Courseiva

CCNA Content Security Questions

75 of 85 questions · Page 1/2 · Content Security · Answers revealed

1
Multi-Selecthard

Which THREE parameters can be configured when tuning an Antivirus profile in Junos OS UTM? (Choose three.)

Select 3 answers
A.Action upon virus detection (e.g., block or permit)
B.Protocol-specific sub-profiles (HTTP, FTP, SMTP, etc.)
C.Maximum file size inspection limit
D.URL rating server timeout threshold
E.DNSBL blacklist server domain
AnswersA, B, C

Action defines what happens when malware is found.

Why this answer

Antivirus profiles allow tuning options such as inspection protocols, action upon virus detection, and maximum file size limits.

2
Multi-Selecthard

Which THREE parameters can be configured under a Content Filtering profile to inspect incoming HTTP payloads? (Choose three.)

Select 3 answers
A.File extension block list
B.DNSBL blacklist server configuration
C.MIME type block list
D.URL category rating database
E.Custom string pattern matching
AnswersA, C, E

File extensions specify blocked filename suffixes.

Why this answer

Content filtering profiles inspect HTTP traffic using MIME type lists, file extension lists, and custom string matching.

3
Multi-Selectmedium

Which TWO methods can be used to check the operational health and status of the UTM engines on a Juniper SRX Series device? (Choose two.)

Select 2 answers
A.The 'show chassis cluster status' command.
B.The 'show interfaces terse' command.
C.The 'show security utm web-filtering status' command.
D.The 'show security utm status' command.
E.The 'show system routing-table' command.
AnswersC, D

This command checks web filtering connectivity and engine health.

Why this answer

Operational commands starting with 'show security utm ...' display engine status and health information.

4
Multi-Selecthard

Which THREE parameters are typically required when defining a custom URL pattern object for use in web filtering overrides? (Choose three.)

Select 3 answers
A.Matching type (such as exact, prefix, or suffix)
B.SSL private key password
C.URL pattern string or regular expression
D.Action (such as permit or block)
E.DNSBL server IP address
AnswersA, C, D

Matching type dictates how the pattern string is evaluated against traffic.

Why this answer

Custom URL patterns in Junos UTM allow specifying matching criteria such as URL strings, matching types, and actions.

5
MCQeasy

Which UTM feature on Juniper SRX Series firewalls is designed to prevent malware and viruses from entering the network via HTTP or SMTP streams?

A.Antispam
B.Antivirus
C.Web Filtering
D.Content Filtering
AnswerB

Antivirus inspects streams for malware signatures.

Why this answer

Antivirus is the UTM feature designed to detect and block malware and viruses.

6
Multi-Selecthard

An administrator is troubleshooting an antivirus profile on an SRX Series device where certain archive files (.zip) containing test malware are bypassing inspection. Which THREE configuration elements or factors should the administrator verify? (Choose three.)

Select 3 answers
A.Ensure the AppID service object is explicitly disabled for all antivirus inspection policies.
B.Confirm whether password-protected or encrypted archives are configured to be blocked or bypassed.
C.Check if the file size exceeds the configured max-file-size limit for antivirus inspection.
D.Verify whether archive-depth is set too low to inspect nested compressed files.
E.Verify that the antispam whitelist contains the specific MIME type of the .zip file.
AnswersB, C, D

Encrypted archives cannot be scanned by default, and policies dictate whether they are blocked or permitted.

Why this answer

When archives bypass antivirus inspection, it is often due to archive nesting depth limits, encrypted/password-protected archives exceeding inspection capabilities, or file size limits configured in the UTM profile that cause large files to be skipped.

7
Multi-Selecthard

Which THREE parameters can be configured when setting up a custom URL category in Junos OS UTM? (Choose three.)

Select 3 answers
A.Matching type (such as exact, prefix, or suffix)
B.DNSBL server IP addresses
C.Antivirus signature database version
D.Custom category name
E.URL pattern strings or regular expressions
AnswersA, D, E

Matching type controls how patterns are evaluated.

Why this answer

Custom URL categories allow defining pattern strings, matching types, and grouping custom URLs together.

8
MCQeasy

What is the primary function of the Junos Express Antivirus engine on SRX Series firewalls?

A.To inspect Layer 7 application handshakes for AppID classification.
B.To detect and block malware within network traffic streams.
C.To filter out unsolicited bulk email messages over SMTP.
D.To categorize URLs into security and productivity groups.
AnswerB

Antivirus engines scan files to prevent malware infections.

Why this answer

The Express antivirus engine provides high-performance, stream-based malware detection on Juniper SRX devices.

9
MCQmedium

An administrator configures Antispam with a DNSBL server. After committing the changes, logs show that no antispam queries are being performed. What is the most common reason for this when configuring DNSBL?

A.The antispam license must be activated using a hardware token.
B.The SRX security policy lacks an application ALG for SMTP.
C.The system DNS name servers are not configured on the SRX device.
D.The antispam profile must be attached to an interface rather than a UTM policy.
AnswerC

External DNSBL lookups require functional DNS name server configuration on the SRX.

Why this answer

Antispam requires DNS name resolution (DNS servers configured on the SRX) to query external DNSBL servers. Without DNS configured, blacklist queries fail.

10
Multi-Selectmedium

Which TWO components are required for Integrated Web Filtering to function properly on an SRX Series firewall? (Choose two.)

Select 3 answers
A.An active Integrated Web Filtering license
B.An active IDP signature pack subscription
C.A local database containing all 10 million global URLs
D.An SMTP mail server relay
E.Connectivity to a cloud-based URL rating server
AnswersA, B, E

A valid IWF license is required to enable cloud queries.

Why this answer

Integrated Web Filtering requires an active cloud rating license and functional internet reachability to query categorization servers.

