Juniper JN0-231 Practice Exam - 103 Unique Questions
Latest Questions JN0-231 Guide to Prepare Free Practice Tests
NEW QUESTION 13
Which three Web filtering deployment actions are supported by Junos? (Choose three.)
- A. Use Juniper Enhanced Web Filtering.
- B. Use Websense Redirect.
- C. Use local lists.
- D. Use IPS.
- E. Use remote lists.
Answer: A,B,C
NEW QUESTION 14
Which type of security policy protect restricted services from running on non-standard ports?
- A. IDP
- B. antivirus
- C. Sky ATP
- D. Application firewall
Answer: A
NEW QUESTION 15
What must you do first to use the Monitor/Alarms/Policy Log workspace in J-Web?
- A. You must enable event mode security logging on the SRX Series device.
- B. You must enable logging that uses the SD-Syslog format.
- C. You must enable stream mode security logging on the SRX Series device.
- D. You must enable security logging that uses the TLS transport mode.
Answer: A
NEW QUESTION 16
You want to prevent other users from modifying or discarding your changes while you are also editing the configuration file.
In this scenario, which command would accomplish this task?
- A. configure
- B. configure exclusive
- C. cli privileged
- D. configure master
Answer: B
NEW QUESTION 17
Click the Exhibit button.
Referring to the exhibit, which two statements are correct about the ping command? (Choose two.)
- A. The DMZ routing-instance is the source.
- B. The DMZ routing-instance is the destination.
- C. The 10.10.102.10 IP address is the destination.
- D. The 10.10.102.10 IP address is the source.
Answer: A,C
NEW QUESTION 18
Click the exhibit button
You are configuring an IPsec VPN for the network show in the exhibit
Which feature must be enabled the VPN to established successfully?
- A. Aggressive mode must be configured on the IPsec VPN
- B. Main mode must be configured on the IPsec VPN
- C. Aggressive mode must be configured on IKE gateway
- D. Main mode must be configured on the IKE gateway
Answer: C
NEW QUESTION 19
A security zone is configured with the source IP address 192.168.0.12/255.255.0.255 wildcard match.
In this scenario, which two IP packets will match the criteria? (Choose two.)
- A. 192.168.1.21
- B. 192.168.22.12
- C. 192.168.0.1
- D. 192.168.1.12
Answer: B,D
NEW QUESTION 20
Which Juniper Networks solution uses static and dynamic analysis to search for day-zero malware threats?
- A. firewall filters
- B. IPS
- C. UTM
- D. Juniper ATP Cloud
Answer: D
NEW QUESTION 21
When configuring antispam, where do you apply any local lists that are configured?
- A. advanced security policy
- B. antispam UTM policy
- C. antispam feature-profile
- D. custom objects
Answer: D
Explanation:
user@host# set security utm custom-objects url-pattern url-pattern-name https://www.juniper.net/documentation/us/en/software/junos/utm/topics/topic-map/security-local-list-antispam-filtering.html
NEW QUESTION 22
Which statement is correct about unified security policies on an SRX Series device?
- A. The most restrictive policy is applied regardless of the policy level.
- B. The first policy rule is applied regardless of the policy level.
- C. A zone-based policy is always evaluated first.
- D. A global policy is always evaluated first.
Answer: C
NEW QUESTION 23
You want to generate reports from the l-Web on an SRX Series device.
Which logging mode would you use in this scenario?
- A. Syslog
- B. Event
- C. Stream
- D. local
Answer: C
NEW QUESTION 24
Which three Web filtering deployment actions are supported by Junos? (Choose three.)
- A. Use Juniper Enhanced Web Filtering.
- B. Use Websense Redirect.
- C. Use local lists.
- D. Use IPS.
- E. Use remote lists.
Answer: A,B,C
Explanation:
https://www.juniper.net/documentation/us/en/software/junos/utm/topics/concept/utm-web-filtering-overview.html
NEW QUESTION 25
Referring to the exhibit.
Host-inbound-traffic is configured on the DMZ zone and the ge-0/0/9.0 interface attached to that zone.
Which to types of management traffic would be performed on the SRX Series device? (Choose two.)
- A. HTTP
- B. HTTPS
- C. Finger
- D. SSH
Answer: A,D
NEW QUESTION 26
Which statement about global NAT address persistence is correct?
- A. The same IP address from a source NAT pool will be assigned for all sessions from a given host.
- B. The same IP address from a destination NAT pool will be assigned for all sessions for a given host.
- C. The same IP address from a source NAT pool is not guaranteed to be assigned for all sessions from a given host.
- D. The same IP address from a destination NAT pool is not guaranteed to be assigned for all sessions for a given host.
Answer: A
NEW QUESTION 27
The Sky ATP premium or basic-Threat Feed license is needed fort which two features? (Choose two.)
- A. Outbound protection
- B. C&C feeds
- C. Executable inspection
- D. Custom feeds
Answer: B,D
NEW QUESTION 28
Which statement about NAT is correct?
- A. Static NAT takes precedence over destination NAT.
- B. Static NAT is processed after forwarding lookup.
- C. Destination NAT takes precedence over static NAT.
- D. Source NAT is processed before security policy lookup.
Answer: A
NEW QUESTION 29
Which actions would be applied for the pre-ID default policy unified policies?
- A. Silently drop the session
- B. Redirect the session
- C. Log the session
- D. Reject the session
Answer: C
NEW QUESTION 30
Which statement about IPsec is correct?
- A. IPsec support both tunnel and transport modes.
- B. IPsec can provide encryption but not data integrity.
- C. IPsec support packet fragmentation by intermediary devices.
- D. IPsec must use certificates to provide data encryption
Answer: A
NEW QUESTION 31
......
Correct and Up-to-date Juniper JN0-231 BrainDumps: https://testking.testpassed.com/JN0-231-pass-rate.html