You have deployed automated threat mitigation using Security Director with Policy Enforcer, Juniper ATP Cloud, SRX Series devices, and EX Series switches.
In this scenario, which device is responsible for blocking infected hosts?
AEX Series switch
BJuniper ATP Cloud
CPolicy Enforcer
DSecurity Director
0
Community Discussion
No comments yet. Be the first to start the discussion!
An SRX Series device is deployed at the network edge to protect Internet-bound sessions from local hosts by using source NAT. You need to ensure that users can interact with Internet applications that require more than one TCP session for the same application session.
Which two features meet this requirement?
Choose two
Apersistent NAT
Baddress persistence
CSTUN
Ddouble NAT
0
Community Discussion
No comments yet. Be the first to start the discussion!
Troubleshooting Security Policies and Security Zones
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
0
Community Discussion
No comments yet. Be the first to start the discussion!
How does an SRX Series device inspect exception traffic?
AThe device examines the host-outbound traffic for the ingress interface and zone.
BThe device examines the host-inbound traffic for the ingress interface and zone.
CThe device examines the host-outbound traffic for the egress interface and zone.
DThe device examines the host-inbound traffic for the egress interface and zone.
You configure two Ethernet interfaces on an SRX Series device as Layer 2 interfaces and place them in the same VLAN. The SRx uses the default 12-learning setting. You do not add these interfaces to a security zone.
Which two statements are true in this scenario?
Choose two
AYou cannot add Layer 2 interfaces to a security zone.
BYou are unable to apply stateful security features to traffic that is switched between the two interfaces.
CThe interfaces will not forward traffic by default.
DYou are able to apply stateful security features to traffic that enters and exits the VLAN.
Which three attributes does APBR query from the application system cache (ASC) module?
Choose three
ATTL
Bdestination port
Cservice
Dprotocol type
EDSCP
You have cloud deployments in Azure, AWS, and a private cloud. You deployed a multicloud environment by using Security Director with Policy Enforcer to simplify your company's separate cloud solutions.
Which three statements are true for this scenario?
Choose three
AYou can run Juniper ATP scans only on traffic from your private cloud.
BYou can run Juniper ATP scans for all three domains.
CThe Policy Enforcer is able to flag infected hosts in all three domains.
DYou must secure the policies individually by domain.
EYou can simultaneously manage the security policies in all three domains.
Click the Exhibit button.
You can use SSH from SRX-1 to R-1, but not Telnet. Both Telnet and SSH services are enabled on R-1.
With reference to the exhibit, which configuration on SRX-1 is denying access?
AThe security policy from the junos-host zone to the TRUST zone is denying port 22.
BThe security policy from the TRUST zone to the junos-host zone is denying port 22.
CThe security policy from the junos-host zone to the TRUST zone is denying port 23.
DThe security policy from the TRUST zone to the junos-host zone is denying port 23.
You are deploying OSPF over IPsec, using GRE, between an SRX Series device and a third-party device.
Which two statements are correct?
Choose two
AOverlapping addresses are allowed between remote networks.
BThe GRE interface should use lo0 as endpoints
CThe GRE interface must be configured under the OSPF protocol.
DThe OSPF protocol must be enabled under the VPN zone.
You need to connect two hosts directly attached to an SRX Series device. Traffic must pass through the SRX unchanged, with neither routing nor switching lookups performed; however, it must still undergo security-policy checks.
What provides this functionality?
Atransparent mode
Bsecure wire
CMACsec
Dmixed mode
Which two statements concerning Policy Enforcer and the Forescout Integration are true?
Choose two
AA Forescout CounterACT agent must be installed on third-party devices.
B802.1X authenticated devices are supported
CA Forescout CounterACT agent is agentless and does not need to be installed on third-party devices.
D802.1X authenticated devices are not supported.
What role does an SRX Series device perform in a DS-Lite deployment?
Asoftwire concentrator
Bsoftwire initiator
CSTUN client
DSTUN server
A user reports that a particular application is not functioning properly. The application creates multiple connections to the server and must use the same address every time. The firewall assigns several different source addresses from a pool, and this behavior must be changed.
What would resolve this problem?
AUse the persistent-nat parameter.
BUse STUN.
CUse the address-persistent parameter.
DUse DNS doctoring.
Click the Exhibit button.
You are troubleshooting a newly configured IPsec VPN between your corporate office and the RemoteSite1 SRX Series device. The VPN is currently not establishing. The RemoteSite1 device receives an IP address for its gateway interface through DHCP.
Referring to the exhibit, which action will resolve this issue?
AOn the RemoteSite1 device, change the IKE gateway external interface to st0.0.
BOn both devices, change the IKE version to use version 2 only.
COn both devices, change the IKE policy proposal set to basic.
DOn both devices, change the IKE policy mode to aggressive.
Which two statements about transparent mode and Ethernet switching mode on an SRX Series device are correct?
Choose two
AIn transparent mode, IRB Interfaces must be placed in a security zone
BIn Ethernet switching mode Layer 2 Interfaces must be placed in a security zone.
CIn transparent mode, Layer 2 interfaces must be placed in a security zone.
DIn Ethernet switching mode. IRB Interfaces must be placed in a security zone.
Select the Exhibit button.
Based on the exhibit, which two statements are true?
Choose two
AThe traffic was initiated by the 10.10.102.10 address.
BThe traffic is denied.
CThe traffic is permitted.
DThe destination device is not responding.
Select the Exhibit button.
Referring to the exhibit, you are experiencing problems configuring advanced policy-based routing.
What should you do to resolve the problem?
AApply a policy to the ABPR RIB group to only allow the exact routes you need.
BRemove the default static route from the main instance configuration.
CChange the routing instance to a forwarding instance.
DChange the routing instance to a virtual router instance.
You want to establish communication between tenant systems without using physical revenue ports on an SRX Series device.
Which two methods can accomplish this?
Choose two
AUse an interconnect VPLS switch.
BUse a secure wire.
CUse a point-to-point logical tunnel.
DUse an external router.
A company has acquired a new branch office with the same address space as one of its local networks, 192.168.100/24. The offices must be able to communicate with one another.
Which two NAT configurations meet this requirement?
Choose two
A
B
C
D
You want to use a security profile to restrict the system resources allocated to user logical systems.
In this scenario, which two statements are correct?
Choose two
AOne security profile can only be applied to one logical system.
BIf you do not specify anything for a resource, no resource is reserved for a specific logical system, but the entire system can compete for resources up to the maximum available.
COne security profile system can be applied to multiple logical systems.
DIf nothing is specified for a resource a default reserved resource is set for a specific logical system.
What are the three core components required to enable advanced policy-based routing?
Choose three
AAPBR profile
Brouting instance
Cfilter-based forwarding
Dpolicies
Erouting options
You have set the backup signal route IP for your multinode HA deployment, and the ICL link fails.
Which two statements are correct for this scenario?
Choose two
AThe current active node retains the active role.
BThe active node keeps the active signal route.
CThe backup node changes the routing preference to the other node at its medium priority.
DThe active node removes the active signal route.
Which two statements correctly describe the procedures a Junos security device uses to handle traffic destined for the device itself?
Choose two
AIf the received packet is addressed to the ingress interface, then the device first performs a security policy evaluation for the junos-host zone.
BIf the received packet is addressed to the ingress interface, then the device first examines the host -inbound-traffic configuration for the ingress interface and zone.
CIf the received packet is destined for an interface other than the ingress interface, then the device performs a security policy evaluation based on the ingress and egress zone.
DIf the received packet is destined for an interface other than the ingress interface, then the device performs a security policy evaluation for the junos-host zone.
Community Discussion