Practice JNCIA-SEC Junos OS Security Objects questions with full explanations on every answer.
Start practicing
Junos OS Security Objects — choose a session length
Free · No account required
Click any question to see the full explanation and answer options, or start a focused practice session above.
Which statement accurately describes a security zone in Junos OS?
2Which Junos OS CLI command is used to display currently active Application Layer Gateways (ALGs) and their status?
3You need to group multiple IPv4 subnets and range combinations into a single object for use in security policies. Which configuration object should you create?
4You want to configure SCREEN options to detect and block SYN flood attacks on an interface. Which specific SCREEN option parameter should you adjust within the screen profile?
5An administrator creates a global address book and a security zone-specific address book. A host address is defined with the same name in both address books, but with different IP subnets. When a packet originates from that security zone, which address book entry takes precedence?
6An administrator notices that FTP traffic is failing inspection when traversing the SRX device. Upon investigation, it is found that the default ALG for FTP is interfering with non-standard control ports. Where would you modify or disable the FTP ALG in Junos OS?
7You are configuring a security zone and need to apply a SCREEN option to protect against IP spoofing attacks. Under which hierarchy level must you associate the SCREEN option profile in Junos OS?
8An administrator needs to configure a security zone in Junos OS that will contain the management interface for out-of-band access. Which zone type is appropriate for this requirement?
9Which statement is true regarding Junos OS address books?
10When defining a custom application in Junos OS, you specify the protocol as TCP and set a source port range of 1024-65535 and a destination port of 8080. How does Junos evaluate this application in security policies?
11An administrator needs to ensure that packets with source routing options enabled are dropped before they enter the network through the untrusted zone. Which SCREEN option handles this?
12Which command allows you to view the configured security zones and their assigned interfaces in Junos OS?
13You are troubleshooting an issue where TFTP file transfers are failing across an SRX device. Traffic is permitted by security policies. What is the most likely cause of this behavior?
14An administrator configures a security zone and enables the 'tcp-rst' SCREEN option. What is the primary purpose of this SCREEN option?
15Which functional zone in Junos OS is automatically used for traffic that is generated by the SRX device itself, such as routing protocol updates or syslog messages?
16You have configured a custom application object named 'CUSTOM-APP' matching TCP port 9090. When you attempt to commit the configuration, Junos returns an error stating that the application conflicts with a predefined Junos application. How should you resolve this?
17An administrator configures a security zone and applies a SCREEN profile. Under load, legitimate traffic starts getting dropped due to SCREEN option thresholds being exceeded. Which CLI command should the administrator use to view real-time statistics and counters for triggered SCREEN attacks?
18Which statement best describes an Application Layer Gateway (ALG) in Junos OS?
19An enterprise network uses multiple virtual routers. Can security zones span across different virtual routers on the same SRX Series device?
20Which command is used to verify the configuration of address books in Junos OS?
21You are troubleshooting a connectivity issue where SIP VoIP calls are establishing control sessions, but audio streams (RTP) are failing. Which Junos security feature must be properly configured or enabled to resolve this?
22An administrator configures a security zone and adds the 'tcp-drop-synfin-set' SCREEN option. What specific packet characteristic does this option target?
23Which statement is true regarding Junos OS predefined applications?
24Which command displays the configured security policies in Junos OS?
25An administrator creates a security zone and assigns multiple interfaces to it. One of the interfaces is configured with host-inbound-traffic allowed services for SSH. What happens to SSH access to the other interfaces in the same security zone?
26Which type of Junos OS address book entry is available to all security zones on the device without needing to be redefined?
27An administrator notices that FTP data connections are failing when clients behind an SRX device connect to external servers using active FTP mode. Passive FTP works correctly. What is the most likely root cause?
28You want to apply a SCREEN option to protect against ICMP ping floods across all interfaces in a specific security zone. How should you structure this in the CLI?
29You need to inspect traffic matching a proprietary application that uses dynamic TCP ports. You have written a custom application. What additional Junos security feature can be combined with custom applications to inspect deep packet content for non-standard ports?
30You are configuring security zones and need to allow Ping (ICMP echo request) to be processed by the SRX routing engine for troubleshooting. Where do you configure this?
31An administrator configures an address set named 'DMZ-SERVERS' containing three individual IP addresses. Later, one of those IP addresses is removed from the base address book. What happens to the 'DMZ-SERVERS' address set configuration?
32An administrator configures a security zone and enables traceoptions for security flow. Where are these traceoptions configured in the Junos OS hierarchy?
33Which Junos OS feature inspects packet headers for layer 3 and layer 4 denial-of-service (DoS) attacks such as SYN floods, IP spoofing, and LAND attacks?
34You need to create a custom application in Junos OS that matches HTTP traffic running on non-standard port 8080. How should you define this application?
35You are configuring host-inbound traffic for a security zone and want to allow SNMP polling from a monitoring server. Which option under host-inbound-traffic system-services should you enable?
36Which command is used to display active security sessions currently tracked by the Junos OS flow module?
37An administrator creates a security zone and defines both a zone-specific address book and a global address book. The same address name exists in both address books with conflicting subnets. When a security policy references this address name from a different security zone, which address definition is selected?
38Which statement correctly identifies the purpose of Junos OS functional zones?
39You need to apply a screen profile that detects IP address spoofing where the source IP address belongs to the local subnet of the ingress interface. Which screen option addresses this?
