Pre-Summer Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: best70

JN0-336 Security, Specialist (JNCIS-SEC) Questions and Answers

Questions 4

Which two statements are correct about IDP policy templates? (Choose two.)

Options:

A.

They are provided by Juniper Networks.

B.

They are not customizable.

C.

They are available on a “factory-default config.”

D.

They must be installed.

Buy Now
Questions 5

Which two statements are correct about client-protection Secure Socket Layer (SSL) proxy configurations? (Choose two.)

Options:

A.

Server certificate is required.

B.

Root certificate authority (CA) configuration is required.

C.

Root certificate authority (CA) configuration is not required.

D.

Server certificate is not required.

Buy Now
Questions 6

An administrator decides to designate a node as the primary node for the chassis cluster.

Which statement is correct in this scenario?

Options:

A.

Configure the burnt-in-address (BIA) to the highest value to bring the node as the primary node.

B.

The node with the highest priority will become a primary node.

C.

The node with the lowest priority will become a primary node.

D.

Nodes with a priority of one are ineligible to participate in the election process.

Buy Now
Questions 7

Which two statements are correct about fabric interfaces on an SRX Series Firewall? (Choose two.)

Options:

A.

In an active/active configuration, inter-chassis traffic uses the fab link.

B.

In an active/passive configuration, inter-chassis traffic uses the fab link.

C.

The node ID is reflected in the fabric interface name.

D.

The cluster ID is reflected in the fabric interface name.

Buy Now
Questions 8

What are two chassis cluster data plane interfaces? (Choose two.)

Options:

A.

swfab

B.

fab

C.

fxp1

D.

fxp0

Buy Now
Questions 9

Referring to the exhibit, what should you do to ensure that Juniper ATP Cloud detects malware in HTTPS traffic?

JN0-336 Question 9

Options:

A.

Manually configure and apply an SSL proxy profile.

B.

Lower the threat score.

C.

Configure a new device profile that includes encrypted traffic.

D.

Change the action to redirect the encrypted traffic to a decryption device.

Buy Now
Questions 10

You want to configure the SSL proxy feature on your SRX Series Firewall.

Which two actions must you perform to accomplish this task? (Choose two.)

Options:

A.

Enable the SSL ALG.

B.

Create an SSL proxy profile.

C.

Create an SSL application object.

D.

Associate an SSL proxy profile with a security policy.

Buy Now
Questions 11

Which two statements are correct about a chassis cluster? (Choose two.)

Options:

A.

If the cluster ID is set to 0, the HA configuration is ignored.

B.

You must reboot the device anytime you change the node ID configuration.

C.

If the node ID is set to 0, the HA configuration is ignored.

D.

You must have multiple Layer 2 domains if you require more than 255 node IDs.

Buy Now
Questions 12

Which SRX Series device configuration setting must be configured first to use Juniper ATP Cloud?

Options:

A.

Start up the anti-malware service on the SRX Series device.

B.

Apply the firewall rules on the SRX Series device.

C.

Enable connectivity between the SRX Series device and Juniper ATP Cloud.

D.

Configure the anti-malware policies on the SRX Series device.

Buy Now
Questions 13

You are asked to configure your company SRX Series device to use identity-aware security policies. Information about your Active Directory network is shown in the exhibit.

JN0-336 Question 13

In this scenario, why must you configure JIMS instead of Active Directory as an identity source?

Options:

A.

JIMS is the only way to get data from Active Directory.

B.

You have too many Active Directory users.

C.

The version of Windows OS is too old.

D.

You have too many domain controllers.

Buy Now
Questions 14

You need to set up a forward proxy on your SRX Series device.

In this scenario, which two statements are correct? (Choose two.)

Options:

A.

The forward proxy uses the managed SRX as a trusted certificate authority (CA).

B.

The forward proxy forwards the server certificate.

C.

The forward proxy looks like a client to the servers to which it communicates.

D.

The forward proxy uses Encrypted Traffic Insights to monitor traffic.

Buy Now
Questions 15

You have configured a new site-to-site VPN tunnel. The exhibit shows the security IPsec statistics output for the specific tunnel index from one of the tunnel-end devices.

JN0-336 Question 15

Which two statements are correct in this scenario? (Choose two.)

Options:

A.

AH is incorrectly configured.

B.

The far-end tunnel device is rebooting.

C.

The ESP configuration is not set up correctly.

D.

No traffic passes through this tunnel.

Buy Now
Questions 16

Which three actions does Junos Space Security Director perform during the device discovery process? (Choose three.)

Options:

A.

It imports the device’s active device configuration.

B.

it reboots the device.

C.

It imports device status information.

D.

It adds a local superuser account to the device configuration.

E.

It connects to the device using SSH.

Buy Now
Questions 17

Referring to the exhibit, which two statements are correct? (Choose two.)

JN0-336 Question 17

Options:

A.

Fabric link 0 is working.

B.

The control link is working.

C.

Fabric link 1 is failing.

D.

The control link is failing.

Buy Now
Questions 18

You are configuring a redundancy group using Ethernet interfaces.

In this scenario, which two actions must be performed? (Choose two.)

Options:

A.

Assign a physical interface from each node to the reth0 interface.

B.

Set the retry interval

C.

Define the number of reth interfaces in a cluster under the chassis cluster hierarchy.

D.

Configure the heartbeat interval.

Buy Now
Questions 19

What are two properties negotiated during IKE Phase 2? (Choose two.)

Options:

A.

routing protocol

B.

tunneling protocol

C.

aggressive mode

D.

Perfect Forward Secrecy

Buy Now
Exam Code: JN0-336
Exam Name: Security, Specialist (JNCIS-SEC)
Last Update: Jun 3, 2026
Questions: 66

PDF + Testing Engine

$134.99

Testing Engine

$99.99

PDF (Q&A)

$84.99