JNCIA-SEC · domain
Junos OS Security Objects
Practise Juniper Networks Security, Associate (JNCIA-SEC, JN0-232) (JNCIA-SEC) Junos OS Security Objects practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.
Focused practice
Practice Junos OS Security Objects questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Junos OS Security Objects
Junos OS Security Objects questions test whether you can apply the concept in context, not just recognise a definition.
How the topic appears in realistic exam-style scenarios.
Which detail in the question changes the correct answer.
How to eliminate plausible but wrong options.
How to connect the question back to the wider exam objective.
Watch out for
Common Junos OS Security Objects exam traps
- ▸Answering from memory before reading the full scenario.
- ▸Missing a constraint such as cost, availability, security, scope or command context.
- ▸Choosing a broad answer when the question asks for the most specific fix.
- ▸Ignoring why the wrong options are tempting.
Question index
All Junos OS Security Objects questions (88)
Click any question to see the full explanation, or start a practice session above.
Which type of Junos OS address book entry is available to all security zones on the device without needing to be redefined?
Easy2Which statement correctly identifies the purpose of Junos OS functional zones?
Easy3Which statement is true regarding the default security zone behavior in Junos OS?
Easy4An administrator configures a security zone and applies a SCREEN profile. Under load, legitimate traffic starts getting dropped due to SCREEN option thresholds being exceeded. Which CLI command should the administrator use to view real-time statistics and counters for triggered SCREEN attacks?
Hard5Which command allows you to view the configured security zones and their assigned interfaces in Junos OS?
Easy6Which TWO statements are correct regarding Junos OS security zones? (Choose two)
Easy7An administrator configures a security zone and enables the 'udp-flood' SCREEN option with a specified threshold. How does Junos measure UDP flood attacks for this option?
Hard8You need to inspect traffic matching a proprietary application that uses dynamic TCP ports. You have written a custom application. What additional Junos security feature can be combined with custom applications to inspect deep packet content for non-standard ports?
Medium9Which TWO statements are true regarding Junos OS security policies and address books? (Choose two)
Easy10You are configuring an SRX Series device and want to ensure that all traffic entering the untrusted zone is checked for LAND attacks. Which configuration steps are required?
Medium11You want to apply a SCREEN option to protect against ICMP ping floods across all interfaces in a specific security zone. How should you structure this in the CLI?
Medium12Which TWO statements are true regarding Junos OS global address books versus zone-specific address books? (Choose two)
Hard13You need to modify the default session timeout for a specific custom application in Junos OS. Where is application timeout configured?
Medium14Which statement is true regarding Junos OS security zone interfaces?
Easy15An enterprise network uses multiple virtual routers. Can security zones span across different virtual routers on the same SRX Series device?
Hard16An administrator configures an address book containing an IPv6 address prefix. How does Junos OS handle IPv6 addresses in security policies compared to IPv4?
Hard17Which functional zone in Junos OS is automatically used for traffic that is generated by the SRX device itself, such as routing protocol updates or syslog messages?
Easy18Which Junos command displays the operational status of all SCREEN options and their associated counters across security zones?
Easy19Which command displays the configured functional zones in Junos OS?
Easy20Which Junos OS feature is responsible for translating port numbers for protocols like FTP during transit across security zones?
Easy21An administrator creates a global address book and a security zone-specific address book. A host address is defined with the same name in both address books, but with different IP subnets. When a packet originates from that security zone, which address book entry takes precedence?
Hard22You need to configure a custom application that matches UDP traffic on a range of destination ports from 5000 to 5010. How should you specify this range in the application configuration?
Medium23You need to group multiple IPv4 subnets and range combinations into a single object for use in security policies. Which configuration object should you create?
Medium24Which statement is true regarding Junos OS address books?
Easy25Which Junos OS CLI command is used to display currently active Application Layer Gateways (ALGs) and their status?
Easy26An administrator configures a security zone and adds the 'tcp-drop-synfin-set' SCREEN option. What specific packet characteristic does this option target?