40Which Junos command displays the operational status of all SCREEN options and their associated counters across security zones?
41An administrator configures an application set in Junos OS. What is the primary function of an application set?
42You want to configure a security zone to automatically reject new TCP connections with a TCP RST packet when the zone's transit sessions exceed capacity or policies deny them. Where is this behavior configured?
43Which command is used to view the list of all predefined Junos OS application objects?
44You are configuring an SRX Series device and want to ensure that all traffic entering the untrusted zone is checked for LAND attacks. Which configuration steps are required?
45An administrator configures an address book with an address object using the DNS name of a remote server instead of an IP address. How does Junos OS handle DNS-based address objects in security policies?
46An administrator configures an address set that includes another address set as a member (nested address sets). What is the maximum nesting depth supported for address sets in Junos OS?
47Which command displays the configured functional zones in Junos OS?
48Which statement is true regarding the default security zone behavior in Junos OS?
49An administrator configures a security zone and enables traceoptions for zone management. What is the correct configuration hierarchy to enable traceoptions for security zones?
50You need to modify the default session timeout for a specific custom application in Junos OS. Where is application timeout configured?
51You want to create a security zone and explicitly block all traffic between interfaces assigned to that same zone (intra-zone traffic). Which configuration statement accomplishes this?
52An administrator configures an address book containing an IPv6 address prefix. How does Junos OS handle IPv6 addresses in security policies compared to IPv4?
53Which Junos OS feature allows an administrator to define a collection of applications that should be treated as a single unit in security policies?
54Which statement is true regarding Junos OS security zone interfaces?
55An administrator configures a security zone and applies a SCREEN profile that includes 'limit-session source-ip'. What is the function of this specific SCREEN option?
56You are troubleshooting an issue where an ALG is altering port numbers during FTP sessions, causing authentication failures with an application-layer proxy. Which command shows active ALG sessions and their port translations?
57Which Junos OS command displays the configuration of all security zones?
58You need to configure a custom application that matches UDP traffic on a range of destination ports from 5000 to 5010. How should you specify this range in the application configuration?
59An administrator configures a security zone and enables the 'udp-flood' SCREEN option with a specified threshold. How does Junos measure UDP flood attacks for this option?
60You want to create an address set that combines two address sets and one individual IP address object. Is this supported in Junos OS?
61Which Junos OS feature is responsible for translating port numbers for protocols like FTP during transit across security zones?
62An administrator configures a security zone and enables traceoptions for SCREEN option processing. Where are SCREEN traceoptions configured?
63Which command is used to display the currently configured global address books in Junos OS?
64You are troubleshooting an issue where an application defined with a specific timeout is timing out prematurely during periods of inactivity. Where would you verify or adjust the flow session timeout globally in Junos OS?
65An administrator configures a security zone and enables the 'icmp all' SCREEN option with threshold parameters. What does the 'icmp all' option encompass?
66You want to create a security zone that permits all host-inbound traffic for system services and protocols without manually listing every service. Is there a wildcard or all-inclusive keyword for host-inbound-traffic in Junos OS?
67An administrator configures a security zone and enables the 'icmp timestamp' SCREEN option. What is the purpose of this option?
68Which TWO methods can be used to define IP addresses in Junos OS address books? (Choose two)
69Which TWO statements are correct regarding Junos OS security zones? (Choose two)
70Which THREE components can be grouped within a Junos OS address set? (Choose three)
71Which TWO actions occur when an Application Layer Gateway (ALG) inspects traffic in Junos OS? (Choose two)
72Which TWO functional zones are built-in and available by default in Junos OS? (Choose two)
73Which THREE types of attacks are mitigated by Junos OS SCREEN options? (Choose three)
74Which TWO statements are true regarding Junos OS global address books versus zone-specific address books? (Choose two)
75Which TWO objects can be referenced inside a Junos OS security policy? (Choose two)
76Which THREE services can be enabled under host-inbound-traffic system-services in Junos OS security zones? (Choose three)
77Which TWO commands are valid operational mode commands in Junos OS for security objects? (Choose two)
78Which TWO characteristics apply to custom applications created in Junos OS? (Choose two)
79Which TWO statements are accurate regarding the evaluation order of address books in Junos OS? (Choose two)
80Which THREE protocols typically require Application Layer Gateways (ALGs) in Junos OS to function correctly across security policies? (Choose three)
81Which THREE parameters can be configured within a custom application definition in Junos OS? (Choose three)
82Which TWO features or options are associated with Junos OS SCREEN option profiles? (Choose two)
83Which TWO statements describe the behavior of Junos OS Application Layer Gateways (ALGs)? (Choose two)
84Which TWO statements are true regarding Junos OS security policies and address books? (Choose two)
85Which THREE settings can be configured under a security zone in Junos OS? (Choose three)
86Which TWO traffic types are typically handled by functional zones in Junos OS? (Choose two)
87Which THREE security features are configured under the [edit security] hierarchy in Junos OS? (Choose three)
88Which TWO statements are true regarding Junos OS address sets and their usage in security policies? (Choose two)
The Junos OS Security Objects domain covers the key concepts tested in this area of the JNCIA-SEC exam blueprint published by Juniper Networks. Courseiva provides free domain-focused practice, mock exams, missed-question review, and readiness tracking across all JNCIA-SEC domains — no account required.
The Courseiva JNCIA-SEC question bank contains 88 questions in the Junos OS Security Objects domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Junos OS Security Objects domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included