nerdexam
Juniper

JN0-637 · Question #84

You have deployed a new site as shown in the exhibit. Hosts in the 10.10.10.0/24 network must access the DB1 server. The DB1 server must also have internet access the DB1 server encrypted. Which two…

The correct answer is A. set security macsec interfaces ge-0/0/1 connectivity association access-sw C. set security macsec connectivity-association access-sw security-mode static-cak. Option A is correct because it enables MACsec encryption on the interface (ge-0/0/1) by binding it to a Connectivity Association (CA) named access-sw. Option C is correct because it defines the security mode for the MACsec association (static-cak), which is required for…

Advanced Junos OS Security Platform

Question

You have deployed a new site as shown in the exhibit. Hosts in the 10.10.10.0/24 network must access the DB1 server. The DB1 server must also have internet access the DB1 server encrypted. Which two configuration statements will be required as part of the configuration on SRX1 to satisfy this requirement? (Choose two)

Exhibit

JN0-637 question #84 exhibit

Options

  • Aset security macsec interfaces ge-0/0/1 connectivity association access-sw
  • Bset security forwarding-options secure-wire access-sw interface ge-0/0/1.0
  • Cset security macsec connectivity-association access-sw security-mode static-cak
  • Dset protocols 12-learning global mode transparent-bridge

How the community answered

(29 responses)
  • A
    66% (19)
  • B
    24% (7)
  • D
    10% (3)

Explanation

Option A is correct because it enables MACsec encryption on the interface (ge-0/0/1) by binding it to a Connectivity Association (CA) named access-sw. Option C is correct because it defines the security mode for the MACsec association (static-cak), which is required for pre-shared key-based encryption.

Topics

#MACsec#secure wire#connectivity association#interface configuration

Community Discussion

No community discussion yet for this question.

Full JN0-637 Practice