Pass Your Juniper Exam with JN0-636 Exam Dumps (Updated 117 Questions)
JN0-636 Exam Dumps - Juniper Practice Test Questions
NEW QUESTION # 48
You are asked to allocate security profile resources to the interconnect logical system for it to work properly.
In this scenario, which statement is correct?
- A. The flow-session resource must be defined in the security profile for the interconnect logical system.
- B. The resources must be calculated based on the amount of traffic that will flow between the logical systems.
- C. No resources are needed to be allocated to the interconnect logical system.
- D. The NAT resources must be defined in the security profile for the interconnect logical system.
Answer: B
NEW QUESTION # 49
Exhibit
You are using traceoptions to verify NAT session information on your SRX Series device. Referring to the exhibit, which two statements are correct? (Choose two.)
- A. This is the first packet in the session.
- B. The SRX Series device is performing both source and destination NAT on this session.
- C. This is the last packet in the session.
- D. The SRX Series device is performing only source NAT on this session.
Answer: A,B
Explanation:
The SRX Series device is performing both source and destination NAT on this session because the traceoptions output shows that both source and destination IP addresses and ports are translated. The source IP address 192.168.5.2 is translated to 192.168.100.1 and the destination IP address 1.1.1.1 is translated to 192.168.5.1. The source port 0 is translated to 14777 and the destination port 80 is translated to 80. The traceoptions output also shows the rule and pool IDs for both source and destination NAT: 2/32770 and 1/1 respectively.
This is the first packet in the session because the traceoptions output shows the flag flow_first_packet, which indicates that this is the first packet of a new session. The traceoptions output also shows the flag flow_first_src_xlate and flow_first_rule_dst_xlate, which indicate that this is the first time that source and destination NAT are applied to this session.
Reference:
traceoptions (Security NAT) | Junos OS | Juniper Networks
[SRX] How to interpret Flow TraceOptions output for NAT troubleshooting
NEW QUESTION # 50
You have configured three logical tunnel interfaces in a tenant system on an SRX1500 device.
When committing the configuration, the commit fails.
In this scenario, what would cause this problem?
- A. There is no GRE tunnel between the tenant system and master system allowing SSH traffic
- B. The SRX1500 device does not support more than two logical interfaces per tenant system
- C. There is no VPLS switch on the tenant system containing a peer It-0/0/0 interface
- D. The SRX1500 device requires a tunnel PIC to allow for logical tunnel interfaces
Answer: C
Explanation:
https://www.juniper.net/documentation/en_US/junos/topics/topic-map/logical-systems- overview.html
NEW QUESTION # 51
Refer to the Exhibit.
Referring to the exhibit, which three topologies are supported by Policy Enforcer? (Choose three.)
- A. Topology 1
- B. Topology 3
- C. Topology 5
- D. Topology 4
- E. Topology 2
Answer: A,B,D
NEW QUESTION # 52
Exhibit
Referring to the exhibit, which statement is true?
- A. This custom block list feed will be used after the Juniper Seclntel block list feed.
- B. This custom block list feed cannot be saved if the Juniper Seclntel block list feed is configured.
- C. This custom block list feed will be used instead of the Juniper Seclntel block list feed
- D. This custom block list feed will be used before the Juniper Seclntel
Answer: A
NEW QUESTION # 53
Exhibit
Which two statements are correct about the output shown in the exhibit? (Choose two.)
- A. The packet matches a configured security policy.
- B. The packet matches the default security policy.
- C. The packet is processed as host inbound traffic.
- D. The packet is processed in the first path packet flow.
Answer: C,D
Explanation:
The packet is processed as host inbound traffic because the traceoptions output shows that the destination IP address 10.10.10.1 belongs to the SRX device itself, which is configured with the ge-0/0/1.0 interface. The traceoptions output also shows the flag flow_host_inbound, which indicates that the packet is destined to the device.
The packet matches the default security policy because the traceoptions output shows that the policy name is default-deny, which is the implicit system-default security policy that denies all packets. The traceoptions output also shows the flag flow_policy_deny, which indicates that the packet is denied by the policy.
Reference:
traceoptions (Security NAT) | Junos OS | Juniper Networks
[SRX] How to interpret Flow TraceOptions output for NAT troubleshooting Default Security Policies | Junos OS | Juniper Networks
NEW QUESTION # 54
You are asked to control access to network resources based on the identity of an authenticated device Which three steps will accomplish this goal on the SRX Series firewalls? (Choose three )
- A. Reference the end-user-profile in the security policy.
