JN0-231 Sample Practice Exam Questions 2024 Updated Verified [Q51-Q75]

Share

JN0-231 Sample Practice Exam Questions 2024 Updated Verified

Exam Study Guide Free Practice Test LAST UPDATED JN0-231

NEW QUESTION # 51
Which Web filtering solution uses a direct Internet-based service for URL categorization?

  • A. Websense Redirect
  • B. local blocklist
  • C. Juniper Enhanced Web Filtering
  • D. Juniper ATP Cloud

Answer: C

Explanation:
Juniper Enhanced Web Filtering is a web filtering solution that uses a direct Internet-based service for URL categorization. This service allows Enhanced Web Filtering to quickly and accurately categorize URLs and other web content, providing real-time protection against malicious content. Additionally, Enhanced Web Filtering is able to provide detailed reporting on web usage, as well as the ability to define and enforce acceptable use policies.


NEW QUESTION # 52
Which statements about NAT are correct? (Choose two.)

  • A. When multiple NAT rules have overlapping match conditions, the rule listed first is chosen.
  • B. Source NAT translates the source IP address of packet.
  • C. When multiple NAT rules have overlapping match conditions, the most specific rule is chosen.
  • D. Source NAT translates the source port and destination IP address.

Answer: A,B


NEW QUESTION # 53
Your ISP gives you an IP address of 203.0.113.0/27 and informs you that your default gateway is 203.0.113.1.
You configure destination NAT to your internal server, but the requests sent to the webserver at 203.0.113.5 are not arriving at the server.
In this scenario, which two configuration features need to be added? (Choose two.)

  • A. UTM policy
  • B. security policy
  • C. proxy-ARP
  • D. firewall filter

Answer: B,C


NEW QUESTION # 54
Referring to the exhibit.

You have configured antispam to allow e-mail from example.com, however the logs you see that [email protected] is blocked What are two ways to solve this problem?

Answer: B,C


NEW QUESTION # 55
Which two user authentication methods are supported when using a Juniper Secure Connect VPN? (Choose two.)

  • A. local authentication
  • B. certificate-based
  • C. multi-factor authentication
  • D. active directory

Answer: A,B


NEW QUESTION # 56
Click the Exhibit button.

You are asked to allow only ping and SSH access to the security policies shown in the exhibit.
Which statement will accomplish this task?

  • A. Rename policy Rule-2 to policy Rule-0.
  • B. Rename policy Rule-1 to policy Rule-3.
  • C. Replace application any with application [junos-ping junos-ssh] in policy Rule-1.
  • D. Insert policy Rule-2 before policy Rule-1.

Answer: D


NEW QUESTION # 57
Your ISP gives you an IP address of 203.0.113.0/27 and informs you that your default gateway is 203.0.113.1. You configure destination NAT to your internal server, but the requests sent to the webserver at 203.0.113.5 are not arriving at the server.
In this scenario, which two configuration features need to be added? (Choose two.)

  • A. UTM policy
  • B. security policy
  • C. proxy-ARP
  • D. firewall filter

Answer: B,C


NEW QUESTION # 58
Which statement about global NAT address persistence is correct?

  • A. The same IP address from a source NAT pool will be assigned for all sessions from a given host.
  • B. The same IP address from a destination NAT pool is not guaranteed to be assigned for all sessions for a given host.
  • C. The same IP address from a destination NAT pool will be assigned for all sessions for a given host.
  • D. The same IP address from a source NAT pool is not guaranteed to be assigned for all sessions from a given host.

Answer: A


NEW QUESTION # 59
Which two statements are correct about IPsec security associations? (Choose two.)

  • A. IPsec security associations are established during IKE Phase 2 negotiations.
  • B. IPsec security associations are bidirectional.
  • C. IPsec security associations are unidirectional.
  • D. IPsec security associations are established during IKE Phase 1 negotiations.

Answer: A,B

Explanation:
The two statements that are correct about IPsec security associations are that they are bidirectional and that they are established during IKE Phase 2 negotiations. IPsec security associations are bidirectional, meaning that they provide security for both incoming and outgoing traffic. IPsec security associations are established during IKE Phase 2 negotiations, which negotiates the security parameters and establishes the security association between the two peers. For more information, please refer to the Juniper Networks IPsec VPN Configuration Guide, which can be found on Juniper's website.


NEW QUESTION # 60
Exhibit.

Which statement is correct regarding the interface configuration shown in the exhibit?

  • A. The interface is assigned to the trust zone by default.
  • B. The IP address has an invalid subnet mask.
  • C. The interface MTU has been increased.
  • D. The IP address is assigned to unit 0.

Answer: D


NEW QUESTION # 61
Your company uses SRX Series devices to secure the edge of the network. You are asked protect the company from ransom ware attacks.
Which solution will satisfy this requirement?

  • A. Unified security policies
  • B. Sky ATP
  • C. AppSecure
  • D. screens

Answer: B


NEW QUESTION # 62
Which two statements are true regarding zone-based security policies? (Choose two.)

  • A. Zone-based policies must reference a URL category in the match criteria.
  • B. Zone-based policies must reference a destination address in the match criteria
  • C. Zone-based policies must reference a dynamic application in the match criteria.
  • D. Zone-based policies must reference a source address in the match criteria.

