JN0-332 Exam Questions
472 real JN0-332 exam questions with expert-verified answers and explanations. Page 1 of 10.
- Question #1
Which configuration keyword ensures that all in-progress sessions are re-evaluated upon committing a security policy change?
- Question #2
Click the Exhibit button. You need to alter the security policy shown in the exhibit to send matching traffic to an IPsec VPN tunnel. Which command causes traffic to be sent throug...
- Question #3
Which three security concerns can be addressed by a tunnel mode IPsec VPN secured by AH? (Choose three.)
- Question #4
You must configure a SCREEN option that would protect your router from a session table flood.Which configuration meets this requirement?
- Question #5
Which type of Web filtering by default builds a cache of server actions associated with each URL it has checked?
- Question #6
Which security or functional zone name has special significance to the Junos OS?
- Question #7
Which command do you use to display the status of an antivirus database update?
- Question #8
Which statement contains the correct parameters for a route-based IPsec VPN?
- Question #9
Which zone is system-defined?
- Question #10
You want to allow your device to establish OSPF adjacencies with a neighboring device connected to interface ge-0/0/3.0. Interface ge-0/0/3.0 is a member of the HR zone. Under whic...
- Question #11
Click the Exhibit button. Your IKE SAs are up, but the IPsec SAs are not up.Referring to the exhibit, what is the problem?
- Question #12
Which three statements are true regarding IDP? (Choose three.)
- Question #13
Which two statements regarding symmetric key encryption are true? (Choose two.)
- Question #14
Regarding content filtering, what are two pattern lists that can be configured in the Junos OS? (Choose two.)
- Question #15
Which two statements are true about hierarchical architecture? (Choose two.)
- Question #16
Which two statements regarding external authentication servers for firewall user authentication are true? (Choose two.)
- Question #17
Click the Exhibit button. In the exhibit, a new policy named DenyTelnet was created. You notice that Telnet traffic is still allowed. Which statement will allow you to rearrange th...
- Question #18
Which UTM feature requires a license to function?
- Question #19
Click the Exhibit button. System services SSH, Telnet, FTP, and HTTP are enabled on the SRX Series device. Referring to the configuration shown in the exhibit, which two statements...
- Question #20
A user wants to establish an HTTP session to a server behind an SRX device but is being pointed to Web page on the SRX device for additional authentication. Which type of user auth...
- Question #21
Which two UTM features require a license to be activated? (Choose two.)
- Question #22
Which two statements in a source NAT configuration are true regarding addresses, rule-sets, or rules that overlap? (Choose two.)
- Question #23
A network administrator has configured source NAT, translating to an address that is on a locally connected subnet. The administrator sees the translation working, but traffic does...
- Question #24
Which statement describes an ALG?
- Question #25
Which three components can be leveraged when defining a local whitelist or blacklist for antispam on a branch SRX Series device? (Choose three.)
- Question #26
What is the correct syntax for applying node-specific parameters to each node in a chassis cluster?
- Question #27
Which statement describes a security zone?
- Question #28
A system administrator detects thousands of open idle connections from the same source.Which problem can arise from this type of attack?
- Question #29
Under which Junos hierarchy level are security policies configured?
- Question #30
You must configure a SCREEN option that would protect your device from a session table flood. Which configuration meets this requirement?
- Question #31
Which three methods of source NAT does the Junos OS support? (Choose three.)
- Question #32
Which three firewall user authentication objects can be referenced in a security policy? (Choose three.)
- Question #33
What is the default session timeout for TCP sessions?
- Question #34
Which three advanced permit actions within security policies are valid? (Choose three.)
- Question #35
Which statement is true regarding the Junos OS for security platforms?
- Question #36
Click the Exhibit button. Which type of NAT is being used in the exhibit?
- Question #37
At which two levels of the Junos CLI hierarchy is the host-inbound-traffic command configured? (Choose two.)
- Question #38
Which two parameters are configured in IPsec policy? (Choose two.)
- Question #39
The SRX device receives a packet and determines that it does not match an existing session.After SCREEN options are evaluated, what is evaluated next?
- Question #40
Which zone type can be specified in a policy?
- Question #41
Which two statements about Junos software packet handling are correct? (Choose two.)
- Question #42
Which Web-filtering technology can be used at the same time as integrated Web filtering on a single branch SRX Series device?
- Question #43
In a chassis cluster with two SRX 5800 devices, the interface ge-13/0/0 belongs to which device?
- Question #44
An IPsec tunnel is established on an SRX Series Gateway on an interface whose IP address was obtained using DHCP. Which two statements are true? (Choose two.)
- Question #45
Which two statements about the use of SCREEN options are correct? (Choose two.)
- Question #46
Click the Exhibit button. In the exhibit, you decided to change my Hosts addresses. What will happen to the new sessions matching the policy and in-progress sessions that had alrea...
- Question #47
When using UTM features in an HA cluster, which statement is true for installing the licenses on the cluster members?
- Question #48
Which statement is true regarding NAT?
- Question #49
Which two functions of the Junos OS are handled by the data plane? (Choose two.)
- Question #50
After applying the policy-rematch statement under the security policies stanza, what would happen to an existing flow if the policy source address or the destination address is cha...