Pass the Juniper JNCIP-SEC JN0-637 Questions and answers with CertsForce

Viewing page 2 out of 4 pages
Viewing questions 11-20 out of questions
Questions # 11:

Exhibit:

Question # 11

You have deployed an SRX Series device as shown in the exhibit. The devices in the Local zone have recently been added, but their SRX interfaces have not been configured. You must configure the SRX to meet the following requirements:

    Devices in the 10.1.1.0/24 network can communicate with other devices in the same network but not with other networks or the SRX.

    You must be able to apply security policies to traffic flows between devices in the Local zone.

Which three configuration elements will be required as part of your configuration? (Choose three.)

Options:

A.

set security zones security-zone Local interfaces ge-0/0/1.0


B.

set interfaces ge-0/0/1 unit 0 family ethernet-switching vlan-members 10


C.

set protocols l2-learning global-mode switching


D.

set protocols l2-learning global-mode transparent-bridge


E.

set security zones security-zone Local interfaces irb.10


Expert Solution
Questions # 12:

Exhibit:

Question # 12

You have deployed a pair of SRX series devices in a multimode HA environment. You need to enable IPsec encryption on the interchassis link.

Referring to the exhibit, which three steps are required to enable ICL encryption? (Choose three.)

Options:

A.

Install the Junos IKE package on both nodes.


B.

Enable OSPF for both interchassis link interfaces and tum on the dynamic-neighbors parameter.


C.

Configure a VPN profile for the HA traffic and apply to both nodes.


D.

Enable HA link encryption in the IPsec profile on both nodes.


E.

Enable HA link encryption in the IKE profile on both nodes,


Expert Solution
Questions # 13:

You are deploying threat remediation to endpoints connected through third-party devices.

In this scenario, which three statements are correct? (Choose three.)

Options:

A.

All third-party switches must support AAA/RADIUS and Dynamic Authorization Extensions to the RADIUS protocol.


B.

The connector uses an API to gather endpoint MAC address information from the RADIUS server.


C.

All third-party switches in the specified network are automatically mapped and registered with the RADIUS server.


D.

The connector queries the RADIUS server for the infected host endpoint details and initiates a change of authorization (CoA) for the infected host.


E.

The RADIUS server sends Status-Server messages to update infected host information to the connector.


Expert Solution
Questions # 14:

Referring to the exhibit,

Question # 14

which two statements about User1 are true? (Choose two.)

Options:

A.

User1 has access to the configuration specific to their assigned logical system.


B.

User1 is logged in to logical system LSYS-1.


C.

User1 can add logical units to an interface that a primary administrator has not previously assigned.


D.

User1 can view outputs from other user logical systems.


Expert Solution
Questions # 15:

An ADVPN configuration has been verified on both the hub and spoke devices and it seems fine. However, OSPF is not functioning as expected.

Question # 15

Referring to the exhibit, which two statements under interface st0.0 on both the hub and spoke devices would solve this problem? (Choose two.)

Options:

A.

interface-type p2mp


B.

dynamic-neighbors


C.

passive


D.

interface-type p2p


Expert Solution
Questions # 16:

Exhibit:

Question # 16

Question # 16

You are having problems configuring advanced policy-based routing.

What should you do to solve the problem?

Options:

A.

Apply a policy to the APBR RIB group to only allow the exact routes you need.


B.

Change the routing instance to a forwarding instance.


C.

Change the routing instance to a virtual router instance.


D.

Remove the default static route from the main instance configuration.


Expert Solution
Questions # 17:

You want to enable transparent mode on your SRX series device.

In this scenario, which three actions should you perform? (Choose three.)

Options:

A.

Enable the ethernet-switching family on your Layer 2 interfaces


B.

Install a Layer 2 feature license.


C.

Reboot the SRX device.


D.

Ensure that no IRB interfaces are configured on the device.


E.

Add your Layer 2 interfaces to a security zone.


Expert Solution
Questions # 18:

You want to bypass IDP for traffic destined to social media sites using APBR, but it is not working and IDP is dropping the session.

What are two reasons for this problem? (Choose two.)

Options:

A.

IDP disable is not configured on the APBR rule.


B.

The application services bypass is not configured on the APBR rule.


C.

The APBR rule does a match on the first packet.


D.

The session did not properly reclassify midstream to the correct APBR rule.


Expert Solution
Questions # 19:

Click the Exhibit button.

Question # 19

Referring to the exhibit, which two statements are true? (Choose two.)

Options:

A.

The traffic is permitted.


B.

The traffic was initiated by the 10.10.102.10 address.


C.

The destination device is not responding.


D.

The traffic is denied.


Expert Solution
Questions # 20:

You have a multinode HA default mode deployment and the ICL is down.

In this scenario, what are two ways that the SRX Series devices verify the activeness of their peers? (Choose two.)

Options:

A.

Custom IP addresses may be configured for the activeness probe.


B.

Fabric link heartbeats are used to verify the activeness of the peers.


C.

Each peer sends a probe with the virtual IP address as the destination IP address.


D.

Each peer sends a probe with the virtual IP address as the source IP address and the upstream router as the destination IP address.


Expert Solution
Viewing page 2 out of 4 pages
Viewing questions 11-20 out of questions