JN0-636 Exam Questions
112 real JN0-636 exam questions with expert-verified answers and explanations. Page 1 of 3.
- Question #2
Referring to the exhibit, which two statements are true?
- Question #3
The show network-access aaa radius-servers command has been issued to solve authentication issues. Referring to the exhibit, to which two authentication servers will the SRX Series...
- Question #5
Referring to the exhibit, a spoke member of an ADVPN is not functioning correctly. Which two commands will solve this problem? (Choose two.)
- Question #6
You are using ATP Cloud and notice that there is a host with a high number of ETI and C&C hits sourced from the same investigation and notice that some of the events have not been...
- Question #7
Which two features would be used for DNS doctoring on an SRX Series firewall? (Choose two.)
- Question #8
You want to configure a threat prevention policy. Which three profiles are configurable in this scenario? (Choose three.)
- Question #9
You are asked to download and install the IPS signature database to a device operating in chassis cluster mode. Which statement is correct in this scenario?
- Question #10
You are using traceoptions to verity NAT session information on your SRX Series device. Referring to the exhibit, which two statements are correct? (Choose two.)
- Question #11
Referring to the exhibit. You are asked to establish an IBGP peering between the SRX Series device and the router, but the session is not being established. In the security flow tr...
- Question #12
SRX Series device enrollment with Policy Enforcer fails. To debug further, the user issues the following command show configuration services security-intelligence url https://cloud...
- Question #13
Referring to the exhibit, which three statements are true? (Choose three.)
- Question #15
You have configured the SRX Series device to switch packets for multiple directly connected hosts that are within the same broadcast domain. However, the traffic between two hosts...
- Question #16
You are asked to deploy filter-based forwarding on your SRX Series device for incoming traffic sourced from the 10.10.100.0/24 network. In this scenario, which three statements are...
- Question #17
You are connecting two remote sites to your corporate headquarters site. You must ensure that all traffic is secured and sent directly between sites. In this scenario, which VPN sh...
- Question #18
Your Source NAT implementation uses an address pool that contains multiple IPv4 addresses. Your users report that when they establish more than one session with an external applica...
- Question #19
You are asked to determine if the 203.0.113.5 IP address has been added to the third-party security feed. OS hield, from Juniper Secinte1. You have an SRX Series device that is rec...
- Question #20
You want to use selective stateless packet-based forwarding based on the source address. In this scenario, which command will allow traffic to bypass the SRX Series device flow dae...
- Question #21
You are requested to enroll an SRX Series device with Juniper ATP Cloud. Which statement is correct in this scenario?
- Question #22
Referring to the exhibit, which two statements are true? (Choose two.)
- Question #23
You configure Source NAT using a pool of addresses that are in the same subnet range as the external ge-0/0/0 interface on your vSRX device. Traffic that is exiting the internal ne...
- Question #24
In Juniper ATP Cloud, what are two different actions available in a threat prevention policy to deal with an infected host? (Choose two.)
- Question #25
You want to identify potential threats within SSL-encrypted sessions without requiring SSL proxy to decrypt the session contents. Which security feature achieves this objective?
- Question #26
The highlighted incident (arrow shown in the exhibit) shows a progression level of "Download" in the kill chain. What are two appropriate mitigation actions for the selected incide...
- Question #27
Referring to the exhibit, which three protocols will be allowed on the ge-0/0/0.5 interface? (Choose three.)
- Question #28
Referring to the exhibit, which type of NAT is being performed?
- Question #29
Regarding IPsec CoS-based VPNs, what is the number of IPsec SAs associated with a peer based upon?
- Question #30
Which method does an SRX Series device in transparent mode use to learn about unknown devices in a network?
- Question #31
While troubleshooting security policies, you added the count action. Where do you see the result of this action?
- Question #32
You are asked to detect domain generation algorithms. Which two steps will accomplish this goal on an SRX Series firewall? (Choose two.)
- Question #33
You are validating bidirectional traffic flows through your IPsec tunnel. The 4546 session represents traffic that is sourced from the local network destined to the remote network....
- Question #34
Which two statements are correct about the output shown in the exhibit? (Choose two.)
- Question #35
Referring to the exhibit, which statement explains this problem?
- Question #36
Your manager asks you to show which attacks have been detected on your SRX Series device using the IPS feature. Which command would you use to accomplish this task?
- Question #37
Which statement is correct regarding the outputs shown in the exhibit?
- Question #38
You are using destination NAT to translate the address of your HTTPS server to a private address on your SRX Series device. You have decided to implement IDP SSL decryption. Upon e...
- Question #39
You are asked to ensure that your IPS engine blocks attacks. You must ensure that your system continues to drop additional malicious traffic without additional IPS processing for u...
- Question #40
You must ensure that your Layer 2 traffic is secured on your SRX Series device in transparent mode. What must be considered when accomplishing this task?
- Question #41
What is a secure key management protocol used by IPsec?
- Question #42
As an SRX administrator, you must find all encrypted sessions on an SRX Series device. Which command would you use to accomplish this task?
- Question #43
Which configurable SRX Series device feature allows you to capture transit traffic?
- Question #44
You have already configured a hub-and-spoke VPN with one hub device and two spoke devices. However, the hub device has one neighbor in the Init state and one neighbor in the Full s...
- Question #45
DMZ zone. What are two reasons for this problem? (Choose two.)
- Question #46
Click the Exhibit button. IPv6 to IPv4 addresses are not being translated as shown in the exhibit. Which two configurations would resolve the problem? (Choose two.)
- Question #47
Click the Exhibit button. user@host# run show route inet.0: 4 destinations, 1 routes (4 active, 0 holddown, 0 hidden) + = Active Route, - = Last Active, * = Both 0.0.0.0/0 *[Static...
- Question #48
Click the Exhibit button. user@srx> show security mka statistics Interface name: fxpl Received packets: 3 Transmitted packets: 3 Version mismatch packets: 0 CAR mismatch packets: 6...
- Question #49
Click the Exhibit button.
- Question #50
You have recently committed the IPS policy shown in the exhibit. When evaluating the expected scenario, you notice that you have a session that matches all the rules in your IPS po...
- Question #51
Your organization has multiple Active Directory domains to control user access. You must ensure that security policies are passing traffic based upon the users' access rights. What...
- Question #52
You are asked to set up notifications if one of your collector traffic feeds drops below 100 kbps. Which two configuration parameters must be set to accomplish this task? (Choose t...
- Question #53
You have configured static NAT for a webserver in your DMZ. Both internal and external users can reach the webserver using the webserver's IP address. However, only internal users...