Sample questions
Juniper Networks Security, Associate (JNCIA-SEC, JN0-232) (JNCIA-SEC) practice questions
An administrator configures interface-based Source NAT on the outgoing external interface of a SRX Series device. However, internal hosts report being unable to reach external web…
You are troubleshooting a Junos security deployment where Source NAT is configured with a pool. You observe that certain internal applications fail because the external receiving s…
An administrator deploys Static NAT on a Junos OS device to provide a one-to-one mapping between a public IP address (198.51.100.10) and an internal server IP address (10.1.1.10).…
An administrator has configured multiple rules within a single Source NAT rule-set. When traffic traverses the SRX device, how does Junos OS determine which specific rule within th…
You manage an SRX device where multiple internal subnets require Source NAT out to the internet using a shared pool of public IP addresses. However, specific internal servers must…
An administrator configures Static NAT for an internal server. After committing the configuration, the administrator notices that when external clients initiate connections, the se…
You are troubleshooting a Destination NAT rule where traffic matching the rule is dropped. You run 'Traceoptions' for security flow and notice that the packet hits the destination…
An administrator configures Destination NAT so that traffic to public IP 198.51.100.10 is translated to internal server 10.1.1.10. However, when the administrator checks the securi…
You are reviewing a Junos configuration containing both Destination NAT and Static NAT. An incoming packet matches both a Destination NAT rule and a Static NAT rule. Based on Junos…
Which command is used to clear active NAT sessions on an SRX Series device during troubleshooting?
An administrator configures Destination NAT so that traffic arriving on the external interface destined for IP 198.51.100.25 is translated to 10.0.0.5. After applying the configura…
You are troubleshooting a complex Static NAT setup where an internal mail server (10.10.10.5) is mapped to a public IP (198.51.100.5). External inbound connections work, but outbou…
An administrator configures a Source NAT pool and notices that multiple internal clients sharing the same public IP address are experiencing session disruptions with certain web ap…
You are troubleshooting a scenario where an SRX device is performing Static NAT for a web server. External users experience intermittent packet drops when loading large web pages.…
You configure a Static NAT mapping for a server. External users report that they can connect to the server, but internal users on the trust zone trying to reach the server via the…
You are troubleshooting a complex network where Destination NAT forwards traffic to a server farm. Due to high availability requirements, the destination NAT pool contains multiple…
You are auditing a Junos security device configuration. You observe multiple Static NAT rules configured across different rule sets. One of the rules uses the 'off-path' or similar…
You are troubleshooting a production SRX device where a Source NAT pool is shared across multiple security zones. Users in Zone A report normal internet access, but users in Zone B…
An administrator configures Destination NAT to forward incoming traffic on port 80 to an internal server. After committing, the administrator notices that ping tests to the destina…
You are troubleshooting a scenario where an SRX device is performing Static NAT. An internal server initiates outbound connections to the internet. When external recipients examine…
Which THREE parameters are typically required when defining a custom URL pattern object for use in web filtering overrides? (Choose three.)
Which THREE actions can be configured within a Content Filtering profile when a matched file type or MIME type violation occurs? (Choose three.)
Which command is used to clear UTM antivirus statistics counters on an SRX Series firewall?
You are configuring Antivirus inspection on an SRX Series firewall and want to ensure that files larger than 20 MB are not scanned, in order to prevent CPU and memory exhaustion on…