[2022年03月31日] JN0-635問題集でJunos Security合格確定させる練習問題集 [Q17-Q33]

Share

[2022年03月31日]GoShiken JN0-635問題集でJunos Security合格確定させる練習問題集

Juniper JN0-635実際にある問題とブレーン問題集


Juniper JN0-635 認定試験の出題範囲:

トピック出題範囲
トピック 1
  • ファイアウォールフィルターとACLの概念、操作、または機能を説明する
  • 悪意のある横方向のトラフィックの識別または軽減
トピック 2
  • 脅威軽減
  • 高度なネットワークアドレス変換の概念、操作、または機能を説明する
トピック 3
  • 選択的なパケット処理、フィルターベースの転送、ファイアウォールフィルターを使用したトラブルシューティング
  • 脅威の軽減を構成または監視する方法のデモンストレーション
トピック 4
  • ジュニパーATP
  • リモートアクセスVPN
  • IPsecを使用したルーティング
  • 動的ゲートウェイを構成または監視する方法を示します
トピック 5
  • レイヤー2のセキュリティ
  • マルウェアの識別または軽減を構成または監視する方法を示します
  • 論理システムの概念、操作、または機能を説明します
トピック 6
  • セキュリティポリシーまたはセキュリティゾーンのトラブルシューティングまたは監視方法のデモンストレーション
  • セキュリティコンプライアンスの概念または操作の説明
トピック 7
  • 高度なIPsec機能
  • 重複するIPアドレスを構成、トラブルシューティング、または監視する方法を示します
トピック 8
  • エッジセキュリティ機能の概念、操作、または機能を説明する
  • 高度なNATシナリオを構成、トラブルシューティング、または監視する方法を示す
トピック 9
  • 高度なNAT機能
  • 高度な脅威保護の概念、操作、または機能

 

質問 17
Which three type of peer devices are supported for Cos-Based IPsec VPN?

  • A. cSRX
  • B. High-end SRX Series device
  • C. vSRX
  • D. Branch-end SRX Series devics

正解: B,C,D

 

質問 18
Click the Exhibit button.

Referring to the exhibit, you are attempting to enable IPsec power mode to improve IPsec VPN performance.
However, you are unable to use IPsec power mode.
What is the problem?

  • A. IPsec power mode requires that you configure a policy-based VPN
  • B. IPsec power mode cannot be used with high IPsec maximum segment size values
  • C. IPsec power mode cannot be used with IPsec performance acceleration
  • D. IPsec power mode cannot be used with advanced services

正解: D

 

質問 19
Click the Exhibit button.

A host is unable to communicate with a webserver. Referring to the exhibit, which statement is correct?

  • A. The webserver is not listening for traffic on port 80
  • B. A session is created for this flow
  • C. The session table is running out of resources
  • D. A policy is denying the traffic between these two hosts

正解: D

 

質問 20
The monitor traffic interface command is being used to capture the packets destined to and the from the SRX Series device.
In this scenario, which two statements related to the feature are true? (Choose two.)

  • A. This feature is supported on high-end SRX Series devices only.
  • B. This feature captures ICMP traffic to and from the SRX Series device.
  • C. This feature does not capture transit traffic.
  • D. This feature is supported on both branch and high-end SRX Series devices.

正解: C,D

解説:
Reference:
https://forums.juniper.net/t5/Ethernet-Switching/monitor-traffic-interface/td-p/462528

 

質問 21
You have a remote access VPN where the remote users are using the NCP client. The remote users can access the internal corporate resources as intended; however, traffic that is destined to all other Internet sites is going through the remote access VPN. You want to ensure that only traffic that is destined to the internal corporate resources use the remote access VPN.
Which two actions should you take to accomplish this task? (Choose two.)

  • A. Enable IKEv2 within the VPN configuration on the SRX Series device
  • B. Configure split tunneling on the NCP profile on the remote client
  • C. Configure the necessary traffic selectors within the VPN configuration on the SRX Series device
  • D. Enable the split tunneling feature within the VPN configuration on the SRX Series device

正解: B,C

 

質問 22
Click the Exhibit button.

When attempting to enroll an SRX Series device to JATP, you receive the error shown in the exhibit. What is the cause of the error?

  • A. The SRX Series device certificate does not match the JATP certificate
  • B. The fxp0 IP address is not routable
  • C. The SRX Series device does not have an IP address assigned to the interface that accesses JATP
  • D. A firewall is blocking HTTPS on fxp0

正解: C

 

質問 23
Which three roles or protocols are required when configuring an ADVPN? (Choose three.)