11
Multi-Selectmedium

Which TWO types of web filtering providers are natively supported by Juniper SRX Series Integrated Web Filtering? (Choose two.)

Select 2 answers
A.Trend Micro
B.Symantec
C.McAfee
D.Sophos
E.Webroot
AnswersD, E

Sophos is a supported cloud web filtering provider for SRX.

Why this answer

Juniper Integrated Web Filtering natively partners with Sophos and Webroot to supply cloud-based URL categorization databases.

12
MCQhard

When configuring Kaspersky-based Antivirus on an SRX Series device, which operational mode reduces resource consumption by only scanning files matching specific high-risk protocol extensions?

A.Passive monitor mode
B.Stateless AV filtering
C.Extension-based or type-based scanning filtering
D.Fast-track scanning mode
AnswerC

Configuring file extension filters ensures only executable or high-risk extensions are sent to the AV engine.

Why this answer

Kaspersky antivirus on SRX supports extension-based filtering to optimize performance by skipping non-risk file types.

13
MCQmedium

An administrator configures Web Filtering and wants to view summary statistics of blocked categories. Which operational command should be executed?

A.show security utm web-filtering statistics
B.show system services web-filtering summary
C.show security flow session statistics utm
D.show utm web-filter counters
AnswerA

This command displays counters for allowed, blocked, and categorized web requests.

Why this answer

Operational commands under 'show security utm web-filtering statistics' provide details on categories blocked and queries processed.

14
MCQmedium

An administrator notices that web filtering queries are failing because the SRX device cannot reach the cloud rating server over the internet. Which command can be used to troubleshoot connectivity to the cloud rating server from the Junos CLI?

A.traceroute utm-rating-engine
B.ping security utm cloud-server
C.show security utm web-filtering status
D.test utm cloud-connectivity
AnswerC

This operational command displays the connection status between the SRX and the web filtering cloud server.

Why this answer

The 'show security utm web-filtering statistics' or connection debugging commands help verify cloud reachability, while ping/traceroute commands test basic network paths.

15
MCQmedium

An administrator configures Antispam inspection, but wants to ensure that emails from internal trusted hosts bypass antispam scanning. How should this be handled?

A.Add the trusted internal hosts or sender domains to the antispam custom permit list.
B.Disable security policies for internal traffic.
C.Attach the antispam profile to the egress interface instead of the ingress policy.
D.Configure source NAT to hide internal host IP addresses.
AnswerA

Local permit lists allow trusted senders to bypass antispam checks.

Why this answer

Antispam policies and custom objects allow defining local permit lists for trusted hosts or domains.

16
MCQhard

An enterprise network uses Juniper SRX Series devices running Junos OS with Integrated Web Filtering. Due to privacy regulations, the administrator needs to ensure that specific sensitive URLs are not logged by the cloud rating server or the local SRX log. Which CLI parameter should be adjusted within the web-filtering profile?

A.set security log mode stream-disable
B.set security utm feature-profile web-filtering profile <name> custom-block-message <text>
C.set security utm feature-profile web-filtering profile <name> disable-cloud-logging
D.set security utm feature-profile web-filtering profile <name> no-log
AnswerD

The 'no-log' command disables logging of URLs matched by the specific web-filtering profile.

Why this answer

Web filtering profiles allow configuring logging options, including disabling URL logging to maintain user privacy.

17
MCQeasy

What is the primary function of the Integrated Web Filtering feature on Juniper SRX Series firewalls?

A.To scan email attachments for virus payloads.
B.To categorize URLs and enforce access control based on website categories.
C.To inspect DNS queries for cache poisoning attacks.
D.To enforce user authentication passwords.
AnswerB

Web filtering categorizes websites to control user browsing.

Why this answer

Integrated Web Filtering categorizes websites and allows administrators to enforce access policies.

18
MCQmedium

An administrator needs to ensure that when a web filtering block occurs, a specific redirect URL is presented to the user. Where is the redirect URL configured within the web filtering profile?

A.set security policies policy-profile redirect-url <url>
B.set security utm web-filtering redirect-action url <url>
C.set security utm feature-profile web-filtering profile <name> block-message-type redirect-url <url>
D.set security utm feature-profile web-filtering profile <name> redirect <url>
AnswerC

This command specifies the redirect URL when traffic matches a blocked web category.

Why this answer

Web filtering profile settings allow configuring custom block actions, including specifying a redirect URL.

19
Multi-Selectmedium

Which TWO elements are mandatory when attaching a UTM policy to a security policy in Junos OS? (Choose two.)

Select 2 answers
A.A stateless firewall filter attached to the loopback interface
B.An IPv6 address family on the egress interface
C.The 'utm-policy <name>' statement inside the security policy 'then' block
D.An active BGP routing neighbor in the routing table
E.A valid UTM policy name defined under [edit security utm policy-profile]
AnswersC, E

The command attaches the UTM policy to the matched traffic flow.

Why this answer

Attaching a UTM policy to a security policy requires referencing a valid UTM policy name within the policy's 'then' statement.

20
MCQmedium

An administrator configures Web Filtering with a custom block message. When users visit a blocked site, they do not see the custom message; instead, they receive a generic browser connection error. What is the most likely cause of this behavior?

A.The browser cache needs to be cleared.
B.The web filtering license has expired.
C.SSL proxy (HTTPS decryption) is not configured to inspect and inject the block page for HTTPS traffic.
D.The default action must be set to 'log' instead of 'block'.
AnswerC

HTTPS traffic cannot have custom block pages injected into the encrypted stream unless SSL proxy decrypts the flow.

Why this answer

When browsing via HTTPS, if the firewall attempts to inject a block page without SSL proxy (SSL initiation/decryption) enabled, the browser rejects the invalid certificate or connection reset, causing a generic browser error.

