Juniperは2022年最新のJN0-635テスト解説(更新されたのは90問があります) [Q46-Q65]

Share

Juniperは2022年最新のJN0-635テスト解説(更新されたのは90問があります)

JN0-635試験問題集を提供していますJuniper問題

質問 46
Click the Exhibit button.

Referring to the exhibit, which two statements are true? (Choose two.)

  • A. Events based on this third-party feed will not affect a host's threat score
  • B. Events based on this third-party feed will affect a host's threat score
  • C. SRX Series devices will not block traffic based on this third-party feed
  • D. SRX Series devices will block traffic based on this third-party feed

正解: A,D

 

質問 47
You have configured static NAT for a webserver in your DMZ. Both internal and external users can reach the webserver using the webserver's IP address. However, only internal users can reach the webserver using the webserver's DNS name. When external users attempt to reach the webserver using the webserver's DNS name, an error message is received.
Which action would solve this problem?

  • A. Use destination NAT instead of static NAT
  • B. Modify the security policy
  • C. Use DNS doctoring
  • D. Disable Web filtering

正解: C

 

質問 48
You have set up Security Director with Policy Enforcer and have configured 12 third-party feeds and a Sky ATP feed. You are also injecting 16 feeds using the available open API. You want to add another compatible feed using the available open API, but Policy Enforcer is not receiving the new feed.
What is the problem in this scenario?

  • A. You cannot add more than 16 feeds through the available open API
  • B. You cannot add more than 16 feeds with the available open API
  • C. You have reached the maximum limit of 29 total feeds
  • D. You must wait 48 hours for the feed to update

正解: C

 

質問 49
Which two VPN features are supported with CoS-based IPsec VPNs? (Choose two.)

  • A. VPN monitoring
  • B. dead peer detection
  • C. IKEv2
  • D. IKEv1

正解: B,C

解説:
Explanation/Reference: https://www.juniper.net/documentation/en_US/junos/topics/topic-map/secuirty-cos-based-ipsec- vpns.html

 

質問 50
Which three type of peer devices are supported for Cos-Based IPsec VPN?

  • A. cSRX
  • B. High-end SRX Series device
  • C. vSRX
  • D. Branch-end SRX Series devics

正解: B,C,D

 

質問 51
Click the Exhibit button.

You have two hosts on the same subnet connecting to an SRX340 on interfaces ge-0/0/4 and ge-0/0/5.
However, the two hosts cannot communicate with each other.
Referring to the exhibit, what are two actions that would solve this problem? (Choose two.)

  • A. Put the ge-0/0/4 and ge-0/0/5 interfaces in different VLANs
  • B. Remove the ge-0/0/4 and ge-0/0/5 interfaces from the L2 security zone
  • C. Add an IRB interface to the VLAN
  • D. Set the SRX340 to Ethernet switching mode and reboot

正解: B,D

 

質問 52
You are asked to configure a new SRX Series CPE device at a remote office. The device must participate in forwarding MPLS and IPsec traffic.
Which two statements are true regarding this implementation? (Choose two.)

  • A. The SRX Series device can process both MPLS and IPsec with default traffic handling
  • B. Host inbound traffic must not be processed by the flow module
  • C. A firewall filter must be configured to enable packet mode forwarding
  • D. Host inbound traffic must be processed by the flow module

正解: B,C

解説:
Explanation/Reference: https://www.juniper.net/documentation/en_US/junos/topics/topic-map/security-packet-based- forwarding.html

 

質問 53
Click the Exhibit button.

A host is unable to communicate with a webserver. Referring to the exhibit, which statement is correct?

  • A. The webserver is not listening for traffic on port 80
  • B. A session is created for this flow
  • C. The session table is running out of resources
  • D. A policy is denying the traffic between these two hosts

正解: D

 

質問 54
Exhibit.

Referring to the exhibit, which two statements are true? (Choose two.)

  • A. The configured solution allows IPv4 to IPv6 translation.
  • B. The configured solution allows IPv6 to IPv4 translation.
  • C. The IPv6 address is invalid.
  • D. External hosts cannot initiate contact.

正解: B,C

 

質問 55
Exhibit.

Referring to the exhibit, a spoke member of an ADVPN is not functioning correctly.
Which two commands will solve this problem? (Choose two.)

  • A. [edit security ike gateway advpn-gateway]
    user@srx# delete advpn partner
  • B. [edit security ike gateway advpn-gateway]
    user@srx# set advpn suggester disable
  • C. [edit security ike gateway advpn-gateway]
    user@srx# set version v1-only
  • D. [edit interfaces]
    user@srx# delete st0.0 multipoint

正解: A,B

解説:
Reference:
https://www.juniper.net/documentation/en_US/junos/topics/topic-map/security-auto-discovery-vpns.html

 

質問 56
Click the Exhibit button.

