Juniper JN0-637 Practice Test - Questions Answers, Page 8
List of questions
Related questions
Click the Exhibit button.
Referring to the exhibit, which two statements are correct? (Choose two.)
You cannot secure intra-VLAN traffic with a security policy on this device.
You can secure inter-VLAN traffic with a security policy on this device.
The device can pass Layer 2 and Layer 3 traffic at the same time.
The device cannot pass Layer 2 and Layer 3 traffic at the same time.
Which two statements are correct about automated threat mitigation with Security Director? (Choose two.)
It works with third-party switches.
It provides endpoint protection by running a Juniper ATP Cloud agent on the servers.
It provides endpoint protection by running a Juniper ATP Cloud agent on EX Series devices.
It works with SRX Series devices.
You are deploying OSPF over IPsec with an SRX Series device and third-party device using GRE.
Which two statements are correct? (Choose two.)
The GRE interface should use lo0 as endpoints.
The OSPF protocol must be enabled under the VPN zone.
Overlapping addresses are allowed between remote networks.
The GRE interface must be configured under the OSPF protocol.
You are asked to set up advanced policy-based routing.
Which type of routing instance is designed to support this scenario?
forwarding
virtual switch
virtual router
non-forwarding
Click the Exhibit button.
Referring to the exhibit, which two statements are correct? (Choose two.)
This device is the backup node for SRG1.
The ge-0/0/3.0 and ge-0/0/4.0 interfaces are not active and will not respond to ARP requests to the virtual IP MAC address.
This device is the active node for SRG1.
The ge-0/0/3.0 and ge-0/0/4.0 interfaces are active and will respond to ARP requests to the virtual IP MAC address.
Click the Exhibit button.
Referring to the exhibit. SRX-1 and SRX-3 have to be connected using EBGP. The BGP configuration on SRX-1 and SRX-3 is verified and correct.
Which configuration on SRX-2 would establish an EBGP connection successfully between SRX-1 and SRX-3?
The host-inbound-traffic statements do not allow EBGP traffic to traverse SRX-2.
The security policy to allow SRX-1 and SRX-3 to communicate on TCP port 79 should be configured.
The security policy to allow SRX-1 and SRX-3 to communicate on TCP port 169 should be configured.
The security policy to allow SRX-1 and SRX-3 to communicate on TCP port 179 should be configured.
You are attempting to ping an interface on your SRX Series device, but the ping is unsuccessful.
What are three reasons for this behavior? (Choose three.)
The interface is not assigned to a security zone.
The interface's host-inbound-traffic security zone configuration does not permit ping
The ping traffic is matching a firewall filter.
The device has J-Web enabled.
The interface has multiple logical units configured.
You are deploying IPsec VPNs to securely connect several enterprise sites with ospf for dynamic
routing. Some of these sites are secured by third-party devices not running Junos.
Which two statements are true for this deployment? (Choose two.)
OSPF over IPsec can be used for intersite dynamic routing.
Sites with overlapping address spaces can be supported.
OSPF over GRE over IPsec is required to enable intersite dynamic routing
Sites with overlapping address spaces cannot be supported.
Exhibit:
You have deployed a pair of SRX series devices in a multimode HA environment. You need to enable IPsec encryption on the interchassis link.
Referring to the exhibit, which three steps are required to enable ICL encryption? (Choose three.)
Install the Junos IKE package on both nodes.
Enable OSPF for both interchassis link interfaces and tum on the dynamic-neighbors parameter.
Configure a VPN profile for the HA traffic and apply to both nodes.
Enable HA link encryption in the IPsec profile on both nodes.
Enable HA link encryption in the IKE profile on both nodes,
Exhibit:
Which two statements are correct about the output shown in the exhibit. (Choose Two)
The data shown requires a traceoptions flag of basic-datapath.
The data shown requires a traceoptions flag of host-traffic.
The packet is dropped by the default security policy.
The packet is dropped by a configured security policy.
Question