JN0-332 Exam Questions
472 real JN0-332 exam questions with expert-verified answers and explanations. Page 9 of 10.
- Question #434
You want to add a dynamic VPN to your SRX650. This dynamic VPN must be able to support five users at the same time. What are two primary requirements? (Choose two.)
- Question #435
What can cause a node in an SRX Series chassis cluster to be in the disabled state?
- Question #436
You have been asked to implement a hub-and-spoke IPSec VPN in a multi-vendor environment where the spoke devices are not always Junos devices. Which statement is correct?
- Question #437
In the sequence of IPS inspection steps, protocol anomaly detection is performed after which step?
- Question #438
You have configured persistent NAT in your NAT rule base. You create a security policy in the direction of external to internal. Which persistent NAT parameter should you configure...
- Question #439
Which component can you use to find an attack for traffic that uses a nonstandard service?
- Question #440
Which two make up the context of an IPS attack signature? (Choose two.)
- Question #441
The integrated user firewall feature requires which authentication server type?
- Question #442
You want to form a chassis cluster. What are two requirements to accomplish this task? (Choose two.)
- Question #443
What are two valid zones available on an SRX Series device? (Choose two)
- Question #444
Click the Exhibit button. Which three statements are correct about the configuration shown in the exhibit? (Choose three)
- Question #445
You committed a new security policy on an SRX Series device. Now, traffic appears to be incorrectly dropped. Which two tools would you use to explain why traffic is dropped? (Choos...
- Question #446
Which two statements are true about route-based IPsec VPNs on an SRX Series device? (Choose two)
- Question #447
You are asked to control access through an SRX Series device by username, using integrated user firewall feature. For non-domain users, which statement is correct?
- Question #448
Click the Exhibit button. Referring to the exhibit, which security policy configuration change must be made to allow HTTP traffic to server 192.188.1.100 from user3?
- Question #449
Click the Exhibit button. Referring to the exhibit, what is the post-translated address on the SRX Series device?
- Question #450
What are two ways to manage all UTM features on an SRX Series device? (Choose two)
- Question #451
Which interface serves as a control link for a chassis cluster on an SRX Series device?
- Question #452
A packet that belongs to an existing session enters your SRX Series device. Your SRX Series device is operating in its default mode. Which two statements about ingress processing a...
- Question #453
When configuring a destination NAT rule, you notice that you are unable to configure the to match condition on an SRX Series device in this scenario, which two statements are corre...
- Question #454
What are two benefits of enhanced Web filtering when configured on an SRX Series device? (Choose two)
- Question #455
Which statement describes the function of NAT?
- Question #456
Which two statements are true regarding branch SRX Series devices? (Choose two)
- Question #457
Which two types of attacks does the SRX Series device identify using screens? (Choose two)
- Question #458
You want to configure one-to-one static mapping of IP addresses using an address pool without using PAT on an SRX Series device. Which source NAT option would you use?
- Question #459
What is an example of single address translation (one-to-one)?
- Question #460
Which feature on the SRX Series device would be processed first for transit traffic?
- Question #461
Which three criteria determine if a packet entering an SRX Series device belongs to an existing session? (Choose three)
- Question #462
Which two statements are true about local host traffic on an SRX Series device? (Choose two)
- Question #463
Which two statements are correct regarding the null zone on an SRX Series device? (Choose two)
- Question #464
You want to have a private server that multiple users can access from the Internet simultaneously. Which two NAT solutions would you configure on the SRX Series device? (Choose two...
- Question #465
Your network administrator asked you to replace Node I of an SRX5800 chassis cluster running in an active/active mode. The administrator wants to know any impact this could cause....
- Question #466
Which two types of traffic are affected by security policies on an SRX Series device? (Choose two)
- Question #467
What does the set security screen ids-option protector icmp flood threshold 1500 command do?
- Question #468
Which two statements are true regarding built-in applications on Junos SRX Series devices? (Choose two.)
- Question #469
You are configuring an SRX Series device with policy rematching disabled. You change a permit policy to have an action of deny and commit the configuration. Which statement is true...
- Question #470
You are creating a new security policy on your SRX Series device to control traffic entering a zone. What are three valid actions? (Choose three.)
- Question #471
Click the Exhibit button. Users are able to access hosts on the Internet, however, they are using the TO_INTERNET pool instead of the IP address associated with the external interf...
- Question #472
You have implemented NAT on your SRX Series device. You now want to be notified if the configured NAT pool is nearing its maximum usage capacity. Which two actions are required? (C...
- Question #473
What are two valid functions of the fabric interface in a chassis cluster? (Choose two)
- Question #474
Which two statements are true regarding SRX Series devices? (Choose two)
- Question #475
Which statement describes the function of screen options?
- Question #476
Which two statements are correct regarding IPSec security associations on the SRX Series devices? (Choose two.)
- Question #477
You want to enable antivirus scanning on your SRX Series device. You want a solution that will scan individual data packets by a hardware pattern-matching engine with minimal impac...
- Question #478
Click the Exhibit button. Which two statements are true regarding the output shown in the exhibit? (Choose two.)
- Question #479
Click the Exhibit button Referring to the exhibit, what is the expected behavior?
- Question #480
Click the Exhibit button. Which two statements are true about the output shown in the exhibit? (Choose two)
- Question #481
What are three types of reconnaissance attacks? (Choose three)
- Question #482
Which two statements regarding screens on SRX Series devices are correct? (Choose two.)
- Question #483
The local side of an IPSec VPN is an SRX Series device. The remote side of the IPSec VPN is a third-party vendor and it is using a local proxy ID of 1.1.1.1/32 and a remote proxy I...