[UPDATED] Juniper JN0-636 Certification Exam Questions [Q41-Q64]

Share

[UPDATED] Juniper JN0-636 Certification Exam Questions

Quickly and Easily Pass Juniper Exam with JN0-636 real Dumps


The Juniper JN0-636 (Security, Professional (JNCIP-SEC)) Certification Exam is designed for individuals who wish to demonstrate their expertise in network security and gain recognition in the industry. This certification is intended for those who have a strong foundation in Juniper security technology and can design, implement, and troubleshoot advanced security solutions. The JN0-636 exam covers a wide range of topics, including security policies, VPNs, intrusion detection and prevention, UTM, and more.

 

NEW QUESTION # 41
When would you use the port-overloading-factor 1 setting?

  • A. to disable the port-overloading
  • B. to map ports with 1:1 ratio for port-overloading
  • C. to set the maximum port-overloading capacity to 65,536
  • D. to enable the port-overloading

Answer: A

Explanation:
https://www.juniper.net/documentation/en_US/junos/topics/reference/configuration- statement/security-edit-port-overloading-interface-source-nat.html


NEW QUESTION # 42
Exhibit

Referring to the exhibit, a spoke member of an ADVPN is not functioning correctly.
Which two commands will solve this problem? (Choose two.)
A)

B)

C)

D)

  • A. Option A
  • B. Option D
  • C. Option C
  • D. Option B

Answer: C


NEW QUESTION # 43
Exhibit

The exhibit shows a snippet of a security flow trace.
In this scenario, which two statements are correct? (Choose two.)

  • A. This packet arrived on interface ge-0/0/4.0.
  • B. Destination NAT occurs.
  • C. An existing session is found in the table.
  • D. The capture is a packet from the source address 172.20.101.10 destined to 10.0.1.129.

Answer: C,D


NEW QUESTION # 44
Exhibit

You configure a traceoptions file called radius on your returns the output shown in the exhibit What is the source of the problem?

  • A. The RADIUS server IP address is unreachable.
  • B. An incorrect password is being used.
  • C. The authentication order is misconfigured.
  • D. The RADIUS server suffered a hardware failure.

Answer: D


NEW QUESTION # 45
Exhibit

Referring to the exhibit, which two statements are true? (Choose two.)

  • A. The SRX-1 device creates the Proxy_wodes feed, so it cannot use it in another security policy.
  • B. You can use the Proxy_Nodes feed as the source-address and destination-address match criteria of another security policy on a different SRX Series device.
  • C. You can only use the Proxy_Node3 feed as the destination-address match criteria of another security policy on a different SRX Series device.
  • D. The SRX-1 device can use the Proxy__Nodes feed in another security policy.

Answer: A,D


NEW QUESTION # 46
The IPsec VPN on your SRX Series device establishes both the Phase 1 and Phase 2 security associations. Users are able to pass traffic through the VPN. During peak VPN usage times, users complain about decreased performance. Network connections outside of the VPN are not seriously impacted.
Which two actions will resolve the problem? (Choose two.)

  • A. Verify that the PKI certificate used to establish the VPN is being properly verified using either the CPL or OCSP.
  • B. Lower the MSS setting in the security flow stanza for IPsec VPNs.
  • C. Lower the MTU size on the interface to reduce the likelihood of packet fragmentation.
  • D. Verify that NAT-T is not disabled in the properties of the phase 1 gateway.

