Spring Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: save70

Free and Premium Juniper JN0-336 Dumps Questions Answers

Page: 1 / 5
Total 66 questions

Security, Specialist (JNCIS-SEC) Questions and Answers

Question 1

How does the SSL proxy service identify SSL traffic?

Options:

A.

by examining the URL

B.

by using AppID results

C.

by examining the destination port

D.

by reading the server certificate

Buy Now
Question 2

Which two steps are necessary to prepare the Active Directory domain for a JIMS installation? (Choose two.)

Options:

A.

Create two limited access user accounts.

B.

Create three limited access user accounts.

C.

Add one full access user account to Active Directory groups.

D.

Add limited access user accounts to Active Directory groups.

Question 3

Using Junos Space Security Director, you want to configure a unique firewall policy for a specific SRX Series device.

Which firewall policy rule would satisfy the requirement?

Options:

A.

all devices policy prerules

B.

group policy prerules

C.

device policy rules

D.

all devices policy postrules

Question 4

What are two ways that Juniper Secure Connect provides flexibility in connection and authentication methods while ensuring that remote users are able to securely access company servers and cloud resources? (Choose two.)

Options:

A.

It uses a persistent agent.

B.

It uses Kerberos authentication.

C.

It uses external authentication.

D.

It uses an SSL VPN.

Question 5

You want to use user identity information to secure your network.

Which two actions must you perform on your SRX Series Firewall to accomplish this task? (Choose two.)

Options:

A.

Create security policies that include user identity configuration

B.

Add user accounts to the Active Directory Domain Users group

C.

Configure an identity provider on your SRX Series Firewall.

D.

Add the user identity feature license to your SRX Series Firewall.

Question 6

You are asked to set up SSL proxy in SRX Series devices. An SSL proxy profile is already defined for you.

Which two steps are required to complete the setup? (Choose two.)

Options:

A.

Enable host-inbound-traffic HTTPS in the security zone in which SSL proxy is referenced.

B.

Reference the SSL proxy profile in a security zone.

C.

Reference the SSL proxy profile in a security policy.

D.

Enable any Layer 7 services in the security policy in which SSL proxy is referenced.

Question 7

Which two statements are correct about fabric interfaces on an SRX Series Firewall? (Choose two.)

Options:

A.

In an active/active configuration, inter-chassis traffic uses the fab link.

B.

In an active/passive configuration, inter-chassis traffic uses the fab link.

C.

The node ID is reflected in the fabric interface name.

D.

The cluster ID is reflected in the fabric interface name.

Question 8

What are two properties negotiated during IKE Phase 2? (Choose two.)

Options:

A.

routing protocol

B.

tunneling protocol

C.

aggressive mode

D.

Perfect Forward Secrecy

Question 9

Which SRX Series device configuration setting must be configured first to use Juniper ATP Cloud?

Options:

A.

Start up the anti-malware service on the SRX Series device.

B.

Apply the firewall rules on the SRX Series device.

C.

Enable connectivity between the SRX Series device and Juniper ATP Cloud.

D.

Configure the anti-malware policies on the SRX Series device.

Question 10

Which two statements are correct about redundant fabric interfaces in a chassis cluster? (Choose two.)

Options:

A.

fab0 and fab1 are located on both node0 and node1.

B.

fab0 is located on node0, whereas fab1 is located on node1.

C.

The media type must be the same for each redundant fabric interface.

D.

The media type can be different for each redundant fabric interface.

Question 11

Your manager asks you to update your SRX Series device’s IDP security package. You perform the required steps; however, when you attempt to install the package, you receive an error.

Referring to the exhibit, which two statements are correct about this error? (Choose two.)

Options:

A.

IDP stops inspecting traffic.

B.

The IDP license has expired.

C.

IDP continues to inspect traffic only using the installed signatures.

D.

The IDP license is missing/not installed.

Question 12

How does the SSL proxy detect if a particular session is SSL encrypted?

Options:

A.

It uses AppID services.

B.

It verifies the length of the packet.

C.

It looks at the destination port number.

D.

It uses a certificate authority (CA).

Question 13

Using Junos Space Security Director, you want to configure a unique firewall policy for a specific SRX Series device.

Which firewall policy rules would satisfy the requirement?

Options:

A.

all devices policy prerules

B.

group policy prerules

C.

device policy rules

D.

all devices policy postrules

Question 14

Which two statements are correct about a chassis cluster? (Choose two.)

Options:

A.

If the cluster ID is set to 0, the HA configuration is ignored.

B.

You must reboot the device anytime you change the node ID configuration.

C.

If the node ID is set to 0, the HA configuration is ignored.

D.

You must have multiple Layer 2 domains if you require more than 255 node IDs.

Question 15

What are two causes that end the processing of rules in IDP? (Choose two.)

Options:

A.

when a rule is matched in the rule base with an action of close

B.

when a terminal rule is matched in the rule base

C.

when any rule is matched in the exempt rule base

D.

when a rule is matched in the rule base with an action of ignore

Question 16

You are asked to ensure that traffic that matches an IDP policy is not impacted until administrators have a chance to evaluate it.

In this scenario, which IP action should be configured for the policy?

Options:

A.

ip-block

B.

ip-notify

C.

ip-connection-rate-limit

D.

ip-close

Question 17

You are asked to configure your company SRX Series device to use identity-aware security policies. Information about your Active Directory network is shown in the exhibit.

In this scenario, why must you configure JIMS instead of Active Directory as an identity source?

Options:

A.

JIMS is the only way to get data from Active Directory.

B.

You have too many Active Directory users.

C.

The version of Windows OS is too old.

D.

You have too many domain controllers.

Question 18

What are three policy types available in Junos Space Security Director? (Choose three.)

Options:

A.

device

B.

local

C.

group

D.

universal

E.

global

Question 19

Which two statements are correct about Juniper Secure Connect? (Choose two.)

Options:

A.

Juniper Secure Connect uses a policy-based VPN.

B.

Juniper Secure Connect can use a self-signed certificate.

C.

Juniper Secure Connect uses a route-based VPN.

D.

Juniper Secure Connect cannot use a self-signed certificate.

Page: 1 / 5
Total 66 questions