Free JN0-335 Exam Braindumps (page: 11)

Page 10 of 25

Which two statements are correct about SSL proxy server protection? (Choose two.)

  1. You do not need to configure the servers to use the SSL proxy the function on the SRX Series device.
  2. You must load the server certificates on the SRX Series device.
  3. The servers must be configured to use the SSL proxy function on the SRX Series device.
  4. You must import the root CA on the servers.

Answer(s): B,C

Explanation:

You must load the server certificates on the SRX Series device and configure the servers to use the SSL proxy function on the SRX Series device. This is done to ensure that the SSL proxy is able to decrypt the traffic between the client and server. Additionally, you must import the root CA on the servers in order for the SSL proxy to properly validate the server certificate.



Which two statements are correct about chassis clustering? (Choose two.)

  1. The node ID value ranges from 1 to 255.
  2. The node ID is used to identify each device in the chassis cluster.
  3. A system reboot is required to activate changes to the cluster.
  4. The cluster ID is used to identify each device in the chassis cluster.

Answer(s): A,B

Explanation:

The node ID value ranges from 1 to 255 and is used to identify each device in the chassis cluster. The cluster ID is also used to identify each device, but it is not part of the node ID configuration. A system reboot is not required to activate changes to the cluster, but it is recommended to ensure that all changes are applied properly.



You want to use IPS signatures to monitor traffic.
Which module in the AppSecure suite will help in this task?

  1. AppTrack
  2. AppQoS
  3. AppFW
  4. APPID

Answer(s): C

Explanation:

The AppFW module in the AppSecure suite provides IPS signatures that can be used to monitor traffic and detect malicious activities. AppFW also provides other security controls such as Web application firewall, URL filtering, and application-level visibility.



Which two statements are correct about JSA data collection? (Choose two.)

  1. The Event Collector collects information using BGP FlowSpec.
  2. The Flow Collector can use statistical sampling
  3. The Flow Collector parses logs.
  4. The Event Collector parses logs

Answer(s): B,D

Explanation:

The Flow Collector can use statistical sampling to collect and store network flow data in the JSA database. The Event Collector collects information from various sources including syslog, SNMP, NetFlow, and BGP FlowSpec. Both the Flow Collector and the Event Collector parse logs to extract useful information from the logs.






Post your Comments and Discuss Juniper JN0-335 exam with other Community members:

JN0-335 Discussions & Posts