Download Juniper JN0-336 Mock Test Study Material [Q48-Q66]

Share

Download Juniper JN0-336 Mock Test Study Material

JN0-336 Questions Prepare with Learning Information

NEW QUESTION # 48
Your JIMS server is unable to view event logs.
Which two actions would you take to solve this issue? (Choose two.)

  • A. Enable remote event log management within Windows Firewall on the necessary domain controllers.
  • B. Enable the correct host-inbound-traffic rules on the SRX Series devices.
  • C. Enable remote event log management within Windows Firewall on the necessary Exchange servers.
  • D. Enable remote event log management within Windows Firewall on the JIMS server.

Answer: A,D

Explanation:
JIMS needs to access the event logs from domain controllers to function properly, as it relies on these logs to track user and device activity across the network. If the Windows Firewall on the domain controllers is blocking this access, enabling remote event log management will allow JIMS to retrieve the necessary information.
While it's less common, ensuring that any firewall settings on the JIMS server itself do not block outgoing requests or responses related to event log management is also crucial. This ensures that JIMS can send out requests and receive responses without any hindrance from its own firewall.


NEW QUESTION # 49
Click the Exhibit button.

You are asked to create a security policy that will automatically add infected hosts to the infected hosts feed and block further communication through the SRX Series device.
What needs to be added to this configuration to complete this task?

  • A. Add logging to the permit portion of the security policy.
  • B. Add a security intelligence policy to the permit portion of the security policy.
  • C. Add an action to the permit portion of the security policy.
  • D. Add a match rule to the security policy with an appropriate threat level.

Answer: B

Explanation:
To create a security policy that will automatically add infected hosts to the infected hosts feed and block further communication through the SRX Series device, you need to add a security intelligence policy to the permit portion of the security policy. A security intelligence policy is a policy that allows you to block or monitor traffic from malicious sources based on threat intelligence feeds from Juniper ATP Cloud or other providers. One of the feeds that you can use is the Infected-Hosts feed, which contains IP addresses of hosts that are infected with malware and communicate with command-and-control servers.
You can create a profile and a rule for the Infected-Hosts feed and specify the threat level and the action to take for the infected hosts. Then, you can link the security intelligence policy with the firewall policy and apply it to the traffic that you want to protect. Reference: = Security Intelligence Overview, Configuring Security Intelligence Policy, Configure the Security Intelligence Policy on the SRX Series Device


NEW QUESTION # 50
How does Juniper ATP Cloud protect a network from zero-day threats?

  • A. It uses a cache lookup.
  • B. It uses dynamic analysis.
  • C. It uses known virus signatures.
  • D. It uses antivirus software.

Answer: B

Explanation:
Juniper ATP Cloud is a cloud-based service that provides advanced threat prevention and detection for your network. It integrates with SRX Series firewalls and MX Series routers to analyze files and network traffic for signs of malicious activity. Juniper ATP Cloud protects a network from zero-day threats by using dynamic analysis, which is a method of executing files in a sandbox environment and observing their behavior and network interactions. Dynamic analysis can uncover unknown malware that may evade static analysis or signature-based detection methods.
Reference: = Juniper Advanced Threat Prevention - Juniper Networks, Juniper Advanced Threat Prevention Datasheet, Juniper Advanced Threat Prevention | NetworkScreen.com


NEW QUESTION # 51
You administer a JSA host and want to include a rule that sets a threshold for excessive firewall denies and sends an SNMP trap after receiving related syslog messages from an SRX Series firewall.
Which JSA rule type satisfies this requirement?

  • A. offense
  • B. event
  • C. flow
  • D. common

Answer: A

Explanation:
An offense rule in JSA is designed to aggregate multiple events or log entries based on specified criteria into a single offense, which can then trigger responses such as notifications or actions like sending an SNMP trap. This type of rule is well-suited for scenarios where you need to monitor for patterns or rates of events, such as excessive firewall denies, and take action when these exceed defined thresholds.
Offense rules can analyze both event and flow data, making them highly versatile for comprehensive security monitoring.


