New Year Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: pass65

JN0-231 Security-Associate (JNCIA-SEC) Questions and Answers

Questions 4

What must be enabled on an SRX Series device for the reporting engine to create reports?

Options:

A.

System logging

B.

SNMP

C.

Packet capture

D.

Security logging

Buy Now
Questions 5

Which Web filtering solution uses a direct Internet-based service for URL categorization?

Options:

A.

Juniper ATP Cloud

B.

Websense Redirect

C.

Juniper Enhanced Web Filtering

D.

local blocklist

Buy Now
Questions 6

Which order is correct for Junos security devices that examine policies for transit traffic?

Options:

A.

zone policies

global policies

default policies

B.

default policies

zone policies

global policies

C.

default policies

global policies

zone policies

D.

global policies

zone policies

default policies

Buy Now
Questions 7

Which two traffic types are considered exception traffic and require some form of special handling by the PFE? (Choose two.)

Options:

A.

SSH sessions

B.

ICMP reply messages

C.

HTTP sessions

D.

traceroute packets

Buy Now
Questions 8

What are two logical properties of an interface? (Choose two.)

Options:

A.

link mode

B.

IP address

C.

VLAN ID

D.

link speed

Buy Now
Questions 9

What is the order of the first path packet processing when a packet enters a device?

Options:

A.

security policies –> screens –> zones

B.

screens –> security policies –> zones

C.

screens –> zones –> security policies

D.

security policies –> zones –> screens

Buy Now
Questions 10

When operating in packet mode, which two services are available on the SRX Series device? (Choose two.)

Options:

A.

MPLS

B.

UTM

C.

CoS

D.

IDP

Buy Now
Questions 11

You are deploying an SRX Series firewall with multiple NAT scenarios.

In this situation, which NAT scenario takes priority?

Options:

A.

interface NAT

B.

source NAT

C.

static NAT

D.

destination NAT

Buy Now
Questions 12

You are investigating a communication problem between two hosts and have opened a session on the SRX Series device closest to one of the hosts and entered the show security flow session command.

What information will this command provide? (Choose two.)

Options:

A.

The total active time of the session.

B.

The end-to-end data path that the packets are taking.

C.

The IP address of the host that initiates the session.

D.

The security policy name that is controlling the session.

Buy Now
Questions 13

Which two criteria should a zone-based security policy include? (Choose two.)

Options:

A.

a source port

B.

a destination port

C.

zone context

D.

an action

Buy Now
Questions 14

Corporate security requests that you implement a policy to block all POP3 traffic from traversing the Internet firewall.

In this scenario, which security feature would you use to satisfy this request?

Options:

A.

antivirus

B.

Web filtering

C.

content filtering

D.

antispam

Buy Now
Questions 15

When configuring antispam, where do you apply any local lists that are configured?

Options:

A.

custom objects

B.

advanced security policy

C.

antispam feature-profile

D.

antispam UTM policy

Buy Now
Questions 16

Which Juniper ATP feed provides a dynamic list of known botnet servers and known sources of malware downloads?

Options:

A.

infected host cloud feed

B.

Geo IP feed

C.

C&C cloud feed

D.

blocklist feed

Buy Now
Questions 17

What are two functions of Juniper ATP Cloud? (Choose two.)

Options:

A.

malware inspection

B.

Web content filtering

C.

DDoS protection

D.

Geo IP feeds

Buy Now
Questions 18

You are creating Ipsec connections.

In this scenario, which two statements are correct about proxy IDs? (Choose two.)

Options:

A.

Proxy IDs are used to configure traffic selectors.

B.

Proxy IDs are optional for Phase 2 session establishment.

C.

Proxy IDs must match for Phase 2 session establishment.

D.

Proxy IDs default to 0.0.0.0/0 for policy-based VPNs.

Buy Now
Questions 19

Which two IPsec hashing algorithms are supported on an SRX Series device? (Choose two.)

Options:

A.

