Spring Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: pass65

JN0-336 Security, Specialist (JNCIS-SEC) Questions and Answers

Questions 4

You are establishing an IPsec VPN and must ensure that payload data is encrypted.

In this scenario, which IPsec security protocol should you configure?

Options:

A.

SHA-1

B.

ESP

C.

AH

D.

PFS

Buy Now
Questions 5

Which IDP action is also referred to as a silent discard?

Options:

A.

no action

B.

close client and server

C.

ignore connection

D.

drop packet

Buy Now
Questions 6

You are deploying a new SRX Series device and you need to log denied traffic.

In this scenario, which two policy parameters are required to accomplish this task? (Choose two.)

Options:

A.

session-init

B.

session-close

C.

deny

D.

count

Buy Now
Questions 7

What are two ways to help reduce false positives for an IDP rule? (Choose two.)

Options:

A.

Change the rule to a lower severity action.

B.

Remove the attack object from the rule.

C.

Create an exempt rule.

D.

Configure a terminal rule at the end of the rule base.

Buy Now
Questions 8

You want to show tabular data for operational mode commands.

In this scenario, which logging parameter will provide this function?

Options:

A.

permit

B.

count

C.

session-init

D.

session-close

Buy Now
Questions 9

Which action will the SRX Series device take if traffic matches the custom attack object shown in the exhibit?

JN0-336 Question 9

Options:

A.

the action taken is defined in the IDP policy that includes this attack object.

B.

the action taken is defined by the security policy.

C.

The SRX Series device will reject the traffic.

D.

The SRX series device will drop the traffic.

Buy Now
Questions 10

You are asked to configure your company SRX Series device to use identity-aware security policies. Information about your Active Directory network is shown in the exhibit.

JN0-336 Question 10

In this scenario, why must you configure JIMS instead of Active Directory as an identity source?

Options:

A.

JIMS is the only way to get data from Active Directory.

B.

You have too many Active Directory users.

C.

The version of Windows OS is too old.

D.

You have too many domain controllers.

Buy Now
Questions 11

Which two statements are correct about IDP policy templates? (Choose two.)

Options:

A.

They are provided by Juniper Networks.

B.

They are not customizable.

C.

They are available on a “factory-default config.”

D.

They must be installed.

Buy Now
Questions 12

You work on the security operations team that manages firewalls only. In your data center, there are two SRX chassis clusters. These clusters operate on VLAN 1042. The network team advises you that they see the same MAC address coming from both chassis clusters for reth0.

Why is this occurring?

Options:

A.

The same cluster ID was used on both clusters.

B.

RGO is active on both node0 and node1 due to split-brain.

C.

Chassis clusters must be on separate VLANs.

D.

Link Aggregation Control Protocol is not synchronized.

Buy Now
Questions 13

Which three different objects would be created, modified, cloned, and deleted in the Shared Objects workspace of Junos Space Security Director? (Choose three.)

Options:

A.

geo IP

B.

IP address

C.

audit logs

D.

policy enforcement groups

E.

policy rules

Buy Now
Questions 14

A pair of branch SRX Series devices are booted up in cluster mode.

JN0-336 Question 14

Referring to the exhibit, which statement is correct?

Options:

A.

the devices are not running the same version of Junos.

B.

the devices are not the same hardware.

C.

fxp0 or fxp1 on either device has an existing configuration.

D.

node1 is running a " factory-default config " .

Buy Now
Questions 15

An administrator decides to designate a node as the primary node for the chassis cluster.

Which statement is correct in this scenario?

Options:

A.

Configure the burnt-in-address (BIA) to the highest value to bring the node as the primary node.

B.

The node with the highest priority will become a primary node.

C.

The node with the lowest priority will become a primary node.

D.

Nodes with a priority of one are ineligible to participate in the election process.

Buy Now
Questions 16

What are two causes that end the processing of rules in IDP? (Choose two.)

Options:

A.

when a rule is matched in the rule base with an action of close

B.

when a terminal rule is matched in the rule base

C.

when any rule is matched in the exempt rule base

D.

when a rule is matched in the rule base with an action of ignore

Buy Now
Questions 17

You are asked to onboard an SRX Series device to Junos Space Security Director, but it is not working.

In this scenario, what are three areas that should be reviewed? (Choose three.)

Options:

A.

chassis serial number

B.

SSH port number

C.

active security policies

D.

authentication credentials

E.

IP address

Buy Now
Questions 18

You have configured a new site-to-site VPN tunnel. The exhibit shows the security IPsec statistics output for the specific tunnel index from one of the tunnel-end devices.

JN0-336 Question 18

Which two statements are correct in this scenario? (Choose two.)

Options:

A.

AH is incorrectly configured.

B.

The far-end tunnel device is rebooting.

C.

The ESP configuration is not set up correctly.

D.

No traffic passes through this tunnel.

Buy Now
Questions 19

You are asked to configure a cluster between SRX1 and SRX2.

Which two commands must be used to accomplish this task? (Choose two.)

Options:

A.

user@SRX2# set chassis cluster cluster-id 0 node 1

B.

user@SRX1 > set chassis cluster cluster-id 1 node 0

C.

user@SRX2 > set chassis cluster cluster-id 1 node 1

D.

user@SRX1# set chassis cluster cluster-id 0 node 2

Buy Now
Exam Code: JN0-336
Exam Name: Security, Specialist (JNCIS-SEC)
Last Update: May 31, 2026
Questions: 66

PDF + Testing Engine

$64.99   $185.69

Testing Engine

$49.99   $142.83

PDF (Q&A)

$54.99   $157.11