Pre-Summer Sale Special - Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: mxmas70

Home > Juniper > JNCIS-SEC > JN0-336

JN0-336 Security, Specialist (JNCIS-SEC) Question and Answers

Question # 4

In Juniper high availability (HA) SRX Series device implementations, which interface will be used to exchange session state, configuration files, and ensure session continuity across nodes using the proprietary Trivial Network Protocol?

A.

fab

B.

fxp0

C.

fxp1

D.

swfab

Full Access
Question # 5

What are two ways that Juniper Secure Connect provides flexibility in connection and authentication methods while ensuring that remote users are able to securely access company servers and cloud resources? (Choose two.)

A.

It uses a persistent agent.

B.

It uses Kerberos authentication.

C.

It uses external authentication.

D.

It uses an SSL VPN.

Full Access
Question # 6

Which two statements are correct about Juniper ATP Cloud malware analysis? (Choose two.)

A.

If no match exists in cache, the remaining analysis features are processed with the cumulative threat score transmitted to the SRX Series device.

B.

If a match exists in cache, that threat score is sent to the SRX Series device and the analysis continues.

C.

If a match exists in cache, that threat score is sent to the SRX Series device and the analysis stops.

D.

If no match exists in cache, the first analysis feature to generate a threat score is transmitted to the SRX Series device.

Full Access
Question # 7

You are establishing an IPsec VPN and must ensure that payload data is encrypted.

In this scenario, which IPsec security protocol should you configure?

A.

SHA-1

B.

ESP

C.

AH

D.

PFS

Full Access
Question # 8

Referring to the exhibit, which two statements are correct? (Choose two.)

A.

IP address 192.168.1.10 is the SRX Series device.

B.

IP address 192.168.1.10 is the primary JIMS server.

C.

The JIMS server to the domain controller connection is online.

D.

The SRX Series device to the JIMS connection is online.

Full Access
Question # 9

How does the SSL proxy detect if a particular session is SSL encrypted?

A.

It uses AppID services.

B.

It verifies the length of the packet.

C.

It looks at the destination port number.

D.

It uses a certificate authority (CA).

Full Access
Question # 10

You are configuring a redundancy group using Ethernet interfaces.

In this scenario, which two actions must be performed? (Choose two.)

A.

Assign a physical interface from each node to the reth0 interface.

B.

Set the retry interval

C.

Define the number of reth interfaces in a cluster under the chassis cluster hierarchy.

D.

Configure the heartbeat interval.

Full Access
Question # 11

Which two statements describe how Juniper ATP Cloud improves security? (Choose two.)

A.

It tracks and logs malicious traffic.

B.

It offers real-time threat analysis and mitigation.

C.

It simulates real user environments to trigger malicious code execution.

D.

It increases performance speeds.

Full Access
Question # 12

Which two statements are correct about client-protection Secure Socket Layer (SSL) proxy configurations? (Choose two.)

A.

Server certificate is required.

B.

Root certificate authority (CA) configuration is required.

C.

Root certificate authority (CA) configuration is not required.

D.

Server certificate is not required.

Full Access
Question # 13

When using Adaptive Threat Profiling, which two deployment modes are available on SRX Series devices? (Choose two.)

A.

bridge

B.

inline

C.

tap

D.

promiscuous

Full Access
Question # 14

Referring to the exhibit, what should you do to ensure that Juniper ATP Cloud detects malware in HTTPS traffic?

A.

Manually configure and apply an SSL proxy profile.

B.

Lower the threat score.

C.

Configure a new device profile that includes encrypted traffic.

D.

Change the action to redirect the encrypted traffic to a decryption device.

Full Access
Question # 15

Which two steps are necessary to prepare the Active Directory domain for a JIMS installation? (Choose two.)

A.

Create two limited access user accounts.

B.

Create three limited access user accounts.

C.

Add one full access user account to Active Directory groups.

D.

Add limited access user accounts to Active Directory groups.

Full Access
Question # 16

You are asked to onboard an SRX Series device to Junos Space Security Director, but it is not working.

In this scenario, what are three areas that should be reviewed? (Choose three.)

A.

chassis serial number

B.

SSH port number

C.

active security policies

D.

authentication credentials

E.

IP address

Full Access
Question # 17

Which two services would an SRX Series device use to connect to an LDAP server for identity-aware security policies? (Choose two.)

A.

Active Directory

B.

TACACS+

C.

RADIUS

D.

JIMS

Full Access
Question # 18

Regarding static attack object groups, which two statements are true? (Choose two.)

A.

Matching attack objects are automatically added to a custom group.

B.

Group membership automatically changes when Juniper updates the IPS signature database.

C.

Group membership does not automatically change when Juniper updates the IPS signature database.

D.

You must manually add matching attack objects to a custom group.

Full Access
Question # 19

What are two causes that end the processing of rules in IDP? (Choose two.)

A.

when a rule is matched in the rule base with an action of close

B.

when a terminal rule is matched in the rule base

C.

when any rule is matched in the exempt rule base

D.

when a rule is matched in the rule base with an action of ignore

Full Access