ExamGecko
Question list
Search
Search

List of questions

Search

Question 14 - JN0-335 discussion

Report
Export

Click the Exhibit button.

You are validating the configuration template for device access. The commands in the exhibit have been entered to secure IP access to an SRX Series device.

Referring to the exhibit, which two statements are true? (Choose two.)

A.
The device manager can access the device from 192.168.11.248.
Answers
A.
The device manager can access the device from 192.168.11.248.
B.
The loopback interface blocks invalid traffic on its entry into the device.
Answers
B.
The loopback interface blocks invalid traffic on its entry into the device.
C.
The loopback interface blocks invalid traffic on its exit from the device.
Answers
C.
The loopback interface blocks invalid traffic on its exit from the device.
D.
The device manager can access the device from 10.253.1.2.
Answers
D.
The device manager can access the device from 10.253.1.2.
Suggested answer: B, D

Explanation:

The commands in the exhibit show how to configure a firewall filter on the loopback interface (lo0) of an SRX Series device. The loopback interface is a gateway for all the control traffic that enters the Routing Engine of the device. The firewall filter can be used to monitor and protect this control traffic from various attacks. Two statements that are true based on the exhibit are:

The loopback interface blocks invalid traffic on its entry into the device: The firewall filter applied on lo0 has a term that matches any packet with an invalid source address (such as 0.0.0.0/8 or 127.0.0.0/8) and discards it. This prevents spoofing or DoS attacks using invalid source addresses.

The device manager can access the device from 10.253.1.2: The firewall filter applied on lo0 has a term that matches any packet with a source address of 10.253.1.2 and accepts it. This allows the device manager to access the device from this IP address using protocols such as SSH, Telnet, HTTP, or HTTPS.

asked 18/09/2024
Sergio Guerra
43 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first