ExamGecko
Home / Juniper / JN0-231 / List of questions
Ask Question

Juniper JN0-231 Practice Test - Questions Answers, Page 2

Add to Whishlist

List of questions

Question 11

Report Export Collapse

Which statement about global NAT address persistence is correct?

The same IP address from a source NAT pool will be assigned for all sessions from a given host.
The same IP address from a source NAT pool will be assigned for all sessions from a given host.
The same IP address from a source NAT pool is not guaranteed to be assigned for all sessions from a given host.
The same IP address from a source NAT pool is not guaranteed to be assigned for all sessions from a given host.
The same IP address from a destination NAT pool will be assigned for all sessions for a given host.
The same IP address from a destination NAT pool will be assigned for all sessions for a given host.
The same IP address from a destination NAT pool is not guaranteed to be assigned for all sessions for a given host.
The same IP address from a destination NAT pool is not guaranteed to be assigned for all sessions for a given host.
Suggested answer: A
Explanation:

Use the persistent-nat feature to ensure that all requests from the same internal transport address are mapped to the same reflexive transport address (the public IP address and port created by the NAT device closest to the STUN server).

The source NAT rule action can use a source NAT pool (with or without port translation) or an egress interface.

asked 18/09/2024
Judith Persons
48 questions

Question 12

Report Export Collapse

You are asked to configure your SRX Series device to block all traffic from certain countries. The solution must be automatically updated as IP prefixes become allocated to those certain countries.

Which Juniper ATP solution will accomplish this task?

Geo IP
Geo IP
unified security policies
unified security policies
IDP
IDP
C&C feed
C&C feed
Suggested answer: A
Explanation:

Juniper ATP Geo IP can help to accomplish this task by using geolocation services to determine the geographical location of IP addresses. As IP prefixes get allocated to the countries that you have specified, the Geo IP solution will automatically update the configured firewall policies to block any traffic that is coming from those specific countries.

This is a great solution for blocking specific countries - as it will allow for a more personalized and targeted approach to firewall policies - and thus, to increase the effectiveness of the solution at blocking potential malicious traffic.

asked 18/09/2024
Romain Casagrande
38 questions

Question 13

Report Export Collapse

Which two statements are correct about IKE security associations? (Choose two.)

IKE security associations are established during IKE Phase 1 negotiations.
IKE security associations are established during IKE Phase 1 negotiations.
IKE security associations are unidirectional.
IKE security associations are unidirectional.
IKE security associations are established during IKE Phase 2 negotiations.
IKE security associations are established during IKE Phase 2 negotiations.
IKE security associations are bidirectional.
IKE security associations are bidirectional.
Suggested answer: A, D
asked 18/09/2024
garima sharma
55 questions

Question 14

Report Export Collapse

You want to deploy a NAT solution.

In this scenario, which solution would provide a static translation without PAT?

interface-based source NAT
interface-based source NAT
pool-based NAT with address shifting
pool-based NAT with address shifting
pool-based NAT with PAT
pool-based NAT with PAT
pool-based NAT without PAT
pool-based NAT without PAT
Suggested answer: B
Explanation:

Translation of the original source IP address to an IP address from a user-defined address pool by shifting the IP addresses. This type of translation is one-to-one, static, and without port address translation. If the original source IP address range is larger than the IP address range in the userdefined pool, untranslated packets are dropped.

https://www.juniper.net/documentation/us/en/software/junos/nat/topics/topic-map/nat-securitysource-and-source-pool.html

asked 18/09/2024
Colin Huisman
41 questions

Question 15

Report Export Collapse

Which Juniper Networks solution uses static and dynamic analysis to search for day-zero malware threats?

firewall filters
firewall filters
UTM
UTM
Juniper ATP Cloud
Juniper ATP Cloud
IPS
IPS
Suggested answer: C
Explanation:

Malware Sandboxing

Detect and stop zero-day and commodity malware within web, email, data center, and application traffic targeted for Windows, Mac, and IoT devices.

https://www.juniper.net/us/en/products/security/advanced-threat-prevention.html

asked 18/09/2024
Nael Abal
40 questions

Question 16

Report Export Collapse

You are configuring an SRX Series device. You have a set of servers inside your private network that need one-to-one mappings to public IP addresses.

Which NAT configuration is appropriate in this scenario?

source NAT with PAT
source NAT with PAT
destination NAT
destination NAT
NAT-T
NAT-T
static NAT
static NAT
Suggested answer: D
Explanation:

https://www.juniper.net/documentation/en_US/day-one-books/nat-and-pat-en.htmlAnd the specific text that would support the above answer is as follows: "Static NAT, which requiresmanual configuration, is often the most appropriate configuration for mapping one internal addressto one external address."

asked 18/09/2024
Francesco Gallo
38 questions

Question 17

Report Export Collapse

You want to provide remote access to an internal development environment for 10 remote developers.

Which two components are required to implement Juniper Secure Connect to satisfy this requirement? (Choose two.)

an additional license for an SRX Series device
an additional license for an SRX Series device
Juniper Secure Connect client software
Juniper Secure Connect client software
an SRX Series device with an SPC3 services card
an SRX Series device with an SPC3 services card
Marvis virtual network assistant
Marvis virtual network assistant
Suggested answer: A, B
asked 18/09/2024
alain giansily
46 questions

Question 18

Report Export Collapse

You are deploying an SRX Series firewall with multiple NAT scenarios.

In this situation, which NAT scenario takes priority?

interface NAT
interface NAT
source NAT
source NAT
static NAT
static NAT
destination NAT
destination NAT
Suggested answer: A
Explanation:

This is because the interface NAT would allow the connections to pass through the firewall - and thus, would ensure that the appropriate ports are open in order to allow for the connections to be established.

This is a really important step in order to ensure that all of the appropriate traffic is allowed through the SRX Series firewall - and thus, it must be a priority when deploying the firewall.

asked 18/09/2024
Yuriy Kitsis
40 questions

Question 19

Report Export Collapse

Your ISP gives you an IP address of 203.0.113.0/27 and informs you that your default gateway is 203.0.113.1. You configure destination NAT to your internal server, but the requests sent to the webserver at 203.0.113.5 are not arriving at the server.

In this scenario, which two configuration features need to be added? (Choose two.)

firewall filter
firewall filter
security policy
security policy
proxy-ARP
proxy-ARP
UTM policy
UTM policy
Suggested answer: B, C
asked 18/09/2024
Barret Tan
29 questions

Question 20

Report Export Collapse

Click the Exhibit button.

Juniper JN0-231 image Question 20 50275 09182024211116000000

Referring to the exhibit, which two statements are correct about the ping command? (Choose two.)

The DMZ routing-instance is the source.
The DMZ routing-instance is the source.
The 10.10.102.10 IP address is the source.
The 10.10.102.10 IP address is the source.
The 10.10.102.10 IP address is the destination.
The 10.10.102.10 IP address is the destination.
The DMZ routing-instance is the destination.
The DMZ routing-instance is the destination.
Suggested answer: A, C
asked 18/09/2024
Nito Nobel
49 questions
Total 105 questions
Go to page: of 11
Search