Juniper JN0-231 - Security, Associate (JNCIA-SEC) Exam
Page: 3 / 22
Total 109 questions
Question #11 (Topic: Exam A)
Which statement about global NAT address persistence is correct?
A. The same IP address from a source NAT pool will be assigned for all sessions from a given host.
B. The same IP address from a source NAT pool is not guaranteed to be assigned for all sessions from a given host.
C. The same IP address from a destination NAT pool will be assigned for all sessions for a given host.
D. The same IP address from a destination NAT pool is not guaranteed to be assigned for all sessions for a given host.
Answer: A
Question #12 (Topic: Exam A)
You are asked to configure your SRX Series device to block all traffic from certain countries. The solution must be automatically updated as IP prefixes become allocated to those certain countries.
Which Juniper ATP solution will accomplish this task?
Which Juniper ATP solution will accomplish this task?
A. Geo IP
B. unified security policies
C. IDP
D. C&C feed
Answer: A
Question #13 (Topic: Exam A)
Which two statements are correct about IKE security associations? (Choose two.)
A. IKE security associations are established during IKE Phase 1 negotiations.
B. IKE security associations are unidirectional.
C. IKE security associations are established during IKE Phase 2 negotiations.
D. IKE security associations are bidirectional.
Answer: AD
Question #14 (Topic: Exam A)
You want to deploy a NAT solution.
In this scenario, which solution would provide a static translation without PAT?
In this scenario, which solution would provide a static translation without PAT?
A. interface-based source NAT
B. pool-based NAT with address shifting
C. pool-based NAT with PAT
D. pool-based NAT without PAT
Answer: B
Question #15 (Topic: Exam A)
Which Juniper Networks solution uses static and dynamic analysis to search for day-zero malware threats?
A. firewall filters
B. UTM
C. Juniper ATP Cloud
D. IPS
Answer: C