Hard27An administrator creates a security zone and assigns multiple interfaces to it. One of the interfaces is configured with host-inbound-traffic allowed services for SSH. What happens to SSH access to the other interfaces in the same security zone?
Hard28When defining a custom application in Junos OS, you specify the protocol as TCP and set a source port range of 1024-65535 and a destination port of 8080. How does Junos evaluate this application in security policies?
Hard29Which THREE services can be enabled under host-inbound-traffic system-services in Junos OS security zones? (Choose three)
Medium30Which TWO functional zones are built-in and available by default in Junos OS? (Choose two)
Easy31An administrator notices that FTP traffic is failing inspection when traversing the SRX device. Upon investigation, it is found that the default ALG for FTP is interfering with non-standard control ports. Where would you modify or disable the FTP ALG in Junos OS?
Hard32An administrator needs to configure a security zone in Junos OS that will contain the management interface for out-of-band access. Which zone type is appropriate for this requirement?
Easy33You need to create a custom application in Junos OS that matches HTTP traffic running on non-standard port 8080. How should you define this application?
Medium34You want to create an address set that combines two address sets and one individual IP address object. Is this supported in Junos OS?
Medium35An administrator configures an address set named 'DMZ-SERVERS' containing three individual IP addresses. Later, one of those IP addresses is removed from the base address book. What happens to the 'DMZ-SERVERS' address set configuration?
Hard36You want to create a security zone that permits all host-inbound traffic for system services and protocols without manually listing every service. Is there a wildcard or all-inclusive keyword for host-inbound-traffic in Junos OS?
Medium37You have configured a custom application object named 'CUSTOM-APP' matching TCP port 9090. When you attempt to commit the configuration, Junos returns an error stating that the application conflicts with a predefined Junos application. How should you resolve this?
Medium38Which TWO actions occur when an Application Layer Gateway (ALG) inspects traffic in Junos OS? (Choose two)
Hard39Which command displays the configured security policies in Junos OS?
Easy40You are troubleshooting an issue where an application defined with a specific timeout is timing out prematurely during periods of inactivity. Where would you verify or adjust the flow session timeout globally in Junos OS?
Medium41An administrator configures an application set in Junos OS. What is the primary function of an application set?
Hard42An administrator configures a security zone and enables traceoptions for security flow. Where are these traceoptions configured in the Junos OS hierarchy?
Hard43Which Junos OS command displays the configuration of all security zones?
Easy44Which TWO statements are accurate regarding the evaluation order of address books in Junos OS? (Choose two)
Hard45Which statement best describes an Application Layer Gateway (ALG) in Junos OS?
Easy46An administrator configures an address set that includes another address set as a member (nested address sets). What is the maximum nesting depth supported for address sets in Junos OS?
Hard47You are troubleshooting a connectivity issue where SIP VoIP calls are establishing control sessions, but audio streams (RTP) are failing. Which Junos security feature must be properly configured or enabled to resolve this?
Medium48An administrator configures a security zone and enables traceoptions for zone management. What is the correct configuration hierarchy to enable traceoptions for security zones?
Hard49An administrator creates a security zone and defines both a zone-specific address book and a global address book. The same address name exists in both address books with conflicting subnets. When a security policy references this address name from a different security zone, which address definition is selected?
Hard50You want to configure SCREEN options to detect and block SYN flood attacks on an interface. Which specific SCREEN option parameter should you adjust within the screen profile?
Medium51Which TWO methods can be used to define IP addresses in Junos OS address books? (Choose two)
Easy52An administrator notices that FTP data connections are failing when clients behind an SRX device connect to external servers using active FTP mode. Passive FTP works correctly. What is the most likely root cause?
Hard53Which TWO statements are true regarding Junos OS address sets and their usage in security policies? (Choose two)
Hard54An administrator configures a security zone and enables the 'icmp timestamp' SCREEN option. What is the purpose of this option?
Hard55You want to configure a security zone to automatically reject new TCP connections with a TCP RST packet when the zone's transit sessions exceed capacity or policies deny them. Where is this behavior configured?
Medium56Which command is used to display active security sessions currently tracked by the Junos OS flow module?