  • A. shortcut partner
  • B. shortcut suggester
  • C. BGP
  • D. IKEv1
  • E. OSPF

正解: A,B,E

解説:
Explanation/Reference: https://www.juniper.net/documentation/en_US/junos/topics/topic-map/security-auto-discovery- vpns.html

 

質問 24
Click the Exhibit button.

Referring to the exhibit, which statement is true?

  • A. Source NAT without PAT is occurring
  • B. Source NAT with PAT is occurring
  • C. Static NAT without PAT is occurring
  • D. Destination NAT is occurring

正解: B

 

質問 25
Click the Exhibit button.

Referring to the exhibit, which two statements are true? (Choose two.)

  • A. The device cannot pass Layer 2 and Layer 3 traffic at the same time
  • B. The device can pass Layer 2 and Layer 3 traffic at the same time
  • C. You can secure intra-VLAN traffic with a security policy on this device
  • D. You can secure inter-VLAN traffic with a security policy on this device

正解: A,C

 

質問 26
You are asked to configure a new SRX Series CPE device at a remote office. The device must participate in forwarding MPLS and IPsec traffic.
Which two statements are true regarding this implementation? (Choose two.)

  • A. The SRX Series device can process both MPLS and IPsec with default traffic handling
  • B. A firewall filter must be configured to enable packet mode forwarding
  • C. Host inbound traffic must be processed by the flow module
  • D. Host inbound traffic must not be processed by the flow module

正解: B,C

 

質問 27
You configured a security policy permitting traffic from the trust zone to the DMZ zone, inserted the new policy at the top of the list, and successfully committed it to the SRX Series device. Upon monitoring, you notice that the hit count does not increase on the newly configured policy.
In this scenario, which two commands would help you to identify the problem? (Choose two.) user@srx> show security zones trust detail

  • A. 192.168.10.100/32
    destination-ip 10.10.10.80/32 protocol tcp source-port 5806 destination-port
    443 result-count 10
  • B. 192.168.10.100/32
    destination-ip 10.10.10.80/32 protocol tcp source-port 5806 destination-port
    443
    user@srx> show security match-policies from-zone trust to-zone DMZ source-ip
  • C. user@srx> show security shadow-policies from zone trust to zone DMZ
  • D. user@srx> show security match-policies from-zone trust to-zone DMZ source-ip

正解: A,D

解説:
Explanation/Reference: https://www.juniper.net/documentation/en_US/junos/topics/topic-map/monitoring- troubleshooting-security-policy.html

 

質問 28
You have the NAT rule, shown in the exhibit, applied to allow communication across an IPsec tunnel between your two sites with identical networks. Which statement is correct in this scenario?

  • A. The NAT rule will only translate two addresses at a time.
  • B. The NAT rule in applied to the N/A routing instance.
  • C. The NAT rule with translate the source and destination addresses.
  • D. 10 packets have been processed by the NAT rule.

正解: C

 

質問 29
Click the Exhibit button.

A user is trying to reach a company's website, but the connection errors out. The security policies are configured correctly.
Referring to the exhibit, what is the problem?

  • A. Persistent NAT must be enabled
  • B. The action for rule 1 must change to static-nat inet
  • C. DNS ALG must be disabled
  • D. Static NAT is missing a rule for DNS server

正解: D

解説:
Explanation

 

質問 30
Click the Exhibit button.

Branch 1 and Branch 2 have an active VPN tunnel configured, but internal hosts cannot communicate with each other.
Referring to the exhibit, which type of configuration should be applied to solve the problem?

  • A. Configure static NAT on both Branch 1 and Branch 2
  • B. Configure destination NAT on both Branch 1 and Branch 2
  • C. Configure destination NAT on Branch 2 only
  • D. Configure source NAT on Branch 1

正解: A

 

質問 31
Which two statements are true about ADVPN members? (Choose two.)

  • A. ADVPN members are authenticated using pre-shared keys
  • B. ADVPN members can use IKEv1
  • C. ADVPN members are authenticated using certificates
  • D. ADVPN members can use IKEv2

正解: C,D

解説:
Explanation/Reference: https://www.juniper.net/documentation/en_US/junos/topics/topic-map/security-auto-discovery- vpns.html

 

質問 32
Click the Exhibit button.

Which type of NAT is shown in the exhibit?

  • A. NAT46
  • B. persistent NAT
  • C. NAT64
  • D. DS-Lite

正解: C

 

質問 33
......

最新JN0-635合格保証 試験問題集でには正確で最新な 問題:https://www.goshiken.com/Juniper/JN0-635-mondaishu.html