21
MCQmedium

An administrator configures Content Filtering to block all .exe files, but users report that they can still download .exe files over encrypted HTTPS connections. What is the most likely reason for this?

A.HTTPS decryption (SSL proxy) is not configured, so the firewall cannot inspect the encrypted payload for file extensions.
B.Content filtering only supports FTP traffic.
C.The content filtering license has expired.
D.The SRX control plane lacks memory.
AnswerA

Encrypted HTTPS traffic hides file content and extensions from content filtering unless decrypted by SSL proxy.

Why this answer

Content filtering inspects cleartext HTTP streams; encrypted HTTPS streams cannot be inspected for file extensions unless SSL Proxy (HTTPS decryption) is enabled.

22
MCQhard

When configuring an Integrated Web Filtering profile, you want to ensure that URLs categorized as 'Malware' or 'Phishing' are blocked immediately, while URLs categorized as 'Streaming Media' generate a log entry but are permitted. How should you configure this in Junos?

A.Configure AppSecure to block malware and allow streaming media.
B.Assign 'block' action to Malware and Phishing categories, and 'permit' with logging enabled to Streaming Media.
C.Assign a global block action and create bypass exceptions for streaming media.
D.Use content filtering to block malware URLs and web filtering for streaming media.
AnswerB

Individual category actions within the web filtering profile allow granular enforcement (blocking threats while permitting and logging entertainment sites).

Why this answer

Web filtering profiles allow assigning different actions (block, permit, log) to individual categories independently.

23
MCQhard

You are configuring Antispam on an SRX device and want to ensure that emails originating from partner domains are never flagged as spam, regardless of DNSBL results. Where should you configure this local white-listing rule?

A.Under [edit security utm custom-objects antispam block-list] and [edit security utm custom-objects antispam permit-list]
B.Under [edit security policies global permit-spam]
C.Under [edit security utm custom-objects antispam anti-spam-profile]
D.Under [edit security utm feature-profile antispam profile <name> whitelist]
AnswerA

Local overrides for antispam are configured within custom objects under antispam.

Why this answer

Antispam custom objects allow defining local white-lists and black-lists (block/permit lists) which take precedence over external DNSBL queries.

24
Multi-Selectmedium

Which TWO actions can be taken when an email message is identified as spam by an Antispam profile on an SRX Series firewall? (Choose two.)

Select 2 answers
A.Reboot the mail server via SNMP
B.Block the message
C.Automatically encrypt the email payload
D.Log the event
E.Delete the user mailbox on the mail server
AnswersB, D

Blocking stops the delivery of spam.

Why this answer

Antispam profiles support blocking spam messages and logging the detection event.

25
MCQeasy

An administrator needs to configure basic web filtering on a Juniper SRX Series device using the Integrated Web Filtering feature. Which license is strictly required on the SRX Series device to enable communication with the cloud-based web filtering rating server?

A.An IDP (Intrusion Detection and Prevention) license
B.An AppSecure license
C.An Anti-Virus license
D.An Integrated Web Filtering license
AnswerD

Integrated Web Filtering requires a dedicated IWF license to query the cloud database.

Why this answer

Integrated Web Filtering on Juniper SRX devices relies on cloud-based categorization servers, which requires a valid Sophos or Webroot web filtering license installed on the device.

26
MCQmedium

An administrator notices that Antivirus scanning is causing high latency for VoIP and real-time streaming traffic passing through the SRX firewall. How should the administrator resolve this issue while maintaining security for web traffic?

A.Convert the antivirus profile from stream mode to batch mode.
B.Disable stateful inspection globally across the device.
C.Configure a higher priority routing metric for VoIP packets.
D.Remove the UTM policy profile attachment from the security policy specifically handling real-time VoIP traffic.
AnswerD

Real-time traffic should bypass resource-intensive stream inspection by excluding UTM from its security policy.

Why this answer

To prevent latency-sensitive traffic (like VoIP) from being impacted by UTM, the security policy matching VoIP traffic should omit the UTM policy profile attachment.

27
MCQhard

You notice that CPU utilization on the SRX Routing Engine spikes significantly whenever large archives are downloaded through the UTM antivirus inspection engine. Which architectural adjustment or feature configuration helps mitigate control plane impact during stream scanning?

A.Disabling stateful inspection across all zones.
B.Offloading stream scanning buffers and ensuring fast-path processing on Security Processing Cards (SPCs).
C.Moving all UTM antivirus processing to the Routing Engine CPU.
D.Configuring static routing for all HTTP traffic.
AnswerB

Leveraging SPCs keeps traffic inspection in the data plane rather than stressing the Routing Engine control plane.

Why this answer

Stream scanning on SRX devices leverages specialized hardware (such as SPCs / Flow Processing Cards) where applicable, but tuning stream buffer sizes or utilizing hardware acceleration helps manage resource utilization.

28
MCQmedium

You are configuring a UTM policy on a Juniper SRX firewall that includes antivirus, web filtering, and antispam profiles. To apply these UTM services to traffic, where must the UTM policy profile be explicitly attached in the Junos configuration?

A.Under the [edit security zones security-zone <zone> utm-profile] hierarchy.
B.Under the [edit security policies from-zone <zone> to-zone <zone> policy <name> match] hierarchy.
C.Under the [edit interfaces <interface> unit <0> family inet utm] hierarchy.
D.Under the [edit security policies from-zone <zone> to-zone <zone> policy <name> then] hierarchy.
AnswerD

UTM policies are attached within the 'then' statement of a security policy to enforce inspection on matched sessions.

Why this answer

UTM policies in Junos OS are bound directly to security policies using the 'utm-policy <name>' statement within the security policy rule.

29
MCQeasy

Which Junos CLI command displays the version and status of the Integrated Web Filtering engine?

