Winter Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: geek65

JN0-231 Security-Associate (JNCIA-SEC) Questions and Answers

Questions 4

Click the Exhibit button.

Which two statements are correct about the partial policies shown in the exhibit? (Choose two.)

Options:

A.

UDP traffic matched by the deny-all policy will be silently dropped.

B.

TCP traffic matched by the reject-all policy will have a TCP RST sent.

C.

TCP traffic matched from the zone trust is allowed by the permit-all policy.

D.

UDP traffic matched by the reject-all policy will be silently dropped.

Buy Now
Questions 5

What is the order of the first path packet processing when a packet enters a device?

Options:

A.

security policies –> screens –> zones

B.

screens –> security policies –> zones

C.

screens –> zones –> security policies

D.

security policies –> zones –> screens

Buy Now
Questions 6

Which two IPsec hashing algorithms are supported on an SRX Series device? (Choose two.)

Options:

A.

SHA-1

B.

SHAKE128

C.

MD5

D.

RIPEMD-256

Buy Now
Questions 7

What are two logical properties of an interface? (Choose two.)

Options:

A.

link mode

B.

IP address

C.

VLAN ID

D.

link speed

Buy Now
Questions 8

When are Unified Threat Management services performed in a packet flow?

Options:

A.

before security policies are evaluated

B.

as the packet enters an SRX Series device

C.

only during the first path process

D.

after network address translation

Buy Now
Questions 9

Which statement is correct about Web filtering?

Options:

A.

The Juniper Enhanced Web Filtering solution requires a locally managed server.

B.

The decision to permit or deny is based on the body content of an HTTP packet.

C.

The decision to permit or deny is based on the category to which a URL belongs.

D.

The client can receive an e-mail notification when traffic is blocked.

Buy Now
Questions 10

You want to enable the minimum Juniper ATP services on a branch SRX Series device.

In this scenario, what are two requirements to accomplish this task? (Choose two.)

Options:

A.

Install a basic Juniper ATP license on the branch device.

B.

Configure the juniper-atp user account on the branch device.

C.

Register for a Juniper ATP account on https://sky.junipersecurity.net.

D.

Execute the Juniper ATP script on the branch device.

Buy Now
Questions 11

Which two services does Juniper Connected Security provide? (Choose two.)

Options:

A.

protection against zero-day threats

B.

IPsec VPNs

C.

Layer 2 VPN tunnels

D.

inline malware blocking

Buy Now
Questions 12

SRX Series devices have a maximum of how many rollback configurations?

Options:

A.

40

B.

60

C.

50

D.

10

Buy Now
Questions 13

A security zone is configured with the source IP address 192.168.0.12/255.255.0.255 wildcard match.

In this scenario, which two IP packets will match the criteria? (Choose two.)

Options:

A.

192.168.1.21

B.

192.168.0.1

C.

192.168.1.12

D.

192.168.22.12

Buy Now
Questions 14

Which two statements are true about Juniper ATP Cloud? (Choose two.)

Options:

A.

Juniper ATP Cloud is an on-premises ATP appliance.

B.

Juniper ATP Cloud can be used to block and allow IPs.

C.

Juniper ATP Cloud is a cloud-based ATP subscription.

D.

Juniper ATP Cloud delivers intrusion protection services.

Buy Now
Questions 15

Which Juniper Networks solution uses static and dynamic analysis to search for day-zero malware threats?

Options:

A.

firewall filters

B.

UTM

C.

Juniper ATP Cloud

D.

IPS

Buy Now
Questions 16

What is the correct order in which interface names should be identified?

Options:

A.

system slot number –> interface media type –> port number –> line card slot number

B.

system slot number –> port number –> interface media type –> line card slot number

C.

interface media type –> system slot number –> line card slot number –> port number

D.

interface media type –> port number –> system slot number –> line card slot number

Buy Now
Questions 17

You are assigned a project to configure SRX Series devices to allow connections to your webservers. The webservers have a private IP address, and the packets must use NAT to be accessible from the Internet. The webservers must use the same address for both connections from the Internet and communication with update servers.

Which NAT type must be used to complete this project?

Options:

A.

source NAT

B.

destination NAT

C.

static NAT

D.

hairpin NAT

Buy Now
Questions 18

What information does the show chassis routing-engine command provide?

Options:

A.

chassis serial number

B.

resource utilization

C.

system version

D.

routing tables

Buy Now
Questions 19

You want to provide remote access to an internal development environment for 10 remote developers.

