Security policy schedulers are a feature that allows you to activate or deactivate a policy for a specified time period. You can create schedulers for a single or recurrent time slot, and apply them to one or more policies. A policy can only have one scheduler associated with it, but a scheduler can have multiple policies associated with it. When a scheduler is active, the policy is available for policy lookup. When a scheduler is inactive, the policy is unavailable for policy lookup. A policy without a defined scheduler will always be active, unless it is explicitly disabled. References:
Scheduling Security Policies
schedulers (Security Policies)
Security Policy Schedulers
scheduler (Security Policies)
Question 2
Which two statements about unified security policies are correct? (Choose two.)
Options:
A.
Unified security policies require an advanced feature license.
B.
Unified security policies are evaluated after global security policies.
C.
Traffic can initially match multiple unified security policies.
D.
APPID results are used to determine the final security policy
Answer:
C, D
Explanation:
Explanation:
Unified policies are security policies that enable you to use dynamic applications as match conditions along with the existing 5-tuple or 6-tuple (with user firewall) match conditions to detect application changes over time3 If the traffic matches the security policy rule, one or more actions defined in the policy are applied to the traffic3 During the initial policy lookup phase, which occurs prior to a dynamic application being identified, if there are multiple policies in the potential policy list, the SRX Series Firewall applies the default security policy until a more explicit match has occurred2 The policy that best matches the application is the final policy2 APPID results are used to determine the final security policy1 References:
1: Unified Security Policies | Junos OS | Juniper Networks
2: Unified Policies Support for Flow | Junos OS | Juniper Networks
Which two statements about SRX Series device chassis clusters are correct? (Choose two.)
Options:
A.
The chassis cluster data plane is connected with revenue ports.
B.
The chassis cluster can contain a maximum of three devices.
C.
The chassis cluster data plane is connected with SPC ports.
D.
The chassis cluster can contain a maximum of two devices.
Answer:
A, D
Explanation:
Explanation:
SRX Series device chassis clusters are created by physically connecting two identical cluster-supported SRX Series devices using a pair of the same type of Ethernet connections. The connection is made for both a control link and a fabric (data) link between the two devices. The chassis cluster data plane is connected with revenue ports, which are the ports that carry user traffic. The chassis cluster can contain a maximum of two devices, as only two nodes can form a cluster. The chassis cluster data plane is not connected with SPC ports, which are the ports that provide services processing. The chassis cluster cannot contain more than two devices, as this would violate the cluster design. References: Chassis Cluster Overview, Connecting SRX Series Firewalls to Create a Chassis Cluster