Pre-Summer Sale - Special 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70dumps

JN0-336 Questions and Answers

Question # 6

You want to include a custom attack object named Custom-FTP-Attack and set the action to drop the packet.

Question # 6

Referring to the exhibit, which modifications would you make?

A.

Add custom-attack Custom-FTP-Attack to the attacks section and change the action to close-client.

B.

Add custom-attack Custom-FTP-Attack to the attacks section and change the action to drop-packet.

C.

Add custom-attack Custom-FTP-Attack to the action section and change the action to drop-packet.

D.

Add custom-attack Custom-FTP-Attack to the notification section and change the action to drop-packet.

Full Access
Question # 7

You have configured a new site-to-site VPN tunnel. The exhibit shows the security IPsec statistics output for the specific tunnel index from one of the tunnel-end devices.

Question # 7

Which two statements are correct in this scenario? (Choose two.)

A.

AH is incorrectly configured.

B.

The far-end tunnel device is rebooting.

C.

The ESP configuration is not set up correctly.

D.

No traffic passes through this tunnel.

Full Access
Question # 8

You are asked to configure your company SRX Series device to use identity-aware security policies. Information about your Active Directory network is shown in the exhibit.

Question # 8

In this scenario, why must you configure JIMS instead of Active Directory as an identity source?

A.

JIMS is the only way to get data from Active Directory.

B.

You have too many Active Directory users.

C.

The version of Windows OS is too old.

D.

You have too many domain controllers.

Full Access
Question # 9

Which three algorithms are used to encrypt IP packets? (Choose three.)

A.

Data Encryption Standard (DES)

B.

Secure Hash Algorithm (SHA) - 1

C.

Message Digest 5 (MD5)

D.

Triple Data Encryption Standard (3DES)

E.

Advanced Encryption Standard (AES)

Full Access
Question # 10

Referring to the exhibit, what should you do to ensure that Juniper ATP Cloud detects malware in HTTPS traffic?

Question # 10

A.

Manually configure and apply an SSL proxy profile.

B.

Lower the threat score.

C.

Configure a new device profile that includes encrypted traffic.

D.

Change the action to redirect the encrypted traffic to a decryption device.

Full Access
Question # 11

You want to configure the SSL proxy feature on your SRX Series Firewall.

Which two actions must you perform to accomplish this task? (Choose two.)

A.

Enable the SSL ALG.

B.

Create an SSL proxy profile.

C.

Create an SSL application object.

D.

Associate an SSL proxy profile with a security policy.

Full Access
Question # 12

Your manager asks you to update your SRX Series device’s IDP security package. You perform the required steps; however, when you attempt to install the package, you receive an error.

Question # 12

Referring to the exhibit, which two statements are correct about this error? (Choose two.)

A.

IDP stops inspecting traffic.

B.

The IDP license has expired.

C.

IDP continues to inspect traffic only using the installed signatures.

D.

The IDP license is missing/not installed.

Full Access
Question # 13

You want to use user identity information to secure your network.

Which two actions must you perform on your SRX Series Firewall to accomplish this task? (Choose two.)

A.

Create security policies that include user identity configuration

B.

Add user accounts to the Active Directory Domain Users group

C.

Configure an identity provider on your SRX Series Firewall.

D.

Add the user identity feature license to your SRX Series Firewall.

Full Access
Question # 14

You are asked to ensure that traffic that matches an IDP policy is not impacted until administrators have a chance to evaluate it.

In this scenario, which IP action should be configured for the policy?

A.

ip-block

B.

ip-notify

C.

ip-connection-rate-limit

D.

ip-close

Full Access
Question # 15

What are two causes that end the processing of rules in IDP? (Choose two.)

A.

when a rule is matched in the rule base with an action of close

B.

when a terminal rule is matched in the rule base

C.

when any rule is matched in the exempt rule base

D.

when a rule is matched in the rule base with an action of ignore

Full Access
Question # 16

You are asked to configure a cluster between SRX1 and SRX2.

Which two commands must be used to accomplish this task? (Choose two.)

A.

user@SRX2# set chassis cluster cluster-id 0 node 1

B.

user@SRX1 > set chassis cluster cluster-id 1 node 0

C.

user@SRX2 > set chassis cluster cluster-id 1 node 1

D.

user@SRX1# set chassis cluster cluster-id 0 node 2

Full Access
Question # 17

Which two services would an SRX Series device use to connect to an LDAP server for identity-aware security policies? (Choose two.)

A.

Active Directory

B.

TACACS+

C.

RADIUS

D.

JIMS

Full Access
Question # 18

You are deploying a new SRX Series device and you need to log denied traffic.

In this scenario, which two policy parameters are required to accomplish this task? (Choose two.)

A.

session-init

B.

session-close

C.

deny

D.

count

Full Access
Question # 19

Which rule base in an IDP policy is used to eliminate false positives?

A.

IPS

B.

monitor

C.

signature

D.

exempt

Full Access