Download Free Juniper JN0-636 Exam Questions & Answer [Q84-Q101]

Share

Download Free Juniper JN0-636 Exam Questions & Answer 

Online VALID JN0-636 Exam Dumps File Instantly


The JN0-636 exam is a comprehensive test that requires candidates to demonstrate their knowledge and skills in a variety of security-related topics. JN0-636 exam is comprised of multiple-choice and scenario-based questions and is designed to test the candidate's ability to apply their knowledge in real-world scenarios. Candidates have two hours to complete the exam.

 

NEW QUESTION # 84
You are asked to look at a configuration that is designed to take all traffic with a specific source ip address and forward the traffic to a traffic analysis server for further evaluation. The configuration is no longer working as intended.
Referring to the exhibit which change must be made to correct the configuration?

  • A. Apply the filter as in input filter on interface xe-0/2/1.0
  • B. Create a routing instance named default
  • C. Apply the filter as in output filter on interface xe-0/1/0.0
  • D. Apply the filter as in input filter on interface xe-0/0/1.0

Answer: D


NEW QUESTION # 85
Which statement is true about persistent NAT types?

  • A. The target-host-port parameter cannot be used with IPv4 addresses in NAT46.
  • B. The target-host-port parameter cannot be used with IPv6 addresses in NAT64
  • C. The target-host parameter cannot be used with IPv4 addresses inNAT46
  • D. The target-host parameter cannot be used with IPv6 addressee in NAT64.

Answer: C


NEW QUESTION # 86
Click the Exhibit button.

The IKE policy and proposal are configured properly on both devices as shown in the exhibit.
Which configuration snippet will complete the IKE configuration on the branch SRX Series device?

  • A.
  • B.
  • C.
  • D.

Answer: C


NEW QUESTION # 87
Referring to the exhibit, which two statements are true? (Choose two.)

  • A. The SRX-1 device creates the Proxy_wodes feed, so it cannot use it in another security policy.
  • B. You can use the Proxy_Nodes feed as the source-address and destination-address match criteria of another security policy on a different SRX Series device.
  • C. The SRX-1 device can use the Proxy__Nodes feed in another security policy.
  • D. You can only use the Proxy_Node3 feed as the destination-address match criteria of another security policy on a different SRX Series device.

Answer: A,C


NEW QUESTION # 88
You are asked to configure a new SRX Series CPE device at a remote office. The device must participate in forwarding MPLS and IPsec traffic.
Which two statements are true regarding this implementation? (Choose two.)

  • A. The SRX Series device can process both MPLS and IPsec with default traffic handling
  • B. Host inbound traffic must not be processed by the flow module
  • C. A firewall filter must be configured to enable packet mode forwarding
  • D. Host inbound traffic must be processed by the flow module

Answer: B,C

Explanation:
https://www.juniper.net/documentation/en_US/junos/topics/topic-map/security-packet-based- forwarding.html


NEW QUESTION # 89
Exhibit

You are validating bidirectional traffic flows through your IPsec tunnel. The 4546 session represents traffic being sourced from the remote end of the IPsec tunnel. The 4547 session represents traffic that is sourced from the local network destined to the remote network.
Which statement is correct regarding the output shown in the exhibit?

  • A. The local gateway address for the IPsec tunnel is 10.20.20.2
  • B. NAT is being used to change the source address of outgoing packets
  • C. The session information indicates that the IPsec tunnel has not been established
  • D. The remote gateway address for the IPsec tunnel is 10.20.20.2

Answer: D


NEW QUESTION # 90
Referring to the exhibit, which two statements are true? (Choose two.)

  • A. The data that traverses the ge-O/0/0 interface is secured by a connectivity association key.
  • B. The data that traverses the ge-070/0 interface can be intercepted and read by anyone.
  • C. The data that traverses the ge-0/070 interface is secured by a secure association key.
  • D. The data that traverses the ge-070/0 interface cannot be intercepted and read by anyone.

Answer: B,D


NEW QUESTION # 91
Your Source NAT implementation uses an address pool that contains multiple IPv4 addresses.
Your users report that when they establish more than one session with an external application, they are prompted to authenticate multiple times External hosts must not be able to establish sessions with internal network hosts.
What will solve this problem?

  • A. Disable PAT.
  • B. Enable address persistence.
  • C. Enable destination NAT.
  • D. Enable persistent NAT

Answer: D


NEW QUESTION # 92
Your organization has multiple Active Directory domains to control user access. You must ensure that security policies are passing traffic based upon the users' access rights.
What would you use to assist your SRX Series devices to accomplish this task?

