Spring Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: scxmas70

JN0-336 Exam Dumps - Security, Specialist (JNCIS-SEC)

Searching for workable clues to ace the Juniper JN0-336 Exam? You’re on the right place! ExamCert has realistic, trusted and authentic exam prep tools to help you achieve your desired credential. ExamCert’s JN0-336 PDF Study Guide, Testing Engine and Exam Dumps follow a reliable exam preparation strategy, providing you the most relevant and updated study material that is crafted in an easy to learn format of questions and answers. ExamCert’s study tools aim at simplifying all complex and confusing concepts of the exam and introduce you to the real exam scenario and practice it with the help of its testing engine and real exam dumps

Go to page:
Question # 9

How does Juniper’s identity-aware firewall facilitate compliance with security policies and regulations?

A.

by granting access based on user roles or identities

B.

by simplifying the design of the network architecture

C.

by increasing network capacity to accommodate user requirements

D.

by enforcing the need for user confidentiality

Full Access
Question # 10

Which two statements are correct about redundant fabric interfaces in a chassis cluster? (Choose two.)

A.

fab0 and fab1 are located on both node0 and node1.

B.

fab0 is located on node0, whereas fab1 is located on node1.

C.

The media type must be the same for each redundant fabric interface.

D.

The media type can be different for each redundant fabric interface.

Full Access
Question # 11

You need to secure communications from a mobile command center which uses a 5G mobile ISP behind CGNAT to an SRX Series Firewall at headquarters.

Which two actions should be performed on the SRX Series Firewall in this scenario? (Choose two.)

A.

Configure the IPsec VPN to use NAT-T.

B.

Configure the IPsec VPN to use IKEv1 aggressive mode.

C.

Configure the IPsec VPN to use IKEv2 aggressive mode.

D.

Configure the IPsec VPN to use DPD.

Full Access
Question # 12

You want to include a custom attack object named Custom-FTP-Attack and set the action to drop the packet.

Referring to the exhibit, which modifications would you make?

A.

Add custom-attack Custom-FTP-Attack to the attacks section and change the action to close-client.

B.

Add custom-attack Custom-FTP-Attack to the attacks section and change the action to drop-packet.

C.

Add custom-attack Custom-FTP-Attack to the action section and change the action to drop-packet.

D.

Add custom-attack Custom-FTP-Attack to the notification section and change the action to drop-packet.

Full Access
Question # 13

You are implementing an SRX Series device at a branch office that has low bandwidth and also uses a cloud-based VoIP solution with an outbound policy that permits all traffic.

Which service would you implement at your edge device to prioritize VoIP traffic in this scenario?

A.

AppFW

B.

SIP ALG

C.

AppQoE

D.

AppQoS

Full Access
Question # 14

Which two steps are necessary to prepare the Active Directory domain for a JIMS installation? (Choose two.)

A.

Create two limited access user accounts.

B.

Create three limited access user accounts.

C.

Add one full access user account to Active Directory groups.

D.

Add limited access user accounts to Active Directory groups.

Full Access
Question # 15

Which two statements are correct about fabric interfaces on an SRX Series Firewall? (Choose two.)

A.

In an active/active configuration, inter-chassis traffic uses the fab link.

B.

In an active/passive configuration, inter-chassis traffic uses the fab link.

C.

The node ID is reflected in the fabric interface name.

D.

The cluster ID is reflected in the fabric interface name.

Full Access
Question # 16

Using Junos Space Security Director, you want to configure a unique firewall policy for a specific SRX Series device.

Which firewall policy rules would satisfy the requirement?

A.

all devices policy prerules

B.

group policy prerules

C.

device policy rules

D.

all devices policy postrules

Full Access
Go to page: