Get Jun-2026 Dumps to Pass your JN0-336 Exam with 100% Real Questions and Answers
Updated Exam JN0-336 Dumps with New Questions
NEW QUESTION # 23
Which solution enables you to create security policies that include user and group information?
- A. JIMS
- B. NETCONF
- C. ATP Appliance
- D. Network Director
Answer: A
Explanation:
The solution that enables you to create security policies that include user and group information is JIMS (Juniper Identity Management Service). JIMS collects and maintains a large database of user, device, and group information from Active Directory domains or syslog sources, and enables SRX Series devices to rapidly identify thousands of users in a large, distributed enterprise. With JIMS, you can create security policies that include user and group information, and enforce user-based access control policies to protect network resources.
NEW QUESTION # 24
You are asked to implement IPS on your SRX Series device.
In this scenario, which two tasks must be completed before a configuration will work? (Choose two.)
- A. Reboot the SRX Series device.
- B. Download the IPS signature database.
- C. Enroll the SRX Series device with Juniper ATP Cloud.
- D. Install the IPS signature database.
Answer: B,D
Explanation:
The two tasks that must be completed before a configuration for IPS on an SRX Series device will work are downloading the IPS signature database and installing the IPS signature database. The Security, Specialist (JNCIS-SEC) Study guide provides further information on how to download and install the IPS signature database. Enrolling the SRX Series device with Juniper ATP Cloud is not necessary to make a configuration work, and rebooting the SRX Series device is not required either.
NEW QUESTION # 25
Which two statements are true about application identification? (Choose two.)
- A. Application identification cannot identify nested applications that are within Layer 7.
- B. Application identification can identity nested applications that are within Layer 7.
- C. Application signatures are the same as IDP signatures.
- D. Application signatures are not the same as IDP signatures.
Answer: B,D
Explanation:
Application identification is a feature that enables SRX Series devices to identify and classify network traffic based on application signatures or custom rules. Application identification can enhance security, visibility, and control over network applications.
Two statements that are true about application identification are:
Application identification can identify nested applications that are within Layer 7: Nested applications are applications that run within another application protocol, such as HTTP or SSL. For example, Facebook or YouTube are nested applications within HTTP. Application identification can identify nested applications by inspecting the application payload and matching it against predefined or custom signatures.
Application signatures are not the same as IDP signatures: Application signatures are patterns of bytes or strings that uniquely identify an application protocol or a nested application. IDP signatures are patterns of bytes or strings that indicate an attack or an exploit against a vulnerability. Application signatures are used for application identification and classification, while IDP signatures are used for intrusion detection and prevention.
Reference: = [Application Identification Overview], [Application Identification Concepts], [Understanding Signature Rules and Protocol Anomaly Rules]
NEW QUESTION # 26
Click the Exhibit button.
Referring to the exhibit, what will the SRX Series device do in this configuration?
- A. Packets from the infected hosts with a threat level of 8 will be dropped and a log message will be generated.
- B. Packets from the infected hosts with a threat level of 8 or above will be dropped and a log message will be generated.
- C. Packets from the infected hosts with a threat level of 8 or above will be dropped and no log message will be generated.
- D. Packets from the infected hosts with a threat level of 8 will be dropped and no log message will be generated.
Answer: C
Explanation:
The exhibit shows a configuration snippet for security intelligence on an SRX Series device. Security intelligence is a feature that allows you to block or monitor traffic from malicious sources based on threat intelligence feeds from Juniper ATP Cloud or other providers. The configuration defines a profile for ATP Infected-Hosts, which is a feed that contains IP addresses of hosts that are infected with malware and communicate with command-and-control servers. The configuration also defines a rule for threat level 8, which is a parameter that indicates the severity of the threat.
Based on this configuration, the SRX Series device will do the following:
Packets from the infected hosts with a threat level of 8 or above will be dropped: The action block-and- drop under the rule means that the device will block any traffic from the infected hosts that have a threat level equal to or higher than 8. This will prevent the hosts from sending or receiving malicious commands or data.
