Exhibit
Referring to the exhibit, an internal host is sending traffic to an Internet host using the 203.0.113.1 reflexive address with source port 54311. Which statement is correct in this situation?
A. Only the Internet host that the internal host originally communicated with can initiate traffic to reach the internal host using the 203.0.113.1 address, source port 54311, and a random destination port.
B. Only the Internet host that the internal host originally communicated with can initiate traffic to reach the internal host using the 203.0 113.1 address, a random source port, and destination port 54311.
C. Any host on the Internet can initiate traffic to reach the internal host using the 203.0.113.1 address, source port 54311, and a random destination port.
D. Any host on the Internet can initiate traffic to reach the internal host using the 203.0.113.1 address, a random source port, and destination port 54311.
Click the Exhibit button.
Which type of NAT is shown in the exhibit?
A. NAT46
B. NAT64
C. persistent NAT
D. DS-Lite
Exhibit
You are not able to ping the default gateway of 192.168 100 1 (or your network that is located on your SRX Series firewall. Referring to the exhibit, which two commands would correct the configuration of your SRX Series device? (Choose two.)
A. Option A
B. Option B
C. Option C
D. Option D
Exhibit.
Referring to the exhibit, a spoke member of an ADVPN is not functioning correctly.
Which two commands will solve this problem? (Choose two.)
A. [edit interfaces] user@srx# delete st0.0 multipoint
B. [edit security ike gateway advpn-gateway] user@srx# delete advpn partner
C. [edit security ike gateway advpn-gateway] user@srx# set version v1-only
D. [edit security ike gateway advpn-gateway] user@srx# set advpn suggester disable
Exhibit.
Referring to the exhibit, which two statements are true? (Choose two.)
A. The c-1 TSYS has a reservation for the security flow resource.
B. The c-1 TSYS can use security flow resources up to the system maximum.
C. The c-1 TSYS cannot use any security flow resources.
D. The c-1 TSYS has no reservation for the security flow resource.
Exhibit
You are validating bidirectional traffic flows through your IPsec tunnel. The 4546 session represents traffic being sourced from the remote end of the IPsec tunnel. The 4547 session represents traffic that is sourced from the local network destined to the remote network.
Which statement is correct regarding the output shown in the exhibit?
A. The remote gateway address for the IPsec tunnel is 10.20.20.2
B. The session information indicates that the IPsec tunnel has not been established
C. The local gateway address for the IPsec tunnel is 10.20.20.2
D. NAT is being used to change the source address of outgoing packets
Exhibit
Referring to the exhibit, which three protocols will be allowed on the ge-0/0/5.0 interface? (Choose three.)
A. IBGP
B. OSPF
C. IPsec
D. DHCP
E. NTP
You configured a chassis cluster for high availability on an SRX Series device and enrolled this HA cluster with the Juniper ATP Cloud. Which two statements are correct in this scenario? (Choose two.)
A. You must use different license keys on both cluster nodes.
B. When enrolling your devices, you only need to enroll one node.
C. You must set up your HA cluster after enrolling your devices with Juniper ATP Cloud
D. You must use the same license key on both cluster nodes.
Exhibit Referring to the exhibit, which three statements are true? (Choose three.)
A. The packet's destination is to an interface on the SRX Series device.
B. The packet's destination is to a server in the DMZ zone.
C. The packet originated within the Trust zone.
D. The packet is dropped before making an SSH connection.
E. The packet is allowed to make an SSH connection.
You are configuring transparent mode on an SRX Series device. You must permit IP-based traffic only, and BPDUs must be restricted to the VLANs from which they originate.
Which configuration accomplishes these objectives?
A. Option A
B. Option B
C. Option C
D. Option D