A.show utm engine status web-filter
B.show security utm web-filtering status
C.show security license web-filtering detail
D.show system software web-filter
AnswerB

This command shows the status, license validity, and cloud connection state of web filtering.

Why this answer

Operational commands starting with 'show security utm web-filtering' display status and version details.

30
MCQeasy

Which Junos configuration hierarchy is used to create a UTM Policy Profile that bundles multiple security features?

A.[edit security utm policy-profile <name>]
B.[edit security policies utm-profile <name>]
C.[edit utm profile-policy <name>]
D.[edit security firewall utm-policy <name>]
AnswerA

This is the correct configuration path for creating UTM policy profiles.

Why this answer

UTM policy profiles are configured under the [edit security utm policy-profile] hierarchy.

31
MCQmedium

You are troubleshooting a web filtering policy on an SRX Series firewall configured for Integrated Web Filtering. Users report that a specific educational website is being blocked under the 'Finance' category. Where should you configure a custom exemption or local override to permit access to this specific URL without changing the global category assignment?

A.Modify the Junos global bypass list under [edit system services web-management].
B.Add the URL to the application firewall (AppID) custom application definition.
C.Configure a security policy source NAT rule to bypass the UTM profile for that specific IP.
D.Configure a custom URL category and assign a permit action within the UTM policy profile.
AnswerD

Creating a custom URL category with a permit action allows administrators to override cloud-based category blocking for specific URLs.

Why this answer

Custom local overrides for web filtering URLs on SRX devices are configured under the [edit security UTM custom-objects url-pattern] and referenced in the custom-url-category.

32
MCQmedium

An administrator wants to verify that the antivirus signature database on an SRX firewall is up to date. Which operational command should be used?

A.show security utm antivirus status
B.show security license antivirus detail
C.show system software status antivirus
D.request security utm antivirus update-check
AnswerA

This command displays the antivirus engine version, signature database release date, and connection status.

Why this answer

The command 'show security utm antivirus status' provides details regarding the antivirus engine status and signature database version.

33
Multi-Selectmedium

Which TWO protocols are inspected by Integrated Web Filtering on Juniper SRX Series firewalls? (Choose two.)

Select 2 answers
A.SNMP
B.HTTP
C.ICMP
D.HTTPS
E.SMTP
AnswersB, D

HTTP web traffic is inspected and categorized.

Why this answer

Integrated Web Filtering inspects HTTP and HTTPS web traffic to categorize and control browsing.

34
MCQhard

An administrator configures Unified Threat Management (UTM) antivirus inspection on an SRX device using the Junos Express antivirus engine. During high-traffic periods, users report that large file downloads are failing or timing out. Which CLI command or configuration adjustment is most appropriate to resolve this issue by increasing the maximum file size limit inspected by the antivirus engine?

A.set security utm default-profile antivirus max-buffer-size <size>
B.set security utm feature-profile antivirus profile default http-profile maximum-file-size <size>
C.set security flow tcp-mss <size>
D.set security utm engine stream-scanning max-object-size <size>
AnswerB

The maximum-file-size parameter under the HTTP profile of the UTM antivirus configuration controls the threshold for file inspection.

Why this answer

The antivirus engine on SRX devices has configurable size limits for stream inspection. Modifying the maximum file size under the UTM antivirus profile prevents timeouts or drops on large files.

35
MCQeasy

When configuring Antispam on an SRX Series device using the SBL (Spam Black List) feature, what is the primary function of the block/permit action list?

A.To inspect the payload of HTTPS encrypted webmail traffic for spam keywords.
B.To rewrite the headers of outgoing spam messages before they reach the mail server.
C.To quarantine infected executable attachments found inside incoming emails.
D.To query external DNSBL servers and apply local overrides for known good or bad senders.
AnswerD

The antispam profile integrates with DNSBL services and allows local custom block and permit rules.

Why this answer

Antispam on Juniper SRX devices uses DNS-based Blackhole Lists (DNSBL) and local allow/block lists to determine if an email sender should be flagged as spam.

36
MCQhard

You are configuring an SRX Series device with Antivirus inspection. You want to ensure that files transferred over FTP are scanned, but HTTP traffic bypasses antivirus inspection due to performance constraints. How should you configure the antivirus profile?

A.Create two separate security policies and attach antivirus only to the FTP security policy.
B.Enable antivirus under ftp-profile and disable or omit it under http-profile.
C.Set the HTTP antivirus action to 'permit-without-scanning'.
D.Use a custom firewall filter to drop HTTP traffic before UTM processing.
AnswerB

Antivirus profiles contain protocol-specific sub-profiles (e.g., http-profile, ftp-profile) where inspection can be enabled or disabled individually.

Why this answer

Antivirus profiles allow enabling or disabling inspection per protocol (such as http, ftp, smtp, pop3, imap).

37
MCQhard

You are troubleshooting an issue where Integrated Web Filtering traffic is intermittently failing with a 'server connection timeout' error to the cloud rating service. Which troubleshooting command allows you to test DNS resolution for the cloud rating server directly from the SRX CLI?

A.test dns resolution <hostname>
B.traceroute utm-cloud
C.ping <cloud-rating-server-hostname>
D.show security utm dns-cache
AnswerC

Pinging the hostname verifies both DNS resolution and network connectivity to the cloud rating server.

Why this answer

The standard Junos operational ping command with domain names tests DNS resolution and reachability.

38
MCQhard

When configuring an SRX firewall with Content Filtering, you want to ensure that any HTTP response containing a specific sensitive keyword is blocked. Which CLI configuration path and command accomplish this?

A.[edit security utm custom-objects content-filtering custom-string <name>] and reference it in the content-filtering profile.
B.[edit security policies content-string-filter <text>]
C.[edit firewall filter custom-string action block]
D.[edit security utm feature-profile content-filtering profile <name> block-string <text>]
AnswerA

Custom string objects are created under content-filtering custom-objects and applied via the content filtering profile.