No log message will be generated: The absence of any log option under the rule means that the device will not generate any log message for the blocked traffic. This may reduce the load on the device and the logging server, but it may also limit the visibility and analysis of the security events. Reference: = Security Intelligence Theory, Firewall Filter Support on Loopback Interface
NEW QUESTION # 27
Which two statements about SRX Series device chassis clusters are correct? (Choose two.)
- A. The chassis cluster can contain a maximum of three devices.
- B. The chassis cluster data plane is connected with revenue ports.
- C. The chassis cluster can contain a maximum of two devices.
- D. The chassis cluster data plane is connected with SPC ports.
Answer: B,C
Explanation:
Two statements that are correct about SRX Series device chassis clusters are:
The chassis cluster data plane is connected with revenue ports: A chassis cluster is a high-availability feature that groups two identical SRX Series devices into a cluster that acts as a single device. The cluster has two types of links: control links and fabric links. The control links are used for exchanging heartbeat messages and configuration synchronization between the nodes. The fabric links are used for forwarding data traffic between the nodes. The fabric links are connected with revenue ports, which are regular Ethernet interfaces that can also be used for normal traffic when not in cluster mode.
The chassis cluster can contain a maximum of two devices: A chassis cluster can only consist of two nodes: node 0 and node 1. The nodes must be the same model, have the same hardware configuration, run the same software version, and have the same license keys. The nodes share a common configuration and act as backup for each other in case of failure.
Reference: = Configuring Chassis Clustering on SRX Series Devices, SRX Series Chassis Cluster Configuration Overview, Connecting SRX Series Firewalls to Create a Chassis Cluster
NEW QUESTION # 28
Which method does the loT Security feature use to identify traffic sourced from IoT devices?
- A. The SRX Series device identifies loT devices using their MAC address.
- B. The SRX Series device streams metadata from the loT device transit traffic to Juniper ATP Cloud Juniper ATP Cloud.
- C. The SRX Series device identifies loT devices from metadata extracted from their transit traffic.
- D. The SRX Series device streams transit traffic received from the IoT device to Juniper ATP Cloud.
Answer: C
Explanation:
The metadata is used to identify the type of device, its associated activities and its threat profile. This information is used to determine the appropriate security policy for the device. For more information on loT Security, please refer to the Juniper Security, Specialist (JNCIS-SEC) study guide.
NEW QUESTION # 29
Exhibit
Referring to the SRX Series flow module diagram shown in the exhibit, where is application security processed?
- A. Security Policy
- B. Services ALGs
- C. Screens
- D. Forwarding Lookup
Answer: B
NEW QUESTION # 30
Exhibit
Referring to the exhibit which statement is true?
- A. SSL proxy leverages pre-match result
- B. SSL proxy leverages post-match results.
- C. SSL proxy functions will ignore the session.
- D. SSL proxy must wait for return traffic for the final match to occur.
Answer: D
NEW QUESTION # 31
When a security policy is modified, which statement is correct about the default behavior for active sessions allowed by that policy?
- A. The active sessions allowed by the policy will continue unchanged.
- B. The active sessions allowed by the policy will be dropped.
- C. Only policy changes that involve modification of the action field will cause the active sessions affected by the change to be dropped.
- D. Only policy changes that involve modification of the application will cause the active sessions affected by the change to be dropped.
Answer: A
Explanation:
When you modify a security policy on the SRX Series device, the default behavior is that the existing sessions that match the policy will continue unchanged. This means that the policy modification will only affect new sessions that are initiated after the change. However, you can change this behavior by using the clear-policy-session command, which will clear all the sessions that match the modified policy and force them to re-evaluate the new policy. Reference: = JNCIS-SEC Certification, Open Learning - Security, Specialist (JNCIS-SEC), Security Policies (Advanced)
NEW QUESTION # 32
Which two statements are correct about a reth LAG? (Choose two.)
- A. You should have two or more interfaces.
- B. You must have a "minimum-links" statement value of two.
- C. Links must use the same cable type
- D. Links must have the same speed and duplex setting.
