Weekend Sale 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: sale65best

Free Juniper JN0-231 Practice Exam with Questions & Answers | Set: 3

Questions 21

What is the default timeout value for TCP sessions on an SRX Series device?

Options:
A.

30 seconds

B.

60 minutes

C.

60 seconds

D.

30 minutes

Juniper JN0-231 Premium Access
Questions 22

You are assigned a project to configure SRX Series devices to allow connections to your webservers. The webservers have a private IP address, and the packets must use NAT to be accessible from the

Internet. You do not want the webservers to initiate connections with external update servers on the Internet using the same IP address as customers use to access them.

Which two NAT types must be used to complete this project? (Choose two.)

Options:
A.

static NAT

B.

hairpin NAT

C.

destination NAT

D.

source NAT

Questions 23

Which Juniper ATP feed provides a dynamic list of known botnet servers and known sources of malware downloads?

Options:
A.

infected host cloud feed

B.

Geo IP feed

C.

C&C cloud feed

D.

blocklist feed

Questions 24

You want to deploy a NAT solution.

In this scenario, which solution would provide a static translation without PAT?

Options:
A.

interface-based source NAT

B.

pool-based NAT with address shifting

C.

pool-based NAT with PAT

D.

pool-based NAT without PAT

Questions 25

When configuring antispam, where do you apply any local lists that are configured?

Options:
A.

custom objects

B.

advanced security policy

C.

antispam feature-profile

D.

antispam UTM policy

Questions 26

You want to block executable files ("exe) from being downloaded onto your network.

Which UTM feature would you use in this scenario?

Options:
A.

IPS

B.

Web filtering

C.

content filtering

D.

antivirus

Questions 27

Which two non-configurable zones exist by default on an SRX Series device? (Choose two.)

Options:
A.

Junos-host

B.

functional

C.

null

D.

management

Questions 28

When are Unified Threat Management services performed in a packet flow?

Options:
A.

before security policies are evaluated

B.

as the packet enters an SRX Series device

C.

only during the first path process

D.

after network address translation

Questions 29

When creating a site-to-site VPN using the J-Web shown in the exhibit, which statement is correct?

Options:
A.

The remote gateway is configured automatically based on the local gateway settings.

B.

RIP, OSPF, and BGP are supported under Routing mode.

C.

The authentication method is pre-shared key or certificate based.

D.

Privately routable IP addresses are required.

Questions 30

You are configuring an SRX Series device. You have a set of servers inside your private network that need one-to-one mappings to public IP addresses.

Which NAT configuration is appropriate in this scenario?

Options:
A.

source NAT with PAT

B.

destination NAT

C.

NAT-T

D.

static NAT