New Year Special 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: best70

JN0-231 Security-Associate (JNCIA-SEC) Questions and Answers

Questions 4

You are asked to verify that a license for AppSecure is installed on an SRX Series device.

In this scenario, which command will provide you with the required information?

Options:

A.

user@srx> show system license

B.

user@srx> show services accounting

C.

user@srx> show configuration system

D.

user@srx> show chassis firmware

Buy Now
Questions 5

SRX Series devices have a maximum of how many rollback configurations?

Options:

A.

40

B.

60

C.

50

D.

10

Buy Now
Questions 6

Which statement is correct about packet mode processing?

Options:

A.

Packet mode enables session-based processing of incoming packets.

B.

Packet mode works with NAT, VPNs, UTM, IDP, and other advanced security services.

C.

Packet mode bypasses the flow module.

D.

Packet mode is the basis for stateful processing.

Buy Now
Questions 7

What are two valid address books? (Choose two.)

Options:

A.

66.129.239.128/25

B.

66.129.239.154/24

C.

66.129.239.0/24

D.

66.129.239.50/25

Buy Now
Questions 8

Screens on an SRX Series device protect against which two types of threats? (Choose two.)

Options:

A.

IP spoofing

B.

ICMP flooding

C.

zero-day outbreaks

D.

malicious e-mail attachments

Buy Now
Questions 9

Which three Web filtering deployment actions are supported by Junos? (Choose three.)

Options:

A.

Use IPS.

B.

Use local lists.

C.

Use remote lists.

D.

Use Websense Redirect.

E.

Use Juniper Enhanced Web Filtering.

Questions 10

Which Web filtering solution uses a direct Internet-based service for URL categorization?

Options:

A.

Juniper ATP Cloud

B.

Websense Redirect

C.

Juniper Enhanced Web Filtering

D.

local blocklist

Buy Now
Questions 11

Which order is correct for Junos security devices that examine policies for transit traffic?

Options:

A.

zone policies

global policies

default policies

B.

default policies

zone policies

global policies

C.

default policies

global policies

zone policies

D.

global policies

zone policies

default policies

Buy Now
Questions 12

Which two statements are correct about the default behavior on SRX Series devices? (Choose two.)

Options:

A.

The SRX Series device is in flow mode.

B.

The SRX Series device supports stateless firewalls filters.

C.

The SRX Series device is in packet mode.

D.

The SRX Series device does not support stateless firewall filters.

Buy Now
Questions 13

In J-Web. the management and loopback address configuration option allows you to configure which area?

Options:

A.

the IP address of the primary Gigabit Ethernet port

B.

the IP address of the Network Time Protocol server

C.

the CIDR address

D.

the IP address of the device management port

Buy Now
Questions 14

Exhibit.

Which two statements are correct referring to the output shown in the exhibit? (Choose two.)

Options:

A.

FTP and ping access for the Trust-DMZ-Access policy is permitted.

B.

FTP and ping access for the Trust-DMZ-Access policy is denied.

C.

The SSH access for the Trust-DMZ-Block policy is permitted.

D.

The SSH access for the Trust-DMZ-Block policy is denied.

Buy Now
Questions 15

Which two statements are correct about the null zone on an SRX Series device? (Choose two.)

Options:

A.

The null zone is created by default.

B.

The null zone is a functional security zone.

C.

Traffic sent or received by an interface in the null zone is discarded.

D.

You must enable the null zone before you can place interfaces into it.

Buy Now
Questions 16

What does the number ‘’2’’ indicate in interface ge—0/1/2?

Options:

A.

The interface logical number

B.

The physical interface card (PIC)

C.

The port number

D.

The flexible PIC concentrator (FPC)

Buy Now
Questions 17

Which two UTM features should be used for tracking productivity and corporate user behavior? (Choose two.)

Options:

A.

the content filtering UTM feature

B.

the antivirus UTM feature

C.

the Web filtering UTM feature

D.

the antispam UTM feature

Buy Now
Questions 18

Your company is adding IP cameras to your facility to increase physical security. You are asked to help protect these loT devices from becoming zombies in a DDoS attack.

