Weekend Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

Pass the Juniper JNCIP-SEC JN0-637 Questions and answers with ValidTests

Exam JN0-637 All Questions
Exam JN0-637 Premium Access

View all detail and faqs for the JN0-637 exam

Viewing page 1 out of 4 pages
Viewing questions 1-10 out of questions
Questions # 1:

Exhibit:

Question # 1

Host A shown in the exhibit is attempting to reach the Web1 webserver, but the connection is failing. Troubleshooting reveals that when Host A attempts to resolve the domain name of the server (web.acme.com), the request is resolved to the private address of the server rather than its public IP.

Which feature would you configure on the SRX Series device to solve this issue?

Options:

A.

Persistent NAT

B.

Double NAT

C.

DNS doctoring

D.

STUN protocol

Expert Solution
Questions # 2:

You are asked to set up advanced policy-based routing.

Which type of routing instance is designed to support this scenario?

Options:

A.

forwarding

B.

virtual switch

C.

virtual router

D.

non-forwarding

Expert Solution
Questions # 3:

Which two statements are true about the procedures the Junos security device uses when handling traffic destined for the device itself? (Choose two.)

Options:

A.

If the received packet is addressed to the ingress interface, then the device first performs a security policy evaluation for the junos-host zone.

B.

If the received packet is destined for an interface other than the ingress interface, then the device performs a security policy evaluation for the junos-host zone.

C.

If the received packet is addressed to the ingress interface, then the device first examines the host-inbound-traffic configuration for the ingress interface and zone.

D.

If the received packet is destined for an interface other than the ingress interface, then the device performs a security policy evaluation based on the ingress and egress zone.

Expert Solution
Questions # 4:

Exhibit:

Question # 4

Referring to the exhibit, which two statements are true? (Choose two.)

Options:

A.

Hosts in the Local zone can be enabled for control plane access to the SRX.

B.

An IRB interface is required to enable communication between the Trust and the Untrust zones.

C.

You can configure security policies for traffic flows between hosts in the Local zone.

D.

Hosts in the Local zone can communicate with hosts in the Trust zone with a security policy.

Expert Solution
Questions # 5:

What is the advantage of using separate st0 logical units for each spoke connection?

Options:

A.

It is easy to configure even when managing many st0 units.

B.

It facilitates scalability.

C.

Junos devices can exchange NHTB data automatically using this method.

D.

It enables assignments of different settings to each logical unit.

Expert Solution
Questions # 6:

You are asked to see if your persistent NAT binding table is exhausted.

Which show command would you use to accomplish this task?

Options:

A.

show security nat source persistent-nat-table summary

B.

show security nat source summary

C.

show security nat source pool all

D.

show security nat source persistent-nat-table all

Expert Solution
Questions # 7:

Referring to the exhibit,

Question # 7

which two statements are correct about the NAT configuration? (Choose two.)

Options:

A.

Both the internal and the external host can initiate a session after the initial translation.

B.

Only a specific host can initiate a session to the reflexive address after the initial session.

C.

Any external host will be able to initiate a session to the reflexive address.

D.

The original destination port is used for the source port for the session.

Expert Solution
Questions # 8:

Exhibit:

Question # 8

Which two statements are correct about the output shown in the exhibit. (Choose Two)

Options:

A.

The data shown requires a traceoptions flag of basic-datapath.

B.

The data shown requires a traceoptions flag of host-traffic.

C.

The packet is dropped by the default security policy.

D.

The packet is dropped by a configured security policy.

Expert Solution
Questions # 9:

The SRX series device is performing static NAT. you want to ensure that host A can reach the

internal webserver www.juniper.net using domain name.

Question # 9

Referring to the exhibit, which two Junos features are required to accomplish this task? (Choose two.)

Options:

A.

DNS doctoring

B.

proxy ARP

C.

persistent NAT

D.

STUN

Expert Solution
Questions # 10:

Exhibit:

Question # 10

Referring to the flow logs exhibit, which two statements are correct? (Choose two.)

Options:

A.

The packet is dropped by the default security policy.

B.

The packet is dropped by a configured security policy.

C.

The data shown requires a traceoptions flag of host-traffic.

D.

The data shown requires a traceoptions flag of basic-datapath.

Expert Solution
Viewing page 1 out of 4 pages
Viewing questions 1-10 out of questions