[Oct 15, 2021] New 2021 Juniper JN0-230 Exam Dumps with PDF from Easy4Engine (Updated 85 Questions) [Q43-Q68]

Share

New 2021 JN0-230 exam questions Welcome to download the newest Easy4Engine JN0-230 PDF dumps (85  Q&As)

P.S. Free 2021 JNCIA-SEC JN0-230  dumps are available on Google Drive shared by Easy4Engine

NEW QUESTION 43
The Sky ATP premium or basic-Threat Feed license is needed fort which two features? (Choose two.)

  • A. Outbound protection
  • B. Executable inspection
  • C. C&C feeds
  • D. Custom feeds

Answer: C,D

 

NEW QUESTION 44
Which two elements are needed on an SRX Series device to set up a remote syslog server? (Choose two.)

  • A. Data size
  • B. IP address
  • C. Data type
  • D. Data throughput

Answer: B,C

 

NEW QUESTION 45
Your company has been assigned one public IP address. You want to enable internet traffic to reach multiple servers in your DMZ that are configured with private address.
In this scenario, which type of NAT would be used to accomplish this tasks?

  • A. Static NAT
  • B. NAT without PAT
  • C. Source NAT
  • D. Destination NAT

Answer: D

 

NEW QUESTION 46
Which statement about IPsec is correct?

  • A. IPsec can provide encryption but not data integrity.
  • B. IPsec support packet fragmentation by intermediary devices.
  • C. IPsec support both tunnel and transport modes.
  • D. IPsec must use certificates to provide data encryption

Answer: C

 

NEW QUESTION 47
Which two actions are performed on an incoming packet matching an existing session? (Choose two.)

  • A. Service ALG processing
  • B. Screens processing
  • C. Zone processing
  • D. Security policy evolution

Answer: B,C

 

NEW QUESTION 48
Which two statements are true about security policies in the factory-default configuration of an SRX340?
(Choose two.)

  • A. All traffic from the untrust zone to the trust zone is denied.
  • B. All traffic from the trust zone to the untrust zone is allowed.
  • C. All interzone traffic is allowed.
  • D. All interzone traffic is denied.

Answer: A,B

 

NEW QUESTION 49
You have created a zone-based security policy that permits traffic to a specific webserver for the marketing team. Other groups in the company are not permitted to access the webserver. When marketing users attempt to access the server they are unable to do so.
What are two reasons for this access failure? (Choose two.)

  • A. You failed to position the policy after the policy that denies access to the webserver.
  • B. You failed to position the policy before the policy that denies access to the webserver.
  • C. You failed to commit the policy change.
  • D. You failed to change the source zone to include any source zone.

Answer: B,C

 

NEW QUESTION 50
Users should not have access to Facebook, however, a recent examination of the logs security show that users are accessing Facebook.
Referring to the exhibit,

what should you do to solve this problem?

  • A. Change the Internet-Access rule from a zone policy to a global policy
  • B. Change the source address for the Block-Facebook-Access rule to the prefix of the users
  • C. Move the Block-Facebook-Access rule before the Internet-Access rule
  • D. Move the Block-Facebook-Access rule from a zone policy to a global policy

Answer: C

 

NEW QUESTION 51
What is the definition of a zone on an SRX Series device?

  • A. a collection of one or more network segments sharing similar security requirements
  • B. an individual logical interface with a public IP address
  • C. a collection of one or more network segments with different security requirements
  • D. an individual logical interface with a private IP address

Answer: A

 

NEW QUESTION 52
What are two characteristic of static NAT SRX Series devices? (Choose two.)

  • A. Source and destination NAT rules take precedence over static NAT rules.
  • B. Static rules cannot coexist with destination NAT rules on the same SRX Series device configuration.
  • C. Static NAT rule take precedence over source and destination NAT rules.
  • D. A reverse mapping rule is automatically created for the source translation.

Answer: C,D

 

NEW QUESTION 53
What is the correct order of processing when configuring NAT rules and security policies?

  • A. destination NAT > policy lookup > source NAT > static NAT
  • B. static NAT > destination NAT > policy lookup > source NAT
  • C. source NAT > static NAT > destination NAT > policy lookup
  • D. policy lookup > source NAT > static NAT > destination NAT

Answer: B

Explanation:
Explanation/Reference:

 

NEW QUESTION 54
Which statement is correct about IKE?

