Security, Associate (JNCIA-SEC)
JN0-231 Exam

Which two statements are correct about IKE security associations? (Choose two.)

  1. IKE security associations are established during IKE Phase 1 negotiations.
  2. IKE security associations are unidirectional.
  3. IKE security associations are established during IKE Phase 2 negotiations.
  4. IKE security associations are bidirectional.

Answer(s): A,D



You want to deploy a NAT solution.
In this scenario, which solution would provide a static translation without PAT?

  1. interface-based source NAT
  2. pool-based NAT with address shifting
  3. pool-based NAT with PAT
  4. pool-based NAT without PAT

Answer(s): B

Explanation:

Translation of the original source IP address to an IP address from a user-defined address pool by shifting the IP addresses. This type of translation is one-to-one, static, and without port address translation. If the original source IP address range is larger than the IP address range in the user- defined pool, untranslated packets are dropped.
https://www.juniper.net/documentation/us/en/software/junos/nat/topics/topic-map/nat-security- source-and-source-pool.html



Which Juniper Networks solution uses static and dynamic analysis to search for day-zero malware threats?

  1. firewall filters
  2. UTM
  3. Juniper ATP Cloud
  4. IPS

Answer(s): C

Explanation:

Malware Sandboxing
Detect and stop zero-day and commodity malware within web, email, data center, and application traffic targeted for Windows, Mac, and IoT devices.
https://www.juniper.net/us/en/products/security/advanced-threat-prevention.html



You are configuring an SRX Series device. You have a set of servers inside your private network that need one-to-one mappings to public IP addresses.
Which NAT configuration is appropriate in this scenario?

  1. source NAT with PAT
  2. destination NAT
  3. NAT-T
  4. static NAT

Answer(s): D

Explanation:

https://www.juniper.net/documentation/en_US/day-one-books/nat-and-pat-en.html And the specific text that would support the above answer is as follows: "Static NAT, which requires manual configuration, is often the most appropriate configuration for mapping one internal address to one external address."




MD. MAZBAHUL KARIM
This is a superb site for practice.
- Anonymous
Upvote


MD. MAZBAHUL KARIM
This is a superb site for quality exam, I really appreciate this site.
- Anonymous
Upvote


PJT
Need for preparing to Certification exam
- Anonymous
Upvote


Mohan Krishna, arevrapu
I need it please sent asap in 2 days
- INDIA
Upvote


Dan
Ans to 355 is wrong, pls have a certified to work on the answers again pls
- Anonymous
Upvote


dnllin
366 Ans Hypervisor-level software patching is wrong, should be B - Customers are responsible for managing their data (including encryption options) Why there are so many wrong answers?
- UNITED STATES
Upvote


dnllin
Q342: Which AWS service or feature for technical assistance is available to a user who has the AWS Basic Support plan? - Ans AWS senior support engineers is wrong. Should be D. Basic Support offers support for account and billing questions and service quota increases. The other plans offer a number of technical support cases with pay-by-the-month pricing and no long-term contracts.
- UNITED STATES
Upvote


Dnllin
Which AWS services or features enable users to connect on-premises networks to a VPC? (Choose two.) Answer(s): A,D. D (VPC peering) is wrong. C is correct - AWS Direct Connect. Using AWS Direct Connect, you can establish private connectivity between AWS and your datacenter, office,
- UNITED STATES
Upvote


Lin Tzu
QUESTION: 154 - answer (D) - Transit gateway is wrong, should be C & E. Below are the components of the site to site VPN: Customer Gateway: A customer gateway is a physical device or software application on your side of the Site-to-Site VPN connection. Virtual Private Gateway: A virtual private gateway is the VPN concentrator on the AWS side of the Site-to-Site VPN connection. You create a virtual private gateway and attach it to the VPC from which you want to create the Site-to-Site VPN connection.
- Anonymous
Upvote


saritha
I have passed the exam thankyou
- UNITED STATES
Upvote

Read more ...