Weekend Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: xmas50

Juniper JN0-637 - Security, Professional (JNCIP-SEC)

Page: 2 / 4
Total 115 questions

Exhibit:

Referring to the exhibit, which statement is true?

A.

SRG1 is configured in hybrid mode.

B.

The ICL is encrypted.

C.

If SRG1 moves to peer 2, peer 1 will drop packets sent to the SRG1 interfaces.

D.

If SRG1 moves to peer 2, peer 1 will forward packets sent to the SRG1 interfaces.

You have a multinode HA default mode deployment and the ICL is down.

In this scenario, what are two ways that the SRX Series devices verify the activeness of their peers? (Choose two.)

A.

Custom IP addresses may be configured for the activeness probe.

B.

Fabric link heartbeats are used to verify the activeness of the peers.

C.

Each peer sends a probe with the virtual IP address as the destination IP address.

D.

Each peer sends a probe with the virtual IP address as the source IP address and the upstream router as the destination IP address.

Exhibit:

Host A shown in the exhibit is attempting to reach the Web1 webserver, but the connection is failing. Troubleshooting reveals that when Host A attempts to resolve the domain name of the server (web.acme.com), the request is resolved to the private address of the server rather than its public IP.

Which feature would you configure on the SRX Series device to solve this issue?

A.

Persistent NAT

B.

Double NAT

C.

DNS doctoring

D.

STUN protocol

Which two statements are correct about the ICL in an active/active mode multinode HA environment? (Choose two.)

A.

The ICL is strictly a Layer 2 interface.

B.

The ICL uses a separate routing instance to communicate with remote multinode HA peers.

C.

The ICL traffic can be encrypted.

D.

The ICL is the local device management interface in a multinode HA environment.

Which two statements describe the behavior of logical systems? (Choose two.)

A.

Each logical system shares the routing protocol process.

B.

A default routing instance must be manually created for each logical system

C.

Each logical system has a copy of the routing protocol process.

D.

A default routing instance is automatically created for each logical system.

You have cloud deployments in Azure, AWS, and your private cloud. You have deployed

multicloud using security director with policy enforcer to. Which three statements are true in this scenario? (Choose three.)

A.

You can run Juniper ATP scans only on traffic from your private cloud.

B.

You can run Juniper ATP scans for all three domains.

C.

You must secure the policies individually by domain.

D.

The Policy Enforcer is able to flag infected hosts in all three domains.

E.

You can simultaneously manage the security policies in all three domains.

What is the advantage of using separate st0 logical units for each spoke connection?

A.

It is easy to configure even when managing many st0 units.

B.

It facilitates scalability.

C.

Junos devices can exchange NHTB data automatically using this method.

D.

It enables assignments of different settings to each logical unit.

You are attempting to ping the IP address that is assigned to the loopback interface on the

SRX series device shown in the exhibit.

What is causing this problem?

A.

The loopback interface requires encapsulation.

B.

The loopback interface is not assigned to a security zone.

C.

The incorrect interface index ID is assigned to the loopback interface.

D.

The IP address on the loopback interface is a private address.

You are asked to establish IBGP between two nodes, but the session is not established. To troubleshoot this problem, you configured trace options to monitor BGP protocol message exchanges.

Referring to the exhibit, which action would solve the problem?

A.

Add the junos-host zone policy to permit the BGP packets.

B.

Add a firewall filter to lo0 that permits the BGP packets.

C.

Modify the security policy to permit the BGP packets.

D.

Add BGP to the lo0 host-inbound-traffic configuration.

Click the Exhibit button.

Referring to the exhibit, which two statements are true? (Choose two.)

A.

The traffic is permitted.

B.

The traffic was initiated by the 10.10.102.10 address.

C.

The destination device is not responding.

D.

The traffic is denied.