Try Before You Buy

Download a free sample of any of our exam questions and answers

  • 24/7 customer support, Secure shopping site
  • Free One year updates to match real exam scenarios
  • If you failed your exam after buying our products we will refund the full amount back to you.

JN0-231 Practice Dumps - Verified By BraindumpsIT Updated 103 Questions [Q55-Q75]

Share

JN0-231 Practice Dumps - Verified By BraindumpsIT Updated 103 Questions

Updated JN0-231 Exam Dumps - PDF Questions and Testing Engine


Juniper JN0-231 exam is designed to test the skills and knowledge of individuals who want to become certified as a Security Associate with Juniper Networks. Security, Associate (JNCIA-SEC) certification is ideal for those who wish to pursue a career in network security, as it validates their ability to perform basic security functions on Juniper Networks products. JN0-231 exam covers a variety of topics, including security concepts, security policies, security zones, and security threats.

 

NEW QUESTION # 55
Users in your network are downloading files with file extensions that you consider to be unsafe for your network. You must prevent files with specific file extensions from entering your network.
Which UTM feature should be enable on an SRX Series device to accomplish this task?

  • A. URL filtering
  • B. Web filtering
  • C. Content filtering
  • D. Antispam

Answer: C


NEW QUESTION # 56
Click the Exhibit button.

Which two user roles shown in the exhibit are available be defaults? (choose two)

  • A. Admin
  • B. Super-user
  • C. Operator
  • D. Jtac

Answer: B,C


NEW QUESTION # 57
You are installing a new SRX Series device and you are only provided one IP address from your ISP.
In this scenario, which NAT solution would you implement?

  • A. pool-based NAT with address shifting
  • B. interface-based source NAT
  • C. pool-based NAT without PAT
  • D. pool-based NAT with PAT

Answer: B


NEW QUESTION # 58
Which two user authentication methods are supported when using a Juniper Secure Connect VPN? (Choose two.)

  • A. active directory
  • B. local authentication
  • C. multi-factor authentication
  • D. certificate-based

Answer: A,B

Explanation:
"Local Authentication-In local authentication, the SRX Series device validates the user credentials by checking them in the local database. In this method, the administrator handles change of password or resetting of forgotten password. Here, it requires that an user must remember a new password. This option is not much preferred from a security standpoint.
* External Authentication-In external authentication, you can allow the users to use the same user credentials they use when accessing other resources on the network. In many cases, user credentials are domain logon used for Active Directory or any other LDAP authorization system. This method simplifies user experience and improves the organization's security posture; because you can maintain the authorization system with the regular security policy used by your organization."
https://www.juniper.net/documentation/us/en/software/secure-connect/secure-connect-administrator-guide/topics/topic-map/secure-connect-getting-started.html


NEW QUESTION # 59
You want to provide remote access to an internal development environment for 10 remote developers.
Which two components are required to implement Juniper Secure Connect to satisfy this requirement?
(Choose two.)

  • A. an SRX Series device with an SPC3 services card
  • B. Marvis virtual network assistant
  • C. an additional license for an SRX Series device
  • D. Juniper Secure Connect client software

Answer: C,D


NEW QUESTION # 60
When are Unified Threat Management services performed in a packet flow?

  • A. as the packet enters an SRX Series device
  • B. only during the first path process
  • C. after network address translation
  • D. before security policies are evaluated

Answer: C

Explanation:
https://iosonounrouter.wordpress.com/2018/07/07/how-does-a-flow-based-srx-work/


NEW QUESTION # 61
Your company is adding IP cameras to your facility to increase physical security. You are asked to help protect these loT devices from becoming zombies in a DDoS attack.
Which Juniper ATP feature should you configure to accomplish this task?

  • A. IPsec
  • B. static NAT
  • C. allowlists
  • D. C&C feeds

Answer: D

Explanation:
Juniper ATP should be configured with C&C feeds that contain lists of malicious domains and IP addresses in order to prevent IP cameras from becoming zombies in a DDoS attack.
This is an important step to ensure that the IP cameras are protected from malicious requests - and thus, they will not be able to be used in any DDoS attacks against the facility.


NEW QUESTION # 62
You are monitoring an SRX Series device that has the factory-default configuration applied.
In this scenario, where are log messages sent by default?

  • A. Junos Space Security Director
  • B. to a local syslog server on the management network
  • C. to a local log file named messages
  • D. Junos Space Log Director

Answer: B


NEW QUESTION # 63
You want to integrate an SRX Series device with SKY ATP.
What is the first action to accomplish task?

  • A. Create an account with the Sky ATP Web UI.
  • B. Issue the commit script to register the SRX Series device.
  • C. Copy the operational script from the Sky ATP Web UI.
  • D. Create the SSL VPN tunnel between the SRX Series device and Sky ATP.

Answer: A


NEW QUESTION # 64
On an SRX device, you want to regulate traffic base on network segments.
In this scenario, what do you configure to accomplish this task?

