juniper认证考试

You have a firewall enforcer protecting resources in a data center. A user is experiencing difficulty connecting to a protected resource.Which two elements must exist so the user can access the resource?()A、Resource access policy on the MAG Series deviceB

题目

You have a firewall enforcer protecting resources in a data center. A user is experiencing difficulty connecting to a protected resource.Which two elements must exist so the user can access the resource?()

  • A、Resource access policy on the MAG Series device
  • B、IPsec routing policy on the MAG Series device
  • C、General traffic policy blocking access through the firewall enforcer
  • D、Auth table entry on the firewall enforcer
如果没有搜索结果,请直接 联系老师 获取答案。
如果没有搜索结果,请直接 联系老师 获取答案。
相似问题和答案

第1题:

You have a firewall enforcer protecting sensitive internal resources in a data center. The network traversed by endpoint traffic is semi-trusted, so you need to encrypt the traffic between the endpoints accessing the resources and the firewall enforcer.Which type of policies provide this level of protection?()

A. resource access policies

B. Host Enforcer policies

C. source IP enforcement policies

D. IPsec enforcement policies


参考答案:D

第2题:

A user is successfully authenticating to the network but is unable to access protected resources behind a ScreenOS enforcer. You log in to the ScreenOS enforcer and issue the command get auth table infranet and you do not see the user listed.Which two event log settings on the Junos Pulse Access Control Service must you enable to troubleshootthis issue?()

A. Connection Requests

B. System Errors

C. Enforcer Events

D. Enforcer Command Trace


参考答案:C, D

第3题:

You are configuring an SRX210 as a firewall enforcer that will tunnel IPsec traffic from several Junos Pulse users.Which two parameters must you configure on the SRX210?()

A. access profile

B. IKE parameters

C. tunneled interface

D. redirect policy


参考答案:A, B

第4题:

You need to control SSH, HTTP, and Telnet access to an MX240 router through any interface.You have decided to use a firewall filter. How should you apply the firewall filter?()

  • A、as an outbound filter on interface fxp0
  • B、as an outbound filter on interface lo0
  • C、as an inbound filter on interface fxp0
  • D、as an inbound filter on interface lo0

正确答案:D

第5题:

Which statement is correct about defining an Infranet Enforcer for use as a RADIUS Client? ()

A. You do not need to configure a RADIUS client policy.

B. You must know the exact model number of the Infranet Enforcer.

C. You must specify the NACN password of the device in the RADIUS client policy.

D. You do not need to designate a location group to which the Infranet Enforcer will belong.


参考答案:A

第6题:

You are receiving reports of possible unauthorized access to resources protected by a firewall enforcer running the Junos OS. You want to verity which users are currently accessing resources through the enforcer.Which command should you use to verify user access on the enforcer?()

A. show services unified-access-control authentication-table

B. show auth table

C. show services unified-access-control policies

D. show services unified-access-control captive-portal


参考答案:A

第7题:

You have a firewall enforcer protecting resources in a data center. A user is experiencing difficulty connecting to a protected resource.Which two elements must exist so the user can access the resource?()

A. Resource access policy on the MAG Series device

B. IPsec routing policy on the MAG Series device

C. General traffic policy blocking access through the firewall enforcer

D. Auth table entry on the firewall enforcer


参考答案:A, D

第8题:

You have a firewall enforcer receiving resource access policies from a Junos Pulse Access Control Service. You are using Network and Security Manager (NSM) for configuration management on that firewall. The firewall can also be configured using its built-in command-line interface (CLI) or Web-based user interface (WebUI).To avoid conflicting configurations, which two interfaces must you use to configure the firewall enforcer?()

A. CLI

B. WebUI

C. NSM

D. Junos Pulse Access Control Service


参考答案:C, D

第9题:

You are configuring an active/passive cluster of SRX Series devices as the firewall enforcer on a MAG Series device.Which statement is true?()

  • A、Multiple Infranet Enforcer instances are created with a single serial number of an SRX Series device defined in each configuration.
  • B、A single Infranet Enforcer instance is created with both serial numbers of the clustered SRX Series devices defined in the configuration.
  • C、Multiple Infranet Enforcer instances are created with a single IP address of an SRX Series device defined in each configuration.
  • D、A single Infranet enforcer instance is created with the VIP of the clustered SRX Series device defined in the configuration.

正确答案:B

第10题:

Which statement is correct about defining an Infranet Enforcer for use as a RADIUS Client? ()

  • A、You do not need to configure a RADIUS client policy.
  • B、You must know the exact model number of the Infranet Enforcer.
  • C、You must specify the NACN password of the device in the RADIUS client policy.
  • D、You do not need to designate a location group to which the Infranet Enforcer will belong.

正确答案:A

更多相关问题