Prepare Top Juniper JN0-335 Exam Study Guide Practice Questions Edition [Q13-Q38]

Share

Prepare Top Juniper JN0-335 Exam Study Guide Practice Questions Edition

Go to JN0-335 Questions - Try JN0-335 dumps pdf


Juniper JN0-335 (Security, Specialist (JNCIS-SEC)) certification exam is designed for network security professionals who want to take their skills to the next level. JN0-335 exam validates the candidate's expertise in various security technologies and concepts, including firewall, VPN, intrusion detection and prevention, and security policies. By passing JN0-335 exam, candidates demonstrate their proficiency in configuring and troubleshooting Juniper Networks security solutions.


The JN0-335 certification exam consists of 65 multiple-choice questions and has a time limit of 90 minutes. Candidates must score at least 65% to pass the exam and obtain their JNCIS-SEC certification. Upon successful completion of the exam, candidates will have demonstrated their understanding of Juniper Networks security technologies and can confidently configure and troubleshoot security issues in a variety of network environments. The JN0-335 certification can lead to a variety of network security roles, including security analyst, network security engineer, and security consultant.

 

NEW QUESTION # 13
You are asked to ensure that servers running the Ubuntu OS will not be able to update automatically by blocking their access at the SRX firewall. You have configured a unified security policy named Blockuburrtu, but it is not blocking the updates to the OS.
Referring to the exhibit which statement will block the Ubuntu OS updates?

  • A. Configure the Allowweb policy to have a dynamic application of any.
  • B. Change the default policy to permit-all.
  • C. Configure the Blockubuntu policy with the junos-https application parameter.
  • D. Move the Blockubuntu policy after the Allowweb policy.

Answer: C


NEW QUESTION # 14
Referring to the exhibit, which statement is true?

  • A. Hosts are always able to communicate through the SRX Series device no matter the threat score assigned to them on the infected host feed.
  • B. Malicious HTTP file downloads are never blocked.
  • C. Hosts are unable to communicate through the SRX Series device after being placed on the infected host feed with a high enough threat score.
  • D. Malicious HTTP file downloads are always blocked.

Answer: C


NEW QUESTION # 15
Referring to the SRX Series flow module diagram shown in the exhibit, where is IDP/IPS processed?

  • A. Services ALGs
  • B. Security Policy
  • C. Screens
  • D. Forwarding Lookup

Answer: A


NEW QUESTION # 16
You are asked to implement IPS on your SRX Series device.
In this scenario, which two tasks must be completed before a configuration will work? (Choose two.)

  • A. Enroll the SRX Series device with Juniper ATP Cloud.
  • B. Download the IPS signature database.
  • C. Reboot the SRX Series device.
  • D. Install the IPS signature database.

Answer: B,D

Explanation:
The two tasks that must be completed before a configuration for IPS on an SRX Series device will work are downloading the IPS signature database and installing the IPS signature database. The Security, Specialist (JNCIS-SEC) Study guide provides further information on how to download and install the IPS signature database. Enrolling the SRX Series device with Juniper ATP Cloud is not necessary to make a configuration work, and rebooting the SRX Series device is not required either.


NEW QUESTION # 17
You are troubleshooting advanced policy-based routing (APBR). Which two actions should you perform in this scenario? (Choose two.)

  • A. Verify that the APBR profiles are applied to the egress zone.
  • B. Inspect the application system cache for the application entry.
  • C. Verity inet.0 for correct route leaking.
  • D. Review the APBR statistics for matching rules and route modifications.

Answer: B,D


NEW QUESTION # 18
Exhibit

Referring to the exhibit, which two statements describe the type of proxy used? (Choose two.)

  • A. client protection proxy
  • B. forward proxy
  • C. reverse proxy
  • D. server protection proxy

Answer: A,D

Explanation:
B) Client protection proxy: This statement is correct because a forward proxy can also be called a client protection proxy since it protects the user's identity and computer information from the web server4.
C) Server protection proxy: This statement is correct because a reverse proxy can also be called a server protection proxy since it protects the web server's identity and location from the user4.


NEW QUESTION # 19
What are three capabilities of AppQoS? (Choose three.)

