Summer Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70percent

Juniper JN0-232 Security, Associate (JNCIA-SEC) Exam Practice Test

Demo: 33 questions
Total 110 questions

Security, Associate (JNCIA-SEC) Questions and Answers

Question 1

In which order does Junos OS process the various forms of NAT?

Options:

A.

static NAT, destination NAT, source NAT

B.

destination NAT, source NAT, static NAT

C.

source NAT, static NAT, destination NAT

D.

source NAT, destination NAT, static NAT

Question 2

What is transit traffic in the Junos OS?

Options:

A.

It is traffic that is processed solely through the forwarding plane.

B.

It is traffic that is rate-limited to prevent denial-of-service attacks.

C.

It is traffic that is processed by the control plane.

D.

It is traffic that requires special handling by the Routing Engine.

Question 3

What are two ways that an SRX Series device identifies content? (Choose two.)

Options:

A.

It identifies and inspects the file extension of each file.

B.

It uses AppID.

C.

It identifies file types in HTTP, FTP, and e-mail protocols.

D.

It uses ALGs.

Question 4

You are asked to create a security policy that controls traffic allowed to pass between the Internet and private security zones. You must ensure that this policy is evaluated before all other policy types on your SRX Series device.

In this scenario, which type of security policy should you create?

Options:

A.

routing policy

B.

default policy

C.

zone policy

D.

global policy

Question 5

What are three requirements for creating a custom application? (Choose three.)

Options:

A.

You must define the port number.

B.

You must define the security policy.

C.

You must define the application name.

D.

You must define the source address.

E.

You must define the protocol.

Question 6

Referring to the exhibit,

which action would you take to permit the traffic shown in the exhibit?

Options:

A.

Assign the ge-0/0/1.0 interface to a security zone.

B.

Assign the fxp0.0 interface to a security zone.

C.

Enable flow-mode processing for family mpls.

D.

Enable flow-mode processing for family inet.

Question 7

You want to confirm that your SRX Series Firewall is connected to the SBL server.

Which operational mode command would you use in this scenario?

Options:

A.

show security utm anti-virus status

B.

show security web filtering status

C.

show security utm content-filtering statistics

D.

show security utm anti-spam status

Question 8

Click the Exhibit button.

Which two statements are correct about the content filter shown in the exhibit? (Choose two.)

Options:

A.

.exe files will not be allowed to be uploaded over HTTP.

B.

.exe files will not be allowed to be downloaded over HTTP.

C.

There will be a notice added to the SRX log file about the file being blocked.

D.

There will be an e-mail sent to the user about why the SRX is blocking the file.

Question 9

You have created a series of security policies permitting access to a variety of services. You now want to create a policy that blocks access to all other services for all user groups.

What should you create in this scenario?

Options:

A.

global security policy

B.

Juniper ATP policy

C.

IDP policy

D.

integrated user firewall policy

Question 10

An SRX Series Firewall operates in which two modes? (Choose two.)

Options:

A.

flow mode

B.

packet mode

C.

route mode

D.

wireless mode

Question 11

What are two purposes of configuring application sets? (Choose two.)

Options:

A.

to organize multiple applications into a single group

B.

to open dynamic ports used by particular applications for the duration of a session

C.

to organize multiple addresses into a single group

D.

to change the applications referenced in a security policy without editing the security policy

Question 12

Click the Exhibit button.

Which security policy component is highlighted in the exhibit?

Options:

A.

security zone context

B.

unique policy name

C.

match criteria

D.

policy action

Question 13

When traffic enters an interface, which two results does a route lookup determine? (Choose two.)

Options:

A.

egress interface

B.

egress security zone

C.

ingress interface

D.

DNS name

Question 14

Which two statements are correct about unified security policies on SRX Series Firewalls? (Choose two.)

Options:

A.

Unified security policies match applications before processing policy statements.

B.

Unified security policies can be zone-based or global.

C.

Unified security policies use the application identification (AppID) engine.

D.

Unified security policies with multiple matches use the most restrictive match.

Question 15

Which statement is correct about capturing transit packets on an SRX Series Firewall?

Options:

A.

You can capture transit packets on the egress interface using a firewall filter.

B.

You can capture transit packets by using a firewall filter on the loopback interface.

C.

You can capture transit packets by using the tcpdump utility in the shell.

D.

You can capture transit packets using sampling and port mirroring.

Question 16

What must also be enabled when using source NAT if the address pool is in the same subnet as the interface?

Options:

A.

static NAT

B.

dynamic DNS

C.

destination NAT

D.

proxy ARP

Question 17

When a new traffic flow enters an SRX Series device, in which order are these processes performed?

Options:

A.

screens → security policies → zones → routes

B.

screens → routes → zones → security policies

C.

routes → zones → screens → security policies

D.

screens → zones → security policies → routes

Question 18

Referring to the exhibit, which two statements are correct about the traffic flow shown in the exhibit? (Choose two.)

Options:

A.

There is no change to the original source IP address.

B.

The original destination IP address was translated to a new destination IP address.

