Juniper JN0-333 Exam Practice Questions (P. 4)
- Full Access (68 questions)
- Six months of Premium Access
- Access to one million comments
- Seamless ChatGPT Integration
- Ability to download PDF files
- Anki Flashcard files for revision
- No Captcha & No AdSense
- Advanced Exam Configuration
Question #16
Which statement describes the function of NAT?
- ANAT encrypts transit traffic in a tunnel.
- BNAT detects various attacks on traffic entering a security device.
- CNAT translates a public address to a private address.
- DNAT restricts or permits users individually or in a group.
Correct Answer:
C
C
send
light_mode
delete
Question #17
Click the Exhibit button.

You are monitoring traffic, on your SRX300 that was configured using the factory default security parameters. You notice that the SRX300 is not blocking traffic between Host A and Host B as expected.
Referring to the exhibit, what is causing this issue?

You are monitoring traffic, on your SRX300 that was configured using the factory default security parameters. You notice that the SRX300 is not blocking traffic between Host A and Host B as expected.
Referring to the exhibit, what is causing this issue?
- AHost B was not assigned to the Untrust zone.
- BYou have not created address book entries for Host A and Host B.
- CThe default policy has not been committed.
- DThe default policy permits intrazone traffic within the Trust zone.
Correct Answer:
D
D
send
light_mode
delete
Question #18
What is the function of redundancy group 0 in a chassis cluster?
- ARedundancy group 0 identifies the node controlling the cluster management interface IP addresses.
- BThe primary node for redundancy group 0 identifies the first member node in a chassis cluster.
- CThe primary node for redundancy group 0 determines the interface naming for all chassis cluster nodes.
- DThe node on which redundancy group 0 is primary determines which Routing Engine is active in the cluster.
Correct Answer:
D
D
send
light_mode
delete
Question #19
Which statement describes the function of screen options?
- AScreen options encrypt transit traffic in a tunnel.
- BScreen options protect against various attacks on traffic entering a security device.
- CScreen options translate a private address to a public address.
- DScreen options restrict or permit users individually or in a group.
Correct Answer:
B
B
send
light_mode
delete
Question #20
You want to protect your SRX Series device from the ping-of-death attack coming from the untrust security zone.
How would you accomplish this task?
How would you accomplish this task?
- AConfigure the host-inbound-traffic system-services ping except parameter in the untrust security zone.
- BConfigure the application tracking parameter in the untrust security zone.
- CConfigure a from-zone untrust to-zone trust security policy that blocks ICMP traffic.
- DConfigure the appropriate screen and apply it to the [edit security zone security-zone untrust] hierarchy.
Correct Answer:
D
D
send
light_mode
delete
All Pages