Get Instant Access to JN0-335 Practice Exam Questions [Q37-Q59]

Share

Get Instant Access to JN0-335 Practice Exam Questions

Reliable Study Materials & Testing Engine for JN0-335 Exam Success!


To earn the JNCIS-SEC certification, candidates must pass a rigorous exam that tests their knowledge and skills in the field of network security. JN0-335 exam is designed to be challenging, and candidates must demonstrate their ability to apply their knowledge to real-world scenarios. Security, Specialist (JNCIS-SEC) certification is valid for three years, after which candidates must recertify to maintain their credentials.

 

NEW QUESTION # 37
Which two statements are true about mixing traditional and unified security policies? (Choose two.)

  • A. When a packet matches a traditional security policy, the evaluation process terminates
  • B. Unified security policies must come before traditional security policies
  • C. When a packet matches a unified security policy, the evaluation process terminates
  • D. Traditional security policies must come before unified security policies

Answer: A,C


NEW QUESTION # 38
Which two protocols are supported for Sky ATP advanced anti-malware scanning? (Choose two.)

  • A. POP3
  • B. IMAP
  • C. SMTP
  • D. MAPI

Answer: B,C


NEW QUESTION # 39
You are deploying a vSRX into a vSphere environment which applies the configuration from a bootable ISO file containing the juniper.conf file. After the vSRX boots and has the configuration applied, you make additional device specific configuration changes, commit, and reboot the device. Once the device finishes rebooting, you notice the specific changes you made are missing but the original configuration is applied.
In this scenario, what is the problem?

  • A. Configuration changes do not persist after reboots on vSRX.
  • B. The juniper.conf file was not applied to the vSRX.
  • C. The configuration file is corrupt.
  • D. The ISO file is still mounted on the vSRX.

Answer: D

Explanation:
https://www.juniper.net/documentation/us/en/software/vsrx/vsrx-kvm/topics/task/security-vsrx- kvm-bootstrap-config.html


NEW QUESTION # 40
You just finished setting up your command-and-control (C&C) category with Juniper ATP Cloud.
You notice that all of the feeds have zero objects in them.
Which statement is correct in this scenario?

  • A. No action is required, the feeds take a few minutes to download.
  • B. Set the maximum C&C entries within the Juniper ATP Cloud GUI.
  • C. Use the commit full command to start the download.
  • D. The security intelligence policy must be configured; on a unified security policy

Answer: A

Explanation:
According to the Juniper Networks JNCIS-SEC Study Guide, when you set up your command- and- control (C&C) category with Juniper ATP Cloud, all of the feeds will initially have zero objects in them. This is normal, as it can take a few minutes for the feeds to download. No action is required in this scenario and you will notice the feeds start to populate with objects once the download is complete.


NEW QUESTION # 41
You enable chassis clustering on two devices and assign a cluster ID and a node ID to each device.
In this scenario, what is the correct order for rebooting the devices?

  • A. Reboot the primary device, then the secondary device.
  • B. Reboot the secondary device, then the primary device.
  • C. Reboot only the primary device since the secondary will assign itself the correct cluster and node ID.
  • D. Reboot only the secondary device since the primary will assign itself the correct cluster and node ID.

Answer: A

Explanation:
when enabling chassis clustering on two devices, the correct order for rebooting them is to reboot the primary device first, followed by the secondary device. It is not possible for either device to assign itself the correct cluster and node ID, so both devices must be rebooted to ensure the proper configuration is applied.


NEW QUESTION # 42
Click the Exhibit button.

You examine the log file shown in the exhibit after running the set security idp active-policy command.
Which two statements are true in this scenario? (Choose two.)

  • A. The IDP hit cache is set to 16384.
  • B. The IDP policy loaded successfully.
  • C. The entire configuration was committed.
  • D. The IDP policy compiled successfully.

Answer: B,D

Explanation:
https://www.juniper.net/documentation/en_US/junos/topics/topic-map/security-idp-policies- overview.html


NEW QUESTION # 43
Which statement defines the function of an Application Layer Gateway (ALG)?

  • A. The ALG uses software processes for managing specific protocols.
  • B. The ALG uses software that is used by a single TCP session using the same port numbers as the application.
  • C. The ALG contains protocols that use one application session for each TCP session.
  • D. The ALG uses software processes for permitting or disallowing specific IP address ranges.

Answer: A

Explanation:
The statement that defines the function of an Application Layer Gateway (ALG) is: The ALG uses software processes for managing specific protocols. An ALG is a security component that operates at the application layer (layer 7) of the OSI model and handles data associated with certain application protocols, such as SIP, FTP, RTSP, etc. An ALG acts as a proxy or intermediary between the client and the server applications and performs various functions, such as address and port translation, resource allocation, application response control, and synchronization of data and control traffic. An ALG can also inspect and modify the application payload to enable firewall or NAT traversal, prevent spoofing or DoS attacks, or enforce granular security policies based on application-specific commands. Reference := Application-level gateway - Wikipedia, What Is an Application Layer Gateway (ALG)? | F5, What is ALG ** Application Layer Gateway | 3CX


NEW QUESTION # 44
Which statement about the control link in a chassis cluster is correct?