- B. Apply the end-user-profile at the interface connecting the devices
- C. Configure an end-user-profile that characterizes a device or set of devices
- D. Configure the authentication source to be used to authenticate the device
- E. Reference the end-user-profile in the security zone
Answer: A,C,D
Explanation:
To control access to network resources based on the identity of an authenticated device on the SRX Series firewalls, you need to perform the following steps:
A) Configure an end-user-profile that characterizes a device or set of devices. An end-user-profile is a device identity profile that contains a collection of attributes that are characteristics of a specific group of devices, or of a specific device, depending on the attributes configured in the profile. The end-user-profile must contain a domain name and at least one value in each attribute. The attributes include device-identity, device-category, device-vendor, device-type, device-os, and device-os-version1. You can configure an end-user-profile by using the Junos Space Security Director or the CLI2.
C) Reference the end-user-profile in the security policy. A security policy is a rule that defines the action to be taken for the traffic that matches the specified criteria, such as source and destination addresses, zones, protocols, ports, and applications. You can reference the end-user-profile in the source-end-user-profile field of the security policy to identify the traffic source based on the device from which the traffic issued. The SRX Series device matches the IP address of the device to the end-user-profile and applies the security policy accordingly3. You can reference the end-user-profile in the security policy by using the Junos Space Security Director or the CLI4.
E) Configure the authentication source to be used to authenticate the device. An authentication source is a system that provides the device identity information to the SRX Series device. The authentication source can be Microsoft Windows Active Directory or a third-party network access control (NAC) system. You need to configure the authentication source to be used to authenticate the device and to send the device identity information to the SRX Series device. The SRX Series device stores the device identity information in the device identity authentication table5. You can configure the authentication source by using the Junos Space Security Director or the CLI6.
The other options are incorrect because:
B) Referencing the end-user-profile in the security zone is not a valid step to control access to network resources based on the identity of an authenticated device. A security zone is a logical grouping of interfaces that have similar security requirements. You can reference the user role in the security zone to identify the user who is accessing the network resources, but not the end-user-profile7.
D) Applying the end-user-profile at the interface connecting the devices is also not a valid step to control access to network resources based on the identity of an authenticated device. You cannot apply the end-user-profile at the interface level, but only at the security policy level. The end-user-profile is not a firewall filter or a security policy, but a device identity profile that is referenced in the security policy1.
Reference:
End User Profile Overview
Creating an End User Profile
source-end-user-profile
Creating Firewall Policy Rules
Understanding the Device Identity Authentication Table and Its Entries
Configuring the Authentication Source for Device Identity
user-role
NEW QUESTION # 55
SRX Series device enrollment with Policy Enforcer fails To debug further, the user issues the following commandshow configuration services security-intelligence url
https : //cloudfeeds . argon . juniperaecurity . net/api/manifeat. xml
and receives the following output:
What is the problem in this scenario?
- A. The SRX Series device does not have a valid license.
- B. The device is already enrolled with Policy Enforcer.
- C. Junos Space does not have matching schema based on the
- D. The device is directly enrolled with Juniper ATP Cloud.
Answer: A
NEW QUESTION # 56
Exhibit
Which statement is true about the output shown in the exhibit?
- A. The SRX Series device is configured with packet-based IPv6 forwarding options.
- B. The SRX Series device is configured with flow-based IPv6 forwarding options.
- C. The SRX Series device is configured to disable IPv6 packet forwarding.
- D. The SRX Series device is configured with default security forwarding options.
Answer: B
Explanation:
The output shown in the exhibit is from the command "show security flow session family inet6". This command displays the IPv6 flow sessions on the SRX Series device. The output shows that there are two total sessions, both of which are valid. This means that the SRX Series device is configured with flow-based IPv6 forwarding options. Flow-based IPv6 forwarding options enable the device to process IPv6 packets using the security policies, NAT, and other security features. To configure flow-based IPv6 forwarding options, use the command set security forwarding-options family inet6 mode flow-based and reboot the device. Reference:
show security flow session family inet6
Configuring Flow-Based IPv6 Forwarding Options
SRX Getting Started - Configure IPv6
NEW QUESTION # 57
A hub member of an ADVPN is not functioning correctly.
Referring the exhibit, which action should you take to solve the problem?
- A. [edit security]
user@hub-1# set ike gateway advpn-gateway advpn suggester disable - B. [edit interfaces]
root@vSRX-1# delete st0.0 multipoint - C. [edit interfaces]
user@hub-1# delete ipsec vpn advpn-vpn traffic-selector - D. [edit security]
user@hub-1# delete ike gateway advpn-gateway advpn partner
Answer: C
NEW QUESTION # 58
You are required to secure a network against malware. You must ensure that in the event that a compromised host is identified within the network. In this scenario after a threat has been identified, which two components are responsible for enforcing MAC-level infected host ?