Answer: A,D
Explanation:
A reth LAG is a redundant Ethernet link aggregation group that combines multiple physical interfaces into a single logical interface in a chassis cluster. A reth LAG provides load balancing and redundancy for traffic within or between redundancy groups. Two statements that are correct about a reth LAG are:
Links must have the same speed and duplex setting: To form a reth LAG, the physical interfaces must have the same speed and duplex setting. This ensures that the links can operate at the same capacity and avoid performance issues or errors.
You should have two or more interfaces: To create a reth LAG, you need to have at least two physical interfaces. One interface should be connected to node 0 and the other interface should be connected to node 1. You can also have more than two interfaces in a reth LAG for increased bandwidth and redundancy.
Reference: = Configuring Redundant Ethernet Interfaces, [Understanding Redundant Ethernet Interfaces]
NEW QUESTION # 33
Click the Exhibit button.
Which two statements about the log output shown in the exhibit are correct? (Choose two?
- A. Traffic destined to the HTTP server is placed in an IPsec tunnel
- B. AppTrack is enabled on the trost zone:
- C. AppTrack is enabled on the untrust zone
- D. Source NAT is performed
Answer: B,D
NEW QUESTION # 34
You administer a JSA host and want to include a rule that sets a threshold for excessive firewall denies and sends an SNMP trap after receiving related syslog messages from an SRX Series firewall.
Which JSA rule type satisfies this requirement?
- A. common
- B. flow
- C. offense
- D. event
Answer: C
Explanation:
An offense rule in JSA is designed to aggregate multiple events or log entries based on specified criteria into a single offense, which can then trigger responses such as notifications or actions like sending an SNMP trap. This type of rule is well-suited for scenarios where you need to monitor for patterns or rates of events, such as excessive firewall denies, and take action when these exceed defined thresholds.
Offense rules can analyze both event and flow data, making them highly versatile for comprehensive security monitoring.
NEW QUESTION # 35
Which two statements are correct about the fab interface in a chassis cluster? (Choose two.)
- A. Heartbeat signals sent on the fab interface monitor the health of the control plane link.
- B. The fab interface enables configuration synchronization.
- C. Real-time objects (RTOs) are exchanged on the fab interface to maintain session synchronization.
- D. In an active/active configuration, inter-chassis transit traffic is sent over the fab interface.
Answer: C,D
Explanation:
The fab interface is a fabric link that connects the two nodes in a chassis cluster. A chassis cluster is a high-availability feature that groups two identical SRX Series devices into a cluster that acts as a single device.
The fab interface has two functions:
Real-time objects (RTOs) are exchanged on the fab interface to maintain session synchronization: RTOs are data structures that store information about active sessions, such as source and destination IP addresses, ports, protocols, and security policies. RTOs are exchanged between the nodes on the fab interface to ensure that both nodes have the same session information and can take over the traffic in case of a failover.
In an active/active configuration, inter-chassis transit traffic is sent over the fab interface: In an active/active configuration, both nodes in a cluster can process traffic for different redundancy groups (RGs). RGs are collections of interfaces or services that fail over together from one node to another. If traffic needs to transit from one RG to another RG that is active on a different node, it is sent over the fab interface.
Reference: = Configuring Chassis Clustering on SRX Series Devices, Chassis Cluster Redundancy Groups, Chassis Cluster Data Plane
NEW QUESTION # 36
What are three capabilities of AppQoS? (Choose three.)
- A. re-write DSCP values
- B. re-write the TTL
- C. assign a forwarding class
- D. rate-limit traffic
- E. reserve bandwidth
Answer: A,C,D
Explanation:
AppQoS can modify the DSCP (Differentiated Services Code Point) values in IP packet headers. This is crucial for defining the level of service for each packet, influencing how network devices prioritize traffic.
It can assign traffic to specific forwarding classes. This feature allows network administrators to group different types of traffic (e.g., VoIP, streaming, bulk data) into categories that are treated differently based on predefined network policies, ensuring that critical applications receive the necessary bandwidth and priority.