Easy57An administrator configures a security zone and enables the 'tcp-rst' SCREEN option. What is the primary purpose of this SCREEN option?
Hard58Which TWO features or options are associated with Junos OS SCREEN option profiles? (Choose two)
Hard59Which THREE types of attacks are mitigated by Junos OS SCREEN options? (Choose three)
Medium60Which Junos OS feature inspects packet headers for layer 3 and layer 4 denial-of-service (DoS) attacks such as SYN floods, IP spoofing, and LAND attacks?
Easy61Which THREE parameters can be configured within a custom application definition in Junos OS? (Choose three)
Medium62Which command is used to verify the configuration of address books in Junos OS?
Easy63Which THREE settings can be configured under a security zone in Junos OS? (Choose three)
Medium64Which TWO commands are valid operational mode commands in Junos OS for security objects? (Choose two)
Easy65An administrator needs to ensure that packets with source routing options enabled are dropped before they enter the network through the untrusted zone. Which SCREEN option handles this?
Medium66Which THREE security features are configured under the [edit security] hierarchy in Junos OS? (Choose three)
Medium67Which TWO characteristics apply to custom applications created in Junos OS? (Choose two)
Hard68You want to create a security zone and explicitly block all traffic between interfaces assigned to that same zone (intra-zone traffic). Which configuration statement accomplishes this?
Medium69Which TWO traffic types are typically handled by functional zones in Junos OS? (Choose two)
Easy70You need to apply a screen profile that detects IP address spoofing where the source IP address belongs to the local subnet of the ingress interface. Which screen option addresses this?
Medium71You are configuring host-inbound traffic for a security zone and want to allow SNMP polling from a monitoring server. Which option under host-inbound-traffic system-services should you enable?
Medium72An administrator configures a security zone and enables traceoptions for SCREEN option processing. Where are SCREEN traceoptions configured?
Hard73Which statement accurately describes a security zone in Junos OS?
Easy74Which THREE protocols typically require Application Layer Gateways (ALGs) in Junos OS to function correctly across security policies? (Choose three)
Medium75You are configuring a security zone and need to apply a SCREEN option to protect against IP spoofing attacks. Under which hierarchy level must you associate the SCREEN option profile in Junos OS?
Medium76Which statement is true regarding Junos OS predefined applications?
Easy77Which Junos OS feature allows an administrator to define a collection of applications that should be treated as a single unit in security policies?
Easy78Which TWO objects can be referenced inside a Junos OS security policy? (Choose two)
Easy79Which THREE components can be grouped within a Junos OS address set? (Choose three)
Medium80You are troubleshooting an issue where TFTP file transfers are failing across an SRX device. Traffic is permitted by security policies. What is the most likely cause of this behavior?
Hard81Which command is used to display the currently configured global address books in Junos OS?
Easy82An administrator configures a security zone and applies a SCREEN profile that includes 'limit-session source-ip'. What is the function of this specific SCREEN option?
Hard83An administrator configures a security zone and enables the 'icmp all' SCREEN option with threshold parameters. What does the 'icmp all' option encompass?
Hard84You are configuring security zones and need to allow Ping (ICMP echo request) to be processed by the SRX routing engine for troubleshooting. Where do you configure this?
Medium85Which TWO statements describe the behavior of Junos OS Application Layer Gateways (ALGs)? (Choose two)
Hard86An administrator configures an address book with an address object using the DNS name of a remote server instead of an IP address. How does Junos OS handle DNS-based address objects in security policies?
Hard87Which command is used to view the list of all predefined Junos OS application objects?
Easy88You are troubleshooting an issue where an ALG is altering port numbers during FTP sessions, causing authentication failures with an application-layer proxy. Which command shows active ALG sessions and their port translations?
MediumOther domains
All JNCIA-SEC exam domains
Frequently asked questions
- What does the Junos OS Security Objects domain cover on the JNCIA-SEC exam?
- Junos OS Security Objects questions test whether you can apply the concept in context, not just recognise a definition.
- How many questions are in this domain?
- This page lists all 88 Junos OS Security Objects questions in the JNCIA-SEC question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Junos OS Security Objects questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.