[Free] 2018(Jan) EnsurePass Examcollection Juniper JN0-370 Dumps with VCE and PDF 81-90

Ensurepass.com : Ensure you pass the IT Exams
2018 Jan Juniper Official New Released JN0-370
100% Free Download! 100% Pass Guaranteed!
http://www.EnsurePass.com/JN0-370.html

Juniper Networks Certified Internet Specialist, SEC (JNCIS-SEC)

Question No: 81 – (Topic 1)

Which two statements are true regarding IDP? (Choose two.)

  1. IDP can be used in conjunction with other Junos security features such as SCREEN options, zones, and security policy.

  2. IDP cannot be used in conjunction with other Junos security features such as SCREEN options, zones, and security policy.

  3. IDP inspects traffic up to the Presentation Layer.

  4. IDP inspects traffic up to the Application Layer.

Answer: A,D

Question No: 82 – (Topic 1)

Which two functions of the Junos OS are handled by the data plane? (Choose two.)

  1. NAT

  2. OSPF

  3. SNMP

  4. SCREEN options

Answer: A,D

Question No: 83 – (Topic 1)

Which Web-filtering technology can be used at the same time as integrated Web filtering on a single branch SRX Series device?

  1. Websense redirect Web filtering

  2. local Web filtering (blacklist or whitelist)

  3. firewall user authentication

  4. ICAP

Answer: B

Question No: 84 – (Topic 1)

Which two statements are true about the relationship between static NAT and proxy ARP? (Choose two.)

  1. It is necessary to forward ARP requests to remote hosts.

  2. It is necessary when translated traffic belongs to the same subnet as the ingress interface.

  3. It is not automatic and you must configure it.

  4. It is enabled by default and you do not need to configure it.

Answer: B,C

Question No: 85 – (Topic 1)

Click the Exhibit button.

Ensurepass 2018 PDF and VCE

What are two valid reasons for the output shown inthe exhibit? (Choose two.)

  1. The local Web-filtering daemon is not enabled or is not running.

  2. The integrated Web-filtering policy server is not reachable.

  3. No DNS is configured on the SRX Series device.

  4. No security policy is configured to use Web filtering.

Answer: B,C

Question No: 86 – (Topic 1)

Which three components can be leveraged when defining a local whitelist or blacklist for antispam on a branch SRX Series device? (Choose three.)

  1. spam assassin filtering score

  2. sender country

  3. sender IP address

  4. sender domain

  5. sender e-mail address

Answer: C,D,E

Question No: 87 – (Topic 1)

How many IDP policies can be active at one time on an SRX Series device by means of the set security idp active-policyconfiguration statement?

  1. 1

  2. 2

  3. 4

  4. 8

Answer: A

Question No: 88 – (Topic 1)

Which two statements are true with regard to policy ordering? (Choose two.)

  1. The last policy is the default policy, which allows all traffic.

  2. The order of policies is not important.

  3. New policies are placed at the end of the policy list.

  4. The insert command can be used to change the order.

Answer: C,D

Question No: 89 – (Topic 1)

A network administrator receives complaints from the engineering group that an application on one server is not working properly. After further investigation, the administrator determines that source NAT translation is using a different source address after a random number of flows. Which two actions can the administrator take to force the server to use oneaddress? (Choose two.)

  1. Use the custom application feature.

  2. Configure static NAT for the host.

  3. Use port address translation (PAT).

  4. Use the address-persistent option.

Answer: B,D

Question No: 90 – (Topic 1)

When an SRX series device receives an ESP packet, what happens?

  1. If the destination address of the outer IP header of the ESP packet matches the IP address of the ingress interface, it will immediately decrypt the packet.

  2. If the destination IP address in the outer IP header of ESP does not match the IP address of the ingress interface, it will discard the packet.

  3. If the destination address of the outer IP header of the ESP packet matches the IP address of the ingress interface, based on SPI match, it will decrypt the packet.

  4. If the destination address of the outer IP header of the ESP packet matches the IP address of the ingress interface, based on SPI match and route lookup of inner header, it will decrypt the packet.

Answer: C

100% Ensurepass Free Download!
Download Free Demo:JN0-370 Demo PDF
100% Ensurepass Free Guaranteed!
JN0-370 Dumps

EnsurePass ExamCollection Testking
Lowest Price Guarantee Yes No No
Up-to-Dated Yes No No
Real Questions Yes No No
Explanation Yes No No
PDF VCE Yes No No
Free VCE Simulator Yes No No
Instant Download Yes No No

This entry was posted in JN0-370 Latest Exam (Jan 2018) and tagged , , , , , , , . Bookmark the permalink.

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.