Answer: B,D


NEW QUESTION # 63
Which two private cloud solution support vSRX devices? (Choose two.)

  • A. VMware Web Services (AWS)
  • B. Contrail Cloud
  • C. VMware NSX
  • D. Microsoft Azure
  • E. Amazon Web Services (AWS)

Answer: D,E


NEW QUESTION # 64
Corporate security requests that you implement a policy to block all POP3 traffic from traversing the Internet firewall.
In this scenario, which security feature would you use to satisfy this request?

  • A. content filtering
  • B. Web filtering
  • C. antispam
  • D. antivirus

Answer: A


NEW QUESTION # 65
What information does the show chassis routing-engine command provide?

  • A. routing tables
  • B. chassis serial number
  • C. resource utilization
  • D. system version

Answer: C


NEW QUESTION # 66
Which Juniper Networks solution uses static and dynamic analysis to search for day-zero malware threats?

  • A. IPS
  • B. firewall filters
  • C. UTM
  • D. Juniper ATP Cloud

Answer: D

Explanation:
Malware Sandboxing
Detect and stop zero-day and commodity malware within web, email, data center, and application traffic targeted for Windows, Mac, and IoT devices. https://www.juniper.net/us/en/products/security/advanced-threat-prevention.html


NEW QUESTION # 67
Click the Exhibit button.

Which two user roles shown in the exhibit are available be defaults? (choose two)

  • A. Operator
  • B. Super-user
  • C. Admin
  • D. Jtac

Answer: A,B


NEW QUESTION # 68
The free licensing model for Sky ATP includes which features? (Choose two.)

  • A. C & C feeds
  • B. Executable file inspection
  • C. Infected host blocking
  • D. Compromised endpoint dashboard

Answer: B,C


NEW QUESTION # 69
You must monitor security policies on SRX Series devices dispersed throughout locations in your organization using a 'single pane of glass' cloud-based solution.
Which solution satisfies the requirement?

  • A. J-Web
  • B. Junos Secure Connect
  • C. Junos Space
  • D. Juniper Sky Enterprise

Answer: C

Explanation:
Junos Space is a management platform that provides a single pane of glass view of SRX Series devices dispersed throughout locations in your organization. It provides visibility into the security policies of the devices, allowing you to quickly identify and respond to security threats. Additionally, it provides the ability to manage multiple devices remotely and in real-time, enabling you to quickly deploy and update security policies on all devices. For more information, please refer to the Juniper Networks Junos Space Network Director User Guide, which can be found on Juniper's website.


NEW QUESTION # 70
You want to deploy a NAT solution.
In this scenario, which solution would provide a static translation without PAT?

  • A. pool-based NAT with PAT
  • B. pool-based NAT with address shifting
  • C. pool-based NAT without PAT
  • D. interface-based source NAT

Answer: B

Explanation:
Translation of the original source IP address to an IP address from a user-defined address pool by shifting the IP addresses. This type of translation is one-to-one, static, and without port address translation. If the original source IP address range is larger than the IP address range in the user-defined pool, untranslated packets are dropped. https://www.juniper.net/documentation/us/en/software/junos/nat/topics/topic-map/nat-security-source-and-source-pool.html


NEW QUESTION # 71
What is the default timeout value for TCP sessions on an SRX Series device?

  • A. 60 seconds
  • B. 60 minutes
  • C. 30 seconds
  • D. 30 minutes

Answer: D

Explanation:
By default, TCP has a 30-minute idle timeout, and UDP has a 60-second idle timeout. Additionally, known IP protocols have a 30-minute timeout, whereas unknown ones have a 60-second timeout. Setting the inactivity timeout is very useful, particularly if you are concerned about applications either timing out or remaining idle for too long and filling up the session table. According to the Juniper SRX Series Services Guide, this can be configured using the 'timeout inactive' statement for the security policy.


NEW QUESTION # 72
Which two statements are correct about using global-based policies over zone-based policies? (Choose two.)

  • A. With global-based policies, you do not need to specify a source address in the match criteria.
  • B. With global-based policies, you do not need to specify a source zone in the match criteria.
  • C. With global-based policies, you do not need to specify a destination address in the match criteria.
  • D. With global-based policies, you do not need to specify a destination zone in the match criteria.

Answer: B,D


NEW QUESTION # 73
On an SRX Series device, how should you configure your IKE gateway if the remote endpoint is a branch office-using a dynamic IP address?

  • A. Configure the IKE policy to use aggressive mode.
  • B. Configure the IKE policy to use a static IP address
  • C. Configure the IPsec policy to use aggressive mode.
  • D. Configure the IPsec policy to use MDS authentication.

Answer: A


NEW QUESTION # 74
Click the Exhibit button.

Referring to the exhibit, which two statements are correct about the ping command? (Choose two.)

  • A. The DMZ routing-instance is the source.
  • B. The 10.10.102.10 IP address is the destination.
  • C. The 10.10.102.10 IP address is the source.
  • D. The DMZ routing-instance is the destination.

Answer: A,B


NEW QUESTION # 75
......

The New JN0-231 2024 Updated Verified Study Guides & Best Courses: https://www.test4cram.com/JN0-231_real-exam-dumps.html

Authentic JN0-231 Exam Dumps PDF - 2024 Updated: https://drive.google.com/open?id=1Qr4_bHCskGXsvUT8om-3O8n6UkuAaLHp