ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 103 - JN0-636 discussion

Report
Export

you must create a secure fabric in your company's network

In this Scenario, Which three statements are correct? (Choose Three)

A.
MX Series device associated with tenants can belong to only one site
Answers
A.
MX Series device associated with tenants can belong to only one site
B.
A switch must be assigned to the site to enforce an infected host policy within the network
Answers
B.
A switch must be assigned to the site to enforce an infected host policy within the network
C.
SRX Series devices can belong to multiple sites
Answers
C.
SRX Series devices can belong to multiple sites
D.
SRX Series devices can belong to only one site
Answers
D.
SRX Series devices can belong to only one site
E.
Switches and connectors cannot be added to the same site
Answers
E.
Switches and connectors cannot be added to the same site
Suggested answer: B, D, E

Explanation:

To create a secure fabric in your company's network, you need to know the following facts:

A secure fabric is a collection of sites that contain network devices (switches, routers, firewalls, and other security devices) that are used in policy enforcement groups. A site is a grouping of network devices that contribute to threat prevention. When threat prevention policies are applied to policy enforcement groups, the system automatically discovers to which sites those groups belong. This is how threat prevention is aggregated across your secure fabric1.

MX Series devices associated with tenants can belong to multiple sites. Tenants are logical partitions of the network that can have their own security policies and enforcement points. Sites that are associated with tenants do not need switches as enforcement points, because MX Series devices can perform tenant-based policy enforcement1.

SRX Series devices can belong to only one site. SRX Series devices are firewalls that can act as perimeter enforcement points for the secure fabric. They can send potentially malicious objects and files to the Juniper ATP Cloud for analysis and receive threat intelligence from the Juniper ATP Cloud to block malicious traffic. SRX Series devices cannot belong to multiple sites, because they do not support tenant-based policy enforcement1.

A switch must be assigned to the site to enforce an infected host policy within the network. An infected host policy is a policy that blocks or quarantines hosts that are identified as infected by the Juniper ATP Cloud. A switch can act as an internal enforcement point for the secure fabric by applying the infected host policy to the hosts that are connected to it. A switch must be assigned to the site where the infected hosts are located, because SRX Series devices cannot enforce infected host policies1.

Switches and connectors cannot be added to the same site. Connectors are software agents that can be installed on Windows or Linux servers to enable them to act as enforcement points for the secure fabric. Connectors can apply infected host policies to the hosts that are connected to them. However, connectors cannot coexist with switches in the same site, because they use different methods of policy enforcement. Switches use VLANs and ACLs, while connectors use IPtables and WFP1.

Therefore, the correct answer is B, D, and E. The other options are incorrect because:

A) MX Series devices associated with tenants can belong to multiple sites, not only one site1.

C) SRX Series devices can belong to only one site, not multiple sites1.

Reference:

Secure Fabric Overview

asked 18/09/2024
Ronald Zegwaard
30 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first