Winter Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: dumps65

Juniper JN0-231 Dumps

Page: 1 / 10
Total 101 questions

Security-Associate (JNCIA-SEC) Questions and Answers

Question 1

Which two addresses are valid address book entries? (Choose two.)

Options:

A.

173.145.5.21/255.255.255.0

B.

153.146.0.145/255.255.0.255

C.

203.150.108.10/24

D.

191.168.203.0/24

Question 2

What is the number of concurrent Secure Connect user licenses that an SRX Series device has by default?

Options:

A.

3

B.

4

C.

2

D.

5

Question 3

You are assigned a project to configure SRX Series devices to allow connections to your webservers. The webservers have a private IP address, and the packets must use NAT to be accessible from the

Internet. You do not want the webservers to initiate connections with external update servers on the Internet using the same IP address as customers use to access them.

Which two NAT types must be used to complete this project? (Choose two.)

Options:

A.

static NAT

B.

hairpin NAT

C.

destination NAT

D.

source NAT

Question 4

Which two non-configurable zones exist by default on an SRX Series device? (Choose two.)

Options:

A.

Junos-host

B.

functional

C.

null

D.

management

Question 5

Which Web filtering solution uses a direct Internet-based service for URL categorization?

Options:

A.

Juniper ATP Cloud

B.

Websense Redirect

C.

Juniper Enhanced Web Filtering

D.

local blocklist

Question 6

Which two statements are correct about IPsec security associations? (Choose two.)

Options:

A.

IPsec security associations are bidirectional.

B.

IPsec security associations are unidirectional.

C.

IPsec security associations are established during IKE Phase 1 negotiations.

D.

IPsec security associations are established during IKE Phase 2 negotiations.

Question 7

You are deploying an SRX Series firewall with multiple NAT scenarios.

In this situation, which NAT scenario takes priority?

Options:

A.

interface NAT

B.

source NAT

C.

static NAT

D.

destination NAT

Question 8

What are two logical properties of an interface? (Choose two.)

Options:

A.

link mode

B.

IP address

C.

VLAN ID

D.

link speed

Question 9

Click the Exhibit button.

as

Referring to the exhibit, which two statements are correct about the ping command? (Choose two.)

Options:

A.

The DMZ routing-instance is the source.

B.

The 10.10.102.10 IP address is the source.

C.

The 10.10.102.10 IP address is the destination.

D.

The DMZ routing-instance is the destination.

Question 10

Which two IKE Phase 1 configuration options must match on both peers to successfully establish a tunnel? (Choose two.)

Options:

A.

VPN name

B.

gateway interfaces

C.

IKE mode

D.

Diffie-Hellman group

Question 11

What is the default timeout value for TCP sessions on an SRX Series device?

Options:

A.

30 seconds

B.

60 minutes

C.

60 seconds

D.

30 minutes

Question 12

Which Juniper Networks solution uses static and dynamic analysis to search for day-zero malware threats?

Options:

A.

firewall filters

B.

UTM

C.

Juniper ATP Cloud

D.

IPS

Question 13

You are configuring an SRX Series device. You have a set of servers inside your private network that need one-to-one mappings to public IP addresses.

Which NAT configuration is appropriate in this scenario?

Options:

A.

source NAT with PAT

B.

destination NAT

C.

NAT-T

D.

static NAT

Question 14

What are two functions of Juniper ATP Cloud? (Choose two.)

Options:

A.

malware inspection

B.

Web content filtering

C.

DDoS protection

D.

Geo IP feeds

Question 15

You must monitor security policies on SRX Series devices dispersed throughout locations in your organization using a 'single pane of glass' cloud-based solution.

Which solution satisfies the requirement?

Options:

A.

Juniper Sky Enterprise

B.

J-Web

C.

Junos Secure Connect

D.

Junos Space

Page: 1 / 10
Total 101 questions