  • A. re-write the TTL
  • B. assign a forwarding class
  • C. rate-limit traffic
  • D. re-write DSCP values
  • E. reserve bandwidth

Answer: B,D,E

Explanation:
AppQoS (Application Quality of Service) is a Junos OS feature that provides advanced control and prioritization of application traffic. With AppQoS, you can classify application traffic, assign a forwarding class to the traffic, and apply quality of service (QoS) policies to the traffic. You can also re-write DSCP values and reserve bandwidth for important applications. However, AppQoS does not re-write the TTL or rate-limit traffic.
Source: Juniper Networks, Security, Specialist (JNCIS-SEC) Study Guide. Chapter 3: AppSecure. Page 66-67.


NEW QUESTION # 20
You are asked to ensure that if the session table on your SRX Series device gets close to exhausting its resources, that you enforce a more aggress.ve age-out of existing flows.
In this scenario, which two statements are correct? (Choose two.)

  • A. The high-watermark configuration specifies the percentage of how much of the session table is left before disabling a more aggressive age- out timer.
  • B. The early-ageout configuration specifies the timeout value, in seconds, that will be applied once the low-watermark value is met.
  • C. The early-ageout configuration specifies the timeout value, in seconds, that will be applied once the high-watermark value is met.
  • D. The high-watermark configuration specifies the percentage of how much of the session table can be allocated before applying a more aggressive age-out timer

Answer: C,D

Explanation:
Explanation
The session table is a limited resource for SRX Series devices. If the session table is full, any new sessions will be rejected by the device. The aggressive session-aging mechanism accelerates the session timeout process when the number of sessions in the session table exceeds the specified high-watermark threshold. This mechanism minimizes the likelihood that the SRX Series devices will reject new sessions when the session table becomes full1. To perform aggressive session aging, you need to configure the following parameters1:
early-ageout -During aggressive session aging, the sessions with an age-out time lower than the early-ageout threshold are marked as invalid. The early-ageout configuration specifies the timeout value, in seconds, that will be applied once the high-watermark value is met. For example, if you set the early-ageout to 30 seconds, any session that has been inactive for at least 30 seconds will be aged out when the high-watermark is reached2.
high-watermark -The device performs aggressive session aging when the number of sessions in the session table exceeds the high-watermark threshold. The high-watermark configuration specifies the percentage of how much of the session table can be allocated before applying a more aggressive age-out timer. For example, if you set the high-watermark to 90 percent, the device will start aging out sessions more aggressively when the session table reaches 90 percent of its capacity3.
Therefore, the correct statements are B and D.
References: Understanding Aggressive Session Aging high-watermark early-ageout


NEW QUESTION # 21
After performing a software upgrade on an SRX5800 chassis cluster, you notice that node1 is in the primary state and node0 is in the backup state. Your network standards dictate that node0 should be in the primary state.
In this scenario, which command should be used to comply with the network standards?

  • A. request chassis cluster failover redundancy-group 254 mode 0
  • B. request chassis cluster failover redundancy-group 0 node 0
  • C. request chassis cluster failover redundancy-group 0 node 1
  • D. request chassis cluster failover redundancy-group 254 node 1

Answer: B

Explanation:
https://www.juniper.net/documentation/en_US/junos/topics/topic-map/security-chassis-cluster- redundancy-group-failover.html


NEW QUESTION # 22
Your company is using the Juniper ATP Cloud free model. The current inspection profile is set at 10 MB You are asked to configure ATP Cloud so that executable files up to 30 MB can be scanned while at the same time minimizing the change in scan time for other file types.
Which configuration should you use in this scenario?

  • A. Use the ATP Cloud Ul to change the default profile to increase the scan limit for all files to 30 MB.
  • B. Use the CLI to change the default profile to increase the scan limit for all files to 30 MB.
  • C. Use the ATP Cloud Ul to update a custom profile and increase the scan limit for executable files to 30 MB.
  • D. Use the CLI to create a custom profile and increase the scan limit.

Answer: C

Explanation:
In this scenario, you should use the ATP Cloud Ul to create a custom profile and update the scan limit for executable files to 30 MB. This will ensure that executable files up to 30 MB can be scanned, while at the same time minimizing the change in scan time for other file types. To do this, log in to the ATP Cloud Ul and go to the Profiles tab. Click the Create button to create a new profile, and then adjust the scan limits for executable files to 30 MB. Once you have saved the custom profile, you can apply it to the desired systems and the new scan limit will be in effect.


