You are asked to see if your persistent NAT binding table is exhausted.
Which show command would you use to accomplish this task?
A. show security nat source persistent-nat-table summary
B. show security nat source summary
C. show security nat source pool all
D. show security nat source persistent-nat-table all
Exhibit:

Your company uses SRX Series devices to establish an IPsec VPN that connects Site-1 and the HQ networks. You want VoIP traffic to receive priority over data traffic when it is forwarded across the VPN.
Which three actions should you perform in this scenario? (Choose three.)
A. Enable next-hop tunnel binding.
B. Create a firewall filter that identifies VoIP traffic and associates it with the correct forwarding class.
C. Configure CoS forwarding classes and scheduling parameters.
D. Enable the copy-outer-dscp parameter so that DSCP header values are copied to the tunneled packets.
E. Enable the multi-sa parameter to enable two separate IPsec SAs for the VoIP and data traffic.
You want to deploy two vSRX instances in different public cloud providers to provide redundant security services for your network. Layer 2 connectivity between the two vSRX instances is not possible.
What would you configure on the vSRX instances to accomplish this task?
A. Chassis cluster
B. Secure wire
C. Multinode HA
D. Virtual chassis
You have an initial setup of ADVPN with two spokes and a hub. A host at partner Spoke-1 is sending traffic to a host at partner Spoke-2.
In this scenario, which statement is true?
A. Spoke-1 will establish a VPN to Spoke-2 when this is first deployed, so traffic will be sent immediately to Spoke-2.
B. Spoke-1 will send the traffic through the hub and not use a direct VPN to Spoke-2.
C. Spoke-1 will establish the tunnel to Spoke-2 before sending any of the host traffic.
D. Spoke-1 will send the traffic destined to Spoke-2 through the hub until the VPN is established between the spokes.
Referring to the exhibit.

What do you use to dynamically secure traffic between the Azure and AWS clouds?
A. You can dynamically secure traffic between the clouds by using user identities in the security policies.
B. You can dynamically secure traffic between the clouds by using advanced connection tracking in the security policies.
C. You can dynamically secure traffic between the clouds by using security tags in the security policies.
D. You can dynamically secure traffic between the clouds by using URL filtering in the security policies.
You configure two Ethernet interfaces on your SRX Series device as Layer 2 interfaces and add them to the same VLAN. The SRX is using the default L2-learning setting. You do not add the interfaces to a security zone.
Which two statements are true in this scenario? (Choose two.)
A. You are unable to apply stateful security features to traffic that is switched between the two interfaces.
B. You are able to apply stateful security features to traffic that enters and exits the VLAN.
C. The interfaces will not forward traffic by default.
D. You cannot add Layer 2 interfaces to a security zone.
Which two statements are correct about the ICL in an active/active mode multinode HA environment? (Choose two.)
A. The ICL is strictly a Layer 2 interface.
B. The ICL uses a separate routing instance to communicate with remote multinode HA peers.
C. The ICL traffic can be encrypted.
D. The ICL is the local device management interface in a multinode HA environment.
In a multinode HA environment, which service must be configured to synchronize between nodes?
A. Advanced policy-based routing
B. PKI certificates
C. IPsec VPN
D. IDP
How does an SRX Series device examine exception traffic?
A. The device examines the host-inbound traffic for the ingress interface and zone.
B. The device examines the host-outbound traffic for the ingress interface and zone.
C. The device examines the host-inbound traffic for the egress interface and zone.
D. The device examines the host-outbound traffic for the egress interface and zone.
Referring to the exhibit.

Host A shown in the exhibit is attempting to reach the Web1 webserver, but the connection is failing. Troubleshooting reveals that when Host A attempts to resolve the domain name of the server (web.acme. com), the request is resolved to the private address of the server rather than its public IP.
Which feature would you configure on the SRX Series device to solve this issue?
A. Persistent NAT
B. Double NAT
C. DNS doctoring
D. STUN protocol