Which parameters must you select when configuring operating system probes SCREEN options?
A. syn-fin, syn-flood, and tcp-no-frag
B. syn-fin, syn-ack-ack-proxy, and tcp-no-frag
C. syn-fin, port-scan, and tcp-no-flag
D. syn-fin, fin-no-ack, and tcp-no-frag
正解:D
質問 2:
Click the Exhibit button.
Which configuration would result in the output shown in the exhibit?

A. [edit security zones security-zone trust]
user@host# show
host-inbound-traffic {
system-services {
ssh;
ping;
telnet;
}
}
interfaces {
ge-0/0/3.0 {
host-inbound-traffic {
system-services {
ping;
}
}
B. [edit security zones security-zone trust]
user@host# show
host-inbound-traffic {
system-services {
ping;
telnet;
}
interfaces {
ge-0/0/0.0 {
host-inbound-traffic {
system-services {
ssh;
telnet;
}
C. [edit security zones functional-zone management]
user@host# show
interfaces {
all;
}
host-inbound-traffic {
system-services {
all;
ftp {
except;
}
D. [edit security zones functional-zone management]
user@host# show
interfaces {
all {
host-inbound-traffic {
system-services {
ping;
}
}
}
}
正解:A
質問 3:
Which two are uses of NAT? (Choose two.)
A. enabling network migrations
B. preventing unauthorized connections from outside the network
C. allowing stateful packet inspection
D. conserving public IP addresses
正解:A,D
質問 4:
Which two configurations are valid? (Choose two.)
A. [edit routing-instances]
user@host# show
foo {
interface ge-0/0/3.0;
interface ge-0/0/3.102;
}
bar {
interface ge-0/0/0.0;
interface ge-0/0/2.0;
}
B. [edit routing-instances]
user@host# show
foo {
interface ge-0/0/3.0;
interface ge-0/0/2.102;
}
bar {
interface ge-0/0/0.0;
interface ge-0/0/3.0;
}
C. [edit security zones]
user@host# show
security-zone foo {
interfaces {
ge-0/0/1.0;
ge-0/0/3.0;
}
security-zone bar {
interfaces {
ge-0/0/2.0;
ge-0/0/3.102;
}
D. [edit security zones]
user@host# show
security-zone foo {
interfaces {
ge-0/0/1.0;
ge-0/0/2.0;
}
security-zone bar {
interfaces {
ge-0/0/1.0;
ge-0/0/3.0;
}
正解:A,C
質問 5:
You must configure a policy-based VPN. Which command causes traffic to be sent through an IPSec VPN named remote-vpn?
A. [edit security policies from-zone trust to-zone untrust]
user@host# set policy tunnel-traffic then permit ipsec-vpn remote-vpn
B. [edit security policies from-zone trust to-zone untrust]
user@host# set policy tunnel-traffic then permit tunnel ipsec-vpn remote-vpn
C. [edit security policies from-zone trust to-zone untrust]
user@host# set policy tunnel-traffic then tunnel ipsec-vpn remote-vpn
D. [edit security policies from-zone trust to-zone untrust]
user@host# set policy tunnel-traffic then tunnel remote-vpn
正解:B
高石** -
Pass4Testから提供されたこのJN0-330問題集一つで習得できました。今回は試験に受かりそうです。