AppQoS is capable of rate-limiting traffic, which involves setting a maximum bandwidth limit for certain types of traffic. This ensures that no single application or service consumes more bandwidth than allocated, thus preventing network congestion and ensuring fair bandwidth distribution among all applications.
These features are essential for managing network performance and ensuring that critical applications receive the necessary resources to function effectively. AppQoS does not inherently include capabilities to re-write TTL (Time To Live) values or reserve bandwidth as primary functions, but it manages bandwidth usage through rate limiting and priority settings.
NEW QUESTION # 37
What are two types of system logs that Junos generates? (Choose two.)
- A. control plane logs
- B. SQL log files
- C. system core dump files
- D. data plane logs
Answer: A,D
Explanation:
The two types of system logs that Junos generates are control plane logs and data plane logs. Control plane logs are generated by the Junos operating system and contain system-level events such as system startup and shutdown, configuration changes, and system alarms. Data plane logs are generated by the network protocol processes and contain messages about the status of the network and its components, such as routing, firewall, NAT, and IPS. SQL log files and system core dump files are not types of system logs generated by Junos.
NEW QUESTION # 38
You have implemented a vSRX in your VMware environment. You want to implement a second vSRX Series device and enable chassis clustering.
Which two statements are correct in this scenario about the control-link settings? (Choose two.)
- A. In the vSwitch properties settings, set the VLAN ID to None.
- B. In the vSwitch security settings, reject forged transmits.
- C. In the vSwitch security settings, accept promiscuous mode.
- D. In the vSwitch security settings, reject MAC address changes.
Answer: C,D
NEW QUESTION # 39
You are troubleshooting unexpected issues on your JIMS server due to out of order event log timestamps.
Which action should you take to solve this issue?
- A. Enable time synchronization on the client devices.
- B. Enable time synchronization on the domain controllers.
- C. Enable time synchronization on the SRX Series devices.
- D. Enable time synchronization on the JIMS server.
Answer: B
Explanation:
To solve the issue of out of order event log timestamps on your JIMS server, you should enable time synchronization on the domain controllers. JIMS (Juniper Identity Management Service) is a Windows service that collects user, device, and group information from Active Directory domains or syslog sources and provides it to SRX Series devices and CSO for identity-based security policies. JIMS relies on the timestamps of the event logs generated by the domain controllers to track user logins, logouts, and IP address changes. If the domain controllers have different or inaccurate clocks, the event logs may have out of order or incorrect timestamps, which can cause JIMS to miss or misinterpret some events and affect its accuracy and performance. Therefore, you should ensure that all the domain controllers in your network are synchronized with a reliable time source, such as an NTP server or a Windows Time service. Reference: = Juniper Identity Management Service User Guide, Juniper Identity Management Service Feature Guide, Configure JIMS Collector to Get Microsoft Event Logs, Considerations for timestamps in centralized logging platforms
NEW QUESTION # 40
Your company is using the Juniper ATP Cloud free model. The current inspection profile is set at 10 MB You are asked to configure ATP Cloud so that executable files up to 30 MB can be scanned while at the same time minimizing the change in scan time for other file types.
Which configuration should you use in this scenario?
- A. Use the ATP Cloud Ul to change the default profile to increase the scan limit for all files to 30 MB.
- B. Use the CLI to create a custom profile and increase the scan limit.
- C. Use the CLI to change the default profile to increase the scan limit for all files to 30 MB.
- D. Use the ATP Cloud Ul to update a custom profile and increase the scan limit for executable files to 30 MB.
Answer: D
Explanation:
In this scenario, you should use the ATP Cloud Ul to create a custom profile and update the scan limit for executable files to 30 MB. This will ensure that executable files up to 30 MB can be scanned, while at the same time minimizing the change in scan time for other file types. To do this, log in to the ATP Cloud Ul and go to the Profiles tab. Click the Create button to create a new profile, and then adjust the scan limits for executable files to 30 MB. Once you have saved the custom profile, you can apply it to the desired systems and the new scan limit will be in effect.
NEW QUESTION # 41
You are asked to reduce the load that the JIMS server places on your
Which action should you take in this situation?
