You want to use a security profile to limit the system resources allocated to user logical systems.
In this scenario, which two statements are true? (Choose two.)
A. If nothing is specified for a resource, a default reserved resource is set for a specific logical system.
B. If you do not specify anything for a resource, no resource is reserved for a specific logical system, but the entire system can compete for resources up to the maximum available.
C. One security profile can only be applied to one logical system.
D. One security profile can be applied to multiple logical systems.
You have deployed an SRX Series device at your network edge to secure Internet-bound sessions for your local hosts using source NAT. You want to ensure that your users are able to interact with applications on the Internet that require more than one TCP session for the same application session.
Which two features would satisfy this requirement? (Choose two.)
A. address persistence
B. STUN
C. persistent NAT
D. double NAT
Referring to the exhibit.


In which mode is the SRX Series device?
A. Packet
B. Ethernet switching
C. Mixed
D. Transparent
Referring to the exhibit.

You are asked to ensure that Internet users can access the company's internal webserver using its FQDN.
However, the internal DNS server's A record only points to the webserver's private address.
Referring to the exhibit, which two actions are required to complete this task? (Choose two.)
A. Disable the DNS ALG.
B. Configure static NAT for both the DNS server and the webserver.
C. Configure destination NAT for both the DNS server and the webserver.
D. Configure proxy ARP on ge-0/0/3.
Referring to the exhibit,

which two statements about User1 are true? (Choose two.)
A. User1 has access to the configuration specific to their assigned logical system.
B. User1 is logged in to logical system LSYS-1.
C. User1 can add logical units to an interface that a primary administrator has not previously assigned.
D. User1 can view outputs from other user logical systems.
Referring to the exhibit.

Which statement is true?
A. SRG1 is configured in hybrid mode.
B. The ICL is encrypted.
C. If SRG1 moves to peer 2, peer 1 will drop packets sent to the SRG1 interfaces.
D. If SRG1 moves to peer 2, peer 1 will forward packets sent to the SRG1 interfaces.
An ADVPN configuration has been verified on both the hub and spoke devices and it seems fine. However, OSPF is not functioning as expected.

Referring to the exhibit, which two statements under interface st0.0 on both the hub and spoke devices would solve this problem? (Choose two.)
A. interface-type p2mp
B. dynamic-neighbors
C. passive
D. interface-type p2p
In a multinode HA environment, which service must be configured to synchronize between nodes?
A. Advanced policy-based routing
B. PKI certificates
C. IPsec VPN
D. IDP
You have configured the backup signal route IP for your multinode HA deployment, and the ICL link fails. Which two statements are correct in this scenario? (Choose two.)
A. The current active node retains the active role.
B. The active node removes the active signal route.
C. The backup node changes the routing preference to the other node at its medium priority.
D. The active node keeps the active signal route.
Referring to the exhibit.

Host A shown in the exhibit is attempting to reach the Web1 webserver, but the connection is failing. Troubleshooting reveals that when Host A attempts to resolve the domain name of the server (web.acme. com), the request is resolved to the private address of the server rather than its public IP.
Which feature would you configure on the SRX Series device to solve this issue?
A. Persistent NAT
B. Double NAT
C. DNS doctoring
D. STUN protocol