Special Summer Sale - Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 65percent

Welcome To DumpsPedia

JN0-231 Sample Questions Answers

Questions 4

You need to collect the serial number of an SRX Series device to replace it. Which command will accomplish this task?

Options:

A.

show chassis hardware

B.

show system information

C.

show chassis firmware

D.

show chassis environment

Buy Now
Questions 5

Which order is correct for Junos security devices that examine policies for transit traffic?

Options:

A.

zone policies

global policies

default policies

B.

default policies

zone policies

global policies

C.

default policies

global policies

zone policies

D.

global policies

zone policies

default policies

Buy Now
Questions 6

Click the Exhibit button.

What is the purpose of the host-inbound-traffic configuration shown in the exhibit?

Options:

A.

to permit host inbound HTTP traffic and deny all other traffic on the internal security zone

B.

to deny and log all host inbound traffic on the internal security zone, except for HTTP traffic

C.

to permit all host inbound traffic on the internal security zone, but deny HTTP traffic

D.

to permit host inbound HTTP traffic on the internal security zone

Buy Now
Questions 7

What are three Junos UTM features? (Choose three.)

Options:

A.

screens

B.

antivirus

C.

Web filtering

D.

IDP/IPS

E.

content filtering

Buy Now
Questions 8

When operating in packet mode, which two services are available on the SRX Series device? (Choose two.)

Options:

A.

MPLS

B.

UTM

C.

CoS

D.

IDP

Buy Now
Questions 9

Which two statements are correct about functional zones? (Choose two.)

Options:

A.

Functional zones must have a user-defined name.

B.

Functional zone cannot be referenced in security policies or pass transit traffic.

C.

Multiple types of functional zones can be defined by the user.

D.

Functional zones are used for out-of-band device management.

Buy Now
Questions 10

Click the Exhibit button.

Which two statements are correct about the partial policies shown in the exhibit? (Choose two.)

Options:

A.

UDP traffic matched by the deny-all policy will be silently dropped.

B.

TCP traffic matched by the reject-all policy will have a TCP RST sent.

C.

TCP traffic matched from the zone trust is allowed by the permit-all policy.

D.

UDP traffic matched by the reject-all policy will be silently dropped.

Buy Now
Questions 11

Which Juniper Networks solution uses static and dynamic analysis to search for day-zero malware threats?

Options:

A.

firewall filters

B.

UTM

C.

Juniper ATP Cloud

D.

IPS

Buy Now
Questions 12

Which two statements are correct about the default behavior on SRX Series devices? (Choose two.)

Options:

A.

The SRX Series device is in flow mode.

B.

The SRX Series device supports stateless firewalls filters.

C.

The SRX Series device is in packet mode.

D.

The SRX Series device does not support stateless firewall filters.

Buy Now
Questions 13

Which two statements are correct about IKE security associations? (Choose two.)

Options:

A.

IKE security associations are established during IKE Phase 1 negotiations.

B.

IKE security associations are unidirectional.

C.

IKE security associations are established during IKE Phase 2 negotiations.

D.

IKE security associations are bidirectional.

Buy Now
Questions 14

Which statement is correct about static NAT?

Options:

A.

Static NAT supports port translation.

B.

Static NAT rules are evaluated after source NAT rules.

C.

Static NAT implements unidirectional one-to-one mappings.

D.

Static NAT implements unidirectional one-to-many mappings.

Buy Now
Questions 15

What are two characteristics of a null zone? (Choose two.)

Options:

A.

The null zone is configured by the super user.

B.

By default, all unassigned interfaces are placed in the null zone.

C.

All ingress and egress traffic on an interface in a null zone is permitted.

D.

When an interface is deleted from a zone, it is assigned back to the null zone.

Buy Now
Questions 16

Your company is adding IP cameras to your facility to increase physical security. You are asked to help protect these loT devices from becoming zombies in a DDoS attack.

Which Juniper ATP feature should you configure to accomplish this task?

Options:

A.

IPsec

B.

static NAT

C.

allowlists

D.

C&C feeds

Buy Now
Questions 17

You want to verify the peer before IPsec tunnel establishment.

What would be used as a final check in this scenario?

Options:

A.

traffic selector

B.

perfect forward secrecy

C.

st0 interfaces

D.

proxy ID

Buy Now
Questions 18

Which two statements are correct about screens? (Choose two.)

