ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 60 - JN0-636 discussion

Report
Export

Exhibit

Referring to the exhibit, which two statements are true? (Choose two.)

A.
The data that traverses the ge-0/070 interface is secured by a secure association key.
Answers
A.
The data that traverses the ge-0/070 interface is secured by a secure association key.
B.
The data that traverses the ge-070/0 interface can be intercepted and read by anyone.
Answers
B.
The data that traverses the ge-070/0 interface can be intercepted and read by anyone.
C.
The data that traverses the ge-070/0 interface cannot be intercepted and read by anyone.
Answers
C.
The data that traverses the ge-070/0 interface cannot be intercepted and read by anyone.
D.
The data that traverses the ge-O/0/0 interface is secured by a connectivity association key.
Answers
D.
The data that traverses the ge-O/0/0 interface is secured by a connectivity association key.
Suggested answer: A, C

Explanation:

The exhibit shows the output of the show security macsec statistics interface ge-0/0/70 detail command on an SRX Series device. This command displays the statistics for the Media Access Control Security (MACsec) feature on the ge-0/0/70 interface. MACsec is a feature that provides point-topoint security on Ethernet links by using encryption and data integrity checks. MACsec uses two types of keys to secure the traffic: the Connectivity Association Key (CAK) and the Secure Association Key (SAK). The CAK is used for authentication and key exchange between the MACsec peers. The SAK is used for encryption and decryption of the MACsec traffic.

The two statements that are true based on the exhibit are:

The data that traverses the ge-0/0/70 interface is secured by a secure association key. This is because the exhibit shows that the interface has a Secure Channel (SC) and a Secure Association (SA) established. The SC is a logical connection between the MACsec peers that carries the encrypted traffic. The SA is a subset of the SC that contains the SAK and other parameters for encrypting and decrypting the traffic. The exhibit shows that the interface has encrypted and protected packets, which means that the traffic is secured by the SAK.

The data that traverses the ge-0/0/70 interface cannot be intercepted and read by anyone. This is because the exhibit shows that the interface has encryption enabled. The encryption option indicates whether the MACsec traffic is encrypted or not. If encryption is enabled, the traffic is encrypted by the SAK and cannot be viewed by anyone monitoring the link. If encryption is disabled, the traffic is only protected by the SAK and can be viewed by anyone monitoring the link.

Reference: Juniper Security, Professional (JNCIP-SEC) Reference Materials source and documents:

https://www.juniper.net/documentation/en_US/junos/topics/reference/command-summary/show-security-macsec-statistics-interface-detail.html

https://www.juniper.net/documentation/en_US/junos/topics/concept/security-macsecoverview.html

asked 18/09/2024
alejandro capel
49 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first