JN0-632 Exam Questions
165 real JN0-632 exam questions with expert-verified answers and explanations. Page 1 of 4.
- Question #1
Which two configuration tasks should you use to implement filter-based forwarding? (Choose two.)
- Question #2
Your corporate network consists of a central office and four branch offices. You are responsible for coming up with an effective solution to provide secure connectivity between the...
- Question #3
You have been asked to configure a signature to block an attack released by a security vulnerability reporting agency. Which two characteristics of the attack must you understand t...
- Question #4
In a group VPN topology, you have three members A, B, and C. You want A lo communicate with B using a different encryption key from the one it uses to communicate with C. How do yo...
- Question #5
Juniper JN0-632 Exam Click the Exhibit button. The client is downloading a file from the FTP server. The FTP control channel is established using a security policy named t rust-to-...
- Question #6
Click the Exhibit button. A junior network administrator has configured an inbound destination NAT to an internal server translating a public IP to an RFC1918 IP address on the int...
- Question #7
What is the primary function of Junos Intrusion Prevention System (IPS)?
- Question #9
You are implementing a chassis cluster and adding the cluster to your multicast domain. Which two statements are valid considerations for this implementation scenario? (Choose two....
- Question #10
Click the Exhibit button. In the exhibit, a site-to-site IPSec tunnel between the chassis cluster and the remote SRX240 device will not establish. The chassis cluster and the remot...
- Question #11
In terms of application and protocol recognition, how does the IPS engine inspect the traffic?
- Question #12
Your company has installed a new transparent proxy server that it wants all employee traffic to traverse before taking the default route to the Internet. The proxy server is within...
- Question #13
Click the Exhibit button. In the exhibit, traffic from the client is routed to Server A by default you have just implemented filter-based forwarding to redirect specific traffic fr...
- Question #14
You are configuring a hub-and-spoke VPN topology between an SRX Series device deployed at the hub site and several non-Juniper devices at spoke sites. You have decided to use stati...
- Question #15
Click the Exhibit button. Your company uses a custom-built application that uses RSH. You have configured a new application definition to support it on your SRX Series device as sh...
- Question #16
Which two protection mechanisms are supported on SRX Series Services Gateways? (Choose two)
- Question #17
You have a VoIP application that requires external sessions to be initiated into your environment. Your network only has a single public IP address configured on the egress interfa...
- Question #18
Your new employer has contacted you because the company's Web servers located at the DM2 (dmz zone) are not reachable from the Internet (untrust zone). After examining the configur...
- Question #19
You configure an SRX Series chassis cluster with graceful restart support for the configured routing protocols. When testing your cluster failover in a large, multivendor lab envir...
- Question #20
Two High End SRX Series devices are configured in a chassis cluster, but interchassis communication is problematic and intermittent. Node 0 has SPCs located in slots 1, 2, 5, and 1...
- Question #21
Click the Exhibit button. You are configuring a hub-and-spoke VPN in your company network Connectivity between the branches and company headquarters is not working. Referring to th...
- Question #22
You want to limit attacks on TCP ports. Which two scans should you be concerned about? (Choose two)
- Question #23
Click the Exhibit button. You want to verify a security flow on your SRX Series device. Which statement is true regarding the output shown in the exhibit?
- Question #24
You are working at a service provider that offers only residential access to DSL subscribers. Your company has decided to make customer traffic subject to further inspection. When...
- Question #25
Click the Exhibit button. Which two statements are true based on the configuration shown in the Juniper JN0-632 Exam exhibit? (Choose two)
- Question #26
Click the Exhibit button. In the exhibit, a chassis cluster is deployed in active/active mode. This chassis cluster control and fabric links are connected through 100 Mbps WAN conn...
- Question #27
You have correctly implemented a SIP Application Layer Gateway (ALG) on your company's SRX Series device to support SIP traffic on the network. However, after committing the config...
- Question #28
Your company is bringing a remote office online and is using an IPSec VPN to establishes secure communication between the offices. The remote SRX Series device is receiving its IP...
- Question #29
You want to source NAT all traffic initiated from Host A behind an SRX Series device to Server B. The internal transport address must be mapped to the same external transport addre...
- Question #31
Click the Exhibit button. In the exhibit, you are configuring a flow trace of all packets for a TCP session initiated by the client to the server "Die server's IP address is transl...
- Question #32
Click the Exhibit button. The output shown in the exhibit is from an SRX Series device that is the hub in a hub-and-spoke VPN. Which two statements is true regarding this output? (...
- Question #33
Click the Exhibit button. Referring to the exhibit, an IPSec tunnel is established between SRXA and SRXB. A GRE tunnel is established between router A and router B. Users in LANA c...
- Question #34
You are asked to set up a multi-tenant configuration on your SRX Series device. Several remote branch locations are connected to the device. You will connect each remote site to a...
- Question #35
Click the Exhibit button. You are troubleshooting a new IPSec VPN tunnel that is failing to establish an IKE security association between SRX Series devices. You notice the error i...
- Question #36
In planning for your core data center's SRX5800 cluster software upgrade, minimal downtime is requested by your management team. With a goal to achieve maximum uptime, how should y...
- Question #37
A site-to-site VPN is configured between satellite offices and headquarters using a digital certificate from a neutral party. Once the VPN is up and stable, the certificate issued...
- Question #38
Click the Exhibit button.You configured a security policy with an address book entry using a DNS name. Traffic matching the security policy for the DNS name is being dropped. Refer...
- Question #39
An attacker from IP address 1.1.1.2 is filling your SRX Series device's session table with TCP sessions that have all completed a legitimate three-way handshake. What will help thr...
- Question #40
A SYN packet traverses an SRX Series device and a session is created. When the return SYN-ACK packet arrives at the SRX, the original interface on which the SYN packet arrived is d...
- Question #41
A security analyst at your company wants to make sure packets coming from the Internet accessing your public Web servers are protected from HTTP packets that do not meet standards....
- Question #42
You want to allow users from routing-instance Juniper1 to route to the destination 2.2.2.2, reached through routing-instance Juniper2 without sharing all the routes between the two...
- Question #43
You want to deploy an SRX Series cluster for a distributed data center between two remote locations. The earner will provide you with dark fiber capable of the following: a 100 km...
- Question #44
A site-to-site VPN is configured between the main office and a remote office. An administrator wants to keep track of the VPN tunnel. Which feature is used to verify that the VPN t...
- Question #45
You want to add a dynamic VPN to your SRX650. This dynamic VPN must be able to support five users at the same time. What are two primary requirements? (Choose two.)
- Question #46
What can cause a node in an SRX Series chassis cluster to be in the disabled state?
- Question #47
Click the Exhibit button. Referring to the exhibit, what happens when the source pool is Juniper JN0-632 Exam exhausted?
- Question #48
You initiated the download of the attack database. The system indicates that it will run asynchronous and returns you to a command prompt in the CLI. You want to know if the downlo...
- Question #49
Click the Exhibit button. A junior member of the network team has set up a new VPN tunnel using a PKI certificate and is unable to establish the tunnel. After troubleshooting the p...
- Question #50
Click the Exhibit button. In the exhibit, Node 0 had primacy of RG 1 until interface ge-0/0/1 failed. Upon restoration of interface ge-0/0/1 Node 1 retained primacy for RG 1. What...
- Question #51
You have been asked to implement a hub-and-spoke IPSec VPN in a multi-vendor environment Juniper JN0-632 Exam where the spoke devices are not always Junos devices. Which statement...
- Question #52
You have a VoIP application that requires external sessions to be initiated into your environment. The internal host has previously sent a packet to the external VoIP application's...