- A. Connect JIMS to another SRX Series device.
- B. Connect JIMS to the domain Exchange server
- C. Connect JIMS to the RADIUS server
- D. Connect JIMS to the domain SQL server.
Answer: A
Explanation:
JIMS server is a Juniper Identity Management Service that collects user identity information from different authentication sources for SRX Series devices12. It can connect to SRX Series devices and CSO platform in your network1.
NEW QUESTION # 42
You are currenty using a third-party threat analyzer. You want your SRX Series device to send decrypted SSE traffic to......
In this scenario, which feature should you configure on the SRX device?
- A. JSA vulnerability assessment
- B. IPS IPanotify action
- C. SSL decryption mirroring
- D. Phase 2 proxy ID
Answer: A,B
NEW QUESTION # 43
Exhibit
You just finished setting up your command-and-control (C&C) category with Juniper ATP Cloud. You notice that all of the feeds have zero objects in them.
Which statement is correct in this scenario?
- A. The security intelligence policy must be configured; on a unified security policy
- B. Set the maximum C&C entries within the Juniper ATP Cloud GUI.
- C. Use the commit full command to start the download.
- D. No action is required, the feeds take a few minutes to download.
Answer: D
Explanation:
According to the Juniper Networks JNCIS-SEC Study Guide, when you set up your command-and- control (C&C) category with Juniper ATP Cloud, all of the feeds will initially have zero objects in them.
This is normal, as it can take a few minutes for the feeds to download. No action is required in this scenario and you will notice the feeds start to populate with objects once the download is complete.
NEW QUESTION # 44
You want to control when cluster failovers occur.
In this scenario, which two specific parameters would you configure on an SRX Series device? (Choose two.)
- A. heartbeat-interval
- B. heartbeat-address
- C. heartbeat-cos
- D. heartbeat-threshold
Answer: A,D
Explanation:
To control when cluster failovers occur, you need to configure two specific parameters on an SRX Series device: heartbeat-interval and heartbeat-threshold. These parameters determine how often the nodes in a cluster exchange heartbeat messages and how many consecutive heartbeats can be missed before a failover is triggered. The heartbeat-interval specifies the time interval in seconds between each heartbeat message. The default value is 1 second and the range is from 0.1 to 10 seconds. The heartbeat- threshold specifies the number of consecutive heartbeats that must be missed before a failover occurs.
The default value is 3 and the range is from 2 to 255.
Reference: = Configuring Chassis Clustering on SRX Series Devices, Chassis Cluster Redundancy Group Failover
NEW QUESTION # 45
Click the Exhibit button.
You are asked to create a security policy that will automatically add infected hosts to the infected hosts feed and block further communication through the SRX Series device.
What needs to be added to this configuration to complete this task?
- A. Add a security intelligence policy to the permit portion of the security policy.
- B. Add an action to the permit portion of the security policy.
- C. Add logging to the permit portion of the security policy.
- D. Add a match rule to the security policy with an appropriate threat level.
Answer: A
Explanation:
To create a security policy that will automatically add infected hosts to the infected hosts feed and block further communication through the SRX Series device, you need to add a security intelligence policy to the permit portion of the security policy. A security intelligence policy is a policy that allows you to block or monitor traffic from malicious sources based on threat intelligence feeds from Juniper ATP Cloud or other providers. One of the feeds that you can use is the Infected-Hosts feed, which contains IP addresses of hosts that are infected with malware and communicate with command-and-control servers.
You can create a profile and a rule for the Infected-Hosts feed and specify the threat level and the action to take for the infected hosts. Then, you can link the security intelligence policy with the firewall policy and apply it to the traffic that you want to protect. Reference: = Security Intelligence Overview, Configuring Security Intelligence Policy, Configure the Security Intelligence Policy on the SRX Series Device
NEW QUESTION # 46
......
100% Pass Guarantee for JN0-336 Exam Dumps with Actual Exam Questions: https://prep4sure.vce4dumps.com/JN0-336-latest-dumps.html