JN0-231別格な問題集をダウンロードして無料で最新の(JN0-231テスト問題集をゲット2024年04月08日)
JN0-231問題集は合格保証します合格できるJN0-231試験問題2024年更新
質問 # 35
What is a type of security feed that Sky ATP provides to a vSRX series device by default?
- A. Malware feeds
- B. ACL feeds
- C. RSS feeds
- D. C&C feeds
正解:D
質問 # 36
Which statement about NAT is correct?
- A. Destination NAT takes precedence over static NAT.
- B. Source NAT is processed before security policy lookup.
- C. Static NAT is processed after forwarding lookup.
- D. Static NAT takes precedence over destination NAT.
正解:D
質問 # 37
Firewall filters define which type of security?
- A. NGFW
- B. Stateful
- C. Dynamic enforcement
- D. Stateless
正解:D
質問 # 38
You verify that the SSH service is configured correctly on your SRX Series device, yet administrators attempting to connect through a revenue port are not able to connect.
In this scenario, what must be configured to solve this problem?
- A. An MTU value target than the default value
- B. A screen on the internal interface
- C. A security policy allowing SSH traffic.
- D. A host-inbound-traffic setting on the incoming zone
正解:D
質問 # 39
You are configuring an IPsec VPN tunnel between two location on your network. Each packet must be encrypted and authenticated.
Which protocol would satisfy these requirements?
- A. SHA
- B. AH
- C. MD5
- D. ESP
正解:D
質問 # 40
You are asked to configure your SRX Series device to block all traffic from certain countries. The solution must be automatically updated as IP prefixes become allocated to those certain countries.
Which Juniper ATP solution will accomplish this task?
- A. IDP
- B. Geo IP
- C. C&C feed
- D. unified security policies
正解:B
質問 # 41
Referring to the exhibit.
You have configured antispam to allow e-mail from example.com, however the logs you see that [email protected] is blocked What are two ways to solve this problem?
- A. Delete [email protected] from the profile antispam address whitelist
- B. Delete [email protected] from the profile antispam address blacklist
- C. Verify connectivity with the SBL server.
- D. Add [email protected] to the profile antispam address whitelist.
正解:B、D
質問 # 42
Click the Exhibit button.
Referring to the exhibit, a user is placed in which hierarchy when the exit command is run?
- A. [edit]
user@vSRX-1# - B. [edit security policies]
user@vSRX-1# - C. [edit security policies from-zone trust to-zone dmz]
user@vSRX-1# - D. user@vSRX-1>
正解:B
質問 # 43
Which order is correct for Junos security devices that examine policies for transit traffic?
- A. default policies
global policies
zone policies - B. default policies
zone policies
global policies - C. global policies
zone policies
default policies - D. zone policies
global policies
default policies
正解:D
質問 # 44
Click the Exhibit button.
You are asked to allow only ping and SSH access to the security policies shown in the exhibit.
Which statement will accomplish this task?
- A. Insert policy Rule-2 before policy Rule-1.
- B. Rename policy Rule-1 to policy Rule-3.
- C. Replace application any with application [junos-ping junos-ssh] in policy Rule-1.
- D. Rename policy Rule-2 to policy Rule-0.
正解:A
質問 # 45
What is the order of the first path packet processing when a packet enters a device?
- A. screens -> security policies -> zones
- B. screens -> zones -> security policies
- C. security policies -> screens -> zones
- D. security policies -> zones -> screens
正解:B
質問 # 46
Referring to the exhibit.
Users should not have access to Facebook, however, a recent examination of the logs security show that users are accessing Facebook.
what should you do to solve this problem?
- A. Move the Block-Facebook-Access rule from a zone policy to a global policy
- B. Change the Internet-Access rule from a zone policy to a global policy
- C. Change the source address for the Block-Facebook-Access rule to the prefix of the users
- D. Move the Block-Facebook-Access rule before the Internet-Access rule
正解:D
質問 # 47
Which two statements are correct about the null zone on an SRX Series device? (Choose two.)
- A. Traffic sent or received by an interface in the null zone is discarded.
- B. The null zone is created by default.
- C. You must enable the null zone before you can place interfaces into it.
- D. The null zone is a functional security zone.
正解:A、B
解説:
According to the Juniper SRX Series Services Guide, the null zone is a predefined security zone that is created on the SRX Series device when it is booted. Traffic that is sent to or received on an interface in the null zone is discarded. The null zone is not a functional security zone, so you cannot enable or disable it.
質問 # 48
When configuring IPsec VPNs, setting a hash algorithm solves which security concern?
- A. Integrity
- B. Redundancy
- C. Availability
- D. Encryption
正解:A
質問 # 49
Which two statements about user-defined security zones are correct? (Choose two.)
- A. Users can share security zones between routing instances.
- B. Users cannot share security zones between routing instances.
- C. User-defined security zones do not apply to transit traffic.
- D. Users can configure multiple security zones.
正解:A、D
解説:
User-defined security zones allow users to configure multiple security zones and share them between routing instances. This allows users to easily manage multiple security zones and their associated policies. For example, a user can create a security zone for corporate traffic, a security zone for guest traffic, and a security zone for public traffic, and then configure policies to control the flow of traffic between each of these security zones. Transit traffic can also be managed using user-defined security zones, as the policies applied to these zones will be applied to the transit traffic as well.
質問 # 50
You need to collect the serial number of an SRX Series device to replace it. Which command will accomplish this task?
- A. show chassis hardware
- B. show chassis firmware
- C. show system information
- D. show chassis environment
正解:A
解説:
The correct command to collect the serial number of an SRX Series device is the show chassis hardware command [1]. This command will return the serial number of the device, along with other information about the device such as the model number, part number, and version.
This command is available in Junos OS. More information about the show chassis hardware command can be found in the Juniper Networks technical documentation here [1]: https://www.juniper.net/documentation/en_US/junos/topics/reference/command-summary/show-chassis-hardware.html.
質問 # 51
Referring to the exhibit.
Host-inbound-traffic is configured on the DMZ zone and the ge-0/0/9.0 interface attached to that zone.
Which to types of management traffic would be performed on the SRX Series device? (Choose two.)
- A. Finger
- B. HTTP
- C. SSH
- D. HTTPS
正解:B、C
質問 # 52
What is the behavior of an SRX series device when UDP and TCP is rejected by a security policy actions? (choose two)
- A. The reject action drops UDP packets and does not send ant message to the source
- B. The reject action drops TCP packets and send an RST message to the source.
- C. The reject action drops UDP packets and sends an ICMP message to the source
- D. The reject actions drops TCP packets and sends an ICMP message to the source
正解:B、C
質問 # 53
......
検証済みのJN0-231問題集で問題と解答で合格保証試験問題集テストエンジン:https://jp.fast2test.com/JN0-231-premium-file.html
検証済みのJN0-231問題集103格別な問題:https://drive.google.com/open?id=1asCq9g4-9KHBBg3PtqnV--Y9gmUfEddk