Free Cheat-test Samples and Demo Questions Download
Adobe exams Adobe
Apple exams Apple
Avaya exams Avaya
Check Point exams Check Point
Cisco exams Cisco
Citrix exams Citrix
CIW exams CIW
CompTIA exams CompTIA
CWNP exams CWNP
EC-Council exams EC-Council
EMC exams EMC
Exin exams Exin
Fortinet exams Fortinet
GIAC exams GIAC
Hitachi exams Hitachi
HP exams HP
IBM exams IBM
Isaca exams Isaca
ISC exams ISC
ISEB exams ISEB
Juniper exams Juniper
LPI exams LPI
McAfee exams McAfee
Microsoft exams Microsoft
Oracle exams Oracle
PMI exams PMI
Riverbed exams Riverbed
SNIA exams SAP
Sun exams SAS
Symantec exams Symantec
VMware exams VMware
All certification exams

Juniper JN0-350 Exam - Cheat-Test.com

Free JN0-350 Sample Questions:

Q: 1
Which two statements are correct about IPSec-over-GRE tunnels? (Choose two.)

A. You can send multicast traffic over an IPsec-over-GRE tunnel.
B. You can use the same endpoint IP addresses for both the IPSec and GRE tunnels.
C. You must use a next-hop-style service set when configuring an IPSec-over-GRE tunnel.
D. You must use a next-hop-style service set in order to send multicast traffic over an IPSec- over-GRE tunnel.

Answer: A, B

Q: 2
What information can be gathered using traceoptions? (Choose two.)

A. chassis status
B. firewall counters
C. routing protocol information
D. interface operational information

Answer: C, D

Q: 3
Which command do you use to collect necessary information for JTAC assistance?

A. show tech-support
B. show configuration
C. request support information
D. request system support information

Answer: C

Q: 4
Which two statements are true regarding IPSec VPN service rules configured at the [edit services ipsec-vpn] hierarchy? (Choose two.)

A. Each term can specify a different lPSec policy.
B. Each term can specify a different local gateway.
C. Each term can specify a different remote gateway.
D. Each term can match multiple source and destination prefixes.

Answer: A, C

Q: 5
In the:
[edit services]
lab@R1# show
stateful-firewall
{ rule my-rule [
match-direction input-output;
term 1{
from {
source-address-range {
low 1.2.3.4 high 1.2.3.4;
}
}
then {
accept;
}
}
}
}
service-set my-services-set
{ stateful-firewall-rules my-rules;
interface-service {
service-interface sp-0/0/0.0;
}
}
What will the router do when it receives a packet from source address 10.10.10.10 on an interface where the my-service-set service set is applied?

A. Send a TCP RST.
B. Accept the packet.
C. Silently discard the packet.
D. Send an ICMP error message.

Answer: C

Q: 6
The re-protect firewall filter is applied as an input filter on the lo0.0 interface.
[edit firewall filter re-protect]
lab@host#show
term one {
from {
source-address {
10.0.0.1/32;
}
then accept;
}
term three {
then {
reject;
}
}
You have a single BGP peering session with 10.0.0.1.
Which statement is true?

A. term two has an incorrect match condition.
B. term one has an incorrect match condition.
C. term one is necessary for the correct operation of BGP.
D. term three is necessary for the correct operation of BGP.

Answer: C

Q: 7
Which two statements are true about scheduler maps? (Choose two.)

A. A default scheduler map is applied to each interface.
B. A scheduler map is only needed on low speed interfaces.
C. A scheduler map is applied before a multifield firewall filter.
D. A scheduler map controls the resources assigned to a specific queue.

Answer: A, D

Q: 8
Your Juniper WAN router is connected to an Ethernet switch that is configured to use 802.1p bits for classifying traffic. Which statement is correct about the configuration of CoS on the router?

A. You can only use multifield rewrites for this traffic.
B. You can only use multifield classifiers for this traffic.
C. By default the router will use the 802.1p bits for classification.
D. Additional configuration is needed to use the 802.1 bits for classification.

Answer: D

Q: 9
Which two statements about policers are correct? (Choose two.)

A. You can only police traffic once per direction.
B. Policers can only be configured using firewall filters.
C. Policers are useful against Denial of Service (DoS) attacks.
D. Traffic exceeding the policer can be dropped or reclassified.

Answer: C, D

Q: 10
In the:
term testing-1-2-3 {
from {
route-filter 10.0.0.0/16 or longer accept;
route-filter 10.0.67.0/24 or longer accept;
route-filter 192.168.64/18 or longer reject;
route-filter 192.168/16 or longer accept;
}
then {
metric 10;
accept;
}
}
What would the result be when the prefix 10.0.67.43/32 is evaluated by the term?

A. No match is found.
B. The route would be rejected.
C. The route would be accepted with no modifications.
D. The route would be accepted with the metric set to 10.

Answer: D

Q: 11
Which two statements are true about Port Address Translation (PAT) on J-series routers? (Choose two.)

A. It supports TCP and UDP.
B. It supports dynamic source PAT
C. It supports dynamic destination PAT.
D. It does not support ICMP as it has no port numbers.

Answer: A, B

Q: 12
You are configuring a router at the [edit] hierarchy. Which command will configure the router to log information regarding IKE sessions?

