Go to JN0-230 Questions - Try JN0-230 dumps pdf [Q28-Q45]

Share

Go to JN0-230 Questions - Try JN0-230 dumps pdf

Dumps Practice Exam Questions Study Guide for the JN0-230 Exam

NEW QUESTION 28
What must you do first to use the Monitor/Events workspace in the j-Web interface?

  • A. You must enable security logging that uses the SD-Syslog format.
  • B. You must enable security logging that uses the TLS transport mode.
  • C. You must enable event mode security logging on the SRX Series device.
  • D. You must enable stream mode security logging on the SRX Series device

Answer: A

 

NEW QUESTION 29
You have created a zones-based security policy that permits traffic to a specific webserver for the marketing team. Other groups in the company are not permitted to access the webserver. When marketing users attempt to access the server they are unable to do so.
What are two reasons for this access failure? (Choose two.)

  • A. You failed to change the source zone to include any source zone.
  • B. You failed to commit the policy change.
  • C. You failed to position the policy before the policy that denies access the webserver
  • D. You failed to position the policy after the policy that denies access to the webserver.

Answer: B,C

 

NEW QUESTION 30
Which security feature is applied to traffic on an SRX Series device when the device is running n packet mode?

  • A. ALGs
  • B. Unified policies
  • C. Sky ATP
  • D. Firewall filters

Answer: D

 

NEW QUESTION 31
On an SRX Series device, how should you configure your IKE gateway if the remote endpoint is a branch office-using a dynamicIP address?

  • A. Configure the IKE policy to use a static IP address
  • B. Configure the IPsec policy to use MDS authentication.
  • C. Configure the IPsec policy to use aggressive mode.
  • D. Configure the IKE policy to use aggressive mode.

Answer: B

 

NEW QUESTION 32
Which zone is considered a functional zone?

  • A. Trust
  • B. Management
  • C. Junos host
  • D. Null

Answer: B

 

NEW QUESTION 33
Which UTM feature should you use to protect users from visiting certain blacklisted websites?

  • A. Antivirus
  • B. antispam
  • C. Content filtering
  • D. Web filtering

Answer: A

 

NEW QUESTION 34
Which type of security policy protect restricted services from running on non-standard ports?

  • A. Application firewall
  • B. IDP
  • C. Sky ATP
  • D. antivirus

Answer: B

 

NEW QUESTION 35
Which two private cloud solution support vSRX devices? (Choose two.)

  • A. VMware Web Services (AWS)
  • B. VMware NSX
  • C. Contrail Cloud
  • D. Microsoft Azure
  • E. Amazon Web Services (AWS)

Answer: D,E

 

NEW QUESTION 36
Which method do VPNs use to prevent outside parties from viewing packet in clear text?

  • A. Authentication
  • B. NAT_T
  • C. Encryption
  • D. Integrity

Answer: C

 

NEW QUESTION 37
Which actions would be applied for the pre-IDdefault policy unified policies?

  • A. Redirect the session
  • B. Reject the session
  • C. Silently drop the session
  • D. Log the session

Answer: A

 

NEW QUESTION 38
Which statement is correct about IKE?

  • A. IKE phase 1 establishes the tunnel between devices
  • B. IKE phase 1 is used to establish the data path
  • C. IKE phase 1 negotiates a secure channel between gateways.
  • D. IKE phase 1 only support aggressive mode.

Answer: C

 

NEW QUESTION 39
You have configured antispam to allow e-mail from example.com, however the logs you see [email protected] blocked Referring to the exhibit.

What are two ways to solve this problem?

Answer: B,D

 

NEW QUESTION 40
You are concerned that unauthorized traffic is using non-standardized ports on your network.
In this scenario, which type of security feature should you implement?

  • A. Application firewall
  • B. Firewall filters
  • C. Sky ATP
  • D. Zone-based policies

Answer: A

 

NEW QUESTION 41
Click the Exhibit button.

You have configured source NAT using an address pool as shown in the exhibit. Traffic is reaching the
203.0.113.6 server but return traffic is not being received by the SRX Series device.
Which feature must be configured to allow return traffic to be accepted by the SRX Series device?

  • A. destination NAT
  • B. port forwarding
  • C. reverse static NAT
  • D. proxy ARP

Answer: A

 

NEW QUESTION 42
When configuring IPsec VPNs, setting a hash algorithm solves which security concern?

  • A. Integrity
  • B. Encryption
  • C. Redundancy
  • D. Availability

Answer: A

 

NEW QUESTION 43
Host-inbound-traffic is configured on the DMZ zone and the ge-0/0/9.0 interface attached to that zone.
Referring to the exhibit,

which to types of management traffic would be performed on the SRX Series device? (Choose two.)

  • A. Finger
  • B. SSH
  • C. HTTP
  • D. HTTPS

Answer: B,C

 

NEW QUESTION 44
Exhibit.

Which two statements are true? (Choose two.)

  • A. Logs for this security policy are not generated.
  • B. Logs for this security policy are generated.
  • C. Traffic statistics for this security policy are generated.
  • D. Traffic static for this security policy are not generated.

Answer: B,D

 

NEW QUESTION 45
......


Who should take the JN0-362 exam

This exam is intended for learners who are pursuing routing and switching technologies and related platform configuration and troubleshooting skills.

 

Free JNCIA-SEC JN0-230 Exam Question: https://prepaway.updatedumps.com/Juniper/JN0-230-updated-exam-dumps.html