Practice JN0-336 Questions With Certification guide Q&A from Training Expert PracticeDump
Free Juniper JN0-336 Test Practice Test Questions Exam Dumps
NEW QUESTION # 47
How does the SSL proxy detect if encryption is being used?
- A. It verifies the length of the packet
- B. It looks at the destination port number.
- C. It uses application identity services.
- D. It queries the client device.
Answer: B
Explanation:
The SSL proxy can detect if encryption is being used by looking at the destination port number of the packet. If the port number is 443, then the proxy can assume that the packet is being sent over an encrypted connection. If the port number is different, then the proxy can assume that the packet is not encrypted. For more information, please refer to the Juniper Networks JNCIS-SEC Study Guide.
NEW QUESTION # 48
Which two statements about SRX Series device chassis clusters are correct? (Choose two.)
- A. The chassis cluster data plane is connected with SPC ports.
- B. The chassis cluster can contain a maximum of two devices.
- C. The chassis cluster data plane is connected with revenue ports.
- D. The chassis cluster can contain a maximum of three devices.
Answer: B,C
Explanation:
Two statements that are correct about SRX Series device chassis clusters are:
The chassis cluster data plane is connected with revenue ports: A chassis cluster is a high-availability feature that groups two identical SRX Series devices into a cluster that acts as a single device. The cluster has two types of links: control links and fabric links. The control links are used for exchanging heartbeat messages and configuration synchronization between the nodes. The fabric links are used for forwarding data traffic between the nodes. The fabric links are connected with revenue ports, which are regular Ethernet interfaces that can also be used for normal traffic when not in cluster mode.
The chassis cluster can contain a maximum of two devices: A chassis cluster can only consist of two nodes: node 0 and node 1. The nodes must be the same model, have the same hardware configuration, run the same software version, and have the same license keys. The nodes share a common configuration and act as backup for each other in case of failure.
Reference: = Configuring Chassis Clustering on SRX Series Devices, SRX Series Chassis Cluster Configuration Overview, Connecting SRX Series Firewalls to Create a Chassis Cluster
NEW QUESTION # 49
Which two statements about the DNS ALG are correct? (Choose two.)
- A. The DNS ALG supports VPN tunnels.
- B. The DNS ALG does not support NAT.
- C. The DNS ALG performs DNS doctoring.
- D. The DNS ALG supports DDNS.
Answer: A,C
Explanation:
The DNS Application Layer Gateway (ALG) is designed to manage and facilitate the successful passage of DNS traffic through a network device such as a firewall or NAT. Here are the correct statements regarding DNS ALG:
The DNS ALG performs DNS doctoring.
DNS doctoring is indeed a function of the DNS ALG where it modifies the payload of DNS responses to ensure that the information is aligned with the NAT policy. For example, it can rewrite the IP addresses in DNS responses to match the internal or external NAT'd IP address that the client should use.
The DNS ALG supports VPN tunnels.
DNS ALG can function across VPN tunnels by managing DNS traffic that traverses the tunnel, ensuring that the DNS queries and responses are correctly handled in environments where IP address translation occurs due to the VPN.
NEW QUESTION # 50
Which two functions does Juniper ATP Cloud perform to reduce delays in the inspection of files?
(Choose two.)
- A. Juniper ATP Cloud performs a cache lookup on files.
- B. Juniper ATP Cloud allows the creation of allowlists.
- C. Juniper ATP Cloud uses a single antivirus software package to analyze files.
- D. Juniper ATP Cloud allows end users to bypass the inspection of files.
Answer: A,B
Explanation:
Juniper ATP Cloud is a cloud-based service that provides advanced threat prevention and detection for your network. It integrates with SRX Series firewalls and MX Series routers to analyze files and network traffic for signs of malicious activity.