NEW QUESTION # 23
Which two statements are correct about JSA data collection? (Choose two.)

  • A. The Flow Collector parses logs.
  • B. The Event Collector collects information using BGP FlowSpec.
  • C. The Flow Collector can use statistical sampling
  • D. The Event Collector parses logs

Answer: C,D

Explanation:
The Flow Collector can use statistical sampling to collect and store network flow data in the JSA database. The Event Collector collects information from various sources including syslog, SNMP, NetFlow, and BGP FlowSpec. Both the Flow Collector and the Event Collector parse logs to extract useful information from the logs.


NEW QUESTION # 24
Exhibit

Using the information from the exhibit, which statement is correct?

  • A. Node1 is the active node for the control plane
  • B. Redundancy group 0 is in an ineligible state.
  • C. There are no issues with the cluster.
  • D. Redundancy group 1 is in an ineligible state.

Answer: A

Explanation:
Explanation
Based on the information from the exhibit, node0 is the primary node for both redundancy group 0 (RG0) and redundancy group 1 (RG1). RG0 is responsible for the control plane, which includes the Routing Engine and the management interface. RG1 is responsible for the data plane, which includes the interfaces and services. Therefore, node0 is the active node for the data plane, and node1 is the active node for the control plane34 References:
Chassis Cluster Redundancy Groups | Junos OS | Juniper Networks
Troubleshooting a Redundancy Group that Does Not Fail Over in an SRX Chassis Cluster | Junos OS | Juniper Networks Understanding Chassis Cluster Redundancy Group 0: Routing Engines | Junos OS | Juniper Networks Understanding Chassis Cluster Redundancy Groups 1 Through 128 | Junos OS | Juniper Networks


NEW QUESTION # 25
What are two examples of RTOs? (Choose two.)

  • A. control link heartbeats
  • B. IPsec SA entries
  • C. session table entries
  • D. fabric link probes

Answer: A,D


NEW QUESTION # 26
What are three capabilities of AppQoS? (Choose three.)

  • A. reserve bandwidth
  • B. rate-limit traffic
  • C. re-write the TTL
  • D. assign a forwarding class
  • E. re-write DSCP values

Answer: B,D,E

Explanation:
Explanation
AppQoS is a feature that enables you to identify and control access to specific applications and provides the granularity of the stateful firewall rule base to match and enforce quality of service (QoS) at the application layer. AppQoS expands the capability of Junos OS class of service (CoS) to include the following capabilities12:
Re-write DSCP values based on Layer-7 application types. DSCP values are used to convey the packet's quality of service through both the forwarding class and a loss priority.
Assign a forwarding class based on the application type. Forwarding classes are used to group packets with similar QoS requirements and map them to output queues on the egress interface.
Rate-limit traffic based on the application type. Rate limiters are used to control the transmission speed and volume for the associated queues. You can configure rate limiters and profiles to specify the bandwidth, burst size, and action for each application type.
AppQoS does not have the capability to re-write the TTL or reserve bandwidth. Re-writing the TTL is not related to QoS and could cause routing loops or packet drops. Reserving bandwidth is a function of traffic engineering, not AppQoS. References:
1: Application QoS | Junos OS | Juniper Networks
2: AppQoS for Tenant Systems | Junos OS | Juniper Networks


NEW QUESTION # 27
You are deploying a new SRX Series device and you need to log denied traffic.
In this scenario, which two policy parameters are required to accomplish this task? (Choose two.)

  • A. session-close
  • B. session-init
  • C. deny
  • D. count

Answer: B,C

Explanation:
Explanation
To log denied traffic, you need to configure a security policy with the action of deny and the option of log session-init. The deny action blocks the traffic that matches the policy criteria, and the log session-init option generates a log entry when the session is denied. The session-close option is not required, as it only logs the end of a session. The count option is not required, as it only increments a counter for the policy. References:
[SRX] How to log traffic that is denied by default system security policy1
[SRX] How to log traffic for the default deny policy2
How to log traffic dropped by Juniper SRX firewalls3


NEW QUESTION # 28
Which two statements are correct about security policy changes when using the policy rematch feature?
(Choose two.)