A. set system syslog file messages ike
B. set security ipsec traceoptions flag ike
C. set services ipsec-vpn traceoptions flag ike
D. set services ipsec-vpn ike traceoptions flag all

Answer: C

Q: 13
You are examining the output of the stateful firewall session table. Which state indicates that the router is using an application-layer gateway (ALG) to forward traffic?

A. NAT
B. ALG
C. Watch
D. Forward

Answer: C

Q: 14
Firewall filters are processed by which component in the router?

A. The routing protocols.
B. The master routing table.
C. The Packet Forwarding Engine.
D. The Routing Process Daemon (rpd).

Answer: C

Q: 15
Which command would you use to display the stateful firewall session table?

A. show services flows
B. show services session-table
C. show services stateful4irewall flows
D. show services stateful-firewall session-table

Answer: C

Q: 16
Which two statements are correct about CoS processing on enterprise routers? (Choose two.)

A. On the J-series platform, CoS functions are performed in the hardware and have limitations that are dependent on the interface type.
B. On the M-series platform, CoS functions are performed in the hardware and have limitations that are dependent on the interface type.
C. On the J-series platform, CoS functions are performed in the software and their availability and limitations are not dependent on the interface type.
D. On the M-series platform, CoS functions are performed in the software and their availability and limitations are not dependent on the interface type.

Answer: B, C

Q: 17
Your enterprise is dual homed to two different lSPs (A and B).
Your AS number is 2001. You want to make sure you will not be a transit AS between the two
ISPs. You see a partial configuration.
[edit]
policy-options {
policy-statement not-a-transit {
term one
{ from
{ protocol
bgp;
as-path no_transit;
}
then accept;
}
term two {
then reject;
}
}
}
protocols bgp {
export not-a- transit;
Which AS-path regular expressions complete the configuration to accomplish this goal?

A. [edit policy-options]
set as-path no_transit "()";
B. [edit policy-options]
set as-path no_transit ." *"
C. [edit policy-options]
set as-path no_transit "2001";
D. [edit policy-options]
set as-path no_transit " .* 2001 *";

Answer: A

Q: 18
You found a log message from your router as follows:
Aug 9 19:16:51 radon-re0 chassisd[2622]: CHASSISD_FRU_EVENT:
scb_recv_slot_attach: attached FPC 0
Which part of the message code indicates the process that generated the message?

A. radon-re0
B. chassisd[2622]
C. CHASSISD_FRU_EVENT
D. scb_recv_slot_attach

Answer: B

Q: 19
You want to run RIPv2 as the IGP in your network. Which two statements are true? (Choose two.)

A. RIP multicasts updates to neighbors by default.
B. RIP broadcasts updates to neighbors by default.
C. You must apply an export policy to RIP in order to send RIP routes to neighbors.
D. RIP routers automatically discover neighbors on an interface and send RIP routes to them.

Answer: A, C

Q: 20
All operations team members are authenticated and authorized by a TACACS+ server. All users
are members of the same login class with view permissions only. You want to give one user in
the same login class permission to also run the show configuration command. How do you accomplish this?

A. You cannot do this without assigning the user to a different login class.
B. You must have the TACACS+ server return the Juniper-Configure attribute.
C. You must have the TACACS+ server return the Juniper-Local-User-Name attribute.
D. You must have the TACACS+ server return the Juniper-Allow-Commands attribute.

Answer: D

Q: 21
You have policy-statement my-policy configured at the [edit policy-options] configuration
hierarchy. At which two configuration hierarchies could you reference this policy? (Choose two.)

A. [edit protocols bgp]
B. [edit routing-options forwarding-table]
C. [edit interfaces 100 family met filter]
D. [edit services service-set my-service-set]

Answer: A, B

Q: 22
You set the syslog to log any warning messages. Which command allows you to monitor warning messages in realtime?

A. monitor traffic
B. show log messages
C. show system alarms
D. monitor start messages

Answer: D

Q: 23
Which benefit do IPSec VPNs provide compared to MPLS-based VPNs?

A. control
B. security
C. performance
D. Internet connectivity

Answer: B

Q: 24
Which two statements are true with regard to outbound GP policies in a dual homed scenario? (Choose two.)

A. To enforce strict primary/secondary outbound routing full BGP routes should be received from both your ISPs.
B. To enforce strict primary/secondary outbound routing only default routes should be received from both your lSPs.
C. To enforce load-sharing between both lSPs, when multiple routers are used, configurations should be synchronized between them.
D. To enforce load-sharing between both ISPs, when multiple routers are used, configurations should not be synchronized between them.

Answer: B, C

Q: 25
You need to transport non-IP traffic between a branch office and headquarters. What is a valid connectivity option?

A. IPSec tunnel
B. IP in IP tunnel
C. MPLS Layer 2 VPN
D. MPLS Layer 3 VPN

Answer: C

Q: 26
Given OSPF AS external, RIP, EBGP, and IBGP learned routes to the same destination, which route is preferred?

A. the RIP route
B. the IBGP route
C. the EBGP route
D. the OSPF AS external route

Answer: A

Q: 27
You make changes to an existing NAT rule and commit the configuration. Which two statements are true? (Choose two.)

A. The change affects new flows immediately.
B. The change affects existing flows immediately.
C. The change affects new flows only after you clear the flow table.
D. The change affects existing flows only after you clear the flow table.

Answer: A, D


© 2014 Cheat-Test.com, All Rights Reserved