C.

There is no change to the original destination IP address.

D.

The original source IP address was translated to a new source IP address.

Question 19

A URL is not found in the local allow list, block list, or local cache during the NextGen Web Filtering process. Which action does the SRX Series Firewall take in this scenario?

Options:

A.

It allows the URL by default.

B.

It sends a TCP reset message to the client.

C.

It forwards the URL to the NextGen Web Filtering application in the Juniper cloud.

D.

It blocks the URL by default.

Question 20

Which two statements about global security policies are correct? (Choose two.)

Options:

A.

The from-zone and to-zone contexts are not required for a global security policy.

B.

Global security policies require specific zone contexts.

C.

Global policies are processed before zone-based security policies.

D.

You can use both zone-based security policies and global security policies at the same time.

Question 21

When does screening occur in the flow module?

Options:

A.

before session lookup

B.

during policy lookup

C.

during route lookup

D.

after session lookup

Question 22

Click the Exhibit button.

Referring to the exhibit, which two statements are correct? (Choose two.)

Options:

A.

This security policy uses a non-default inactivity timeout.

B.

This security policy is the second security policy in the list.

C.

This security policy permits HTTPS traffic.

D.

This security policy is a zone-based security policy.

Question 23

Referring to the exhibit, which two statements are correct? (Choose two.)

Options:

A.

Traffic does not match this NAT rule.

B.

All traffic that ingresses the trust security zone and egresses the untrust security zone matches this NAT rule.

C.

Only traffic that matches the default route matches this NAT rule.

D.

This is the first NAT rule in the rule set.

Question 24

Which two statements are correct about enabling the Avira Antivirus engine on an SRX Series Firewall? (Choose two.)

Options:

A.

A license is required.

B.

A license is not required.

C.

A reboot is required.

D.

A reboot is not required.

Question 25

Referring to the exhibit,

which two statements are correct? (Choose two.)

Options:

A.

The SRX Series Firewall is performing destination NAT.

B.

The SRX Series Firewall is performing source NAT.

C.

The SRX Series Firewall is not performing PAT.

D.

The SRX Series Firewall is performing PAT.

Question 26

You are asked to enable trace options to debug the packet flow.

In this scenario, which flag would you configure at the [edit security flow traceoptions] hierarchy?

Options:

A.

packet-dump

B.

general

C.

state

D.

basic-datapath

Question 27

Which two statements are correct about the processing of NAT rules within a rule set? (Choose two.)

Options:

A.

NAT rule processing processes all rules.

B.

NAT rule processing stops at the first match.

C.

NAT rules are processed from top to bottom.

D.

NAT rules are processed from bottom to top.

Question 28

You are asked to reduce security configuration complexity on your external facing firewalls. You notice that a previous administrator included hundreds of private subnet NAT rules covering various RFC1918 addresses. You want to replace all these rules with a single rule covering all RFC1918 addresses.

Which rule would you use in this scenario?

Options:

A.

set security nat source rule-set private-to-pub rule RFC1918 match source-address [10.0.0.0/8 192.168.0.0/16 172.16.0.0/12]

B.

set security nat source rule-set private-to-pub rule RFC1918 match source-address [10.0.0.0/8 192.16.0.0/12 172.168.0.0/16]

C.

set security nat source rule-set private-to-pub rule RFC1918 match source-address [10.0.0.0/8 172.168.0.0/16 192.0.2.0/24 203.1.113.0/24]

D.

set security nat source rule-set private-to-pub rule RFC1918 match source-address [10.0.0.0/8 192.168.0.0/16 172.16.0.0/12 192.0.2.0/24]

Question 29

Which type of policy is shown in the exhibit?

Options:

A.

default policy

B.

intra-zone policy

C.

inter-zone policy

D.

global policy

Question 30

Your manager asks you to ping 192.0.2.128. The ping fails and you do not know why, so you enable a trace option on your SRX Series Firewall.

Referring to the exhibit, what is the reason for this behavior?

Options:

A.

It is matching a web filter.

B.

It is matching an ALG.

C.

It is matching a screen.

D.

There is no known route.

Question 31

Referring to the exhibit, the top table shows the source and destination IP addresses and also the source and destination ports of the incoming packet.

The lower table represents the security policies from the trust zone to the untrust zone.

In this scenario, which two statements are correct? (Choose two.)

Options:

A.

The incoming packet is permitted by the HTTPS application.

B.

The incoming packet is permitted because it does not match any policy listed.

C.

The incoming packet is denied by the final security policy.

D.

The firewall processes security policies in a top-down manner.

Question 32

What are two system-defined zones created on the SRX Series Firewalls? (Choose two.)

Options:

A.

null

B.

junos-host

C.

management

D.

DMZ

Question 33

What is a purpose for creating multiple routing instances on an SRX Series Firewall device?

Options:

A.

to enable network monitoring through SNMP

B.

to maintain separation of routing information for security purposes

C.

to manage routing protocols and updates

D.

to simplify the configuration of network interfaces

Demo: 33 questions
Total 110 questions