JN0-633 Exam Questions
209 real JN0-633 exam questions with expert-verified answers and explanations. Page 2 of 5.
- Question #51Advanced Security Services (IDP, UTM)
An external host is attacking your network. The host sends an HTTP request to a Web server, but does not include the version of HTTP in the request. Which type of attack is being p...
protocol anomalyHTTP attackIPS detectionapplication layer - Question #52Advanced Security Services (IDP, UTM)
You configured a custom signature attack object to match specific components of an attack: HTTP-request Pattern .*\x90 90 90 ... 90 Direction: client-to-server Which client traffic...
custom IDP signaturesHTTP pattern matchinghex encodingattack objects - Question #53Layer 2 Security
You are deploying a standalone SRX650 in transparent mode for evaluation purposes in a potential client's network. The client will need to access the device to modify security poli...
transparent modeIRB interfacemanagement accessLayer 2 deployment - Question #54
Which two configuration components are required for enabling transparent mode on an SRX device? (Choose two.)
- Question #55
You want to configure in-band management of an SRX device in transparent mode. Which command is required to enable this functionality?
- Question #56
For an SRX chassis cluster in transparent mode, which action occurs to signal a high availability failover to neighboring switches?
- Question #57Layer 2 Security
What is the default action for an SRX device in transparent mode to determine the outgoing interface for an unknown destination MAC address?
transparent modeunknown MACpacket floodingLayer 2 forwarding - Question #58
Which QoS function is supported in transparent mode?
- Question #59
You are asked to configure class of service (CoS) on an SRX device running in transparent mode. Which command would you use?
- Question #60
A security administrator has configured an IPsec tunnel between two SRX devices. The devices are configured with OSPF on the st0 interface and an external interface destined to the...
- Question #61
You are asked to troubleshoot ongoing problems with IPsec tunnels and security policy processing. Your network consists of SRX240s and SRX5600s. Regarding this scenario, which two...
- Question #62VPNs (IPsec, SSL)
You are troubleshooting an IPsec session and see the following IPsec security associations: ID Gateway Port Algorithm SPI Life:sec/kb Mon vsys < 192.168.224.1 500 ESP:aes-256/sha1...
IPsec SA duplicationPhase 2 lifetimeestablish-tunnels immediatelyduplicate tunnels - Question #63
HostA (1.1.1.1) is sending TCP traffic to HostB (2.2.2.2). You need to capture the TCP packets locally on the SRX240. Which configuration would you use to enable this capture?
- Question #64
You are troubleshooting an SRX240 acting as a NAT translator for transit traffic. Traffic is dropping at the SRX240 in your network. Which three tools would you use to troubleshoot...
- Question #65Advanced Security Services (IDP, UTM)
Somebody has inadvertently configured several security policies with application firewall rule sets on an SRX device. These security policies are now dropping traffic that should b...
application firewallsecurity policy associationAppFW rule-setshow commands - Question #66Advanced Security Services (IDP, UTM)
[edit security] user@srx# show idp ... application-ddos Webserver { service http; connection-rate-threshold 1000; context http-get-url { hit-rate-threshold 60000; value-hit-rate-th...
AppDoShit-rate thresholdIDP action timeoutfalse positive tuning - Question #67
Click the Exhibit button.You have been asked to block YouTube video streaming for internal users. You have implemented the configuration shown in the exhibit, however users are sti...
- Question #68Monitoring and Troubleshooting
Click the Exhibit button. Referring to the exhibit, AppTrack is only logging the session closure messages for sessions that last 1 to 3 minutes. What is causing this behavior?
AppTracksession closure messagesupdate intervalapplication tracking - Question #69
Click the Exhibit button. Referring to the exhibit, the session close log was generated by the application firewall rule set HTTP. Why did the session close?
- Question #70
Click the Exhibit button. Referring to the exhibit, the application firewall configuration fails to commit. What must you do to allow the configuration to commit?
- Question #71Security Policies and Zones
Click the Exhibit button. TCP traffic sourced from Host A destined for Host B is being redirected using filter-based forwarding to use the Red network. However, return traffic from...
filter-based forwardingasymmetric routingsecurity zone membershipreturn traffic - Question #72Monitoring and Troubleshooting
Click the Exhibit button. In the output, how many user-configured routing instances have active routes?
routing instancesactive routesroute table outputshow route - Question #73
Click the Exhibit button. In the network shown in the exhibit, you want to forward traffic from the employees to ISP1 and ISP2. You want to forward all Web traffic to ISP1 and all...
- Question #74
Click the Exhibit button. Referring to the exhibit, which feature allows the hosts in the Trust and DMZ zones to route to either ISP, based on source address?
- Question #75
Click the Exhibit button. In the network shown in the exhibit, you want to forward traffic from the employees to ISP1 and ISP2. You want to forward all Web traffic to ISP1 and all...
