[Free] 2018(Jan) EnsurePass Examcollection Juniper JN0-346 Dumps with VCE and PDF 101-110

Ensurepass.com : Ensure you pass the IT Exams
2018 Jan Juniper Official New Released JN0-346
100% Free Download! 100% Pass Guaranteed!
http://www.EnsurePass.com/JN0-346.html

Juniper Networks Certified Internet Specialist, SEC (JNCIS-SEC)

Question No: 101 – (Topic 2)

Click the Exhibit button.

Ensurepass 2018 PDF and VCE

In the configuration shown in the exhibit, you decided to eliminate the junos-ftp application from the match condition of the policy My Traffic. What will happen to the existing FTP and BGP sessions?

  1. The existing FTP and BGP sessions will continue.

  2. The existing FTP and BGP sessions will be re-evaluated and only FTP sessions will be dropped.

  3. The existing FTP and BGP sessions will be re-evaluated and all sessions will be dropped.

  4. The existing FTP sessions will continue and only the existing BGP sessions will be dropped.

Answer: B

Question No: 102 – (Topic 2)

Which three security concerns can be addressed by a tunnel mode IPsec VPN secured by ESP? (Choose three.)

  1. data integrity

  2. data confidentiality

  3. data authentication

  4. outer IP header confidentiality

  5. outer IP header authentication

Answer: A,B,C

Question No: 103 – (Topic 2)

Which type of Web filtering by default builds a cache of server actions associated with each URL it has checked?

  1. Websense Redirect Web filtering

  2. integrated Web filtering

  3. local Web filtering

  4. enhanced Web filtering

Answer: B

Question No: 104 – (Topic 2)

Which two statements are true for a security policy? (Choose two.)

  1. It controls inter-zone traffic.

  2. It controls intra-zone traffic.

  3. It is named with a system-defined name.

  4. It controls traffic destined to the device#39;s ingress interface.

Answer: A,B

Question No: 105 – (Topic 2)

In the Junos OS, which statement is true?

  1. vlan.0 belongs to the untrust zone.

  2. You must configure Web authentication to allow inbound traffic in the untrust zone.

  3. he zone name untrust has no special meaning

  4. The untrust zone is not configurable.

Answer: C

Question No: 106 – (Topic 2)

When an SRX series device receives an ESP packet, what happens?

  1. If the destination address of the outer IP header of the ESP packet matches the IP address of the ingress interface, it will immediately decrypt the packet.

  2. If the destination IP address in the outer IP header of ESP does not match the IP address of the ingress interface, it will discard the packet.

  3. If the destination address of the outer IP header of the ESP packet matches the IP address of the ingress interface, based on SPI match, it will decrypt the packet.

  4. If the destination address of the outer IP header of the ESP packet matches the IP address of the ingress interface, based on SPI match and route lookup of inner header, it will decrypt the packet.

Answer: C

Question No: 107 – (Topic 2)

Which element occurs first during the first-packet-path processing?

  1. destination NAT

  2. forwarding lookup

  3. route lookup

  4. SCREEN options

Answer: D

Question No: 108 – (Topic 2)

What is the purpose of an address book?

  1. It holds security policies for particular hosts.

  2. It holds statistics about traffic to and from particular hosts.

  3. It defines the hosts in a zone so they can be referenced by policies.

  4. It maps hostnames to IP addresses to serve as a backup to DNS resolution.

Answer: C

Question No: 109 – (Topic 2)

Which two statements are true about the Websense redirect Web filter solution? (Choose two.)

  1. The Websense redirect Web filter solution does not require a license on the SRX device.

  2. The Websense server provides the SRX device with a category for the URL and the SRX device then matches the category with its configured polices and decides to permit or deny the URL.

  3. The Websense server provides the SRX device with a decision as to whether the SRX device permits or denies the URL.

  4. When the Websense server does not know the category of the URL, it sends a request back to the SRX device to validate against the integrated SurfControl server in the cloud.

Answer: A,C

Question No: 110 – (Topic 2)

The Junos OS blocks an HTTP request due to its inclusion on the url-blacklist. Which form of Web filtering on the branch SRX device is fully executed within the device itself?

  1. redirect Web filtering

  2. integrated Web filtering

  3. blacklist Web filtering

  4. local Web filtering

Answer: D

100% Ensurepass Free Download!
Download Free Demo:JN0-346 Demo PDF
100% Ensurepass Free Guaranteed!
JN0-346 Dumps

EnsurePass ExamCollection Testking
Lowest Price Guarantee Yes No No
Up-to-Dated Yes No No
Real Questions Yes No No
Explanation Yes No No
PDF VCE Yes No No
Free VCE Simulator Yes No No
Instant Download Yes No No

This entry was posted in JN0-346 Latest Exam (Jan 2018) and tagged , , , , , , , . Bookmark the permalink.

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.