Options:

A.

Screens process inbound packets.

B.

Screens are processed on the routing engine.

C.

Screens process outbound packets.

D.

Screens are processed on the flow module.

Buy Now
Questions 19

SRX Series devices have a maximum of how many rollback configurations?

Options:

A.

40

B.

60

C.

50

D.

10

Buy Now
Questions 20

Which statement is correct about unified security policies on an SRX Series device?

Options:

A.

A zone-based policy is always evaluated first.

B.

The most restrictive policy is applied regardless of the policy level.

C.

A global policy is always evaluated first.

D.

The first policy rule is applied regardless of the policy level.

Buy Now
Questions 21

You have multiple branch locations using an SRX Series device. You want a cloud-based solution to configure and monitor this device.

this scenario, which solution would you use?

Options:

A.

J-Web

B.

Juniper Sky Enterprise

C.

Junos Space Security Director

D.

Juniper Secure Analytics

Buy Now
Questions 22

Which statement is correct about Web filtering?

Options:

A.

The Juniper Enhanced Web Filtering solution requires a locally managed server.

B.

The decision to permit or deny is based on the body content of an HTTP packet.

C.

The decision to permit or deny is based on the category to which a URL belongs.

D.

The client can receive an e-mail notification when traffic is blocked.

Buy Now
Questions 23

What does the number “2” indicate in interface ge-0/1/2?

Options:

A.

the physical interface card (PIC)

B.

the flexible PIC concentrator (FPC)

C.

the interface logical number

D.

the port number

Buy Now
Questions 24

What are two valid address books? (Choose two.)

Options:

A.

66.129.239.128/25

B.

66.129.239.154/24

C.

66.129.239.0/24

D.

66.129.239.50/25

Buy Now
Questions 25

Which two security features inspect traffic at Layer 7? (Choose two.)

Options:

A.

IPS/IDP

B.

security zones

C.

application firewall

D.

integrated user firewall

Buy Now
Questions 26

You are installing a new SRX Series device and you are only provided one IP address from your ISP.

In this scenario, which NAT solution would you implement?

Options:

A.

pool-based NAT with PAT

B.

pool-based NAT with address shifting

C.

interface-based source NAT

D.

pool-based NAT without PAT

Buy Now
Questions 27

You are creating Ipsec connections.

In this scenario, which two statements are correct about proxy IDs? (Choose two.)

Options:

A.

Proxy IDs are used to configure traffic selectors.

B.

Proxy IDs are optional for Phase 2 session establishment.

C.

Proxy IDs must match for Phase 2 session establishment.

D.

Proxy IDs default to 0.0.0.0/0 for policy-based VPNs.

Buy Now
Questions 28

What is the default timeout value for TCP sessions on an SRX Series device?

Options:

A.

30 seconds

B.

60 minutes

C.

60 seconds

D.

30 minutes

Buy Now
Questions 29

Which statement about global NAT address persistence is correct?

Options:

A.

The same IP address from a source NAT pool will be assigned for all sessions from a given host.

B.

The same IP address from a source NAT pool is not guaranteed to be assigned for all sessions from a given host.

C.

The same IP address from a destination NAT pool will be assigned for all sessions for a given host.

D.

The same IP address from a destination NAT pool is not guaranteed to be assigned for all sessions for a given host.

Buy Now
Questions 30

You are assigned a project to configure SRX Series devices to allow connections to your webservers. The webservers have a private IP address, and the packets must use NAT to be accessible from the Internet. The webservers must use the same address for both connections from the Internet and communication with update servers.

Which NAT type must be used to complete this project?

Options:

A.

source NAT

B.

destination NAT

C.

static NAT

D.

hairpin NAT

Buy Now
Questions 31

Which two statements are correct about the integrated user firewall feature?(Choose two.)

Options:

A.

It maps IP addresses to individual users.

B.

It supports IPv4 addresses.

C.

It allows tracking of non-Windows Active Directory users.

D.

It uses the LDAP protocol.

Buy Now
Exam Code: JN0-231
Exam Name: Security-Associate (JNCIA-SEC)
Last Update: Mar 29, 2025
Questions: 105
$57.75  $164.99
$43.75  $124.99
$36.75  $104.99
buy now JN0-231