Two functions that Juniper ATP Cloud performs to reduce delays in the inspection of files are:
Juniper ATP Cloud allows the creation of allowlists: Allowlists are lists of trusted files or file hashes that are excluded from scanning by Juniper ATP Cloud. You can create allowlists based on file name, file type, file size, file hash, or sender domain. By using allowlists, you can reduce the number of files that need to be uploaded to Juniper ATP Cloud for analysis and improve the performance and efficiency of your network.
Juniper ATP Cloud performs a cache lookup on files: Cache lookup is a process that checks if a file has been previously scanned by Juniper ATP Cloud and if there is a cached verdict for it. If there is a cached verdict, Juniper ATP Cloud returns it immediately without scanning the file again. If there is no cached verdict, Juniper ATP Cloud uploads the file for analysis. By using cache lookup, you can reduce the time and bandwidth required for scanning files by Juniper ATP Cloud.
Reference: = [Juniper Advanced Threat Prevention Cloud (ATP Cloud)], [Configuring Allowlists],
[Understanding Cache Lookup]
NEW QUESTION # 51
What are three capabilities of AppQoS? (Choose three.)
- A. rate-limit traffic
- B. reserve bandwidth
- C. re-write the TTL
- D. assign a forwarding class
- E. re-write DSCP values
Answer: A,D,E
Explanation:
AppQoS can modify the DSCP (Differentiated Services Code Point) values in IP packet headers. This is crucial for defining the level of service for each packet, influencing how network devices prioritize traffic.
It can assign traffic to specific forwarding classes. This feature allows network administrators to group different types of traffic (e.g., VoIP, streaming, bulk data) into categories that are treated differently based on predefined network policies, ensuring that critical applications receive the necessary bandwidth and priority.
AppQoS is capable of rate-limiting traffic, which involves setting a maximum bandwidth limit for certain types of traffic. This ensures that no single application or service consumes more bandwidth than allocated, thus preventing network congestion and ensuring fair bandwidth distribution among all applications.
These features are essential for managing network performance and ensuring that critical applications receive the necessary resources to function effectively. AppQoS does not inherently include capabilities to re-write TTL (Time To Live) values or reserve bandwidth as primary functions, but it manages bandwidth usage through rate limiting and priority settings.
NEW QUESTION # 52
Which statement about security policy schedulers is correct?
- A. Multiple policies can use the same scheduler.
- B. When the scheduler is disabled, the policy will still be available.
- C. A policy without a defined scheduler will not become active
- D. A policy can have multiple schedulers.
Answer: A
Explanation:
Schedulers can be defined and reused by multiple policies, allowing for more efficient management of policy activation and deactivation. This can be particularly useful for policies that need to be activated during specific time periods, such as business hours or maintenance windows.
NEW QUESTION # 53
You are asked to block malicious applications regardless of the port number being used.
In this scenario, which two application security features should be used? (Choose two.)
- A. AppFW
- B. APPID
- C. AppQoE
- D. AppTrack
Answer: A,B
NEW QUESTION # 54
You are currenty using a third-party threat analyzer. You want your SRX Series device to send decrypted SSE traffic to......
In this scenario, which feature should you configure on the SRX device?
- A. SSL decryption mirroring
- B. JSA vulnerability assessment
- C. IPS IPanotify action
- D. Phase 2 proxy ID
Answer: B,C
NEW QUESTION # 55
Exhibit
Referring to the exhibit, which two statements are true? (Choose two.)
- A. The IP address of the authenticating domain controller is 172.25.11.140.
- B. Nancy logged in to the juniper.net Active Directory domain.
- C. The IP address of Nancy's client PC is 172.25.11.
- D. Nancy is a member of the Active Directory sales group.
Answer: A,B
NEW QUESTION # 56
Which two types of SSL proxy are available on SRX Series devices? (Choose two.)
- A. DNS proxy
- B. Web proxy
- C. client-protection
- D. server-protection
Answer: C,D
Explanation:
Based on SSL proxy is a feature that allows SRX Series devices to decrypt and inspect SSL/TLS traffic for security purposes.