  • A. The control link heartbeats contain the configuration file of the nodes.
  • B. The control messages sent over the link are encrypted by default.
  • C. Recovering from a control link failure requires a reboot.
  • D. A cluster can have redundant control links.

Answer: D

Explanation:
https://www.juniper.net/documentation/en_US/junos/topics/topic-map/security-chassis-cluster- dual-control-links.html


NEW QUESTION # 45
Which two statements are true about Juniper ATP Cloud? (Choose two.)

  • A. Juniper ATP Cloud only uses one antivirus software package to analyze files.
  • B. Juniper ATP Cloud uses antivirus software packages to protect against zero-day threats.
  • C. Juniper ATP Cloud uses multiple antivirus software packages to analyze files.
  • D. Juniper ATP Cloud does not use antivirus software packages to protect against zero-day threats.

Answer: C,D

Explanation:
Two statements that are true about Juniper ATP Cloud are:
Juniper ATP Cloud uses multiple antivirus software packages to analyze files: Juniper ATP Cloud is a cloud-based service that provides advanced threat prevention and detection for your network. It integrates with SRX Series firewalls and MX Series routers to analyze files and network traffic for signs of malicious activity. Juniper ATP Cloud uses multiple antivirus software packages from different vendors to scan files for known malware signatures and provide a comprehensive verdict based on their results.
Juniper ATP Cloud does not use antivirus software packages to protect against zero-day threats: Juniper ATP Cloud protects against zero-day threats by using dynamic analysis, not antivirus software packages. Dynamic analysis is a method of executing files in a sandbox environment and observing their behavior and network interactions. Dynamic analysis can uncover unknown malware that may evade static analysis or signature-based detection methods.


NEW QUESTION # 46
Data plane logging operates in which two modes? (Choose two.)

  • A. syslog
  • B. event
  • C. stream
  • D. binary

Answer: B,C


NEW QUESTION # 47
You are troubleshooting unexpected issues on your JIMS server due to out of order event log timestamps.
Which action should you take to solve this issue?

  • A. Enable time synchronization on the JIMS server.
  • B. Enable time synchronization on the SRX Series devices.
  • C. Enable time synchronization on the client devices.
  • D. Enable time synchronization on the domain controllers.

Answer: D

Explanation:
To solve the issue of out of order event log timestamps on your JIMS server, you should enable time synchronization on the domain controllers. JIMS (Juniper Identity Management Service) is a Windows service that collects user, device, and group information from Active Directory domains or syslog sources and provides it to SRX Series devices and CSO for identity-based security policies. JIMS relies on the timestamps of the event logs generated by the domain controllers to track user logins, logouts, and IP address changes. If the domain controllers have different or inaccurate clocks, the event logs may have out of order or incorrect timestamps, which can cause JIMS to miss or misinterpret some events and affect its accuracy and performance. Therefore, you should ensure that all the domain controllers in your network are synchronized with a reliable time source, such as an NTP server or a Windows Time service. Reference := Juniper Identity Management Service User Guide, Juniper Identity Management Service Feature Guide, Configure JIMS Collector to Get Microsoft Event Logs, Considerations for timestamps in centralized logging platforms


NEW QUESTION # 48
You must block the lateral spread of Remote Administration Tools (RATs) that use SMB to propagate within the network, using the JATP solution.
Which action would accomplish this task?

  • A. Configure whitelist rules
  • B. Configure YARA rules.
  • C. Configure a new anti-virus configuration rule.
  • D. Configure the SAML settings.

Answer: B


NEW QUESTION # 49
You have implemented a vSRX in your VMware environment. You want to implement a second vSRX Series device and enable chassis clustering.
Which two statements are correct in this scenario about the control-link settings? (Choose two.)

  • A. In the vSwitch properties settings, set the VLAN ID to None.
  • B. In the vSwitch security settings, reject MAC address changes.
  • C. In the vSwitch security settings, accept promiscuous mode.
  • D. In the vSwitch security settings, reject forged transmits.

Answer: B,D


NEW QUESTION # 50
You want to permit access to an application but block application sub-Which two security policy features provide this capability? (Choose two.)

  • A. URL filtering
  • B. micro application detection
  • C. APPID
  • D. content filtering

Answer: A,B

Explanation:
The two security policy features that provide the capability to permit access to an application but block its sub-applications are URL filtering and micro application detection. URL filtering allows you to create policies that permit or block access to certain websites or webpages based on URL patterns. Micro application detection is a more sophisticated approach that can identify and block specific applications, even if they are embedded within other applications or websites. "micro application detection is the most accurate way to detect and control applications." Content filtering and APPID are more general approaches and are not as effective in providing the level of granularity needed to block sub-applications.


