JN0-231 Questions Prepare with Learning Information! 2024 Regularly updated
Get JN0-231 Products Practice Material for JN0-231 Exam Question Preparation
To pass the Juniper JN0-231 exam, candidates must have a solid understanding of security concepts and their application in network environments. They must also be well-versed in the use of Juniper Networks products and the various security features they offer. In addition, candidates must be able to identify and mitigate common security threats, such as malware and phishing attacks.
NEW QUESTION # 45
Which two statements about user-defined security zones are correct? (Choose two.)
- A. User-defined security zones do not apply to transit traffic.
- B. Users can share security zones between routing instances.
- C. Users cannot share security zones between routing instances.
- D. Users can configure multiple security zones.
Answer: B,D
Explanation:
User-defined security zones allow users to configure multiple security zones and share them between routing instances. This allows users to easily manage multiple security zones and their associated policies. For example, a user can create a security zone for corporate traffic, a security zone for guest traffic, and a security zone for public traffic, and then configure policies to control the flow of traffic between each of these security zones. Transit traffic can also be managed using user-defined security zones, as the policies applied to these zones will be applied to the transit traffic as well.
NEW QUESTION # 46
On an SRX device, you want to regulate traffic base on network segments.
In this scenario, what do you configure to accomplish this task?
- A. ALGs
- B. Screens
- C. Zones
- D. NAT
Answer: C
NEW QUESTION # 47
Which Statement is correct about Sky ATP?
- A. Sky ATP relies on the SRX series device to open and analyze suspect file attachments
- B. Sky ATP is a local hardware-based security threat analyzer that performs multiple tasks.
- C. Sky ATP can provide live threat feeds to SRX series devices
- D. The local Sky ATP platform downloads the latest threat from managed site
Answer: C
NEW QUESTION # 48
Which two elements are needed on an SRX Series device to set up a remote syslog server? (Choose two.)
- A. Data type
- B. Data size
- C. IP address
- D. Data throughput
Answer: A,C
NEW QUESTION # 49
What is the default timeout value for TCP sessions on an SRX Series device?
- A. 60 seconds
- B. 30 seconds
- C. 30 minutes
- D. 60 minutes
Answer: C
Explanation:
By default, TCP has a 30-minute idle timeout, and UDP has a 60-second idle timeout. Additionally, known IP protocols have a 30-minute timeout, whereas unknown ones have a 60-second timeout. Setting the inactivity timeout is very useful, particularly if you are concerned about applications either timing out or remaining idle for too long and filling up the session table. According to the Juniper SRX Series Services Guide, this can be configured using the 'timeout inactive' statement for the security policy.
NEW QUESTION # 50
You are assigned a project to configure SRX Series devices to allow connections to your webservers. The webservers have a private IP address, and the packets must use NAT to be accessible from the Internet. You do not want the webservers to initiate connections with external update servers on the Internet using the same IP address as customers use to access them.
Which two NAT types must be used to complete this project? (Choose two.)
- A. destination NAT
- B. hairpin NAT
- C. source NAT
- D. static NAT
Answer: A,C
NEW QUESTION # 51
Which two criteria should a zone-based security policy include? (Choose two.)
- A. a destination port
- B. a source port
- C. an action
- D. zone context
Answer: A,B
Explanation:
A security policy is a set of statements that controls traffic from a specified source to a specified destination using a specified service. A policy permits, denies, or tunnels specified types of traffic unidirectionally between two points.
Each policy consists of:
A unique name for the policy.
A from-zone and a to-zone, for example: user@host# set security policies from-zone untrust to-zone untrust A set of match criteria defining the conditions that must be satisfied to apply the policy rule. The match criteria are based on a source IP address, destination IP address, and applications. The user identity firewall provides greater granularity by including an additional tuple, source-identity, as part of the policy statement.
A set of actions to be performed in case of a match-permit, deny, or reject.
Accounting and auditing elements-counting, logging, or structured system logging.
https://www.juniper.net/documentation/us/en/software/junos/security-policies/topics/topic-map/security-policy-configuration.html
NEW QUESTION # 52
Exhibit.
Which statement is correct regarding the interface configuration shown in the exhibit?
- A. The IP address has an invalid subnet mask.
- B. The IP address is assigned to unit 0.
- C. The interface is assigned to the trust zone by default.
- D. The interface MTU has been increased.
Answer: B
NEW QUESTION # 53
Which Juniper ATP feed provides a dynamic list of known botnet servers and known sources of malware downloads?
- A. infected host cloud feed
- B. blocklist feed
- C. Geo IP feed
- D. C&C cloud feed
Answer: A
NEW QUESTION # 54
You are investigating a communication problem between two hosts and have opened a session on the SRX Series device closest to one of the hosts and entered the show security flow session command.
What information will this command provide? (Choose two.)
- A. The security policy name that is controlling the session.
- B. The end-to-end data path that the packets are taking.
- C. The IP address of the host that initiates the session.
- D. The total active time of the session.
Answer: A,C
NEW QUESTION # 55
Which two match conditions would be used in both static NAT and destination NAT rule sets? (Choose two.)
