JN0-332 Exam Questions
472 real JN0-332 exam questions with expert-verified answers and explanations. Page 6 of 10.
- Question #284
Which statement accurately describes firewall user authentication?
- Question #285
Which two firewall user authentication objects can be referenced in a security policy? (Choose two.)
- Question #286
Which high availability feature is supported only on Junos security platforms?
- Question #287
What is a security policy?
- Question #288
What is a zone?
- Question #289
What is the function of NAT?
- Question #290
Which statement correctly describes the default state of a high-end SRX Series Services Gateway?
- Question #291
Which Junos security feature helps protect against spam, viruses, trojans, and malware?
- Question #292
When the first packet in a new flow is received, which high-end SRX component is responsible for setting up the flow?
- Question #293
Which three elements are contained in a session-close log message? (Choose three.)
- Question #294
Which card performs flow lookup on incoming packets on high-end SRX Series devices?
- Question #295
How is the control plane separated from the data plane on branch SRX Series devices?
- Question #296
Which three parameters does the Junos OS attempt to match against during session lookup? (Choose three.)
- Question #297
You have packet loss on an IPsec VPN using the default maximum transmission unit (MTU) where the packets have the DF-bit (do not fragment) set. Which configuration solves this prob...
- Question #298
The branch SRX Series Services Gateways implement the data plane on which two components? (Choose two.)
- Question #299
Which configuration must be completed to use both packet-based and session-based forwarding on a branch SRX Series Services Gateway?
- Question #300
Which branch SRX Series Services Gateway model has a hardware-based, modular Routing Engine?
- Question #301
Which two statements are true about zones? (Choose two.)
- Question #302
Which statement is true about factory-default zones?
- Question #303
Which two statements are true when configuring security zones? (Choose two.)
- Question #304
What are two system-defined zones? (Choose two.)
- Question #305
Which statement is correct about zone and interface dependencies?
- Question #306
What are two functions of the junos-host zone? (Choose two.)
- Question #307
Which two parameters are configurable under the [edit security zones security-zone zoneA] stanza? (Choose two.)
- Question #308
What are two predefined address-book entries? (Choose two.)
- Question #309
What are two valid network prefixes in address books? (Choose two.)
- Question #310
You want to show interface-specific zone information and statistics. Which operational command would be used to accomplish this?
- Question #311
Which two statements are correct regarding the security policy parameter policy-rematch? (Choose two.)
- Question #312
An engineer has just created a single policy allowing ping traffic from a host in the Users zone to a server in the Servers zone. When the host pings the server, what will happen t...
- Question #313
Following a recent security audit, you find that users are able to ping between the untrust zone and the trust zone, which is contrary to your organization's current security polic...
- Question #314
You must create a security policy for a custom application that requires a longer session timeout than the default application offers. Which two actions are valid? (Choose two.)
- Question #315
You need to build a scheduler to apply to a policy that will allow traffic from Monday to Friday only. What will accomplish this task?
- Question #316
You want to silently drop HTTP traffic. Which action will accomplish this task?
- Question #317
You are asked to change the behavior of the system-default policy from the default setting on an SRX Series device. What would be the result of this change?
- Question #318
You have just added the policy deny-host-a to prevent traffic from Host A that was previously allowed by the policy permit-all. After committing the changes, you notice that all tr...
- Question #319
You are troubleshooting a security policy. The operational command show security flow session does not show any sessions for this policy. Which statement is correct?
- Question #320
You want to enable local logging for security policies and have the log information stored in a separate file on a branch SRX Series device. Which configuration will accomplish thi...
- Question #321
You want to authenticate users accessing an internal FTP server using the SRX Series Services Gateway. You also want to use an internal LDAP server as the authentication server. Wh...
- Question #322
Which two settings in the options field of an IP header will Junos Screen options block? (Choose two.)
- Question #323
Which two statements are true about the SYN cookie Junos Screen option? (Choose two.)
- Question #324
Which three actions should be used when initially implementing Junos Screen options? (Choose three.)
- Question #325
At which step in the packet flow are Junos Screen checks applied?
- Question #326
You need to apply the Junos Screen protect-zone to the public zone. Which configuration meets this requirement?
- Question #327
You need to implement Junos Screen options to protect traffic coming through the ge-0/0/0 and ge-0/0/1 interfaces which are located in the trust and DMZ zones, respectively. Where...
- Question #328
While reviewing the logs on your SRX240 device, you notice SYN floods coming from multiple hosts out on the Internet. Which Junos Screen option would protect against these denial-o...
- Question #329
You want to protect against attacks on interfaces in ZoneA. You create a Junos Screen option called no-flood and commit the configuration. In the weeks that follow, the Screen does...
- Question #330
While reviewing the logs on your SRX240 device, you notice SYN floods coming from a host out on the Internet towards several hosts on your trusted network. Which Junos Screen optio...
- Question #331
During packet flow on an SRX Series device, which two processes occur before route lookup? (Choose two.)
- Question #332
Which Junos NAT implementation requires the use of proxy ARP?
- Question #333
You are configuring source NAT. Which three elements are used for matching the traffic direction in the from and to statements? (Choose three.)