Winter Special Sale - Limited Time 60% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 575363r9

Welcome To DumpsPedia

JN0-231 Sample Questions Answers

Questions 4

Which two services does Juniper Connected Security provide? (Choose two.)

Options:

A.

protection against zero-day threats

B.

IPsec VPNs

C.

Layer 2 VPN tunnels

D.

inline malware blocking

Buy Now
Questions 5

Screens on an SRX Series device protect against which two types of threats? (Choose two.)

Options:

A.

IP spoofing

B.

ICMP flooding

C.

zero-day outbreaks

D.

malicious e-mail attachments

Buy Now
Questions 6

Which statement about NAT is correct?

Options:

A.

Destination NAT takes precedence over static NAT.

B.

Source NAT is processed before security policy lookup.

C.

Static NAT is processed after forwarding lookup.

D.

Static NAT takes precedence over destination NAT.

Buy Now
Questions 7

Which statement is correct about packet mode processing?

Options:

A.

Packet mode enables session-based processing of incoming packets.

B.

Packet mode works with NAT, VPNs, UTM, IDP, and other advanced security services.

C.

Packet mode bypasses the flow module.

D.

Packet mode is the basis for stateful processing.

Buy Now
Questions 8

Which two statements are correct about the default behavior on SRX Series devices? (Choose two.)

Options:

A.

The SRX Series device is in flow mode.

B.

The SRX Series device supports stateless firewalls filters.

C.

The SRX Series device is in packet mode.

D.

The SRX Series device does not support stateless firewall filters.

Buy Now
Questions 9

You want to deploy a NAT solution.

In this scenario, which solution would provide a static translation without PAT?

Options:

A.

interface-based source NAT

B.

pool-based NAT with address shifting

C.

pool-based NAT with PAT

D.

pool-based NAT without PAT

Buy Now
Questions 10

What are two functions of Juniper ATP Cloud? (Choose two.)

Options:

A.

malware inspection

B.

Web content filtering

C.

DDoS protection

D.

Geo IP feeds

Buy Now
Questions 11

Your ISP gives you an IP address of 203.0.113.0/27 and informs you that your default gateway is 203.0.113.1. You configure destination NAT to your internal server, but the requests sent to the webserver at 203.0.113.5 are not arriving at the server.

In this scenario, which two configuration features need to be added? (Choose two.)

Options:

A.

firewall filter

B.

security policy

C.

proxy-ARP

D.

UTM policy

Buy Now
Questions 12

What is an IP addressing requirement for an IPsec VPN using main mode?

Options:

A.

One peer must have dynamic IP addressing.

B.

One peer must have static IP addressing.

C.

Both peers must have dynamic IP addresses.

D.

Both peers must have static IP addressing.

Buy Now
Questions 13

You want to prevent other users from modifying or discarding your changes while you are also editing the configuration file.

In this scenario, which command would accomplish this task?

Options:

A.

configure master

B.

cli privileged

C.

configure exclusive

D.

configure

Buy Now
Questions 14

What are two characteristics of a null zone? (Choose two.)

Options:

A.

The null zone is configured by the super user.

B.

By default, all unassigned interfaces are placed in the null zone.

C.

All ingress and egress traffic on an interface in a null zone is permitted.

D.

When an interface is deleted from a zone, it is assigned back to the null zone.

Buy Now
Questions 15

Which two traffic types are considered exception traffic and require some form of special handling by the PFE? (Choose two.)

Options:

A.

SSH sessions

B.

ICMP reply messages

C.

HTTP sessions

D.

traceroute packets

Buy Now
Questions 16

You are creating Ipsec connections.

In this scenario, which two statements are correct about proxy IDs? (Choose two.)

Options:

A.

Proxy IDs are used to configure traffic selectors.

B.

Proxy IDs are optional for Phase 2 session establishment.

C.

Proxy IDs must match for Phase 2 session establishment.

D.

Proxy IDs default to 0.0.0.0/0 for policy-based VPNs.

Buy Now
Questions 17

Which two IKE Phase 1 configuration options must match on both peers to successfully establish a tunnel? (Choose two.)

Options:

A.

VPN name

B.

gateway interfaces

C.

IKE mode

D.

