Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Juniper Exam JN0-335 Topic 6 Question 20 Discussion

Actual exam question for Juniper's JN0-335 exam
Question #: 20
Topic #: 6
[All JN0-335 Questions]

Which two statements are correct about SSL proxy server protection? (Choose two.)

Show Suggested Answer Hide Answer
Suggested Answer: A, D

Juniper ATP Cloud is a cloud-based service that provides advanced threat prevention and detection for your network. It integrates with SRX Series firewalls and MX Series routers to analyze files and network traffic for signs of malicious activity. Two functions that Juniper ATP Cloud performs to reduce delays in the inspection of files are:

Juniper ATP Cloud allows the creation of allowlists: Allowlists are lists of trusted files or file hashes that are excluded from scanning by Juniper ATP Cloud. You can create allowlists based on file name, file type, file size, file hash, or sender domain. By using allowlists, you can reduce the number of files that need to be uploaded to Juniper ATP Cloud for analysis and improve the performance and efficiency of your network.

Juniper ATP Cloud performs a cache lookup on files: Cache lookup is a process that checks if a file has been previously scanned by Juniper ATP Cloud and if there is a cached verdict for it. If there is a cached verdict, Juniper ATP Cloud returns it immediately without scanning the file again. If there is no cached verdict, Juniper ATP Cloud uploads the file for analysis. By using cache lookup, you can reduce the time and bandwidth required for scanning files by Juniper ATP Cloud.


Contribute your Thoughts:

Cassandra
18 days ago
Wait, so we need to load the server certs and the root CA? That's like having the keys to the front door and the back door just to get into your own house.
upvoted 0 times
Jaime
19 hours ago
A) You do not need to configure the servers to use the SSL proxy function on the SRX Series device.
upvoted 0 times
...
...
Gail
19 days ago
I'm not sure about A, but I'm pretty confident that B and D are the right answers. Gotta love those SSL/TLS shenanigans, am I right?
upvoted 0 times
...
Kami
30 days ago
Haha, imagine if A was correct! 'You don't need to configure the servers?' Yeah, right, that's like trying to play a game without turning on the console.
upvoted 0 times
...
Teresita
1 months ago
I think C is also correct. The servers have to be configured to use the SSL proxy function on the SRX device. It's like the servers need to know where to send the encrypted traffic.
upvoted 0 times
Elmira
18 hours ago
D) You must import the root CA on the servers.
upvoted 0 times
...
Lemuel
8 days ago
A) You do not need to configure the servers to use the SSL proxy function on the SRX Series device.
upvoted 0 times
...
...
Ceola
1 months ago
Well, I guess the correct answers are B and D. You need to load the server certificates on the SRX device and import the root CA on the servers. Seems pretty straightforward to me.
upvoted 0 times
Aja
20 hours ago
Yeah, you need to load the server certificates on the SRX device and import the root CA on the servers.
upvoted 0 times
...
Erick
10 days ago
I think you're right, B and D are the correct answers.
upvoted 0 times
...
...
Valentine
2 months ago
I believe statement D is also correct because you must import the root CA on the servers for SSL proxy protection. It helps in verifying the server's identity.
upvoted 0 times
...
Luis
2 months ago
I agree with Valentine. Statement B is important for the SSL proxy server protection. What do you think about statement D?
upvoted 0 times
...
Valentine
2 months ago
I think statement B is correct because you need to load the server certificates on the SRX Series device for SSL proxy protection.
upvoted 0 times
...

Save Cancel