- A. SRX Series device
- B. Juniper ATP Appliance
- C. EX Series device
- D. Policy Enforcer
Answer: C,D
Explanation:
You are required to secure a network against malware. You must ensure that in the event that a compromised host is identified within the network, the host is isolated from the rest of the network. In this scenario, after a threat has been identified, the two components that are responsible for enforcing MAC-level infected host are:
C) Policy Enforcer. Policy Enforcer is a software solution that integrates with Juniper ATP Cloud and Juniper ATP Appliance to provide automated threat remediation across the network. Policy Enforcer can receive threat intelligence feeds from Juniper ATP Cloud or Juniper ATP Appliance and apply them to the security policies on the SRX Series devices and the EX Series devices. Policy Enforcer can also enforce MAC-level infected host, which is a feature that allows you to quarantine a compromised host by blocking its MAC address on the switch port. Policy Enforcer can communicate with the EX Series devices and instruct them to apply the MAC-level infected host policy to the infected host1.
D) EX Series device. EX Series devices are Ethernet switches that can provide Layer 2 and Layer 3 switching capabilities and security features. EX Series devices can integrate with Policy Enforcer and Juniper ATP Cloud or Juniper ATP Appliance to provide automated threat remediation across the network. EX Series devices can support MAC-level infected host, which is a feature that allows them to quarantine a compromised host by blocking its MAC address on the switch port. EX Series devices can receive instructions from Policy Enforcer and apply the MAC-level infected host policy to the infected host2.
The other options are incorrect because:
A) SRX Series device. SRX Series devices are high-performance firewalls that can provide Layer 3 and Layer 4 security features and integrate with Juniper ATP Cloud or Juniper ATP Appliance to provide advanced threat prevention. SRX Series devices can receive threat intelligence feeds from Juniper ATP Cloud or Juniper ATP Appliance and apply them to the security policies. However, SRX Series devices cannot enforce MAC-level infected host, which is a feature that requires Layer 2 switching capabilities and is supported by EX Series devices3.
B) Juniper ATP Appliance. Juniper ATP Appliance is a hardware solution that provides advanced threat prevention by detecting and blocking malware, ransomware, and other cyberattacks. Juniper ATP Appliance can analyze the network traffic and identify the compromised hosts based on their behavior and communication patterns. Juniper ATP Appliance can also send threat intelligence feeds to Policy Enforcer and SRX Series devices to enable automated threat remediation across the network. However, Juniper ATP Appliance cannot enforce MAC-level infected host, which is a feature that requires Layer 2 switching capabilities and is supported by EX Series devices.
Reference:
Policy Enforcer Overview
EX Series Switches Overview
SRX Series Services Gateways Overview
[Juniper ATP Appliance Overview]
NEW QUESTION # 59
Exhibit
Referring to the exhibit, which three statements are true? (Choose three.)
- A. The packet's destination is to a server in the DMZ zone.
- B. The packet is dropped before making an SSH connection.
- C. The packet is allowed to make an SSH connection.
- D. The packet's destination is to an interface on the SRX Series device.
- E. The packet originated within the Trust zone.
Answer: B,D,E
NEW QUESTION # 60
You want to enable inter-tenant communicaon with tenant system.
In this Scenario, Which two solutions will accomplish this task?
- A. interconnect EVPN switch
- B. external router
- C. interconnect VPLS switch
- D. logical tunnel interface
Answer: B,D
Explanation:
To enable inter-tenant communication with tenant system, you need to use an external router or a logical tunnel interface. The other options are incorrect because:
A) Interconnecting EVPN switch is not a valid solution for inter-tenant communication with tenant system. EVPN (Ethernet VPN) is a technology that provides layer 2 connectivity over an IP network. It can be used to connect different logical systems on the same device, but not tenant systems. Tenant systems are isolated from each other and do not share the same layer 2 domain1.
B) Interconnecting VPLS switch is also not a valid solution for inter-tenant communication with tenant system. VPLS (Virtual Private LAN Service) is another technology that provides layer 2 connectivity over an IP network. It can also be used to connect different logical systems on the same device, but not tenant systems. Tenant systems are isolated from each other and do not share the same layer 2 domain1.
