Juniper JN0-633 - Juniper Networks Certified Professional Security (JNCIP-SEC) Exam

Question #11 (Topic: )
Which two are required for the SRX device to perform DNS doctoring? (Choose two.)
A. DNS ALG B. dns-doctoring stanza C. name-server D. static NAT
Answer: A,D
Question #12 (Topic: )
You have recently deployed a dynamic VPN. Some remote users are complaining that they
cannot authenticate through the SRX device at the corporate network. The SRX device
serves as the tunnel endpoint for the dynamic VPN. What are two reasons for this
problem? (Choose two.)
A. The supported number of users has been exceeded for the applied license. B. The users are connecting to the portal using Windows Vista. C. The SRX device does not have the required user account definitions. D. The SRX device does not have the required access profile definitions.
Answer: A,D
Question #13 (Topic: )
You want to configure in-band management of an SRX device in transparent mode.
Which command is required to enable this functionality?
A. set interfaces irb unit 1 family inet address B. set interfaces vlan unit 1 family inet address C. set interfaces ge-0/0/0 unit 0 family inet address D. set interfaces ge-0/0/0 unit 0 family bridge address
Answer: A
Question #14 (Topic: )
Click the Exhibit button.
-- Exhibit --
security {
nat {
destination {
pool Web-Server {
address 10.0.1.5/32;
rule-set From-Internet {
from zone Untrust;
rule To-Web-Server {
match {
source-address 0.0.0.0/0;
destination-address 172.16.1.7/32;
then {
destination-nat pool Web-Server;
zones {
security-zone Untrust {
address-book {
address Web-Server-External 172.16.1.7/32;
address Web-Server-Internal 10.0.1.5/32;
interfaces {
ge-0/0/0.0;
security-zone DMZ {
address-book {
address Web-Server-External 172.16.1.7/32;
address Web-Server-Internal 10.0.1.5/32;
interfaces {
ge-0/0/1.0;
-- Exhibit --
You are migrating from one external address block to a different external address block.
You want to enable a smooth transition to the new address block. You temporarily want to
allow external users to contact the Web server using both the existing external address as
well as the new external address 192.168.1.1.
How do you accomplish this goal?
A. Add address 192.168.1.1/32 under [edit security nat destination pool Web-Server]. B. Change the address Web-Server-Ext objects to be address-set objects that include both addresses. C. Change the destination address under [edit security nat destination rule-set From- Internet rule To-Web-Server match] to include both 172.16.1.7/32 and 192.168.1.2/32. D. Create a new rule for the new address in the [edit security nat destination rule-set From- Internet] hierarchy.
Answer: D
Question #15 (Topic: )
Click the Exhibit button.
-- Exhibit
[Juniper-JN0-633-1, VPN: to-spoke-2 Gateway: spoke-2, Local:/Juniper-JN0-633-11_2.png]
-- Exhibit --
Referring to the exhibit, the application firewall configuration fails to commit.
What must you do to allow the configuration to commit?
A. Each firewall rule set must only have one rule. B. A firewall rule set cannot mix dynamic applications and dynamic application groups. C. The action in the rules must be different than the action in the default rule. D. The action in the default rule must be set to deny.
Answer: C
Download Exam
Page: 3 / 35
Total 175 questions