Pre-Summer Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: validbest

Pass the Juniper JNCIP-SEC JN0-637 Questions and answers with ValidTests

Exam JN0-637 All Questions
Exam JN0-637 Premium Access

View all detail and faqs for the JN0-637 exam

Viewing page 3 out of 4 pages
Viewing questions 21-30 out of questions
Questions # 21:

Which two statements are correct about DNS doctoring?

Options:

A.

The DNS ALG must be disabled.

B.

Proxy ARP is required if your NAT pool for the server is on the same subnet as the uplink interface.

C.

Proxy ARP is required if your NAT pool for the server is on a different subnet as the uplink interface

D.

The DNS ALG must be enabled.

Expert Solution
Questions # 22:

What are three requirements to run OSPF over GRE over IPsec? (Choose Three)

Options:

A.

The GRE interface must be configured in OSPF Area 0.

B.

The OSPF interface must be placed in a zone and must have GRE configured

C.

Overlapping addresses should exist between remote networks.

D.

The GRE interface must be placed in a zone and must have OSPF configured in is host

E.

Overlapping addresses should not exist between remote networks.

Expert Solution
Questions # 23:

You have deployed an SRX Series device at your network edge to secure Internet-bound sessions for your local hosts using source NAT. You want to ensure that your users are able to interact with applications on the Internet that require more than one TCP session for the same application session.

Which two features would satisfy this requirement? (Choose two.)

Options:

A.

address persistence

B.

STUN

C.

persistent NAT

D.

double NAT

Expert Solution
Questions # 24:

Exhibit:

Question # 24

Referring to the exhibit, which two statements are correct? (Choose two.)

Options:

A.

You cannot secure intra-VLAN traffic with a security policy on this device.

B.

You can secure inter-VLAN traffic with a security policy on this device.

C.

The device can pass Layer 2 and Layer 3 traffic at the same time.

D.

The device cannot pass Layer 2 and Layer 3 traffic at the same time.

Expert Solution
Questions # 25:

Exhibit:

Question # 25

You have configured a CoS-based VPN that is not functioning correctly.

Referring to the exhibit, which action will solve the problem?

Options:

A.

You must delete one forwarding class.

B.

You must change the loss priorities of the forwarding classes to low.

C.

You must use inet precedence instead of DSCP.

D.

You must change the code point for the DB-data forwarding class to 10000.

Expert Solution
Questions # 26:

Which two statements are correct about automated threat mitigation with Security Director? (Choose two.)

Options:

A.

It works with third-party switches.

B.

It provides endpoint protection by running a Juniper ATP Cloud agent on the servers.

C.

It provides endpoint protection by running a Juniper ATP Cloud agent on EX Series devices.

D.

It works with SRX Series devices.

Expert Solution
Questions # 27:

You want to create a connection for communication between tenant systems without using physical revenue ports on the SRX Series device.

What are two ways to accomplish this task? (Choose two.)

Options:

A.

Use an external router.

B.

Use an interconnect VPLS switch.

C.

Use a secure wire.

D.

Use a point-to-point logical tunnel.

Expert Solution
Questions # 28:

A user reports that a specific application is not working properly. This application makes

multiple connection to the server and must have the same address every time from a pool and this behavior needs to be changed.

What would solve this problem?

Options:

A.

Use STUN.

B.

Use DNS doctoring.

C.

Use the address-persistent parameter.

D.

Use the persistent-nat parameter.

Expert Solution
Questions # 29:

Which two statements are true regarding NAT64? (Choose two.)

Options:

A.

An SRX Series device should be in packet-based forwarding mode for IPv4.

B.

An SRX Series device should be in packet-based forwarding mode for IPv6.

C.

An SRX Series device should be in flow-based forwarding mode for IPv4.

D.

An SRX Series device should be in flow-based forwarding mode for IPv6.

Expert Solution
Questions # 30:

Which two statements are true when setting up an SRX Series device to operate in mixed mode? (Choose two.)

Options:

A.

A physical interface can be configured to be both a Layer 2 and a Layer 3 interface at the same time.

B.

User logical systems support Layer 2 traffic processing.

C.

The SRX must be rebooted after configuring at least one Layer 3 and one Layer 2 interface.

D.

Packets from Layer 2 interfaces are switched within the same bridge domain.

Expert Solution
Viewing page 3 out of 4 pages
Viewing questions 21-30 out of questions