Therefore, the correct answer is C and D. You need to use an external router or a logical tunnel interface to enable inter-tenant communication with tenant system. To do so, you need to perform the following steps:
For external router, you need to connect the external router to the interfaces of the tenant systems that you want to communicate with. You also need to configure the routing protocols and policies on the external router and the tenant systems to exchange routes and traffic. The external router acts as a gateway between the tenant systems and provides layer 3 connectivity2.
For logical tunnel interface, you need to create a logical tunnel interface on the device and assign it to a tenant system. You also need to configure the IP address and routing protocols on the logical tunnel interface and the tenant systems that you want to communicate with. The logical tunnel interface acts as a virtual link between the tenant systems and provides layer 3 connectivity3.
Reference:
Tenant Systems Overview
Example: Configuring Inter-Tenant Communication Using External Router
Example: Configuring Inter-Tenant Communication Using Logical Tunnel Interface
NEW QUESTION # 61
Which statement is true about persistent NAT types?
- A. The target-host parameter cannot be used with IPv6 addressee in NAT64.
- B. The target-host-port parameter cannot be used with IPv6 addresses in NAT64
- C. The target-host parameter cannot be used with IPv4 addresses inNAT46
- D. The target-host-port parameter cannot be used with IPv4 addresses in NAT46.
Answer: C
NEW QUESTION # 62
Exhibit
The show network-access aaa radius-servers command has been issued to solve authentication issues.
Referring to the exhibit, to which two authentication servers will the SRX Series device continue to send requests? (Choose TWO)
- A. 192.168.30.190
- B. 192.168.30.191
- C. 200l:DB8:0:f101;:2
- D. 192.168.30.188
Answer: A,B
Explanation:
The SRX Series device will continue to send requests to authentication servers 192.168.30.190 and 192.168.30.191. This is because the exhibit shows the output of the show network-access aaa radius-servers command. This command displays the status of the RADIUS servers configured on the device. In the output, we can see that there are three RADIUS servers configured - 192.168.30.190, 192.168.30.191, and 2001:DB8:0:f101::2. However, the status of the third server is shown as "DOWN". This means that the device is not able to communicate with this server. Therefore, the device will continue to send requests to the other two servers - 192.168.30.190 and 192.168.30.191. Reference: Juniper Security, Professional (JNCIP-SEC) Reference Materials source and documents: https://www.juniper.net/documentation/en_US/junos/topics/reference/command-summary/show-network-access-aaa-radius-servers.html
NEW QUESTION # 63
you must create a secure fabric in your company's network
In this Scenario, Which three statements are correct? (Choose Three)
- A. Switches and connectors cannot be added to the same site
- B. MX Series device associated with tenants can belong to only one site
- C. A switch must be assigned to the site to enforce an infected host policy within the network
- D. SRX Series devices can belong to only one site
- E. SRX Series devices can belong to multiple sites
Answer: A,C,D
Explanation:
To create a secure fabric in your company's network, you need to know the following facts:
A secure fabric is a collection of sites that contain network devices (switches, routers, firewalls, and other security devices) that are used in policy enforcement groups. A site is a grouping of network devices that contribute to threat prevention. When threat prevention policies are applied to policy enforcement groups, the system automatically discovers to which sites those groups belong. This is how threat prevention is aggregated across your secure fabric1.
MX Series devices associated with tenants can belong to multiple sites. Tenants are logical partitions of the network that can have their own security policies and enforcement points. Sites that are associated with tenants do not need switches as enforcement points, because MX Series devices can perform tenant-based policy enforcement1.
SRX Series devices can belong to only one site. SRX Series devices are firewalls that can act as perimeter enforcement points for the secure fabric. They can send potentially malicious objects and files to the Juniper ATP Cloud for analysis and receive threat intelligence from the Juniper ATP Cloud to block malicious traffic. SRX Series devices cannot belong to multiple sites, because they do not support tenant-based policy enforcement1.
A switch must be assigned to the site to enforce an infected host policy within the network. An infected host policy is a policy that blocks or quarantines hosts that are identified as infected by the Juniper ATP Cloud. A switch can act as an internal enforcement point for the secure fabric by applying the infected host policy to the hosts that are connected to it. A switch must be assigned to the site where the infected hosts are located, because SRX Series devices cannot enforce infected host policies1.
Switches and connectors cannot be added to the same site. Connectors are software agents that can be installed on Windows or Linux servers to enable them to act as enforcement points for the secure fabric. Connectors can apply infected host policies to the hosts that are connected to them. However, connectors cannot coexist with switches in the same site, because they use different methods of policy enforcement. Switches use VLANs and ACLs, while connectors use IPtables and WFP1.
