Updated PDF (New 2021) Actual Juniper JN0-230 Exam Questions [Q45-Q65]

Share

Updated PDF (New 2021) Actual Juniper JN0-230 Exam Questions

Verified JN0-230 Exam Dumps PDF [2021] Access using ITExamDownload

NEW QUESTION 45
Which security object defines a source or destination IP address that is used for an employee Workstation?

  • A. Screen
  • B. Zone
  • C. Address book entry
  • D. scheduler

Answer: B

 

NEW QUESTION 46
Click the Exhibit button.

You have configured source NAT using an address pool as shown in the exhibit. Traffic is reaching the
203.0.113.6 server but return traffic is not being received by the SRX Series device.
Which feature must be configured to allow return traffic to be accepted by the SRX Series device?

  • A. destination NAT
  • B. reverse static NAT
  • C. proxy ARP
  • D. port forwarding

Answer: A

 

NEW QUESTION 47
Which two elements are needed on an SRX Series device to set up a remote syslog server? (Choose two.)

  • A. Data size
  • B. IP address
  • C. Data type
  • D. Data throughput

Answer: B,C

 

NEW QUESTION 48
Which two statements are true regarding zone-based security policies? (Choose two.)

  • A. Zone-based policies must reference a URL category in the match criteria.
  • B. Zone-based policies must reference a dynamic application in the match criteria.
  • C. Zone-based policies must reference a source address in the match criteria.
  • D. Zone-based policies must reference a destination address in the match criteria

Answer: C,D

 

NEW QUESTION 49
Which statements is correct about Junos security zones?

  • A. Logical interface are added to user defined security zones
  • B. Security policies are referenced within a user-defined security zone.
  • C. User-defined security must contains the key word ''zone''
  • D. User-defined security must contain at least one interface.

Answer: A

 

NEW QUESTION 50
Which two statements are true about Junos Space Security Director? (Choose two.)

  • A. Security Director is preinstalled on SRX Series devices.
  • B. Security Director can perform deep-packet analysis.
  • C. Security Director can deploy enforcement policies automatically to firewalls and switches.
  • D. Security Director supports creation and maintenance of metadata-based policies.

Answer: C,D

 

NEW QUESTION 51
Users in your network are downloading files with file extensions that you consider to be unsafe for your network. You must prevent files with specific file extensions from entering your network.
Which UTM feature should be enabled on an SRX Series device to accomplish this task?

  • A. URL filtering
  • B. content filtering
  • C. antispam
  • D. Web filtering

Answer: B

 

NEW QUESTION 52
What must you do first to use the Monitor/Events workspace in the j-Web interface?

  • A. You must enable event mode security logging on the SRX Series device.
  • B. You must enable stream mode security logging on the SRX Series device
  • C. You must enable security logging that uses the SD-Syslog format.
  • D. You must enable security logging that uses the TLS transport mode.

Answer: A

 

NEW QUESTION 53
You are designing a new security policy on an SRX Series device. You must block an application silently and log all occurrences of the application access attempts.
In this scenario, which two actions must be enabled in the security policy? (Choose two.)

  • A. Enable a reject action.
  • B. Log the session initiations.
  • C. Log the session closures.
  • D. Enable a deny action.

Answer: B,D

 

NEW QUESTION 54
Which two statements are true about security policies in the factory-default configuration of an SRX340?
(Choose two.)

  • A. All interzone traffic is allowed.
  • B. All interzone traffic is denied.
  • C. All traffic from the untrust zone to the trust zone is denied.
  • D. All traffic from the trust zone to the untrust zone is allowed.

Answer: C,D

 

NEW QUESTION 55
What are two characteristic of static NAT SRX Series devices? (Choose two.)

  • A. Static rules cannot coexist with destination NAT rules on the same SRX Series device configuration.
  • B. A reverse mapping rule is automatically created for the source translation.
  • C. Source and destination NAT rules take precedence over static NAT rules.
  • D. Static NAT rule take precedence over source and destination NAT rules.

Answer: B,D

 

NEW QUESTION 56
You want to integrate an SRX Series device with SKY ATP.
What is the first action to accomplish task?

  • A. Copy the operational script from the Sky ATP Web UI.
  • B. Issue the commit script to register the SRX Series device.
  • C. Create an account with the Sky ATP Web UI.
  • D. Create the SSL VPN tunnel between the SRX Series device and Sky ATP.

