JN0-633 Exam Questions
209 real JN0-633 exam questions with expert-verified answers and explanations. Page 1 of 5.
- Question #1Advanced Threat Prevention Features
You are asked to apply individual upload and download bandwidth limits to YouTube traffic. Where in the configuration would you create the necessary bandwidth limits?
application traffic shapingbandwidth policingfirewall policerAppFW - Question #2Advanced Threat Prevention Features
You want to verify that all application traffic traversing your SRX device uses standard ports. For example, you need to verify that only DNS traffic runs through port 53, and no o...
IDP policyapplication identificationnon-standard portsAppID - Question #3Advanced Threat Prevention Features
You are asked to establish a baseline for your company's network traffic to determine the bandwidth usage per application. You want to undertake this task on the central SRX device...
AppTracktraffic baselineapplication visibilitysyslog - Question #4Advanced Threat Prevention Features
Microsoft has altered the way their Web-based Hotmail application works. You want to update your application firewall policy to correctly identify the altered Hotmail application....
application-identificationcustom applicationAppFW policyapplication copy - Question #5Advanced Security Concepts
Two companies, A and B, are connected as separate customers on an SRX5800 residing on two virtual routers (VR-A and VR-B). These companies have recently been merged and now operate...
virtual routing instancesinstance-importinter-VR routingnext-table - Question #6
You have been asked to configure traffic to flow between two virtual routers (VRs) residing on two unique logical systems (LSYSs) on the same SRX5800. How would you accomplish this...
- Question #7Advanced Security Concepts
You are responding to a proposal request from an enterprise with multiple branch offices. All branch offices connect to a single SRX device at a centralized location. The request r...
logical systemsinterconnect LSYSlogical tunnel interfacemulti-tenant security - Question #8
Your company provides managed services for two customers. Each customer has been segregated within its own routing instance on your SRX device. Customer A and customer B inform you...
- Question #9Advanced Security Concepts
You are using logical systems to segregate customers. You have a requirement to enable communication between the logical systems. What are two ways to accomplish this goal? (Choose...
logical systemsinterconnect LSYSinter-LSYS communicationvirtual tunnel - Question #10Advanced Security Concepts
Your company is providing multi-tenant security services on an SRX5800 cluster. You have been asked to create a new logical system (LSYS) for a customer. The customer must be able...
logical systemsLSYS administratorresource allocationmulti-tenant SRX - Question #11
Your company has added a connection to a new ISP and you have been asked to send specific traffic to the new ISP. You have decided to implement filter-based forwarding. You have co...
- Question #12
You have implemented a tunnel in your network using DS-Lite. The tunnel is formed between one of the SRX devices in your network and a DS-Lite-compatible CPE device in your custome...
- Question #13
You are asked to merge the corporate network with the network from a recently acquired company. Both networks use the same private IPv4 address space (172.25.126.0/24). An SRX devi...
- Question #14Advanced Security Concepts
You want requests from the same internal transport address to be mapped to the same external transport address. Only internal hosts can initialize the session. Which Junos configur...
persistent NATaddress-persistentsource NATinternal transport address - Question #15
Which statement is true regarding dual-stack lite?
- Question #16Advanced Security Concepts
Which two statements are true regarding DNS doctoring? (Choose two.)
DNS doctoringDNS A-recordALGIPv4 NAT - Question #17Advanced Security Concepts
In which situation is NAT proxy NDP required?
NAT proxy NDPIPv6 NATstatic NATneighbor discovery - Question #18Advanced Security Concepts
Which statement is true about NAT?
static NATdestination NATNAT rule orderingNAT behavior - Question #19
You have configured static NAT for a Web server in your DMZ. Both internal and external users can reach the Web server using its IP address. However, only internal users are able t...
- Question #20Advanced Security Concepts
Which two are required for the SRX device to perform DNS doctoring? (Choose two.)
DNS doctoringDNS ALGstatic NATDNS A-record translation - Question #21Advanced Security Concepts
You want to implement persistent NAT for an internal resource so that external hosts are able to initiate communications to the resource, without the internal resource having previ...
persistent NATany-remote-hostexternal session initiationsource NAT - Question #22Network Address Translation (NAT)
Your SRX device is performing NAT to provide an internal resource with a public address. Your DNS server is on the same network segment as the server. You want your internal hosts...
NAT hairpinningproxy ARPDNS resolutionstatic NAT - Question #23Network Address Translation (NAT)
You are asked to provide access for an external VoIP server to VoIP phones in your network using private addresses. However, due to security concerns, the VoIP server should only b...
persistent NATtarget-hostVoIPNAT types - Question #24
You must configure a central SRX device connected to two branch offices with overlapping IP address space. The branch office connections to the central SRX device must reside in se...
- Question #25VPNs (IPsec, SSL)
You are attempting to establish an IPsec VPN between two SRX devices. However, there is another device between the SRX devices that does not pass traffic that is using UDP port 450...
