Labour Day Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: geek65

JN0-231 Security-Associate (JNCIA-SEC) Questions and Answers

Questions 4

You want to deploy a NAT solution.

In this scenario, which solution would provide a static translation without PAT?

Options:

A.

interface-based source NAT

B.

pool-based NAT with address shifting

C.

pool-based NAT with PAT

D.

pool-based NAT without PAT

Buy Now
Questions 5

When creating a site-to-site VPN using the J-Web shown in the exhibit, which statement is correct?

Options:

A.

The remote gateway is configured automatically based on the local gateway settings.

B.

RIP, OSPF, and BGP are supported under Routing mode.

C.

The authentication method is pre-shared key or certificate based.

D.

Privately routable IP addresses are required.

Buy Now
Questions 6

Which two statements are correct about screens? (Choose two.)

Options:

A.

Screens process inbound packets.

B.

Screens are processed on the routing engine.

C.

Screens process outbound packets.

D.

Screens are processed on the flow module.

Buy Now
Questions 7

SRX Series devices have a maximum of how many rollback configurations?

Options:

A.

40

B.

60

C.

50

D.

10

Buy Now
Questions 8

You are creating Ipsec connections.

In this scenario, which two statements are correct about proxy IDs? (Choose two.)

Options:

A.

Proxy IDs are used to configure traffic selectors.

B.

Proxy IDs are optional for Phase 2 session establishment.

C.

Proxy IDs must match for Phase 2 session establishment.

D.

Proxy IDs default to 0.0.0.0/0 for policy-based VPNs.

Buy Now
Questions 9

Which two statements are correct about functional zones? (Choose two.)

Options:

A.

Functional zones must have a user-defined name.

B.

Functional zone cannot be referenced in security policies or pass transit traffic.

C.

Multiple types of functional zones can be defined by the user.

D.

Functional zones are used for out-of-band device management.

Buy Now
Questions 10

You are investigating a communication problem between two hosts and have opened a session on the SRX Series device closest to one of the hosts and entered the show security flow session command.

What information will this command provide? (Choose two.)

Options:

A.

The total active time of the session.

B.

The end-to-end data path that the packets are taking.

C.

The IP address of the host that initiates the session.

D.

The security policy name that is controlling the session.

Buy Now
Questions 11

Which IPsec protocol is used to encrypt the data payload?

Options:

A.

ESP

B.

IKE

C.

AH

D.

TCP

Buy Now
Questions 12

You are assigned a project to configure SRX Series devices to allow connections to your webservers. The webservers have a private IP address, and the packets must use NAT to be accessible from the Internet. The webservers must use the same address for both connections from the Internet and communication with update servers.

Which NAT type must be used to complete this project?

Options:

A.

source NAT

B.

destination NAT

C.

static NAT

D.

hairpin NAT

Buy Now
Questions 13

What are two logical properties of an interface? (Choose two.)

Options:

A.

link mode

B.

IP address

C.

VLAN ID

D.

link speed

Buy Now
Questions 14

You want to enable the minimum Juniper ATP services on a branch SRX Series device.

In this scenario, what are two requirements to accomplish this task? (Choose two.)

Options:

A.

Install a basic Juniper ATP license on the branch device.

B.

Configure the juniper-atp user account on the branch device.

C.

Register for a Juniper ATP account on https://sky.junipersecurity.net.

D.

Execute the Juniper ATP script on the branch device.

Buy Now
Questions 15

Which two statements about user-defined security zones are correct? (Choose two.)

Options:

A.

Users cannot share security zones between routing instances.

B.

Users can configure multiple security zones.

C.

Users can share security zones between routing instances.

D.

User-defined security zones do not apply to transit traffic.

Buy Now
Exam Code: JN0-231
Exam Name: Security-Associate (JNCIA-SEC)
Last Update: May 1, 2024
Questions: 101
JN0-231 pdf

JN0-231 PDF

$28  $80
JN0-231 Engine

JN0-231 Testing Engine

$33.25  $95
JN0-231 PDF + Engine

JN0-231 PDF + Testing Engine

$45.5  $130