JN0-637 Exam Questions
121 real JN0-637 exam questions with expert-verified answers and explanations. Page 2 of 3.
- Question #51Redundant Security Architectures
You are setting up multinode HA for redundancy. Which two statements are correct in this scenario? (Choose two.)
multinode HAdynamic routingICLcontrol link - Question #52Advanced Junos OS Security Platform
You want to configure the SRX Series device to map two peer interfaces together and ensure that there is no switching or routing lookup to forward traffic. Which feature on the SRX...
secure wireLayer 2 bypassinterface mappingtransparent forwarding - Question #53Granular Security Policies
Referring to the exhibit. SRX-1 and SRX-3 have to be connected using EBGP. The BGP configuration on SRX-1 and SRX-3 is verified and correct. Which configuration on SRX-2 would esta...
EBGPBGP TCP port 179security policyhost-inbound-traffic - Question #54Security Monitoring and Troubleshooting
You are attempting to ping an interface on your SRX Series device, but the ping is unsuccessful. What are three reasons for this behavior? (Choose three.)
ping troubleshootingsecurity zone assignmenthost-inbound-trafficfirewall filter - Question #55Site-to-Site and Remote Access VPNs
You are deploying IPsec VPNs to securely connect several enterprise sites with ospf for dynamic routing. Some of these sites are secured by third-party devices not running Junos. W...
OSPF over GRE over IPsecoverlapping addressesthird-party VPNdynamic routing - Question #56Redundant Security Architectures
You have deployed a pair of SRX series devices in a multimode HA environment. You need to enable IPsec encryption on the interchassis link. Referring to theexhibit, which three ste...
multinode HAICL encryptionIKE packageIPsec profile - Question #57Security Monitoring and Troubleshooting
Which two statements are correct about the output shown in the exhibit. (Choose Two)
traceoptionsbasic-datapath flagsecurity policy droppacket debugging - Question #58Advanced Junos OS Security Platform
Which two elements are necessary to configure a rule under an APBR profile? (Choose Two)
APBR profilematch conditionrouting actionpolicy-based routing rule - Question #59Site-to-Site and Remote Access VPNs
Referring to the exhibit, you are attempting to set up a remote access VPN on your SRX series devices. However you are unsure of which system services you should allow and in which...
remote access VPNhost-inbound-trafficIKE system servicetcp-encap - Question #60Redundant Security Architectures
What are three configurable monitor components for a service redundancy group? (Choose three)
service redundancy groupSRG monitoringinterface monitorIP monitoring - Question #61Complex NAT Deployments
The SRX series device is performing static NAT. you want to ensure that host A can reach the Referring to the exhibit, which two Junos features are required to accomplish this task...
static NATDNS doctoringproxy ARPhairpin NAT - Question #62Advanced Junos OS Security Platform
You want to enable transparent mode on your SRX series device. In this scenario, which three actions should you perform? (Choose three.)
transparent modeethernet-switchingLayer 2security zone - Question #63Advanced Junos OS Security Platform
Referring to the exhibit, you have been assigned the user LogicalSYS1 credentials shown in the configuration. In this scenario, which two statements are correct? (Choose two.)
logical systemsuser credentialsrouting tablesoperational mode - Question #64Granular Security Policies
You created a Unified Security Policy called "test" on the network edge's SRX Series firewall. According to the firewall, this new security policy is not passing any traffic, and t...
unified security policydynamic applicationAppIDpolicy ordering - Question #65Complex NAT Deployments
Referring to the exhibit, which technology would you use to provide communication between IPv4 host1 and ipv4 internal host
DS-LiteIPv4/IPv6 transitionCGNNAT technology - Question #66Security Monitoring and Troubleshooting
You are attempting to ping the IP address that is assigned to the loopback interface on the SRX series device shown in the exhibit. What is causing this problem?
loopback interfaceinterface indexping troubleshootingSRX configuration - Question #67Site-to-Site and Remote Access VPNs
What are three requirements to run OSPF over GRE over IPsec? (Choose Three)
OSPFGRE tunnelIPsechost-inbound-traffic - Question #68Site-to-Site and Remote Access VPNs
You need to generate a certificate for a PKI-based site-to-site VPN. The peer is expecting to user your domain name vpn.juniper.net. Which two configuration elements are required w...
PKIcertificate requestdomain-nameIKE identity - Question #69Redundant Security Architectures
You configured two SRX series devices in an active/passive multimode HA setup. You just rebooted both devices. In this scenario, which statement is correct?
multinode HAactive/passiveHA state machineactiveness determination - Question #70Advanced Junos OS Security Platform
Which two statements about transparent mode and Ethernet switching mode on an SRX series device are correct.
transparent modeEthernet switching modeIRB interfacesecurity zone - Question #71Complex NAT Deployments
A customer wants to be able to initiate a return connection to an internal host from a specific Server. Which NAT feature would you use in this scenario?
persistent NATtarget-hostreturn connectionsource NAT - Question #72Site-to-Site and Remote Access VPNs
You are using AutoVPN to deploy a hub-and-spoke VPN to connect your enterprise sites. In this scenario, which two statements are true? (Choose two.)
AutoVPNhub-and-spokespoke provisioningIPsec - Question #73Advanced Junos OS Security Platform
You are configuring advanced policy-based routing. You have created a static route with next hop of an interface in your inet.0 routing table Referring to the exhibit, what should...