NEW QUESTION # 52
You need to deploy an SRX Series device in your virtual environment. In this scenario, what are two benefits of using a CSRX? (Choose two.)

  • A. The cSRX supports Layer 2 and Layer 3 deployments.
  • B. The cSRX has low memory requirements.
  • C. The cSRX default configuration contains three default zones: trust, untrust, and management.
  • D. The cSRX supports firewall, NAT, IPS, and UTM services.

Answer: B,D

Explanation:
Two benefits of using a cSRX in your virtual environment are:
The cSRX supports firewall, NAT, IPS, and UTM services: The cSRX is a containerized version of the SRX Series firewall that runs as a Docker container on Linux hosts. It provides the same features and functionality as the SRX Series physical firewalls, such as firewall, NAT, IPS, and UTM services. The cSRX can protect your virtual workloads and applications from various threats and attacks.
The cSRX has low memory requirements: The cSRX is designed to be lightweight and efficient, with low memory and CPU requirements. The cSRX can run on as little as 1 GB of RAM and 1 vCPU, making it suitable for resource-constrained environments. Reference: = cSRX Overview, cSRX Container Firewall Datasheet


NEW QUESTION # 53
Exhibit

You just finished setting up your command-and-control (C&C) category with Juniper ATP Cloud. You notice that all of the feeds have zero objects in them.
Which statement is correct in this scenario?

  • A. The security intelligence policy must be configured; on a unified security policy
  • B. Use the commit full command to start the download.
  • C. Set the maximum C&C entries within the Juniper ATP Cloud GUI.
  • D. No action is required, the feeds take a few minutes to download.

Answer: D

Explanation:
According to the Juniper Networks JNCIS-SEC Study Guide, when you set up your command-and- control (C&C) category with Juniper ATP Cloud, all of the feeds will initially have zero objects in them.
This is normal, as it can take a few minutes for the feeds to download. No action is required in this scenario and you will notice the feeds start to populate with objects once the download is complete.


NEW QUESTION # 54
Which two statements about SRX Series device chassis clusters are true? (Choose two.)

  • A. Chassis cluster member devices must be the same model.
  • B. Each chassis cluster member device can host active redundancy groups
  • C. Each chassis cluster member requires a unique cluster ID value.
  • D. Redundancy group 0 is only active on the cluster backup node.

Answer: A,B

Explanation:
In a chassis cluster, both nodes can host active redundancy groups. The active redundancy groups can be distributed between the two nodes, depending on the configuration and failover status, allowing each node to handle traffic for different sets of services or interfaces.
For the chassis clustering to function correctly, both nodes in the cluster must be of the same model.
This requirement ensures that the hardware capabilities, such as processing power and interface compatibility, are identical, which is crucial for maintaining consistent performance and behavior between cluster nodes.


NEW QUESTION # 55
Which two statements about SRX chassis clustering are correct? (Choose two.)

  • A. SRX chassis clustering supports active/active for the control plane.
  • B. SRX chassis clustering supports active/passive for the control plane.
  • C. SRX chassis clustering only supports active/passive for the data plane.
  • D. SRX chassis clustering supports active/passive and active/active for the data plane.

Answer: B,D

Explanation:
SRX chassis clustering allows for both active/passive and active/active configurations for the data plane.
In an active/passive setup, one node is active (handling traffic) while the other remains passive (idle and waiting to take over in case of failure). In an active/active setup, both nodes can handle traffic simultaneously, distributing different traffic flows or services between them for load balancing and redundancy.
For the control plane, SRX chassis clustering typically operates in an active/passive mode. This means one node actively handles the control plane responsibilities, such as managing routing tables and maintaining sessions, while the other stands by ready to take over these tasks if the active node fails.


NEW QUESTION # 56
Exhibit

Using the information from the exhibit, which statement is correct?

  • A. There are no issues with the cluster.
  • B. Redundancy group 0 is in an ineligible state.
  • C. Node1 is the active node for the control plane
  • D. Redundancy group 1 is in an ineligible state.

Answer: A


NEW QUESTION # 57
You want to deploy a virtualized SRX in your environment.
In this scenario, why would you use a vSRX instead of a cSRX? (Choose two.)