  • A. IKE phase 1 is used to establish the data path
  • B. IKE phase 1 establishes the tunnel between devices
  • C. IKE phase 1 only support aggressive mode.
  • D. IKE phase 1 negotiates a secure channel between gateways.

Answer: D

 

NEW QUESTION 55
Firewall filters define which type of security?

  • A. Stateless
  • B. NGFW
  • C. Stateful
  • D. Dynamic enforcement

Answer: A

 

NEW QUESTION 56
You are designing a new security policy on an SRX Series device. You must block an application silently and log all occurrences of the application access attempts.
In this scenario, which two actions must be enabled in the security policy? (Choose two.)

  • A. Log the session closures.
  • B. Enable a deny action.
  • C. Enable a reject action.
  • D. Log the session initiations.

Answer: B,D

 

NEW QUESTION 57
Referring to the exhibit.
****Exhibit is Missing****
Which type of NAT is performed by the SRX Series device?

  • A. Destination NAT without PAT
  • B. Destination NAT with PAT
  • C. Source NAT with PAT
  • D. Source Nat without PAT

Answer: B

 

NEW QUESTION 58
Which two elements are needed on an SRX Series device to set up a remotesyslogserver? (Choose two.)

  • A. Data size
  • B. Data type
  • C. IP address
  • D. Data throughput

Answer: A,B

 

NEW QUESTION 59
You are concerned that unauthorized traffic is using non-standardized ports on your network.
In this scenario, which type of security feature should you implement?

  • A. Firewall filters
  • B. Sky ATP
  • C. Application firewall
  • D. Zone-based policies

Answer: C

 

NEW QUESTION 60
What is the correct order of processing when configuring NAT rules and security policies?

  • A. Destination NAT > policy lookup > source NAT > static NAT
  • B. Policy lookup > source NAT > static NAT > destination NAT
  • C. Static NAT > destination NAT> policy lookup > source NAT
  • D. Source NAT > static NAT > destination NAT > policy lookup

Answer: C

 

NEW QUESTION 61
Which two statements are true regarding zone-based security policies? (Choose two.)

  • A. Zone-based policies must reference a source address in the match criteria.
  • B. Zone-based policies must reference a destination address in the match criteria
  • C. Zone-based policies must reference a URL category in the match criteria.
  • D. Zone-based policies must reference a dynamic application in the match criteria.

Answer: A,B

 

NEW QUESTION 62
What is the purpose of the Shadow Policies workspace in J-Web?

  • A. The Shadow Policies workspace shows unused IPS policies due to policy overlap.
  • B. The Shadow Policies workspace shows unused security policies due to policy overlap.
  • C. The Shadow Policies workspace shows used security policies due to policy overlap
  • D. The Shadow Policies workspace shows used IPS policies due to policy overlap

Answer: C

 

NEW QUESTION 63
What are the valid actions for a source NAT rule in J-Web? (choose three.)

  • A. Off
  • B. Source
  • C. On
  • D. interface
  • E. Pool

Answer: A,D,E

Explanation:
Explanation
https://www.juniper.net/documentation/en_US/junos/topics/topic-map/nat-security-source-and-source-pool.html

 

NEW QUESTION 64
Which two statements are correct about security zones? (choose two)

  • A. Security zones use security policies that enforce rules for the transit traffic
  • B. Security zones use address books to link username to IP addresses.
  • C. Security zones use a stateful firewall to provide secure network connections
  • D. Security zones use packet filters to prevent communication between management ports

Answer: A,C

 

NEW QUESTION 65
Which three actions would be performed on traffic traversing an IPsec VPAN? (Choosethree.)

  • A. Payload verification
  • B. Encryption
  • C. Authentication
  • D. Port forwarding
  • E. Deep inspection

Answer: A,B,C

 

NEW QUESTION 66
Users in your network are downloading files with file extensions that you consider to be unsafe for your network. You must prevent files with specific file extensions from entering your network.
Which UTM feature should be enable on an SRX Series device to accomplish this task?

  • A. Content filtering
  • B. Antispam
  • C. URL filtering
  • D. Web filtering

Answer: A

 

NEW QUESTION 67
You configure and applied several global policies and some of the policies have overlapping match criteria.

  • A. The least restrictive policy that matches is applied.
  • B. The most restrictive that matches is applied.
  • C. The first matched policy is the only policy applied.
  • D. In this scenario, how are these global policies applies?

Answer: D

 

NEW QUESTION 68
......

JN0-230 exam questions from Easy4Engine dumps: https://www.easy4engine.com/JN0-230-test-engine.html (85  Q&As)