♥♥ 2021 NEW RECOMMEND ♥♥

Free VCE & PDF File for Juniper JN0-633 Real Exam (Full Version!)

★ Pass on Your First TRY ★ 100% Money Back Guarantee ★ Realistic Practice Exam Questions

Free Instant Download NEW JN0-633 Exam Dumps (PDF & VCE):
Available on: http://www.surepassexam.com/JN0-633-exam-dumps.html

Q91. You have an existing group VPN established in your internal network using the group-id 1. You have been asked to configure a second group using the group-id 2. You must ensure that the key server for group 1 participates in group 2 but is not the key server for that group.Which statement is correct regarding the group configuration on the current key server for group 1?

A. You must configure both groups at the [edit security ipsec vpn] hierarchy.

B. You must configure both groups at the [edit security group-vpn member] hierarchy.

C. You must configure both groups at the [edit security ike] hierarchy.

D. You must configure both groups at the [edit security group-vpn] hierarchy.

Answer: D

Explanation: Reference: http://www.jnpr.net/techpubs/en_US/junos11.4/information-products/topic-collections/security/software-all/security/index.html?topic-45791.html


Q92. You want to verify that all application traffic traversing your SRX device uses standard ports. For example, you need to verify that only DNS traffic runs through port 53, and no other protocols.How would you accomplish this goal?

A. Use an IDP policy to identify the application regardless of the port used.

B. Use a custom ALG to detect the application regardless of the port used.

C. Use AppTrack to detect the application regardless of the port used.

D. Use AppID to detect the application regardless of the port used.

Answer: A

Explanation:

AppTrack for detailed visibility of application traffic Also AppTrack is aka AppID Reference :http://forums.juniper.net/t5/SRX-Services-Gateway/What-is-AppTrack-aka- AppID/td-p/63029

An Application Layer Gateway (ALG) is a software component that is designed to manage specific protocols

Reference :http://www.juniper.net/techpubs/software/junos-security/junos-security95/junos- security-swconfig-security/id-79332.html


Q93. Two companies, A and B, are connected as separate customers on an SRX5800 residing on two virtual routers (VR-A and VR-B). These companies have recently been merged and now operate under a common IT security policy. You have been asked to facilitate communication between these VRs. Which two methods will accomplish this task? (Choose two.)

A. Use instance-import to share the routes between the two VRs.

B. Create logical tunnel interfaces to interconnect the two VRs.

C. Use a physical connection between VR-A and VR-B to interconnect them.

D. Create a static route using the next-table action in both VRs.

Answer: A,D

Explanation:

Logical or physical connections between instances on the same Junos device and route between the connected instances

Reference :http://kb.juniper.net/InfoCenter/index?page=content&id=KB21260


Q94. You are using the AppDoS feature to control against malicious bot client attacks. The bot clients are using file downloads to attack your server farm. You have configured a context value rate of 10,000 hits in 60 seconds.At which threshold will the bot clients no longer be classified as malicious?

A. 5000 hits in 60 seconds

B. 8000 hits in 60 seconds

C. 7500 hits in 60 seconds

D. 9999 hits in 60 seconds

Answer:

Explanation: Reference :

http://www.juniper.net/techpubs/software/junos-security/junos-security10.0/junos-security-swconfig-security/appddos-protection-overview.html


Q95. Click the Exhibit button.

root@host# show system login user user {

uid 2000; class operator;

authentication {

encrypted-password "$1$4s7ePrk5$9S.MZTwmXTV7sovJZFFsw1"; ## SECRET-DATA

]

}

An SRX Series device has been configured for multiple certificate-based VPNs. The IPsec security association used for data replication is currently down . The administrator is a contractor and has the permissions on the SPX Series device as shown in the exhibit

Which command set would allow the administrator to troubleshoot the cause for the VPN being down?

A. set security ipsec traceoptions file ipsec

set security ipsec traceoptions flag security-associations

B. set security ike traceoptions file ike set security ike traceoptions flag ike

C. request security pki verify-integrity-status

D. request security ike debug-enable local <ip of the local gateway> remote <ip of the remote gateway›

Answer: C


Q96. Click the Exhibit button.

user@host> show interfaces routing-instance all ge* terse InterfaceAdmin Link Proto LocalInstance

ge-0/0/0.0 up up inet 172.16.12.205/24 default ge-0/0/1.0 up up inet 5.0.0.5/24

iso A

ge-0/0/2.0 up up inet 25.0.0.5/24 iso B

user@host> show security flow session

Session ID: 82274, Policy name: default-policy-00/2, Timeout: 1770, Valid In: 5.0.0.25/61935 --> 25.0.0.25/23;tcp, If: ge-0/0/1.0, Pkts: 31, Bytes: 1781 Out: 25.0.0.25/23 --> 5.0.0.25/61935;tcp, If: ge-0/0/2.0, Pkts: 23, Bytes: 1452

