Pre-Summer Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: validbest

Pass the Juniper JNCIS-SEC JN0-335 Questions and answers with ValidTests

Exam JN0-335 All Questions
Exam JN0-335 Premium Access

View all detail and faqs for the JN0-335 exam

Viewing page 3 out of 3 pages
Viewing questions 21-30 out of questions
Questions # 21:

Which sequence does an SRX Series device use when implementing stateful session security policies using Layer 3 routes?

Options:

A.

An SRX Series device will perform a security policy search before conducting a longest-match Layer 3 route table lookup.

B.

An SRX Series device performs a security policy search before implementing an ALG security check on the longest-match Layer 3 route.

C.

An SRX Series device will conduct a longest-match Layer 3 route table lookup before performing a security policy search.

D.

An SRX Series device conducts an ALG security check on the longest-match route before performing a security policy search.

Expert Solution
Questions # 22:

Which two statements are correct about security policy changes when using the policy rematch feature? (Choose two.)

Options:

A.

When a policy change includes changing the policy's action from permit to deny, all existing sessions are maintained

B.

When a policy change includes changing the policy's source or destination address match condition, all existing sessions are dropped.

C.

When a policy change includes changing the policy's action from permit to deny, all existing sessions are dropped.

D.

When a policy change includes changing the policy's source or destination address match condition, all existing sessions are reevaluated.

Expert Solution
Questions # 23:

Which three statements about SRX Series device chassis clusters are true? (Choose three.)

Options:

A.

Chassis cluster control links must be configured using RFC 1918 IP addresses.

B.

Chassis cluster member devices synchronize configuration using the control link.

C.

A control link failure causes the secondary cluster node to be disabled.

D.

Recovery from a control link failure requires that the secondary member device be rebooted.

E.

Heartbeat messages verify that the chassis cluster control link is working.

Expert Solution
Questions # 24:

Which two statements are correct about the cSRX? (Choose two.)

Options:

A.

The cSRX supports firewall, NAT, IPS, and UTM services.

B.

The cSRX only supports Layer 2 "bump-in-the-wire" deployments.

C.

The cSRX supports BGP, OSPF. and IS-IS routing services.

D.

The cSRX has three default zones: trust, untrust, and management

Expert Solution
Questions # 25:

Which two statements are correct about chassis clustering? (Choose two.)

Options:

A.

The node ID value ranges from 1 to 255.

B.

The node ID is used to identify each device in the chassis cluster.

C.

A system reboot is required to activate changes to the cluster.

D.

The cluster ID is used to identify each device in the chassis cluster.

Expert Solution
Questions # 26:

You are preparing a proposal for a new customer who has submitted the following requirements for a vSRX deployment:

-- globally distributed,

-- rapid provisioning,

-- scale based on demand,

-- and low CapEx.

Which solution satisfies these requirements?

Options:

A.

AWS

B.

Network Director

C.

Juniper ATP Cloud

D.

VMWare ESXi

Expert Solution
Questions # 27:

Regarding static attack object groups, which two statements are true? (Choose two.)

Options:

A.

Matching attack objects are automatically added to a custom group.

B.

Group membership automatically changes when Juniper updates the IPS signature database.

C.

Group membership does not automatically change when Juniper updates the IPS signature database.

D.

You must manually add matching attack objects to a custom group.

Expert Solution
Questions # 28:

Which statement about security policy schedulers is correct?

Options:

A.

Multiple policies can use the same scheduler.

B.

A policy can have multiple schedulers.

C.

When the scheduler is disabled, the policy will still be available.

D.

A policy without a defined scheduler will not become active

Expert Solution
Viewing page 3 out of 3 pages
Viewing questions 21-30 out of questions