Why this answer

Content filtering profiles allow defining custom string patterns to block traffic containing specific text strings.

39
MCQeasy

Which UTM feature on Juniper SRX Series firewalls is responsible for inspecting incoming Simple Mail Transfer Protocol (SMTP) traffic for unsolicited bulk commercial email?

A.Web filtering
B.Antivirus
C.Antispam
D.Content filtering
AnswerC

Antispam inspects email traffic streams.

Why this answer

Antispam is the specific UTM feature designed to detect and block spam over SMTP protocols.

40
MCQeasy

What is the primary role of Unified Threat Management (UTM) on Juniper SRX Series firewalls?

A.To provide high-availability failover between routing engines.
B.To combine multiple security features (antivirus, web filtering, antispam, content filtering) into a single firewall platform.
C.To optimize BGP routing path selections.
D.To manage IPsec VPN tunnel key exchanges.
AnswerB

UTM unifies multiple security services on the SRX.

Why this answer

UTM integrates multiple security features such as antivirus, web filtering, antispam, and content filtering into a single gateway device.

41
MCQeasy

What is the purpose of a Custom URL Category in Juniper SRX Web Filtering?

A.To define custom URL patterns and group them for specific permit or block actions.
B.To configure IPsec VPN gateway endpoints.
C.To store antivirus malware signatures locally.
D.To define email sender white-lists.
AnswerA

Custom categories let administrators manage specific URL exceptions.

Why this answer

Custom URL categories allow administrators to group specific custom URLs for tailored permit or block policies.

42
Multi-Selecthard

Which THREE actions can be specified when configuring an Antispam profile action on a Juniper SRX Series device? (Choose three.)

Select 3 answers
A.Automatic payload encryption
B.Automatic quarantine to an IMAP mailbox folder
C.Block the email
D.Log the event
E.Custom message insertion
AnswersC, D, E

Blocking prevents delivery of the spam email.

Why this answer

Junos antispam profiles support multiple actions when a message matches spam criteria, including custom messaging, logging, and blocking.

43
MCQeasy

What is the primary function of Content Filtering in Juniper SRX Unified Threat Management?

A.To inspect encrypted SSL/TLS handshake certificates.
B.To prevent buffer overflow attacks using protocol anomaly detection.
C.To scan incoming emails for spam sender addresses.
D.To block specific file types, MIME types, and text strings within traffic streams.
AnswerD

Content filtering restricts undesirable file types and content.

Why this answer

Content filtering inspects traffic streams to enforce organizational policies regarding file types, extensions, and MIME formats.

44
Multi-Selectmedium

Which TWO actions can be configured when a URL is matched against a blocked category in an Integrated Web Filtering profile on an SRX Series device? (Choose two.)

Select 2 answers
A.Send an SNMP trap and instantly reboot the device control plane.
B.Block the connection and display a custom HTML block page message.
C.Redirect the user browser session to a predefined warning URL.
D.Automatically rewrite the HTTP request header to inject user authentication tokens.
E.Drop the packet silently without sending any notification to the client.
AnswersB, C

SRX web filtering supports displaying custom block notification pages.

Why this answer

When a URL is blocked by web filtering, Juniper devices can block the connection with a custom message or redirect the user to a specific warning page URL.

45
MCQhard

You are troubleshooting an antispam deployment where legitimate emails from a trusted customer domain are intermittently marked as spam by the DNSBL provider. To permanently prevent this without disabling antispam for other traffic, what should you configure?

A.Disable DNSBL server queries globally across the SRX device.
B.Add the customer domain to the web-filtering custom override list.
C.Modify the security policy action from 'permit' to 'deny' for that specific source.
D.Create a local antispam permit object containing the customer's sender domain or IP address.
AnswerD

Local permit lists take precedence over DNSBL blacklists, ensuring trusted senders pass through.

Why this answer

Local permit lists (whitelists) under antispam custom objects allow overriding DNSBL spam detections for trusted sender domains.

46
MCQeasy

What is the primary purpose of a UTM policy profile on a Juniper SRX firewall?

A.To configure stateful inspection timeouts for high-speed interfaces.
B.To define routing metrics for secure VPN tunnels.
C.To enforce user authentication mechanisms before granting network access.
D.To bundle multiple individual UTM feature profiles into a single assignable policy object.
AnswerD

UTM profiles group antivirus, web filtering, and other security profiles for policy attachment.

Why this answer

A UTM policy profile acts as a container that bundles various UTM feature profiles (antivirus, web-filtering, antispam, content-filtering) together for application in security policies.

47
Multi-Selecthard

Which THREE configuration elements are required to successfully implement Integrated Web Filtering on a Juniper SRX Series firewall? (Choose three.)

Select 3 answers
A.A valid Integrated Web Filtering license installed on the SRX
B.A web filtering feature profile defining category actions
C.An SMTP mail server relay configuration
D.A UTM policy profile referencing the web filtering profile, attached to a security policy
E.An active BGP peering session with the cloud rating provider
AnswersA, B, D

An active license is required for cloud rating queries.

Why this answer

IWF implementation requires an IWF license, a configured web filtering feature profile, and a UTM policy attached to a security policy.

48
MCQmedium

An administrator needs to ensure that Antispam inspection is applied only to inbound mail destined for the corporate mail server. How should this be achieved in the security policy configuration?

A.Configure a global antispam filter under the [edit security utm] hierarchy.
B.Attach an antispam-enabled UTM policy exclusively to the security policy permitting SMTP traffic from the untrusted zone to the mail server.
C.Apply the antispam profile directly to the egress interface facing the mail server.
D.Enable antispam globally within the system services configuration.
AnswerB

Restricting the UTM policy to the specific security policy ensures antispam inspection applies only to that traffic path.