Total sessions: 3 user@host> show route

inet.0: 4 destinations, 4 routes (4 active, 0 holddown, 0 hidden)

+ = Active Route, - = Last Active, + = Both

0.0.0.0/0 *[Static/5] 04:08:52

> to 172.16.12.1 via ge-0/0/0.0 172.16.12.0/24 *[Direct/0] 04:08:52

via ge-0/0/0.0

172.16.12.205/32 *[Local/0] 4w4d 23:04:29

Loca1 via ge-0/0/0.0

224.0.0.5/32 *[OSPF/10] 14:37:35, metric 1

MultiRecv

A. inet.0: 4 destinations, 4 routes {4 active, 0 holddown, 0 hidden)

+ = Active Route, - = Last Active, * = Both 5.0.0.0/24 5 *[Direct/0] 00:05:04

> via ge-0/0/1.0

5.0.0.5/32 *[Local/0] 00:05:04

Local via ge-0/0/1.0 25.0.0.0/24 *[Direct/0] 00:02:37

> via ge-0/0/2.0

B. inet.0: 3 destinations, 3 routes (3 active, 0 holddown, 0 hidden)

+ = Active Route, - = Last Active, * = Both 5.0.0.25/32 *[Static/5] 00:02:38

to table A.inet.0

25.0.0.0/24 *[Direct/0] 00:02:37

> via ge-0/0/2.0

25.0.0.5/32 *[Local/0] 00:02:37

Local via ge-0/0/2.0

Which statement is true about the outputs shown in the exhibit?

C. The routing instances A and B are connected using anltinterface.

D. Routing instance A’s routes are shared with routing instance B.

E. Routing instance B’s routes are shared with routing instance A.

F. The routing instances A and B are connected using avtinterface.

Answer: C


Q97. Click the Exhibit button.

-- Exhibit–

-- Exhibit --

In the exhibit, the SRX device has hosts connected to interface ge-0/0/1 and ge-0/0/6. The devices are not able to ping each other.What is causing this behavior?

A. The interfaces must be in trunk mode.

B. The interfaces need to be configured for Ethernet switching.

C. The default security policy does not apply to transparent mode.

D. A bridge domain has not been defined.

Answer: D


Q98. You have a group IPsec VPN established with a single key server and five client devices. Regarding this scenario, which statement is correct?

A. There is one unique Phase 1 security association and five unique Phase 2 security associations used for this group.

B. There is one unique Phase 1 security association and one unique Phase 2 security association used for this group.

C. There are five unique Phase 1 security associations and five unique Phase 2 security associations used for this group.

D. There are five unique Phase 1 security associations and one unique Phase 2 security association used for this group.

Answer: D

Explanation:

Reference :http://www.thomas-krenn.com/redx/tools/mb_download.php/mid.x6d7672335147784949386f3d/Manual_Confi guring_Group_VPN_Juniper_SRX.pdf


Q99. Click the Exhibit button.

-- Exhibit --

[edit security idp] user@srx# show security-package {

url https://services.netscreen.com/cgi-bin/index.cgi; automatic {

start-time "2012-12-11.01:00:00 +0000";

interval 120; enable;

}

}

-- Exhibit --

You have configured your SRX device to download and install attack signature updates as shown in the exhibit. You discover that updates are not being downloaded.

What are two reasons for this behavior? (Choose two.)

A. No security policy is configured to allow the SRX device to contact the update server.

B. The SRX device does not have a DNS server configured.

C. The management zone interface does not have an IP address configured.

D. The SRX device has no Internet connectivity.

Answer: B,D

Explanation:

Configuration is correct. Only reason is that SRZ device is not able to connect to definition server.

Reference:http://kb.juniper.net/InfoCenter/index?page=content&id=KB16491


Q100. Which statement is true regarding dual-stack lite?

A. The softwire is an IPv4 tunnel over an IPv6 network.

B. The softwire initiator (SI) encapsulates IPv6 packets in IPv4.

C. The softwire concentrator (SC) decapsulates softwire packets.

D. SRX devices support the softwire concentrator and softwire initiator functionality.

Answer:

Explanation: Reference:http://www.juniper.net/techpubs/en_US/junos/topics/concept/ipv6-ds-lite- overview.html