Month End Sale Special - 75% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: newyear

Juniper JN0-336 - Security, Specialist (JNCIS-SEC)

Page: 2 / 2
Total 68 questions

You need to deploy an SRX Series device in your virtual environment.

In this scenario, what are two benefits of using a CSRX? (Choose two.)

A.

The cSRX supports Layer 2 and Layer 3 deployments.

B.

The cSRX default configuration contains three default zones: trust, untrust, and management.

C.

The cSRX supports firewall, NAT, IPS, and UTM services.

D.

The cSRX has low memory requirements.

Which two statements describe how Juniper ATP Cloud improves security? (Choose two.)

A.

It tracks and logs malicious traffic.

B.

It offers real-time threat analysis and mitigation.

C.

It simulates real user environments to trigger malicious code execution.

D.

It increases performance speeds.

Which two statements are correct about Juniper ATP Cloud malware analysis? (Choose two.)

A.

If no match exists in cache, the remaining analysis features are processed with the cumulative threat score transmitted to the SRX Series device.

B.

If a match exists in cache, that threat score is sent to the SRX Series device and the analysis continues.

C.

If a match exists in cache, that threat score is sent to the SRX Series device and the analysis stops.

D.

If no match exists in cache, the first analysis feature to generate a threat score is transmitted to the SRX Series device.

Which two statements are correct about cluster components? (Choose two.)

A.

Cluster ID values range from 1 through 255.

B.

Node ID values are either 0 or 1.

C.

Cluster ID values are either 0 or 1.

D.

Node ID values range from 1 through 255.

Which two statements about PC probes sent by the JIMS server are correct? (Choose two.)

A.

PC probes are triggered only when there is no IP-to-username mapping present in the event log.

B.

PC probes are sent by the JIMS server to domain PCs every 30 seconds.

C.

PC probes are sent by the JIMS server to domain PCs every 60 seconds.

D.

If a probe is successful, the authentication entry is updated on the JIMS server and pushed to the SRX.

You have configured a new site-to-site VPN tunnel. The exhibit shows the security IPsec statistics output for the specific tunnel index from one of the tunnel-end devices.

Which two statements are correct in this scenario? (Choose two.)

A.

AH is incorrectly configured.

B.

The far-end tunnel device is rebooting.

C.

The ESP configuration is not set up correctly.

D.

No traffic passes through this tunnel.

Referring to the exhibit, which two statements are correct? (Choose two.)

A.

IP address 192.168.1.10 is the SRX Series device.

B.

IP address 192.168.1.10 is the primary JIMS server.

C.

The JIMS server to the domain controller connection is online.

D.

The SRX Series device to the JIMS connection is online.

Which SRX Series device configuration setting must be configured first to use Juniper ATP Cloud?

A.

Start up the anti-malware service on the SRX Series device.

B.

Apply the firewall rules on the SRX Series device.

C.

Enable connectivity between the SRX Series device and Juniper ATP Cloud.

D.

Configure the anti-malware policies on the SRX Series device.

Which two statements are correct about client-protection Secure Socket Layer (SSL) proxy configurations? (Choose two.)

A.

Server certificate is required.

B.

Root certificate authority (CA) configuration is required.

C.

Root certificate authority (CA) configuration is not required.

D.

Server certificate is not required.

You are asked to set up SSL proxy in SRX Series devices. An SSL proxy profile is already defined for you.

Which two steps are required to complete the setup? (Choose two.)

A.

Enable host-inbound-traffic HTTPS in the security zone in which SSL proxy is referenced.

B.

Reference the SSL proxy profile in a security zone.

C.

Reference the SSL proxy profile in a security policy.

D.

Enable any Layer 7 services in the security policy in which SSL proxy is referenced.