Summer Sale Special - Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: xmaspas7

Easiest Solution 2 Pass Your Certification Exams

JN0-336 Juniper Security, Specialist (JNCIS-SEC) Free Practice Exam Questions (2026 Updated)

Prepare effectively for your Juniper JN0-336 Security, Specialist (JNCIS-SEC) certification with our extensive collection of free, high-quality practice questions. Each question is designed to mirror the actual exam format and objectives, complete with comprehensive answers and detailed explanations. Our materials are regularly updated for 2026, ensuring you have the most current resources to build confidence and succeed on your first attempt.

Page: 1 / 1
Total 66 questions

Which two steps are necessary to prepare the Active Directory domain for a JIMS installation? (Choose two.)

A.

Create two limited access user accounts.

B.

Create three limited access user accounts.

C.

Add one full access user account to Active Directory groups.

D.

Add limited access user accounts to Active Directory groups.

In Juniper high availability (HA) SRX Series device implementations, which interface will be used to exchange session state, configuration files, and ensure session continuity across nodes using the proprietary Trivial Network Protocol?

A.

fab

B.

fxp0

C.

fxp1

D.

swfab

Which two statements accurately describe the role of hashing in VPNs? (Choose two.)

A.

Hashing compresses data in VPN communications.

B.

Hashing generates a fixed-size string of characters.

C.

Hashing encrypts data to ensure confidentiality.

D.

Hashing verifies that data has not been altered during transmission.

Which two statements are correct about IDP policy templates? (Choose two.)

A.

They are provided by Juniper Networks.

B.

They are not customizable.

C.

They are available on a “factory-default config.”

D.

They must be installed.

Which SRX Series device configuration setting must be configured first to use Juniper ATP Cloud?

A.

Start up the anti-malware service on the SRX Series device.

B.

Apply the firewall rules on the SRX Series device.

C.

Enable connectivity between the SRX Series device and Juniper ATP Cloud.

D.

Configure the anti-malware policies on the SRX Series device.

Which protocol does the SRX Series Firewall use to communicate with a Windows domain controller?

A.

SSH

B.

LDAP

C.

DNS

D.

NETCONF

You need to deploy an SRX Series device in your virtual environment.

In this scenario, what are two benefits of using a CSRX? (Choose two.)

A.

The cSRX supports Layer 2 and Layer 3 deployments.

B.

The cSRX default configuration contains three default zones: trust, untrust, and management.

C.

The cSRX supports firewall, NAT, IPS, and UTM services.

D.

The cSRX has low memory requirements.

What are two types of attack objects included in an IDP attack object database? (Choose two.)

A.

statistic-based

B.

protocol anomaly-based

C.

signature-based

D.

vector-based

Using Junos Space Security Director, you want to configure a unique firewall policy for a specific SRX Series device.

Which firewall policy rule would satisfy the requirement?

A.

all devices policy prerules

B.

group policy prerules

C.

device policy rules

D.

all devices policy postrules

Which three different objects would be created, modified, cloned, and deleted in the Shared Objects workspace of Junos Space Security Director? (Choose three.)

A.

geo IP

B.

IP address

C.

audit logs

D.

policy enforcement groups

E.

policy rules

You need to set up a forward proxy on your SRX Series device.

In this scenario, which two statements are correct? (Choose two.)

A.

The forward proxy uses the managed SRX as a trusted certificate authority (CA).

B.

The forward proxy forwards the server certificate.

C.

The forward proxy looks like a client to the servers to which it communicates.

D.

The forward proxy uses Encrypted Traffic Insights to monitor traffic.

How does the SSL proxy detect if a particular session is SSL encrypted?

A.

It uses AppID services.

B.

It verifies the length of the packet.

C.

It looks at the destination port number.

D.

It uses a certificate authority (CA).

A pair of branch SRX Series devices are booted up in cluster mode.

Referring to the exhibit, which statement is correct?

A.

the devices are not running the same version of Junos.

B.

the devices are not the same hardware.

C.

fxp0 or fxp1 on either device has an existing configuration.

D.

node1 is running a " factory-default config " .

Which two statements are correct about the security associations of an IPsec VPN? (Choose two.)

A.

IPsec security associations are established during IKEv1 Phase 2 negotiations.

B.

IKEv1 security associations are established during IKEv1 Phase 2 negotiations.

C.

IPsec security associations are established during IKEv1 Phase 1 negotiations.

D.

IKEv1 security associations are established during IKEv1 Phase 1 negotiations.

You are configuring a redundancy group using Ethernet interfaces.

In this scenario, which two actions must be performed? (Choose two.)

A.

Assign a physical interface from each node to the reth0 interface.

B.

Set the retry interval

C.

Define the number of reth interfaces in a cluster under the chassis cluster hierarchy.

D.

Configure the heartbeat interval.

Which IDP action is also referred to as a silent discard?

A.

no action

B.

close client and server

C.

ignore connection

D.

drop packet

Which two statements are correct about Juniper Secure Connect? (Choose two.)

A.

Juniper Secure Connect uses a policy-based VPN.

B.

Juniper Secure Connect can use a self-signed certificate.

C.

Juniper Secure Connect uses a route-based VPN.

D.

Juniper Secure Connect cannot use a self-signed certificate.

You are deploying a new SRX Series device and you need to log denied traffic.

In this scenario, which two policy parameters are required to accomplish this task? (Choose two.)

A.

session-init

B.

session-close

C.

deny

D.

count

You want to include a custom attack object named Custom-FTP-Attack and set the action to drop the packet.

Referring to the exhibit, which modifications would you make?

A.

Add custom-attack Custom-FTP-Attack to the attacks section and change the action to close-client.

B.

Add custom-attack Custom-FTP-Attack to the attacks section and change the action to drop-packet.

C.

Add custom-attack Custom-FTP-Attack to the action section and change the action to drop-packet.

D.

Add custom-attack Custom-FTP-Attack to the notification section and change the action to drop-packet.

Page: 1 / 1
Total 66 questions
Copyright © 2014-2026 Solution2Pass. All Rights Reserved