Labour Day Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: scxmas70

JN0-231 Exam Dumps - Security-Associate (JNCIA-SEC)

Question # 4

Click the Exhibit button.

You are asked to allow only ping and SSH access to the security policies shown in the exhibit.

Which statement will accomplish this task?

A.

Rename policy Rule-2 to policy Rule-0.

B.

Insert policy Rule-2 before policy Rule-1.

C.

Replace application any with application [junos-ping junos-ssh] in policy Rule-1.

D.

Rename policy Rule-1 to policy Rule-3.

Full Access
Question # 5

You want to block executable files ("exe) from being downloaded onto your network.

Which UTM feature would you use in this scenario?

A.

IPS

B.

Web filtering

C.

content filtering

D.

antivirus

Full Access
Question # 6

Which two non-configurable zones exist by default on an SRX Series device? (Choose two.)

A.

Junos-host

B.

functional

C.

null

D.

management

Full Access
Question # 7

Click the Exhibit button.

Which two statements are correct about the partial policies shown in the exhibit? (Choose two.)

A.

UDP traffic matched by the deny-all policy will be silently dropped.

B.

TCP traffic matched by the reject-all policy will have a TCP RST sent.

C.

TCP traffic matched from the zone trust is allowed by the permit-all policy.

D.

UDP traffic matched by the reject-all policy will be silently dropped.

Full Access
Question # 8

What are two features of the Juniper ATP Cloud service? (Choose two.)

A.

sandbox

B.

malware detection

C.

EX Series device integration

D.

honeypot

Full Access
Question # 9

You are assigned a project to configure SRX Series devices to allow connections to your webservers. The webservers have a private IP address, and the packets must use NAT to be accessible from the Internet. The webservers must use the same address for both connections from the Internet and communication with update servers.

Which NAT type must be used to complete this project?

A.

source NAT

B.

destination NAT

C.

static NAT

D.

hairpin NAT

Full Access
Question # 10

Which two statements are correct about global policies? (Choose two.)

A.

Global policies are evaluated after default policies.

B.

Global policies do not have to reference zone context.

C.

Global policies are evaluated before default policies.

D.

Global policies must reference zone contexts.

Full Access
Question # 11

Your ISP gives you an IP address of 203.0.113.0/27 and informs you that your default gateway is 203.0.113.1. You configure destination NAT to your internal server, but the requests sent to the webserver at 203.0.113.5 are not arriving at the server.

In this scenario, which two configuration features need to be added? (Choose two.)

A.

firewall filter

B.

security policy

C.

proxy-ARP

D.

UTM policy

Full Access
Question # 12

You are investigating a communication problem between two hosts and have opened a session on the SRX Series device closest to one of the hosts and entered the show security flow session command.

What information will this command provide? (Choose two.)

A.

The total active time of the session.

B.

The end-to-end data path that the packets are taking.

C.

The IP address of the host that initiates the session.

D.

The security policy name that is controlling the session.

Full Access
Question # 13

When creating a site-to-site VPN using the J-Web shown in the exhibit, which statement is correct?

A.

The remote gateway is configured automatically based on the local gateway settings.

B.

RIP, OSPF, and BGP are supported under Routing mode.

C.

The authentication method is pre-shared key or certificate based.

D.

Privately routable IP addresses are required.

Full Access
Question # 14

What is the order of the first path packet processing when a packet enters a device?

A.

security policies –> screens –> zones

B.

screens –> security policies –> zones

C.

screens –> zones –> security policies

D.

security policies –> zones –> screens

Full Access
Question # 15

Which Web filtering solution uses a direct Internet-based service for URL categorization?

A.

Juniper ATP Cloud

B.

Websense Redirect

C.

Juniper Enhanced Web Filtering

D.

local blocklist

Full Access