Summer Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70percent

Juniper JN0-336 Security, Specialist (JNCIS-SEC) Exam Practice Test

Demo: 19 questions
Total 66 questions

Security, Specialist (JNCIS-SEC) Questions and Answers

Question 1

An administrator decides to designate a node as the primary node for the chassis cluster.

Which statement is correct in this scenario?

Options:

A.

Configure the burnt-in-address (BIA) to the highest value to bring the node as the primary node.

B.

The node with the highest priority will become a primary node.

C.

The node with the lowest priority will become a primary node.

D.

Nodes with a priority of one are ineligible to participate in the election process.

Question 2

You want to configure the SSL proxy feature on your SRX Series Firewall.

Which two actions must you perform to accomplish this task? (Choose two.)

Options:

A.

Enable the SSL ALG.

B.

Create an SSL proxy profile.

C.

Create an SSL application object.

D.

Associate an SSL proxy profile with a security policy.

Question 3

Using Junos Space Security Director, you want to configure a unique firewall policy for a specific SRX Series device.

Which firewall policy rules would satisfy the requirement?

Options:

A.

all devices policy prerules

B.

group policy prerules

C.

device policy rules

D.

all devices policy postrules

Question 4

You are configuring a redundancy group using Ethernet interfaces.

In this scenario, which two actions must be performed? (Choose two.)

Options:

A.

Assign a physical interface from each node to the reth0 interface.

B.

Set the retry interval

C.

Define the number of reth interfaces in a cluster under the chassis cluster hierarchy.

D.

Configure the heartbeat interval.

Question 5

Which two statements are correct about fabric interfaces on an SRX Series Firewall? (Choose two.)

Options:

A.

In an active/active configuration, inter-chassis traffic uses the fab link.

B.

In an active/passive configuration, inter-chassis traffic uses the fab link.

C.

The node ID is reflected in the fabric interface name.

D.

The cluster ID is reflected in the fabric interface name.

Question 6

Which two steps are necessary to prepare the Active Directory domain for a JIMS installation? (Choose two.)

Options:

A.

Create two limited access user accounts.

B.

Create three limited access user accounts.

C.

Add one full access user account to Active Directory groups.

D.

Add limited access user accounts to Active Directory groups.

Question 7

What are two chassis cluster data plane interfaces? (Choose two.)

Options:

A.

swfab

B.

fab

C.

fxp1

D.

fxp0

Question 8

You are asked to configure a cluster between SRX1 and SRX2.

Which two commands must be used to accomplish this task? (Choose two.)

Options:

A.

user@SRX2# set chassis cluster cluster-id 0 node 1

B.

user@SRX1 > set chassis cluster cluster-id 1 node 0

C.

user@SRX2 > set chassis cluster cluster-id 1 node 1

D.

user@SRX1# set chassis cluster cluster-id 0 node 2

Question 9

You have configured a new site-to-site VPN tunnel. The exhibit shows the security IPsec statistics output for the specific tunnel index from one of the tunnel-end devices.

Which two statements are correct in this scenario? (Choose two.)

Options:

A.

AH is incorrectly configured.

B.

The far-end tunnel device is rebooting.

C.

The ESP configuration is not set up correctly.

D.

No traffic passes through this tunnel.

Question 10

You are asked to onboard an SRX Series device to Junos Space Security Director, but it is not working.

In this scenario, what are three areas that should be reviewed? (Choose three.)

Options:

A.

chassis serial number

B.

SSH port number

C.

active security policies

D.

authentication credentials

E.

IP address

Question 11

Which SRX Series device configuration setting must be configured first to use Juniper ATP Cloud?

Options:

A.

Start up the anti-malware service on the SRX Series device.

B.

Apply the firewall rules on the SRX Series device.

C.

Enable connectivity between the SRX Series device and Juniper ATP Cloud.

D.

Configure the anti-malware policies on the SRX Series device.

Question 12

You need to deploy an SRX Series device in your virtual environment.

In this scenario, what are two benefits of using a CSRX? (Choose two.)

Options:

A.

The cSRX supports Layer 2 and Layer 3 deployments.

B.

The cSRX default configuration contains three default zones: trust, untrust, and management.

C.

The cSRX supports firewall, NAT, IPS, and UTM services.

D.

The cSRX has low memory requirements.

Question 13

In Juniper high availability (HA) SRX Series device implementations, which interface will be used to exchange session state, configuration files, and ensure session continuity across nodes using the proprietary Trivial Network Protocol?

Options:

A.

fab

B.

fxp0

C.

fxp1

D.

swfab

Question 14

Which protocol does the SRX Series Firewall use to communicate with a Windows domain controller?

Options:

A.

SSH

B.

LDAP

C.

DNS

D.

NETCONF

Question 15

How does the SSL proxy detect if a particular session is SSL encrypted?

Options:

A.

It uses AppID services.

B.

It verifies the length of the packet.

C.

It looks at the destination port number.

D.

It uses a certificate authority (CA).

Question 16

What are two ways to help reduce false positives for an IDP rule? (Choose two.)

Options:

A.

Change the rule to a lower severity action.

B.

Remove the attack object from the rule.

C.

Create an exempt rule.

D.

Configure a terminal rule at the end of the rule base.

Question 17

Referring to the exhibit, which two statements are correct? (Choose two.)

Options:

A.

IP address 192.168.1.10 is the SRX Series device.

B.

IP address 192.168.1.10 is the primary JIMS server.

C.

The JIMS server to the domain controller connection is online.

D.

The SRX Series device to the JIMS connection is online.

Question 18

Which statement is correct about Active Directory as an identity source for identity-aware security policies?

Options:

A.

It supports a maximum of two domains.

B.

It supports logical systems.

C.

It supports 20 Active Directory servers per domain.

D.

It tracks non-Windows Active Directory users.

Question 19

When using Adaptive Threat Profiling, which two deployment modes are available on SRX Series devices? (Choose two.)

Options:

A.

bridge

B.

inline

C.

tap

D.

promiscuous

Demo: 19 questions
Total 66 questions