Question 6 of 71

Users at a branch office report that they cannot reach an internal Web server. The users connect through a single SRX Series device to reach the Web server. A security policy has been configured on the device that allows traffic to flow between interfaces in the Trust zone.

What is causing this problem?

Answer

Suggested Answer

The suggested answer is A.

Host inbound traffic configuration is ignored as this is not destined to the device (SRX) itself.
Question 7 of 71

You are asked to troubleshoot a user communication problem. Users connected to the Trust zone cannot communicate with other devices connected to the same zone. These users are able to communicate with other devices in all other zones.

How should you resolve this problem?

Answer

Suggested Answer

The suggested answer is B.

References:
http://www.juniper.net/documentation/en_US/junos12.1×46/topics/example/security-srx-device-zone-and-policy-configuring.html
Question 8 of 71

You have implemented AppTrack on your SRX Series device to track YouTube streaming video usage in your network. However, many of the YouTube videos that your users are watching are shorter than five minutes. You notice that the statistics for starting these short YouTube videos are not being recorded by

AppTrack.

Which two actions would allow AppTrack to record the statistics for these sessions? (Choose two.)

Answer

Suggested Answer

The suggested answer is A, B.

You need to change the interval to be a smaller window and you need to log at session creation.
References:
http://www.juniper.net/documentation/en_US/junos12.1/topics/example/app-track-configuring-cli.html
Question 9 of 71

While attempting to set up IDP on an SRX Series device, the IDP attack database fails to download.

What is one reason for this behavior?

Answer

Suggested Answer

The suggested answer is B.

Note: The scenarios, which might cause the above error, can be broadly classified as follows:
The SRX device does not have Internet connectivity.
The DNS server is not configured on the SRX device.
The SRX device does not have access to the SIG DB server.
Storage space in the Compact Flash is full.
References:
http://kb.juniper.net/InfoCenter/index?page=content&id=KB23359
Question 10 of 71

When attempting to delete IDP policies and configurations from an SRX Series device, a user enters these configuration commands:

Delete security idp -

Commit -

However, after the commit has completed, the configuration is still present under the [edit security idp] hierarchy.

What should the user do to permanently remove the configuration?

Answer

Suggested Answer

The suggested answer is D.

References:
https://kb.juniper.net/InfoCenter/index?page=content&id=KB27182&actp=search