Pass the Juniper JNCIP-SEC JN0-636 Questions and answers with CertsForce

Viewing page 1 out of 4 pages
Viewing questions 1-10 out of questions
Questions # 1:

To analyze and detect malware, Juniper ATP Cloud performs which two functions? (Choose two.)

Options:

A.

cache lookup: to see if the file is seen already and known to be malicious


B.

antivirus scan: with a single vendor solution to see if the file contains any potential threats


C.

dynamic analysis: to see what happens if you execute the file in a real environment


D.

static analysis: to see what happens if you execute the file in a real environment


Questions # 2:

Exhibit

Question # 2

Which two statements are correct about the output shown in the exhibit. (Choose two.)

Options:

A.

The source address is translated.


B.

The packet is an SSH packet


C.

The packet matches a user-configured policy


D.

The destination address is translated.


Questions # 3:

Exhibit

Question # 3

You are using ATP Cloud and notice that there is a host with a high number of ETI and C&C hits sourced from the same investigation and notice that some of the events have not been automatically mitigated.

Referring to the exhibit, what is a reason for this behavior?

Options:

A.

The C&C events are false positives.


B.

The infected host score is globally set bellow a threat level of 5.


C.

The infected host score is globally set above a threat level of 5.


D.

The ETI events are false positives.


Questions # 4:

Exhibit:

Question # 4

Referring to the exhibit, which two statements are correct?

Options:

A.

All of the entries are a threat level 8


B.

All of the entries are command and control entries.


C.

All of the entries are Dshield entries


D.

All of the entries are a threat level 10.


Questions # 5:

Exhibit.

Question # 5

Referring to the exhibit, a spoke member of an ADVPN is not functioning correctly.

Which two commands will solve this problem? (Choose two.)

Options:

A.

[edit interfaces]

user@srx# delete st0.0 multipoint


B.

[edit security ike gateway advpn-gateway]

user@srx# delete advpn partner


C.

[edit security ike gateway advpn-gateway]

user@srx# set version v1-only


D.

[edit security ike gateway advpn-gateway]

user@srx# set advpn suggester disable


Questions # 6:

You are asked to configure a security policy on the SRX Series device. After committing the policy, you receive the “Policy is out of sync between RE and PFE .” error.

Which command would be used to solve the problem?

Options:

A.

request security polices resync


B.

request service-deployment


C.

request security polices check


D.

restart security-intelligence


Questions # 7:

Exhibit

Question # 7

You are not able to ping the default gateway of 192.168 100 1 (or your network that is located on your SRX Series firewall.

Referring to the exhibit, which two commands would correct the configuration of your SRX Series device? (Choose two.)

A)

Question # 7

B)

Question # 7

C)

Question # 7

D)

Question # 7

Options:

A.

Option A


B.

Option B


C.

Option C


D.

Option D


Questions # 8:

You configured a chassis cluster for high availability on an SRX Series device and enrolled this HA cluster with the Juniper ATP Cloud. Which two statements are correct in this scenario? (Choose two.)

Options:

A.

You must use different license keys on both cluster nodes.


B.

When enrolling your devices, you only need to enroll one node.


C.

You must set up your HA cluster after enrolling your devices with Juniper ATP Cloud


D.

You must use the same license key on both cluster nodes.


Questions # 9:

Exhibit

Question # 9

You are validating bidirectional traffic flows through your IPsec tunnel. The 4546 session represents traffic being sourced from the remote end of the IPsec tunnel. The 4547 session represents traffic that is sourced from the local network destined to the remote network.

Which statement is correct regarding the output shown in the exhibit?

Options:

A.

The remote gateway address for the IPsec tunnel is 10.20.20.2


B.

The session information indicates that the IPsec tunnel has not been established


C.

The local gateway address for the IPsec tunnel is 10.20.20.2


D.

NAT is being used to change the source address of outgoing packets


Questions # 10:

you configured a security policy permitting traffic from the trust zone to the untrust zone but your

traffic not hitting the policy.

In this scenario, which cli command allows you to troubleshoot traffic problem using the match criteria?

Options:

A.

show security policy-report


B.

show security application-tracking counters


C.

show security match-policies


D.

request security policies check


Viewing page 1 out of 4 pages
Viewing questions 1-10 out of questions