  • A. Only the vSRX provides NAT, IPS, and UTM services
  • B. Only the vSRX provides clustering.
  • C. The vSRX supports Layer 2 and Layer 3 configurations.
  • D. The vSRX has faster boot times.

Answer: B,C

Explanation:
vSRX provides flexible networking capabilities which include support for both Layer 2 (data link) and Layer 3 (network) configurations. This allows it to handle a variety of routing and switching tasks within virtual environments.
Clustering capability, which involves grouping multiple vSRX instances to operate as a single entity for redundancy and high availability, is a feature specific to vSRX. This is critical in environments where continuous uptime and resilience are required.


NEW QUESTION # 58
What information does encrypted traffic insights (ETI) use to notify SRX Series devices about known malware sites?

  • A. domain names
  • B. dynamic address groups
  • C. MAC addresses
  • D. certificates

Answer: A

Explanation:
Encrypted traffic insights (ETI) uses domain names to notify SRX Series devices about known malware sites. ETI is a feature of the SRX Series firewall that can detect and block malware that is hidden in encrypted traffic. It works by analyzing the domain names of the websites that the encrypted traffic is attempting to access. If the domain name matches a known malware site, ETIwill send an alert to the SRX Series device, which can then take appropriate action to block the traffic. ETI is a useful tool for protecting against threats that attempt to evade detection by hiding in encrypted traffic.


NEW QUESTION # 59
You want to manually failover the primary Routing Engine in an SRX Series high availability cluster pair.
Which step is necessary to accomplish this task?

  • A. Issue the set chassis cluster disable reboot command on the primary node.
  • B. Manually request the failover and identify the secondary node
  • C. Implement the control link recover/ solution before adjusting the priorities.
  • D. Adjust the priority in the configuration on the secondary node.

Answer: B

Explanation:
This step involves issuing a command to manually initiate a failover from the primary Routing Engine to the secondary. This can typically be done using a command like request chassis cluster failover redundancy-group <group-number> node <node-id>, where <group-number> is the redundancy group you are failing over, and <node-id> specifies the node to which you want to failover (usually the secondary node). This command forces the designated node to take over as primary for the specified redundancy group.


NEW QUESTION # 60
When a security policy is modified, which statement is correct about the default behavior for active sessions allowed by that policy?

  • A. Only policy changes that involve modification of the action field will cause the active sessions affected by the change to be dropped.
  • B. The active sessions allowed by the policy will continue unchanged.
  • C. The active sessions allowed by the policy will be dropped.
  • D. Only policy changes that involve modification of the application will cause the active sessions affected by the change to be dropped.

Answer: B

Explanation:
When you modify a security policy on the SRX Series device, the default behavior is that the existing sessions that match the policy will continue unchanged. This means that the policy modification will only affect new sessions that are initiated after the change. However, you can change this behavior by using the clear-policy-session command, which will clear all the sessions that match the modified policy and force them to re-evaluate the new policy. Reference: = JNCIS-SEC Certification, Open Learning - Security, Specialist (JNCIS-SEC), Security Policies (Advanced)


NEW QUESTION # 61
Click the Exhibit button.

Which two statements describe the output shown in the exhibit? (Choose two.)

  • A. Redundancy group 1 was administratively failed over.
  • B. Redundancy group 1 experienced an operational failure.
  • C. Node 1 is controlling traffic for redundancy group 1.
  • D. Node 0 is controlling traffic for redundancy group 1.

Answer: C,D

Explanation:
The output indicates that node1 has a priority of 200 and is marked as "Primary," which means it is currently the active node controlling traffic for redundancy group 1. The "Primary" status designates that this node is handling the traffic for the specified redundancy group.
According to the exhibit, node0 is listed with a priority of 0 and is marked as "Secondary." This status indicates that node0 is currently not controlling traffic for redundancy group 1, serving instead in a standby role ready to take over should node1 fail or become unavailable.


NEW QUESTION # 62
After JSA receives external events and flows, which two steps occur? (Choose two.)

