ExamGecko
Question list
Search
Search

List of questions

Search

Question 3 - JN0-636 discussion

Report
Export

SRX Series device enrollment with Policy Enforcer fails To debug further, the user issues the following command show configuration services security—intelligence url

https : //cloudfeeds . argon . juniperaecurity . net/api/manifeat. xml and receives the following output:

What is the problem in this scenario?

A.
The device is directly enrolled with Juniper ATP Cloud.
Answers
A.
The device is directly enrolled with Juniper ATP Cloud.
B.
The device is already enrolled with Policy Enforcer.
Answers
B.
The device is already enrolled with Policy Enforcer.
C.
The SRX Series device does not have a valid license.
Answers
C.
The SRX Series device does not have a valid license.
D.
Junos Space does not have matching schema based on the
Answers
D.
Junos Space does not have matching schema based on the
Suggested answer: C

Explanation:

According to the output of the command show configuration services security-intelligence url, the SRX Series device is directly enrolled with Juniper ATP Cloud. This is indicated by the URL https://cloudfeeds.argon.junipersecurity.net/api/manifest.xml, which is the default URL for Juniper ATP Cloud1. This means that the device is not enrolled with Policy Enforcer, which would use a different URL that includes the IP address of the Policy Enforcer server2. Therefore, the problem in this scenario is that the device is directly enrolled with Juniper ATP Cloud, which prevents it from being enrolled with Policy Enforcer.

To enroll the device with Policy Enforcer, the user needs to disenroll the device from Juniper ATP Cloud first. This can be done by using the following command:

delete services security-intelligence url

This command will remove the Juniper ATP Cloud URL from the device configuration and stop the device from receiving threat feeds from Juniper ATP Cloud1. After that, the user can enroll the device with Policy Enforcer by using the Security Director GUI or the SLAX script2.

Reference: 1: Configuring Juniper ATP Cloud on SRX Series Devices 2: Enrolling SRX Series Devices with Policy Enforcer

asked 18/09/2024
Adish Narayan
38 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first