Juniper JN0-633 - Juniper Networks Certified Professional Security (JNCIP-SEC) Exam
Page: 2 / 35
Total 175 questions
Question #6 (Topic: )
Which problem is introduced by setting the terminal parameter on an IPS rule?
A. The SRX device will stop IDP processing for future sessions.
B. The SRX device might detect more false positives.
C. The SRX device will terminate the session in which the terminal rule detected the attack.
D. The SRX device might miss attacks.
Answer: D
Question #7 (Topic: )
You have installed a new IPS license on your SRX device and successfully downloaded
the attack signature database. However, when you run the command to install the
database, the database fails to install. What are two reasons for the failure? (Choose two.)
the attack signature database. However, when you run the command to install the
database, the database fails to install. What are two reasons for the failure? (Choose two.)
A. The file system on the SRX device has insufficient free space to install the database.
B. The downloaded signature database is corrupt.
C. The previous version of the database must be uninstalled first.
D. The SRX device does not have the high memory option installed.
Answer: A,B
Question #8 (Topic: )
You have implemented a tunnel in your network using DS-Lite. The tunnel is formed
between one of the SRX devices in your network and a DS-Lite-compatible CPE device in
your customer's network. Which two statements are true about this scenario? (Choose
two.)
between one of the SRX devices in your network and a DS-Lite-compatible CPE device in
your customer's network. Which two statements are true about this scenario? (Choose
two.)
A. The SRX device will serve as the softwire initiator and the customer CPE device will serve as the softwire concentrator.
B. The SRX device will serve as the softwire concentrator and the customer CPE device will serve as the softwire initiator.
C. The infrastructure network supporting the tunnel will be based on IPv4.
D. The infrastructure network supporting the tunnel will be based on IPv6.
Answer: B,D
Question #9 (Topic: )
You are asked to implement the AppFW feature on an SRX Series device.
Which three tasks must be performed to make the feature work? (Choose three.)
Which three tasks must be performed to make the feature work? (Choose three.)
A. Configure a firewall filter that includes the application-firewall policy.
B. Install an IPS license.
C. Install an AppSecure license.
D. Configure a security policy that includes the application-firewall policy.
E. Configure an application-firewall policy.
Answer: C,D,E
Question #10 (Topic: )
What are two network scanning methods? (Choose two.)
A. SYN flood
B. ping of death
C. ping sweep
D. UDP scan
Answer: C,D