Weekend Sale 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: sale65best

Free Juniper JN0-231 Practice Exam with Questions & Answers | Set: 2

Questions 11

Which order is correct for Junos security devices that examine policies for transit traffic?

Options:
A.

zone policies

global policies

default policies

B.

default policies

zone policies

global policies

C.

default policies

global policies

zone policies

D.

global policies

zone policies

default policies

Juniper JN0-231 Premium Access
Questions 12

You have an FTP server and a webserver on the inside of your network that you want to make available to users outside of the network. You are allocated a single public IP address.

In this scenario, which two NAT elements should you configure? (Choose two.)

Options:
A.

destination NAT

B.

NAT pool

C.

source NAT

D.

static NAT

Questions 13

What are three primary match criteria used in a Junos security policy? (Choose three.)

Options:
A.

application

B.

source address

C.

source port

D.

class

E.

destination address

Questions 14

Which two services does Juniper Connected Security provide? (Choose two.)

Options:
A.

protection against zero-day threats

B.

IPsec VPNs

C.

Layer 2 VPN tunnels

D.

inline malware blocking

Questions 15

Which statement about NAT is correct?

Options:
A.

Destination NAT takes precedence over static NAT.

B.

Source NAT is processed before security policy lookup.

C.

Static NAT is processed after forwarding lookup.

D.

Static NAT takes precedence over destination NAT.

Questions 16

What is the default value of the dead peer detection (DPD) interval for an IPsec VPN tunnel?

Options:
A.

20 seconds

B.

5 seconds

C.

10 seconds

D.

40 seconds

Questions 17

Click the Exhibit button.

JN0-231 Question 17

Referring to the exhibit, which two statements are correct about the ping command? (Choose two.)

Options:
A.

The DMZ routing-instance is the source.

B.

The 10.10.102.10 IP address is the source.

C.

The 10.10.102.10 IP address is the destination.

D.

The DMZ routing-instance is the destination.

Questions 18

Click the Exhibit button.

JN0-231 Question 18

Which two statements are correct about the partial policies shown in the exhibit? (Choose two.)

Options:
A.

UDP traffic matched by the deny-all policy will be silently dropped.

B.

TCP traffic matched by the reject-all policy will have a TCP RST sent.

C.

TCP traffic matched from the zone trust is allowed by the permit-all policy.

D.

UDP traffic matched by the reject-all policy will be silently dropped.

Questions 19

What are two characteristics of a null zone? (Choose two.)

Options:
A.

The null zone is configured by the super user.

B.

By default, all unassigned interfaces are placed in the null zone.

C.

All ingress and egress traffic on an interface in a null zone is permitted.

D.

When an interface is deleted from a zone, it is assigned back to the null zone.

Questions 20

The UTM features are performed during which process of the SRX Series device's packet flow?

Options:
A.

services

B.

security policies

C.

zones

D.

screens