[May-2024] JN0-231 Questions - Truly Beneficial For Your Juniper Exam
Download Juniper JN0-231 Sample Questions
NEW QUESTION # 23
Which two statements are true about Juniper ATP Cloud? (Choose two.)
- A. Juniper ATP Cloud is a cloud-based ATP subscription.
- B. Juniper ATP Cloud can be used to block and allow IPs.
- C. Juniper ATP Cloud delivers intrusion protection services.
- D. Juniper ATP Cloud is an on-premises ATP appliance.
Answer: A,C
Explanation:
Juniper ATP Cloud is a cloud-based ATP subscription that delivers advanced threat protection services, such as URL categorization, file reputation analysis, and malware analysis. It is able to quickly and accurately categorize URLs and other web content, and can also provide detailed reporting on web usage, as well as the ability to define and enforce acceptable use policies. Additionally, Juniper ATP Cloud is able to block and allow specific IPs, providing additional protection against malicious content.
NEW QUESTION # 24
What are the valid actions for a source NAT rule in J-Web? (choose three.)
- A. Pool
- B. On
- C. Source
- D. Off
- E. interface
Answer: A,D,E
NEW QUESTION # 25
Your company uses SRX Series devices to secure the edge of the network. You are asked protect the company from ransom ware attacks.
Which solution will satisfy this requirement?
- A. Sky ATP
- B. screens
- C. AppSecure
- D. Unified security policies
Answer: A
NEW QUESTION # 26
What is the purpose of the Shadow Policies workspace in J-Web?
- A. The Shadow Policies workspace shows used security policies due to policy overlap
- B. The Shadow Policies workspace shows unused security policies due to policy overlap.
- C. The Shadow Policies workspace shows used IPS policies due to policy overlap
- D. The Shadow Policies workspace shows unused IPS policies due to policy overlap.
Answer: B
NEW QUESTION # 27
You want to automatically generate the encryption and authentication keys during IPsec VPN establishment.
What would be used to accomplish this task?
- A. Main mode
- B. Diffie_Hellman
- C. Aggregate mode
- D. IPsec
Answer: B
NEW QUESTION # 28
What are two logical properties of an interface? (Choose two.)
- A. link speed
- B. IP address
- C. link mode
- D. VLAN ID
Answer: B,D
Explanation:
https://www.juniper.net/documentation/us/en/software/junos/interfaces-security-devices/topics/topic-map/security-interface-logical.html
NEW QUESTION # 29
You are configuring an SRX Series device. You have a set of servers inside your private network that need one-to-one mappings to public IP addresses.
Which NAT configuration is appropriate in this scenario?
- A. source NAT with PAT
- B. destination NAT
- C. NAT-T
- D. static NAT
Answer: D
Explanation:
https://www.juniper.net/documentation/en_US/day-one-books/nat-and-pat-en.html And the specific text that would support the above answer is as follows: "Static NAT, which requires manual configuration, is often the most appropriate configuration for mapping one internal address to one external address."
NEW QUESTION # 30
You want to enable the minimum Juniper ATP services on a branch SRX Series device.
In this scenario, what are two requirements to accomplish this task? (Choose two.)
- A. Execute the Juniper ATP script on the branch device.
- B. Install a basic Juniper ATP license on the branch device.
- C. Configure the juniper-atp user account on the branch device.
- D. Register for a Juniper ATP account on https://sky.junipersecurity.net.
Answer: A,D
Explanation:
https://manuals.plus/m/95fded847e67e8f456453182a54526ba3224a61a337c47177244d345d1f3b19e.pdf
NEW QUESTION # 31
Which two UTM features should be used for tracking productivity and corporate user behavior? (Choose two.)
- A. the antivirus UTM feature
- B. the content filtering UTM feature
- C. the antispam UTM feature
- D. the Web filtering UTM feature
Answer: B,D
NEW QUESTION # 32
Referring to the exhibit.
Which type of NAT is being performed?
- A. Destination NAT without PAT
- B. Source NAT with PAT
- C. Source NAT without PAT
- D. Destination NAT with PAT
Answer: B
NEW QUESTION # 33
Screens on an SRX Series device protect against which two types of threats? (Choose two.)
- A. zero-day outbreaks
- B. ICMP flooding
- C. IP spoofing
- D. malicious e-mail attachments
Answer: B,C
Explanation:
ICMP flood
Use the ICMP flood IDS option to protect against ICMP flood attacks. An ICMP flood attack typically occurs when ICMP echo requests use all resources in responding, such that valid network traffic can no longer be processed.
The threshold value defines the number of ICMP packets per second (pps) allowed to be send to the same destination address before the device rejects further ICMP packets.
IP spoofing
Use the IP address spoofing IDS option to prevent spoofing attacks. IP spoofing occurs when an invalid source address is inserted in the packet header to make the packet appear to come from a trusted source.
https://www.juniper.net/documentation/us/en/software/junos/denial-of-service/topics/topic-map/security-introduction-to-adp.html
NEW QUESTION # 34
Exhibit.
Which statement is correct regarding the interface configuration shown in the exhibit?
- A. The interface MTU has been increased.
- B. The IP address is assigned to unit 0.
- C. The IP address has an invalid subnet mask.
- D. The interface is assigned to the trust zone by default.
Answer: B
NEW QUESTION # 35
Which two statements are correct about global policies? (Choose two.)
- A. Global policies must reference zone contexts.
- B. Global policies are evaluated after default policies.
- C. Global policies are evaluated before default policies.
- D. Global policies do not have to reference zone context.
Answer: C,D
Explanation:
Global policies are used to define rules for traffic that is not associated with any particular zone. This type of policy is evaluated first, before any rules related to specific zones are evaluated.
For more detailed information about global policies, refer to the Juniper Networks Security Policy Overview guide, which can be found at https://www.juniper.net/documentation/en_US/junos/topics/reference/security-policy-overview.html. The guide provides an overview of the Juniper Networks security policy architecture, as well as detailed descriptions of the different types of policies and how they are evaluated.
NEW QUESTION # 36
SRX Series devices have a maximum of how many rollback configurations?
- A. 0
- B. 1
- C. 2
- D. 3
Answer: C
NEW QUESTION # 37
You have an FTP server and a webserver on the inside of your network that you want to make available to users outside of the network. You are allocated a single public IP address.
In this scenario, which two NAT elements should you configure? (Choose two.)
- A. destination NAT
- B. source NAT
- C. NAT pool
- D. static NAT
Answer: A,C
Explanation:
With single Ip address it is port forwarding. So, destination NAT and a pool address point to the single public IP of the internet facing interface.
NEW QUESTION # 38
......
Truly Beneficial For Your Juniper Exam: https://www.passexamdumps.com/JN0-231-valid-exam-dumps.html
Real JN0-231 Exam Questions and Answers FREE: https://drive.google.com/open?id=1iUP23-NK2HGDe_JW44GQAME86UBkmVuB
