Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the Juniper Associate JNCIA-SEC JN0-232 Questions and answers with CertsForce

Viewing page 2 out of 4 pages
Viewing questions 11-20 out of questions
Questions # 11:

Which two statements about security zones are correct? (Choose two.)

Options:

A.

You add a network interface to a security zone before it can send or receive traffic.


B.

Security zones control the type of exception traffic accepted by a network interface.


C.

Interfaces in the same security zone can use different routing instances.


D.

A security zone includes interfaces assigned to different routing instances.


Expert Solution
Questions # 12:

You must ensure that sessions can only be established from the external device.

Question # 12

Referring to the exhibit, which type of NAT is being performed?

Options:

A.

static NAT and source NAT


B.

static PAT only


C.

source NAT only


D.

destination NAT only


Expert Solution
Questions # 13:

You just made a configuration change to a security policy on your SRX Series Firewall. Your users alert you that an application that uses FTP is no longer working.

Question # 13

Referring to the exhibit, what are two ways to solve this problem? (Choose two.)

Options:

A.

Enter the rollback 1 command followed by a commit command.


B.

Activate the FTP security policy and commit the configuration.


C.

Insert the FTP security policy before the web-smtp security policy.


D.

Change the destination address in the FTP security policy to any and commit the configuration.


Expert Solution
Questions # 14:

You have a situation where legitimate traffic is incorrectly identified as malicious by your screen options.

In this scenario, what should you do?

Options:

A.

Enable all screen options.


B.

Discard the traffic immediately.


C.

Increase the sensitivity of the screen options.


D.

Use the alarm-without-drop configuration parameter.


Expert Solution
Questions # 15:

Which zone configuration is required to permit transit traffic?

Options:

A.

a system-defined null zone


B.

a system-defined Junos-host zone


C.

a user-defined security zone


D.

a user-defined functional zone


Expert Solution
Questions # 16:

A new packet arrives on an interface on your SRX Series Firewall that is assigned to the trust security zone.

In this scenario, how does the SRX Series Firewall determine the egress security zone?

Options:

A.

by performing a session lookup


B.

by examining the destination port


C.

by performing a route lookup


D.

by examining the ingress security zone properties


Expert Solution
Questions # 17:

Which two statements about functional zones are correct? (Choose two.)

Options:

A.

You can create only one functional zone called management.


B.

Functional zones consist of logical interfaces belonging to multiple zones.


C.

You reference the management functional zone in a security policy.


D.

The management functional zone controls management access to the firewall.


Expert Solution
Questions # 18:

When a new traffic flow enters an SRX Series device, in which order are these processes performed?

Options:

A.

screens → security policies → zones → routes


B.

screens → routes → zones → security policies


C.

routes → zones → screens → security policies


D.

screens → zones → security policies → routes


Expert Solution
Questions # 19:

You are asked to reduce security configuration complexity on your external facing firewalls. You notice that a previous administrator included hundreds of private subnet NAT rules covering various RFC1918 addresses. You want to replace all these rules with a single rule covering all RFC1918 addresses.

Which rule would you use in this scenario?

Options:

A.

set security nat source rule-set private-to-pub rule RFC1918 match source-address [10.0.0.0/8 192.168.0.0/16 172.16.0.0/12]


B.

set security nat source rule-set private-to-pub rule RFC1918 match source-address [10.0.0.0/8 192.16.0.0/12 172.168.0.0/16]


C.

set security nat source rule-set private-to-pub rule RFC1918 match source-address [10.0.0.0/8 172.168.0.0/16 192.0.2.0/24 203.1.113.0/24]


D.

set security nat source rule-set private-to-pub rule RFC1918 match source-address [10.0.0.0/8 192.168.0.0/16 172.16.0.0/12 192.0.2.0/24]


Expert Solution
Questions # 20:

Click the Exhibit button.

Question # 20

Question # 20

Referring to the exhibit, which statement is correct?

Options:

A.

policy3 will be shadowed because it matches the same application as policy1.


B.

None of the policies will be shadowed.


C.

policy1 will be shadowed because it matches the same application as policy3.


D.

policy2 will be shadowed because it matches the same application as policy1.


Expert Solution
Viewing page 2 out of 4 pages
Viewing questions 11-20 out of questions