CIt is a network management system for Juniper devices.
DIt is a network operating system for IoT devices.
An SRX Series Firewall runs in which two modes?
Choose two
Aflow mode
Bpacket mode
Croute mode
Dwireless mode
You are modifying the NAT rule order and notice that a new NAT rule was added at the bottom of the list.
In this situation, which command would you use to reorder NAT rules?
Ainsert
Brun
Ctop
Dup
You are troubleshooting first-path traffic that is not passing through an SRX Series Firewall. A route lookup has confirmed that the traffic enters and leaves through the correct interfaces.
In this scenario, what should be the next troubleshooting step to determine why the device might be dropping the traffic?
AVerify that the correct ALG is being used.
BVerify that the interfaces are in the correct security zones.
CVerify that source NAT is occurring.
DVerify the routing protocol being used.
QuestionQ6
Security Policies
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ7
Network Address Translation
QuestionQ8
Security Policies
QuestionQ9
Junos OS Security Objects
QuestionQ10
Security Policies
QuestionQ11
Content Security
QuestionQ12
Monitoring and Troubleshooting
QuestionQ13
Monitoring and Troubleshooting
QuestionQ14
Content Security
QuestionQ15
Content Security
QuestionQ16
Monitoring and Troubleshooting
QuestionQ17
Junos OS Security Objects
QuestionQ18
Monitoring and Troubleshooting
QuestionQ19
SRX Series Service Gateways
QuestionQ20
Network Address Translation
QuestionQ21
Security Policies
QuestionQ22
Monitoring and Troubleshooting
QuestionQ23
Security Policies
QuestionQ25
Content Security
QuestionQ26
Security Policies
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Ad
Want a break from the ads?
Go ad-free and unlock Learn Mode, Exam Mode, AstroTutor AI and every premium tool — everything you need to walk in prepared, and confident.
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
What occurs when no match is found in either zone-based or global security policies?
AThe traffic is discarded by the default security policy.
BThe traffic is logged for further analysis.
CThe traffic is allowed by default.
DThe traffic is redirected to a predefined safe zone.
Which two statements about destination NAT and static NAT are correct?
Choose two
ADestination NAT requires address range sizes that match the devices being translated.
BDestination NAT supports port forwarding.
CStatic NAT automatically creates a matching rule for the opposite direction.
DStatic NAT uses Port Address Translation.
Which statement is accurate regarding security policies?
ASecurity policies are evaluated before screen in first path processing.
BZone-based security policies reference both source and destination zones.
CSecurity policies are evaluated in both first path and fast path processing.
DZone-based security policies only apply to intra-zone traffic.
Which two security address objects are valid in Juniper Networks?
Choose two
Aglobal address object
Bprefix address object
Crouting address object
DMAC address object
Which two security policies are installed by default on SRX 300 Series Firewalls?
Choose two
Aa security policy to allow all traffic from the trust zone to the trust zone
Ba security policy to allow all traffic from the trust zone to the untrust zone
Ca security policy to allow all traffic from the untrust zone to the trust zone
Da security policy to allow all traffic from the management zone to the trust zone
Which two statements are correct about content filtering on SRX Series devices?
Choose two
AContent filtering requires a license.
BContent filtering examines the file extension to determine the file type.
CContent filtering does not require a license.
DContent filtering examines the file contents to determine the file type.
With reference to the exhibit, which two statements are accurate about the traffic flow displayed?
Choose two
AThere is no change to the original source IP address.
BThe original destination IP address was translated to a new destination IP address.
CThere is no change to the original destination IP address.
DThe original source IP address was translated to a new source IP address.
With reference to the exhibit, which two statements are correct?
Choose two
AThe SRX Series Firewall is performing destination NAT.
BThe SRX Series Firewall is performing source NAT.
CThe SRX Series Firewall is not performing PAT.
DThe SRX Series Firewall is performing PAT.
You want to enable NextGen Web Filtering on SRX Series devices.
In this scenario, which two actions will achieve this task?
Choose two
AGenerate a CA-signed certificate.
BGenerate a self-signed certificate.
CConfigure an SSL initiation profile.
DConfigure an SSL proxy profile.
You want to confirm that the NextGen Web Filtering (NGWF) feature is connected to the Juniper cloud.
Which operational-mode command would you use for this purpose?
Ashow security utm anti-spam status
Bshow security utm content-filtering statistics
Cshow security utm anti-virus status
Dshow security web filtering status
Your manager asks you to ping 192.0.2.128. The ping fails for an unknown reason, so you enable a trace option on your SRX Series Firewall.
Referring to the exhibit, what is the cause of this behavior?
AIt is matching a Web filter.
BIt is matching an ALG.
CIt is matching a screen.
DThere is no known route.
Which two statements regarding the host-inbound-traffic parameter in a zone configuration are correct?
Choose two
ADeleting the host-inbound-traffic parameter blocks SSH access to the firewall.
BThe host-inbound-traffic parameter is implicitly configured in the management zone.
CDeleting the host-inbound-traffic parameter blocks console access to the firewall.
DThe host-inbound-traffic parameter is explicitly configured in a security zone.
Which two statements are accurate about a Juniper Routing Engine?
Choose two
AThe Routing Engine is managed by the Packet Forwarding Engine.
BThe Routing Engine manages the Packet Forwarding Engine.
CThe Routing Engine creates the routing and switching tables.
DThe Routing Engine is responsible for forwarding transit traffic.
At what point does screening take place on an SRX Series Firewall for an ingress traffic flow?
Aafter NAT policy processing
Bafter route lookup
Cafter security policy processing
Dafter session lookup
Your company is acquiring a smaller company that uses the same private address range already used by your company’s North America division. You have only a limited number of public IP addresses available for the acquisition. You want the acquired company’s users to connect to the existing services in North America.
Which two features would you enable on your SRX Series Firewall to accomplish this task?
Choose two
AIDP
BBGP
CNAT
DPAT
Referring to the exhibit, which action would you take to permit the traffic shown in the exhibit?
AAssign the ge-0/0/1.0 interface to a security zone.
BAssign the fxp0.0 interface to a security zone.
CEnable flow-mode processing for family mpls.
DEnable flow-mode processing for family inet.
Which two statements are true regarding a Juniper Packet Forwarding Engine?
Choose two
AThe Packet Forwarding Engine is responsible for forwarding transit traffic.
BThe Packet Forwarding Engine is managed by the Routing Engine.
CThe Packet Forwarding Engine manages the Routing Engine.
DThe Packet Forwarding Engine creates the routing and switching tables.
When traffic arrives on an interface, which two outcomes does a route lookup determine?
Choose two
Aegress interface
Begress security zone
Cingress interface
DDNS name
During the NGWF process, a URL is not present in the local allow list, block list, or local cache.
What action does the SRX Series Firewall take in this situation?
AIt allows the URL by default.
BIt sends a TCP reset message to the client.
CIt forwards the URL to the NGWF application in the Juniper Cloud.
DIt blocks the URL by default.
What is the purpose of rate-limiting exception traffic in Junos OS?
Ato enhance the performance of the forwarding plane
Bto manage routing protocols and updates
Cto simplify the configuration of network interfaces
Dto prevent denial-of-service attacks on the Routing Engine
Community Discussion