Pre-Summer Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the Juniper JNCIS-SEC JN0-336 Questions and answers with CertsForce

Viewing page 2 out of 2 pages
Viewing questions 11-20 out of questions
Questions # 11:

Which two statements are correct about fabric interfaces on an SRX Series Firewall? (Choose two.)

Options:

A.

In an active/active configuration, inter-chassis traffic uses the fab link.


B.

In an active/passive configuration, inter-chassis traffic uses the fab link.


C.

The node ID is reflected in the fabric interface name.


D.

The cluster ID is reflected in the fabric interface name.


Expert Solution
Questions # 12:

Which two statements are correct about Juniper Secure Connect? (Choose two.)

Options:

A.

Juniper Secure Connect uses a policy-based VPN.


B.

Juniper Secure Connect can use a self-signed certificate.


C.

Juniper Secure Connect uses a route-based VPN.


D.

Juniper Secure Connect cannot use a self-signed certificate.


Expert Solution
Questions # 13:

Which rule base in an IDP policy is used to eliminate false positives?

Options:

A.

IPS


B.

monitor


C.

signature


D.

exempt


Expert Solution
Questions # 14:

What are two types of attack objects included in an IDP attack object database? (Choose two.)

Options:

A.

statistic-based


B.

protocol anomaly-based


C.

signature-based


D.

vector-based


Expert Solution
Questions # 15:

You are implementing an SRX Series device at a branch office that has low bandwidth and also uses a cloud-based VoIP solution with an outbound policy that permits all traffic.

Which service would you implement at your edge device to prioritize VoIP traffic in this scenario?

Options:

A.

AppFW


B.

SIP ALG


C.

AppQoE


D.

AppQoS


Expert Solution
Questions # 16:

You want to include a custom attack object named Custom-FTP-Attack and set the action to drop the packet.

Question # 16

Referring to the exhibit, which modifications would you make?

Options:

A.

Add custom-attack Custom-FTP-Attack to the attacks section and change the action to close-client.


B.

Add custom-attack Custom-FTP-Attack to the attacks section and change the action to drop-packet.


C.

Add custom-attack Custom-FTP-Attack to the action section and change the action to drop-packet.


D.

Add custom-attack Custom-FTP-Attack to the notification section and change the action to drop-packet.


Expert Solution
Questions # 17:

What are two chassis cluster data plane interfaces? (Choose two.)

Options:

A.

swfab


B.

fab


C.

fxp1


D.

fxp0


Expert Solution
Questions # 18:

Which SRX Series device configuration setting must be configured first to use Juniper ATP Cloud?

Options:

A.

Start up the anti-malware service on the SRX Series device.


B.

Apply the firewall rules on the SRX Series device.


C.

Enable connectivity between the SRX Series device and Juniper ATP Cloud.


D.

Configure the anti-malware policies on the SRX Series device.


Expert Solution
Questions # 19:

Which two statements are correct about the security associations of an IPsec VPN? (Choose two.)

Options:

A.

IPsec security associations are established during IKEv1 Phase 2 negotiations.


B.

IKEv1 security associations are established during IKEv1 Phase 2 negotiations.


C.

IPsec security associations are established during IKEv1 Phase 1 negotiations.


D.

IKEv1 security associations are established during IKEv1 Phase 1 negotiations.


Expert Solution
Viewing page 2 out of 2 pages
Viewing questions 11-20 out of questions