Spring Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code = getmirror

Pass the Juniper JNCIS-SEC JN0-336 Questions and answers with ExamsMirror

Practice at least 50% of the questions to maximize your chances of passing.
Exam JN0-336 Premium Access

View all detail and faqs for the JN0-336 exam


791 Students Passed

88% Average Score

92% Same Questions
Viewing page 2 out of 2 pages
Viewing questions 11-20 out of questions
Questions # 11:

Which two statements are correct about Juniper Secure Connect? (Choose two.)

Options:

A.

Juniper Secure Connect uses a policy-based VPN.

B.

Juniper Secure Connect can use a self-signed certificate.

C.

Juniper Secure Connect uses a route-based VPN.

D.

Juniper Secure Connect cannot use a self-signed certificate.

Questions # 12:

What are two properties negotiated during IKE Phase 2? (Choose two.)

Options:

A.

routing protocol

B.

tunneling protocol

C.

aggressive mode

D.

Perfect Forward Secrecy

Questions # 13:

Which two statements are correct about IDP policy templates? (Choose two.)

Options:

A.

They are provided by Juniper Networks.

B.

They are not customizable.

C.

They are available on a “factory-default config.”

D.

They must be installed.

Questions # 14:

How does Juniper’s identity-aware firewall facilitate compliance with security policies and regulations?

Options:

A.

by granting access based on user roles or identities

B.

by simplifying the design of the network architecture

C.

by increasing network capacity to accommodate user requirements

D.

by enforcing the need for user confidentiality

Questions # 15:

Which two statements about proxy IDs are correct? (Choose two.)

Options:

A.

Proxy IDs cannot override default Junos behavior.

B.

By default, for a route-based IPsec VPN, a Junos security device sets the proxy ID to 0.0.0.0/0.

C.

Proxy IDs must match on both peers for a Phase 2 tunnel to establish.

D.

Proxy IDs are created during IKE Phase 1.

Questions # 16:

You are deploying a new SRX Series device and you need to log denied traffic.

In this scenario, which two policy parameters are required to accomplish this task? (Choose two.)

Options:

A.

session-init

B.

session-close

C.

deny

D.

count

Questions # 17:

Using Junos Space Security Director, you want to configure a unique firewall policy for a specific SRX Series device.

Which firewall policy rules would satisfy the requirement?

Options:

A.

all devices policy prerules

B.

group policy prerules

C.

device policy rules

D.

all devices policy postrules

Questions # 18:

You are establishing an IPsec VPN and must ensure that payload data is encrypted.

In this scenario, which IPsec security protocol should you configure?

Options:

A.

SHA-1

B.

ESP

C.

AH

D.

PFS

Questions # 19:

What are two ways to help reduce false positives for an IDP rule? (Choose two.)

Options:

A.

Change the rule to a lower severity action.

B.

Remove the attack object from the rule.

C.

Create an exempt rule.

D.

Configure a terminal rule at the end of the rule base.

Viewing page 2 out of 2 pages
Viewing questions 11-20 out of questions
TOP CODES

TOP CODES

Top selling exam codes in the certification world, popular, in demand and updated to help you pass on the first try.