  • A. After formatting the data, the data is stored in an asset database.
  • B. After the information is filtered, JSA responds with active measures
  • C. Before formatting the data, the data is analyzed for relevant information.
  • D. Before the information is filtered, the information is formatted

Answer: A,D

Explanation:
When JSA (Juniper Secure Analytics) receives external events and flows, the typical processing steps are:
Option C. Before the information is filtered, the information is formatted.
Data formatting is an initial step in the process where raw data from events and flows is converted into a standard format that can be more easily processed and analyzed by JSA.
Option A. After formatting the data, the data is stored in an asset database.
Once the data is formatted, it is stored in an asset database. This database acts as a repository for all the formatted data, enabling JSA to perform further analysis, correlation, and eventually, to maintain a comprehensive view of the network assets and activities.
These steps are part of JSA's comprehensive approach to security event management, which involves collecting, normalizing, and analyzing data to identify potential security threats and vulnerabilities efficiently.


NEW QUESTION # 63
Which two statements are correct about JSA data collection? (Choose two.)

  • A. The Flow Collector can use statistical sampling
  • B. The Flow Collector parses logs.
  • C. The Event Collector parses logs
  • D. The Event Collector collects information using BGP FlowSpec.

Answer: A,C

Explanation:
The Flow Collector can use statistical sampling to collect and store network flow data in the JSA database. The Event Collector collects information from various sources including syslog, SNMP, NetFlow, and BGP FlowSpec. Both the Flow Collector and the Event Collector parse logs to extract useful information from the logs.


NEW QUESTION # 64
Which two statements are correct about a reth LAG? (Choose two.)

  • A. Links must use the same cable type
  • B. Links must have the same speed and duplex setting.
  • C. You should have two or more interfaces.
  • D. You must have a "minimum-links" statement value of two.

Answer: B,C

Explanation:
A reth LAG is a redundant Ethernet link aggregation group that combines multiple physical interfaces into a single logical interface in a chassis cluster. A reth LAG provides load balancing and redundancy for traffic within or between redundancy groups. Two statements that are correct about a reth LAG are:
Links must have the same speed and duplex setting: To form a reth LAG, the physical interfaces must have the same speed and duplex setting. This ensures that the links can operate at the same capacity and avoid performance issues or errors.
You should have two or more interfaces: To create a reth LAG, you need to have at least two physical interfaces. One interface should be connected to node 0 and the other interface should be connected to node 1. You can also have more than two interfaces in a reth LAG for increased bandwidth and redundancy.
Reference: = Configuring Redundant Ethernet Interfaces, [Understanding Redundant Ethernet Interfaces]


NEW QUESTION # 65
Your company is using the Juniper ATP Cloud free model. The current inspection profile is set at 10 MB You are asked to configure ATP Cloud so that executable files up to 30 MB can be scanned while at the same time minimizing the change in scan time for other file types.
Which configuration should you use in this scenario?

  • A. Use the ATP Cloud Ul to update a custom profile and increase the scan limit for executable files to 30 MB.
  • B. Use the CLI to create a custom profile and increase the scan limit.
  • C. Use the CLI to change the default profile to increase the scan limit for all files to 30 MB.
  • D. Use the ATP Cloud Ul to change the default profile to increase the scan limit for all files to 30 MB.

Answer: A

Explanation:
In this scenario, you should use the ATP Cloud Ul to create a custom profile and update the scan limit for executable files to 30 MB. This will ensure that executable files up to 30 MB can be scanned, while at the same time minimizing the change in scan time for other file types. To do this, log in to the ATP Cloud Ul and go to the Profiles tab. Click the Create button to create a new profile, and then adjust the scan limits for executable files to 30 MB. Once you have saved the custom profile, you can apply it to the desired systems and the new scan limit will be in effect.


NEW QUESTION # 66
......

Most Reliable Juniper JN0-336 Training Materials: https://www.examcost.com/JN0-336-practice-exam.html

Practice Material for JN0-336 Exam Question Preparation: https://drive.google.com/open?id=1Xc_00O3ph9e50Ka3kYc4brz76eVQBoO4