[Q27-Q43] 認証トレーニングJN0-635試験問題集テストエンジン [2023]

Share

認証トレーニングJN0-635試験問題集テストエンジン [2023]

2023年03月12日ガイド準備でJN0-635試験合格


Juniper JN0-635 認定試験の出題範囲:

トピック出題範囲
トピック 1
  • ジュニパーATP
  • リモートアクセスVPN
  • IPsecを使用したルーティング
  • 動的ゲートウェイを構成または監視する方法を示します
トピック 2
  • レイヤー2のセキュリティ
  • マルウェアの識別または軽減を構成または監視する方法を示します
  • 論理システムの概念、操作、または機能を説明します
トピック 3
  • 脅威軽減
  • 高度なネットワークアドレス変換の概念、操作、または機能を説明する
トピック 4
  • Juniper ATPの概念、操作、または機能を説明する
  • ファイアウォールフィルターを構成、トラブルシューティング、または監視する方法を示す
トピック 5
  • 高度なNAT機能
  • 高度な脅威保護の概念、操作、または機能

 

質問 27
You are connecting two remote sites to your corporate headquarters site; you must ensure that all traffic is secured and only uses a single Phase 2 SA for both sites.
In this scenario, which VPN should be used?

  • A. An IPsec group VPN with the corporate firewall acting as the hub device.
  • B. Full mesh IPsec VPNs with tunnels between all sites.
  • C. A hub-and-spoke IPsec VPN with the corporate firewall acting as the hub device.
  • D. A full mesh Layer 3 VPN with the corporate firewall acting as the hub device.

正解: A

解説:
Explanation
https://www.juniper.net/us/en/local/pdf/app-notes/3500202-en.pdf

 

質問 28
Which two statements are true about ADVPN members? (Choose two.)

  • A. ADVPN members are authenticated using pre-shared keys
  • B. ADVPN members can use IKEv2
  • C. ADVPN members are authenticated using certificates
  • D. ADVPN members can use IKEv1

正解: B,C

 

質問 29
Which two VPN features are supported with CoS-based IPsec VPNs? (Choose two.)

  • A. dead peer detection
  • B. VPN monitoring
  • C. IKEv2
  • D. IKEv1

正解: A,C

解説:
https://www.juniper.net/documentation/en_US/junos/topics/topic-map/secuirty-cos-based-ipsec- vpns.html

 

質問 30
Click the Exhibit button.

Branch 1 and Branch 2 have an active VPN tunnel configured, but internal hosts cannot communicate with each other.
Referring to the exhibit, which type of configuration should be applied to solve the problem?

  • A. Configure source NAT on Branch 1
  • B. Configure destination NAT on both Branch 1 and Branch 2
  • C. Configure static NAT on both Branch 1 and Branch 2
  • D. Configure destination NAT on Branch 2 only

正解: C

 

質問 31
Click the Exhibit button.

You deployed a site-to-site IPsec VPN connecting two data centers together using SRX5800s. After examining the performance of the IPsec VPN, you decide to enable IPsec performance acceleration to increase the rate of traffic that can be sent through the tunnel.
Referring to the exhibit, which two statements should you add to the configuration to accomplish this task?
(Choose two.)

  • A. [edit security flow]
    user@srx# set tcp-mss ipsec-vpn mss 65535
  • B. [edit security flow]
    user@srx# set load-distribution session-affinity ipsec
  • C. [edit security flow]
    user@srx# set ipsec-performance-acceleration
  • D. [edit security flow]
    user@srx# set power-mode-ipsec

正解: B,C

 

質問 32
Click the Exhibit button.

Referring to the exhibit, which statement is true?

  • A. Destination NAT is occurring
  • B. Static NAT without PAT is occurring
  • C. Source NAT with PAT is occurring
  • D. Source NAT without PAT is occurring

正解: C

 

質問 33
Click the Exhibit button.

Referring to the exhibit, you are attempting to enable IPsec power mode to improve IPsec VPN performance.
However, you are unable to use IPsec power mode.
What is the problem?

