[UPDATED 2024] Juniper JN0-231 Questions Prepare with Free Demo of PDF
NEW 2024 Certification Sample Questions JN0-231 Dumps & Practice Exam
NEW QUESTION # 50
You are creating Ipsec connections.
In this scenario, which two statements are correct about proxy IDs? (Choose two.)
- A. Proxy IDs default to 0.0.0.0/0 for policy-based VPNs.
- B. Proxy IDs are used to configure traffic selectors.
- C. Proxy IDs are optional for Phase 2 session establishment.
- D. Proxy IDs must match for Phase 2 session establishment.
Answer: B,C
NEW QUESTION # 51
Which two addresses are valid address book entries? (Choose two.)
- A. 173.145.5.21/255.255.255.0
- B. 203.150.108.10/24
- C. 153.146.0.145/255.255.0.255
- D. 191.168.203.0/24
Answer: A,B
Explanation:
The correct address book entries are:
173.145.5.21/255.255.255.0
203.150.108.10/24
Both of these entries represent a valid IP address and subnet mask combination, which can be used as an address book entry in a Juniper device.
NEW QUESTION # 52
What should you configure if you want to translate private source IP address to a single public IP address?
- A. Source NAT
- B. Security Director
- C. Content filtering
- D. Destination NAT
Answer: A
NEW QUESTION # 53
You are asked to verify that a license for AppSecure is installed on an SRX Series device.
In this scenario, which command will provide you with the required information?
- A. user@srx> show services accounting
- B. user@srx> show chassis firmware
- C. user@srx> show system license
- D. user@srx> show configuration system
Answer: C
NEW QUESTION # 54
Which Juniper ATP feed provides a dynamic list of known botnet servers and known sources of malware downloads?
- A. C&C cloud feed
- B. Geo IP feed
- C. blocklist feed
- D. infected host cloud feed
Answer: D
NEW QUESTION # 55
Click the Exhibit button.
You are asked to allow only ping and SSH access to the security policies shown in the exhibit.
Which statement will accomplish this task?
- A. Insert policy Rule-2 before policy Rule-1.
- B. Rename policy Rule-1 to policy Rule-3.
- C. Replace application any with application [junos-ping junos-ssh] in policy Rule-1.
- D. Rename policy Rule-2 to policy Rule-0.
Answer: A
NEW QUESTION # 56
Which two elements are needed on an SRX Series device to set up a remote syslog server? (Choose two.)
- A. Data throughput
- B. Data type
- C. IP address
- D. Data size
Answer: B,C
NEW QUESTION # 57
What are configuring the antispam UTM feature on an SRX Series device.
Which two actions would be performed by the SRX Series device for e-mail that is identified as spam? (Choose two.)
- A. Tag the e-mail
- B. Quarantine e-mail
- C. Queue the e-mail
- D. Block the e-mail
Answer: A,D
NEW QUESTION # 58
Which two statements are correct about IPsec security associations? (Choose two.)
- A. IPsec security associations are unidirectional.
- B. IPsec security associations are established during IKE Phase 2 negotiations.
- C. IPsec security associations are bidirectional.
- D. IPsec security associations are established during IKE Phase 1 negotiations.
Answer: B,C
Explanation:
The two statements that are correct about IPsec security associations are that they are bidirectional and that they are established during IKE Phase 2 negotiations. IPsec security associations are bidirectional, meaning that they provide security for both incoming and outgoing traffic. IPsec security associations are established during IKE Phase 2 negotiations, which negotiates the security parameters and establishes the security association between the two peers. For more information, please refer to the Juniper Networks IPsec VPN Configuration Guide, which can be found on Juniper's website.
NEW QUESTION # 59
You are assigned a project to configure SRX Series devices to allow connections to your webservers. The webservers have a private IP address, and the packets must use NAT to be accessible from the Internet. The webservers must use the same address for both connections from the Internet and communication with update servers.
Which NAT type must be used to complete this project?
- A. destination NAT
- B. source NAT
- C. static NAT
- D. hairpin NAT
Answer: A
NEW QUESTION # 60
What is the number of concurrent Secure Connect user licenses that an SRX Series device has by default?
- A. 0
- B. 1
- C. 2
- D. 3
Answer: C
Explanation:
The number of concurrent Secure Connect user licenses that an SRX Series device has by default is 2. Secure Connect is a feature of Juniper SRX Series devices that allows you to securely connect to remote networks via IPsec VPN tunnels. Each SRX Series device comes with two concurrent Secure Connect user licenses by default, meaning that it can support up to two simultaneous IPsec VPN connections. For more information, please refer to the Juniper Networks SRX Series Services Gateways Security Configuration Guide, which can be found on Juniper's website.
