[edit security idp]
[edit security zones security-zone trust interfaces ge-0/0/0.0]
[edit security zones security-zone trust]
[edit security screen]
第1题:
A. [edit security idp]
B. [edit security zones security-zone trust interfaces ge-0/0/0.0]
C. [edit security zones security-zone trust]
D. [edit security screen]
第2题:
You want to allow your device to establish OSPF adjacencies with a neighboring device connected to interface ge-0/0/3.0. Interface ge-0/0/3.0 is a member of the HR zone.Under which configuration hierarchy must you permit OSPF traffic?()
A. [edit security policies from-zone HR to-zone HR]
B. [edit security zones functional-zone management protocols]
C. [edit security zones protocol-zone HR host-inbound-traffic]
D. [edit security zones security-zone HR host-inbound-traffic protocols]
第3题:
You want to test a configured screen value prior to deploying.Which statement will allow you to accomplish this?()
第4题:
You want to allow your device to establish OSPF adjacencies with a neighboring device connected tointerface ge-0/0/3.0. Interface ge-0/0/3.0 is a member of the HR zone.Under which configuration hierarchy must you permit OSPF traffic?()
第5题:
You want to allow all hosts on interface ge-0/0/0.0 to be able to ping the device’s ge-0/0/0.0 IP address.Where do you configure this functionality?()
第6题:
You are configuring new BGP neighbor and want to view the configuration for the interface ge-0/0/0.42.Which command do you use to achieve this result?()
第7题:
You are required to configure a SCREEN option that enables IP source route option detection.Which twoconfigurations meet this requirement?() (Choose two.)
第8题:
Which two statements are true regarding the system-default security policy [edit security policies default-policy]?()(Choose two.)
第9题:
[edit security]
[edit protocols]
[edit firewall]
[edit policy-options]
第10题:
set security zones management interfaces ge-0/0/0.0
set zones functional-zone management interfaces ge-0/0/0.0
set security zones functional-zone management interfaces ge-0/0/0.0
set security zones functional-zone out-of-band interfaces ge-0/0/0.0
第11题:
[edit access]
[edit security access]
[edit firewall access]
[edit firewall-authentication]
第12题:
Traffic is permitted from the trust zone to the untrust zone.
Intrazone traffic in the trust zone is permitted.
All traffic through the device is denied.
The policy is matched only when no other matching policies are found.
第13题:
A. [edit security]
B. [edit protocols]
C. [edit firewall]
D. [edit policy-options]
第14题:
A.chgrp
B.chuser
C.edit/etc/user
D.edit/etc/security/group
第15题:
You are configuring a new BGP neighbor and want to view the configuration of interface ge-0/0/0.42. Which command do you use to achieve this result?()
第16题:
Under which configuration hierarchy is an access profile configured for firewall user authentication?()
第17题:
At which two levels of the Junos CLI hierarchy is the host-inbound-traffic command configured? ()(Choose two.)
第18题:
Which two statements are true regarding IDP?()
第19题:
You want to create an out-of-band management zone and assign the ge-0/0/0.0 interface to that zone.From the [edit] hierarchy, which command do you use to configure this assignment?()
第20题:
Under which Junos hierarchy level are security policies configured?()
第21题:
IDP can be used in conjunction with other JUNOS Software security features such as SCREEN options,zones, and security policy.
IDP cannot be used in conjunction with other JUNOS Software security features such as SCREEN options, zones, and security policy.
IDP inspects traffic up to the Presentation layer.
IDP inspects traffic up to the Application layer.
第22题:
[edit security screen] user@host# show ids-option protectFromFlood { ip { loose-source-route-option; strict-source-route-option; } }
[edit security screen] user@host# show ids-option protectFromFlood { ip { source-route-option; } }
[edit security screen] user@host# show ids-option protectFromFlood { ip { record-route-option; security-option; } }
[edit security screen] user@host# show ids-option protectFromFlood { ip { strict-source-route-option; record-route-option; } }
第23题:
[edit interfaces]
[edit security zones]
[edit system services]
[edit security interfaces]