更新された2024年02月テストエンジンに練習JN0-231テスト問題
JN0-231リアル試験問題テストエンジン問題集トレーニングには103問あります
質問 # 34
Which two match conditions would be used in both static NAT and destination NAT rule sets? (Choose two.)
- A. Destination zone
- B. Destination interface
- C. Source zone
- D. Source interface
正解:B、C
質問 # 35
Which three actions would be performed on traffic traversing an IPsec VPAN? (Choose three.)
- A. Authentication
- B. Encryption
- C. Port forwarding
- D. Payload verification
- E. Deep inspection
正解:A、B、D
質問 # 36
Click the Exhibit button
You have configured source ... Being received By the SRX series Which features must be configured
- A. Reverse static NAT
- B. Proxy ARP
- C. Port Forwarding
- D. Destination NAT
正解:B
質問 # 37
Which two statements are correct about the null zone on an SRX Series device? (Choose two.)
- A. The null zone is a functional security zone.
- B. You must enable the null zone before you can place interfaces into it.
- C. The null zone is created by default.
- D. Traffic sent or received by an interface in the null zone is discarded.
正解:C、D
解説:
According to the Juniper SRX Series Services Guide, the null zone is a predefined security zone that is created on the SRX Series device when it is booted. Traffic that is sent to or received on an interface in the null zone is discarded. The null zone is not a functional security zone, so you cannot enable or disable it.
質問 # 38
Which statement is correct about Junos security policies?
- A. Security policies control the flow of internal traffic within an SRX Series device.
- B. Security policies determine which users are allowed to access an SRX Series device.
- C. Security policies enforce rules that should be applied to traffic transiting an SRX Series device.
- D. Security policies identity groups of users that have access to different features on an SRX Series device.
正解:C
解説:
The correct statement about Junos security policies is that they enforce rules that should be applied to traffic transiting an SRX Series device. Security policies control the flow of traffic between different zones on the SRX Series device, and dictate which traffic is allowed or denied. They can also specify which application and service requests are allowed or blocked. More information about Junos security policies can be found in the Juniper Networks technical documentation here: https://www.juniper.net/documentation/en_US/junos/topics/task/configuration/security-policies-overview.html.
質問 # 39
Which security feature is applied to traffic on an SRX Series device when the device is running n packet mode?
- A. Sky ATP
- B. ALGs
- C. Firewall filters
- D. Unified policies
正解:C
質問 # 40
You want to enable the minimum Juniper ATP services on a branch SRX Series device.
In this scenario, what are two requirements to accomplish this task? (Choose two.)
- A. Execute the Juniper ATP script on the branch device.
- B. Register for a Juniper ATP account on https://sky.junipersecurity.net.
- C. Configure the juniper-atp user account on the branch device.
- D. Install a basic Juniper ATP license on the branch device.
正解:B、D
質問 # 41
Referring to the exhibit.
Users should not have access to Facebook, however, a recent examination of the logs security show that users are accessing Facebook.
what should you do to solve this problem?
- A. Change the Internet-Access rule from a zone policy to a global policy
- B. Change the source address for the Block-Facebook-Access rule to the prefix of the users
- C. Move the Block-Facebook-Access rule before the Internet-Access rule
- D. Move the Block-Facebook-Access rule from a zone policy to a global policy
正解:C
質問 # 42
Which two IKE Phase 1 configuration options must match on both peers to successfully establish a tunnel? (Choose two.)
- A. IKE mode
- B. Diffie-Hellman group
- C. gateway interfaces
- D. VPN name
正解:A、B
質問 # 43
Click the Exhibit button.
What is the purpose of the host-inbound-traffic configuration shown in the exhibit?
- A. to deny and log all host inbound traffic on the internal security zone, except for HTTP traffic
- B. to permit host inbound HTTP traffic and deny all other traffic on the internal security zone
- C. to permit all host inbound traffic on the internal security zone, but deny HTTP traffic
- D. to permit host inbound HTTP traffic on the internal security zone
正解:C
質問 # 44
Which two elements are needed on an SRX Series device to set up a remote syslog server? (Choose two.)
- A. Data throughput
- B. Data size
- C. Data type
- D. IP address
正解:C、D
質問 # 45
Which two statements are correct about IKE security associations? (Choose two.)
- A. IKE security associations are bidirectional.
- B. IKE security associations are unidirectional.
- C. IKE security associations are established during IKE Phase 1 negotiations.
- D. IKE security associations are established during IKE Phase 2 negotiations.
正解:A、C
質問 # 46
Which method do VPNs use to prevent outside parties from viewing packet in clear text?
- A. Authentication
- B. Encryption
- C. NAT_T
- D. Integrity
正解:B
質問 # 47
Which three operating systems are supported for installing and running Juniper Secure Connect client software? (Choose three.)
- A. Android
- B. Windows 7
- C. macOS
- D. Windows 10
- E. Linux
正解:B、C、D
解説:
Juniper Secure Connect client software is supported on the following three operating systems: Windows 7, Windows 10, and macOS. For more information, please refer to the Juniper Secure Connect Administrator Guide, which can be found on Juniper's website. The guide states: "The Juniper Secure Connect client is supported on Windows 7, Windows 10, and macOS." It also provides detailed instructions on how to install and configure the software for each of these operating systems.
質問 # 48
Which source NAT rule set would be used when a packet matches the conditions in multiple rule sets?
- A. The most specific rule set will be used
- B. The least specific rule set will be used
- C. The last rule set matched will be used
- D. The first rule set matched will be used
正解:D
質問 # 49
Referring to the exhibit.
Users should not have access to Facebook, however, a recent examination of the logs security show that users are accessing Facebook.
what should you do to solve this problem?
- A. Change the Internet-Access rule from a zone policy to a global policy
- B. Change the source address for the Block-Facebook-Access rule to the prefix of the users
- C. Move the Block-Facebook-Access rule before the Internet-Access rule
- D. Move the Block-Facebook-Access rule from a zone policy to a global policy
正解:C
質問 # 50
What should you configure if you want to translate private source IP address to a single public IP address?
- A. Content filtering
- B. Source NAT
- C. Security Director
- D. Destination NAT
正解:B
質問 # 51
......
JN0-231実際の問題解答PDFには100%カバー率リアル試験問題:https://jp.fast2test.com/JN0-231-premium-file.html
JN0-231試験問題解答:https://drive.google.com/open?id=1asCq9g4-9KHBBg3PtqnV--Y9gmUfEddk