Summer Certification Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: cramtick70

JN0-336 Security, Specialist (JNCIS-SEC) Questions and Answers

Questions 4

Which two statements about proxy IDs are correct? (Choose two.)

Options:

A.

Proxy IDs cannot override default Junos behavior.

B.

By default, for a route-based IPsec VPN, a Junos security device sets the proxy ID to 0.0.0.0/0.

C.

Proxy IDs must match on both peers for a Phase 2 tunnel to establish.

D.

Proxy IDs are created during IKE Phase 1.

Buy Now
Questions 5

What are three policy types available in Junos Space Security Director? (Choose three.)

Options:

A.

device

B.

local

C.

group

D.

universal

E.

global

Buy Now
Questions 6

You need to set up a forward proxy on your SRX Series device.

In this scenario, which two statements are correct? (Choose two.)

Options:

A.

The forward proxy uses the managed SRX as a trusted certificate authority (CA).

B.

The forward proxy forwards the server certificate.

C.

The forward proxy looks like a client to the servers to which it communicates.

D.

The forward proxy uses Encrypted Traffic Insights to monitor traffic.

Buy Now
Questions 7

What are two types of attack objects included in an IDP attack object database? (Choose two.)

Options:

A.

statistic-based

B.

protocol anomaly-based

C.

signature-based

D.

vector-based

Buy Now
Questions 8

Which protocol does the SRX Series Firewall use to communicate with a Windows domain controller?

Options:

A.

SSH

B.

LDAP

C.

DNS

D.

NETCONF

Buy Now
Questions 9

Which two statements are correct about the security associations of an IPsec VPN? (Choose two.)

Options:

A.

IPsec security associations are established during IKEv1 Phase 2 negotiations.

B.

IKEv1 security associations are established during IKEv1 Phase 2 negotiations.

C.

IPsec security associations are established during IKEv1 Phase 1 negotiations.

D.

IKEv1 security associations are established during IKEv1 Phase 1 negotiations.

Buy Now
Questions 10

Which two statements describe how Juniper ATP Cloud improves security? (Choose two.)

Options:

A.

It tracks and logs malicious traffic.

B.

It offers real-time threat analysis and mitigation.

C.

It simulates real user environments to trigger malicious code execution.

D.

It increases performance speeds.

Buy Now
Questions 11

Your manager asks you to update your SRX Series device’s IDP security package. You perform the required steps; however, when you attempt to install the package, you receive an error.

Referring to the exhibit, which two statements are correct about this error? (Choose two.)

Options:

A.

IDP stops inspecting traffic.

B.

The IDP license has expired.

C.

IDP continues to inspect traffic only using the installed signatures.

D.

The IDP license is missing/not installed.

Buy Now
Questions 12

Which rule base in an IDP policy is used to eliminate false positives?

Options:

A.

IPS

B.

monitor

C.

signature

D.

exempt

Buy Now
Questions 13

Regarding static attack object groups, which two statements are true? (Choose two.)

Options:

A.

Matching attack objects are automatically added to a custom group.

B.

Group membership automatically changes when Juniper updates the IPS signature database.

C.

Group membership does not automatically change when Juniper updates the IPS signature database.

D.

You must manually add matching attack objects to a custom group.

Buy Now
Questions 14

A pair of branch SRX Series devices are booted up in cluster mode.

Referring to the exhibit, which statement is correct?

Options:

A.

the devices are not running the same version of Junos.

B.

the devices are not the same hardware.

C.

fxp0 or fxp1 on either device has an existing configuration.

D.

node1 is running a " factory-default config " .

Buy Now
Questions 15

Which statement is correct about Active Directory as an identity source for identity-aware security policies?

Options:

A.

It supports a maximum of two domains.

B.

It supports logical systems.

C.

It supports 20 Active Directory servers per domain.

D.

It tracks non-Windows Active Directory users.

Buy Now
Questions 16

When using Adaptive Threat Profiling, which two deployment modes are available on SRX Series devices? (Choose two.)

Options:

A.

bridge

B.

inline

C.

tap

D.

promiscuous

Buy Now
Questions 17

Which two statements are correct about Juniper Secure Connect? (Choose two.)

Options:

A.

Juniper Secure Connect uses a policy-based VPN.

B.

Juniper Secure Connect can use a self-signed certificate.

C.

Juniper Secure Connect uses a route-based VPN.

D.

Juniper Secure Connect cannot use a self-signed certificate.

Buy Now
Questions 18

You are asked to configure a cluster between SRX1 and SRX2.

Which two commands must be used to accomplish this task? (Choose two.)

Options:

A.

user@SRX2# set chassis cluster cluster-id 0 node 1

B.

user@SRX1 > set chassis cluster cluster-id 1 node 0

C.

user@SRX2 > set chassis cluster cluster-id 1 node 1

D.

user@SRX1# set chassis cluster cluster-id 0 node 2

Buy Now
Questions 19

What are two chassis cluster data plane interfaces? (Choose two.)

Options:

A.

swfab

B.

fab

C.

fxp1

D.

fxp0

Buy Now
Exam Code: JN0-336
Exam Name: Security, Specialist (JNCIS-SEC)
Last Update: Aug 9, 2026
Questions: 66
JN0-336 pdf

JN0-336 PDF

$25.5  $84.99
JN0-336 Engine

JN0-336 Testing Engine

$30  $99.99
JN0-336 PDF + Engine

JN0-336 PDF + Testing Engine

$40.5  $134.99