Diffie-Hellman group

Buy Now
Questions 18

Unified threat management (UTM) inspects traffic from which three protocols? (Choose three.)

Options:

A.

FTP

B.

SMTP

C.

SNMP

D.

HTTP

E.

SSH

Buy Now
Questions 19

Which two statements about the Junos OS CLI are correct? (Choose two.)

Options:

A.

The default configuration requires you to log in as the admin user.

B.

A factory-default login assigns the hostname Amnesiac to the device.

C.

Most Juniper devices identify the root login prompt using the % character.

D.

Most Juniper devices identify the root login prompt using the > character.

Buy Now
Questions 20

You must monitor security policies on SRX Series devices dispersed throughout locations in your organization using a 'single pane of glass' cloud-based solution.

Which solution satisfies the requirement?

Options:

A.

Juniper Sky Enterprise

B.

J-Web

C.

Junos Secure Connect

D.

Junos Space

Buy Now
Questions 21

You are asked to verify that a license for AppSecure is installed on an SRX Series device.

In this scenario, which command will provide you with the required information?

Options:

A.

user@srx> show system license

B.

user@srx> show services accounting

C.

user@srx> show configuration system

D.

user@srx> show chassis firmware

Buy Now
Questions 22

Which two statements are correct about the integrated user firewall feature?(Choose two.)

Options:

A.

It maps IP addresses to individual users.

B.

It supports IPv4 addresses.

C.

It allows tracking of non-Windows Active Directory users.

D.

It uses the LDAP protocol.

Buy Now
Questions 23

You are assigned a project to configure SRX Series devices to allow connections to your webservers. The webservers have a private IP address, and the packets must use NAT to be accessible from the

Internet. You do not want the webservers to initiate connections with external update servers on the Internet using the same IP address as customers use to access them.

Which two NAT types must be used to complete this project? (Choose two.)

Options:

A.

static NAT

B.

hairpin NAT

C.

destination NAT

D.

source NAT

Buy Now
Questions 24

Your company is adding IP cameras to your facility to increase physical security. You are asked to help protect these loT devices from becoming zombies in a DDoS attack.

Which Juniper ATP feature should you configure to accomplish this task?

Options:

A.

IPsec

B.

static NAT

C.

allowlists

D.

C&C feeds

Buy Now
Questions 25

You are assigned a project to configure SRX Series devices to allow connections to your webservers. The webservers have a private IP address, and the packets must use NAT to be accessible from the Internet. The webservers must use the same address for both connections from the Internet and communication with update servers.

Which NAT type must be used to complete this project?

Options:

A.

source NAT

B.

destination NAT

C.

static NAT

D.

hairpin NAT

Buy Now
Questions 26

Which two components are part of a security zone? (Choose two.)

Options:

A.

inet.0

B.

fxp0

C.

address book

D.

ge-0/0/0.0

Buy Now
Questions 27

Click the Exhibit button.

You are asked to allow only ping and SSH access to the security policies shown in the exhibit.

Which statement will accomplish this task?

Options:

A.

Rename policy Rule-2 to policy Rule-0.

B.

Insert policy Rule-2 before policy Rule-1.

C.

Replace application any with application [junos-ping junos-ssh] in policy Rule-1.

D.

Rename policy Rule-1 to policy Rule-3.

Buy Now
Questions 28

What are two features of the Juniper ATP Cloud service? (Choose two.)

Options:

A.

sandbox

B.

malware detection

C.

EX Series device integration

D.

honeypot

Buy Now
Questions 29

Which security policy type will be evaluated first?

Options:

A.

A zone policy with no dynamic application set

B.

A global with no dynamic application set

C.

A zone policy with a dynamic application set

D.

A global policy with a dynamic application set

Buy Now
Questions 30

Which two statements are correct about screens? (Choose two.)

Options:

A.

Screens process inbound packets.

B.

Screens are processed on the routing engine.

C.

Screens process outbound packets.

D.

Screens are processed on the flow module.

Buy Now
Exam Code: JN0-231
Exam Name: Security-Associate (JNCIA-SEC)
Last Update: Dec 2, 2024
Questions: 101
$66  $164.99
$50  $124.99
$42  $104.99
buy now JN0-231