Pre-Winter Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: cramtick70

JN0-336 Security, Specialist (JNCIS-SEC) Questions and Answers

Questions 4

Which two statements are correct about fabric interfaces on an SRX Series Firewall? (Choose two.)

Options:

A.

In an active/active configuration, inter-chassis traffic uses the fab link.

B.

In an active/passive configuration, inter-chassis traffic uses the fab link.

C.

The node ID is reflected in the fabric interface name.

D.

The cluster ID is reflected in the fabric interface name.

Buy Now
Questions 5

You need to secure communications from a mobile command center which uses a 5G mobile ISP behind CGNAT to an SRX Series Firewall at headquarters.

Which two actions should be performed on the SRX Series Firewall in this scenario? (Choose two.)

Options:

A.

Configure the IPsec VPN to use NAT-T.

B.

Configure the IPsec VPN to use IKEv1 aggressive mode.

C.

Configure the IPsec VPN to use IKEv2 aggressive mode.

D.

Configure the IPsec VPN to use DPD.

Buy Now
Questions 6

You want to configure a reth interface.

Which two actions are required to accomplish this task? (Choose two.)

Options:

A.

Member interfaces can be of different speeds.

B.

Member interfaces must all be of the same media type.

C.

Member interfaces must all be the same speed.

D.

Member interfaces can be of different media types.

Buy Now
Questions 7

What are two ways that Juniper Secure Connect provides flexibility in connection and authentication methods while ensuring that remote users are able to securely access company servers and cloud resources? (Choose two.)

Options:

A.

It uses a persistent agent.

B.

It uses Kerberos authentication.

C.

It uses external authentication.

D.

It uses an SSL VPN.

Buy Now
Questions 8

You are asked to onboard an SRX Series device to Junos Space Security Director, but it is not working.

In this scenario, what are three areas that should be reviewed? (Choose three.)

Options:

A.

chassis serial number

B.

SSH port number

C.

active security policies

D.

authentication credentials

E.

IP address

Buy Now
Questions 9

You are asked to use Junos Space Security Director to download the latest application signatures in the AppID database.

In this scenario, which two statements are correct? (Choose two.)

Options:

A.

The AppID database is stored in Junos Space Security Director.

B.

The AppID database is stored on the managed SRX Series device.

C.

The AppID database is maintained by a third-party host.

D.

The AppID database is stored on a local storage server in the management network.

Buy Now
Questions 10

What are two types of attack objects included in an IDP attack object database? (Choose two.)

Options:

A.

statistic-based

B.

protocol anomaly-based

C.

signature-based

D.

vector-based

Buy Now
Questions 11

Which two statements describe how Juniper ATP Cloud improves security? (Choose two.)

Options:

A.

It tracks and logs malicious traffic.

B.

It offers real-time threat analysis and mitigation.

C.

It simulates real user environments to trigger malicious code execution.

D.

It increases performance speeds.

Buy Now
Questions 12

Which two statements are correct about a chassis cluster? (Choose two.)

Options:

A.

If the cluster ID is set to 0, the HA configuration is ignored.

B.

You must reboot the device anytime you change the node ID configuration.

C.

If the node ID is set to 0, the HA configuration is ignored.

D.

You must have multiple Layer 2 domains if you require more than 255 node IDs.

Buy Now
Questions 13

Which rule base in an IDP policy is used to eliminate false positives?

Options:

A.

IPS

B.

monitor

C.

signature

D.

exempt

Buy Now
Questions 14

You are asked to ensure that traffic that matches an IDP policy is not impacted until administrators have a chance to evaluate it.

In this scenario, which IP action should be configured for the policy?

Options:

A.

ip-block

B.

ip-notify

C.

ip-connection-rate-limit

D.

ip-close

Buy Now
Questions 15

Which two statements are correct about the security associations of an IPsec VPN? (Choose two.)

Options:

A.

IPsec security associations are established during IKEv1 Phase 2 negotiations.

B.

IKEv1 security associations are established during IKEv1 Phase 2 negotiations.

C.

IPsec security associations are established during IKEv1 Phase 1 negotiations.

D.

IKEv1 security associations are established during IKEv1 Phase 1 negotiations.

Buy Now
Questions 16

What are two causes that end the processing of rules in IDP? (Choose two.)

Options:

A.

when a rule is matched in the rule base with an action of close

B.

when a terminal rule is matched in the rule base

C.

when any rule is matched in the exempt rule base

D.

when a rule is matched in the rule base with an action of ignore

Buy Now
Questions 17

Which three actions does Junos Space Security Director perform during the device discovery process? (Choose three.)

Options:

A.

It imports the device’s active device configuration.

B.

it reboots the device.

C.

It imports device status information.

D.

It adds a local superuser account to the device configuration.

E.

It connects to the device using SSH.

Buy Now
Questions 18

What is a function of the Juniper Identity Management Service?

Options:

A.

encrypting user e-mail

B.

logging malicious code sent through ingress and egress ports

C.

encrypting network data traffic

D.

maintaining a centralized authentication table

Buy Now
Questions 19

What are three policy types available in Junos Space Security Director? (Choose three.)

Options:

A.

device

B.

local

C.

group

D.

universal

E.

global

Buy Now
Questions 20

You are asked to configure your company SRX Series device to use identity-aware security policies. Information about your Active Directory network is shown in the exhibit.

In this scenario, why must you configure JIMS instead of Active Directory as an identity source?

Options:

A.

JIMS is the only way to get data from Active Directory.

B.

You have too many Active Directory users.

C.

The version of Windows OS is too old.

D.

You have too many domain controllers.

Buy Now
Exam Code: JN0-336
Exam Name: Security, Specialist (JNCIS-SEC)
Last Update: Sep 23, 2026
Questions: 68
JN0-336 pdf

JN0-336 PDF

$25.5  $84.99
JN0-336 Engine

JN0-336 Testing Engine

$30  $99.99
JN0-336 PDF + Engine

JN0-336 PDF + Testing Engine

$40.5  $134.99