  • A. When a policy change includes changing the policy's source or destination address match condition, all existing sessions are dropped.
  • B. When a policy change includes changing the policy's source or destination address match condition, all existing sessions are reevaluated.
  • C. When a policy change includes changing the policy's action from permit to deny, all existing sessions are dropped.
  • D. When a policy change includes changing the policy's action from permit to deny, all existing sessions are maintained

Answer: B,C

Explanation:
Explanation
The policy rematch feature enables the device to reevaluate an active session when its associated security policy is modified. The session remains open if it still matches the policy that allowed the session initially. The session is closed if its associated policy is renamed, deactivated, or deleted1 When a policy change includes changing the policy's action from permit to deny, all existing sessions are dropped. This is because the policy rematch feature does not allow a session to continue if it violates the new policy action1 When a policy change includes changing the policy's source or destination address match condition, all existing sessions are reevaluated. This is because the policy rematch feature tries to find a suitable policy that can still permit the session based on the new address criteria. If no such policy exists, the session is dropped12 References: 1: policy-rematch | Junos OS | Juniper Networks 2: What is session rematch and how to use it to avoid traffic disruption during a policy update via NSM - Juniper Networks


NEW QUESTION # 29
Your manager asks you to provide firewall and NAT services in a private cloud.
Which two solutions will fulfill the minimum requirements for this deployment? (Choose two.)

  • A. a single cSRX
  • B. a vSRX for firewall services and a separate vSRX for NAT services
  • C. a single vSRX
  • D. a cSRX for firewall services and a separate cSRX for NAT services

Answer: B,D

Explanation:
A single vSRX or cSRX cannot provide both firewall and NAT services simultaneously. To meet the minimum requirements for this deployment, you need to deploy a vSRX for firewall services and a separate vSRX for NAT services (option B), or a cSRX for firewall services and a separate cSRX for NAT services (option C). This is according to the Juniper Networks Certified Security Specialist (JNCIS-SEC) Study Guide.


NEW QUESTION # 30
You are asked to find systems running applications that increase the risks on your network. You must ensure these systems are processed through IPS and Juniper ATP Cloud for malware and virus protection.
Which Juniper Networks solution will accomplish this task?

  • A. Adaptive Threat Profiling
  • B. JIMS
  • C. UTM
  • D. Encrypted Traffic Insights

Answer: A

Explanation:
Explanation
Adaptive Threat Profiling is a feature that allows SRX Series Firewalls to generate, propagate, and consume threat feeds based on their own advanced detection and policy-match events. This feature enables you to configure security or IDP policies that, when matched, inject the source IP address, destination IP address, source identity, or destination identity into a threat feed, which can be leveraged by other devices as a dynamic-address-group (DAG). With adaptive threat profiling, the Juniper ATP Cloud service acts as a feed-aggregator and consolidates feeds from SRX across your enterprise and shares the deduplicated results back to all SRX Series Firewalls in the realm at regular intervals. SRX Series Firewalls can then use these feeds to perform further actions against the traffic. This feature allows you to find systems running applications that increase the risks on your network and ensure these systems are processed through IPS and Juniper ATP Cloud for malware and virus protection1. References:
Adaptive Threat Profiling Overview and Configuration
Adaptive Threat Profiling Overview
Juniper Launches Adaptive Threat Profiling, New VPN Features
Juniper Networks Answers Who and What is On the Network with Risk-Based Access Control Capabilities and New VPN Application Adaptive Threat Profiling Overview | SD Cloud


NEW QUESTION # 31
What are two types of system logs that Junos generates? (Choose two.)

  • A. system core dump files
  • B. data plane logs
  • C. SQL log files
  • D. control plane logs

Answer: B,D

Explanation:
The two types of system logs that Junos generates are control plane logs and data plane logs.
Control plane logs are generated by the Junos operating system and contain system-level events such as system startup and shutdown, configuration changes, and system alarms. Data plane logs are generated by the network protocol processes and contain messages about the status of the network and its components, such as routing, firewall, NAT, and IPS. SQL log files and system core dump files are not types of system logs generated by Junos.


