Juniper JN0-637 Practice Test - Questions Answers, Page 2
List of questions
Related questions
Exhibit:
You are having problems configuring advanced policy-based routing.
What should you do to solve the problem?
Apply a policy to the APBR RIB group to only allow the exact routes you need.
Change the routing instance to a forwarding instance.
Change the routing instance to a virtual router instance.
Remove the default static route from the main instance configuration.
Exhibit:
In which mode is the SRX Series device?
Packet
Ethernet switching
Mixed
Transparent
You configure two Ethernet interfaces on your SRX Series device as Layer 2 interfaces and add them to the same VLAN. The SRX is using the default L2-learning setting. You do not add the interfaces to a security zone.
Which two statements are true in this scenario? (Choose two.)
You are unable to apply stateful security features to traffic that is switched between the two interfaces.
You are able to apply stateful security features to traffic that enters and exits the VLAN.
The interfaces will not forward traffic by default.
You cannot add Layer 2 interfaces to a security zone.
Which two statements are true about the procedures the Junos security device uses when handling traffic destined for the device itself? (Choose two.)
If the received packet is addressed to the ingress interface, then the device first performs a security policy evaluation for the junos-host zone.
If the received packet is destined for an interface other than the ingress interface, then the device performs a security policy evaluation for the junos-host zone.
If the received packet is addressed to the ingress interface, then the device first examines the host-inbound-traffic configuration for the ingress interface and zone.
If the received packet is destined for an interface other than the ingress interface, then the device performs a security policy evaluation based on the ingress and egress zone.
Exhibit:
You have deployed an SRX Series device as shown in the exhibit. The devices in the Local zone have recently been added, but their SRX interfaces have not been configured. You must configure the SRX to meet the following requirements:
Devices in the 10.1.1.0/24 network can communicate with other devices in the same network but not with other networks or the SRX.
You must be able to apply security policies to traffic flows between devices in the Local zone.
Which three configuration elements will be required as part of your configuration? (Choose three.)
set security zones security-zone Local interfaces ge-0/0/1.0
set interfaces ge-0/0/1 unit 0 family ethernet-switching vlan-members 10
set protocols l2-learning global-mode switching
set protocols l2-learning global-mode transparent-bridge
set security zones security-zone Local interfaces irb.10
Exhibit:
Referring to the exhibit, which statement is true?
SRG1 is configured in hybrid mode.
The ICL is encrypted.
If SRG1 moves to peer 2, peer 1 will drop packets sent to the SRG1 interfaces.
If SRG1 moves to peer 2, peer 1 will forward packets sent to the SRG1 interfaces.
You are asked to create multiple virtual routers using a single SRX Series device. You must ensure that each virtual router maintains a unique copy of the routing protocol daemon (RPD) process.
Which solution will accomplish this task?
Secure wire
Tenant system
Transparent mode
Logical system
Click the Exhibit button.
Referring to the exhibit, which three actions do you need to take to isolate the hosts at the switch port level if they become infected with malware? (Choose three.)
Enroll the SRX Series device with Juniper ATP Cloud.
Use a third-party connector.
Deploy Security Director with Policy Enforcer.
Configure AppTrack on the SRX Series device.
Deploy Juniper Secure Analytics.
You want to deploy two vSRX instances in different public cloud providers to provide redundant security services for your network. Layer 2 connectivity between the two vSRX instances is not possible.
What would you configure on the vSRX instances to accomplish this task?
Chassis cluster
Secure wire
Multinode HA
Virtual chassis
You are asked to connect two hosts that are directly connected to an SRX Series device. The traffic should flow unchanged as it passes through the SRX, and routing or switch lookups should not be performed. However, the traffic should still be subjected to security policy checks.
What will provide this functionality?
MACsec
Mixed mode
Secure wire
Transparent mode
Question