Summer Certification Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: clap70

JN0-336 Security - Specialist (JNCIS-SEC) Questions and Answers

Questions 4

Using Junos Space Security Director, you want to configure a unique firewall policy for a specific SRX Series device.

Which firewall policy rule would satisfy the requirement?

Options:

A.

all devices policy prerules

B.

group policy prerules

C.

device policy rules

D.

all devices policy postrules

Buy Now
Questions 5

You are asked to onboard an SRX Series device to Junos Space Security Director, but it is not working.

In this scenario, what are three areas that should be reviewed? (Choose three.)

Options:

A.

chassis serial number

B.

SSH port number

C.

active security policies

D.

authentication credentials

E.

IP address

Buy Now
Questions 6

What are two types of attack objects included in an IDP attack object database? (Choose two.)

Options:

A.

statistic-based

B.

protocol anomaly-based

C.

signature-based

D.

vector-based

Buy Now
Questions 7

Which two statements are correct about IDP policy templates? (Choose two.)

Options:

A.

They are provided by Juniper Networks.

B.

They are not customizable.

C.

They are available on a “factory-default config.”

D.

They must be installed.

Buy Now
Questions 8

You want to include a custom attack object named Custom-FTP-Attack and set the action to drop the packet.

Referring to the exhibit, which modifications would you make?

Options:

A.

Add custom-attack Custom-FTP-Attack to the attacks section and change the action to close-client.

B.

Add custom-attack Custom-FTP-Attack to the attacks section and change the action to drop-packet.

C.

Add custom-attack Custom-FTP-Attack to the action section and change the action to drop-packet.

D.

Add custom-attack Custom-FTP-Attack to the notification section and change the action to drop-packet.

Buy Now
Questions 9

Which two statements are correct about client-protection Secure Socket Layer (SSL) proxy configurations? (Choose two.)

Options:

A.

Server certificate is required.

B.

Root certificate authority (CA) configuration is required.

C.

Root certificate authority (CA) configuration is not required.

D.

Server certificate is not required.

Buy Now
Questions 10

When using Adaptive Threat Profiling, which two deployment modes are available on SRX Series devices? (Choose two.)

Options:

A.

bridge

B.

inline

C.

tap

D.

promiscuous

Buy Now
Questions 11

How does Juniper’s identity-aware firewall facilitate compliance with security policies and regulations?

Options:

A.

by granting access based on user roles or identities

B.

by simplifying the design of the network architecture

C.

by increasing network capacity to accommodate user requirements

D.

by enforcing the need for user confidentiality

Buy Now
Questions 12

You want to configure the SSL proxy feature on your SRX Series Firewall.

Which two actions must you perform to accomplish this task? (Choose two.)

Options:

A.

Enable the SSL ALG.

B.

Create an SSL proxy profile.

C.

Create an SSL application object.

D.

Associate an SSL proxy profile with a security policy.

Buy Now
Questions 13

Which two services would an SRX Series device use to connect to an LDAP server for identity-aware security policies? (Choose two.)

Options:

A.

Active Directory

B.

TACACS+

C.

RADIUS

D.

JIMS

Buy Now
Questions 14

You are asked to configure your company SRX Series device to use identity-aware security policies. Information about your Active Directory network is shown in the exhibit.

In this scenario, why must you configure JIMS instead of Active Directory as an identity source?

Options:

A.

JIMS is the only way to get data from Active Directory.

B.

You have too many Active Directory users.

C.

The version of Windows OS is too old.

D.

You have too many domain controllers.

Buy Now
Questions 15

You are asked to configure a cluster between SRX1 and SRX2.

Which two commands must be used to accomplish this task? (Choose two.)

Options:

A.

user@SRX2# set chassis cluster cluster-id 0 node 1

B.

user@SRX1 > set chassis cluster cluster-id 1 node 0

C.

user@SRX2 > set chassis cluster cluster-id 1 node 1

D.

user@SRX1# set chassis cluster cluster-id 0 node 2

Buy Now
Questions 16

Which two statements are correct about the security associations of an IPsec VPN? (Choose two.)

Options:

A.

IPsec security associations are established during IKEv1 Phase 2 negotiations.

B.

IKEv1 security associations are established during IKEv1 Phase 2 negotiations.

C.

IPsec security associations are established during IKEv1 Phase 1 negotiations.

D.

IKEv1 security associations are established during IKEv1 Phase 1 negotiations.

Buy Now
Questions 17

You want to show tabular data for operational mode commands.

In this scenario, which logging parameter will provide this function?

Options:

A.

permit

B.

count

C.

session-init

D.

session-close

Buy Now
Questions 18

Your manager asks you to update your SRX Series device’s IDP security package. You perform the required steps; however, when you attempt to install the package, you receive an error.

Referring to the exhibit, which two statements are correct about this error? (Choose two.)

Options:

A.

IDP stops inspecting traffic.

B.

The IDP license has expired.

C.

IDP continues to inspect traffic only using the installed signatures.

D.

The IDP license is missing/not installed.

Buy Now
Questions 19

What are three policy types available in Junos Space Security Director? (Choose three.)

Options:

A.

device

B.

local

C.

group

D.

universal

E.

global

Buy Now
Exam Code: JN0-336
Exam Name: Security - Specialist (JNCIS-SEC)
Last Update: Jun 20, 2026
Questions: 0
JN0-336 pdf

JN0-336 PDF

$25.5  $84.99
JN0-336 Engine

JN0-336 Testing Engine

$30  $99.99
JN0-336 PDF + Engine

JN0-336 PDF + Testing Engine

$255  $850