You need to generate a certificate for a PKI-based site-to-site VPN. The peer is expecting to
user your domain name vpn.juniper.net.
Which two configuration elements are required when you generate your certificate request? (Chose two,)
In a multinode HA environment, which service must be configured to synchronize between nodes?
Your customer needs embedded security in an EVPN-VXLAN solution.
What are two benefits of adding an SRX Series device in this scenario? (Choose two.)
You want to deploy two vSRX instances in different public cloud providers to provide redundant security services for your network. Layer 2 connectivity between the two vSRX instances is not possible.
What would you configure on the vSRX instances to accomplish this task?
You Implement persistent NAT to allow any device on the external side of the firewall to
initiate traffic.
Referring to the exhibit, which statement is correct?
What are three attributes that APBR queries from the application system cache module. (Choose Three)
Click the Exhibit button.
Referring to the exhibit, which three actions do you need to take to isolate the hosts at the switch port level if they become infected with malware? (Choose three.)
Which two statements are correct about DNS doctoring?
Referring to the exhibit, which two statements are true ?
Referring to the exhibit, you are assigned the tenantSYS1 user credentials on an SRX series
device.
In this scenario, which two statements are correct? (Choose two.)
Exhibit:
Which two statements are correct about the output shown in the exhibit. (Choose Two)
A customer wants to be able to initiate a return connection to an internal host from a specific
Server.
Which NAT feature would you use in this scenario?
You configure two Ethernet interfaces on your SRX Series device as Layer 2 interfaces and add them to the same VLAN. The SRX is using the default L2-learning setting. You do not add the interfaces to a security zone.
Which two statements are true in this scenario? (Choose two.)
You want to test how the device handles a theoretical session without generating traffic on the Junos security device.
Which command is used in this scenario?
You are attempting to ping an interface on your SRX Series device, but the ping is unsuccessful.
What are three reasons for this behavior? (Choose three.)
You have deployed an SRX Series device at your network edge to secure Internet-bound sessions for your local hosts using source NAT. You want to ensure that your users are able to interact with applications on the Internet that require more than one TCP session for the same application session.
Which two features would satisfy this requirement? (Choose two.)
You are configuring an interconnect logical system that is configured as a VPLS switch to allow two logical systems to communicate.
Which two parameters are required when configuring the logical tunnel interfaces? (Choose two.)
Which two statements are true when setting up an SRX Series device to operate in mixed mode? (Choose two.)
Exhibit:
Referring to the exhibit, which two statements are true? (Choose two.)
Click the Exhibit button.
Referring to the exhibit, which two statements are correct? (Choose two.)
Referring to the exhibit,
which two statements about User1 are true? (Choose two.)
Referring to the exhibit,
which three statements about the multinode HA environment are true? (Choose three.)
A company has acquired a new branch office that has the same address space as one of its local networks, 192.168.100.0/24. The offices need to communicate with each other.
Which two NAT configurations will satisfy this requirement? (Choose two.)
You are asked to see if your persistent NAT binding table is exhausted.
Which show command would you use to accomplish this task?
Exhibit:
You are asked to ensure that Internet users can access the company's internal webserver using its FQDN. However, the internal DNS server's A record only points to the webserver's private address.
Referring to the exhibit, which two actions are required to complete this task? (Choose two.)
Click the Exhibit button.
You have configured a CoS-based VPN that is not functioning correctly.
Referring to the exhibit, which action will solve the problem?
Referring to the exhibit, you are attempting to set up a remote access VPN on your SRX series devices.
However you are unsure of which system services you should allow and in which zones they should be allowed to correctly finish the remote access VPN configuration
Which two statements are correct? (Choose two.)
You are using ADVPN to deploy a hub-and-spoke VPN to connect your enterprise sites.
Which two statements are true in this scenario? (Choose two.)
You want to enable transparent mode on your SRX series device.
In this scenario, which three actions should you perform? (Choose three.)
You are deploying IPsec VPNs to securely connect several enterprise sites with ospf for dynamic
routing. Some of these sites are secured by third-party devices not running Junos.
Which two statements are true for this deployment? (Choose two.)
Which two statements about the differences between chassis cluster and multinode HA on
SRX series devices are true? (Choose Two)
You are attempting to ping the IP address that is assigned to the loopback interface on the
SRX series device shown in the exhibit.
What is causing this problem?
Which two statements are correct about advanced policy-based routing?
Exhibit:
You have deployed a pair of SRX series devices in a multimode HA environment. You need to enable IPsec encryption on the interchassis link.
Referring to the exhibit, which three steps are required to enable ICL encryption? (Choose three.)