单选题You are configuring an active/passive cluster of SRX Series devices as the firewall enforcer on a MAG Series device.Which statement is true?()A Multiple Infranet Enforcer instances are created with a single serial number of an SRX Series device defined

题目
单选题
You are configuring an active/passive cluster of SRX Series devices as the firewall enforcer on a MAG Series device.Which statement is true?()
A

Multiple Infranet Enforcer instances are created with a single serial number of an SRX Series device defined in each configuration.

B

A single Infranet Enforcer instance is created with both serial numbers of the clustered SRX Series devices defined in the configuration.

C

Multiple Infranet Enforcer instances are created with a single IP address of an SRX Series device defined in each configuration.

D

A single Infranet enforcer instance is created with the VIP of the clustered SRX Series device defined in the configuration.

如果没有搜索结果或未解决您的问题,请直接 联系老师 获取答案。
相似问题和答案

第1题:

Which statement is true regarding NAT?()

A. NAT is not supported on SRX Series devices.

B. NAT requires special hardware on SRX Series devices.

C. NAT is processed in the control plane.

D. NAT is processed in the data plane.


参考答案:D

第2题:

You are configuring an active/passive cluster of SRX Series devices as the firewall enforcer on a MAG Series device.Which statement is true?()

A. Multiple Infranet Enforcer instances are created with a single serial number of an SRX Series device defined in each configuration.

B. A single Infranet Enforcer instance is created with both serial numbers of the clustered SRX Series devices defined in the configuration.

C. Multiple Infranet Enforcer instances are created with a single IP address of an SRX Series device defined in each configuration.

D. A single Infranet enforcer instance is created with the VIP of the clustered SRX Series device defined in the configuration.


参考答案:B

第3题:

Which statement is true regarding IPsec VPNs?()

A. There are five phases of IKE negotiation.

B. There are two phases of IKE negotiation.

C. IPsec VPN tunnels are not supported on SRX Series devices.

D. IPsec VPNs require a tunnel PIC in SRX Series devices.


参考答案:D

第4题:

You are installing a MAG Series device for access control using an SRX Series device as the firewall enforcer. The MAG Series device resides in the same security zone as users. However, the users reside in different subnets and use the SRX Series device as an IP gateway.Which statement is true?()

  • A、You must configure a security policy on the SRX Series device to allow traffic to flow from the user devices to the MAG Series device.
  • B、No security policy is necessary on the SRX Series device to allow traffic to flow from the user devices to the MAG Series device.
  • C、You must configure host-inbound traffic on the SRX Series device to allow SSL traffic between the MAG Series device and the user devices.
  • D、You must configure host-inbound traffic on the SRX Series device to allow EAP traffic between the MAG Series device and the user devices.

正确答案:A

第5题:

Which statement is true regarding NAT?()

  • A、NAT is not supported on SRX Series devices.
  • B、NAT requires special hardware on SRX Series devices.
  • C、NAT is processed in the control plane.
  • D、NAT is processed in the data plane.

正确答案:D

第6题:

You have a firewall enforcer protecting resources in a data center. A user is experiencing difficulty connecting to a protected resource.Which two elements must exist so the user can access the resource?()

A. Resource access policy on the MAG Series device

B. IPsec routing policy on the MAG Series device

C. General traffic policy blocking access through the firewall enforcer

D. Auth table entry on the firewall enforcer


参考答案:A, D

第7题:

What is a type of firewall enforcer supported by the Junos Pulse Access Control Service?()

A. Checkpoint firewall

B. SRX Series device

C. DP sensor

D. MX Series device


参考答案:A

第8题:

You are validating the configuration of your SRX Series device and see the output shown below.What does this indicate?()

A.The SRX Series device has been configured correctly, the Junos Pulse Access Control Service is reachable on the network, and the SRX Series device is waiting to receive the initial connection from the Junos Pulse Access Control Service.

B.The SRX Series device has confirmed that the Junos Pulse Access Control Service is configured and is reachable on the network, the SRX Series device is waiting to receive the connection from the Junos Pulse Access Control Service, and all that remains to be accomplished is to configure the SRX Series device.

C.The SRX Series device is configured correctly and connected to the Junos Pulse Access Control Service. All that remains to be done to complete the configuration is to configure the SRX Series device on the Junos Pulse Access Control Service.

D.Both the Junos Pulse Access Control Service and the SRX Series device are configured correctly and communicating with each other.


参考答案:D

第9题:

What is a type of firewall enforcer supported by the Junos Pulse Access Control Service?()

  • A、Checkpoint firewall
  • B、SRX Series device
  • C、DP sensor
  • D、MX Series device

正确答案:A

第10题:

You have a firewall enforcer protecting resources in a data center. A user is experiencing difficulty connecting to a protected resource.Which two elements must exist so the user can access the resource?()

  • A、Resource access policy on the MAG Series device
  • B、IPsec routing policy on the MAG Series device
  • C、General traffic policy blocking access through the firewall enforcer
  • D、Auth table entry on the firewall enforcer

正确答案:A,D

更多相关问题