Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the Juniper Associate JNCIA-SEC JN0-232 Questions and answers with CertsForce

Viewing page 3 out of 4 pages
Viewing questions 21-30 out of questions
Questions # 21:

Referring to the exhibit, which two statements are correct about the traffic flow shown in the exhibit? (Choose two.)

Question # 21

Options:

A.

There is no change to the original source IP address.


B.

The original destination IP address was translated to a new destination IP address.


C.

There is no change to the original destination IP address.


D.

The original source IP address was translated to a new source IP address.


Expert Solution
Questions # 22:

You want to enable NextGen Web Filtering (NGWF) on your SRX Series Firewall.

Which two actions must you perform in this scenario? (Choose two.)

Options:

A.

Install a NextGen Web Filtering feature license.


B.

Enable NextGen Web Filtering as the default Web Filtering type.


C.

Assign a public IP address to the loopback interface.


D.

Enable SSL host inbound traffic on the untrust security zone.


Expert Solution
Questions # 23:

Which UI enables you to manage, monitor, and maintain multiple firewalls using a single interface?

Options:

A.

Juniper Secure Analytics


B.

Security Director


C.

Juniper Identity Management Service


D.

Secure Connect


Expert Solution
Questions # 24:

What is the purpose of a feature profile in a UTM configuration?

Options:

A.

It applies a UTM feature to a security policy.


B.

It applies a UTM feature to protocol traffic.


C.

It defines the operation of a specific UTM feature.


D.

It defines an object list.


Expert Solution
Questions # 25:

You are modifying the NAT rule order and you notice that a new NAT rule has been added to the bottom of the list.

In this situation, which command would you use to reorder NAT rules?

Options:

A.

top


B.

run


C.

up


D.

insert


Expert Solution
Questions # 26:

Which type of NAT performs port address translation?

Options:

A.

interface-based source NAT


B.

static NAT


C.

source NAT with address shifting


D.

destination NAT without port forwarding


Expert Solution
Questions # 27:

Which two statements are correct about enabling the Avira Antivirus engine on an SRX Series Firewall? (Choose two.)

Options:

A.

A license is required.


B.

A license is not required.


C.

A reboot is required.


D.

A reboot is not required.


Expert Solution
Questions # 28:

Which statement about the flow module is correct in the context of destination NAT?

Options:

A.

The flow module performs NAT during both first path and fast path processing.


B.

The flow module performs NAT only for source IP addresses.


C.

The flow module performs NAT only during fast path processing.


D.

The flow module performs NAT only during first path processing.


Expert Solution
Questions # 29:

You are troubleshooting traffic traversing the SRX Series Firewall and require detailed information showing how the flow module is handling the traffic.

How would you accomplish this task?

Options:

A.

Review the flow session table.


B.

Review the forwarding table.


C.

Enable flow trace options.


D.

Enable firewall filters.


Expert Solution
Questions # 30:

Referring to the exhibit, the top table shows the source and destination IP addresses and also the source and destination ports of the incoming packet.

Question # 30

The lower table represents the security policies from the trust zone to the untrust zone.

In this scenario, which two statements are correct? (Choose two.)

Options:

A.

The incoming packet is permitted by the HTTPS application.


B.

The incoming packet is permitted because it does not match any policy listed.


C.

The incoming packet is denied by the final security policy.


D.

The firewall processes security policies in a top-down manner.


Expert Solution
Viewing page 3 out of 4 pages
Viewing questions 21-30 out of questions