APBRRIB groupsrouting instancerib-groups order - Question #74Granular Security Policies
What are three attributes that APBR queries from the application system cache module. (Choose Three)
APBRapplication system cachedestination portprotocol type - Question #75Advanced Threat Prevention
Which two statements about policy enforcer and the forescout integration are true? (Choose two)
policy enforcerForescout CounterACT802.1Xthird-party integration - Question #76Complex NAT Deployments
Which three statements about persistent NAT are correct? (Choose Three)
persistent NATreflexive addresssource NATsession initiation - Question #77Complex NAT Deployments
You implement persistent NAT to allow any device on the external side of the firewall to initiate traffic once the initial translation has been established. Communication is not wo...
persistent NATany-remote-hostinterface-based NATIP pool requirement - Question #78Redundant Security Architectures
Which two statements about the differences between chassis cluster and multinode HA on SRX series devices are true? (Choose Two)
chassis clustermultinode HALayer 2 connectivityLayer 3 connectivity - Question #79Advanced Junos OS Security Platform
Referring to the exhibit, you are assigned the tenantSYS1 user credentials on an SRX series device. In this scenario, which two statements are correct? (Choose two.)
tenant systemsuser credentialsrouting tablesoperational mode - Question #80Complex NAT Deployments
A user reports that a specific application is not working properly. This application makes multiple connection to the server and must have the same address every time from a pool a...
persistent NATaddress-persistentNAT poolsource NAT - Question #81Advanced Threat Prevention
You have cloud deployments in Azure, AWS, and your private cloud. You have deployed multicloud using security director with policy enforcer to. Which three statements are true in t...
multicloudSecurity DirectorPolicy EnforcerATP scans - Question #82Advanced Junos OS Security Platform
Which two statements describe the behavior of logical systems? (Choose two.)
logical systemsrouting protocol processdefault routing instancevirtualization - Question #83Granular Security Policies
Which two statements are correct about advanced policy-based routing?
APBRapplication system cacheforwarding instancerouting instance - Question #84Advanced Junos OS Security Platform
You have deployed a new site as shown in the exhibit. Hosts in the 10.10.10.0/24 network must access the DB1 server. The DB1 server must also have internet access the DB1 server en...
MACsecsecure wireconnectivity associationinterface configuration - Question #85Site-to-Site and Remote Access VPNs
The Ipsec VPN does not establish when the peer initiates, but it does establish when the SRX series device initiates. Referring to the exhibit, what will solve this problem?
IPsec VPNIKEhost-inbound trafficVPN troubleshooting - Question #86Site-to-Site and Remote Access VPNs
You are experiencing problem with your ADVPN tunnels getting established. The tunnel and egress interface are located in different zone. What are two reasons for these problems? (C...
ADVPNIKEsecurity zonetunnel interface - Question #87Complex NAT Deployments
Which two statements are correct about DNS doctoring?
DNS doctoringDNS ALGProxy ARPNAT - Question #88Advanced Junos OS Security Platform
Which encapsulation type must be configured on the lt-0/0/0 logical units for an interconnect logical systems VPLS switch?
logical systemsVPLSlt-0/0/0encapsulation - Question #89Security Monitoring and Troubleshooting
Referring to the exhibit, which two statements are true?
IPsec VPNESP sequencetunnel trafficVPN counters - Question #90Site-to-Site and Remote Access VPNs
Which two statements are true about ADVPN members? (Choose two.)
ADVPNcertificate authenticationIKEv2VPN members - Question #91Advanced Junos OS Security Platform
You are deploying a virtualization solution with the security devices in your network Each SRX Series device must support at least 100 virtualized instances and each virtualized in...
logical systemstenant systemsvirtualizationadministrative domain - Question #92Advanced Junos OS Security Platform
How does secure wire mode differ from transparent mode?
secure wire modetransparent modeswitching lookuptraffic forwarding - Question #93Advanced Junos OS Security Platform
In an effort to reduce client-server latency transparent mode was enabled an SRX series device. Which two types of traffic will be permitted in this scenario? (Choose Two.)
transparent modeARPLayer 2 multicastpermitted traffic - Question #94Granular Security Policies
You are enabling advanced policy-based routing. You have configured a static route that has a next hop from the inet.0 routing table. Unfortunately, this static route is not active...
APBRRIB groupsrouting instancestatic route - Question #95Security Monitoring and Troubleshooting
Referring to the flow logs exhibit, which two statements are correct? (Choose two.)
flow logssecurity policytraceoptionsbasic-datapath - Question #96Complex NAT Deployments
You are configuring NAT64 on your SRX Series device. You have committed the configuration shown in the exhibit. Unfortunately, the communication with the 10.10.201.10 server is not...
NAT64IPv6proxy-NDPsource NAT - Question #97Granular Security Policies
What are three core components for enabling advanced policy-based routing? (Choose three.)
APBRfilter-based forwardingrouting instanceAPBR profile - Question #98Granular Security Policies
You want to bypass IDP for traffic destined to social media sites using APBR, but it is not working and IDP is dropping the session. What are two reasons for this problem? (Choose...
APBRIDP bypassapplication services bypasssession reclassification - Question #99Advanced Junos OS Security Platform
Which two statements are correct about mixed mode? (Choose two.)
mixed modeIRB interfacesecurity zoneLayer 2/3 interfaces - Question #100Granular Security Policies
Referring to the exhibit, you are having problems configuring advanced policy-based routing. What should you do to solve the problem?
APBRforwarding instancerouting instance typeRIB group