According to SRX Series devices support two types of SSL proxy:
Client-protection SSL proxy also known as forward proxy - The SRX Series device resides between the internal client and outside server. It decrypts and inspects traffic from internal users to the web.
Server-protection SSL proxy also known as reverse proxy - The SRX Series device resides between outside clients and internal servers. It decrypts and inspects traffic from web users to internal servers.
NEW QUESTION # 57
You administer a JSA host and want to include a rule that sets a threshold for excessive firewall denies and sends an SNMP trap after receiving related syslog messages from an SRX Series firewall.
Which JSA rule type satisfies this requirement?
- A. flow
- B. event
- C. common
- D. offense
Answer: D
Explanation:
An offense rule in JSA is designed to aggregate multiple events or log entries based on specified criteria into a single offense, which can then trigger responses such as notifications or actions like sending an SNMP trap. This type of rule is well-suited for scenarios where you need to monitor for patterns or rates of events, such as excessive firewall denies, and take action when these exceed defined thresholds.
Offense rules can analyze both event and flow data, making them highly versatile for comprehensive security monitoring.
NEW QUESTION # 58
Your network uses a single JSA host and you want to implement a cluster.
In this scenario, which two statements are correct? (Choose two.)
- A. The primary and secondary hosts must be configured with the same storage devices.
- B. The cluster virtual IP will need an unused IP address assigned.
- C. The secondary host can backup multiple JSA primary hosts.
- D. The software versions on both primary and secondary hosts
Answer: B,D
Explanation:
According to the Juniper Networks JNCIP-SEC Study Guide, when setting up a cluster with a single JSA host, both the primary and secondary hosts must have the same software version installed. Additionally, an unused IP address must be assigned to the cluster virtual IP. The primary and secondary hosts do not need to be configured with the same storage devices, and the secondary host cannot be used to backup multiple JSA primary hosts.
NEW QUESTION # 59
Which two statements about unified security policies are correct? (Choose two.)
- A. Unified security policies require an advanced feature license.
- B. APPID results are used to determine the final security policy
- C. Unified security policies are evaluated after global security policies.
- D. Traffic can initially match multiple unified security policies.
Answer: B,D
NEW QUESTION # 60
Exhibit
You are asked to track BitTorrent traffic on your network. You need to automatically add the workstations to the High_Risk_Workstations feed and the servers to the BitTorrent_Servers feed automatically to help mitigate future threats.
Which two commands would add this functionality to the FindThreat policy? (Choose two.)
- A.

- B.

- C.

- D.

Answer: A,B
NEW QUESTION # 61
Which two sources are used by Juniper Identity Management Service (JIMS) for collecting username and device IP addresses? (Choose two.)
- A. DNS
- B. Active Directory domain controller event logs
- C. Microsoft Exchange Server event logs
- D. OpenLDAP service ports
Answer: A,B
Explanation:
Juniper Identity Management Service (JIMS) collects username and device IP addresses from both DNS and Active Directory domain controller event logs. DNS is used to resolve hostnames to IP addresses, while Active Directory domain controller event logs are used to get information about user accounts, such as when they last logged in.
NEW QUESTION # 62
You are preparing a proposal for a new customer who has submitted the following requirements for a vSRX deployment:
-- globally distributed,
-- rapid provisioning,
-- scale based on demand,
-- and low CapEx.
Which solution satisfies these requirements?
- A. AWS
- B. Juniper ATP Cloud
- C. Network Director
- D. VMWare ESXi
Answer: A
Explanation:
The solution that satisfies the requirements for a vSRX deployment is AWS. AWS (Amazon Web Services) is a cloud computing platform that provides on-demand services such as infrastructure, platform, software, and database as a service. AWS is globally distributed, meaning that it has data centers in multiple regions around the world. AWS also allows rapid provisioning, meaning that you can launch vSRX instances in minutes using preconfigured Amazon Machine Images (AMIs) or custom templates. AWS also enables scaling based on demand, meaning that you can adjust the number and size of vSRX instances according to your network traffic and performance needs. AWS also has low CapEx (capital expenditure), meaning that you only pay for what you use and do not need to invest in hardware or maintenance costs.