NEW QUESTION # 32
Which two statements are true about the fab interface in a chassis cluster? (Choose two.)

  • A. The fab link does not support fragmentation.
  • B. The physical interface for the fab link must be specified in the configuration.
  • C. The fab link supports traditional interface features.
  • D. The Junos OS supports only one fab link.

Answer: B,C

Explanation:
The physical interface for the fab link must be specified in the configuration. Additionally, the fab link supports traditional interface features such as MAC learning, security policy enforcement, and dynamic routing protocols. The fab link does not support fragmentation and the Junos OS supports up to two fab links.


NEW QUESTION # 33
Which statement about the control link in a chassis cluster is correct?

  • A. The control link heartbeats contain the configuration file of the nodes.
  • B. The control messages sent over the link are encrypted by default.
  • C. A cluster can have redundant control links.
  • D. Recovering from a control link failure requires a reboot.

Answer: C

Explanation:
https://www.juniper.net/documentation/en_US/junos/topics/topic-map/security-chassis-cluster- dual-control-links.html


NEW QUESTION # 34
What are two types of collectors for the JATP core engine? (Choose two.)

  • A. telemetry
  • B. SNMP
  • C. Web
  • D. e-mail

Answer: C,D


NEW QUESTION # 35
Which two statements are true about the vSRX? (Choose two.)

  • A. OpenStack is not supported as a cloud orchestration solution.
  • B. OpenStack is supported as a cloud orchestration solution.
  • C. AWS is supported as an laaS solution.
  • D. AWS is not supported as an laaS solution.

Answer: B,C

Explanation:
Explanation
vSRX is a virtual firewall that runs on various cloud platforms, including AWS and OpenStack. AWS is a cloud service provider that offers infrastructure as a service (IaaS) solutions, such as compute, storage, and networking resources. OpenStack is an open source software platform that enables cloud orchestration, which is the automated management of cloud resources and services. vSRX supports both AWS and OpenStack as deployment options, and integrates with their features and tools. For example, vSRX can use cloud-init to automate the initialization of vSRX instances in AWS and OpenStack environments. vSRX can also leverage the security groups and elastic IP addresses of AWS, and the network and security services of OpenStack. References:
vSRX Deployment Guide for AWS
vSRX Virtual Firewall
Use Cloud-Init in an OpenStack Environment to Automate the Initialization of vSRX Instances


NEW QUESTION # 36
Which three features are parts of Juniper Networks' AppSecure suite? (Choose three.)

  • A. AppFormix
  • B. Secure Application Manager
  • C. APBR
  • D. AppQoE
  • E. AppQoS

Answer: C,D,E


NEW QUESTION # 37
You want to manually failover the primary Routing Engine in an SRX Series high availability cluster pair.
Which step is necessary to accomplish this task?

  • A. Issue the set chassis cluster disable reboot command on the primary node.
  • B. Implement the control link recover/ solution before adjusting the priorities.
  • C. Adjust the priority in the configuration on the secondary node.
  • D. Manually request the failover and identify the secondary node

Answer: D

Explanation:
Explanation
To manually failover the primary Routing Engine in an SRX Series high availability cluster pair, you need to issue the request chassis cluster failover redundancy-group group-id node node-id command on the primary node, where group-id is the redundancy group number and node-id is the node number of the secondary node.
This command initiates a graceful failover of the specified redundancy group to the secondary node, making it the new primary node. The other options are not necessary or correct for this task. Option A would disable the chassis cluster and reboot the primary node, which is not a graceful failover. Option B is not relevant, as the control link recovery solution is used to restore the control link connectivity between the nodes, not to initiate a failover. Option D would not trigger a failover, as the priority of the secondary node would only take effect after a reboot or a control link failure. References:
Chassis Cluster Redundancy Group Manual Failover
Initiating a Chassis Cluster Manual Redundancy Group Failover
SRX Getting Started - Troubleshoot High Availability (HA)


NEW QUESTION # 38
......

Free JNCIS-SEC JN0-335 Exam Question: https://www.dumps4pdf.com/JN0-335-valid-braindumps.html

Dumps Practice Exam Questions Study Guide for the JN0-335 Exam: https://drive.google.com/open?id=1IZ1sKWyn9G_U1TZQNKNjvrcf52rXKVTN