JN0-336 Exam Questions
103 real JN0-336 exam questions with expert-verified answers and explanations. Page 1 of 3.
- Question #1Juniper Advanced Threat Prevention (ATP)
A client has attempted communication with a known command-and-control server and it has reached the configured threat level threshold. Which feed will the clients IP address be aut...
command-and-controlinfected host feedthreat level thresholdATP Cloud - Question #2SSL Proxy
Exhibit When trying to set up a server protection SSL proxy, you receive the error shown. What are two reasons for this error? (Choose two.)
SSL proxyserver protectionproxy certificatecertificate configuration - Question #3Identity-Aware Security Policies
You are asked to reduce the load that the JIMS server places on your Which action should you take in this situation?
JIMSidentity managementserver loadSRX integration - Question #4Security Zones, Policies, and Objects
Exhibit You are trying to create a security policy on your SRX Series device that permits HTTP traffic from your private 172 25.11.0/24 subnet to the Internet You create a policy n...
security policycommit errorapplication definitionJunos-http - Question #5SRX Series Devices and Packet Flow
What are two types of system logs that Junos generates? (Choose two.)
system logsdata plane logscontrol plane logsJunos logging - Question #6SRX Series Devices and Packet Flow
You are asked to ensure that if the session table on your SRX Series device gets close to exhausting its resources, that you enforce a more aggress.ve age-out of existing flows. In...
session tableearly ageouthigh watermarkflow management - Question #7SSL Proxy
Exhibit Referring to the exhibit which statement is true?
SSL proxypre-matchpost-matchsession matching - Question #8Security Zones, Policies, and Objects
When a security policy is deleted, which statement is correct about the default behavior of active sessions allowed by that policy?
security policyactive sessionslegacy flowpolicy deletion - Question #9Application Security
You want to use IPS signatures to monitor traffic. Which module in the AppSecure suite will help in this task?
AppSecureAppFWIPS signaturesapplication monitoring - Question #10High Availability (HA) Clustering
Exhibit Using the information from the exhibit, which statement is correct?
chassis clusterredundancy groupcluster statusHA monitoring - Question #11Additional Security Services
After JSA receives external events and flows, which two steps occur? (Choose two.)
JSAevent processingflow analysisdata formatting - Question #12Juniper Advanced Threat Prevention (ATP)
Your company is using the Juniper ATP Cloud free model. The current inspection profile is set at 10 MB You are asked to configure ATP Cloud so that executable files up to 30 MB can...
ATP Cloudinspection profilefile scan limitexecutable files - Question #13SRX Series Devices and Packet Flow
What are two benefits of using a vSRX in a software-defined network? (Choose two.)
vSRXSDNscalabilityvirtual firewall - Question #14High Availability (HA) Clustering
You enable chassis clustering on two devices and assign a cluster ID and a node ID to each device. In this scenario, what is the correct order for rebooting the devices?
chassis clusteringcluster IDnode IDreboot sequence - Question #15Identity-Aware Security Policies
Exhibit Referring to the exhibit, which two statements are true? (Choose two.)
Active Directoryuser authenticationdomain controlleridentity mapping - Question #16High Availability (HA) Clustering
Which three statements about SRX Series device chassis clusters are true? (Choose three.)
chassis clustercontrol linkheartbeatconfiguration synchronization - Question #17Security Director
Which two devices would you use for DDoS protection with Policy Enforcer? (Choose two.)
DDoS protectionPolicy Enforcernetwork enforcementQFX MX devices - Question #18High Availability (HA) Clustering
You have implemented a vSRX in your VMware environment. You want to implement a second vSRX Series device and enable chassis clustering. Which two statements are correct in this sc...
vSRXVMwarechassis clusteringvSwitch configuration - Question #19High Availability (HA) Clustering
Which two statements are true about the fab interface in a chassis cluster? (Choose two.)
fab linkfabric interfacechassis clusterHA configuration - Question #20High Availability (HA) Clustering
You want to manually failover the primary Routing Engine in an SRX Series high availability cluster pair. Which step is necessary to accomplish this task?
HA failoverRouting Enginemanual failoverchassis cluster - Question #21SSL Proxy
How does the SSL proxy detect if encryption is being used?
SSL proxyencryption detectiondestination portpacket inspection - Question #22SSL Proxy
Which two types of SSL proxy are available on SRX Series devices? (Choose two.)
SSL proxy typesclient-protectionserver-protectionSRX - Question #23Application Security
What are three capabilities of AppQoS? (Choose three.)
AppQoSDSCP rewriteforwarding classrate limiting - Question #24Juniper Advanced Threat Prevention (ATP)
You are asked to find systems running applications that increase the risks on your network. You must ensure these systems are processed through IPS and Juniper ATP Cloud for malwar...
Adaptive Threat ProfilingIPSATP Cloudmalware detection - Question #25Security Zones, Policies, and Objects
Which statement about security policy schedulers is correct?
security policyschedulertime-based policypolicy activation - Question #26Application Security
Exhibit Referring to the SRX Series flow module diagram shown in the exhibit, where is application security processed?