Answer: C

 

NEW QUESTION 57
What must you do first to use the Monitor/Events workspace in the j-Web interface?

  • A. You must enable event mode security logging on the SRX Series device.
  • B. You must enable stream mode security logging on the SRX Series device
  • C. You must enable security logging that uses the TLS transport mode.
  • D. You must enable security logging that uses the SD-Syslog format.

Answer: D

 

NEW QUESTION 58
You want to generate reports from the l-Web on an SRX Series device.
Which logging mode would you use in this scenario?

  • A. Event
  • B. Syslog
  • C. local
  • D. Stream

Answer: B

 

NEW QUESTION 59
Click the exhibit button

You are configuring an IPsec VPN for the network show in the exhibit
Which feature must be enabled the VPN to established successfully?

  • A. Aggressive mode must be configured on the IPsec VPN
  • B. Main mode must be configured on the IPsec VPN
  • C. Main mode must be configured on the IKE gateway
  • D. Aggressive mode must be configured on IKE gateway

Answer: D

 

NEW QUESTION 60
Which two statements are correct about functional zones? (Choose two.)

  • A. A function is used for special purpose, such as management interface
  • B. Traffic received on the management interface in the functional zone cannot transit out other interface.
  • C. Functional zones separate groups of users based on their function.
  • D. A functional zone uses security policies to enforce rules for transit traffic.

Answer: A,B

 

NEW QUESTION 61
Which two statements are true about the null zone? (Choose two.)

  • A. All interface belong to the bull zone by default.
  • B. The null zone is a user-defined zone
  • C. All traffic to the null zone is dropped.
  • D. All traffic to the null zone is allowed

Answer: B,D

 

NEW QUESTION 62
Which Statement is correct about Sky ATP?

  • A. Sky ATP is a local hardware-based security threat analyzer that performs multiple tasks.
  • B. Sky ATP relies on the SRX series device to open and analyze suspect file attachments
  • C. Sky ATP can provide live threat feeds to SRX series devices
  • D. The local Sky ATP platform downloads the latest threat from managed site

Answer: C

 

NEW QUESTION 63
Which statement is correct about IKE?

  • A. IKE phase 1 establishes the tunnel between devices
  • B. IKE phase 1 only support aggressive mode.
  • C. IKE phase 1 is used to establish the data path
  • D. IKE phase 1 negotiates a secure channel between gateways.

Answer: D

 

NEW QUESTION 64
Which security feature is applied to traffic on an SRX Series device when the device is running n packet mode?

  • A. Unified policies
  • B. ALGs
  • C. Sky ATP
  • D. Firewall filters

Answer: A

 

NEW QUESTION 65
......


Understanding functional and technical aspects of Layer 2 Bridging or VLANS

The following will be discussed in JN0-362 dumps:

  • Port modes
  • End-to-end packet flow and forwarding
  • Provider bridging (for example, Q-in-Q Tunneling)
  • MVRP
  • Demonstrate knowledge of how to configure, monitor, or troubleshoot MPLS
  • VLANs
  • Multiprotocol Label Switching (MPLS)
  • STP, RSTP, MSTP and VSTP concepts
  • Labels and the label information base
  • BPDUs
  • IRB
  • Spanning-tree protocols: STP, RSTP, MSTP, and VSTP
  • MPLS and routing tables
  • Spanning-Tree Protocols
  • MPLS forwarding
  • RSVP
  • Convergence and reconvergence
  • Tagging
  • LDP
  • Interfaces and ports
  • Demonstrate knowledge of how to configure, monitor, or troubleshoot STP and its variants
  • MPLS packet header
  • Identify the concepts, benefits, or functionality of VLANs
  • Frame processing
  • Port roles and states
  • Virtual Switches
  • BPDU, loop, and root protection
  • MVRP
  • Bridging elements and terminology
  • Demonstrate knowledge of how to configure, monitor, or troubleshoot Layer 2 bridging or VLANs
  • Identify the concepts, benefits, operation, or functionality of Spanning Tree Protocol and its variants
  • Service provider switching platforms
  • Spanning-tree security
  • Identify the concepts, operation, or functionality of Layer 2 bridging for the Junos OS
  • MPLS terminology
  • IRB
  • Provider bridging
  • RSVP-signaled and LDP-signaled LSPs
  • Identify the concepts, operation, or functionality of MPLS

Try Best JN0-230 Exam Questions from Training Expert ITExamDownload: https://www.itexamdownload.com/JN0-230-valid-questions.html