JN0-332 Exam Questions
472 real JN0-332 exam questions with expert-verified answers and explanations. Page 5 of 10.
- Question #229
Which zone is a system-defined zone?
- Question #230
Which type of zone is used by traffic transiting the device?
- Question #231
Which two steps are performed when configuring a zone? (Choose two.)
- Question #232
You want to allow all hosts on interface ge-0/0/0.0 to be able to ping the device's ge- 0/0/0.0 IP address. Where do you configure this functionality?
- Question #236
Based on the exhibit, client PC 192.168.10.10 cannot ping 1.1.1.2. Which is a potential cause for this problem?
- Question #237
Click the Exhibit button. [edit security zones security-zone HR] user@host# show host-inbound-traffic { system-services { ping; ssh; https; }} interfaces { ge-0/0/0.0; ge-0/0/1.0 {...
- Question #238
Click the Exhibit button. user@host> show interfaces ge-0/0/0.0 | match host-inbound Allowed host-inbound traffic : bgp ospf Which configuration would result in the output shown in...
- Question #239
Click the Exhibit button. user@host> show interfaces ge-0/0/0.0 | match host-inbound Allowed host-inbound traffic : ping ssh telnet Which configuration would result in the output s...
- Question #240
Click the Exhibit button. [edit security] user@host# show zones { security-zone ZoneA { tcp-rst; host-inbound-traffic { system-services { ping; telnet; }} interfaces { ge-0/0/0.0;...
- Question #241
Which two commands can be used to monitor firewall user authentication? (Choose two.)
- Question #243
Which two external authentication server types are supported by JUNOS Software for firewall user authentication? (Choose two.)
- Question #244
Click the Exhibit button. [edit security zones security-zone trust] user@host# show host-inbound-traffic { system-services { all; }} interfaces { ge-0/0/0.0; } Referring to the exh...
- Question #245
What are three main phases of an attack? (Choose three.)
- Question #246
An attacker sends a low rate of TCP SYN segments to hosts, hoping that at least one port replies. Which type of an attack does this scenario describe?
- Question #247
Where do you configure SCREEN options?
- Question #248
Prior to applying SCREEN options to drop traffic, you want to determine how your configuration will affect traffic. Which mechanism would you configure to achieve this objective?
- Question #250
Which two statements describe the purpose of a security policy? (Choose two.)
- Question #251
Click the Exhibit button. [edit security policies] user@host# show from-zone trust to-zone untrust { policy AllowHTTP{ match { source-address HOSTA; destination-address any; applic...
- Question #252
Which two security policy actions are valid? (Choose two.)
- Question #253
Click the Exhibit button. [edit schedulers] user@host# show scheduler now { monday all-day; tuesday exclude; wednesday { start-time 07:00:00 stop-time 18:00:00; } thursday { start-...
- Question #254
Click the Exhibit button. [edit security policies from-zone HR to-zone trust] user@host# show policy two { match { source-address subnet_a; destination-address host_b; application...
- Question #255
Which statement is true about interface-based source NAT?
- Question #256
Which two statements are true about pool-based destination NAT? (Choose two.)
- Question #257
Which statement is true about source NAT?
- Question #258
Which two statements are true about overflow pools? (Choose two.)
- Question #259
Which statement is true regarding proxy ARP?
- Question #260
You are creating a destination NAT rule-set. Which two are valid for use with the from clause? (Choose two.)
- Question #261
Regarding an IPsec security association (SA), which two statements are true? (Choose two.)
- Question #262
Which operational mode command displays all active IPsec phase 2 security associations?
- Question #263
Two VPN peers are negotiating IKE phase 1 using main mode. Which message pair in the negotiation contains the phase 1 proposal for the peers?
- Question #264
Which attribute is required for all IKE phase 2 negotiations?
- Question #265
Which attribute is optional for IKE phase 2 negotiations?
- Question #266
A route-based VPN is required for which scenario?
- Question #267
A policy-based IPsec VPN is ideal for which scenario?
- Question #268
Regarding a route-based versus policy-based IPsec VPN, which statement is true?
- Question #269
Which two configuration elements are required for a route-based VPN? (Choose two.)
- Question #270
Click the Exhibit button. [edit security] user@host# show ike { policy ike-policy1 { mode main; proposal-set standard; pre-shared-key ascii-text "$9$GFjm5OBEclM5QCuO1yrYgo"; ## SEC...
- Question #271
Regarding secure tunnel (st) interfaces, which statement is true?
- Question #272
What are three benefits of using chassis clustering? (Choose three.)
- Question #273
You have been tasked with installing two SRX 5600 platforms in a high-availability cluster. Which requirement must be met for a successful installation?
- Question #274
Click the Exhibit button. [edit chassis] user@host# show cluster { reth-count 3; redundancy-group 1 { node 0 priority 1; node 1 priority 100; }} When applying the configuration in...
- Question #275
What is a redundancy group in JUNOS Software?
- Question #276
When devices are in cluster mode, which new interfaces are created?
- Question #277
What are two interfaces created when enabling a chassis cluster? (Choose two.)
- Question #278
Which statement is true regarding redundancy groups?
- Question #279
Which IDP policy action drops a packet before it can reach its destination, but does not close the connection?
- Question #280
You have been tasked with performing an update to the IDP attack database. Which three requirements are included as part of this task? (Choose three.)
- Question #281
You are implementing an IDP policy template from Juniper Networks. Which three steps are included in this process? (Choose three.)
- Question #282
Which statement regarding the implementation of an IDP policy template is true?
- Question #283
Which two statements are true regarding firewall user authentication? (Choose two.)