Juniper JN0-637 Practice Test - Questions Answers, Page 3
List of questions
Related questions
Which two statements are true when setting up an SRX Series device to operate in mixed mode? (Choose two.)
A physical interface can be configured to be both a Layer 2 and a Layer 3 interface at the same time.
User logical systems support Layer 2 traffic processing.
The SRX must be rebooted after configuring at least one Layer 3 and one Layer 2 interface.
Packets from Layer 2 interfaces are switched within the same bridge domain.
You have configured the backup signal route IP for your multinode HA deployment, and the ICL link fails.
Which two statements are correct in this scenario? (Choose two.)
The current active node retains the active role.
The active node removes the active signal route.
The backup node changes the routing preference to the other node at its medium priority.
The active node keeps the active signal route.
Exhibit:
Host A shown in the exhibit is attempting to reach the Web1 webserver, but the connection is failing. Troubleshooting reveals that when Host A attempts to resolve the domain name of the server (web.acme.com), the request is resolved to the private address of the server rather than its public IP.
Which feature would you configure on the SRX Series device to solve this issue?
Persistent NAT
Double NAT
DNS doctoring
STUN protocol
Exhibit:
Referring to the exhibit, what do you use to dynamically secure traffic between the Azure and AWS clouds?
You can dynamically secure traffic between the clouds by using user identities in the security policies.
You can dynamically secure traffic between the clouds by using advanced connection tracking in the security policies.
You can dynamically secure traffic between the clouds by using security tags in the security policies.
You can dynamically secure traffic between the clouds by using URL filtering in the security policies.
Exhibit:
Referring to the exhibit, which IKE mode will be configured on the HQ-Gateway and Subsidiary-Gateway?
Main mode on both the gateways
Aggressive mode on both the gateways
Main mode on the HQ-Gateway and aggressive mode on the Subsidiary-Gateway
Aggressive mode on the HQ-Gateway and main mode on the Subsidiary-Gateway
You are deploying threat remediation to endpoints connected through third-party devices.
In this scenario, which three statements are correct? (Choose three.)
All third-party switches must support AAA/RADIUS and Dynamic Authorization Extensions to the RADIUS protocol.
The connector uses an API to gather endpoint MAC address information from the RADIUS server.
All third-party switches in the specified network are automatically mapped and registered with the RADIUS server.
The connector queries the RADIUS server for the infected host endpoint details and initiates a change of authorization (CoA) for the infected host.
The RADIUS server sends Status-Server messages to update infected host information to the connector.
Exhibit:
Referring to the exhibit, which two statements are correct? (Choose two.)
You cannot secure intra-VLAN traffic with a security policy on this device.
You can secure inter-VLAN traffic with a security policy on this device.
The device can pass Layer 2 and Layer 3 traffic at the same time.
The device cannot pass Layer 2 and Layer 3 traffic at the same time.
You want to test how the device handles a theoretical session without generating traffic on the Junos security device.
Which command is used in this scenario?
request security policies check
show security flow session
show security match-policies
show security policies
Exhibit:
Referring to the exhibit, which two statements are correct? (Choose two.)
The ge-0/0/3.0 and ge-0/0/4.0 interfaces are not active and will not respond to ARP requests to the virtual IP MAC address.
This device is the backup node for SRG1.
The ge-0/0/3.0 and ge-0/0/4.0 interfaces are active and will respond to ARP requests to the virtual IP MAC address.
This device is the active node for SRG1.
Which role does an SRX Series device play in a DS-Lite deployment?
Softwire concentrator
STUN server
STUN client
Softwire initiator
Question