Pass the Juniper JNCIP-SEC JN0-636 Questions and answers with CertsForce

Viewing page 2 out of 4 pages
Viewing questions 11-20 out of questions
Questions # 11:

You want to configure a threat prevention policy.

Which three profiles are configurable in this scenario? (Choose three.)

Options:

A.

device profile


B.

SSL proxy profile


C.

infected host profile


D.

C&C profile


E.

malware profile


Expert Solution
Questions # 12:

Which method does an SRX Series device in transparent mode use to learn about unknown devices in a network?

Options:

A.

LLDP-MED


B.

IGMP snooping


C.

RSTP


D.

packet flooding


Expert Solution
Questions # 13:

Which two statements are correct regarding tenant systems on SRX Series devices? (Choose two.)

Options:

A.

A maximum of 32 tenant systems can be configured on a physical SRX device.


B.

All tenant systems share a single routing protocol process.


C.

Each tenant system runs its own instance of the routing protocol process


D.

A maximum of 500 tenant systems can be configured on a physical SRX device.


Expert Solution
Questions # 14:

You want to identify potential threats within SSL-encrypted sessions without requiring SSL proxy to decrypt the session contents. Which security feature achieves this objective?

Options:

A.

infected host feeds


B.

encrypted traffic insights


C.

DNS security


D.

Secure Web Proxy


Expert Solution
Questions # 15:

Exhibit

Question # 15

Which two statements are correct about the output shown in the exhibit? (Choose two.)

Options:

A.

The packet is silently discarded.


B.

The packet is part of an existing session.


C.

The packet is part of a new session.


D.

The packet is explicitly rejected.


Expert Solution
Questions # 16:

Exhibit.

Question # 16

Referring to the exhibit, which two statements are true? (Choose two.)

Options:

A.

The configured solution allows IPv6 to IPv4 translation.


B.

The configured solution allows IPv4 to IPv6 translation.


C.

The IPv6 address is invalid.


D.

External hosts cannot initiate contact.


Expert Solution
Questions # 17:

Your company uses non-Juniper firewalls and you are asked to provide a Juniper solution for zero-day malware protection. Which solution would work in this scenario?

Options:

A.

Juniper ATP Cloud


B.

Juniper Secure Analytics


C.

Juniper ATP Appliance


D.

Juniper Security Director


Expert Solution
Questions # 18:

You have a webserver and a DNS server residing in the same internal DMZ subnet. The public Static NAT addresses for

the servers are in the same subnet as the SRX Series devices internet-facing interface. You implement DNS doctoring to

ensure remote users can access the webserver.Which two statements are true in this scenario? (Choose two.)

Options:

A.

The DNS doctoring ALG is not enabled by default.


B.

The Proxy ARP feature must be configured.


C.

The DNS doctoring ALG is enabled by default.


D.

The DNS CNAME record is translated.


Expert Solution
Questions # 19:

What are two valid modes for the Juniper ATP Appliance? (Choose two.)

Options:

A.

flow collector


B.

event collector


C.

all-in-one


D.

core


Expert Solution
Questions # 20:

Click the Exhibit button.

Question # 20

When attempting to enroll an SRX Series device to JATP, you receive the error shown in the exhibit. What is the cause of the error?

Options:

A.

The fxp0 IP address is not routable


B.

The SRX Series device certificate does not match the JATP certificate


C.

The SRX Series device does not have an IP address assigned to the interface that accesses JATP


D.

A firewall is blocking HTTPS on fxp0


Expert Solution
Viewing page 2 out of 4 pages
Viewing questions 11-20 out of questions