You are asked to implement IPsec tunnels between your SRX devices located at various
locations. You will use the public key infrastructure (PKI) to verify the identification of the
endpoints. What are two certificate enrollment options available for this deployment?
(Choose two.)
A.
Manually generating a PKCS10 request and submitting it to an authorized CA.
B.
Dynamically generating and sending a certificate request to an authorized CA using
OCSP.
C.
Manually generating a CRL request and submitting that request to an authorized CA.
D.
Dynamically generating and sending a certificate request to an authorized CA using
SCEP.
A and D are correct
A & D Are correct
https://www.juniper.net/documentation/en_US/junos12.1×46/topics/reference/command-summary/request-security-pki-generate-certificate-request-certificate-id.html
Note: Junos OS supports automatic sending of certificate requests through the Simple Certificate Enrollment Protocol (SCEP).
https://www.juniper.net/documentation/en_US/junos15.1×49/topics/concept/certificate-digital-understanding.html#id-45699