Which Juniper ATP feature should you configure to accomplish this task?

Options:

A.

IPsec

B.

static NAT

C.

allowlists

D.

C&C feeds

Buy Now
Questions 19

What does the number “2” indicate in interface ge-0/1/2?

Options:

A.

the physical interface card (PIC)

B.

the flexible PIC concentrator (FPC)

C.

the interface logical number

D.

the port number

Buy Now
Questions 20

You are asked to configure your SRX Series device to block all traffic from certain countries. The solution must be automatically updated as IP prefixes become allocated to those certain countries.

Which Juniper ATP solution will accomplish this task?

Options:

A.

Geo IP

B.

unified security policies

C.

IDP

D.

C&C feed

Buy Now
Questions 21

Which statement about NAT is correct?

Options:

A.

Destination NAT takes precedence over static NAT.

B.

Source NAT is processed before security policy lookup.

C.

Static NAT is processed after forwarding lookup.

D.

Static NAT takes precedence over destination NAT.

Buy Now
Questions 22

What is the correct order in which interface names should be identified?

Options:

A.

system slot number –> interface media type –> port number –> line card slot number

B.

system slot number –> port number –> interface media type –> line card slot number

C.

interface media type –> system slot number –> line card slot number –> port number

D.

interface media type –> port number –> system slot number –> line card slot number

Buy Now
Questions 23

What is the default timeout value for TCP sessions on an SRX Series device?

Options:

A.

30 seconds

B.

60 minutes

C.

60 seconds

D.

30 minutes

Buy Now
Questions 24

You are assigned a project to configure SRX Series devices to allow connections to your webservers. The webservers have a private IP address, and the packets must use NAT to be accessible from the

Internet. You do not want the webservers to initiate connections with external update servers on the Internet using the same IP address as customers use to access them.

Which two NAT types must be used to complete this project? (Choose two.)

Options:

A.

static NAT

B.

hairpin NAT

C.

destination NAT

D.

source NAT

Buy Now
Questions 25

You have multiple branch locations using an SRX Series device. You want a cloud-based solution to configure and monitor this device.

this scenario, which solution would you use?

Options:

A.

J-Web

B.

Juniper Sky Enterprise

C.

Junos Space Security Director

D.

Juniper Secure Analytics

Buy Now
Questions 26

Which two statements are correct about screens? (Choose two.)

Options:

A.

Screens process inbound packets.

B.

Screens are processed on the routing engine.

C.

Screens process outbound packets.

D.

Screens are processed on the flow module.

Buy Now
Questions 27

You are installing a new SRX Series device and you are only provided one IP address from your ISP.

In this scenario, which NAT solution would you implement?

Options:

A.

pool-based NAT with PAT

B.

pool-based NAT with address shifting

C.

interface-based source NAT

D.

pool-based NAT without PAT

Buy Now
Questions 28

When configuring antispam, where do you apply any local lists that are configured?

Options:

A.

custom objects

B.

advanced security policy

C.

antispam feature-profile

D.

antispam UTM policy

Buy Now
Questions 29

You are creating Ipsec connections.

In this scenario, which two statements are correct about proxy IDs? (Choose two.)

Options:

A.

Proxy IDs are used to configure traffic selectors.

B.

Proxy IDs are optional for Phase 2 session establishment.

C.

Proxy IDs must match for Phase 2 session establishment.

D.

Proxy IDs default to 0.0.0.0/0 for policy-based VPNs.

Buy Now
Questions 30

Which three operating systems are supported for installing and running Juniper Secure Connect client software? (Choose three.)

Options:

A.

Windows 7

B.

Android

C.

Windows 10

D.

Linux

E.

macOS

Buy Now
Questions 31

Which two user authentication methods are supported when using a Juniper Secure Connect VPN? (Choose two.)

Options:

A.

certificate-based

B.

multi-factor authentication

C.

local authentication

D.

active directory

Buy Now
Exam Code: JN0-231
Exam Name: Security-Associate (JNCIA-SEC)
Last Update: Dec 26, 2024
Questions: 105

PDF + Testing Engine

$134.99

Testing Engine

$99.99

PDF (Q&A)

$84.99