Free JN0-231 Exam Braindumps (page: 5)

Page 4 of 26

Which two statements are correct about IKE security associations? (Choose two.)

  1. IKE security associations are established during IKE Phase 1 negotiations.
  2. IKE security associations are unidirectional.
  3. IKE security associations are established during IKE Phase 2 negotiations.
  4. IKE security associations are bidirectional.

Answer(s): A,D



You want to deploy a NAT solution.
In this scenario, which solution would provide a static translation without PAT?

  1. interface-based source NAT
  2. pool-based NAT with address shifting
  3. pool-based NAT with PAT
  4. pool-based NAT without PAT

Answer(s): B

Explanation:

Translation of the original source IP address to an IP address from a user-defined address pool by shifting the IP addresses. This type of translation is one-to-one, static, and without port address translation. If the original source IP address range is larger than the IP address range in the user- defined pool, untranslated packets are dropped.
https://www.juniper.net/documentation/us/en/software/junos/nat/topics/topic-map/nat-security- source-and-source-pool.html



Which Juniper Networks solution uses static and dynamic analysis to search for day-zero malware threats?

  1. firewall filters
  2. UTM
  3. Juniper ATP Cloud
  4. IPS

Answer(s): C

Explanation:

Malware Sandboxing
Detect and stop zero-day and commodity malware within web, email, data center, and application traffic targeted for Windows, Mac, and IoT devices.
https://www.juniper.net/us/en/products/security/advanced-threat-prevention.html



You are configuring an SRX Series device. You have a set of servers inside your private network that need one-to-one mappings to public IP addresses.
Which NAT configuration is appropriate in this scenario?

  1. source NAT with PAT
  2. destination NAT
  3. NAT-T
  4. static NAT

Answer(s): D

Explanation:

https://www.juniper.net/documentation/en_US/day-one-books/nat-and-pat-en.html And the specific text that would support the above answer is as follows: "Static NAT, which requires manual configuration, is often the most appropriate configuration for mapping one internal address to one external address."






Post your Comments and Discuss Juniper JN0-231 exam with other Community members:

JN0-231 Discussions & Posts