Therefore, the correct answer is B, D, and E. The other options are incorrect because:
A) MX Series devices associated with tenants can belong to multiple sites, not only one site1.
C) SRX Series devices can belong to only one site, not multiple sites1.
Reference:
Secure Fabric Overview
NEW QUESTION # 64
Exhibit
An administrator wants to configure an SRX Series device to log binary security events for tenant systems.
Referring to the exhibit, which statement would complete the configuration?
- A. Configure the tenant as master for the pi security profile.
- B. Configure the tenant as TSYS1 for the pi security profile.
- C. Configure the tenant as root for the pi security profile.
- D. Configure the tenant as local for the pi security profile
Answer: C
NEW QUESTION # 65
You are trying to configure an IPsec tunnel between SRX Series devices in the corporate office and branch1. You have committed the configuration shown in the exhibit, but the IPsec tunnel is not establishing.
In this scenario, what would solve this problem?
- A. Add multipoint to the st0.0 interface configuration on the branch1 device.
- B. Change the local identity to inet advpn on the branch1 device.
- C. Change the IKE mode to aggressive on the branch1 and corporate devices.
- D. Change the IKE proposal-set to compatible on the branch1 and corporate devices.
Answer: B
NEW QUESTION # 66
You configured a chassis cluster for high availability on an SRX Series device and enrolled this HA cluster with the Juniper ATP Cloud. Which two statements are correct in this scenario? (Choose two.)
- A. You must set up your HA cluster after enrolling your devices with Juniper ATP Cloud
- B. You must use the same license key on both cluster nodes.
- C. You must use different license keys on both cluster nodes.
- D. When enrolling your devices, you only need to enroll one node.
Answer: A,B
NEW QUESTION # 67
Referring to the exhibit. You configure a traceoptions file called radius on your returns the output shown in the exhibit. What is the source of the problem?
- A. The RADIUS server IP address is unreachable.
- B. An incorrect password is being used.
- C. The RADIUS server suffered a hardware failure.
- D. The authentication order is misconfigured.
Answer: C
NEW QUESTION # 68
Your IPsec VPN configuration uses two CoS forwarding classes to separate voice and data traffic. How many IKE security associations are required between the IPsec peers in this scenario?
- A. 0
- B. 1
- C. 2
- D. 3
Answer: C
NEW QUESTION # 69
You want to configure a threat prevention policy.
Which three profiles are configurable in this scenario? (Choose three.)
- A. infected host profile
- B. malware profile
- C. device profile
- D. SSL proxy profile
- E. C&C profile
Answer: A,B,E
Explanation:
The three profiles that are configurable in a threat prevention policy are infected host profile, C&C profile, and malware profile. A threat prevention policy is a feature of Juniper ATP Cloud that provides protection and monitoring for selected threat profiles, including command and control servers, infected hosts, and malware. Using feeds from Juniper ATP Cloud and optional custom feeds that you configure, ingress and egress traffic is monitored for suspicious content and behavior. Based on a threat score, detected threats are evaluated and action may be taken once a verdict is reached. You can create a threat prevention policy by selecting one or more of the following profiles:
Infected host profile: This profile detects and blocks traffic from hosts that are infected with malware or compromised by attackers. You can configure the threat score thresholds and the actions for different levels of severity. You can also enable Geo IP filtering to block traffic from or to specific countries or regions.
C&C profile: This profile detects and blocks traffic to or from command and control servers that are used by attackers to control malware or botnets. You can configure the threat score thresholds and the actions for different levels of severity. You can also enable Geo IP filtering to block traffic from or to specific countries or regions.
Malware profile: This profile detects and blocks traffic that contains malware or malicious content. You can configure the threat score thresholds and the actions for different levels of severity. You can also enable protocol-specific settings for HTTP and SMTP traffic, such as file type filtering, file size filtering, and file name filtering.
The other two profiles, device profile and SSL proxy profile, are not configurable in a threat prevention policy. A device profile is a feature of Policy Enforcer that defines the device type, the device group, and the device settings for the SRX Series devices that are enrolled with Juniper ATP Cloud. An SSL proxy profile is a feature of SRX Series devices that enables SSL proxy to decrypt and inspect SSL/TLS traffic for threats and policy violations.
NEW QUESTION # 70
......
New Real JN0-636 Exam Dumps Questions: https://drive.google.com/open?id=1dZI1itI37QGa8sA6_IkxABy5FhyEnbt2
Pass Your JN0-636 Exam Easily with Accurate PDF Questions: https://www.actual4exams.com/JN0-636-valid-dump.html