Juniper JN0-231 Practice Test Pdf Exam Material
JN0-231 Answers JN0-231 Free Demo Are Based On The Real Exam
NEW QUESTION # 52
Click the Exhibit button
You have configured source ... Being received By the SRX series Which features must be configured
- A. Port Forwarding
- B. Destination NAT
- C. Reverse static NAT
- D. Proxy ARP
Answer: D
NEW QUESTION # 53
Unified threat management (UTM) inspects traffic from which three protocols? (Choose three.)
- A. SNMP
- B. FTP
- C. SSH
- D. SMTP
- E. HTTP
Answer: B,D,E
Explanation:
https://www.inetzero.com/blog/unified-threat-management-deeper-dive-traffic-inspection/
NEW QUESTION # 54
The free licensing model for Sky ATP includes which features? (Choose two.)
- A. Infected host blocking
- B. Compromised endpoint dashboard
- C. C & C feeds
- D. Executable file inspection
Answer: A,D
NEW QUESTION # 55
What is the correct order of processing when configuring NAT rules and security policies?
- A. Source NAT > static NAT > destination NAT > policy lookup
- B. Destination NAT > policy lookup > source NAT > static NAT
- C. Static NAT > destination NAT> policy lookup > source NAT
- D. Policy lookup > source NAT > static NAT > destination NAT
Answer: C
NEW QUESTION # 56
On an SRX device, you want to regulate traffic base on network segments.
In this scenario, what do you configure to accomplish this task?
- A. NAT
- B. ALGs
- C. Screens
- D. Zones
Answer: D
NEW QUESTION # 57
What must you do first to use the Monitor/Alarms/Policy Log workspace in J-Web?
- A. You must enable event mode security logging on the SRX Series device.
- B. You must enable security logging that uses the TLS transport mode.
- C. You must enable logging that uses the SD-Syslog format.
- D. You must enable stream mode security logging on the SRX Series device.
Answer: A
NEW QUESTION # 58
Click the Exhibit button.
Which two user roles shown in the exhibit are available be defaults? (choose two)
- A. Jtac
- B. Operator
- C. Admin
- D. Super-user
Answer: B,D
NEW QUESTION # 59
Which two statements are correct about global policies? (Choose two.)
- A. Global policies do not have to reference zone context.
- B. Global policies are evaluated after default policies.
- C. Global policies must reference zone contexts.
- D. Global policies are evaluated before default policies.
Answer: A,D
Explanation:
Global policies are used to define rules for traffic that is not associated with any particular zone. This type of policy is evaluated first, before any rules related to specific zones are evaluated.
For more detailed information about global policies, refer to the Juniper Networks Security Policy Overview guide, which can be found at https://www.juniper.net/documentation/en_US/junos/topics/reference/security-policy-overview.html. The guide provides an overview of the Juniper Networks security policy architecture, as well as detailed descriptions of the different types of policies and how they are evaluated.
NEW QUESTION # 60
Which two statements are true about the null zone? (Choose two.)
- A. All traffic to the null zone is dropped.
- B. All traffic to the null zone is allowed
- C. The null zone is a user-defined zone
- D. All interface belong to the bull zone by default.
Answer: A,D
NEW QUESTION # 61
Which two elements are needed on an SRX Series device to set up a remote syslog server? (Choose two.)
- A. Data throughput
- B. Data size
- C. IP address
- D. Data type
Answer: C,D
NEW QUESTION # 62
When configuring antispam, where do you apply any local lists that are configured?
- A. custom objects
- B. antispam feature-profile
- C. antispam UTM policy
- D. advanced security policy
Answer: A
Explanation:
user@host# set security utm custom-objects url-pattern url-pattern-name https://www.juniper.net/documentation/us/en/software/junos/utm/topics/topic-map/security-local-list-antispam-filtering.html
NEW QUESTION # 63
Which two statements are true regarding zone-based security policies? (Choose two.)
- A. Zone-based policies must reference a source address in the match criteria.
- B. Zone-based policies must reference a destination address in the match criteria
- C. Zone-based policies must reference a URL category in the match criteria.
- D. Zone-based policies must reference a dynamic application in the match criteria.
Answer: A,B
NEW QUESTION # 64
You configure and applied several global policies and some of the policies have overlapping match criteria.
- A. The first matched policy is the only policy applied.
- B. In this scenario, how are these global policies applies?
- C. The most restrictive that matches is applied.
- D. The least restrictive policy that matches is applied.
Answer: B
NEW QUESTION # 65
What is the order in which malware is detected and analyzed?
- A. antivirus scanning -> cache lookup -> dynamic analysis -> static analysis
- B. cache lookup -> static analysis -> dynamic analysis -> antivirus scanning
- C. cache lookup -> antivirus scanning -> static analysis -> dynamic analysis
- D. antivirus scanning -> cache lookup -> static analysis -> dynamic analysis
Answer: C
NEW QUESTION # 66
What is the number of concurrent Secure Connect user licenses that an SRX Series device has by default?