Answer: B,C


NEW QUESTION # 47
Click the Exhibit button.
[edit protocols ospf area 0.0.0.0]
user@host# run show security ike security-associations
Index State Initiator cookie Responder cookie Mode Remote
Address
3289542 UP 48d928408940de28 e418fc7702fe483b Main
172.31.50.1
3289543 UP eb45940484082b14 428086b100427326 Main 10.10.50.1
[edit protocols ospf area 0.0.0.0]
user@host# run show security ipsec; security-associations
Total active tunnels: 2
ID Algorithm SPI Life:sec/kb Mon lsys Port Gateway
<131073 ESP:des/ shal 6d40899b 1360/ unlim - root 500 10.10.50.1
>131073 ESP:des/ shal 5a89400e 1360/ unlim - root 500 10.10.50.1
<131074 ESP:des/ shal c04046f 1359/ unlim - root 500 172.31.50.1
>131074 ESP:des/ shal 5508946c 1359/ unlim - root 500 172.31.50.1
[edit protocols ospf area 0.0.0.0]
user@host# run show ospf neighbor
Address Interface State ID Pri Dead 10.40.60.1 st0.0 Init 10.30.50.1
128 35
10.40.60.2 st0.0 Full 10.30.50.1 128 31
[edit protocols ospf area 0.0.0.0]
user@host# show
interface st0.0;
You have already configured a hub-and-spoke VPN with one hub device and two spoke devices. However, the hub device has one neighbor in the Init state and one neighbor in the Full state.
What would you do to resolve this problem?

  • A. Configure the st0.0 interface under OSPF as an unnumbered interface.
  • B. Configure the st0.0 interface under OSPF as a point-to-multipoint interface.
  • C. Configure the st0.0 interface under OSPF as a point-to-point interface.
  • D. Configure the st0.0 interface under OSPF as a nonbroadcast multiple access interface.

Answer: B


NEW QUESTION # 48
What are two valid modes for the Juniper ATP Appliance? (Choose two.)

  • A. event collector
  • B. core
  • C. flow collector
  • D. all-in-one

Answer: C,D


NEW QUESTION # 49
Exhibit

You have configured the SRX Series device to switch packets for multiple directly connected hosts that are within the same broadcast domain However, the traffic between two hosts in the same broadcast domain are not matching any security policies Referring to the exhibit, what should you do to solve this problem?

  • A. You must change the global mode to security switching mode.
  • B. You must change the global mode to transparent bridge mode.
  • C. You must change the global mode to switching mode.
  • D. You must change the global mode to security bridging mode

Answer: D


NEW QUESTION # 50
Which two log format types are supported by the JATP appliance? (Choose two.)

  • A. YAML
  • B. CSV
  • C. XML
  • D. YANG

Answer: B,C

Explanation:
https://www.juniper.net/documentation/en_US/release-independent/jatp/topics/topic-map/jatp-custom-log-ingestion.html


NEW QUESTION # 51
You want to enroll an SRX Series device with Juniper ATP Appliance. There is a firewall device in the path between the devices. In this scenario, which port should be opened in the firewall device?

  • A. 0
  • B. 1
  • C. 2
  • D. 3

Answer: D


NEW QUESTION # 52
Exhibit

Which statement is true about the output shown in the exhibit?

  • A. The SRX Series device is configured to disable IPv6 packet forwarding.
  • B. The SRX Series device is configured with flow-based IPv6 forwarding options.
  • C. The SRX Series device is configured with packet-based IPv6 forwarding options.
  • D. The SRX Series device is configured with default security forwarding options.

Answer: D


NEW QUESTION # 53
Click the Exhibit button.

While configuring the SRX345, you review the MACsec connection between devices and note that it is not working.
Referring to the exhibit, which action would you use to identify problem?

  • A. Verify that the formatting settings are correct between the devices and that the software supports the version of MACsec in use
  • B. Verify that the transmission path is not replicating packets or correcting frame check sequence error packets
  • C. Verify that the interface between the two devices is up and not experiencing errors
  • D. Verify that the connectivity association key and the connectivity association key name match on both devices

Answer: D

Explanation:
https://www.juniper.net/documentation/en_US/junos/topics/reference/command-summary/show- security-mka-statistics.html


NEW QUESTION # 54
You are connecting two remote sites to your corporate headquarters site.
You must ensure that all traffic is secured and sent directly between sites.
In this scenario, which VPN should be used?

  • A. IPsec ADVPN
  • B. hub-and-spoke IPsec VPN
  • C. full mesh Layer 3 VPN with EBGP
  • D. Layer 2 VPN

Answer: B


NEW QUESTION # 55
Exhibit

An administrator wants to configure an SRX Series device to log binary security events for tenant systems.
Referring to the exhibit, which statement would complete the configuration?

