Pre-Summer Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the Juniper JNCIS-SEC JN0-336 Questions and answers with CertsForce

Viewing page 1 out of 2 pages
Viewing questions 1-10 out of questions
Questions # 1:

How does the SSL proxy detect if a particular session is SSL encrypted?

Options:

A.

It uses AppID services.


B.

It verifies the length of the packet.


C.

It looks at the destination port number.


D.

It uses a certificate authority (CA).


Expert Solution
Questions # 2:

How does the SSL proxy service identify SSL traffic?

Options:

A.

by examining the URL


B.

by using AppID results


C.

by examining the destination port


D.

by reading the server certificate


Expert Solution
Questions # 3:

Which action will the SRX Series device take if traffic matches the custom attack object shown in the exhibit?

Question # 3

Options:

A.

the action taken is defined in the IDP policy that includes this attack object.


B.

the action taken is defined by the security policy.


C.

The SRX Series device will reject the traffic.


D.

The SRX series device will drop the traffic.


Expert Solution
Questions # 4:

You need to deploy an SRX Series device in your virtual environment.

In this scenario, what are two benefits of using a CSRX? (Choose two.)

Options:

A.

The cSRX supports Layer 2 and Layer 3 deployments.


B.

The cSRX default configuration contains three default zones: trust, untrust, and management.


C.

The cSRX supports firewall, NAT, IPS, and UTM services.


D.

The cSRX has low memory requirements.


Expert Solution
Questions # 5:

You are deploying a new SRX Series device and you need to log denied traffic.

In this scenario, which two policy parameters are required to accomplish this task? (Choose two.)

Options:

A.

session-init


B.

session-close


C.

deny


D.

count


Expert Solution
Questions # 6:

You have configured a new site-to-site VPN tunnel. The exhibit shows the security IPsec statistics output for the specific tunnel index from one of the tunnel-end devices.

Question # 6

Which two statements are correct in this scenario? (Choose two.)

Options:

A.

AH is incorrectly configured.


B.

The far-end tunnel device is rebooting.


C.

The ESP configuration is not set up correctly.


D.

No traffic passes through this tunnel.


Expert Solution
Questions # 7:

What are two properties negotiated during IKE Phase 2? (Choose two.)

Options:

A.

routing protocol


B.

tunneling protocol


C.

aggressive mode


D.

Perfect Forward Secrecy


Expert Solution
Questions # 8:

Regarding static attack object groups, which two statements are true? (Choose two.)

Options:

A.

Matching attack objects are automatically added to a custom group.


B.

Group membership automatically changes when Juniper updates the IPS signature database.


C.

Group membership does not automatically change when Juniper updates the IPS signature database.


D.

You must manually add matching attack objects to a custom group.


Expert Solution
Questions # 9:

You are asked to onboard an SRX Series device to Junos Space Security Director, but it is not working.

In this scenario, what are three areas that should be reviewed? (Choose three.)

Options:

A.

chassis serial number


B.

SSH port number


C.

active security policies


D.

authentication credentials


E.

IP address


Expert Solution
Questions # 10:

Which two statements are correct about a chassis cluster? (Choose two.)

Options:

A.

If the cluster ID is set to 0, the HA configuration is ignored.


B.

You must reboot the device anytime you change the node ID configuration.


C.

If the node ID is set to 0, the HA configuration is ignored.


D.

You must have multiple Layer 2 domains if you require more than 255 node IDs.


Expert Solution
Viewing page 1 out of 2 pages
Viewing questions 1-10 out of questions