- A. 0
- B. 1
- C. 2
- D. 3
Answer: C
Explanation:
The number of concurrent Secure Connect user licenses that an SRX Series device has by default is 2. Secure Connect is a feature of Juniper SRX Series devices that allows you to securely connect to remote networks via IPsec VPN tunnels. Each SRX Series device comes with two concurrent Secure Connect user licenses by default, meaning that it can support up to two simultaneous IPsec VPN connections. For more information, please refer to the Juniper Networks SRX Series Services Gateways Security Configuration Guide, which can be found on Juniper's website.
NEW QUESTION # 67
Your company uses SRX Series devices to secure the edge of the network. You are asked protect the company from ransom ware attacks.
Which solution will satisfy this requirement?
- A. AppSecure
- B. screens
- C. Unified security policies
- D. Sky ATP
Answer: D
NEW QUESTION # 68
Which feature would you use to protect clients connected to an SRX Series device from a SYN flood attack?
- A. application layer gateway
- B. security policy
- C. screen option
- D. host inbound traffic
Answer: C
Explanation:
A screen option in the SRX Series device can be used to protect clients connected to the device from a SYN flood attack. Screens are security measures that you can use to protect your network from various types of attacks, including SYN floods. A screen option specifies a set of rules to match against incoming packets, and it can take specific actions such as discarding, logging, or allowing the packets based on the rules.
Reference:
Juniper Networks SRX Series Services Gateway Screen Configuration Guide: https://www.juniper.net/documentation/en_US/junos/topics/topic-map/security-screen-configuring.html
NEW QUESTION # 69
You have created a zones-based security policy that permits traffic to a specific webserver for the marketing team. Other groups in the company are not permitted to access the webserver. When marketing users attempt to access the server they are unable to do so.
What are two reasons for this access failure? (Choose two.)
- A. You failed to commit the policy change.
- B. You failed to change the source zone to include any source zone.
- C. You failed to position the policy after the policy that denies access to the webserver.
- D. You failed to position the policy before the policy that denies access the webserver
Answer: A,D
NEW QUESTION # 70
What does the number "2" indicate in interface ge-0/1/2?
- A. the interface logical number
- B. the port number
- C. the physical interface card (PIC)
- D. the flexible PIC concentrator (FPC)
Answer: B
NEW QUESTION # 71
Which statement about IPsec is correct?
- A. IPsec can be used to transport native Layer 2 packets.
- B. IPsec is a standards-based protocol.
- C. IPsec can provide encapsulation but not encryption
- D. IPsec is used to provide data replication
Answer: B
NEW QUESTION # 72
Click the Exhibit button.
Referring to the exhibit, a user is placed in which hierarchy when the exit command is run?
- A. user@vSRX-1>
- B. [edit security policies]
user@vSRX-1# - C. [edit security policies from-zone trust to-zone dmz]
user@vSRX-1# - D. [edit]
user@vSRX-1#
Answer: D
NEW QUESTION # 73
Referring to the exhibit.
You have configured antispam to allow e-mail from example.com, however the logs you see that [email protected] is blocked What are two ways to solve this problem?
- A. Delete [email protected] from the profile antispam address blacklist
- B. Verify connectivity with the SBL server.
- C. Add [email protected] to the profile antispam address whitelist.
- D. Delete [email protected] from the profile antispam address whitelist
Answer: A,C
NEW QUESTION # 74
You have configured a UTM feature profile.
Which two additional configuration steps are required for your UTM feature profile to take effect? (Choose two.)
- A. Associate the UTM policy with an address book.
- B. Associate the UTM feature profile with a UTM policy.
- C. Associate the UTM policy with a security policy.
- D. Associate the UTM policy with a firewall filter.
Answer: B,C
Explanation:
For the UTM feature profile to take effect, it must be associated with a security policy and a UTM policy. The security policy defines the traffic flow and the actions that should be taken on the traffic, while the UTM policy defines the security features to be applied to the traffic, such as antivirus, intrusion prevention, and web filtering. The UTM feature profile provides the necessary configuration for the security features defined in the UTM policy.
Reference:
Juniper Networks SRX Series Services Gateway UTM Configuration Guide: https://www.juniper.net/documentation/en_US/release-independent/junos/topics/topic-map/security-services-utm.html
NEW QUESTION # 75
......
JN0-231 [Dec-2023] Newly Released] Exam Questions For You To Pass: https://www.exam4pdf.com/JN0-231-dumps-torrent.html
Juniper JN0-231 Exam: Basic Questions With Answers: https://drive.google.com/open?id=1XXxvqLM_XarwOve0QDnIUAfxfK8wRUWK

