Ensurepass.com : Ensure you pass the IT Exams
2018 Jan Juniper Official New Released JN0-360
100% Free Download! 100% Pass Guaranteed!
http://www.EnsurePass.com/JN0-360.html
Juniper Networks Certified Internet Specialist, SEC (JNCIS-SEC)
Question No: 331 – (Topic 4)
While reviewing the logs on your SRX240 device, you notice SYN floods coming from multiple hosts out on the Internet.
Which Junos Screen option would protect against these denial-of-service (DoS) attacks?
-
[edit security screen] user@host# show
ids-option no-flood { limit-session {
destination-ip-based 150;
}
}
-
[edit security screen] user@host# show
ids-option no-flood {
tcp { syn-fin;
}
}
-
[edit security screen] user@host# show
ids-option no-flood { limit-session {
source-ip-based 150;
}
}
-
[edit security screen] user@host# show
ids-option no-flood { icmp {
flood threshold 10;
}
}
Answer: A
Question No: 332 – (Topic 4)
Click the Exhibit button.
Your network management station has generated an alarm regarding NAT utilization based on an SNMP trap received from an SRX Series device.
Referring to the exhibit, which statement is correct about the alarm?
-
The network management station will require manual intervention to clear the alarm.
-
Once utilization is below 40 percent, the Junos OS will send an SNMP trap to the network management station to clear the alarm.
-
Once utilization is below 50 percent, the Junos OS will send an SNMP trap to the network management station to clear the alarm.
-
Once utilization is below 80 percent, the Junos OS will send an SNMP trap to the network management station to clear the alarm.
Answer: B
Question No: 333 – (Topic 4)
A security association is uniquely identified by which two values? (Choose two.)
-
security parameter index value
-
security association ID
-
tunnel source address
-
security protocol
Answer: A,D
Question No: 334 – (Topic 4)
You want to enable local logging for security policies and have the log information stored in a separate file on a branch SRX Series device.
Which configuration will accomplish this task?
-
[edit system syslog] user@host# show
file sec-pol-log { user info;
}
-
[edit system syslog] user@host# show host 192.168.1.1 { user info;
}
-
[edit system syslog] user@host# show
file sec-pol-log { any any;
}
-
[edit system syslog] user@host# show
file sec-pol-log { security info;
}
Answer: A
Question No: 335 – (Topic 4)
Click the Exhibit button.
Referring to the exhibit, which three statements are correct? (Choose three.)
-
Source NAT is configured.
-
Address shifting is configured.
-
Interface-based NAT is configured.
-
Pool-based NAT is configured.
-
IPv6 is configured to bypass NAT.
Answer: A,C,E
Question No: 336 – (Topic 4)
You must create a security policy for a custom application that requires a longer session timeout than the default application offers.
Which two actions are valid? (Choose two.)
-
Set the timeout value in the security forwarding-options section of the CLI.
-
Set the timeout value for the application in the security zone configuration.
-
Alter a built-in application and set the timeout value under the application-protocol section of the CLI.
-
Create a custom application and set the timeout value under the application-protocol section of the CLI.
Answer: C,D
Question No: 337 – (Topic 4)
You want to show interface-specific zone information and statistics. Which operational command would be used to accomplish this?
-
show security zones detail
-
show interfaces ge-0/0/3.0
-
show interfaces terse
-
show interfaces ge-0/0/3.0 extensive
Answer: D
Question No: 338 – (Topic 4)
Click the Exhibit button.
You have created an IPsec VPN on an SRX Series device. You believe the tunnel is configured correctly, but traffic from a host with the IP address of 10.12.1.10 cannot reach a remote device over the tunnel with an IP address of 10.128.64.132. The ge-0/0/1.0 interface is in the trust zone and the st0.0 interface is in the vpn zone. The output of four show commands is shown in the exhibit.
What is the configuration problem with the tunnel?
-
Only one IKE tunnel exists so there is no path for return IKE traffic. You need to allow IKE inbound on interface ge-0/0/0.0.
-
Because there are no IPsec security associations, the problem is in the IPsec proposal settings.
-
The static route created to reach the remote host is incorrect.
-
The VPN settings are correct, the traffic is being blocked by a security policy.
Answer: C
Question No: 339 – (Topic 4)
An engineer has just created a single policy allowing ping traffic from a host in the Users zone to a server in the Servers zone.
When the host pings the server, what will happen to the return traffic?
-
The return traffic will match the session and will be permitted.
-
The return traffic will match the new policy and will be permitted.
-
The return traffic will not be permitted; it will need a separate policy.
-
The return traffic will not be permitted; it will match the system default policy.
Answer: A
Question No: 340 – (Topic 4)
Which two statements are true about the SYN cookie Junos Screen option? (Choose two.)
-
The SYN cookie mechanism is stateless; therefore, the initial three-way handshake can complete before a session table entry is completed.
-
The SRX device will implement the SYN cookie mechanism on all connections once SYN cookies are enabled.
-
The SYN cookie mechanism uses a cryptographic hash, which can detect spoofed source addresses.
-
SYN cookie protection can stop UDP floods as well as TCP floods.
Answer: A,C
100% Ensurepass Free Download!
–Download Free Demo:JN0-360 Demo PDF
100% Ensurepass Free Guaranteed!
–JN0-360 Dumps
EnsurePass | ExamCollection | Testking | |
---|---|---|---|
Lowest Price Guarantee | Yes | No | No |
Up-to-Dated | Yes | No | No |
Real Questions | Yes | No | No |
Explanation | Yes | No | No |
PDF VCE | Yes | No | No |
Free VCE Simulator | Yes | No | No |
Instant Download | Yes | No | No |
100-105 Dumps VCE PDF
200-105 Dumps VCE PDF
300-101 Dumps VCE PDF
300-115 Dumps VCE PDF
300-135 Dumps VCE PDF
300-320 Dumps VCE PDF
400-101 Dumps VCE PDF
640-911 Dumps VCE PDF
640-916 Dumps VCE PDF
70-410 Dumps VCE PDF
70-411 Dumps VCE PDF
70-412 Dumps VCE PDF
70-413 Dumps VCE PDF
70-414 Dumps VCE PDF
70-417 Dumps VCE PDF
70-461 Dumps VCE PDF
70-462 Dumps VCE PDF
70-463 Dumps VCE PDF
70-464 Dumps VCE PDF
70-465 Dumps VCE PDF
70-480 Dumps VCE PDF
70-483 Dumps VCE PDF
70-486 Dumps VCE PDF
70-487 Dumps VCE PDF
220-901 Dumps VCE PDF
220-902 Dumps VCE PDF
N10-006 Dumps VCE PDF
SY0-401 Dumps VCE PDF