SRX flow moduleapplication securitypacket flowServices ALGs - Question #27Juniper Advanced Threat Prevention (ATP)
What information does encrypted traffic insights (ETI) use to notify SRX Series devices about known malware sites?
Encrypted Traffic InsightsETImalware sitesdomain names - Question #28SRX Series Devices and Packet Flow
Your manager asks you to provide firewall and NAT services in a private cloud. Which two solutions will fulfill the minimum requirements for this deployment? (Choose two.)
vSRXcSRXprivate cloudvirtualized firewall - Question #29SRX Series Devices and Packet Flow
You want to deploy a virtualized SRX in your environment. In this scenario, why would you use a vSRX instead of a cSRX? (Choose two.)
vSRXcSRXvirtualizationLayer 2 Layer 3 - Question #30Intrusion Detection and Prevention (IDP)
Regarding static attack object groups, which two statements are true? (Choose two.)
IPSstatic attack object groupscustom groupsignature database - Question #31Identity-Aware Security Policies
Which statement regarding Juniper Identity Management Service (JIMS) domain PC probes is true?
JIMSdomain PC probesusername to IP mappingidentity management - Question #32Application Security
Exhibit Which two statements are correct about the configuration shown in the exhibit? (Choose two.)
AppTracksession loggingapplication trackingsession-init - Question #33SRX Series Devices and Packet Flow
Which two statements are true about the vSRX? (Choose two.)
vSRXVMXNET3Linux base OSvirtualized SRX - Question #34High Availability (HA) Clustering
Which two statements about SRX Series device chassis clusters are true? (Choose two.)
chassis clusterredundancy groupcluster IDHA member - Question #35SSL Proxy
Which two statements are correct about SSL proxy server protection? (Choose two.)
SSL proxyserver protectionserver certificatesroot CA - Question #36Security Zones, Policies, and Objects
Which two statements are true about mixing traditional and unified security policies? (Choose two.)
unified security policytraditional security policypolicy orderingpolicy evaluation - Question #37Intrusion Detection and Prevention (IDP)
You are asked to create an IPS-exempt rule base to eliminate false positives from happening. Which two configuration parameters are available to exclude traffic from being examined...
IPSexempt rule basefalse positivestraffic exclusion - Question #38Application Security
You are asked to determine how much traffic a popular gaming application is generating on your network. Which action will you perform to accomplish this task?
AppTrackapplication monitoringtraffic visibilityapplication identification - Question #39Juniper Advanced Threat Prevention (ATP)
Exhibit You just finished setting up your command-and-control (C&C) category with Juniper ATP Cloud. You notice that all of the feeds have zero objects in them. Which statement is...
ATP CloudC&C feedssecurity intelligencethreat feed download - Question #40Juniper Advanced Threat Prevention (ATP)
You have deployed an SRX300 Series device and determined that files have stopped being scanned. In this scenario, what is a reason for this problem?
ATP Cloudfile scanningplatform limitsfile submission quota - Question #41Security Zones, Policies, and Objects
Which two statements about unified security policies are correct? (Choose two.)
unified security policiesAPPIDpolicy evaluation orderdynamic application matching - Question #42Intrusion Detection and Prevention (IDP)
You are asked to implement IPS on your SRX Series device. In this scenario, which two tasks must be completed before a configuration will work? (Choose two.)
IPS signature databaseIPS prerequisitessignature installationIDP configuration - Question #43Application Security
You want to permit access to an application but block application sub. Which two security policy features provide this capability? (Choose two.)
micro application detectionAPPIDapplication sub-detectionAppFW - Question #44Security Zones, Policies, and Objects
You are deploying a new SRX Series device and you need to log denied traffic. In this scenario, which two policy parameters are required to accomplish this task? (Choose two.)
security policy loggingdenied traffic loggingsession-initcount action - Question #45Juniper Advanced Threat Prevention (ATP)
Exhibit You are asked to track BitTorrent traffic on your network. You need to automatically add the workstations to the High_Risk_Workstations feed and the servers to the BitTorre...
dynamic address groupsinfected hosts feedpolicy actionsthreat feed automation - Question #46SRX Series Devices and Packet Flow
Which two statements are correct about the cSRX? (Choose two.)
cSRXcontainer SRXsupported servicesdefault security zones - Question #47High Availability (HA) Clustering
Which two statements are correct about chassis clustering? (Choose two.)
chassis clusternode IDcluster IDHA configuration - Question #48Additional Security Services
Which two features are configurable on Juniper Secure Analytics (JSA) to ensure that alerts are triggered when matching certain criteria? (Choose two.)
JSASIEM alertsbuilding blocksalert criteria - Question #49Identity-Aware Security Policies
Which two sources are used by Juniper Identity Management Service (JIMS) for collecting username and device IP addresses? (Choose two.)
JIMSidentity managementActive Directory event logsuser-IP mapping - Question #50Application Security
You are experiencing excessive packet loss on one of your two WAN links route traffic from the degraded link to the working link Which AppSecure component would you use to accompli...
APBRAppSecureWAN link failoveradvanced policy-based routing