JN0-636 Free Exam Questions and Answers PDF Updated on Apr-2024
Latest JN0-636 Exam Dumps Recently Updated 117 Questions
NEW QUESTION # 33
You are asked to configure an IPsec VPN between two SRX Series devices that allows for processing of CoS on the intermediate routers.
What will satisfy this requirement?
- A. policy-based VPN
- B. OpenVPN
- C. remote access VPN
- D. route-based VPN
Answer: D
Explanation:
https://www.juniper.net/documentation/en_US/junos/topics/topic-map/secuirty-cos-based-ipsec- vpns.html
NEW QUESTION # 34
You are asked to provide single sign-on (SSO) to Juniper ATP Cloud. Which two steps accomplish this goal?
(Choose two.)
- A. Configure Juniper ATP Cloud as the service provider (SP).
- B. Configure Juniper ATP Cloud as the identity provider (IdP).
- C. Configure Microsoft Azure as the service provider (SP).
- D. Configure Microsoft Azure as the identity provider (IdP).
Answer: C,D
NEW QUESTION # 35
You want to configure a threat prevention policy.
Which three profiles are configurable in this scenario? (Choose three.)
- A. C&C profile
- B. infected host profile
- C. malware profile
- D. device profile
- E. SSL proxy profile
Answer: B,D,E
NEW QUESTION # 36
Exhibit:
The security trace options configuration shown in the exhibit is committed to your SRX series firewall. Which two statements are correct in this Scenario? (Choose Two)
- A. Once the trace has generated 10 log files, the trace process will halt.
- B. Once the trace has generated 10 log files, older logs will be overwritten.
- C. The file debugger will be readable by all users.
- D. The file debugger will be readable only by the user who committed this configuration
Answer: B,D
NEW QUESTION # 37
Click the Exhibit button.
You are asked to look at a configuration that is designed to take all traffic with a specific source IP address and forward the traffic to a traffic analysis server for further evaluation. The configuration is not working as intended.
Referring to the exhibit, which change must be made to correct the configuration?
- A. Create a routing instance named default
- B. Apply the filter as an input filter on interface xe-0/2/1.0
- C. Apply the filter as an input filter on interface xe-0/0/1.0
- D. Apply the filter as an output filter on interface xe-0/1/0.0
Answer: C
NEW QUESTION # 38
You are connecting two remote sites to your corporate headquarters site; you must ensure that all traffic is secured and only uses a single Phase 2 SA for both sites.
In this scenario, which VPN should be used?
- A. An IPsec group VPN with the corporate firewall acting as the hub device.
- B. Full mesh IPsec VPNs with tunnels between all sites.
- C. A full mesh Layer 3 VPN with the corporate firewall acting as the hub device.
- D. A hub-and-spoke IPsec VPN with the corporate firewall acting as the hub device.
Answer: A
NEW QUESTION # 39
Exhibit.
Referring to the exhibit, which two statements are true? (Choose two.)
- A. The c-1 TSYS has a reservation for the security flow resource.
- B. The c-1 TSYS has no reservation for the security flow resource.
- C. The c-1 TSYS cannot use any security flow resources.
- D. The c-1 TSYS can use security flow resources up to the system maximum.
Answer: B,C
Explanation:
https://www.juniper.net/documentation/en_US/junos/topics/topic-map/security-profile-logical-system.html
NEW QUESTION # 40
You want to route traffic between two newly created virtual routers without the use of logical systems using the configuration options on the SRX5800.
Which two methods of forwarding, between virtual routers, would you recommend? (Choose two.)
- A. Use a static route to forward traffic across virtual routers using the next-table option.
Enable the return route by using a RIB group. - B. Create static routes in each virtual router using thenext-tablecommand.
- C. Connect a direct cable between boo physical interfaces, one in each virtual router and use static routes with thenext-hopcommand.
- D. Use a RIB group to share the internal routing protocol routes from the master routing instance.
Answer: B,C
NEW QUESTION # 41
The IPsec VPN on your SRX Series device establishes both the Phase 1 and Phase 2 security associations. Users are able to pass traffic through the VPN. During peak VPN usage times, users complain about decreased performance. Network connections outside of the VPN are not seriously impacted.
