Weekend Sale Limited Time Flat 70% Discount offer - Ends in 0d 00h 00m 00s - Coupon code: 70spcl

Juniper JN0-232 Security, Associate (JNCIA-SEC) Exam Practice Test

Page: 1 / 7
Total 65 questions

Security, Associate (JNCIA-SEC) Questions and Answers

Question 1

You have a situation where legitimate traffic is incorrectly identified as malicious by your screen options.

In this scenario, what should you do?

Options:

A.

Enable all screen options.

B.

Discard the traffic immediately.

C.

Increase the sensitivity of the screen options.

D.

Use the alarm-without-drop configuration parameter.

Question 2

Click the Exhibit button.

Question # 2

Referring to the exhibit, which two statements are correct? (Choose two.)

Options:

A.

The URL matches a predefined Web filtering category.

B.

The NextGen Web Filtering type is being used.

C.

The SRX firewall does not have an SSL proxy configuration.

D.

This is a custom Web filtering block message.

Question 3

Which statement is correct about exception traffic?

Options:

A.

Exception traffic is only handled on the Packet Forwarding Engine.

B.

Exception traffic is rate-limited on the connection between the Packet Forwarding Engine and the Routing Engine.

C.

Exception traffic is anything that is rejected by security policies and requires additional processing.

D.

Exception traffic refers to malformed IP packets received on the Packet Forwarding Engine.

Question 4

What is the purpose of assigning logical interfaces to separate security zones in Junos OS?

Options:

A.

to simplify the configuration of network interfaces

B.

to manage routing protocols and updates

C.

to control traffic that traverses different VLANs using security policies

D.

to enable network monitoring through SNMP

Question 5

Click the Exhibit button.

Question # 5

Question # 5

Referring to the exhibit, which statement is correct?

Options:

A.

policy3 will be shadowed because it matches the same application as policy1.

B.

None of the policies will be shadowed.

C.

policy1 will be shadowed because it matches the same application as policy3.

D.

policy2 will be shadowed because it matches the same application as policy1.

Question 6

Which two statements about the host-inbound-traffic parameter in a zone configuration are correct? (Choose two.)

Options:

A.

Deleting the host-inbound-traffic parameter blocks console access to the firewall.

B.

Deleting the host-inbound-traffic parameter blocks SSH access to the firewall.

C.

The host-inbound-traffic parameter is implicitly configured in the management zone.

D.

The host-inbound-traffic parameter is explicitly configured in a security zone.

Question 7

Which two statements about management functional zones are correct? (Choose two.)

Options:

A.

The management functional zone is used to control the management-related traffic that is allowed to access your device.

B.

The management functional zone contains all available revenue ports until they are assigned to a user-defined security zone.

C.

The management functional zone is automatically created on the SRX Series Firewalls.

D.

The management functional zone cannot be referenced in any security policies.

Question 8

Click the Exhibit button.

Question # 8

You must ensure that sessions can only be established from the external device.

Referring to the exhibit, which type of NAT is being performed?

Options:

A.

destination NAT only

B.

source NAT only

C.

static PAT only

D.

static NAT and source NAT

Question 9

What are two system-defined zones created on the SRX Series Firewalls? (Choose two.)

Options:

A.

null

B.

junos-host

C.

management

D.

DMZ

Question 10

Which two statements are correct about NAT and security policy processing? (Choose two.)

Options:

A.

The security policy is evaluated before destination NAT.

B.

The security policy is evaluated after source NAT.

C.

The security policy is evaluated before source NAT.

D.

The security policy is evaluated after destination NAT.

Question 11

What is transit traffic in the Junos OS?

Options:

A.

It is traffic that is processed solely through the forwarding plane.

B.

It is traffic that is rate-limited to prevent denial-of-service attacks.

C.

It is traffic that is processed by the control plane.

D.

It is traffic that requires special handling by the Routing Engine.

Question 12

Your manager asks you to verify when your antivirus definitions were last updated on your SRX Series Firewall.

Which operational mode command allows you to see this information?

Options:

A.

show security utm content-filtering statistics

B.

show security utm anti-spam status

C.

show security web filtering status

D.

show security utm anti-virus status

Question 13

You want to use Avira Antivirus.

Which two actions should you perform to satisfy this requirement? (Choose two.)

Options:

A.

Restart the management daemon (mgd) to load the components.

B.

Enable the Avira engine in operational mode.

C.

Reboot the SRX Series device to load the components.

D.

Enable the Avira engine in configuration mode.

Question 14

Click the Exhibit button.

Question # 14

Referring to the exhibit, which two statements are correct? (Choose two.)

Options:

A.

This security policy uses a non-default inactivity timeout.

B.

This security policy is the second security policy in the list.

C.

This security policy permits HTTPS traffic.

D.

This security policy is a zone-based security policy.

Question 15

Your company is acquiring a smaller company that uses the same private address range that your company currently uses in its North America division. You have a limited number of public IP addresses to use for the acquisition. You want to allow the new acquisition's users to connect to the existing services in North America.

Which two features would you enable on your SRX Series Firewall to accomplish this task? (Choose two.)

Options:

A.

IDP

B.

NAT

C.

BGP

D.

PAT

Question 16

Which two statements about destination NAT are correct? (Choose two.)

Options:

A.

Destination NAT enables hosts on a private network to access resources on the Internet.

B.

SRX Series Firewalls support interface-based destination NAT.

C.

Destination NAT enables hosts on the Internet to access resources on a private network.

D.

SRX Series Firewalls support pool-based destination NAT.

Question 17

Which two statements are correct about security zones? (Choose two.)

Options:

A.

An interface can exist in multiple security zones.

B.

Interfaces in the same security zone must share the same routing instance.

C.

Interfaces in the same security zone must use separate routing instances.

D.

A security zone can contain multiple interfaces.

Question 18

Which two statements are correct about unified security policies? (Choose two.)

Options:

A.

Traffic that matches a unified policy will not be evaluated by traditional security policy.

B.

Dynamic applications in unified security policies analyze traffic based on Layer 4 information.

C.

Traffic that matches a traditional policy will not be evaluated by unified security policy.

D.

Dynamic applications in unified security policies analyze traffic based on Layer 7 information.

Question 19

Which UI enables you to manage, monitor, and maintain multiple firewalls using a single interface?

Options:

A.

Juniper Secure Analytics

B.

Security Director

C.

Juniper Identity Management Service

D.

Secure Connect

Page: 1 / 7
Total 65 questions