Juniper JN0-696 - Juniper Networks Certified Support Professional Security (JNCSP-SEC) Exam

Question #11 (Topic: Topic 1)
You recently configured the antivirus feature profile on your Junos device. The security policy is sending traffic for antivirus scanning. However, the traffic is being
blocked and you repeatedly receive the system log message that the scan engine is not ready. You must not allow the traffic to be dropped when the scan engine
is not ready.
Which action will resolve this problem?
A. Configure antivirus trickling to prevent the scan engine from timing out. B. Configure an antivirus file scanning extension list to reduce the number of files for scanning. C. Configure an antivirus fallback option to permit the traffic when the scan engine is not ready. D. Configure an antivirus content size limit to minimize the scanning of large files.
Answer: C
Question #12 (Topic: Topic 1)
You are troubleshooting a problem on your Junos device where the antispam SBL server is no longer filtering known spam hosts. You notice that local list
antispam filtering is still working for known spam hosts.
What would cause this problem?
A. You have configured the sbl-default-server parameter in the antispam feature profile. B. DNS has stopped working on your Junos device. C. The antispam license has expired on your Junos device. D. The default spam-action parameter has been set to permit.
Answer: C
Question #13 (Topic: Topic 1)
In preparation for future expansion, a user decides to configure a stand-alone SRX Series device for chassis-clustering mode. The user enters the command set
chassis cluster cluster-id 0 node 0 reboot on the device. After the device reboots, the user sees this output:
user@host> show chassis cluster status
error: Chassis cluster is not enabled.
user@host>
The device does not enter chassis-clustering mode.
What is the problem?
A. An SRX Series device will not enter chassis-clustering mode unless the fxp0 and fxp1 interfaces are defined in the configuration. B. An SRX Series device will only enter chassis-clustering mode when it finds a peer that is also configured for chassis-clustering mode. C. Cluster ID 0 is not valid for a chassis cluster. D. Node ID 0 is not valid for a chassis cluster.
Answer: C
Question #14 (Topic: Topic 1)
-- Exhibit â€"
[Juniper-JN0-696-1.0/xmlfile-10_1.png]
-- Exhibit --
Click the Exhibit button.
You are troubleshooting a communication problem between a trust zone and an untrust zone in the network, where PC-1 cannot ping PC-2.
Referring to the exhibit, which configuration change on SRX-1 would resolve this problem?
A. Configure proxy-arp under the [edit security nat] hierarchy. B. Add a security policy to allow ICMP traffic from the trust zone to the untrust zone. C. Add an address book entry for address 70.1.1.2. D. Add a security policy to allow ICMP traffic from the untrust zone to the trust zone.
Answer: A
Question #15 (Topic: Topic 1)
-- Exhibit â€"
[Juniper-JN0-696-1.0/xmlfile-12_1.png]
-- Exhibit --
Click the Exhibit button.
Referring to the exhibit, PC-1 is unable to ping Server-1. Traffic from PC-1 to Server-1 arrives on interface fe-0/0/3 but return traffic from Server-1 to PC-1 should
be sent out from interface fe-0/0/2.
What would you change on SRX-1 to resolve this problem?
A. Configure a security policy to allow traffic from the DMZ zone to the untrust-1 zone. B. Configure a security policy to allow traffic from the DMZ zone to the untrust-2 zone. C. Move both interface fe-0/0/2 and fe-0/0/3 to the same security zone. D. Disable TCP SYN check and TCP sequence check.
Answer: C
Download Exam
Page: 3 / 15
Total 71 questions