JN0-314 Exam Questions
231 real JN0-314 exam questions with expert-verified answers and explanations. Page 2 of 5.
- Question #51
Using an LDAP authentication server, what do you configure to validate certificate attributes?
- Question #52
In the Junos Pulse Access Control Service, which three actions are only available in the admin GUI? (Choose three.)
- Question #53
What are two steps to configure user authentication for a Junos Pulse Access Control Service? (Choose two.)
- Question #54
Which parameter do you use to enable Junos Pulse Access Control Service enforcement on a policy on a ScreenOS platform?
- Question #55
You notice that during peak hours, some firewall enforcers contain a high number of auth table entries. As you investigate the issue, you discover that all users are getting auth t...
- Question #56
You are configuring an SRX210 as a firewall enforcer that will tunnel IPsec traffic from several Junos Pulse users. Which two parameters must you configure on the SRX210? (Choose t...
- Question #57
Which Junos Pulse feature allows the user to log in once through a Junos Pulse Secure Access Service on the network and then access resources protected by a Junos Pulse Access Cont...
- Question #58
When the Host Enforcer option is enabled, all traffic is denied by default except for which two? (Choose two.)
- Question #59
You have created a Host Enforcer policy and want to verify that it has been applied. In which two places would you look to determine if the policy is being enforced? (Choose two.)
- Question #60
An authentication realm consists of which three authentication resources? (Choose three.)
- Question #61
Your security policy requires that users authenticating to the Junos Pulse Access Control Service are connecting from a domain member endpoint on the internal corporate network. Wh...
- Question #62
A customer wants to create a custom Junos Pulse configuration. Which two are required? (Choose two)
- Question #63
What is a type of firewall enforcer supported by the Junos Pulse Access Control Service?
- Question #64
A customer is trying to decide which 802.1X inner protocol to use on their network. The customer requires that no passwords be sent across the network in plain text, that the proto...
- Question #65
You navigate to "UAC" > "Infranet Enforcer" > "Auth Table Mapping" in the admin GUI. You see one policy, which is the unmodified, original default policy. Which statement is true?
- Question #66
You have a Junos Pulse Secure Access Service acting as an IF-MAP client, configured to federate all user roles to a Junos Pulse Access Control Service acting as an IF-MAP Federatio...
- Question #67
You are configuring an active/passive cluster of SRX Series devices as the firewall enforcer on a MAG Series device. Which statement is true?
- Question #68
A customer has purchased a third-party switch to use for Layer 2 access with their Junos Pulse Access Control Service. When configuring the switch on the Junos Pulse Access Control...
- Question #69
Which three settings are accessible from the serial console menu on a MAG Series device? (Choose three.)
- Question #70
What is the function of Host Checker?
- Question #71
Click the Exhibit button. What is the cause of the error shown in the exhibit?
- Question #72
You have a firewall enforcer protecting resources in a data center. A user is experiencing difficulty connecting to a protected resource. Which two elements must exist so the user...
- Question #73
Which three statements are true about Host Checker? (Choose three.)
- Question #74
What happens when Host Checker is configured to perform checks every "0" minutes?
- Question #75
What are two ways to access the Junos Pulse Access Control Service? (Choose two.)
- Question #76
You are configuring an IPsec routing policy that will be used with a ScreenOS firewall enforcer. What must you also configure?
- Question #77
A customer is deploying a new Junos Pulse Access Control Service and has completed the initial boot configuration as prompted using a serial connection. The customer now wants to c...
- Question #78
A user is successfully authenticating to the network but is unable to access protected resources behind a ScreenOS enforcer. You log in to the ScreenOS enforcer and issue the comma...
- Question #79
A user signs into the Junos Pulse Access Control Service on a wired network. The user then migrates to a wireless network, receives a new IP address, and notices that the session i...
- Question #80
What are two valid configurations for user-driven remediation when a Windows-based endpoint fails a Host Checker policy? (Choose two.)
- Question #81
Click the Exhibit button. A customer configures the Junos Pulse Access Control Service with a Contractor role, an Employee role, and a Remediation role. A user logs in and is assig...
- Question #82
You are receiving reports of possible unauthorized access to resources protected by a firewall enforcer running the Junos OS. You want to verity which users are currently accessing...
- Question #83
You are setting up a Junos Pulse Access Control Service. You cannot obtain a device certificate from an external certificate authority. Which tool should you use to generate a devi...
- Question #84
You have configured the Odyssey Access Client with a profile which has the "Disable Server Verification" setting cleared. What will be the result if the device certificate on the M...
- Question #85
In a Junos Pulse Access Control Service active/active clustered environment, which statement is true about VIPs?
- Question #86
Which three types of policies must you configure to allow remote users transparent access to protected resources using IF-MAP Federation between a Junos Pulse Secure Access Service...
- Question #87
What are two features provided by the Junos Pulse client? (Choose two.)
- Question #88
You have a MAG Series device with IP address 10.0.1.5 and hostname ad .pulse.local acting as an IF-MAP Federation server. The subject name of the device certificate on this server...
- Question #89
You are installing a new deployment of the Junos Pulse Access Control Service. You have an existing RADIUS server that has a populated user file. You are considering using the RADI...
- Question #90
You have multiple realms configured on a MAG Series device. A user is authenticating with a non- Junos Pulse Access Control Service client. The username does not contain a realm su...
- Question #91
A customer is trying to determine which client to deploy. The customer wants to be able to perform Layer 2 authentication as well as connect to the Junos Pulse Secure Access Servic...
- Question #92
A customer has purchased a new Junos Pulse Access Control Service and wants to install it in an existing cluster. After initial configuration, the customer finds that the firmware...
- Question #93
What information does the Junos Pulse Access Control Service provide to Security Threat Response Manager (STRM)? (Choose two.)
- Question #94
Without calling JTAC, which two troubleshooting tools on a MAG Series device would you use to identify the cause of an authentication failure?
- Question #95
Two MAG4610s are running in an active/passive cluster configuration. The system administrator is planning to apply a service package to the cluster. Which process should the admini...
- Question #96
When configuring resource access policies in a Junos Pulse Access Control Service device, which entry is permitted when defining the specific resources?
- Question #97
You are customizing the user interface options for the finance department in your organization. Users in the department are able to see a session counter on the Web interface of th...
- Question #98
You are an administrator of an active/passive cluster of MAG Series devices running in mixed- mode configuration (IF-MAP server and authenticating users). The active user count is...
- Question #99
Which protocol is used for communication between the Junos Pulse client and 802.1X-compliant switches when performing Layer 2 enforcement?
- Question #100
You have configured Junos Pulse on your Windows desktop and want to verify that the IPsec configuration policy is being pushed down to your workstation upon network authentication...