Want to know Exambible JN0-633 Exam practice test features? Want to lear more about Juniper Security, Professional (JNCIP-SEC) certification experience? Study Verified Juniper JN0-633 answers to Up to the minute JN0-633 questions at Exambible. Gat a success with an absolute guarantee to pass Juniper JN0-633 (Security, Professional (JNCIP-SEC)) test on your first attempt.


♥♥ 2021 NEW RECOMMEND ♥♥

Free VCE & PDF File for Juniper JN0-633 Real Exam (Full Version!)

★ Pass on Your First TRY ★ 100% Money Back Guarantee ★ Realistic Practice Exam Questions

Free Instant Download NEW JN0-633 Exam Dumps (PDF & VCE):
Available on: http://www.surepassexam.com/JN0-633-exam-dumps.html

Q61. Click the Exhibit button.

-- Exhibit–

-- Exhibit --

Referring to the exhibit, which two statements are true? (Choose two.)

A. Packets may get fragmented.

B. The tunnel automatically fragments packets based on MTU discovery.

C. The Phase 2 association will never expire.

D. The Phase 2 association will expire without traffic.

Answer: A,D


Q62. You want to implement an IPsec VPN on an SRX device using PKI certificates for authentication. As part of the implementation, you are required to ensure that the certificate submission, renewal, and retrieval processes are handled automatically from the certificate authority.Regarding this scenario, which statement is correct?

A. You can use SCEP to accomplish this behavior.

B. You can use OCSP to accomplish this behavior.

C. You can use CRL to accomplish this behavior.

D. You can use SPKI to accomplish this behavior.

Answer: A

Explanation: Reference: Page 9

http://www.juniper.net/techpubs/en_US/junos/information-products/topic-collections/nce/pki-conf-trouble/configuring-and-troubleshooting-public-key- infrastructure.pdf


Q63. You want to query User Group membership directly using the integrated user firewall services from an Active Directory controller to an SRX Series device.

Which two actions are required? (Choose two.)

A. Configure the LDAP base distinguished name.

B. Connect the SRX Series device and the MAG Series device in an enforcer configuration.

C. Configure a domain name, the username and password of the domain, and the name and IP address of the domain controller in the domain.

D. Configure the Access Control Service on the MAG Series device for local user authentication and verify that authentication information is transferred between the devices.

Answer: A,C


Q64. You are asked to ensure traffic from your executive staff does not use the same ISP connection as your other traffic.

Which three actions are required to accomplish this task? (Choose three)

A. Create a firewall filter to match this traffic and send this traffic to the routing instance.

B. Create a routing instance and define the type asno-forwarding.

C. Assign the outgoing interface to theno-forwardinginstance.

D. Create a routing instance and define the type asforwarding.

E. Create a RIB group to share routes between the main instance and the routing instance.

Answer: A,D,E


Q65. Your company provides managed services for two customers. Each customer has been segregated within its own routing instance on your SRX device. Customer A and customer B inform you that they need to be able to reach certain hosts on each other's network.

Which two configuration settings would be used to share routes between these routing instances? (Choose two.)

A. routing-group

B. instance-import

C. import-rib

D. next-table

Answer: B,D

Explanation:

Reference :http://aconaway.com/2013/03/02/junos-logical-tunnel-interfaces-with-virtual- routers/


Q66. You want requests from the same internal transport address to be mapped to the same external transport address. Only internal hosts can initialize the session.

Which Junos configuration setting supports the requirements?

A. any-remote-host

B. target-host

C. source-host

D. address-persistent

Answer: D

Explanation:

Reference :http://www.juniper.net/techpubs/software/junos-security/junos-security96/junos-security-swconfig-security/understand-persistent-nat-section.html


Q67. At which two times does the IPS rulebase inspect traffic on an SRX device? (Choose two.)

A. When traffic matches the active IDP policy.

B. When traffic first matches an IDP rule with the terminal parameter.

C. When traffic uses the application layer gateway.

D. When traffic is established in the firewall session table.

Answer: A,B

Explanation: Reference: http://books.google.co.in/books?id=2HSLsTJIgEQC&pg=PA814&lpg=PA814&dq=what+time+IPS+rulebase+inspects+traffic+on+SRX&source=bl&ots=_eDe_vLNBA&sig=1I4yX_S0OvkQVP-rqL273laMCyE&hl=en&sa=X&ei=nqvzUfn1Is-rrAf71oHYBA&ved=0CC4Q6AEwAQ#v=onepage&q=what%20time%20IPS%20rulebase% 20inspects%20traffic%20on%20SRX&f=false


Q68. You want to create a custom IDP signature for a new HTTP attack on your SRX device. You have the exact string that identifies the attack.Which two additional elements do you need to define your custom signature? (Choose two.)

A. service context

B. protocol number

C. direction

D. source IP address of the attacker

Answer: A,C

Explanation: Reference: http://rtoodtoo.net/2011/09/22/how-to-write-srx-idp-custom-attacksignature/


Q69. As an SRX administrator, you must find all encrypted sessions on an SRX Series device. Which command would you use to accomplish this task?

A. show security flow session tunnel

B. show security ike tunnel-map

C. show security ike security-associations

D. show security flow session encrypted

Answer: D


Q70. Click the Exhibit button.

user@host> show services application-identification application-system—cache Application System Cache Configurations:

Application-cache: off nested-application-cache: on cache-unknown-result: on

cache-entry-timeout: 3600 seconds

You are using the application identification feature on your SRX Series device. The help desk reports that users are complaining about slow Internet connectivity. You issue the command shown in the exhibit.

What must you do to correct the problem?

A. Modify the configuration with thedelete services application-identification no-application- system-cachecommand and commit the change.

B. Modify the configuration with thedelete services application-identification no-clear- application-system-cachecommand and commit the change.

C. Reboot the SRX Series device.

D. Modify the configuration with thedelete services application-identification no-application

–identificationcommand and commit the change.

Answer: B