Which three functions are provided by JUNOS Software for security platforms?()
第1题:
Which of the following would be BEST to use when identifying HTTP traffic running on TCP port53?()
第2题:
Which statement is true regarding the Junos OS?()
第3题:
Which two statements describe the difference between JUNOS Software for securityplatforms and a traditional router?()
第4题:
You are responsible for increasing the security within the Company LAN. Of the following choices listed below, which is true regarding layer 2 security and mitigation techniques? ()
第5题:
The Company security administrator is concerned with layer 2 network attacks. Which two statements about these attacks are true? ()
第6题:
In JUNOS software, unclassified packets are associated with which forwarding class?()
第7题:
Which two statements are true regarding proxy ARP?()
第8题:
Which three mechanisims support the forwarding plane of a Layer 3 VPN in JUNOS software? ()
第9题:
MPLS LSP
ATM tunnel
GRE tunnel
IPSEC tunnel
L2TPv3 session
第10题:
MAC spoofing attacks allow an attacking device to receive frames intended for a different network host.
Port scanners are the most effective defense against dynamic ARP inspection.
MAC spoofing, in conjunction with ARP snooping, is the most effective counter-measure against reconnaissance attacks that use dynamic ARP inspection (DAI) to determine vulnerable attack points.
Dynamic ARP inspection in conjunction with ARP spoofing can be used to counter DHCP snooping attacks.
DHCP snooping sends unauthorized replies to DHCP queries.
ARP spoofing can be used to redirect traffic to counter dynamic ARP inspection.
None of the other alternatives apply.
第11题:
firewall filters
data encryption
routing protocol authentication
support for BGP path mtu discovery
automatic discovery for IPSEC neighbors
第12题:
Proxy ARP is enabled by default on stand-alone JUNOS security devices.
Proxy ARP is enabled by default on chassis clusters.
JUNOS security devices can forward ARP requests to a remote device when proxy ARP is enabled.
JUNOS security devices can reply to ARP requests intended for a remote device when proxy ARP is enabled
第13题:
Which statement is true regarding proxy ARP?()
第14题:
A traditional router is better suited than a firewall device for which function?()
第15题:
Which three statements are true regarding IDP?()
第16题:
On a Company switch named R1 you configure the following: iparp inspection vlan 10-12, 15 What is the purpose of this global configuration command made on R1?()
第17题:
Which three statements are true about DAI?()
第18题:
Which three JUNOS software features allow for increased security on your network?()
第19题:
Which three functions are provided by the Junos OS for security platforms?()(Choose three.)
第20题:
VPN establishment
stateful ARP lookups
Dynamic ARP inspection
Network Address Translation
inspection of packets at higher levels (Layer 4 and above)
第21题:
Discards ARP packets with invalid IP-to-MAC address bindings on trusted ports
Validates outgoing ARP requests for interfaces configured on VLAN 10, 11, 12, or 15
Intercepts, logs, and discards ARP packets with invalid IP-to-MAC address bindings
Intercepts all ARP requests and responses on trusted ports
None of the other alternatives apply
第22题:
VPN establishment
stateful ARP lookups
Dynamic ARP inspection
Network Address Translation
inspection of packets at higher levels (Layer 4 and above)
第23题:
DAI intercept all ARP packets on untrusted ports
DAI determines the validity of an ARP packet based on the valid MAC address-to-IP address bindings stored in the DHCP Snooping database.
DAI is used to prevent against a DHCP Snooping attack.
DAI forwards all ARP packets received on a trusted interface without any checks.
DAI forwards all ARP packets on untrusted ports.
DAI determines the validity of an ARP packet based on the valid MAC address-to-IP address bindings stored in the CAM table.