- Question #76Monitoring and Troubleshooting
Click the Exhibit button. Referring to the exhibit, you notice that filter-based forwarding is not working. What is the reason for this behavior?
filter-based forwardingrouting instance misconfigurationRIB groupFBF troubleshooting - Question #77Network Address Translation (NAT)
Click the Exhibit button. As shown in the exhibit, Host A's configured DNS server and the Web server hosting the reachability between Host A and the Web server hosting the Web page...
DNS doctoringNATsplit DNSinternal server reachability - Question #78
Click the Exhibit button. You are asked to implement NAT to translate addresses between the IPv4 and IPv6 networks shown in the exhibit. What are three configuration requirements?...
- Question #79Network Address Translation (NAT)
Click the Exhibit button. Referring to the topology shown in the exhibit, which two configuration tasks will allow Host A to telnet to the public IP address associated with Server...
hairpin NATdestination NATsource NATloopback traffic - Question #80Network Address Translation (NAT)
Click the Exhibit button. You must configure two SRX devices to enable bidirectional communications between the two networks shown in the exhibit. You have been allocated the 172.1...
static NATbidirectional NATsite-to-site translationoverlapping addresses - Question #81
Click the Exhibit button. Based on the output shown in the exhibit, what are two results? (Choose two.)
- Question #82Network Address Translation (NAT)
Click the Exhibit button. security { nat { destination { pool Web-Server { address 10.0.1.5/32; } rule-set From-Internet { from zone Untrust; rule To-Web-Server { match { source-ad...
destination NATrule-set modificationNAT poolmultiple destination addresses - Question #83VPNs (IPsec, SSL)
Click the Exhibit button. According to the log shown in the exhibit, you notice that the IPsec session is not establishing. What are two reasons for this behavior? (Choose two.)
IKE Phase 1 failurepeer address mismatchpeer ID mismatchIPsec log analysis - Question #84Advanced Security Services (IDP, UTM)
Click the Exhibit button. An attacker is using a nonstandard port for HTTP for reconnaissance into your network. Referring to the exhibit, which two statements are true? (Choose tw...
IPS application identificationnonstandard portAppIDdeep packet inspection - Question #85Advanced Security Services (IDP, UTM)
Click the Exhibit button. You have configured an IDP policy as shown in the exhibit. The configuration commits successfully. Which traffic will be examined for attacks?
IDP policybidirectional inspectionsession trafficoriginating and reply traffic - Question #86
Click the Exhibit button. [edit security] user@srx# show idp { idp-policy NewPolicy { rulebase-exempt { rule 1 { description AllowExternalRule; match { source-address any; destinat...
- Question #87Advanced Security Services (IDP, UTM)
[edit security idp] user@srx# show security-package { url https://services.netscreen.com/cgi-bin/index.cgi; automatic { start-time "2012-12-11.01:00:00 +0000"; interval 120; enable...
IDP signature updatesDNS configurationautomatic updatesInternet connectivity - Question #88
[edit security idp] user@srx# show | no-more idp-policy basic { rulebase-ips { rule 1 { match { from-zone untrust; source-address any; to-zone trust; destination-address any; appli...
- Question #89
Click the Exhibit button. You receive complaints from users that their Web browsing sessions keep dropping prematurely. Upon investigation, you find that the IDP policy shown in th...
- Question #90
Click the Exhibit button. In the exhibit, the SRX device has hosts connected to interface ge-0/0/1 and ge-0/0/6. The devices are not able to ping each other. What is causing this b...
- Question #91
Click the Exhibit button. Referring to the exhibit, a pair of SRX3600s is in an active/passive chassis cluster configured for transparent mode. Which type of traffic would traverse...
- Question #92
user@srx# show security datapath-debug capture-file pkt-cap-file format pcap size 5m; action-profile { pkt-cap-profile { event np-ingress { packet-dump; } } } packet-filter pkt-fil...
- Question #93
Click the Exhibit button. Host traffic is traversing through an IPsec tunnel. Users are complaining of intermittent issues with their connection. Referring to the exhibit, what is...
- Question #94
Click the Exhibit button. A host is not able to communicate with a Web server. Based on the logs shown in the exhibit, what is the problem?
- Question #95
user@srx> show security flow session Session ID. 7724, Policy namE. default-permit/4, Timeout: 2 In: 1.1.70.6/17 --> 100.0.0.1/2326;icmp, IF. ge-0/0/3 Out: 10.1.10.5/2326 --> 1.1.7...
- Question #96
Click the Exhibit button. Referring to the exhibit, which two statements are true? (Choose two.)
- Question #97
[edit forwarding-options] user@srx240# show packet-capture { file filename my-packet-capture; maximum-capture-size 1500; } Referring to the exhibit, you are attempting to perform a...
- Question #98Advanced Security Services (IDP, UTM)
What are two network scanning methods? (Choose two.)
network scanningping sweepUDP scanreconnaissance techniques - Question #99Advanced Security Services (IDP, UTM)
What are two intrusion protection mechanisms available on SRX Series Services Gateways? (Choose two.)
IPS mechanismstraffic anomaly detectionDoS protectionintrusion prevention - Question #100
What is a benefit of using a dynamic VPN?