Pass JN0-231 Exam Latest Practice Questions Updated on Jul 19, 2023
Juniper JN0-231 Study Guide Archives
NEW QUESTION # 52
You want to provide remote access to an internal development environment for 10 remote developers.
Which two components are required to implement Juniper Secure Connect to satisfy this requirement?
(Choose two.)
- A. an SRX Series device with an SPC3 services card
- B. an additional license for an SRX Series device
- C. Marvis virtual network assistant
- D. Juniper Secure Connect client software
Answer: B,D
NEW QUESTION # 53
Which two components are configured for host inbound traffic? (Choose two.)
- A. routing instance
- B. zone
- C. physical interface
- D. logical interface
Answer: B,D
NEW QUESTION # 54
Your company has been assigned one public IP address. You want to enable internet traffic to reach multiple servers in your DMZ that are configured with private address.
In this scenario, which type of NAT would be used to accomplish this tasks?
- A. Source NAT
- B. Destination NAT
- C. Static NAT
- D. NAT without PAT
Answer: B
NEW QUESTION # 55
Click the Exhibit button.
You are asked to allow only ping and SSH access to the security policies shown in the exhibit.
Which statement will accomplish this task?
- A. Replace application any with application [junos-ping junos-ssh] in policy Rule-1.
- B. Rename policy Rule-1 to policy Rule-3.
- C. Insert policy Rule-2 before policy Rule-1.
- D. Rename policy Rule-2 to policy Rule-0.
Answer: C
NEW QUESTION # 56
What are the valid actions for a source NAT rule in J-Web? (choose three.)
- A. Pool
- B. interface
- C. On
- D. Source
- E. Off
Answer: A,B,E
NEW QUESTION # 57
What are configuring the antispam UTM feature on an SRX Series device.
Which two actions would be performed by the SRX Series device for e-mail that is identified as spam? (Choose two.)
- A. Quarantine e-mail
- B. Queue the e-mail
- C. Block the e-mail
- D. Tag the e-mail
Answer: C,D
NEW QUESTION # 58
What is the behavior of an SRX series device when UDP and TCP is rejected by a security policy actions? (choose two)
- A. The reject actions drops TCP packets and sends an ICMP message to the source
- B. The reject action drops UDP packets and sends an ICMP message to the source
- C. The reject action drops UDP packets and does not send ant message to the source
- D. The reject action drops TCP packets and send an RST message to the source.
Answer: B,D
NEW QUESTION # 59
Which two services does Juniper Connected Security provide? (Choose two.)
- A. protection against zero-day threats
- B. Layer 2 VPN tunnels
- C. IPsec VPNs
- D. inline malware blocking
Answer: A,D
NEW QUESTION # 60
What are two functions of Juniper ATP Cloud? (Choose two.)
- A. Web content filtering
- B. malware inspection
- C. DDoS protection
- D. Geo IP feeds
Answer: B,D
Explanation:
Juniper Advanced Threat Prevention (ATP) Cloud is a security service that helps organizations protect against advanced threats by providing real-time threat intelligence and automated response capabilities. It combines a cloud-based threat intelligence platform with the security capabilities of Juniper Networks security devices to provide comprehensive protection against advanced threats. The two functions of Juniper ATP Cloud include malware inspection and Geo IP feeds. The malware inspection component provides real-time protection against known and unknown threats by analyzing suspicious files and determining if they are malicious. The Geo IP feeds provide a global view of IP addresses and their associated countries, allowing organizations to identify and block traffic from known malicious countries.
NEW QUESTION # 61
You are configuring an SRX Series device. You have a set of servers inside your private network that need one-to-one mappings to public IP addresses.
Which NAT configuration is appropriate in this scenario?
- A. static NAT
- B. destination NAT
- C. NAT-T
- D. source NAT with PAT
Answer: A
NEW QUESTION # 62
A new SRX Series device has been delivered to your location. The device has the factory-default configuration loaded. You have powered on the device and connected to the console port.
What would you use to log into the device to begin the initial configuration?
- A. Root with no password
- B. Admin with password
- C. Admin with a password ''juniper''
- D. Root with a password of juniper''
Answer: A
NEW QUESTION # 63
Click the Exhibit button.