NEW QUESTION # 61
You are configuring an SRX Series device. You have a set of servers inside your private network that need one-to-one mappings to public IP addresses.
Which NAT configuration is appropriate in this scenario?
- A. NAT-T
- B. source NAT with PAT
- C. static NAT
- D. destination NAT
Answer: C
NEW QUESTION # 62
Referring to the exhibit.
Users should not have access to Facebook, however, a recent examination of the logs security show that users are accessing Facebook.
what should you do to solve this problem?
- A. Change the source address for the Block-Facebook-Access rule to the prefix of the users
- B. Move the Block-Facebook-Access rule from a zone policy to a global policy
- C. Move the Block-Facebook-Access rule before the Internet-Access rule
- D. Change the Internet-Access rule from a zone policy to a global policy
Answer: C
NEW QUESTION # 63
Which two statements are correct about functional zones? (Choose two.)
- A. Functional zone cannot be referenced in security policies or pass transit traffic.
- B. Functional zones must have a user-defined name.
- C. Multiple types of functional zones can be defined by the user.
- D. Functional zones are used for out-of-band device management.
Answer: A,D
NEW QUESTION # 64
You are asked to configure your SRX Series device to block all traffic from certain countries. The solution must be automatically updated as IP prefixes become allocated to those certain countries.
Which Juniper ATP solution will accomplish this task?
- A. C&C feed
- B. IDP
- C. Geo IP
- D. unified security policies
Answer: C
Explanation:
Juniper ATP Geo IP can help to accomplish this task by using geolocation services to determine the geographical location of IP addresses. As IP prefixes get allocated to the countries that you have specified, the Geo IP solution will automatically update the configured firewall policies to block any traffic that is coming from those specific countries.
This is a great solution for blocking specific countries - as it will allow for a more personalized and targeted approach to firewall policies - and thus, to increase the effectiveness of the solution at blocking potential malicious traffic.
NEW QUESTION # 65
You want to verify the peer before IPsec tunnel establishment.
What would be used as a final check in this scenario?
- A. st0 interfaces
- B. traffic selector
- C. proxy ID
- D. perfect forward secrecy
Answer: C
Explanation:
The proxy ID is used as a final check to verify the peer before IPsec tunnel establishment. The proxy ID is a combination of local and remote subnet and protocol, and it is used to match the traffic that is to be encrypted. If the proxy IDs match between the two IPsec peers, the IPsec tunnel is established, and the traffic is encrypted.
Reference:
Juniper Networks SRX Series Services Gateway IPsec Configuration Guide: https://www.juniper.net/documentation/en_US/release-independent/junos/topics/topic-map/security-ipsec-vpn-configuring.html
NEW QUESTION # 66
Exhibit.
Which two statements are true? (Choose two.)
- A. Traffic statistics for this security policy are generated.
- B. Traffic static for this security policy are not generated.
- C. Logs for this security policy are not generated.
- D. Logs for this security policy are generated.
Answer: A,D
NEW QUESTION # 67
You want to provide remote access to an internal development environment for 10 remote developers.
Which two components are required to implement Juniper Secure Connect to satisfy this requirement? (Choose two.)
- A. Juniper Secure Connect client software
- B. an additional license for an SRX Series device
- C. an SRX Series device with an SPC3 services card
- D. Marvis virtual network assistant
Answer: A,B
NEW QUESTION # 68
Which Juniper Networks solution uses static and dynamic analysis to search for day-zero malware threats?
- A. UTM
- B. firewall filters
- C. IPS
- D. Juniper ATP Cloud
Answer: D
Explanation:
Malware Sandboxing
Detect and stop zero-day and commodity malware within web, email, data center, and application traffic targeted for Windows, Mac, and IoT devices. https://www.juniper.net/us/en/products/security/advanced-threat-prevention.html
NEW QUESTION # 69
You are asked to configure your SRX Series device to block all traffic from certain countries. The solution must be automatically updated as IP prefixes become allocated to those certain countries.
Which Juniper ATP solution will accomplish this task?
- A. C&C feed
- B. IDP
- C. Geo IP
- D. unified security policies
Answer: C
NEW QUESTION # 70
......
The JN0-231 exam consists of 65 multiple-choice questions that need to be answered within 90 minutes. JN0-231 exam is computer-based and can be taken at any Pearson VUE testing center worldwide. Candidates who pass the exam will receive the JNCIA-SEC certification, which is valid for three years.
JN0-231 Deluxe Study Guide with Online Test Engine: https://www.free4dump.com/JN0-231-braindumps-torrent.html
JN0-231 Test Prep Training Practice Exam Questions Practice Tests: https://drive.google.com/open?id=1NiQBgYhUYkWVoJ76j6NbFzSzpmV6JEsF