Which two actions will resolve the problem? (Choose two.)
- A. Verify that the PKI certificate used to establish the VPN is being properly verified using either the CPL or OCSP.
- B. Lower the MSS setting in the security flow stanza for IPsec VPNs.
- C. Verify that NAT-T is not disabled in the properties of the phase 1 gateway.
- D. Lower the MTU size on the interface to reduce the likelihood of packet fragmentation.
Answer: B,D
NEW QUESTION # 42
You are asked to deploy filter-based forwarding on your SRX Series device for incoming traffic sourced from the 10.10 100 0/24 network in this scenario, which three statements are correct? (Choose three.)
- A. You must create and apply a firewall filter that matches on the source address 10.10.100.0/24 and then sends this traffic to your routing
- B. You must create and apply a firewall filter that matches on the destination address 10 10.100.0/24 and then sends this traffic to your routing instance.
- C. You must create a forwarding-type routing instance.
- D. You must create a VRF-type routing instance.
- E. You must create a RIB group that adds interface routes to your routing instance.
Answer: A,B,D
NEW QUESTION # 43
Your organization has multiple Active Directory domain to control user access. You must ensure that security polices are passing traffic based upon the user's access rights. What would you use to assist your SRX series devices to accomplish this task?
- A. JIMS
- B. JSA
- C. Junos Space
- D. JATP Appliance
Answer: A
Explanation:
https://www.juniper.net/documentation/en_US/junos/topics/topic-map/security-user-auth- configure-jims.html
NEW QUESTION # 44
Exhibit
Which two statements are correct about the output shown in the exhibit? (Choose two.)
- A. The packet is processed as host inbound traffic.
- B. The packet matches the default security policy.
- C. The packet is processed in the first path packet flow.
- D. The packet matches a configured security policy.
Answer: A,C
Explanation:
The packet is processed as host inbound traffic because the traceoptions output shows that the destination IP address 10.10.10.1 belongs to the SRX device itself, which is configured with the ge-0/0/1.0 interface. The traceoptions output also shows the flag flow_host_inbound, which indicates that the packet is destined to the device.
The packet matches the default security policy because the traceoptions output shows that the policy name is default-deny, which is the implicit system-default security policy that denies all packets. The traceoptions output also shows the flag flow_policy_deny, which indicates that the packet is denied by the policy.
Reference:
traceoptions (Security NAT) | Junos OS | Juniper Networks
[SRX] How to interpret Flow TraceOptions output for NAT troubleshooting Default Security Policies | Junos OS | Juniper Networks
NEW QUESTION # 45
Exhibit
You are not able to ping the default gateway of 192.168 100 1 (or your network that is located on your SRX Series firewall.
Referring to the exhibit, which two commands would correct the configuration of your SRX Series device? (Choose two.)
- A.

- B.

- C.

- D.

Answer: A,B
NEW QUESTION # 46
Exhibit
You configure a traceoptions file called radius on your returns the output shown in the exhibit What is the source of the problem?
- A. The authentication order is misconfigured.
- B. The RADIUS server suffered a hardware failure.
- C. An incorrect password is being used.
- D. The RADIUS server IP address is unreachable.
Answer: B
NEW QUESTION # 47
You are asked to detect domain generation algorithms
Which two steps will accomplish this goal on an SRX Series firewall? (Choose two.)
- A. Attach the advanced-anti-malware policy to a security policy.
- B. Define an advanced-anti-malware policy under [edit services].
- C. Define a security-metadata-streaming policy under [edit
- D. Attach the security-metadata-streaming policy to a security
Answer: A,B
NEW QUESTION # 48
You issue the command shown in the exhibit.
Which policy will be active for the identified traffic?
- A. Policy p1
- B. Policy p7
- C. Policy p12
- D. Policy p4
Answer: B
NEW QUESTION # 49
Which three types of peer devices are supported for CoS-based IPsec VPNs? (Choose three.)
