nerdexam
Juniper

JN0-635 · Question #163

You must implement an IPsec VPN on an SRX Series device using PKI certificates for authentication. As part of the implementation, you are required to ensure that the certificate submission, renewal…

The correct answer is B. You can use SCEP to accomplish this behavior. Certificate Renewal The renewal of certificates is much the same as initial certificate enrollment except you are just replacing an old certificate (about to expire) on the VPN device with a new certificate. As with the initial certificate request, only manual renewal is…

Advanced IPsec VPNs

Question

You must implement an IPsec VPN on an SRX Series device using PKI certificates for authentication. As part of the implementation, you are required to ensure that the certificate submission, renewal, and retrieval processes are handled automatically from the certificate authority. In this scenario, which statement is correct.

Options

  • AYou can use CRL to accomplish this behavior.
  • BYou can use SCEP to accomplish this behavior.
  • CYou can use OCSP to accomplish this behavior.
  • DYou can use SPKI to accomplish this behavior.

How the community answered

(16 responses)
  • A
    6% (1)
  • B
    75% (12)
  • C
    13% (2)
  • D
    6% (1)

Explanation

Certificate Renewal The renewal of certificates is much the same as initial certificate enrollment except you are just replacing an old certificate (about to expire) on the VPN device with a new certificate. As with the initial certificate request, only manual renewal is supported. SCEP can be used to re-enroll local certificates automatically before they expire. Refer to Appendix D for more details.

Topics

#IPsec VPN#PKI certificates#SCEP#certificate automation

Community Discussion

No community discussion yet for this question.

Full JN0-635 Practice