Weekend Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70percent

Juniper JN0-232 Security, Associate (JNCIA-SEC) Exam Practice Test

Demo: 19 questions
Total 65 questions

Security, Associate (JNCIA-SEC) Questions and Answers

Question 1

Which security policy action will cause traffic to drop and a message to be sent to the source?

Options:

A.

permit

B.

next-policy

C.

deny

D.

reject

Question 2

When traffic enters an interface, which two results does a route lookup determine? (Choose two.)

Options:

A.

ingress interface

B.

egress interface

C.

DNS name

D.

egress security zone

Question 3

When a new traffic flow enters an SRX Series device, in which order are these processes performed?

Options:

A.

screens → security policies → zones → routes

B.

screens → routes → zones → security policies

C.

routes → zones → screens → security policies

D.

screens → zones → security policies → routes

Question 4

Which two criteria would be used for matching in security policies? (Choose two.)

Options:

A.

MAC address

B.

source address

C.

interface name

D.

applications

Question 5

You want to verify the effectiveness of Web filtering on the SRX Series Firewall.

How would you accomplish this task?

Options:

A.

by installing a local NGWF server

B.

by checking the file extensions of blocked content

C.

by examining the content filtering policies

D.

by attempting to access permitted or blocked URLs

Question 6

Which statement is correct about source NAT?

Options:

A.

It translates MAC addresses to private IP addresses.

B.

It translates private IP addresses to public IP addresses.

C.

It performs bidirectional IP address translation.

D.

It performs translation on ingress traffic only.

Question 7

Click the Exhibit button.

Referring to the exhibit, which two statements are correct? (Choose two.)

Options:

A.

The URL matches a predefined Web filtering category.

B.

The NextGen Web Filtering type is being used.

C.

The SRX firewall does not have an SSL proxy configuration.

D.

This is a custom Web filtering block message.

Question 8

Click the Exhibit button.

You must ensure that sessions can only be established from the external device.

Referring to the exhibit, which type of NAT is being performed?

Options:

A.

destination NAT only

B.

source NAT only

C.

static PAT only

D.

static NAT and source NAT

Question 9

Which two statements are correct about security zones on an SRX Series device? (Choose two.)

Options:

A.

Security zones can be shared between routing instances.

B.

Security zones cannot be shared between routing instances.

C.

Intrazone and interzone traffic both require security policies.

D.

Multiple security zones cannot be configured on an SRX Series device.

Question 10

Click the Exhibit button.

Referring to the exhibit, which two statements are correct about the traffic flow shown in the exhibit? (Choose two.)

Options:

A.

There is no change to the original source IP address.

B.

The original source IP address was translated to a new source IP address.

C.

There is no change to the original destination IP address.

D.

The original destination IP address was translated to a new destination IP address.

Question 11

What is the purpose of rate-limiting exception traffic in the Junos OS?

Options:

A.

to enhance the performance of the forwarding plane

B.

to simplify the configuration of network interfaces

C.

to prevent denial-of-service attacks on the Routing Engine

D.

to manage routing protocols and updates

Question 12

You have a situation where legitimate traffic is incorrectly identified as malicious by your screen options.

In this scenario, what should you do?

Options:

A.

Enable all screen options.

B.

Discard the traffic immediately.

C.

Increase the sensitivity of the screen options.

D.

Use the alarm-without-drop configuration parameter.

Question 13

Content filtering supports which two of the following protocols? (Choose two.)

Options:

A.

SMTP

B.

SNMP

C.

TFTP

D.

HTTP

Question 14

Which UI enables you to manage, monitor, and maintain multiple firewalls using a single interface?

Options:

A.

Juniper Secure Analytics

B.

Security Director

C.

Juniper Identity Management Service

D.

Secure Connect

Question 15

Which two characteristics of destination NAT and static NAT are correct? (Choose two.)

Options:

A.

Static NAT automatically creates a matching rule for the opposite direction.

B.

Destination NAT requires address range sizes that match the devices being translated.

C.

Static NAT uses Port Address Translation.

D.

Destination NAT supports port forwarding.

Question 16

You are asked to enable trace options to debug the packet flow.

In this scenario, which flag would you configure at the [edit security flow traceoptions] hierarchy?

Options:

A.

packet-dump

B.

general

C.

state

D.

basic-datapath

Question 17

Which two statements are correct about unified security policies? (Choose two.)

Options:

A.

Traffic that matches a unified policy will not be evaluated by traditional security policy.

B.

Dynamic applications in unified security policies analyze traffic based on Layer 4 information.

C.

Traffic that matches a traditional policy will not be evaluated by unified security policy.

D.

Dynamic applications in unified security policies analyze traffic based on Layer 7 information.

Question 18

Which two statements about destination NAT are correct? (Choose two.)

Options:

A.

Destination NAT enables hosts on a private network to access resources on the Internet.

B.

SRX Series Firewalls support interface-based destination NAT.

C.

Destination NAT enables hosts on the Internet to access resources on a private network.

D.

SRX Series Firewalls support pool-based destination NAT.

Question 19

What happens if no match is found in both zone-based and global security policies?

Options:

A.

The traffic is discarded by the default security policy.

B.

The traffic is redirected to a predefined safe zone.

C.

The traffic is logged for further analysis.

D.

The traffic is allowed by default.

Demo: 19 questions
Total 65 questions