- A. vSRX
- B. high-end SRX Series device
- C. cSRX
- D. third-party device
- E. branch SRX Series device
Answer: A,B,E
Explanation:
https://www.juniper.net/documentation/en_US/junos/topics/topic-map/secuirty-cos-based- ipsec- vpns.html
NEW QUESTION # 50
Exhibit
You are using traceoptions to verify NAT session information on your SRX Series device. Referring to the exhibit, which two statements are correct? (Choose two.)
- A. This is the last packet in the session.
- B. The SRX Series device is performing only source NAT on this session.
- C. This is the first packet in the session.
- D. The SRX Series device is performing both source and destination NAT on this session.
Answer: A,D
NEW QUESTION # 51
A company wants to paron their physical SRX series firewall into multiple logical units and assign each unit (tenant) to a department within the organization. You are the primary administrator of firewall and a colleague is the administrator for one of the departments.
Which two statements are correct about your colleague? (Choose two)
- A. The colleague can access and view the resources of the tenant system.
- B. The colleague can modify the number of allocated resources for the tenant system
- C. The colleague can configure the resources allocated and routing protocols
- D. The colleague can create and assign logical interfaces to the tenant system
Answer: A,D
Explanation:
A)company wants to partition their physical SRX series firewall into multiple logical units and assign each unit (tenant) to a department within the organization. You are the primary administrator of the firewall and a colleague is the administrator for one of the departments. The two statements that are correct about your colleague are:
B) The colleague can access and view the resources of the tenant system. A tenant system is a type of logical system that is created and managed by the primary administrator of the firewall. A tenant system has its own discrete administrative domain, logical interfaces, routing instances, security policies, and other features. The primary administrator can assign a tenant system to a department within the organization and delegate the administration of the tenant system to a colleague. The colleague can access and view the resources of the tenant system, such as the allocated CPU, memory, and bandwidth, and the configured interfaces, zones, and policies1.
C) The colleague can create and assign logical interfaces to the tenant system. A logical interface is a software interface that represents a subset of the physical interface. A logical interface can have its own address, encapsulation, and routing parameters. The primary administrator can allocate a number of logical interfaces to a tenant system and allow the colleague to create and assign logical interfaces to the tenant system. The colleague can configure the logical interfaces with the appropriate address, encapsulation, and routing parameters for the tenant system2.
The other statements are incorrect because:
A) The colleague cannot configure the resources allocated and routing protocols. The resources allocated and routing protocols are configured by the primary administrator of the firewall. The primary administrator can allocate a fixed amount of resources, such as CPU, memory, and bandwidth, to a tenant system and specify the routing protocols that are allowed for the tenant system. The colleague cannot modify the resources allocated or routing protocols for the tenant system1.
D) The colleague cannot modify the number of allocated resources for the tenant system. The number of allocated resources for the tenant system is configured by the primary administrator of the firewall. The primary administrator can allocate a fixed amount of resources, such as CPU, memory, and bandwidth, to a tenant system and monitor the resource usage of the tenant system. The colleague cannot modify the number of allocated resources for the tenant system1.
Reference:
Understanding Tenant Systems
Understanding Logical Interfaces
NEW QUESTION # 52
You are asked to deploy Juniper atp appliance in your network. You must ensure that incidents and alerts are sent to your SIEM.
In this scenario, which logging output format is supported?
- A. CEF
- B. JSON
- C. WELF
- D. binay
Answer: A
Explanation:
The Juniper ATP Appliance platform collects, inspects and analyzes advanced and stealthy web, file, and email-based threats that exploit and infiltrate client browsers, operating systems, emails and applications. Juniper ATP Appliance's detection of malicious attacks generates incident and event details that can be sent to connected SIEM platforms in CEF, LEEF or Syslog formats1. CEF (Common Event Format) is an open log management standard that improves the interoperability of security-related information from different vendors2. Juniper ATP Appliance supports CEF format for sending events and system audit notifications to SIEM servers. You can configure the CEF format in the Juniper ATP Appliance Central Manager WebUI Config > Notifications > SIEM Settings1. Therefore, the correct answer is C. CEF is a supported logging output format for Juniper ATP Appliance. The other options are incorrect because:
A) WELF (WebTrends Enhanced Log Format) is a proprietary log format developed by WebTrends Corporation for web analytics3. Juniper ATP Appliance does not support WELF format for SIEM integration.
