Want to pass your Security, Specialist (JNCIS-SEC) JN0-333 exam in the very first attempt? Try Pass2lead! It is equally effective for both starters and IT professionals.
VCE
You have recently configured an IPsec tunnel between two SRX Series devices. One of the devices is assigned an IP address using DHCP with an IP address that changes frequently. Initial testing indicates that the IPsec tunnel is not working. Troubleshooting has revealed that Phase 1 negotiations are failing.
Which two actions would solve the problem? (Choose two.)
A. Verify that the device with the IP address assigned by DHCP is the traffic initiator.
B. Verify that VPN monitoring is enabled.
C. Verify that the IKE policy is configured for aggressive mode.
D. Verify that PKI is properly configured.
Click the Exhibit button.

You have configured NAT on your network so that Host A can communicate with Server B. You want to ensure that Host C can initiate communication with Host A using Host A's reflexive address.
Referring to the exhibit, which parameter should you configure on the SRX Series device to satisfy this requirement?
A. Configure persistent NAT with the target-host parameter.
B. Configure persistent NAT with the target-host-port parameter.
C. Configure persistent NAT with the any-remote-host parameter.
D. Configure persistent NAT with the port-overloading parameter.
Click the Exhibit button. Referring to the exhibit, what will happen if client 172.16.128.50 tries to connect to destination 192.168.150.3 using HTTP?

A. The client will be permitted by policy p1.
B. The client will be denied by policy p3.
C. The client will be denied by policy p2.
D. The client will be permitted by the global policy.