What is the purpose of the host-inbound-traffic configuration shown in the exhibit?
- A. to permit all host inbound traffic on the internal security zone, but deny HTTP traffic
- B. to permit host inbound HTTP traffic and deny all other traffic on the internal security zone
- C. to deny and log all host inbound traffic on the internal security zone, except for HTTP traffic
- D. to permit host inbound HTTP traffic on the internal security zone
Answer: A
NEW QUESTION # 64
Which three Web filtering deployment actions are supported by Junos? (Choose three.)
- A. Use IPS.
- B. Use Websense Redirect.
- C. Use remote lists.
- D. Use Juniper Enhanced Web Filtering.
- E. Use local lists.
Answer: B,D,E
NEW QUESTION # 65
Which two segments describes IPsec VPNs? (Choose two.)
- A. IPsec VPNs use security to secure traffic over a public network between two remote sites.
- B. IPsec VPN traffic is always authenticated.
- C. IPsec VPN traffic is always encrypted.
- D. IPsec VPNs are dedicated physical connections between two private networks.
Answer: A,B
NEW QUESTION # 66
What are three Junos UTM features? (Choose three.)
- A. IDP/IPS
- B. Web filtering
- C. content filtering
- D. screens
- E. antivirus
Answer: B,C,E
NEW QUESTION # 67
Your ISP gives you an IP address of 203.0.113.0/27 and informs you that your default gateway is 203.0.113.1.
You configure destination NAT to your internal server, but the requests sent to the webserver at 203.0.113.5 are not arriving at the server.
In this scenario, which two configuration features need to be added? (Choose two.)
- A. firewall filter
- B. security policy
- C. UTM policy
- D. proxy-ARP
Answer: B,D
NEW QUESTION # 68
Which two statements about user-defined security zones are correct? (Choose two.)
- A. Users cannot share security zones between routing instances.
- B. Users can share security zones between routing instances.
- C. Users can configure multiple security zones.
- D. User-defined security zones do not apply to transit traffic.
Answer: B,C
Explanation:
User-defined security zones allow users to configure multiple security zones and share them between routing instances. This allows users to easily manage multiple security zones and their associated policies. For example, a user can create a security zone for corporate traffic, a security zone for guest traffic, and a security zone for public traffic, and then configure policies to control the flow of traffic between each of these security zones. Transit traffic can also be managed using user-defined security zones, as the policies applied to these zones will be applied to the transit traffic as well.
NEW QUESTION # 69
You want to integrate an SRX Series device with SKY ATP.
What is the first action to accomplish task?
- A. Create an account with the Sky ATP Web UI.
- B. Copy the operational script from the Sky ATP Web UI.
- C. Issue the commit script to register the SRX Series device.
- D. Create the SSL VPN tunnel between the SRX Series device and Sky ATP.
Answer: A
NEW QUESTION # 70
Which two criteria should a zone-based security policy include? (Choose two.)
- A. a source port
- B. zone context
- C. a destination port
- D. an action
Answer: A,C
Explanation:
A security policy is a set of statements that controls traffic from a specified source to a specified destination using a specified service. A policy permits, denies, or tunnels specified types of traffic unidirectionally between two points.
Each policy consists of:
A unique name for the policy.
A from-zone and a to-zone, for example: user@host# set security policies from-zone untrust to-zone untrust A set of match criteria defining the conditions that must be satisfied to apply the policy rule. The match criteria are based on a source IP address, destination IP address, and applications. The user identity firewall provides greater granularity by including an additional tuple, source-identity, as part of the policy statement.
A set of actions to be performed in case of a match-permit, deny, or reject.
Accounting and auditing elements-counting, logging, or structured system logging.
https://www.juniper.net/documentation/us/en/software/junos/security-policies/topics/topic-map/security-policy-configuration.html
NEW QUESTION # 71
......
JN0-231 Questions Prepare with Learning Information: https://www.dumpexams.com/JN0-231-real-answers.html
Download JN0-231 Mock Test Study Material: https://drive.google.com/open?id=18Idxh9iQ_H3PVOCiemcmLr_2mkc9Nezu