Which two components are required to implement Juniper Secure Connect to satisfy this requirement? (Choose two.)

Options:

A.

an additional license for an SRX Series device

B.

Juniper Secure Connect client software

C.

an SRX Series device with an SPC3 services card

D.

Marvis virtual network assistant

Buy Now
Questions 20

What is the order in which malware is detected and analyzed?

Options:

A.

antivirus scanning –> cache lookup –> dynamic analysis –> static analysis

B.

cache lookup –> antivirus scanning –> static analysis –> dynamic analysis

C.

antivirus scanning –> cache lookup –> static analysis –> dynamic analysis

D.

cache lookup –> static analysis –> dynamic analysis –> antivirus scanning

Buy Now
Questions 21

Which two statements about the Junos OS CLI are correct? (Choose two.)

Options:

A.

The default configuration requires you to log in as the admin user.

B.

A factory-default login assigns the hostname Amnesiac to the device.

C.

Most Juniper devices identify the root login prompt using the % character.

D.

Most Juniper devices identify the root login prompt using the > character.

Buy Now
Questions 22

Your company is adding IP cameras to your facility to increase physical security. You are asked to help protect these loT devices from becoming zombies in a DDoS attack.

Which Juniper ATP feature should you configure to accomplish this task?

Options:

A.

IPsec

B.

static NAT

C.

allowlists

D.

C&C feeds

Buy Now
Questions 23

An application firewall processes the first packet in a session for which the application has not yet been identified.

In this scenario, which action does the application firewall take on the packet?

Options:

A.

It allows the first packet.

B.

It denies the first packet and sends an error message to the user.

C.

It denies the first packet.

D.

It holds the first packet until the application is identified.

Buy Now
Questions 24

You are monitoring an SRX Series device that has the factory-default configuration applied.

In this scenario, where are log messages sent by default?

Options:

A.

Junos Space Log Director

B.

Junos Space Security Director

C.

to a local syslog server on the management network

D.

to a local log file named messages

Buy Now
Questions 25

Click the Exhibit button.

Referring to the exhibit, which two statements are correct about the ping command? (Choose two.)

Options:

A.

The DMZ routing-instance is the source.

B.

The 10.10.102.10 IP address is the source.

C.

The 10.10.102.10 IP address is the destination.

D.

The DMZ routing-instance is the destination.

Buy Now
Questions 26

What must be enabled on an SRX Series device for the reporting engine to create reports?

Options:

A.

System logging

B.

SNMP

C.

Packet capture

D.

Security logging

Buy Now
Questions 27

Which two traffic types are considered exception traffic and require some form of special handling by the PFE? (Choose two.)

Options:

A.

SSH sessions

B.

ICMP reply messages

C.

HTTP sessions

D.

traceroute packets

Buy Now
Questions 28

Which statement is correct about unified security policies on an SRX Series device?

Options:

A.

A zone-based policy is always evaluated first.

B.

The most restrictive policy is applied regardless of the policy level.

C.

A global policy is always evaluated first.

D.

The first policy rule is applied regardless of the policy level.

Buy Now
Questions 29

When operating in packet mode, which two services are available on the SRX Series device? (Choose two.)

Options:

A.

MPLS

B.

UTM

C.

CoS

D.

IDP

Buy Now
Questions 30

Your ISP gives you an IP address of 203.0.113.0/27 and informs you that your default gateway is 203.0.113.1. You configure destination NAT to your internal server, but the requests sent to the webserver at 203.0.113.5 are not arriving at the server.

In this scenario, which two configuration features need to be added? (Choose two.)

Options:

A.

firewall filter

B.

security policy

C.

proxy-ARP

D.

UTM policy

Buy Now
Questions 31

Which two user authentication methods are supported when using a Juniper Secure Connect VPN? (Choose two.)

Options:

A.

certificate-based

B.

multi-factor authentication

C.

local authentication

D.

active directory

Buy Now
Exam Code: JN0-231
Exam Name: Security-Associate (JNCIA-SEC)
Last Update: Jan 18, 2025
Questions: 105
JN0-231 pdf

JN0-231 PDF

$29.75  $84.99
JN0-231 Engine

JN0-231 Testing Engine

$35  $99.99
JN0-231 PDF + Engine

JN0-231 PDF + Testing Engine

$47.25  $134.99