Sign In
Home/Juniper/JN0-336: Security, Specialist (JNCIS-SEC)/Free questions

JN0-336: Security, Specialist (JNCIS-SEC) — Free Practice Questions

10 free sample questions from a bank of 10, with the correct answers and explanations. No signup required — start practising right now.

1In Juniper high availability (HA) SRX Series device implementations, which interface will be used to exchange session state, configuration files, and ensure session continuity across nodes using the proprietary Trivial Network Protocol?
  • fab
  • fxp0
  • fxp1
  • swfab
Answer: A
2What are two ways that Juniper Secure Connect provides flexibility in connection and authentication methods while ensuring that remote users are able to securely access company servers and cloud resources? (Choose two.)
  • It uses a persistent agent.
  • It uses Kerberos authentication.
  • It uses external authentication.
  • It uses an SSL VPN.
Answer: C, D
3What are three policy types available in Junos Space Security Director? (Choose three.)
  • device
  • local
  • group
  • universal
  • global
Answer: A, C, E
4You are asked to configure a cluster between SRX1 and SRX2. Which two commands must be used to accomplish this task? (Choose two.)
  • user@SRX2# set chassis cluster cluster-id 0 node 1
  • user@SRXl> set chassis cluster cluster-id 1 node 0
  • user@SRX2> set chassis cluster cluster-id 1 node 1
  • user@SRXl# set chassis cluster cluster-id 0 node 2
Answer: B, C
5You need to secure communications from a mobile command center which uses a 5G mobile ISP behind CGNAT to an SRX Series Firewall at headquarters. Which two actions should be performed on the SRX Series Firewall in this scenario? (Choose two.)
  • Configure the IPsec VPN to use NAT-T.
  • Configure the IPsec VPN to use IKEv1 aggressive mode.
  • Configure the IPsec VPN to use IKEv2 aggressive mode.
  • Configure the IPsec VPN to use DPD.
Answer: A, D
6An administrator decides to designate a node as the primary node for the chassis cluster. Which statement is correct in this scenario?
  • Configure the burnt-in-address (BIA) to the highest value to bring the node as the primary node.
  • The node with the highest priority will become a primary node.
  • The node with the lowest priority will become a primary node.
  • Nodes with a priority of one are ineligible to participate in the election process.
Answer: B
7Which two statements are correct about client-protection Secure Socket Layer (SSL) proxy configurations? (Choose two.)
  • Server certificate is required.
  • Root certificate authority (CA) configuration is required.
  • Root certificate authority (CA) configuration is not required.
  • Server certificate is not required.
Answer: A, B
8You are asked to ensure that traffic that matches an IDP policy is not impacted until administrators have a chance to evaluate it. In this scenario, which IP action should be configured for the policy?
  • ip-block
  • ip-notify
  • ip-connection-rate-limit
  • ip-close
Answer: B
9Your manager asks you to update your SRX Series device’s IDP security package. You perform the required steps; however, when you attempt to install the package, you receive an error. Referring to the exhibit, which two statements are correct about this error? (Choose two.)
JN0-336: Security, Specialist (JNCIS-SEC) question 9
  • IDP stops inspecting traffic.
  • The IDP license has expired.
  • IDP continues to inspect traffic only using the installed signatures.
  • The IDP license is missing (not installed).
Answer: C, D
10You are asked to set up SSL proxy in SRX Series devices. An SSL proxy profile is already defined for you. Which two steps are required to complete the setup? (Choose two.)
  • Enable host-inbound-traffic HTTPS in the security zone in which SSL proxy is referenced.
  • Reference the SSL proxy profile in a security zone.
  • Reference the SSL proxy profile in a security policy.
  • Enable any Layer 7 services in the security policy in which SSL proxy is referenced.
Answer: B, C

Want the full bank of 10 questions for JN0-336: Security, Specialist (JNCIS-SEC)? See all practice exams.