No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
When establishing an IPsec tunnel, which encryption type uses public and private keys?
Asymmetric encryption
Basymmetric encryption
CDES encryption
DAES encryption
You are asked to configure your company’s SRX Series device to use identity-aware security policies. Information about your Active Directory network is shown in the exhibit.
In this scenario, why must you configure JIMS rather than Active Directory as the identity source?
AJIMS is the only way to get data from Active Directory.
BYou have too many Active Directory users.
CThe version of Windows OS is too old.
DYou have too many domain controllers.
Which two statements are accurate about client-protection Secure Socket Layer (SSL) proxy configurations?
Choose two
AServer certificate is required.
BRoot certificate authority (CA) configuration is required.
CRoot certificate authority (CA) configuration is not required.
DServer certificate is not required.
You need to configure a cluster between SRX1 and SRX2.
Which two commands are required to complete this task?
Choose two
Auser@SRX2# set chassis cluster cluster-id 0 node 1
Buser@SRXl> set chassis cluster cluster-id 1 node 0
Cuser@SRX2> set chassis cluster cluster-id 1 node 1
Duser@SRXl# set chassis cluster cluster-id 0 node 2
Which two statements regarding PC probes that the JIMS server sends are correct?
Choose two
APC probes are triggered only when there is no IP-to-username mapping present in the event log.
BPC probes are sent by the JIMS server to domain PCs every 30 seconds.
CPC probes are sent by the JIMS server to domain PCs every 60 seconds.
DIf a probe is successful, the authentication entry is updated on the JIMS server and pushed to the SRX.
Which two capabilities give Juniper Secure Connect flexibility in connection and authentication methods while ensuring remote users can securely access company servers and cloud resources?
Choose two
AIt uses a persistent agent.
BIt uses Kerberos authentication.
CIt uses external authentication.
DIt uses an SSL VPN.
When using Adaptive Threat Profiling, which two deployment modes are supported on SRX Series devices?
Choose two
Abridge
Binline
Ctap
Dpromiscuous
You need to configure an SSL proxy on SRX Series devices. An SSL proxy profile has already been defined.
Which two steps are necessary to finish the configuration?
Choose two
AEnable host-inbound-traffic HTTPS in the security zone in which SSL proxy is referenced.
BReference the SSL proxy profile in a security zone.
CReference the SSL proxy profile in a security policy.
DEnable any Layer 7 services in the security policy in which SSL proxy is referenced.
Which IDP action is also known as a silent discard?
Ano action
Bclose client and server
Cignore connection
Ddrop packet
Which two statements correctly describe the role of hashing in VPNs?
Choose two
AHashing compresses data in VPN communications.
BHashing generates a fixed-size string of characters.
CHashing encrypts data to ensure confidentiality.
DHashing verifies that data has not been altered during transmission.
A new site-to-site VPN tunnel has been configured. The exhibit displays the security IPsec statistics output for the particular tunnel index on one tunnel-end device.
Which two statements are correct for this scenario?
Choose two
AAH is incorrectly configured.
BThe far-end tunnel device is rebooting.
CThe ESP configuration is not set up correctly.
DNo traffic passes through this tunnel.
Referring to the exhibit, what must you do to ensure that Juniper ATP Cloud detects malware in HTTPS traffic?
AManually configure and apply an SSL proxy profile.
BLower the threat score.
CConfigure a new device profile that includes encrypted traffic.
DChange the action to redirect the encrypted traffic to a decryption device.
You want to add a custom attack object named Custom-FTP-Attack and configure the action to drop the packet. Referring to the exhibit, which changes would you make?
AAdd custom-attack Custom-FTP-Attack to the attacks section and change the action to close-client.
BAdd custom-attack Custom-FTP-Attack to the attacks section and change the action to drop-packet.
CAdd custom-attack Custom-FTP-Attack to the action section and change the action to drop-packet.
DAdd custom-attack Custom-FTP-Attack to the notification section and change the action to drop-packet.
Which two statements explain how Juniper ATP Cloud enhances security?
Choose two
AIt tracks and logs malicious traffic.
BIt offers real-time threat analysis and mitigation.
CIt simulates real user environments to trigger malicious code execution.
DIt increases performance speeds.
How does the SSL proxy service recognize SSL traffic?
Aby examining the URL
Bby using AppID results
Cby examining the destination port
Dby reading the server certificate
You must secure communications between a mobile command center, using a 5G mobile ISP behind CGNAT, and an SRX Series Firewall at headquarters.
Which two actions should be completed on the SRX Series Firewall for this scenario?
Choose two
AConfigure the IPsec VPN to use NAT-T.
BConfigure the IPsec VPN to use IKEv1 aggressive mode.
CConfigure the IPsec VPN to use IKEv2 aggressive mode.
DConfigure the IPsec VPN to use DPD.
You are setting up an IPsec VPN and must ensure that payload data is encrypted.
Which IPsec security protocol should you configure in this scenario?
ASHA-1
BESP
CAH
DPFS
Which protocol is used by an SRX Series Firewall to communicate with a Windows domain controller?
ASSH
BLDAP
CDNS
DNETCONF
Which two statements about cluster components are accurate?
Choose two
ACluster ID values range from 1 through 255.
BNode ID values are either 0 or 1.
CCluster ID values are either 0 or 1.
DNode ID values range from 1 through 255.
Using Junos Space Security Director, you need to configure a unique firewall policy for a particular SRX Series device.
Which firewall policy rules would meet this requirement?
Community Discussion