0 interface is secured by a connectivity association key.