JN0-232 Security, Associate (JNCIA-SEC) Questions and Answers
Which two characteristics of destination NAT and static NAT are correct? (Choose two.)
What is the purpose of assigning logical interfaces to separate security zones in Junos OS?
When a new traffic flow enters an SRX Series device, in which order are these processes performed?
When traffic enters an interface, which two results does a route lookup determine? (Choose two.)
What are two system-defined zones created on the SRX Series Firewalls? (Choose two.)
You are troubleshooting first path traffic not passing through an SRX Series Firewall. You have determined that the traffic is ingressing and egressing the correct interfaces using a route lookup.
In this scenario, what is the next step in troubleshooting why the device may be dropping the traffic?
What happens if no match is found in both zone-based and global security policies?
Which two statements about the host-inbound-traffic parameter in a zone configuration are correct? (Choose two.)
You are troubleshooting traffic traversing the SRX Series Firewall and require detailed information showing how the flow module is handling the traffic.
How would you accomplish this task?
You are asked to enable trace options to debug the packet flow.
In this scenario, which flag would you configure at the [edit security flow traceoptions] hierarchy?
You have created a series of security policies permitting access to a variety of services. You now want to create a policy that blocks access to all other services for all user groups.
What should you create in this scenario?