NAT-TUDP 4500IPsec traversalIKE - Question #26
Given the following session output: Session ID. , Policy namE. default-policy-00/2, StatE. Active, Timeout: 1794, Valid In: 2001:660:1000:8c00::b/1053 --> 2001:660:1000:9002::aafe/...
- Question #27VPNs (IPsec, SSL)
You are asked to deploy a group VPN between various sites associated with your company. The gateway devices at the remote locations are SRX240 devices. Which two statements about t...
group VPNchassis clusterNAT restrictionsGDOI - Question #28
You are asked to deploy dynamic VPNs between the corporate office and remote employees that work from home. The gateway device at the corporate office consists of a pair of SRX650s...
- Question #29
You are asked to deploy dynamic VPNs between the corporate office and remote employees that work from home. The gateway device at the corporate office is a chassis cluster formed f...
- Question #30VPNs (IPsec, SSL)
You are asked to implement IPsec tunnels between your SRX devices located at various locations. You will use the public key infrastructure (PKI) to verify the identification of the...
PKISCEPcertificate enrollmentCA - Question #31VPNs (IPsec, SSL)
Which statement is true regarding the dynamic VPN feature for Junos devices?
dynamic VPNpreshared keysPhase 1IKE mode - Question #32VPNs (IPsec, SSL)
You are asked to design a solution to verify IPsec peer reachability with data path forwarding. Which feature would meet the design requirements?
VPN monitoringdata plane verificationPhase 2 SADPD - Question #33VPNs (IPsec, SSL)
What are three advantages of group VPNs? (Choose three.)
group VPNGDOIany-to-any connectivitykey server - Question #34
You have been asked to establish a dynamic IPsec VPN between your SRX device and a remote user. Regarding this scenario, which three statements are correct? (Choose three.)
- Question #35VPNs (IPsec, SSL)
You want to implement an IPsec VPN on an SRX device using PKI certificates for authentication. As part of the implementation, you are required to ensure that the certificate submis...
SCEPPKI automationcertificate renewalCA - Question #36VPNs (IPsec, SSL)
You have a group IPsec VPN established with a single key server and five client devices. Regarding this scenario, which statement is correct?
group VPNPhase 1 SAPhase 2 SAkey server - Question #37
You are asked to implement an IPsec VPN between your main office and a new remote office. The remote office receives its IKE gateway address from their ISP dynamically. Regarding t...
- Question #38VPNs (IPsec, SSL)
You are asked to implement a point-to-multipoint hub-and-spoke topology in a mixed vendor environment. The hub device is running the Junos OS and the spoke devices are different ve...
NHTB tablehub-and-spokepoint-to-multipointmixed vendor - Question #39VPNs (IPsec, SSL)
You have recently deployed a dynamic VPN. Some remote users are complaining that they cannot authenticate through the SRX device at the corporate network. The SRX device serves as...
dynamic VPNlicense limitsaccess profileauthentication - Question #40
You have recently deployed a dynamic VPN. The remote users are complaining that communications with devices on the same subnet as the SRX device are intermittent and often fail. Th...
- Question #41
Your company is using a dynamic VPN configuration on their SRX device. Your manager asks you to enforce password expiration policies for all VPN users. Which authentication method...
- Question #42VPNs (IPsec, SSL)
You are asked to implement a monitoring feature that periodically verifies that the data plane is working across your IPsec VPN. Which configuration will accomplish this task?
VPN monitoringdata planeIPsec configurationPhase 2 - Question #43VPNs (IPsec, SSL)
You want to implement a hub-and-spoke VPN topology using a single logical interface on the hub. Which st0 interface configuration is correct for the hub device?
hub-and-spoke VPNst0 interfaceroute-based VPNpoint-to-multipoint - Question #44VPNs (IPsec, SSL)
You have an existing group VPN established in your internal network using the group-id 1. You have been asked to configure a second group using the group-id 2. You must ensure that...
group VPNkey servermember hierarchyGDOI configuration - Question #45Advanced Security Services (IDP, UTM)
What are the three types of attack objects used in an IPS engine? (Choose three.)
IPS attack objectssignatureanomalycompound - Question #46
At which two times does the IPS rulebase inspect traffic on an SRX device? (Choose two.)
- Question #47Advanced Security Services (IDP, UTM)
Which three match condition objects are required when creating IPS rules? (Choose three.)
IPS rulesmatch conditionszone objectsattack objects - Question #48Advanced Security Services (IDP, UTM)
Which problem is introduced by setting the terminal parameter on an IPS rule?
IPS terminal rulerule processing orderfalse negativesIDP policy - Question #49Advanced Security Services (IDP, UTM)
You have installed a new IPS license on your SRX device and successfully downloaded the attack signature database. However, when you run the command to install the database, the da...
IPS signature databaseinstallation failuredisk spacelicense - Question #50
You want to create a custom IDP signature for a new HTTP attack on your SRX device. You have the exact string that identifies the attack. Which two additional elements do you need...