Pass the Juniper Associate JNCIA-SEC JN0-232 Questions and answers with CertsForce

Viewing page 2 out of 2 pages
Viewing questions 11-20 out of questions
Questions # 11:

Which two statements about the null zone on an SRX Series Firewall are correct? (Choose two.)

Options:

A.

Transit interfaces are assigned to the null zone by default.


B.

Traffic rejected by the security policy is sent to the null zone for logging.


C.

The null zone can be configured to accept traffic to or from the SRX Series Firewall.


D.

A logical interface configured in a security zone removes it from the null zone.


Expert Solution
Questions # 12:

Which two criteria would be used for matching in security policies? (Choose two.)

Options:

A.

MAC address


B.

source address


C.

interface name


D.

applications


Expert Solution
Questions # 13:

Which two statements are true about the NextGen Web Filtering (NGWF) feature on an SRX Series device? (Choose two.)

Options:

A.

The NGWF feature consults the Juniper cloud before consulting your local lists.


B.

The NGWF feature requires a license.


C.

The NGWF feature consults your local lists before consulting the Juniper cloud.


D.

The NGWF feature does not require a license.


Expert Solution
Questions # 14:

Click the Exhibit button.

Question # 14

Question # 14

Referring to the exhibit, which statement is correct?

Options:

A.

policy3 will be shadowed because it matches the same application as policy1.


B.

None of the policies will be shadowed.


C.

policy1 will be shadowed because it matches the same application as policy3.


D.

policy2 will be shadowed because it matches the same application as policy1.


Expert Solution
Questions # 15:

What is transit traffic in the Junos OS?

Options:

A.

It is traffic that is processed solely through the forwarding plane.


B.

It is traffic that is rate-limited to prevent denial-of-service attacks.


C.

It is traffic that is processed by the control plane.


D.

It is traffic that requires special handling by the Routing Engine.


Expert Solution
Questions # 16:

Which two security policies are installed by default on SRX 300 Series Firewalls? (Choose two.)

Options:

A.

a security policy to allow all traffic from the untrust zone to the trust zone


B.

a security policy to allow all traffic from the trust zone to the untrust zone


C.

a security policy to allow all traffic from the management zone to the trust zone


D.

a security policy to allow all traffic from the trust zone to the trust zone


Expert Solution
Questions # 17:

Which two statements are correct about security zones? (Choose two.)

Options:

A.

An interface can exist in multiple security zones.


B.

Interfaces in the same security zone must share the same routing instance.


C.

Interfaces in the same security zone must use separate routing instances.


D.

A security zone can contain multiple interfaces.


Expert Solution
Questions # 18:

Which statement is correct about capturing transit packets on an SRX Series Firewall?

Options:

A.

You can capture transit packets on the egress interface using a firewall filter.


B.

You can capture transit packets by using a firewall filter on the loopback interface.


C.

You can capture transit packets by using the tcpdump utility in the shell.


D.

You can capture transit packets using sampling and port mirroring.


Expert Solution
Questions # 19:

Which two statements about management functional zones are correct? (Choose two.)

Options:

A.

The management functional zone is used to control the management-related traffic that is allowed to access your device.


B.

The management functional zone contains all available revenue ports until they are assigned to a user-defined security zone.


C.

The management functional zone is automatically created on the SRX Series Firewalls.


D.

The management functional zone cannot be referenced in any security policies.


Expert Solution
Viewing page 2 out of 2 pages
Viewing questions 11-20 out of questions