The SRX device receives a packet and determines that it does not match an existing session.After SCREEN options are evaluated, what is evaluated next?()
第1题:
A user wants to establish an HTTP session to a server behind an SRX device but is being pointed to Web page on the SRX device for additional authentication.Which type of user authentication is configured?()
A. pass-through with Web redirect
B. WebAuth with HTTP redirect
C. WebAuth
D. pass-through
第2题:
You are configuring an active/passive cluster of SRX Series devices as the firewall enforcer on a MAG Series device.Which statement is true?()
第3题:
Overlay Transport Virtualization (OTV) overlay interface is a logical multiaccess and multicast- capable interface that must be explicitly defined by the user and where the entire OTV configuration is applied. Which statements are true about OTV overlay interface?()
第4题:
When an SRX series device receives an ESP packet, what happens?()
第5题:
Which statement is true about SurfControl integrated Web filter solution?()
第6题:
Multiple Infranet Enforcer instances are created with a single serial number of an SRX Series device defined in each configuration.
A single Infranet Enforcer instance is created with both serial numbers of the clustered SRX Series devices defined in the configuration.
Multiple Infranet Enforcer instances are created with a single IP address of an SRX Series device defined in each configuration.
A single Infranet enforcer instance is created with the VIP of the clustered SRX Series device defined in the configuration.
第7题:
If the destination address of the outer IP header of the ESP packet matches the IP address of the ingress interface, it will
If the destination IP address in the outer IP header of ESP does not match the IP address of the ingress interface, it will
If the destination address of the outer IP header of the ESP packet matches the IP address of the ingress interface, based packet.
If the destination address of the outer IP header of the ESP packet matches the IP address of the ingress interface, based of inner header, it will decrypt the packet.
第8题:
source NAT
destination NAT
route lookup
zone lookup
第9题:
forwards the packet
fragments the packet
drops the packet silently
drops the packet and sends an ICMP message
第10题:
pass-through
WebAuth
WebAuth with Web redirect
pass-through with Web redirect
第11题:
The receiver acknowledges the final packet in each communications stream.
The receiver adds sequencing numbers to the packets received.
The sender adds sequencing numbers to the packets it sends.
The receiver acknowledges each packet it receives from the sending device.
第12题:
Forward the packet.
Fragment the packet.
Drop the packet silently.
Drop the packet and send an ICMPv6 message.
第13题:
A. The receiver acknowledges the final packet in each communications stream.
B. The receiver adds sequencing numbers to the packets received.
C. The sender adds sequencing numbers to the packets it sends.
D. The receiver acknowledges each packet it receives from the sending device.
第14题:
Which two statements are true about TCP communication?()
第15题:
The same Web site is visited for the second time using a branch SRX Series Services Gateway configured with SurfControl integrated Web filtering.Which statement is true?()
第16题:
You are performing the initial setup of a new MAG Series device and have installed a valid CA- signed certificate on the MAG Series device. Connectivity to an existing SRX Series firewall enforcer cannot be obtained.What are two explanations for this behavior?()
第17题:
The SRX Series device has been configured correctly, the Junos Pulse Access Control Service is reachable on the network, and the SRX Series device is waiting to receive the initial connection from the Junos Pulse Access Control Service.
The SRX Series device has confirmed that the Junos Pulse Access Control Service is configured and is reachable on the network, the SRX Series device is waiting to receive the connection from the Junos Pulse Access Control Service, and all that remains to be accomplished is to configure the SRX Series device.
The SRX Series device is configured correctly and connected to the Junos Pulse Access Control Service. All that remains to be done to complete the configuration is to configure the SRX Series device on the Junos Pulse Access Control Service.
Both the Junos Pulse Access Control Service and the SRX Series device are configured correctly and communicating with each other.
第18题:
The server sending the e-mail to the SRX Series device is a known open SMTP relay.
The server sending the e-mail to the SRX Series device is running unknown SMTP server software.
The server sending the e-mail to the SRX Series device is on an IP address range that is known to be dynamically assigned.
The e-mail that the server is sending to the SRX Series device has a virus in its attachment.
The server sending the e-mail to the SRX Series device is a known spammer IP address.
第19题:
The Websense redirect Web filter solution does not require a license on the SRX device.
The Websense server provides the SRX device with a category for the URL and the SRX device then matches the category decides to permit or deny the URL.
The Websense server provides the SRX device with a decision as to whether the SRX device permits or denies the URL.
When the Websense server does not know the category of the URL, it sends a request back to the SRX device SurfControl server in the cloud.
第20题:
The cluster VIP is defined on the MAG4610 cluster, and the VIP of the cluster is defined as an instance on the SRX Series device.
The cluster VIP is not defined on the MAG4610 cluster, and the IP address of both the active and passive nodes of the cluster are defined as separate instances on the SRX Series device.
The cluster VIP is defined on the MAG4610 cluster, and the IP address of the active node is defined as an instance on the SRX Series device.
The cluster VIP is not defined on the MAG4610 cluster, and the IP address of the passive node is defined as an instance on the SRX Series device.
第21题:
The MAG Series device has multiple ports associated with the certificate.
The MAG Series device's serial number needs to be configured on the SRX Series device.
The SRX Series device must have a certificate signed by the same authority as the MAG Series device.
The MAG Series device and SRX Series device are not synchronized to an NTP server.
第22题:
The SurfControl server in the cloud provides the SRX device with the category of the URL as well as the reputation of the URL.
The SurfControl server in the cloud provides the SRX device with only the category of the URL.
The SurfControl server in the cloud provides the SRX device with only the reputation of the URL.
The SurfControl server in the cloud provides the SRX device with a decision to permit or deny the URL.
第23题:
You must configure a security policy on the SRX Series device to allow traffic to flow from the user devices to the MAG Series device.
No security policy is necessary on the SRX Series device to allow traffic to flow from the user devices to the MAG Series device.
You must configure host-inbound traffic on the SRX Series device to allow SSL traffic between the MAG Series device and the user devices.
You must configure host-inbound traffic on the SRX Series device to allow EAP traffic between the MAG Series device and the user devices.
第24题:
The SRX device sends the URL to the SurfControl server in the cloud and the SurfControl server provides the SRX.
The SRX device sends the URL to the SurfControl server in the cloud and the SurfControl server asks the SRX device previously visited.
The SRX device looks at its local cache to find the category of the URL.
The SRX device does not perform any Web filtering operation as the Web site has already been visited.