Which three types of peer devices are supported for CoS-based IPsec VPNs? (Choose three.)
ADE
Explanation:
Reference:
https://www.juniper.net/documentation/en_US/junos/topics/topic-map/secuirty-cos-based-ipsec-vpns.html
You are asked to configure a new SRX Series CPE device at a remote office. The device must
participate in forwarding MPLS and IPsec traffic.
Which two statements are true regarding this implementation? (Choose two.)
BD
Explanation:
Reference:
https://www.juniper.net/documentation/en_US/junos/topics/topic-map/security-packet-based-forwarding.html
Which three roles or protocols are required when configuring an ADVPN? (Choose three.)
ABC
Explanation:
Reference:
https://www.juniper.net/documentation/en_US/junos/topics/topic-map/security-auto-discovery-vpns.html
You must troubleshoot ongoing problems with IPsec tunnels and security policy processing. Your
network consists of SRX340s and SRX5600s.
In this scenario, which two statements are true? (Choose two.)
AD
Click the Exhibit button.
You are implementing a new branch site and want to ensure Internet traffic is sent directly to your
ISP and other traffic is sent to your company headquarters. You have configured filter-based
forwarding to accomplish this objective. You verify proper functionality using the outputs shown in
the exhibit.
Which two statements are true in this scenario? (Choose two.)
AC
Click the Exhibit button.
The exhibit shows a snippet of a security flow trace. A user cannot open an SSH session to a server.
Which action will solve the problem?
A
Click the Exhibit button.
Referring to the exhibit, which two statements are true? (Choose two.)
BD
You are asked to secure your network against TOR network traffic.
Which two Juniper products would accomplish this task? (Choose two.)
CD
You are asked to implement the session cache feature on an SRX5400.
In this scenario, what information does a session cache entry record? (Choose two.)
BC
Explanation:
Reference:
<
https://www.juniper.net/documentation/en_US/junos/topics/topic-map/security-packet-based-forwarding.html
>
A session cache entry records:
To which SPU the traffic of the conversion should be forwarded
To which egress port the traffic of the conversion should be forwarded in Express Path mode
What processing to do for egress traffic, for example, NAT translation in Express Path mode
Which feature of Sky ATP is deployed with Policy Enforcer?
A