NEW QUESTION # 51
You want to support reth LAG interfaces on a chassis cluster. What must be enabled on the interconnecting switch to accomplish this task?

  • A. LLDP
  • B. 802.3ad
  • C. swfab
  • D. RSTP

Answer: B

Explanation:
https://www.juniper.net/documentation/en_US/junos/topics/topic-map/security-chassis-cluster- redundant-ethernet-lag-interfaces.html


NEW QUESTION # 52
Which three statements about SRX Series device chassis clusters are true? (Choose three.)

  • A. A control link failure causes the secondary cluster node to be disabled.
  • B. Chassis cluster control links must be configured using RFC 1918 IP addresses.
  • C. Heartbeat messages verify that the chassis cluster control link is working.
  • D. Chassis cluster member devices synchronize configuration using the control link.
  • E. Recovery from a control link failure requires that the secondary member device be rebooted.

Answer: A,C,D

Explanation:
1. Chassis cluster member devices synchronize configuration using the control link: This statement is correct because the control link is used for configuration synchronization among other functions.
2. A control link failure causes the secondary cluster node to be disabled: This statement is correct because a control link failure causes the secondary node to become ineligible for primary role and remain in secondary role until the control link is restored.
3. Heartbeat messages verify that the chassis cluster control link is working: This statement is correct because heartbeat messages are sent periodically over the control link to monitor its status.


NEW QUESTION # 53
Which three statements are correct about fabric interfaces on the SRX5800? (Choose three.)

  • A. Fabric interfaces must be same interface type.
  • B. Fabric interfaces must be on the same Layer 2 segment.
  • C. Fabric interfaces must be user-assigned interfaces.
  • D. Fabric interfaces must be system-assigned interfaces.
  • E. Fabric interfaces must have a user-assigned IP address.

Answer: A,B,D


NEW QUESTION # 54
The AppQoE module of AppSecure provides which function?

  • A. The AppQoE module blocks access to risky applications.
  • B. The AppQoE module provides routing, based on network conditions.
  • C. The AppQoE module provides application-based routing.
  • D. The AppQoE module prioritizes important applications.

Answer: C


NEW QUESTION # 55
In an Active/Active chassis cluster deployment, which chassis cluster component is responsible for RG0 traffic?

  • A. the backup routing engine of the primary node
  • B. the secondary node
  • C. the primary node
  • D. the master routing engine of the secondary node

Answer: C


NEW QUESTION # 56
Which two statements are true about the configuration shown in the exhibit? (Choose two.)

  • A. Aggressive aging is triggered if the session table reaches 80% capacity.
  • B. The session is removed from the session table after 10 seconds of inactivity.
  • C. Aggressive aging is triggered if the session table reaches 95% capacity.
  • D. The session is removed from the session table after 10 milliseconds of inactivity.

Answer: B,C


NEW QUESTION # 57
You want to be alerted if the wrong password is used more than three times on a single device within five minutes.
Which Juniper Networks solution will accomplish this task?

  • A. Intrusion Prevention System
  • B. Juniper Secure Analytics
  • C. Juniper Identity Management Service
  • D. Adaptive Threat Profiling

Answer: B

Explanation:
The Juniper Networks solution that will accomplish the task of alerting if the wrong password is used more than three times on a single device within five minutes is Juniper Secure Analytics (JSA). JSA is a security intelligence platform that collects, analyzes, and correlates network data from various sources, such as firewalls, routers, switches, servers, and applications. JSA can detect and respond to threats, anomalies, and vulnerabilities in real time using rules, offenses, reports, and dashboards. JSA can also integrate with JIMS (Juniper Identity Management Service) to obtain user identity information from Active Directory domains or syslog sources. JSA can use this information to create custom rules that trigger offenses or alerts based on user behavior or activity, such as failed login attempts or password changes.


NEW QUESTION # 58
Which solution enables you to create security policies that include user and group information?

  • A. JIMS
  • B. Network Director
  • C. NETCONF
  • D. ATP Appliance

Answer: A

Explanation:
The solution that enables you to create security policies that include user and group information is JIMS (Juniper Identity Management Service). JIMS collects and maintains a large database of user, device, and group information from Active Directory domains or syslog sources, and enables SRX Series devices to rapidly identify thousands of users in a large, distributed enterprise. With JIMS, you can create security policies that include user and group information, and enforce user-based access control policies to protect network resources.


NEW QUESTION # 59
......


The JN0-335 certification exam is a challenging exam that requires a great deal of preparation and study. Candidates are expected to have a deep understanding of Junos security technologies and be able to apply this knowledge to real-world scenarios. JN0-335 exam consists of multiple-choice questions, and candidates are given three hours to complete the exam.

 

Validate your Skills with Updated JN0-335 Exam Questions & Answers and Test Engine: https://itexams.lead2passed.com/Juniper/JN0-335-practice-exam-dumps.html