Given the command output shown in the exhibit, which two statements are true? (Choose two.)

  • A. Traffic matching this session has been received since the session was established
  • B. Network Address Translation is applied to this session
  • C. The host 10.10.101.10 is directly connected to interface ge-0/0/4.0
  • D. The host 172.31.15.1 is directly connected to interface ge-0/0/3.0

正解: A,C

 

質問 57
Click the Exhibit button.

Referring to the exhibit, which statement is true?

  • A. Source NAT without PAT is occurring
  • B. Source NAT with PAT is occurring
  • C. Static NAT without PAT is occurring
  • D. Destination NAT is occurring

正解: B

 

質問 58
Click the Exhibit button.

You have two hosts on the same subnet connecting to an SRX340 on interfaces ge-0/0/4 and ge-0/0/5.
However, the two hosts cannot communicate with each other.
Referring to the exhibit, what are two actions that would solve this problem? (Choose two.)

  • A. Put the ge-0/0/4 and ge-0/0/5 interfaces in different VLANs
  • B. Remove the ge-0/0/4 and ge-0/0/5 interfaces from the L2 security zone
  • C. Add an IRB interface to the VLAN
  • D. Set the SRX340 to Ethernet switching mode and reboot

正解: B,D

 

質問 59
Which two modes are supported on Juniper Sky ATP? (Choose two.)

  • A. global mode
  • B. secure wire mode
  • C. private mode
  • D. tap mode

正解: B,D

 

質問 60
You have noticed a high number of TCP-based attacks directed toward your primary edge device. You are asked to configure the IDP feature on your SRX Series device to block this attack.
Which two IDP attack objects would you configure to solve this problem? (Choose two.)

  • A. Signature
  • B. host
  • C. Network
  • D. Protocol anomaly

正解: A,D

 

質問 61
In which two ways are tenant systems different from logical systems? (Choose two.)

  • A. Tenant systems have more routing features than logical systems
  • B. Tenant systems have less scalability than logical systems
  • C. Tenant systems have higher scalability than logical systems
  • D. Tenant systems have fewer routing features than logical systems

正解: C,D

 

質問 62
You are asked to configure an SRX Series device to bypass all security features for IP traffic from the engineering department.
Which firewall filter will accomplish this task?

  • A.
  • B.
  • C.
  • D.

正解: C

 

質問 63
Click the Exhibit button.

You are asked to look at a configuration that is designed to take all traffic with a specific source IP address and forward the traffic to a traffic analysis server for further evaluation. The configuration is not working as intended.
Referring to the exhibit, which change must be made to correct the configuration?

  • A. Apply the filter as an output filter on interface xe-0/1/0.0
  • B. Apply the filter as an input filter on interface xe-0/2/1.0
  • C. Create a routing instance named default
  • D. Apply the filter as an input filter on interface xe-0/0/1.0

正解: D

 

質問 64
Click the Exhibit button.

Referring to the exhibit, which two statements are true? (Choose two.)

  • A. Events based on this third-party feed will not affect a host's threat score
  • B. Events based on this third-party feed will affect a host's threat score
  • C. SRX Series devices will not block traffic based on this third-party feed
  • D. SRX Series devices will block traffic based on this third-party feed

正解: A,D

 

質問 65
......


Juniper JN0-635 認定試験の出題範囲:

トピック出題範囲
トピック 1
  • Demonstrate how to configure or monitor Juniper ATP
  • Remote access VPNs
  • Routing with IPsec
  • Dynamic gateways
トピック 2
  • Describe the concepts, operation, or functionality of Juniper ATP
  • Demonstrate how to configure, troubleshoot, or monitor firewall filters
トピック 3
  • Describe the concepts, operation, or functionality of edge security features
  • demonstrate how to configure, troubleshoot, or monitor advanced NAT scenarios
トピック 4
  • Demonstrate how to configure, troubleshoot, or monitor advanced IPsec functionality
  • Overlapping IP addresses
トピック 5
  • Describe the concepts, operation, or functionality of firewall filters and ACLs
  • Malicious lateral traffic identification or mitigation
トピック 6
  • Demonstrate how to configure or monitor Layer 2 security
  • Malware identification or mitigation
  • Describe the concepts, operation, or functionality of the logical systems
トピック 7
  • Concepts, operation, or functionality of advanced NAT functionality
  • Advance Threat Protection

 

JN0-635認定ガイドPDFは100%カバー率でリアル試験問題:https://www.goshiken.com/Juniper/JN0-635-mondaishu.html