Month End Sale Special - 75% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 75only

Juniper JN0-336 Security, Specialist (JNCIS-SEC) Exam Practice Test

Demo: 20 questions
Total 68 questions

Security, Specialist (JNCIS-SEC) Questions and Answers

Question 1

What is a function of the Juniper Identity Management Service?

Options:

A.

encrypting user e-mail

B.

logging malicious code sent through ingress and egress ports

C.

encrypting network data traffic

D.

maintaining a centralized authentication table

Question 2

Which SRX Series device configuration setting must be configured first to use Juniper ATP Cloud?

Options:

A.

Start up the anti-malware service on the SRX Series device.

B.

Apply the firewall rules on the SRX Series device.

C.

Enable connectivity between the SRX Series device and Juniper ATP Cloud.

D.

Configure the anti-malware policies on the SRX Series device.

Question 3

You want to configure a reth interface.

Which two actions are required to accomplish this task? (Choose two.)

Options:

A.

Member interfaces can be of different speeds.

B.

Member interfaces must all be of the same media type.

C.

Member interfaces must all be the same speed.

D.

Member interfaces can be of different media types.

Question 4

Which rule base in an IDP policy is used to eliminate false positives?

Options:

A.

IPS

B.

monitor

C.

signature

D.

exempt

Question 5

Which two statements are correct about the security associations of an IPsec VPN? (Choose two.)

Options:

A.

IPsec security associations are established during IKEv1 Phase 2 negotiations.

B.

IKEv1 security associations are established during IKEv1 Phase 2 negotiations.

C.

IPsec security associations are established during IKEv1 Phase 1 negotiations.

D.

IKEv1 security associations are established during IKEv1 Phase 1 negotiations.

Question 6

What are two ways to help reduce false positives for an IDP rule? (Choose two.)

Options:

A.

Change the rule to a lower severity action.

B.

Remove the attack object from the rule.

C.

Create an exempt rule.

D.

Configure a terminal rule at the end of the rule base.

Question 7

Which three algorithms are used to encrypt IP packets? (Choose three.)

Options:

A.

Data Encryption Standard (DES)

B.

Secure Hash Algorithm (SHA) - 1

C.

Message Digest 5 (MD5)

D.

Triple Data Encryption Standard (3DES)

E.

Advanced Encryption Standard (AES)

Question 8

Which action will the SRX Series device take if traffic matches the custom attack object shown in the exhibit?

Options:

A.

the action taken is defined in the IDP policy that includes this attack object.

B.

the action taken is defined by the security policy.

C.

The SRX Series device will reject the traffic.

D.

The SRX series device will drop the traffic.

Question 9

Which IDP action is also referred to as a silent discard?

Options:

A.

no action

B.

close client and server

C.

ignore connection

D.

drop packet

Question 10

What are two types of attack objects included in an IDP attack object database? (Choose two.)

Options:

A.

statistic-based

B.

protocol anomaly-based

C.

signature-based

D.

vector-based

Question 11

Regarding static attack object groups, which two statements are true? (Choose two.)

Options:

A.

Matching attack objects are automatically added to a custom group.

B.

Group membership automatically changes when Juniper updates the IPS signature database.

C.

Group membership does not automatically change when Juniper updates the IPS signature database.

D.

You must manually add matching attack objects to a custom group.

Question 12

Referring to the exhibit, which two statements are correct? (Choose two.)

Options:

A.

Fabric link 0 is working.

B.

The control link is working.

C.

Fabric link 1 is failing.

D.

The control link is failing.

Question 13

Using Junos Space Security Director, you want to configure a unique firewall policy for a specific SRX Series device.

Which firewall policy rule would satisfy the requirement?

Options:

A.

all devices policy prerules

B.

group policy prerules

C.

device policy rules

D.

all devices policy postrules

Question 14

How does the SSL proxy service identify SSL traffic?

Options:

A.

by examining the URL

B.

by using AppID results

C.

by examining the destination port

D.

by reading the server certificate

Question 15

You need to secure communications from a mobile command center which uses a 5G mobile ISP behind CGNAT to an SRX Series Firewall at headquarters.

Which two actions should be performed on the SRX Series Firewall in this scenario? (Choose two.)

Options:

A.

Configure the IPsec VPN to use NAT-T.

B.

Configure the IPsec VPN to use IKEv1 aggressive mode.

C.

Configure the IPsec VPN to use IKEv2 aggressive mode.

D.

Configure the IPsec VPN to use DPD.

Question 16

Which three actions does Junos Space Security Director perform during the device discovery process? (Choose three.)

Options:

A.

It imports the device’s active device configuration.

B.

it reboots the device.

C.

It imports device status information.

D.

It adds a local superuser account to the device configuration.

E.

It connects to the device using SSH.

Question 17

Which two statements accurately describe the role of hashing in VPNs? (Choose two.)

Options:

A.

Hashing compresses data in VPN communications.

B.

Hashing generates a fixed-size string of characters.

C.

Hashing encrypts data to ensure confidentiality.

D.

Hashing verifies that data has not been altered during transmission.

Question 18

You have configured a new site-to-site VPN tunnel. The exhibit shows the security IPsec statistics output for the specific tunnel index from one of the tunnel-end devices.

Which two statements are correct in this scenario? (Choose two.)

Options:

A.

AH is incorrectly configured.

B.

The far-end tunnel device is rebooting.

C.

The ESP configuration is not set up correctly.

D.

No traffic passes through this tunnel.

Question 19

Which two statements are correct about a chassis cluster? (Choose two.)

Options:

A.

If the cluster ID is set to 0, the HA configuration is ignored.

B.

You must reboot the device anytime you change the node ID configuration.

C.

If the node ID is set to 0, the HA configuration is ignored.

D.

You must have multiple Layer 2 domains if you require more than 255 node IDs.

Question 20

You are asked to ensure that traffic that matches an IDP policy is not impacted until administrators have a chance to evaluate it.

In this scenario, which IP action should be configured for the policy?

Options:

A.

ip-block

B.

ip-notify

C.

ip-connection-rate-limit

D.

ip-close

Demo: 20 questions
Total 68 questions