  • A. ALGs
  • B. Zones
  • C. Screens
  • D. NAT

Answer: B


NEW QUESTION # 65
Which statements is correct about global security policies?

  • A. Global policies eliminate the need to assign interface to security zones.
  • B. Global policies allow you to regulate traffic with addresses and applications, regardless of their security zones.
  • C. Global security require you to identify a source and destination zone.
  • D. Traffic matching global is not added to the session table.

Answer: B


NEW QUESTION # 66
Which three operating systems are supported for installing and running Juniper Secure Connect client software? (Choose three.)

  • A. Android
  • B. macOS
  • C. Windows 10
  • D. Windows 7
  • E. Linux

Answer: B,C,D

Explanation:
Juniper Secure Connect client software is supported on the following three operating systems: Windows 7, Windows 10, and macOS. For more information, please refer to the Juniper Secure Connect Administrator Guide, which can be found on Juniper's website. The guide states: "The Juniper Secure Connect client is supported on Windows 7, Windows 10, and macOS." It also provides detailed instructions on how to install and configure the software for each of these operating systems.


NEW QUESTION # 67
Which two non-configurable zones exist by default on an SRX Series device? (Choose two.)

  • A. Junos-host
  • B. management
  • C. functional
  • D. null

Answer: A,D

Explanation:
Junos-host and null are two non-configurable zones that exist by default on an SRX Series device. Junos-host is the default zone for all internal interfaces and services, such as management and other loopback interfaces. The null zone is used to accept all traffic that is not explicitly accepted by other security policies, and is the default zone for all unclassified traffic. Both zones cannot be modified or deleted.


NEW QUESTION # 68
Click the Exhibit button.

Which two statements are correct about the partial policies shown in the exhibit? (Choose two.)

  • A. UDP traffic matched by the reject-all policy will be silently dropped.
  • B. TCP traffic matched by the reject-all policy will have a TCP RST sent.
  • C. UDP traffic matched by the deny-all policy will be silently dropped.
  • D. TCP traffic matched from the zone trust is allowed by the permit-all policy.

Answer: B,C


NEW QUESTION # 69
Which statement is correct about IKE?

  • A. IKE phase 1 establishes the tunnel between devices
  • B. IKE phase 1 negotiates a secure channel between gateways.
  • C. IKE phase 1 only support aggressive mode.
  • D. IKE phase 1 is used to establish the data path

Answer: B


NEW QUESTION # 70
Referring to the exhibit.

Which type of NAT is being performed?

  • A. Destination NAT with PAT
  • B. Source NAT with PAT
  • C. Destination NAT without PAT
  • D. Source NAT without PAT

Answer: B


NEW QUESTION # 71
Which two statements are correct about the default behavior on SRX Series devices? (Choose two.)

  • A. The SRX Series device is in packet mode.
  • B. The SRX Series device supports stateless firewalls filters.
  • C. The SRX Series device is in flow mode.
  • D. The SRX Series device does not support stateless firewall filters.

Answer: B,C


NEW QUESTION # 72
You must monitor security policies on SRX Series devices dispersed throughout locations in your organization using a 'single pane of glass' cloud-based solution.
Which solution satisfies the requirement?

  • A. Juniper Sky Enterprise
  • B. Junos Space
  • C. J-Web
  • D. Junos Secure Connect

Answer: B

Explanation:
Junos Space is a management platform that provides a single pane of glass view of SRX Series devices dispersed throughout locations in your organization. It provides visibility into the security policies of the devices, allowing you to quickly identify and respond to security threats. Additionally, it provides the ability to manage multiple devices remotely and in real-time, enabling you to quickly deploy and update security policies on all devices. For more information, please refer to the Juniper Networks Junos Space Network Director User Guide, which can be found on Juniper's website.


NEW QUESTION # 73
An application firewall processes the first packet in a session for which the application has not yet been identified.
In this scenario, which action does the application firewall take on the packet?

  • A. It denies the first packet.
  • B. It denies the first packet and sends an error message to the user.
  • C. It allows the first packet.
  • D. It holds the first packet until the application is identified.

Answer: D

Explanation:
This is necessary to ensure that the application firewall can properly identify the application and the correct security policies can be applied before allowing any traffic to pass through.
If the first packet was allowed to pass without first being identified, then the application firewall would not know which security policies to apply - and this could potentially lead to security vulnerabilities or breaches. So it's important that the first packet is held until the application is identified.


NEW QUESTION # 74
When transit traffic matches a security policy, which three actions are available? (Choose three.)

  • A. Permit
  • B. Allow
  • C. Deny
  • D. Discard
  • E. Reject

Answer: A,C,E


NEW QUESTION # 75
......

New (2023) Juniper JN0-231 Exam Dumps: https://testking.braindumpsit.com/JN0-231-latest-dumps.html