[Free] 2018(Jan) EnsurePass Examcollection Juniper JN0-643 Dumps with VCE and PDF 241-250

Ensurepass.com : Ensure you pass the IT Exams
2018 Jan Juniper Official New Released JN0-643
100% Free Download! 100% Pass Guaranteed!
http://www.EnsurePass.com/JN0-643.html

Juniper Networks Certified Internet Specialist, SEC (JNCIS-SEC)

Question No: 241 – (Topic 3)

Which two traffic types trigger pass-through firewall user authentication? (Choose two.)

  1. SSH

  2. ICMP

  3. Telnet

  4. FTP

Answer: C,D

Question No: 242 – (Topic 3)

Which statement is true about source NAT?

  1. Source NAT works only with source pools.

  2. Destination NAT is required to translate the reply traffic.

  3. Source NAT does not require a security policy to function.

  4. The egress interface IP address can be used for source NAT.

Answer: D

Question No: 243 – (Topic 3)

When devices are in cluster mode, which new interfaces are created?

  1. No new interface is created.

  2. Only the st interface is created.

  3. fxp1, fab0, and fab1 are created.

  4. st, fxp1, reth, fab0, and fab1 are created.

Answer: C

Question No: 244 – (Topic 3)

Which statement regarding the implementation of an IDP policy template is true?

  1. IDP policy templates are automatically installed as the active IDP policy.

  2. IDP policy templates are enabled using a commit script.

  3. IDP policy templates can be downloaded without an IDP license.

  4. IDP policy templates are included in the factory-default configuration.

Answer: B

Question No: 245 – (Topic 3)

Click the Exhibit button.

Ensurepass 2018 PDF and VCE

Which two statements are true about the output shown in the exhibit on the branch SRX device? (Choose two.)

  1. Redirect Web filtering is being used.

  2. Integrated Web filtering is being used.

  3. At some point the SRX had more than 4000 concurrent Web sessions.

  4. Local Web filtering is being used.

Answer: B,C

Question No: 246 – (Topic 3)

Regarding an IPsec security association (SA), which two statements are true? (Choose two.)

  1. IKE SA is bidirectional.

  2. IPsec SA is bidirectional.

  3. IKE SA is established during phase 2 negotiations.

  4. IPsec SA is established during phase 2 negotiations.

Answer: A,D

Question No: 247 – (Topic 3)

Which three parameters does the Junos OS attempt to match against during session lookup? (Choose three.)

  1. session token

  2. ingress interface

  3. protocol number

  4. source port number

  5. egress interface

Answer: A,C,D

Question No: 248 – (Topic 3)

Which two firewall user authentication objects can be referenced in a security policy? (Choose two.)

  1. access profile

  2. client group

  3. client

  4. default profile

Answer: B,C

Question No: 249 – (Topic 3)

Which three functions are provided by JUNOS Software for security platforms? (Choose three.)

  1. VPN establishment

  2. stateful ARP lookups

  3. Dynamic ARP inspection

  4. Network Address Translation

  5. inspection of packets at higher levels (Layer 4 and above)

Answer: A,D,E

Question No: 250 – (Topic 3)

Which two steps are performed when configuring a zone? (Choose two.)

  1. Define a default policy for the zone.

  2. Assign logical interfaces to the zone.

  3. Assign physical interfaces to the zone.

  4. Define the zone as a security or functional zone.

Answer: B,D

100% Ensurepass Free Download!
Download Free Demo:JN0-643 Demo PDF
100% Ensurepass Free Guaranteed!
JN0-643 Dumps

EnsurePass ExamCollection Testking
Lowest Price Guarantee Yes No No
Up-to-Dated Yes No No
Real Questions Yes No No
Explanation Yes No No
PDF VCE Yes No No
Free VCE Simulator Yes No No
Instant Download Yes No No

This entry was posted in JN0-643 Latest Exam (Jan 2018) and tagged , , , , , , , . Bookmark the permalink.

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.