Why this answer

Antispam is bound to a UTM policy, which in turn is attached to a specific security policy governing the mail server traffic flow.

49
MCQmedium

A company requires that employees be blocked from accessing social networking sites during work hours, but allowed to access them during a specific lunch window. How should the administrator achieve this using Juniper Web filtering features?

A.Use the antispam scheduler hierarchy to override web filtering category rules during lunch hours
B.Define a content filtering rule with an active time range for MIME type dropping
C.Attach a custom scheduler object to the security policy that toggles between two different Web filtering profiles containing opposing category actions
D.Configure a time-based exception directly inside the SurfControl cloud portal settings
AnswerC

By applying schedulers to security policies referencing different UTM profiles, administrators can enforce time-based access control.

Why this answer

Web filtering profiles can be associated with custom schedules or applied conditionally, but standard operational practice involves creating multiple Web filtering profiles or leveraging custom URL categories combined with scheduler objects referenced in security policies.

50
MCQhard

When configuring an Antispam profile, you want to specify that emails detected as spam should be tagged in the subject line rather than completely dropped. Which parameter within the antispam profile configuration enables this?

A.set security utm feature-profile antispam profile <name> modify-header subject-tag
B.set security utm antispam-profile <name> subject-rewrite
C.set security utm feature-profile antispam profile <name> spam-action rewrite-subject
D.set security utm feature-profile antispam profile <name> smtp-action tag-subject
AnswerD

The tag-subject action modifies the email header to add a custom prefix to the subject line.

Why this answer

Junos antispam profiles allow customizing the action, including tagging the subject line of suspected spam emails.

51
MCQhard

An administrator notices that the SRX firewall is failing to inspect encrypted HTTPS traffic for web filtering and antivirus violations. The security policy currently permits traffic from the trust zone to the untrust zone with a UTM profile attached. What must be configured to enable content security inspection on this HTTPS traffic?

A.Enable SSH inspection within the content filtering profile configuration hierarchy
B.Change the security policy action from permit to tunnel for encrypted sessions
C.Configure an SSL proxy profile and apply it to the security policy alongside the UTM profile
D.Upgrade the Juniper Secure Connect license to enable TLS deep packet inspection in the UTM profile
AnswerC

SSL forward proxy decryption is mandatory for the SRX to inspect HTTPS payloads with UTM features.

Why this answer

UTM security features on Juniper SRX devices inspect cleartext protocols by default. To inspect HTTPS (SSL/TLS) traffic, the firewall must perform SSL proxy decryption (Forward Proxy) to decrypt the session, inspect the content using the UTM profile, and re-encrypt it before forwarding.

52
MCQeasy

An administrator is configuring a Unified Threat Management (UTM) policy on a Juniper SRX Series device to protect internal users from downloading malicious software. Which UTM feature should the administrator enable and configure to scan HTTP and FTP traffic for viruses?

A.Content filtering
B.Antispam
C.Antivirus
D.Web filtering
AnswerC

Antivirus inspection examines files transferred over HTTP and FTP against signature databases to detect malware. Accepts this correct option.

Why this answer

The antivirus (AV) feature in Juniper UTM is responsible for scanning traffic protocols such HTTP, FTP, SMTP, and POP3 for malicious payloads. Web filtering specifically controls access to URL categories, antispam processes email, and content filtering blocks files based on MIME types or extensions.

53
MCQeasy

Which command is used to view real-time statistics regarding UTM Antivirus blocks and scans on an SRX Series firewall?

A.show utm engine status
B.show security utm antivirus statistics
C.show security flow session utm
D.show system antivirus summary
AnswerB

This command shows counters for files scanned, infected files found, and actions taken by the antivirus engine.

Why this answer

Operational commands starting with 'show security utm' display runtime statistics for all active UTM engines.

54
MCQmedium

An administrator needs to block all users from downloading executable files (.exe and .msi) via HTTP, regardless of the website category. Which UTM feature should be utilized to achieve this efficiently?

A.AppSecure AppID
B.Antivirus
C.Integrated Web Filtering
D.Content Filtering
AnswerD

Content filtering inspects file types, extensions, and MIME types to block undesirable transfers.

Why this answer

Content filtering allows blocking specific file extensions or MIME types across HTTP/FTP sessions.

55
MCQmedium

When configuring an Integrated Web Filtering profile, an administrator wants to block access to social networking sites during working hours. Which profile parameter is used to specify this category-based block?

A.set security utm feature-profile web-filtering profile <name> category <category-name> action block
B.set security policies policy-profile category-block social-networking
C.set security utm feature-profile web-filtering profile <name> block-category social-networking
D.set security utm web-filtering category social-networking drop
AnswerA

This command assigns a block action to a specific web filtering category.

Why this answer

Categories in Web Filtering are assigned actions (permit, block, or log) within the web filtering profile.

56
MCQhard

When configuring Antivirus inspection on an SRX device using Kaspersky, you want to ensure that password-protected archive files (such as .zip or .rar files containing passwords) are blocked because they cannot be scanned for malware. Which profile parameter achieves this?

A.set security utm feature-profile antivirus profile <name> drop-encrypted-streams
B.set security content-filtering password-archives block
C.set security utm antivirus encrypted-files drop
D.set security utm feature-profile antivirus profile <name> http-profile archive password-protected block
AnswerD

This command blocks password-protected archives since the antivirus engine cannot inspect their encrypted contents.

Why this answer

Antivirus profiles allow configuring actions for un-scannable files, such as password-protected archives, to maintain security posture.

57
MCQmedium

An administrator implements Web filtering on an SRX Series firewall using SurfControl as the cloud provider. Users report that access to a newly launched educational website is unexpectedly blocked. Where should the administrator check first to determine why the URL was blocked and override the categorization if necessary?

