Pre-Summer Sale Discount Flat 70% Offer - Ends in 0d 00h 00m 00s - Coupon code: 70diswrap

Juniper JN0-336 Dumps

Page: 1 / 7
Total 66 questions

Security, Specialist (JNCIS-SEC) Questions and Answers

Question 1

Which two services would an SRX Series device use to connect to an LDAP server for identity-aware security policies? (Choose two.)

Options:

A.

Active Directory

B.

TACACS+

C.

RADIUS

D.

JIMS

Question 2

You are asked to configure a cluster between SRX1 and SRX2.

Which two commands must be used to accomplish this task? (Choose two.)

Options:

A.

user@SRX2# set chassis cluster cluster-id 0 node 1

B.

user@SRX1 > set chassis cluster cluster-id 1 node 0

C.

user@SRX2 > set chassis cluster cluster-id 1 node 1

D.

user@SRX1# set chassis cluster cluster-id 0 node 2

Question 3

You want to configure the SSL proxy feature on your SRX Series Firewall.

Which two actions must you perform to accomplish this task? (Choose two.)

Options:

A.

Enable the SSL ALG.

B.

Create an SSL proxy profile.

C.

Create an SSL application object.

D.

Associate an SSL proxy profile with a security policy.

Question 4

Your manager asks you to update your SRX Series device’s IDP security package. You perform the required steps; however, when you attempt to install the package, you receive an error.

as

Referring to the exhibit, which two statements are correct about this error? (Choose two.)

Options:

A.

IDP stops inspecting traffic.

B.

The IDP license has expired.

C.

IDP continues to inspect traffic only using the installed signatures.

D.

The IDP license is missing/not installed.

Question 5

Which protocol does the SRX Series Firewall use to communicate with a Windows domain controller?

Options:

A.

SSH

B.

LDAP

C.

DNS

D.

NETCONF

Question 6

You work on the security operations team that manages firewalls only. In your data center, there are two SRX chassis clusters. These clusters operate on VLAN 1042. The network team advises you that they see the same MAC address coming from both chassis clusters for reth0.

Why is this occurring?

Options:

A.

The same cluster ID was used on both clusters.

B.

RGO is active on both node0 and node1 due to split-brain.

C.

Chassis clusters must be on separate VLANs.

D.

Link Aggregation Control Protocol is not synchronized.

Question 7

You have configured a new site-to-site VPN tunnel. The exhibit shows the security IPsec statistics output for the specific tunnel index from one of the tunnel-end devices.

as

Which two statements are correct in this scenario? (Choose two.)

Options:

A.

AH is incorrectly configured.

B.

The far-end tunnel device is rebooting.

C.

The ESP configuration is not set up correctly.

D.

No traffic passes through this tunnel.

Question 8

Which IDP action is also referred to as a silent discard?

Options:

A.

no action

B.

close client and server

C.

ignore connection

D.

drop packet

Question 9

You want to include a custom attack object named Custom-FTP-Attack and set the action to drop the packet.

as

Referring to the exhibit, which modifications would you make?

Options:

A.

Add custom-attack Custom-FTP-Attack to the attacks section and change the action to close-client.

B.

Add custom-attack Custom-FTP-Attack to the attacks section and change the action to drop-packet.

C.

Add custom-attack Custom-FTP-Attack to the action section and change the action to drop-packet.

D.

Add custom-attack Custom-FTP-Attack to the notification section and change the action to drop-packet.

Question 10

Which two statements about proxy IDs are correct? (Choose two.)

Options:

A.

Proxy IDs cannot override default Junos behavior.

B.

By default, for a route-based IPsec VPN, a Junos security device sets the proxy ID to 0.0.0.0/0.

C.

Proxy IDs must match on both peers for a Phase 2 tunnel to establish.

D.

Proxy IDs are created during IKE Phase 1.

Question 11

You are asked to onboard an SRX Series device to Junos Space Security Director, but it is not working.

In this scenario, what are three areas that should be reviewed? (Choose three.)

Options:

A.

chassis serial number

B.

SSH port number

C.

active security policies

D.

authentication credentials

E.

IP address

Question 12

Referring to the exhibit, what should you do to ensure that Juniper ATP Cloud detects malware in HTTPS traffic?

as

Options:

A.

Manually configure and apply an SSL proxy profile.

B.

Lower the threat score.

C.

Configure a new device profile that includes encrypted traffic.

D.

Change the action to redirect the encrypted traffic to a decryption device.

Question 13

Which two statements are correct about IDP policy templates? (Choose two.)

Options:

A.

They are provided by Juniper Networks.

B.

They are not customizable.

C.

They are available on a “factory-default config.”

D.

They must be installed.

Question 14

Which two statements are correct about cluster components? (Choose two.)

Options:

A.

Cluster ID values range from 1 through 255.

B.

Node ID values are either 0 or 1.

C.

Cluster ID values are either 0 or 1.

D.

Node ID values range from 1 through 255.

Question 15

Which action will the SRX Series device take if traffic matches the custom attack object shown in the exhibit?

as

Options:

A.

the action taken is defined in the IDP policy that includes this attack object.

B.

the action taken is defined by the security policy.

C.

The SRX Series device will reject the traffic.

D.

The SRX series device will drop the traffic.

Question 16

Which two statements about PC probes sent by the JIMS server are correct? (Choose two.)

Options:

A.

PC probes are triggered only when there is no IP-to-username mapping present in the event log.

B.

PC probes are sent by the JIMS server to domain PCs every 30 seconds.

C.

PC probes are sent by the JIMS server to domain PCs every 60 seconds.

D.

If a probe is successful, the authentication entry is updated on the JIMS server and pushed to the SRX.

Question 17

What are two ways to help reduce false positives for an IDP rule? (Choose two.)

Options:

A.

Change the rule to a lower severity action.

B.

Remove the attack object from the rule.

C.

Create an exempt rule.

D.

Configure a terminal rule at the end of the rule base.

Question 18

Using Junos Space Security Director, you want to configure a unique firewall policy for a specific SRX Series device.

Which firewall policy rules would satisfy the requirement?

Options:

A.

all devices policy prerules

B.

group policy prerules

C.

device policy rules

D.

all devices policy postrules

Question 19

Which two statements are correct about Juniper Secure Connect? (Choose two.)

Options:

A.

Juniper Secure Connect uses a policy-based VPN.

B.

Juniper Secure Connect can use a self-signed certificate.

C.

Juniper Secure Connect uses a route-based VPN.

D.

Juniper Secure Connect cannot use a self-signed certificate.

Page: 1 / 7
Total 66 questions