- A. Destination zone
- B. Source zone
- C. Destination interface
- D. Source interface
Answer: B,C
NEW QUESTION # 56
Your ISP gives you an IP address of 203.0.113.0/27 and informs you that your default gateway is 203.0.113.1.
You configure destination NAT to your internal server, but the requests sent to the webserver at 203.0.113.5 are not arriving at the server.
In this scenario, which two configuration features need to be added? (Choose two.)
- A. proxy-ARP
- B. firewall filter
- C. security policy
- D. UTM policy
Answer: A,C
NEW QUESTION # 57
Which two non-configurable zones exist by default on an SRX Series device? (Choose two.)
- A. Junos-host
- B. null
- C. functional
- D. management
Answer: A,B
Explanation:
Junos-host and null are two non-configurable zones that exist by default on an SRX Series device. Junos-host is the default zone for all internal interfaces and services, such as management and other loopback interfaces. The null zone is used to accept all traffic that is not explicitly accepted by other security policies, and is the default zone for all unclassified traffic. Both zones cannot be modified or deleted.
NEW QUESTION # 58
Which UTM feature should you use to protect users from visiting certain blacklisted websites?
- A. antispam
- B. Content filtering
- C. Antivirus
- D. Web filtering
Answer: D
NEW QUESTION # 59
Which two private cloud solution support vSRX devices? (Choose two.)
- A. Contrail Cloud
- B. Amazon Web Services (AWS)
- C. VMware NSX
- D. Microsoft Azure
- E. VMware Web Services (AWS)
Answer: B,D
NEW QUESTION # 60
When configuring antispam, where do you apply any local lists that are configured?
- A. advanced security policy
- B. custom objects
- C. antispam feature-profile
- D. antispam UTM policy
Answer: A
NEW QUESTION # 61
Unified threat management (UTM) inspects traffic from which three protocols? (Choose three.)
- A. FTP
- B. SMTP
- C. SSH
- D. HTTP
- E. SNMP
Answer: A,B,D
Explanation:
https://www.inetzero.com/blog/unified-threat-management-deeper-dive-traffic-inspection/
NEW QUESTION # 62
Which two feature on the SRX Series device are common across all Junos devices? (Choose two.)
- A. Stateless firewall filters
- B. screens
- C. UTM services
- D. The separation of control and forwarding planes
Answer: A,D
NEW QUESTION # 63
What are three primary match criteria used in a Junos security policy? (Choose three.)
- A. source port
- B. source address
- C. class
- D. destination address
- E. application
Answer: B,D,E
NEW QUESTION # 64
What is the purpose of the Shadow Policies workspace in J-Web?
- A. The Shadow Policies workspace shows unused IPS policies due to policy overlap.
- B. The Shadow Policies workspace shows used IPS policies due to policy overlap
- C. The Shadow Policies workspace shows used security policies due to policy overlap
- D. The Shadow Policies workspace shows unused security policies due to policy overlap.
Answer: D
NEW QUESTION # 65
Referring to the exhibit.
You have configured antispam to allow e-mail from example.com, however the logs you see that [email protected] is blocked What are two ways to solve this problem?
- A. Add [email protected] to the profile antispam address whitelist.
- B. Delete [email protected] from the profile antispam address blacklist
- C. Delete [email protected] from the profile antispam address whitelist
- D. Verify connectivity with the SBL server.
Answer: A,B
NEW QUESTION # 66
Which statement is correct about Junos security policies?
- A. Security policies enforce rules that should be applied to traffic transiting an SRX Series device.
- B. Security policies determine which users are allowed to access an SRX Series device.
- C. Security policies control the flow of internal traffic within an SRX Series device.
- D. Security policies identity groups of users that have access to different features on an SRX Series device.
Answer: A
Explanation:
The correct statement about Junos security policies is that they enforce rules that should be applied to traffic transiting an SRX Series device. Security policies control the flow of traffic between different zones on the SRX Series device, and dictate which traffic is allowed or denied. They can also specify which application and service requests are allowed or blocked. More information about Junos security policies can be found in the Juniper Networks technical documentation here: https://www.juniper.net/documentation/en_US/junos/topics/task/configuration/security-policies-overview.html.
NEW QUESTION # 67
You have created a zones-based security policy that permits traffic to a specific webserver for the marketing team. Other groups in the company are not permitted to access the webserver. When marketing users attempt to access the server they are unable to do so.
What are two reasons for this access failure? (Choose two.)
- A. You failed to position the policy before the policy that denies access the webserver
- B. You failed to commit the policy change.
- C. You failed to change the source zone to include any source zone.
- D. You failed to position the policy after the policy that denies access to the webserver.
Answer: A,B
NEW QUESTION # 68
......
Click on the link below for getting more info about the Juniper JN0-231 Exam:
Official link to the Juniper JN0-231 Exam
Most Reliable Juniper JN0-231 Training Materials: https://www.examcollectionpass.com/Juniper/JN0-231-practice-exam-dumps.html
The Realest Study Materials JN0-231 Dumps: https://drive.google.com/open?id=14dLIN2nN1YYzzJgoChCq-q2PVQbxV6RN