  • A. Configure the tenant as master for the pi security profile.
  • B. Configure the tenant as TSYS1 for the pi security profile.
  • C. Configure the tenant as root for the pi security profile.
  • D. Configure the tenant as local for the pi security profile

Answer: C


NEW QUESTION # 56
Exhibit

You are using traceoptions to verity NAT session information on your SRX Series device Referring to the exhibit, which two statements are correct? (Choose two.)

  • A. The SRX device is changing the destination address on this packet 10.0.1 1 to 172 20.101.10.
  • B. This packet is part of an existing session.
  • C. The SRX device is changing the source address on this packet from
  • D. This is the first packet in the session

Answer: A,D


NEW QUESTION # 57
You are asked to configure a new SRX Series CPE device at a remote office. The device must participate in forwarding MPLS and IPsec traffic.
Which two statements are true regarding this implementation? (Choose two.)

  • A. Host inbound traffic must be processed by the flow module
  • B. The SRX Series device can process both MPLS and IPsec with default traffic handling
  • C. Host inbound traffic must not be processed by the flow module
  • D. A firewall filter must be configured to enable packet mode forwarding

Answer: C,D

Explanation:
https://www.juniper.net/documentation/en_US/junos/topics/topic-map/security-packet-based- forwarding.html


NEW QUESTION # 58
Which two statements are correct regarding tenant systems on SRX Series devices? (Choose two.)

  • A. A maximum of 32 tenant systems can be configured on a physical SRX device.
  • B. All tenant systems share a single routing protocol process.
  • C. Each tenant system runs its own instance of the routing protocol process
  • D. A maximum of 500 tenant systems can be configured on a physical SRX device.

Answer: A,C


NEW QUESTION # 59
You are asked to configure a security policy on the SRX Series device. After committing the policy, you receive the "Policy is out of sync between RE and PFE <SPU-name(s)>." error.
Which command would be used to solve the problem?

  • A. request security polices resync
  • B. restart security-intelligence
  • C. request service-deployment
  • D. request security polices check

Answer: A


NEW QUESTION # 60
Exhibit.

Referring to the exhibit, a spoke member of an ADVPN is not functioning correctly.
Which two commands will solve this problem? (Choose two.)

  • A. [edit security ike gateway advpn-gateway]
    user@srx# set version v1-only
  • B. [edit interfaces]
    user@srx# delete st0.0 multipoint
  • C. [edit security ike gateway advpn-gateway]
    user@srx# set advpn suggester disable
  • D. [edit security ike gateway advpn-gateway]
    user@srx# delete advpn partner

Answer: C,D

Explanation:
https://www.juniper.net/documentation/en_US/junos/topics/topic-map/security-auto-discovery-vpns.html


NEW QUESTION # 61
Exhibit

Referring to the exhibit, which two statements are true? (Choose two.)

  • A. The SRX-1 device creates the Proxy_wodes feed, so it cannot use it in another security policy.
  • B. You can use the Proxy_Nodes feed as the source-address and destination-address match criteria of another security policy on a different SRX Series device.
  • C. You can only use the Proxy_Node3 feed as the destination-address match criteria of another security policy on a different SRX Series device.
  • D. The SRX-1 device can use the Proxy__Nodes feed in another security policy.

Answer: A,D


NEW QUESTION # 62
Exhibit

Referring to the exhibit, which type of NAT is being performed?

  • A. Destination NAT
  • B. Static NAT
  • C. Persistent NAT
  • D. Source NAT

Answer: D


NEW QUESTION # 63
Which feature of Sky ATP is deployed with Policy Enforcer?

  • A. service redundancy daemon configuration support
  • B. zero-day threat mitigation
  • C. device inventory management
  • D. software image snapshot support

Answer: B


NEW QUESTION # 64
......

Start your JN0-636 Exam Questions Preparation: https://www.prepawayexam.com/Juniper/braindumps.JN0-636.ete.file.html

Realistic JN0-636 Dumps Questions To Gain Brilliant Result: https://drive.google.com/open?id=1OMOXr-qWR68f2V6n-UqV-fEX4aV_XCOy