認証トレーニングJN0-635試験問題集テストエンジン [2023]
2023年03月12日ガイド準備でJN0-635試験合格
Juniper JN0-635 認定試験の出題範囲:
| トピック | 出題範囲 |
|---|---|
| トピック 1 |
|
| トピック 2 |
|
| トピック 3 |
|
| トピック 4 |
|
| トピック 5 |
|
質問 27
You are connecting two remote sites to your corporate headquarters site; you must ensure that all traffic is secured and only uses a single Phase 2 SA for both sites.
In this scenario, which VPN should be used?
- A. An IPsec group VPN with the corporate firewall acting as the hub device.
- B. Full mesh IPsec VPNs with tunnels between all sites.
- C. A hub-and-spoke IPsec VPN with the corporate firewall acting as the hub device.
- D. A full mesh Layer 3 VPN with the corporate firewall acting as the hub device.
正解: A
解説:
Explanation
https://www.juniper.net/us/en/local/pdf/app-notes/3500202-en.pdf
質問 28
Which two statements are true about ADVPN members? (Choose two.)
- A. ADVPN members are authenticated using pre-shared keys
- B. ADVPN members can use IKEv2
- C. ADVPN members are authenticated using certificates
- D. ADVPN members can use IKEv1
正解: B,C
質問 29
Which two VPN features are supported with CoS-based IPsec VPNs? (Choose two.)
- A. dead peer detection
- B. VPN monitoring
- C. IKEv2
- D. IKEv1
正解: A,C
解説:
https://www.juniper.net/documentation/en_US/junos/topics/topic-map/secuirty-cos-based-ipsec- vpns.html
質問 30
Click the Exhibit button.
Branch 1 and Branch 2 have an active VPN tunnel configured, but internal hosts cannot communicate with each other.
Referring to the exhibit, which type of configuration should be applied to solve the problem?
- A. Configure source NAT on Branch 1
- B. Configure destination NAT on both Branch 1 and Branch 2
- C. Configure static NAT on both Branch 1 and Branch 2
- D. Configure destination NAT on Branch 2 only
正解: C
質問 31
Click the Exhibit button.
You deployed a site-to-site IPsec VPN connecting two data centers together using SRX5800s. After examining the performance of the IPsec VPN, you decide to enable IPsec performance acceleration to increase the rate of traffic that can be sent through the tunnel.
Referring to the exhibit, which two statements should you add to the configuration to accomplish this task?
(Choose two.)
- A. [edit security flow]
user@srx# set tcp-mss ipsec-vpn mss 65535 - B. [edit security flow]
user@srx# set load-distribution session-affinity ipsec - C. [edit security flow]
user@srx# set ipsec-performance-acceleration - D. [edit security flow]
user@srx# set power-mode-ipsec
正解: B,C
質問 32
Click the Exhibit button.
Referring to the exhibit, which statement is true?
- A. Destination NAT is occurring
- B. Static NAT without PAT is occurring
- C. Source NAT with PAT is occurring
- D. Source NAT without PAT is occurring
正解: C
質問 33
Click the Exhibit button.
Referring to the exhibit, you are attempting to enable IPsec power mode to improve IPsec VPN performance.
However, you are unable to use IPsec power mode.
What is the problem?
- A. IPsec power mode cannot be used with IPsec performance acceleration
- B. IPsec power mode requires that you configure a policy-based VPN
- C. IPsec power mode cannot be used with advanced services
- D. IPsec power mode cannot be used with high IPsec maximum segment size values
正解: C
質問 34
Malware that is detonated by the JATP sandbox must be able to communicate with the Internet without being able to harm your local network resources.
Which statement is correct in this scenario?
- A. The management interface must be connected to the Internet zone
- B. The honeypot interface must be connected to the Internet zone
- C. The exhaust interface must be connected to the Internet zone
- D. The monitoring interface must be connected to the Internet zone
正解: A
解説:
https://www.juniper.net/documentation/en_US/release-independent/jatp/topics/topic-map/jatp- getting-started.html
質問 35
Which interface family is required for Layer 2 transparent mode on SRX Series devices?
- A. VPLS
- B. Ethernet switching
- C. inet
- D. LLDP
正解: B
質問 36
Click the Exhibit button.
You have enabled mixed mode on an SRX Series device.
You are unable to commit the configuration shown in the exhibit.
What is the problem in this scenario?
- A. STP is not enabled under the host-inbound-traffic system services hierarchy on the trust and protected security zones.
- B. A Layer 3 interface has not been configured on VLAN v10.
- C. The trust zone cannot contain both Layer 2 and Layer 3 interfaces.
- D. An IRB interface has not been configured.
正解: C
質問 37
Your organization has multiple Active Directory domain to control user access. You must ensure that security polices are passing traffic based upon the user's access rights.
What would you use to assist your SRX series devices to accomplish this task?
- A. JIMS
- B. JSA
- C. JATP Appliance
- D. Junos Space
正解: A
解説:
Explanation
https://www.juniper.net/documentation/en_US/junos/topics/topic-map/security-user-auth-configure-jims.html
質問 38
You are not able to activate the SSH honeypot on the all-in-one Juniper ATP appliance.
What would be a cause of this problem?
- A. The collector must have a minimum of three interfaces.
- B. The collector must have a minimum of two interfaces.
- C. The collector must have a minimum of five interfaces.
- D. The collector must have a minimum of four interfaces.
正解: D
解説:
Reference:
https://www.juniper.net/documentation/en_US/release-independent/jatp/topics/task/configuration/jatp-traffic-collectorsetting-ssh-honeypot-detection.html
質問 39
Which three types of peer devices are supported for CoS-based IPsec VPNs? (Choose three.)
- A. vSRX
- B. cSRX
- C. third-party device
- D. branch SRX Series device
- E. high-end SRX Series device
正解: A,D,E
質問 40
Using the Policy Controller API, which configuration would post Sky ATP with PE mode to the Policy Enforcer controller configuration?
- A. "configs": {"sdsn": true"cloudonly": false}
- B. "configs": {"sdsn": false"cloudonly": true}
- C. "configs": {"sdsn": false"cloud": true}
- D. "configs": {"sdsn": false"cloud": false}
正解: A
質問 41
Click the Exhibit button.
Referring to the exhibit, which statement is true?
- A. Destination NAT is occurring
- B. Static NAT without PAT is occurring
- C. Source NAT with PAT is occurring
- D. Source NAT without PAT is occurring
正解: C
解説:
Explanation/Reference:
質問 42
Click the Exhibit button.
Referring to the exhibit, which three types of traffic would be examined by the IPS policy between Switch-1 and Switch-2? (Choose three.)
- A. ARP
- B. TCP
- C. UDP
- D. ICMP
- E. LLDP
正解: B,C,D
質問 43
......
究極のガイドJN0-635認証試験準備Junos Security:https://www.passtest.jp/Juniper/JN0-635-shiken.html