A.Verify the content filtering profile blocks using show security utm content-filtering statistics
B.Run the show security utm web-filtering statistics command to verify cache hits and category query responses
C.Review the antispam blocklist statistics using show security utm antispam statistics
D.Examine the dynamic application signatures database version using show security alg status
AnswerB

This operational command displays the status and query results from the web filtering cloud service, showing how a URL was categorized.

Why this answer

The Juniper security intelligence and Web filtering features allow administrators to query the cloud rating server or view local logs via security logs and operational commands like 'show security utm web-filtering statistics' or 'show security utm web-filtering status' to check category matches and override incorrect ratings.

58
MCQeasy

Which Junos configuration hierarchy is used to define a UTM Web Filtering profile?

A.[edit security utm feature-profile web-filtering profile <name>]
B.[edit firewall utm-policy web-filter]
C.[edit security web-filter profile <name>]
D.[edit applications utm web-filtering]
AnswerA

This is the correct configuration path for creating and tuning web filtering profiles.

Why this answer

UTM feature profiles are configured under the [edit security utm feature-profile web-filtering] hierarchy.

59
MCQeasy

What is the primary function of the Antispam feature on Juniper SRX Series firewalls?

A.To detect and filter unsolicited bulk email messages over SMTP.
B.To inspect Layer 4 port numbers for port scanning attacks.
C.To block malicious executable file downloads from websites.
D.To categorize web traffic into productivity groups.
AnswerA

Antispam inspects email streams to block spam.

Why this answer

Antispam identifies and blocks unsolicited bulk commercial emails arriving over SMTP.

60
Multi-Selecthard

Which THREE parameters can be configured within a UTM policy profile on a Juniper SRX Series firewall? (Choose three.)

Select 3 answers
A.IPsec VPNike gateway settings
B.Antispam profile reference
C.BGP routing protocol parameters
D.Antivirus profile reference
E.Web-filtering profile reference
AnswersB, D, E

Antispam profiles are bundled into UTM policy profiles.

Why this answer

UTM policy profiles bundle feature profiles such as antivirus, web-filtering, antispam, and content-filtering.

61
MCQmedium

An administrator configures Content Filtering to block executable files (.exe). Users report that they can still download archives containing executable files inside them (.zip). What is the recommended way to prevent users from bypassing file extension blocks using compressed archives?

A.Convert the security policy from stateless to stateful inspection.
B.Enable BGP routing route-reflection for HTTP traffic.
C.Add archive file extensions (such as .zip and .rar) to the content filtering block list.
D.Disable HTTP proxy caching on the client browsers.
AnswerC

Blocking archive file extensions prevents users from circumventing executable blocks using archive containers.

Why this answer

To prevent users from bypassing file extension blocks using archives, content filtering or antivirus profiles should be configured to block archive types (.zip, .rar) or block password-protected/unscannable archives.

62
MCQmedium

An administrator wants to ensure that specific text strings (such as credit card numbers or restricted keywords) found in HTTP web traffic are blocked. Which UTM feature should be configured?

A.Integrated Web Filtering
B.AppSecure AppID
C.Antivirus
D.Content Filtering
AnswerD

Content filtering includes custom string matching capabilities.

Why this answer

Content filtering supports searching for specific text strings within payload streams.

63
MCQhard

You are configuring an SRX firewall with Web Filtering and need to ensure that specific URLs are always permitted regardless of their cloud-assigned category. Where should you define these permitted URLs?

A.In a custom URL category assigned a permit action, referenced in the web-filtering profile.
B.In the system-wide global bypass list under [edit system services web].
C.In the security policy source address book.
D.In the AppSecure custom application signature database.
AnswerA

Custom URL categories allow overriding cloud categorization for specific patterns.

Why this answer

Custom URL patterns and custom categories allow defining local override rules that take precedence over cloud ratings.

64
MCQhard

You are configuring an SRX Series firewall with Antivirus inspection. You want to ensure that if the cloud rating or antivirus update service becomes unreachable, the firewall fails open and does not disrupt user web browsing. Which CLI parameter configures the fail-open behavior?

A.set security flow utm-fail-open
B.set security utm error-action allow
C.set security utm feature-profile antivirus profile <name> fallback-action permit
D.set security utm feature-profile antivirus profile <name> un-scannable permit
AnswerC

The fallback-action (or fail-open setting) determines behavior when the AV service is unavailable.

Why this answer

UTM profiles on SRX allow configuring fail-open or fail-closed behavior when the inspection engine or cloud service encounters errors.

65
MCQhard

An SRX Series firewall is configured with an extensive UTM policy containing antivirus, web filtering, and content filtering. During peak hours, CPU utilization spikes, causing packet drops. Which feature option should the administrator adjust within the UTM policy to optimize performance without disabling security entirely?

A.Disable content filtering and rely solely on AppID rules in security policies
B.Configure the antivirus profile to use express-mode or stream-based scanning options if supported by the platform
C.Set the UTM web-filtering fallback profile action to log-and-permit or block when the cloud server is unreachable
D.Switch the antispam engine from cloud-based lookup to local pattern matching
AnswerB

Stream-based or express scanning modes reduce memory and CPU overhead compared to full buffering/proxy modes.

Why this answer

When Juniper SRX devices experience high CPU due to UTM inspection, offloading scanning or utilizing stream-based inspection modes instead of proxy-based inspection (or tuning cache timeouts and fallback actions) helps maintain performance. Specifically, configuring the fallback action or optimizing local cache settings reduces cloud query latency and overhead.

66
Multi-Selecthard

Which THREE parameters can be defined within a Content Filtering profile on a Juniper SRX device to restrict file transfers? (Choose three.)

