ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 83 - JN0-636 discussion

Report
Export

You must implement an IPsec VPN on an SRX Series device using PKI certificates for authentication.

As part of the implementation, you are required to ensure that the certificate submission, renewal, and retrieval processes are handled automatically from the certificate authority.

In this scenario, which statement is correct.

A.
You can use CRL to accomplish this behavior.
Answers
A.
You can use CRL to accomplish this behavior.
B.
You can use SCEP to accomplish this behavior.
Answers
B.
You can use SCEP to accomplish this behavior.
C.
You can use OCSP to accomplish this behavior.
Answers
C.
You can use OCSP to accomplish this behavior.
D.
You can use SPKI to accomplish this behavior.
Answers
D.
You can use SPKI to accomplish this behavior.
Suggested answer: B

Explanation:

Certificate Renewal

The renewal of certificates is much the same as initial certificate enrollment except you are just replacing an old certificate (about to expire) on the VPN device with a new certificate. As with the initial certificate request, only manual renewal is supported. SCEP can be used to re-enroll local certificates automatically before they expire. Refer to Appendix D for more details.

asked 18/09/2024
Danilo Nogueira
37 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first