Spring Sale Limited Time 75% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code = simple75

Pass the Juniper JNCIS-SEC JN0-336 Questions and answers with Dumpstech

Exam JN0-336 Premium Access

View all detail and faqs for the JN0-336 exam

Practice at least 50% of the questions to maximize your chances of passing.
Viewing page 2 out of 2 pages
Viewing questions 11-20 out of questions
Questions # 11:

You are establishing an IPsec VPN and must ensure that payload data is encrypted.

In this scenario, which IPsec security protocol should you configure?

Options:

A.

SHA-1

B.

ESP

C.

AH

D.

PFS

Questions # 12:

Which two statements about proxy IDs are correct? (Choose two.)

Options:

A.

Proxy IDs cannot override default Junos behavior.

B.

By default, for a route-based IPsec VPN, a Junos security device sets the proxy ID to 0.0.0.0/0.

C.

Proxy IDs must match on both peers for a Phase 2 tunnel to establish.

D.

Proxy IDs are created during IKE Phase 1.

Questions # 13:

You have configured a new site-to-site VPN tunnel. The exhibit shows the security IPsec statistics output for the specific tunnel index from one of the tunnel-end devices.

Question # 13

Which two statements are correct in this scenario? (Choose two.)

Options:

A.

AH is incorrectly configured.

B.

The far-end tunnel device is rebooting.

C.

The ESP configuration is not set up correctly.

D.

No traffic passes through this tunnel.

Questions # 14:

You are asked to ensure that traffic that matches an IDP policy is not impacted until administrators have a chance to evaluate it.

In this scenario, which IP action should be configured for the policy?

Options:

A.

ip-block

B.

ip-notify

C.

ip-connection-rate-limit

D.

ip-close

Questions # 15:

Which two steps are necessary to prepare the Active Directory domain for a JIMS installation? (Choose two.)

Options:

A.

Create two limited access user accounts.

B.

Create three limited access user accounts.

C.

Add one full access user account to Active Directory groups.

D.

Add limited access user accounts to Active Directory groups.

Questions # 16:

You are asked to onboard an SRX Series device to Junos Space Security Director, but it is not working.

In this scenario, what are three areas that should be reviewed? (Choose three.)

Options:

A.

chassis serial number

B.

SSH port number

C.

active security policies

D.

authentication credentials

E.

IP address

Questions # 17:

Which rule base in an IDP policy is used to eliminate false positives?

Options:

A.

IPS

B.

monitor

C.

signature

D.

exempt

Questions # 18:

Which two statements about PC probes sent by the JIMS server are correct? (Choose two.)

Options:

A.

PC probes are triggered only when there is no IP-to-username mapping present in the event log.

B.

PC probes are sent by the JIMS server to domain PCs every 30 seconds.

C.

PC probes are sent by the JIMS server to domain PCs every 60 seconds.

D.

If a probe is successful, the authentication entry is updated on the JIMS server and pushed to the SRX.

Questions # 19:

What is a function of the Juniper Identity Management Service?

Options:

A.

encrypting user e-mail

B.

logging malicious code sent through ingress and egress ports

C.

encrypting network data traffic

D.

maintaining a centralized authentication table

Viewing page 2 out of 2 pages
Viewing questions 11-20 out of questions