PDF Download Free of JN0-231 Valid Practice Test Questions [Q47-Q63]

Share

PDF Download Free of JN0-231 Valid Practice Test Questions

JN0-231 Test Engine files, JN0-231 Dumps PDF


Juniper JN0-231 exam is a multiple-choice exam that consists of 65 questions. Candidates have 90 minutes to complete the exam, and they must achieve a passing score of 65% or higher to earn the certification. JN0-231 exam is available in several languages, including English, Japanese, and Chinese. Upon successfully passing the exam, candidates will be awarded the Juniper Networks Certified Associate - Security (JNCIA-SEC) certification, which is a valuable credential for networking and security professionals.


Juniper JN0-231 exam is an important certification for anyone who is interested in pursuing a career in network security. It covers a wide range of topics related to network security and is designed to test the candidate's knowledge and understanding of fundamental security concepts and technologies. The JNCIA-SEC certification is a valuable credential that is recognized by many industry leaders and is a prerequisite for more advanced certifications offered by Juniper Networks.

 

NEW QUESTION # 47
Unified threat management (UTM) inspects traffic from which three protocols? (Choose three.)

  • A. HTTP
  • B. FTP
  • C. SNMP
  • D. SMTP
  • E. SSH

Answer: A,B,D

Explanation:
https://www.inetzero.com/blog/unified-threat-management-deeper-dive-traffic-inspection/


NEW QUESTION # 48
You want to generate reports from the l-Web on an SRX Series device.
Which logging mode would you use in this scenario?

  • A. Stream
  • B. Syslog
  • C. Event
  • D. local

Answer: A


NEW QUESTION # 49
Which order is correct for Junos security devices that examine policies for transit traffic?

  • A. default policies
    global policies
    zone policies
  • B. global policies
    zone policies
    default policies
  • C. default policies
    zone policies
    global policies
  • D. zone policies
    global policies
    default policies

Answer: D


NEW QUESTION # 50
Screens on an SRX Series device protect against which two types of threats? (Choose two.)

  • A. zero-day outbreaks
  • B. IP spoofing
  • C. ICMP flooding
  • D. malicious e-mail attachments

Answer: B,C

Explanation:
ICMP flood
Use the ICMP flood IDS option to protect against ICMP flood attacks. An ICMP flood attack typically occurs when ICMP echo requests use all resources in responding, such that valid network traffic can no longer be processed.
The threshold value defines the number of ICMP packets per second (pps) allowed to be send to the same destination address before the device rejects further ICMP packets.
IP spoofing
Use the IP address spoofing IDS option to prevent spoofing attacks. IP spoofing occurs when an invalid source address is inserted in the packet header to make the packet appear to come from a trusted source.
https://www.juniper.net/documentation/us/en/software/junos/denial-of-service/topics/topic-map/security-introduction-to-adp.html


NEW QUESTION # 51
What are configuring the antispam UTM feature on an SRX Series device.
Which two actions would be performed by the SRX Series device for e-mail that is identified as spam? (Choose two.)

  • A. Quarantine e-mail
  • B. Queue the e-mail
  • C. Block the e-mail
  • D. Tag the e-mail

Answer: C,D


NEW QUESTION # 52
What are two features of the Juniper ATP Cloud service? (Choose two.)

  • A. malware detection
  • B. honeypot
  • C. sandbox
  • D. EX Series device integration

Answer: A,C


NEW QUESTION # 53
What must you do first to use the Monitor/Alarms/Policy Log workspace in J-Web?

  • A. You must enable event mode security logging on the SRX Series device.
  • B. You must enable logging that uses the SD-Syslog format.
  • C. You must enable stream mode security logging on the SRX Series device.
  • D. You must enable security logging that uses the TLS transport mode.

Answer: A


NEW QUESTION # 54
Which Juniper ATP feed provides a dynamic list of known botnet servers and known sources of malware downloads?

  • A. Geo IP feed
  • B. blocklist feed
  • C. C&C cloud feed
  • D. infected host cloud feed

Answer: D


NEW QUESTION # 55
Which statement about global NAT address persistence is correct?

  • A. The same IP address from a destination NAT pool is not guaranteed to be assigned for all sessions for a given host.
  • B. The same IP address from a source NAT pool will be assigned for all sessions from a given host.
  • C. The same IP address from a source NAT pool is not guaranteed to be assigned for all sessions from a given host.
  • D. The same IP address from a destination NAT pool will be assigned for all sessions for a given host.

Answer: B

Explanation:
Use the persistent-nat feature to ensure that all requests from the same internal transport address are mapped to the same reflexive transport address (the public IP address and port created by the NAT device closest to the STUN server). The source NAT rule action can use a source NAT pool (with or without port translation) or an egress interface.


NEW QUESTION # 56
What are two characteristic of static NAT SRX Series devices? (Choose two.)

  • A. Source and destination NAT rules take precedence over static NAT rules.
  • B. A reverse mapping rule is automatically created for the source translation.
  • C. Static NAT rule take precedence over source and destination NAT rules.
  • D. Static rules cannot coexist with destination NAT rules on the same SRX Series device configuration.

Answer: B,C


NEW QUESTION # 57
Referring to the exhibit.

Which type of NAT is being performed?

  • A. Source NAT without PAT
  • B. Source NAT with PAT
  • C. Destination NAT without PAT
  • D. Destination NAT with PAT

Answer: B


NEW QUESTION # 58
Click the Exhibit button.

Referring to the exhibit, a user is placed in which hierarchy when the exit command is run?

  • A. [edit]
    user@vSRX-1#
  • B. [edit security policies from-zone trust to-zone dmz]
    user@vSRX-1#
  • C. user@vSRX-1>
  • D. [edit security policies]
    user@vSRX-1#

Answer: A


NEW QUESTION # 59
You want to deploy a NAT solution.
In this scenario, which solution would provide a static translation without PAT?

  • A. pool-based NAT without PAT
  • B. interface-based source NAT
  • C. pool-based NAT with address shifting
  • D. pool-based NAT with PAT

Answer: C

Explanation:
Translation of the original source IP address to an IP address from a user-defined address pool by shifting the IP addresses. This type of translation is one-to-one, static, and without port address translation. If the original source IP address range is larger than the IP address range in the user-defined pool, untranslated packets are dropped. https://www.juniper.net/documentation/us/en/software/junos/nat/topics/topic-map/nat-security-source-and-source-pool.html


NEW QUESTION # 60
Which statements about NAT are correct? (Choose two.)

  • A. Source NAT translates the source IP address of packet.
  • B. When multiple NAT rules have overlapping match conditions, the rule listed first is chosen.
  • C. When multiple NAT rules have overlapping match conditions, the most specific rule is chosen.
  • D. Source NAT translates the source port and destination IP address.

Answer: A,B


NEW QUESTION # 61
You want to integrate an SRX Series device with SKY ATP.
What is the first action to accomplish task?

  • A. Copy the operational script from the Sky ATP Web UI.
  • B. Issue the commit script to register the SRX Series device.
  • C. Create the SSL VPN tunnel between the SRX Series device and Sky ATP.
  • D. Create an account with the Sky ATP Web UI.

Answer: D


NEW QUESTION # 62
What are three Junos UTM features? (Choose three.)

  • A. screens
  • B. Web filtering
  • C. antivirus
  • D. content filtering
  • E. IDP/IPS

Answer: B,C,D


NEW QUESTION # 63
......

Pass Your JNCIA-SEC JN0-231 Exam on Apr 17, 2024 with 103 Questions: https://certificationsdesk.examslabs.com/Juniper/JNCIA-SEC/best-JN0-231-exam-dumps.html