Summer Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: xmas50

Juniper JN0-336 - Security, Specialist (JNCIS-SEC)

Page: 1 / 2
Total 66 questions

Which three actions does Junos Space Security Director perform during the device discovery process? (Choose three.)

A.

It imports the device’s active device configuration.

B.

it reboots the device.

C.

It imports device status information.

D.

It adds a local superuser account to the device configuration.

E.

It connects to the device using SSH.

What are three policy types available in Junos Space Security Director? (Choose three.)

A.

device

B.

local

C.

group

D.

universal

E.

global

Which action will the SRX Series device take if traffic matches the custom attack object shown in the exhibit?

A.

the action taken is defined in the IDP policy that includes this attack object.

B.

the action taken is defined by the security policy.

C.

The SRX Series device will reject the traffic.

D.

The SRX series device will drop the traffic.

You need to secure communications from a mobile command center which uses a 5G mobile ISP behind CGNAT to an SRX Series Firewall at headquarters.

Which two actions should be performed on the SRX Series Firewall in this scenario? (Choose two.)

A.

Configure the IPsec VPN to use NAT-T.

B.

Configure the IPsec VPN to use IKEv1 aggressive mode.

C.

Configure the IPsec VPN to use IKEv2 aggressive mode.

D.

Configure the IPsec VPN to use DPD.

Which three algorithms are used to encrypt IP packets? (Choose three.)

A.

Data Encryption Standard (DES)

B.

Secure Hash Algorithm (SHA) - 1

C.

Message Digest 5 (MD5)

D.

Triple Data Encryption Standard (3DES)

E.

Advanced Encryption Standard (AES)

What are two types of attack objects included in an IDP attack object database? (Choose two.)

A.

statistic-based

B.

protocol anomaly-based

C.

signature-based

D.

vector-based

You are asked to set up SSL proxy in SRX Series devices. An SSL proxy profile is already defined for you.

Which two steps are required to complete the setup? (Choose two.)

A.

Enable host-inbound-traffic HTTPS in the security zone in which SSL proxy is referenced.

B.

Reference the SSL proxy profile in a security zone.

C.

Reference the SSL proxy profile in a security policy.

D.

Enable any Layer 7 services in the security policy in which SSL proxy is referenced.

A pair of branch SRX Series devices are booted up in cluster mode.

Referring to the exhibit, which statement is correct?

A.

the devices are not running the same version of Junos.

B.

the devices are not the same hardware.

C.

fxp0 or fxp1 on either device has an existing configuration.

D.

node1 is running a " factory-default config " .

You have configured a new site-to-site VPN tunnel. The exhibit shows the security IPsec statistics output for the specific tunnel index from one of the tunnel-end devices.

Which two statements are correct in this scenario? (Choose two.)

A.

AH is incorrectly configured.

B.

The far-end tunnel device is rebooting.

C.

The ESP configuration is not set up correctly.

D.

No traffic passes through this tunnel.

Referring to the exhibit, which two statements are correct? (Choose two.)

A.

IP address 192.168.1.10 is the SRX Series device.

B.

IP address 192.168.1.10 is the primary JIMS server.

C.

The JIMS server to the domain controller connection is online.

D.

The SRX Series device to the JIMS connection is online.