Which three UTM features require a license? (Choose three.)
A. enhanced Web filtering
B. e-mail filtering
C. local list Web filtering
D. antispam
E. express antivirus
正解:A,D,E
質問 2:
Click the Exhibit button.
[edit security]
user@host# show
zones {
security-zone ZoneA {
tcp-rst;
host-inbound-traffic {
system-services {
ping;
telnet;
}}
interfaces {
ge-0/0/0.0;
ge-0/0/1.0;
}}
security-zone ZoneB {
interfaces {
ge-0/0/3.0;
}}}
policies {
from-zone ZoneA to-zone ZoneB {
policy A-to-B {
match {
source-address any;
destination-address any;
application any;
}
then {
permit;
}}}}
In the exhibit, a host attached to interface ge-0/0/0.0 sends a SYN packet to open a Telnet connection to the device's ge-0/0/1.0 IP address.
What does the device do?
A. The device forwards the packet out the ge-0/0/1.0 interface.
B. The device sends back a TCP reset packet.
C. The device responds with a TCP SYN/ACK packet and opens the connection.
D. The device silently discards the packet.
正解:D
質問 3:
Which two firewall user authentication objects can be referenced in a security policy?
(Choose two.)
A. default profile
B. access profile
C. client group
D. client
正解:C,D
質問 4:
What are two uses of NAT? (Choose two.)
A. enabling network migrations
B. preventing unauthorized connections from outside the network
C. allowing stateful packet inspection
D. conserving public IP addresses
正解:A,D
質問 5:
You want to create a security policy allowing traffic from any host in the Trust zone to hostb.example.com (172.19.1.1) in the Untrust zone. How do you create this policy?
A. Create an address book entry in the Trust zone for the 172.19.1.1/32 prefix and reference this entry in the policy.
B. Specify the DNS entry (hostb.example.com) as the destination address in the policy.
C. Specify the IP address (172.19.1.1/32) as the destination address in the policy.
D. Create an address book entry in the Untrust zone for the 172.19.1.1/32 prefix and reference this entry in the policy.
正解:D
質問 6:
Which two statements are true about the relationship between static NAT and proxy ARP? (Choose two.)
A. It is necessary to forward ARP requests to remote hosts.
B. It is enabled by default and you do not need to configure it.
C. It is not automatic and you must configure it.
D. It is necessary when translated traffic belongs to the same subnet as the ingress interface.
正解:C,D
質問 7:
-- Exhibit --
security {
policies {
from-zone TRUST to-zone UNTRUST {
policy hosts-allow {
match {
source-address hosts;
destination-address any;
application any;
}
then {
permit;
}
scheduler-name block-hosts;
}
policy allow {
match {
source-address any;
destination-address any;
application junos-http;
}
then {
permit;
}
}
policy deny {
match {
source-address any;
destination-address any;
application any;
}
then {
deny;
}
}
}
}
}
schedulers {
scheduler block-hosts {
daily {
start-time 10:00:00 stop-time 18:00:00;
}
}
}
-- Exhibit -
Click the Exhibit button.
Referring to the exhibit, you have configured a scheduler to allow hosts access to the Internet during specific times. You notice that hosts are still accessing the Internet during times outside of the scheduler's parameters.
What is allowing hosts to access the Internet?
A. The policy allow is allowing hosts access during unscheduled hours.
B. The policy hosts-allow should have an application of junos-http.
C. The policy hosts-allow should have a then statement of deny.
D. The policy deny should have the scheduler applied.
正解:A
質問 8:
Which two statements are true regarding firewall user authentication? (Choose two.)
A. Firewall user authentication is performed only for traffic that is denied by a security policy.
B. Firewall user authentication provides an additional method of controlling user access to remote networks.
C. Firewall user authentication provides an additional method of controlling user access to the JUNOS security device itself.
D. Firewall user authentication is performed only for traffic that is accepted by a security policy.
正解:B,D
質問 9:
Which two parameters are configurable under the [edit security zones security-zone zoneA] stanza? (Choose two.)
A. the zone-specific address book
B. the TCP RST feature
C. the default policy action for firewall rules in this zone
D. the security policies for intrazone communication
正解:A,B
973 お客様のコメント





张瑶 -
JN0-332のアプリバージョンはおすすめです。スマートフォンからアクセスしてもできるので、電車での移動中でも利用していました。それのおかげで試験にも無事合格しました。