Reference: = vSRX Deployment Guide for AWS, Understand vSRX Virtual Firewall with AWS, What Is Amazon Web Services?
NEW QUESTION # 63
Which two statements are true about the vSRX? (Choose two.)
- A. Linux is the base OS.
- B. UNIX is the base OS.
- C. It does not have VMXNET3 vNIC support.
- D. It has VMXNET3 vNIC support.
Answer: A,D
NEW QUESTION # 64
Which statement regarding Juniper Identity Management Service (JIMS) domain PC probes is true?
- A. JIMS domain PC probes are triggered to map usernames to group membership information.
- B. JIMS domain PC probes are triggered if no username to IP address mapping is found in the domain security event log.
- C. JIMS domain PC probes analyze domain controller security event logs at60-mmute intervals by default.
- D. JIMS domain PC probes are initiated by an SRX Series device to verify authentication table information.
Answer: B
Explanation:
Juniper Identity Management Service (JIMS) domain PC probes are used to map usernames to IP addresses in the domain security event log. This allows for the SRX Series device to verify authentication table information, such as group membership. The probes are triggered whenever a username to IP address mapping is not found in the domain security event log. By default, the probes are executed at 60-minute intervals.
NEW QUESTION # 65
Which two statements are correct about security policy changes when using the policy rematch feature? (Choose two.)
- A. When a policy change includes changing the policy's action from permit to deny, all existing sessions are dropped.
- B. When a policy change includes changing the policy's source or destination address match condition, all existing sessions are dropped.
- C. When a policy change includes changing the policy's source or destination address match condition, all existing sessions are reevaluated.
- D. When a policy change includes changing the policy's action from permit to deny, all existing sessions are maintained
Answer: A,C
Explanation:
policy rematch is a feature that enables the device to reevaluate an active session when its associated security policy is modified. The session remains open if it still matches the policy that allowed the session initially. The session is closed if its associated policy is renamed, deactivated, or deleted1.
NEW QUESTION # 66
You want to be alerted if the wrong password is used more than three times on a single device within five minutes.
Which Juniper Networks solution will accomplish this task?
- A. Adaptive Threat Profiling
- B. Juniper Identity Management Service
- C. Intrusion Prevention System
- D. Juniper Secure Analytics
Answer: D
Explanation:
The Juniper Networks solution that will accomplish the task of alerting if the wrong password is used more than three times on a single device within five minutes is Juniper Secure Analytics (JSA). JSA is a security intelligence platform that collects, analyzes, and correlates network data from various sources, such as firewalls, routers, switches, servers, and applications. JSA can detect and respond to threats, anomalies, and vulnerabilities in real time using rules, offenses, reports, and dashboards. JSA can also integrate with JIMS (Juniper Identity Management Service) to obtain user identity information from Active Directory domains or syslog sources. JSA can use this information to create custom rules that trigger offenses or alerts based on user behavior or activity, such as failed login attempts or password changes.
Reference: = Juniper Secure Analytics Troubleshooting Guide, Juniper Identity Management Service User Guide
NEW QUESTION # 67
Which method does the loT Security feature use to identify traffic sourced from IoT devices?
- A. The SRX Series device identifies loT devices from metadata extracted from their transit traffic.
- B. The SRX Series device streams metadata from the loT device transit traffic to Juniper ATP Cloud Juniper ATP Cloud.
- C. The SRX Series device streams transit traffic received from the IoT device to Juniper ATP Cloud.
- D. The SRX Series device identifies loT devices using their MAC address.
Answer: A
Explanation:
The metadata is used to identify the type of device, its associated activities and its threat profile. This information is used to determine the appropriate security policy for the device. For more information on loT Security, please refer to the Juniper Security, Specialist (JNCIS-SEC) study guide.
