Month End Sale Special - 75% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: save75geek

JN0-336 Security, Specialist (JNCIS-SEC) Questions and Answers

Questions 4

You are asked to use Junos Space Security Director to download the latest application signatures in the AppID database.

In this scenario, which two statements are correct? (Choose two.)

Options:

A.

The AppID database is stored in Junos Space Security Director.

B.

The AppID database is stored on the managed SRX Series device.

C.

The AppID database is maintained by a third-party host.

D.

The AppID database is stored on a local storage server in the management network.

Buy Now
Questions 5

When using Adaptive Threat Profiling, which two deployment modes are available on SRX Series devices? (Choose two.)

Options:

A.

bridge

B.

inline

C.

tap

D.

promiscuous

Buy Now
Questions 6

You want to show tabular data for operational mode commands.

In this scenario, which logging parameter will provide this function?

Options:

A.

permit

B.

count

C.

session-init

D.

session-close

Buy Now
Questions 7

You are establishing an IPsec VPN and must ensure that payload data is encrypted.

In this scenario, which IPsec security protocol should you configure?

Options:

A.

SHA-1

B.

ESP

C.

AH

D.

PFS

Buy Now
Questions 8

Which protocol does the SRX Series Firewall use to communicate with a Windows domain controller?

Options:

A.

SSH

B.

LDAP

C.

DNS

D.

NETCONF

Buy Now
Questions 9

Using Junos Space Security Director, you want to configure a unique firewall policy for a specific SRX Series device.

Which firewall policy rules would satisfy the requirement?

Options:

A.

all devices policy prerules

B.

group policy prerules

C.

device policy rules

D.

all devices policy postrules

Buy Now
Questions 10

You are asked to set up SSL proxy in SRX Series devices. An SSL proxy profile is already defined for you.

Which two steps are required to complete the setup? (Choose two.)

Options:

A.

Enable host-inbound-traffic HTTPS in the security zone in which SSL proxy is referenced.

B.

Reference the SSL proxy profile in a security zone.

C.

Reference the SSL proxy profile in a security policy.

D.

Enable any Layer 7 services in the security policy in which SSL proxy is referenced.

Buy Now
Questions 11

Which two statements about PC probes sent by the JIMS server are correct? (Choose two.)

Options:

A.

PC probes are triggered only when there is no IP-to-username mapping present in the event log.

B.

PC probes are sent by the JIMS server to domain PCs every 30 seconds.

C.

PC probes are sent by the JIMS server to domain PCs every 60 seconds.

D.

If a probe is successful, the authentication entry is updated on the JIMS server and pushed to the SRX.

Buy Now
Questions 12

Which two statements are correct about IDP policy templates? (Choose two.)

Options:

A.

They are provided by Juniper Networks.

B.

They are not customizable.

C.

They are available on a “factory-default config.”

D.

They must be installed.

Buy Now
Questions 13

What are three policy types available in Junos Space Security Director? (Choose three.)

Options:

A.

device

B.

local

C.

group

D.

universal

E.

global

Buy Now
Questions 14

Referring to the exhibit, which two statements are correct? (Choose two.)

Options:

A.

Fabric link 0 is working.

B.

The control link is working.

C.

Fabric link 1 is failing.

D.

The control link is failing.

Buy Now
Questions 15

You have configured a new site-to-site VPN tunnel. The exhibit shows the security IPsec statistics output for the specific tunnel index from one of the tunnel-end devices.

Which two statements are correct in this scenario? (Choose two.)

Options:

A.

AH is incorrectly configured.

B.

The far-end tunnel device is rebooting.

C.

The ESP configuration is not set up correctly.

D.

No traffic passes through this tunnel.

Buy Now
Questions 16

Referring to the exhibit, what should you do to ensure that Juniper ATP Cloud detects malware in HTTPS traffic?

Options:

A.

Manually configure and apply an SSL proxy profile.

B.

Lower the threat score.

C.

Configure a new device profile that includes encrypted traffic.

D.

Change the action to redirect the encrypted traffic to a decryption device.

Buy Now
Questions 17

What does the exhibit indicate when you have configured a single IPsec VPN on an SRX Series Firewall?

Options:

A.

The IPsec VPN has encountered errors during packet transmission.

B.

The IPsec VPN is established, and traffic is passing through.

C.

The IPsec VPN is not established.

D.

The IPsec VPN is established, but no traffic is passing through.

Buy Now
Questions 18

You want to configure the SSL proxy feature on your SRX Series Firewall.

Which two actions must you perform to accomplish this task? (Choose two.)

Options:

A.

Enable the SSL ALG.

B.

Create an SSL proxy profile.

C.

Create an SSL application object.

D.

Associate an SSL proxy profile with a security policy.

Buy Now
Questions 19

Which two statements are correct about Juniper ATP Cloud malware analysis? (Choose two.)

Options:

A.

If no match exists in cache, the remaining analysis features are processed with the cumulative threat score transmitted to the SRX Series device.

B.

If a match exists in cache, that threat score is sent to the SRX Series device and the analysis continues.

C.

If a match exists in cache, that threat score is sent to the SRX Series device and the analysis stops.

D.

If no match exists in cache, the first analysis feature to generate a threat score is transmitted to the SRX Series device.

Buy Now
Questions 20

Which two statements about proxy IDs are correct? (Choose two.)

Options:

A.

Proxy IDs cannot override default Junos behavior.

B.

By default, for a route-based IPsec VPN, a Junos security device sets the proxy ID to 0.0.0.0/0.

C.

Proxy IDs must match on both peers for a Phase 2 tunnel to establish.

D.

Proxy IDs are created during IKE Phase 1.

Buy Now
Exam Code: JN0-336
Exam Name: Security, Specialist (JNCIS-SEC)
Last Update: Sep 26, 2026
Questions: 68
JN0-336 pdf

JN0-336 PDF

$21.25  $84.99
JN0-336 Engine

JN0-336 Testing Engine

$25  $99.99
JN0-336 PDF + Engine

JN0-336 PDF + Testing Engine

$33.75  $134.99