Pass the Juniper JNCIP-SEC JN0-637 Questions and answers with CertsForce

Viewing page 3 out of 4 pages
Viewing questions 21-30 out of questions
Questions # 21:

You configure two Ethernet interfaces on your SRX Series device as Layer 2 interfaces and add them to the same VLAN. The SRX is using the default L2-learning setting. You do not add the interfaces to a security zone.

Which two statements are true in this scenario? (Choose two.)

Options:

A.

You are unable to apply stateful security features to traffic that is switched between the two interfaces.


B.

You are able to apply stateful security features to traffic that enters and exits the VLAN.


C.

The interfaces will not forward traffic by default.


D.

You cannot add Layer 2 interfaces to a security zone.


Expert Solution
Questions # 22:

Exhibit:

Question # 22

Referring to the exhibit, which two statements are correct? (Choose two.)

Options:

A.

You cannot secure intra-VLAN traffic with a security policy on this device.


B.

You can secure inter-VLAN traffic with a security policy on this device.


C.

The device can pass Layer 2 and Layer 3 traffic at the same time.


D.

The device cannot pass Layer 2 and Layer 3 traffic at the same time.


Expert Solution
Questions # 23:

You want to create a connection for communication between tenant systems without using physical revenue ports on the SRX Series device.

What are two ways to accomplish this task? (Choose two.)

Options:

A.

Use an external router.


B.

Use an interconnect VPLS switch.


C.

Use a secure wire.


D.

Use a point-to-point logical tunnel.


Expert Solution
Questions # 24:

How does an SRX Series device examine exception traffic?

Options:

A.

The device examines the host-inbound traffic for the ingress interface and zone.


B.

The device examines the host-outbound traffic for the ingress interface and zone.


C.

The device examines the host-inbound traffic for the egress interface and zone.


D.

The device examines the host-outbound traffic for the egress interface and zone.


Expert Solution
Questions # 25:

You configured two SRX series devices in an active/passive multimode HA setup.

In this scenario, which statement is correct?

Options:

A.

Both devices are in the passive state until the activeness determination process is completed.


B.

Both devices start in a hold state until the activeness determination process is completed.


C.

Both devices start in the undiscovered state until the activeness determination process is completed.


D.

Both devices are in the active state until the activeness determine determination process is completed.


Expert Solution
Questions # 26:

You have an initial setup of ADVPN with two spokes and a hub. A host at partner Spoke-1 is sending traffic to a host at partner Spoke-2.

In this scenario, which statement is true?

Options:

A.

Spoke-1 will establish a VPN to Spoke-2 when this is first deployed, so traffic will be sent immediately to Spoke-2.


B.

Spoke-1 will send the traffic through the hub and not use a direct VPN to Spoke-2.


C.

Spoke-1 will establish the tunnel to Spoke-2 before sending any of the host traffic.


D.

Spoke-1 will send the traffic destined to Spoke-2 through the hub until the VPN is established between the spokes.


Expert Solution
Questions # 27:

You have deployed automated threat mitigation using Security Director with Policy Enforcer, Juniper ATP Cloud, SRX Series devices, and EX Series switches.

In this scenario, which device is responsible for blocking the infected hosts?

Options:

A.

Policy Enforcer


B.

Security Director


C.

Juniper ATP Cloud


D.

EX Series switch


Expert Solution
Questions # 28:

What is the advantage of using separate st0 logical units for each spoke connection?

Options:

A.

It is easy to configure even when managing many st0 units.


B.

It facilitates scalability.


C.

Junos devices can exchange NHTB data automatically using this method.


D.

It enables assignments of different settings to each logical unit.


Expert Solution
Questions # 29:

Click the Exhibit button.

Question # 29

Referring to the exhibit, which two statements are correct? (Choose two.)

Options:

A.

You cannot secure intra-VLAN traffic with a security policy on this device.


B.

You can secure inter-VLAN traffic with a security policy on this device.


C.

The device can pass Layer 2 and Layer 3 traffic at the same time.


D.

The device cannot pass Layer 2 and Layer 3 traffic at the same time.


Expert Solution
Questions # 30:

You have deployed an SRX Series device at your network edge to secure Internet-bound sessions for your local hosts using source NAT. You want to ensure that your users are able to interact with applications on the Internet that require more than one TCP session for the same application session.

Which two features would satisfy this requirement? (Choose two.)

Options:

A.

address persistence


B.

STUN


C.

persistent NAT


D.

double NAT


Expert Solution
Viewing page 3 out of 4 pages
Viewing questions 21-30 out of questions