NEW QUESTION # 68
Exhibit
Which two statements are correct about the configuration shown in the exhibit? (Choose two.)
- A. Every session that enters the SRX Series device will generate an event
- B. The session-class parameter in only used when troubleshooting.
- C. The others 300 parameter means unidentified traffic flows will be dropped in 300 milliseconds.
- D. Replacing the session-init parameter with session-lose will log unidentified flows.
Answer: A,D
Explanation:
The log session-init; command within the policy configuration specifies that an event log entry will be created every time a session is initialized, meaning each new session will generate a log event. This is useful for tracking and analyzing the traffic flows entering the device.
Changing session-init to session-close in the log statement would mean that the device logs sessions when they close instead of when they open. This setting is typically used to log details about the session upon termination, which can help in analyzing the duration, end status, and other parameters of sessions, including those of unidentified flows.
NEW QUESTION # 69
On which three Hypervisors is vSRX supported? (Choose three.)
- A. KVM
- B. Oracle VM
- C. VMware ESXI
- D. Citrix Hypervisor
- E. Hyper-V
Answer: A,C,E
Explanation:
vSRX is a virtual firewall that runs as a software instance on a hypervisor. A hypervisor is a software layer that allows multiple virtual machines to run on a single physical host. vSRX supports three hypervisors: VMware ESXi, Hyper-V, and KVM. VMware ESXi is a hypervisor that runs on x86 servers and supports various operating systems and applications. Hyper-V is a hypervisor that runs on Windows Server and supports Windows and Linux virtual machines. KVM (Kernel-based Virtual Machine) is a hypervisor that runs on Linux and supports Linux, Windows, and other operating systems.
Reference: = vSRX Overview, VMware ESXi - Wikipedia, Hyper-V - Wikipedia, Kernel-based Virtual Machine - Wikipedia
NEW QUESTION # 70
Which two statements are correct about a policy scheduler? (Choose two.)
- A. A policy scheduler can be defined using a daily schedule.
- B. A policy scheduler determines the time frame that a security policy is actively evaluated.
- C. A policy scheduler can be dynamically activated based on traffic flow volumes.
- D. A policy scheduler can only be applied when using the policy-rematch feature.
Answer: A,B
Explanation:
A policy scheduler is a feature that allows a security policy to be activated or deactivated for a specified time period. You can define schedulers for a single or recurrent time slot within which a policy is active.
Two statements that are correct about a policy scheduler are:
A policy scheduler can be defined using a daily schedule: You can configure a scheduler to be active every day for a certain time interval, such as from 8:00 AM to 5:00 PM. You can also exclude specific days from the daily schedule, such as weekends or holidays.
A policy scheduler determines the time frame that a security policy is actively evaluated: When you associate a scheduler with a security policy, the policy is only available for policy lookup during the time frame specified by the scheduler. When the scheduler is off, the policy is inactive and cannot be matched by any traffic.
Reference: = Scheduling Security Policies, Configuring Schedulers for a Daily Schedule Excluding One Day
NEW QUESTION # 71
Click the Exhibit button.
Which two statements describe the output shown in the exhibit? (Choose two.)
- A. Redundancy group 1 experienced an operational failure.
- B. Node 0 is controlling traffic for redundancy group 1.
- C. Node 1 is controlling traffic for redundancy group 1.
- D. Redundancy group 1 was administratively failed over.
Answer: B,C
Explanation:
The output indicates that node1 has a priority of 200 and is marked as "Primary," which means it is currently the active node controlling traffic for redundancy group 1. The "Primary" status designates that this node is handling the traffic for the specified redundancy group.
According to the exhibit, node0 is listed with a priority of 0 and is marked as "Secondary." This status indicates that node0 is currently not controlling traffic for redundancy group 1, serving instead in a standby role ready to take over should node1 fail or become unavailable.
NEW QUESTION # 72
......
Prepare Top Juniper JN0-336 Exam Audio Study Guide Practice Questions Edition: https://testking.practicedump.com/JN0-336-exam-questions.html