JN0-332 Exam Questions
472 real JN0-332 exam questions with expert-verified answers and explanations. Page 7 of 10.
- Question #334
You have just configured source NAT with a pool of addresses within the same subnet as the egress interface. What else must be configured to make the addresses in the pool usable?
- Question #335
You have just changed a NAT rule and committed the change. Which statement is true?
- Question #336
Which configuration allows direct access to the 10.10.10.0/24 network without NAT, but uses NAT for all other traffic from the untrust zone to the egress interface?
- Question #337
Which two actions occur during IKE Phase 1? (Choose two.)
- Question #338
What are two valid symmetric encryption key types? (Choose two.)
- Question #339
Which two are negotiated during Phase 2 of an IPsec VPN tunnel establishment? (Choose two.)
- Question #340
Which three algorithms are used by an SRX Series device to validate the integrity of the data exchanged through an IPsec VPN? (Choose three.)
- Question #341
You are asked to implement the hashing algorithm that uses the most bits in the calculation on your Junos security device. Which algorithm should you use?
- Question #342
You are asked to establish an IPsec VPN to a remote device whose IP address is dynamically assigned by the ISP. Which IKE Phase 1 mode must you use?
- Question #343
Which three Diffie-Hellman groups are supported during IKE Phase 1 by the Junos OS? (Choose three.)
- Question #344
A security association is uniquely identified by which two values? (Choose two.)
- Question #345
You are asked to establish an IPsec VPN between two sites. The remote device has been preconfigured. Which two parameters must be identical to the remote device's parameters when d...
- Question #346
Which two statements are correct about IPsec security associations? (Choose two.)
- Question #347
You are deploying a branch site which connects to two hub locations over an IPsec VPN. The branch SRX Series device should send all traffic to the first hub unless it is unreachabl...
- Question #348
Which two statements are correct regarding reth interfaces? (Choose two.)
- Question #349
Which two statements are correct about establishing a chassis cluster with IPv6? (Choose two.)
- Question #350
You are asked to set up a chassis cluster between your SRX Series devices. You must ensure that the solution provides both dual redundant links per node and node redundancy. Which...
- Question #351
What is supported on the fabric link?
- Question #352
You are asked to establish a chassis cluster between two SRX Series devices. You must ensure that end-to-end connectivity is monitored and that the redundancy group will fail over...
- Question #353
When using chassis clustering, which link is responsible for configuration synchronization?
- Question #354
Redundant Ethernet interfaces (reths) have a virtual MAC address based on which two attributes? (Choose two.)
- Question #355
You are asked to establish a chassis cluster between two branch SRX Series devices. You must ensure that no single point of failure exists. What would prevent a single point of fai...
- Question #356
Which two statements are correct regarding the cluster ID? (Choose two.)
- Question #357
Which statement is true about real-time objects in an SRX chassis cluster?
- Question #358
When using chassis clustering, which action is taken by the Junos OS if the control link or the fabric link suffers a loss of keepalives or heartbeat messages?
- Question #359
You are configuring the SRX Series Services Gateway in chassis cluster mode. What is a valid way to configure Redundancy Groups (RGs) 1 and 2 for active/active redundancy?
- Question #360
You have just manually failed over Redundancy Group 0 on Node 0 to Node 1. You notice Node 0 is now in a secondary-hold state. Which statement is correct?
- Question #361
Which three Unified Threat Management features require a license? (Choose three.)
- Question #362
Which global UTM configuration parameter contains lists, such as MIME patterns, filename extensions, and URL patterns, that can be used across all UTM features?
- Question #363
Your SRX Series device is configured so that all inbound traffic from the Internet is examined by the UTM content filtering feature. As inbound traffic arrives at the SRX device, w...
- Question #364
Which three UTM features require a license? (Choose three.)
- Question #365
Which two SRX platforms support UTM features? (Choose two.)
- Question #366
Which antivirus protection feature uses the first several packets of a file to determine if the file contains malicious code?
- Question #367
Which antivirus protection feature uses virus patterns and a malware database that are located on external servers?
- Question #368
You have implemented Integrated SurfControl Web filtering on an SRX Series device. You have also created a whitelist and a blacklist on the SRX device. One particular Web site is m...
- Question #369
You have deployed enhanced Web filtering on an SRX Series device. A user requests a URL that is not in the URL filtering cache. What happens?
- Question #370
You are configuring a blacklist for Web filtering on a branch SRX Series device. Which two URL patterns are valid? (Choose two.)
- Question #371
Which two criteria does the enhanced Web filtering solution use to make decisions? (Choose two.)
- Question #372
Referring to the exhibit, you need to allow ping traffic into interface ge-0/0/1. Which configuration step will accomplish this task? [edit interfaces] ge-0/0/1 { unit 0 { family e...
- Question #373
Referring to the exhibit, which two services are allowed on the ge-0/0/2.0 interface? (Choose two.)
- Question #374
Referring to the exhibit, you want to be able to manage your SRX Series device from the Internet using SSH. You have created a security policy to allow the traffic to flow into the...
- Question #375
Referring to the exhibit, you have configured a scheduler to allow hosts access to the Internet during specific times. You notice that hosts are still accessing the Internet during...
- Question #376
Referring to the exhibit, you have configured a scheduler to allow hosts access to the Internet during specific times. You notice that hosts are unable to access the Internet. What...
- Question #377
Referring to the exhibit, which policy will allow traffic from Host 1, Host 2, and Host 3 to the Internet?
- Question #378
Click the Exhibit button. You want to permit access to the Internet from the hr zone during a specified time. Which configuration will accomplish this task? [edit security policies...
- Question #379
Click the Exhibit button. You are asked to configure a hub-and-spoke VPN. All the VPN components have been configured, and you are able to ping the remote tunnel interfaces at Site...
- Question #380
Click the Exhibit button. Referring to the exhibit, you need to allow FTP traffic from the Internet to the FTP server in the Trust zone. You have built a custom application so that...
- Question #381
A server in the DMZ of your company is under attack. The attacker is opening a large number of TCP connections to your server which causes resource utilization problems on the serv...
- Question #382
Referring to the exhibit, you want to use source NAT to translate the Web server's IP address to the IP address of ge-0/0/2. Which source NAT type accomplishes this task and always...
- Question #383
The output of show security flow sessions is shown in the exhibit. user@srx> show security flow session Session ID. 10702, Policy name: default-permit/4, Timeout: 1794, Valid In: 2...