Juniper JN0-332 - Juniper Networks Certified Internet Specialist, SEC (JNCIS-SEC) Exam

Question #11 (Topic: Topic 1)
What are two components of the Junos softwarearchitecture? (Choose two.)
A. Linux kernel B. routing protocol daemon C. session-based forwarding module D. separate routing and security planes
Answer: B,C
Question #12 (Topic: Topic 1)
A network administrator wants to permit Telnet traffic initiated from the address book entry
the10net in a zone called UNTRUST to the address book entry Server in a zone called
TRUST. However, the administrator does not want the server to be able to initiate any type
of traffic from the TRUST zone to the UNTRUST zone.Which configuration statement
would correctly accomplish this task?
A. from-zone UNTRUST to-zone TRUST { policy DenyServer { match { source-address any; destination-address any; application any; } then { deny; } } } from-zone TRUST to-zone UNTRUST { policy AllowTelnetin { match { source-address the10net; destination-address Server; application junos-telnet; } then { permit; } } } B. from-zone TRUST to-zone UNTRUST { policy DenyServer { match { source-address Server; destination-address any; application any; } then { deny; } } } from-zone UNTRUST to-zone TRUST { policy AllowTelnetin { match { source-address the10net; destination-address Server; application junos-telnet; } then { permit; } } } C. from-zone UNTRUST to-zone TRUST { policy AllowTelnetin { match { source-address the10net; destination-address Server; application junos-ftp; } then { permit; } } } D. from-zone TRUST to-zone UNTRUST { policy DenyServer { match { source-address Server; destination-address any; application any; } then { permit; } } } from-zone UNTRUST to-zone TRUST { policy AllowTelnetin { match { source-address the10net; destination-address Server; application junos-telnet; } then { permit; } } }
Answer: B
Question #13 (Topic: Topic 1)
What is the default session timeout for UDP sessions?
A. 30 seconds B. 1 minute C. 5 minutes D. 30 minutes
Answer: B
Question #14 (Topic: Topic 1)
Click the Exhibit button.
[Juniper-JN0-332-25.0/Juniper-JN0-332-14_2.png]
In the exhibit, you decided to change my Hosts addresses. What will happen to the new
sessions matching the policy and in-progress sessions that hadalready matched the
policy?
A. New sessions will be evaluated. In-progress sessions will be re-evaluated. B. New sessions will be evaluated. All in-progress sessions will continue. C. New sessions will be evaluated. All in-progress sessions will be dropped. D. New sessions will halt until all in-progress sessions are re-evaluated. In-progress sessions will be re-evaluated and possibly dropped.
Answer: A
Question #15 (Topic: Topic 1)
Click the Exhibit button.
[Juniper-JN0-332-25.0/Juniper-JN0-332-15_2.png]
You need to alter the security policy shown in the exhibit to send matching traffic to an
IPsec VPN tunnel. Which command causes traffic to be sent through anIPsec VPN named
remote-vpn?
A. [edit security policies from-zone trust to-zone untrust] user@host# set policy tunnel-traffic then tunnel remote-vpn B. [edit security policies from-zone trust to-zone untrust] user@host# set policy tunnel-traffic then tunnel ipsec-vpn remote-vpn C. [edit security policies from-zone trust to-zone untrust] user@host# set policy tunnel-traffic then permit ipsec-vpn remote-vpn D. [edit security policies from-zone trust to-zone untrust] user@host# set policy tunnel-traffic then permit tunnel ipsec-vpn remote-vpn
Answer: D
Download Exam
Page: 3 / 104
Total 517 questions