Select 3 answers
A.File extension block list
B.DNSBL server IP addresses
C.MIME type block list
D.URL block patterns
E.Custom block text strings
AnswersA, C, E

Specific file extensions like .exe or .zip can be blocked.

Why this answer

Content filtering profiles allow defining block rules based on MIME types, file extensions, and blocking text strings within web traffic.

67
Multi-Selectmedium

An administrator is configuring a Web filtering profile on a Juniper SRX Series device using local database caching. Which TWO parameters can be adjusted to optimize cache performance and behavior? (Choose two.)

Select 2 answers
A.fallback-profile
B.block-message
C.server-timeout
D.maximum-entries
E.timeout
AnswersD, E

The maximum-entries parameter defines the upper limit of cached URL rating entries stored locally.

Why this answer

When configuring local web filtering cache on Juniper SRX devices, administrators can tune parameters such as the maximum number of entries the cache can hold and the time-to-live (TTL) or timeout values for cached URL ratings.

68
MCQhard

An administrator configures Content Filtering to block all files with the '.scr' extension. A user renames an executable screensaver file from 'malware.scr' to 'malware.jpg' and uploads it via HTTP. What will the SRX content filtering engine do by default?

A.The file will always pass because content filtering cannot inspect files with modified extensions.
B.The file will be blocked if MIME-type inspection is enabled, because the MIME type in the HTTP header identifies the true payload format.
C.The file will cause a crash of the SRX content filtering daemon.
D.The file will be automatically renamed back to '.scr' by the firewall.
AnswerB

MIME-type inspection inspects the HTTP header content-type, which often reveals the true file type regardless of renamed extensions.

Why this answer

Advanced content filtering or MIME inspection checks actual file signatures (magic numbers) rather than relying solely on file extensions. However, standard extension-based content filtering checks the extension in the filename, while deep inspection checks MIME headers.

69
Multi-Selecthard

When configuring Juniper UTM Content Filtering, an administrator can define matching criteria to take specific actions (block, permit, or log). Which THREE criteria types are supported by the content filtering feature? (Choose three.)

Select 3 answers
A.MIME types
B.Custom pattern strings
C.Email sender IP addresses
D.File extensions
E.URL category ratings
AnswersA, B, D

Content filtering can inspect and act upon specific MIME types (e.g., application/x-msdownload).

Why this answer

Content filtering on Juniper SRX devices inspects traffic based on specific payload characteristics, specifically MIME types, file extensions, and custom string/pattern matches within the transferred files.

70
MCQhard

You are configuring Antivirus inspection on an SRX Series firewall and want to ensure that files larger than 20 MB are not scanned, in order to prevent CPU and memory exhaustion on the processing cards. Which CLI command configures this maximum file size limit for HTTP streams?

A.set security utm antivirus max-size 20mb
B.set security flow max-file-size 20
C.set security utm feature-profile antivirus profile default http-profile maximum-file-size 20
D.set security utm stream-scanning file-limit 20
AnswerC

This command configures the maximum file size (in megabytes or kilobytes depending on syntax) for HTTP antivirus inspection.

Why this answer

Antivirus profiles allow setting the maximum file size for stream inspection to prevent resource exhaustion.

71
MCQeasy

Which UTM feature should an administrator configure to prevent employees from accessing gambling and adult content websites?

A.Antivirus
B.Antispam
C.Web Filtering
D.Content Filtering
AnswerC

Web filtering provides category-based website control.

Why this answer

Web filtering categorizes websites into various groups, including gambling and adult content, allowing administrators to block them.

72
Multi-Selectmedium

Which TWO methods can be used to manually trigger a signature update for UTM services on an SRX Series firewall? (Choose two.)

Select 2 answers
A.Using Juniper Security Director or Junos Space centralized management.
B.Rebooting the Routing Engine via the 'request system reboot' command.
C.Executing a factory default reset on the SRX device.
D.Running a manual commit check on the configuration file.
E.Using the Junos CLI 'request security utm antivirus update' command.
AnswersA, E

Centralized network management systems can push or schedule UTM signature updates.

Why this answer

Junos OS allows manual signature updates via the Junos CLI using 'request security utm ...' commands or via Junos Space / Security Director management platforms.

73
Multi-Selectmedium

Which TWO protocols are supported for Antivirus scanning within Juniper SRX UTM profiles? (Choose two.)

Select 2 answers
A.HTTP
B.BGP
C.SNMP
D.SMTP
E.NTP
AnswersA, D

HTTP traffic is scanned for malware.

Why this answer

Junos UTM antivirus supports multiple protocols, including HTTP and SMTP for file and email attachment scanning.

74
MCQmedium

An administrator configures Web Filtering to log all requests, but security logs show that requests to permitted sites are not generating log entries. What is the most likely cause?

A.The 'log-permitted' option is not enabled within the web-filtering profile.
B.Permitted traffic bypasses UTM inspection entirely.
C.Security logging is globally disabled across the SRX device.
D.The web filtering license does not support logging allowed traffic.
AnswerA

Enabling log-permitted ensures that allowed web requests are recorded in the security logs.

Why this answer

Web filtering profiles often default to logging only blocked or violation events unless explicitly configured to log permitted traffic using the 'log-permitted' parameter.

75
Multi-Selecthard

Which THREE actions can be configured within a Content Filtering profile when a matched file type or MIME type violation occurs? (Choose three.)

Select 3 answers
A.Automatic quarantine to local flash storage
B.Automatic file sanitization (macro removal)
C.Display a custom block message
D.Block the transfer
E.Log the event
AnswersC, D, E

Custom messages notify users why the transfer failed.

Why this answer

Content filtering actions include blocking the transfer, logging the event, and displaying a custom block message.

Page 1 of 2 · 85 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Content Security questions.