  • A. IPsec power mode cannot be used with IPsec performance acceleration
  • B. IPsec power mode requires that you configure a policy-based VPN
  • C. IPsec power mode cannot be used with advanced services
  • D. IPsec power mode cannot be used with high IPsec maximum segment size values

正解: C

 

質問 34
Malware that is detonated by the JATP sandbox must be able to communicate with the Internet without being able to harm your local network resources.
Which statement is correct in this scenario?

  • A. The management interface must be connected to the Internet zone
  • B. The honeypot interface must be connected to the Internet zone
  • C. The exhaust interface must be connected to the Internet zone
  • D. The monitoring interface must be connected to the Internet zone

正解: A

解説:
https://www.juniper.net/documentation/en_US/release-independent/jatp/topics/topic-map/jatp- getting-started.html

 

質問 35
Which interface family is required for Layer 2 transparent mode on SRX Series devices?

  • A. VPLS
  • B. Ethernet switching
  • C. inet
  • D. LLDP

正解: B

 

質問 36
Click the Exhibit button.

You have enabled mixed mode on an SRX Series device.
You are unable to commit the configuration shown in the exhibit.
What is the problem in this scenario?

  • A. STP is not enabled under the host-inbound-traffic system services hierarchy on the trust and protected security zones.
  • B. A Layer 3 interface has not been configured on VLAN v10.
  • C. The trust zone cannot contain both Layer 2 and Layer 3 interfaces.
  • D. An IRB interface has not been configured.

正解: C

 

質問 37
Your organization has multiple Active Directory domain to control user access. You must ensure that security polices are passing traffic based upon the user's access rights.
What would you use to assist your SRX series devices to accomplish this task?

  • A. JIMS
  • B. JSA
  • C. JATP Appliance
  • D. Junos Space

正解: A

解説:
Explanation
https://www.juniper.net/documentation/en_US/junos/topics/topic-map/security-user-auth-configure-jims.html

 

質問 38
You are not able to activate the SSH honeypot on the all-in-one Juniper ATP appliance.
What would be a cause of this problem?

  • A. The collector must have a minimum of three interfaces.
  • B. The collector must have a minimum of two interfaces.
  • C. The collector must have a minimum of five interfaces.
  • D. The collector must have a minimum of four interfaces.

正解: D

解説:
Reference:
https://www.juniper.net/documentation/en_US/release-independent/jatp/topics/task/configuration/jatp-traffic-collectorsetting-ssh-honeypot-detection.html

 

質問 39
Which three types of peer devices are supported for CoS-based IPsec VPNs? (Choose three.)

  • A. vSRX
  • B. cSRX
  • C. third-party device
  • D. branch SRX Series device
  • E. high-end SRX Series device

正解: A,D,E

 

質問 40
Using the Policy Controller API, which configuration would post Sky ATP with PE mode to the Policy Enforcer controller configuration?

  • A. "configs": {"sdsn": true"cloudonly": false}
  • B. "configs": {"sdsn": false"cloudonly": true}
  • C. "configs": {"sdsn": false"cloud": true}
  • D. "configs": {"sdsn": false"cloud": false}

正解: A

 

質問 41
Click the Exhibit button.

Referring to the exhibit, which statement is true?

  • A. Destination NAT is occurring
  • B. Static NAT without PAT is occurring
  • C. Source NAT with PAT is occurring
  • D. Source NAT without PAT is occurring

正解: C

解説:
Explanation/Reference:

 

質問 42
Click the Exhibit button.

Referring to the exhibit, which three types of traffic would be examined by the IPS policy between Switch-1 and Switch-2? (Choose three.)

  • A. ARP
  • B. TCP
  • C. UDP
  • D. ICMP
  • E. LLDP

正解: B,C,D

 

質問 43
......

究極のガイドJN0-635認証試験準備Junos Security:https://www.passtest.jp/Juniper/JN0-635-shiken.html