Summer Sale 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: exams65

ExamsBrite Dumps

Security, Specialist (JNCIS-SEC) Question and Answers

Security, Specialist (JNCIS-SEC)

Last Update Jul 23, 2026
Total Questions : 66

We are offering FREE JN0-336 Juniper exam questions. All you do is to just go and sign up. Give your details, prepare JN0-336 free exam questions and then go for complete pool of Security, Specialist (JNCIS-SEC) test questions that will help you more.

JN0-336 pdf

JN0-336 PDF

$36.75  $104.99
JN0-336 Engine

JN0-336 Testing Engine

$43.75  $124.99
JN0-336 PDF + Engine

JN0-336 PDF + Testing Engine

$57.75  $164.99
Questions 1

What are three policy types available in Junos Space Security Director? (Choose three.)

Options:

A.  

device

B.  

local

C.  

group

D.  

universal

E.  

global

Discussion 0
Questions 2

You need to set up a forward proxy on your SRX Series device.

In this scenario, which two statements are correct? (Choose two.)

Options:

A.  

The forward proxy uses the managed SRX as a trusted certificate authority (CA).

B.  

The forward proxy forwards the server certificate.

C.  

The forward proxy looks like a client to the servers to which it communicates.

D.  

The forward proxy uses Encrypted Traffic Insights to monitor traffic.

Discussion 0
Questions 3

Which two statements are correct about Juniper Secure Connect? (Choose two.)

Options:

A.  

Juniper Secure Connect uses a policy-based VPN.

B.  

Juniper Secure Connect can use a self-signed certificate.

C.  

Juniper Secure Connect uses a route-based VPN.

D.  

Juniper Secure Connect cannot use a self-signed certificate.

Discussion 0
Questions 4

How does Juniper’s identity-aware firewall facilitate compliance with security policies and regulations?

Options:

A.  

by granting access based on user roles or identities

B.  

by simplifying the design of the network architecture

C.  

by increasing network capacity to accommodate user requirements

D.  

by enforcing the need for user confidentiality

Discussion 0
Questions 5

Referring to the exhibit, what should you do to ensure that Juniper ATP Cloud detects malware in HTTPS traffic?

Options:

A.  

Manually configure and apply an SSL proxy profile.

B.  

Lower the threat score.

C.  

Configure a new device profile that includes encrypted traffic.

D.  

Change the action to redirect the encrypted traffic to a decryption device.

Discussion 0
Questions 6

Which two statements about PC probes sent by the JIMS server are correct? (Choose two.)

Options:

A.  

PC probes are triggered only when there is no IP-to-username mapping present in the event log.

B.  

PC probes are sent by the JIMS server to domain PCs every 30 seconds.

C.  

PC probes are sent by the JIMS server to domain PCs every 60 seconds.

D.  

If a probe is successful, the authentication entry is updated on the JIMS server and pushed to the SRX.

Discussion 0
Questions 7

Using Junos Space Security Director, you want to configure a unique firewall policy for a specific SRX Series device.

Which firewall policy rules would satisfy the requirement?

Options:

A.  

all devices policy prerules

B.  

group policy prerules

C.  

device policy rules

D.  

all devices policy postrules

Discussion 0
Questions 8

What are two causes that end the processing of rules in IDP? (Choose two.)

Options:

A.  

when a rule is matched in the rule base with an action of close

B.  

when a terminal rule is matched in the rule base

C.  

when any rule is matched in the exempt rule base

D.  

when a rule is matched in the rule base with an action of ignore

Discussion 0
Questions 9

Which two statements accurately describe the role of hashing in VPNs? (Choose two.)

Options:

A.  

Hashing compresses data in VPN communications.

B.  

Hashing generates a fixed-size string of characters.

C.  

Hashing encrypts data to ensure confidentiality.

D.  

Hashing verifies that data has not been altered during transmission.

Discussion 0
Questions 10

Which two statements are correct about IDP policy templates? (Choose two.)

Options:

A.  

They are provided by Juniper Networks.

B.  

They are not customizable.

C.  

They are available on a “factory-default config.”

D.  

They must be installed.

Discussion 0
Questions 11

You want to configure the SSL proxy feature on your SRX Series Firewall.

Which two actions must you perform to accomplish this task? (Choose two.)

Options:

A.  

Enable the SSL ALG.

B.  

Create an SSL proxy profile.

C.  

Create an SSL application object.

D.  

Associate an SSL proxy profile with a security policy.

Discussion 0
Questions 12

Which two statements describe how Juniper ATP Cloud improves security? (Choose two.)

Options:

A.  

It tracks and logs malicious traffic.

B.  

It offers real-time threat analysis and mitigation.

C.  

It simulates real user environments to trigger malicious code execution.

D.  

It increases performance speeds.

Discussion 0
Questions 13

What are two types of attack objects included in an IDP attack object database? (Choose two.)

Options:

A.  

statistic-based

B.  

protocol anomaly-based

C.  

signature-based

D.  

vector-based

Discussion 0
Questions 14

You need to secure communications from a mobile command center which uses a 5G mobile ISP behind CGNAT to an SRX Series Firewall at headquarters.

Which two actions should be performed on the SRX Series Firewall in this scenario? (Choose two.)

Options:

A.  

Configure the IPsec VPN to use NAT-T.

B.  

Configure the IPsec VPN to use IKEv1 aggressive mode.

C.  

Configure the IPsec VPN to use IKEv2 aggressive mode.

D.  

Configure the IPsec VPN to use DP

D.  

Discussion 0
Questions 15

Which three algorithms are used to encrypt IP packets? (Choose three.)

Options:

A.  

Data Encryption Standard (DES)

B.  

Secure Hash Algorithm (SHA) - 1

C.  

Message Digest 5 (MD5)

D.  

Triple Data Encryption Standard (3DES)

E.  

Advanced Encryption Standard (AES)

Discussion 0
Questions 16

You want to use user identity information to secure your network.

Which two actions must you perform on your SRX Series Firewall to accomplish this task? (Choose two.)

Options:

A.  

Create security policies that include user identity configuration

B.  

Add user accounts to the Active Directory Domain Users group

C.  

Configure an identity provider on your SRX Series Firewall.

D.  

Add the user identity feature license to your SRX Series Firewall.

Discussion 0
Questions 17

An administrator decides to designate a node as the primary node for the chassis cluster.

Which statement is correct in this scenario?

Options:

A.  

Configure the burnt-in-address (BIA) to the highest value to bring the node as the primary node.

B.  

The node with the highest priority will become a primary node.

C.  

The node with the lowest priority will become a primary node.

D.  

Nodes with a priority of one are ineligible to participate in the election process.

Discussion 0
Questions 18

Which protocol does the SRX Series Firewall use to communicate with a Windows domain controller?

Options:

A.  

SSH

B.  

LDAP

C.  

DNS

D.  

NETCONF

Discussion 0
Questions 19

Which IDP action is also referred to as a silent discard?

Options:

A.  

no action

B.  

close client and server

C.  

ignore connection

D.  

drop packet

Discussion 0