B) JSON (JavaScript Object Notation) is a lightweight data-interchange format that is easy for humans and machines to read and write4. Juniper ATP Appliance supports JSON format for HTTP API results, but not for SIEM notifications1.
D) Binary is a numeric system that uses only two digits: 0 and 1. Binary is not a logging output format for Juniper ATP Appliance or any SIEM platform.
Reference:
SIEM Syslog, LEEF and CEF Logging
Common Event Format Configuration Guide
WebTrends Enhanced Log Format
JSON
NEW QUESTION # 53
Which method does an SRX Series device in transparent mode use to learn about unknown devices in a network?
- A. RSTP
- B. packet flooding
- C. LLDP-MED
- D. IGMP snooping
Answer: B
Explanation:
The SRX Series device in transparent mode uses packet flooding to learn about unknown devices in a network. Packet flooding is a process wherein the device sends out packets to every device it knows about or suspects in the network. When the packets are returned, the device can identify and classify the unknown devices in the network.
NEW QUESTION # 54
Exhibit
You have recently configured Adaptive Threat Profiling and notice 20 IP address entries in the monitoring section of the Juniper ATP Cloud portal that do not match the number of entries locally on the SRX Series device, as shown in the exhibit.
What is the correct action to solve this problem on the SRX device?
- A. You must configure the DAE in a security policy on the SRX device.
- B. Force a manual download of the Proxy__Nodes feed.
- C. Flush the DNS cache on the SRX device.
- D. Refresh the feed in ATP Cloud.
Answer: C
NEW QUESTION # 55
To analyze and detect malware, Juniper ATP Cloud performs which two functions? (Choose two.)
- A. dynamic analysis: to see what happens if you execute the file in a real environment
- B. antivirus scan: with a single vendor solution to see if the file contains any potential threats
- C. cache lookup: to see if the file is seen already and known to be malicious
- D. static analysis: to see what happens if you execute the file in a real environment
Answer: A,C
Explanation:
Juniper ATP Cloud performs cache lookup to see if the file is seen already and known to be malicious and dynamic analysis to see what happens if you execute the file in a real environment.
Cache lookup is one of the functions that Juniper ATP Cloud performs to analyze and detect malware. Cache lookup is the first step in the pipeline approach that Juniper ATP Cloud uses to examine files. Cache lookup checks whether the file has been seen before and whether it has a stored verdict in the database. If the file is known to be malicious, the verdict is returned to the SRX Series Firewall and the file is dropped. If the file is not found in the cache, the analysis continues with the other techniques1.
Dynamic analysis is another function that Juniper ATP Cloud performs to analyze and detect malware. Dynamic analysis runs the file in a sandbox environment and observes its behavior and actions. Dynamic analysis can reveal the hidden or obfuscated functionality of malware, such as network connections, file modifications, registry changes, and process injections. Dynamic analysis can also detect zero-day threats and evasive malware that try to avoid static analysis1.
Reference:
How is Malware Analyzed and Detected? | ATP Cloud | Juniper Networks
NEW QUESTION # 56
You want to identify potential threats within SSL-encrypted sessions without requiring SSL proxy to decrypt the session contents. Which security feature achieves this objective?
- A. encrypted traffic insights
- B. Secure Web Proxy
- C. DNS security
- D. infected host feeds
Answer: C
NEW QUESTION # 57
You are asked to look at a configuration that is designed to take all traffic with a specific source ip address and forward the traffic to a traffic analysis server for further evaluation. The configuration is no longer working as intended.
Referring to the exhibit which change must be made to correct the configuration?
- A. Apply the filter as in input filter on interface xe-0/0/1.0
- B. Create a routing instance named default
- C. Apply the filter as in input filter on interface xe-0/2/1.0
- D. Apply the filter as in output filter on interface xe-0/1/0.0
Answer: A
NEW QUESTION # 58
......
Juniper JN0-636 Real 2024 Braindumps Mock Exam Dumps: https://www.exam4tests.com/JN0-636-valid-braindumps.html
JN0-636 Exam Questions | Real JN0-636 Practice Dumps: https://drive.google.com/open?id=1qyLovPBhptW27HzeAvlUvJ9UpMi94nma