SHA-1

B.

SHAKE128

C.

MD5

D.

RIPEMD-256

Buy Now
Questions 20

You need to collect the serial number of an SRX Series device to replace it. Which command will accomplish this task?

Options:

A.

show chassis hardware

B.

show system information

C.

show chassis firmware

D.

show chassis environment

Buy Now
Questions 21

What are three Junos UTM features? (Choose three.)

Options:

A.

screens

B.

antivirus

C.

Web filtering

D.

IDP/IPS

E.

content filtering

Buy Now
Questions 22

You are monitoring an SRX Series device that has the factory-default configuration applied.

In this scenario, where are log messages sent by default?

Options:

A.

Junos Space Log Director

B.

Junos Space Security Director

C.

to a local syslog server on the management network

D.

to a local log file named messages

Buy Now
Questions 23

You are asked to configure your SRX Series device to block all traffic from certain countries. The solution must be automatically updated as IP prefixes become allocated to those certain countries.

Which Juniper ATP solution will accomplish this task?

Options:

A.

Geo IP

B.

unified security policies

C.

IDP

D.

C&C feed

Buy Now
Questions 24

You want to deploy a NAT solution.

In this scenario, which solution would provide a static translation without PAT?

Options:

A.

interface-based source NAT

B.

pool-based NAT with address shifting

C.

pool-based NAT with PAT

D.

pool-based NAT without PAT

Buy Now
Questions 25

What are two features of the Juniper ATP Cloud service? (Choose two.)

Options:

A.

sandbox

B.

malware detection

C.

EX Series device integration

D.

honeypot

Buy Now
Questions 26

Which statement is correct about global security policies on SRX Series devices?

Options:

A.

The to-zone any command configures a global policy.

B.

The from-zone any command configures a global policy.

C.

Global policies are always evaluated first.

D.

Global policies can include zone context.

Buy Now
Questions 27

Click the Exhibit button.

JN0-231 Question 27

You are asked to allow only ping and SSH access to the security policies shown in the exhibit.

Which statement will accomplish this task?

Options:

A.

Rename policy Rule-2 to policy Rule-0.

B.

Insert policy Rule-2 before policy Rule-1.

C.

Replace application any with application [junos-ping junos-ssh] in policy Rule-1.

D.

Rename policy Rule-1 to policy Rule-3.

Buy Now
Questions 28

Which two statements about the Junos OS CLI are correct? (Choose two.)

Options:

A.

The default configuration requires you to log in as the admin user.

B.

A factory-default login assigns the hostname Amnesiac to the device.

C.

Most Juniper devices identify the root login prompt using the % character.

D.

Most Juniper devices identify the root login prompt using the > character.

Buy Now
Questions 29

Which statement about NAT is correct?

Options:

A.

Destination NAT takes precedence over static NAT.

B.

Source NAT is processed before security policy lookup.

C.

Static NAT is processed after forwarding lookup.

D.

Static NAT takes precedence over destination NAT.

Buy Now
Questions 30

What information does the show chassis routing-engine command provide?

Options:

A.

chassis serial number

B.

resource utilization

C.

system version

D.

routing tables

Buy Now
Questions 31

You are assigned a project to configure SRX Series devices to allow connections to your webservers. The webservers have a private IP address, and the packets must use NAT to be accessible from the

Internet. You do not want the webservers to initiate connections with external update servers on the Internet using the same IP address as customers use to access them.

Which two NAT types must be used to complete this project? (Choose two.)

Options:

A.

static NAT

B.

hairpin NAT

C.

destination NAT

D.

source NAT

Buy Now
Exam Code: JN0-231
Exam Name: Security-Associate (JNCIA-SEC)
Last Update: Jan 6, 2025
Questions: 105

PDF + Testing Engine

$57.75  $164.99

Testing Engine

$43.75  $124.99
buy now JN0-231 testing engine

PDF (Q&A)

$36.75  $104.99
buy now JN0-231 pdf