  • A. JIMS
  • B. JATP Appliance
  • C. JSA
  • D. Junos Space

Answer: A

Explanation:
https://www.juniper.net/documentation/en_US/junos/topics/topic-map/security-user-auth- intergrated-user-firewall-overview.html


NEW QUESTION # 93
You are required to deploy a security policy on an SRX Series device that blocks all known Tor network IP addresses. Which two steps will fulfill this requirement? (Choose two.)

  • A. Enroll the devices with Juniper ATP Appliance.
  • B. Create a custom feed containing all current known MAC addresses.
  • C. Enroll the devices with Juniper ATP Cloud.
  • D. Enable a third-party Tor feed.

Answer: A,B


NEW QUESTION # 94
You issue the command shown in the exhibit.
Which policy will be active for the identified traffic?

  • A. Policy p4
  • B. Policy p7
  • C. Policy p1
  • D. Policy p12

Answer: B


NEW QUESTION # 95
The highlighted incident (arrow) shown in the exhibit shows a progression level of "Download" in the kill chain.
What are two appropriate mitigation actions for the selected incident? (Choose two.)

  • A. Immediate response required: Wipe infected endpoint hosts.
  • B. Immediate response required: Block malware IP addresses (download server or CnC server)
  • C. Immediate response required: Deploy IVP integration (if configured) to confirm if the endpoint has executed the malware and is infected.
  • D. Not an urgent action: Use IVP to confirm if machine is infected.

Answer: A,D


NEW QUESTION # 96
Exhibit

Which statement is true about the output shown in the exhibit?

  • A. The SRX Series device is configured with packet-based IPv6 forwarding options.
  • B. The SRX Series device is configured to disable IPv6 packet forwarding.
  • C. The SRX Series device is configured with flow-based IPv6 forwarding options.
  • D. The SRX Series device is configured with default security forwarding options.

Answer: D


NEW QUESTION # 97
What are two important function of the Juniper Networks ATP appliance solution? (Choose two.).

  • A. Statistics
  • B. Filtration
  • C. Detection
  • D. Analysis

Answer: C,D


NEW QUESTION # 98
Click the Exhibit button.
user @host> show bgp summary logical-system LSYS1
Groups : 11 Peers : 10 Down peers: 1
Table Tot. Paths Act Paths Suppressed History Damp State
Pending
inet.0 141 129 0 0 0 Peer AS InPkt OutPkt OutQ Flaps Last Up/Dwn
State|#Active/Received/Accepted/Damped...
192.168.64.12 65008 11153 11459 0 26 3d
3:10:43 9/10/10/0 0/0/0/0
192.168.72.12 65009 11171 11457 0 26 3d
3:10:39 11/12/12/0 0/0/0/0
192.168.80.12 65010 9480 9729 0 27 3d
3:10:42 11/12/12/0 0/0/0/0
192.168.88.12 65011 11171 11457 0 25 3d
3:10:31 12/13/13/0 0/0/0/0
192.168.96.12 65012 9479 9729 0 26 3d
3:10:34 12/13/13/0 0/0/0/0
192.168.10.12 65013 111689 11460 0 27 3d
3:10:46 9/10/10/0 0/0/0/0
192.168.11.12 65014 111688 11458 0 25 3d
3:10:42 9/10/10/0 0/0/0/0
192.168.12.12 65015 111687 11457 0 25 3d
3:10:38 9/10/10/0 0/0/0/0
192.68.11.12 650168 9478 9729 0 25 3d
3:10:42 9/10/10/0 0/0/0/0
192.168.13.12 65017 111687 11457 0 27 3d
3:10:30 9/10/10/0 0/0/0/0
192.168.16.12 65017 111687 11457 0 27 1w3d2h
Connect
user@host> show interfaces ge-0/0/7.0 extensive
Logical interface ge-0/0/7.0 (Index 76) (SNMP ifIndex 548) (Generation
141)
...
Security: Zone: log
Allowed host-inbound traffic : bootp dns dhcp finger ftp tftp ident-
reset http https ike netconf
ping reverse-telnet reverse-ssh rloqin rpm rsh snmp
snmp-trap ssh telnet traceroute xnm-clear-text xnm-ssl lsping ntp sip
r2cp
Flow Statistics:
Flow Input statistics:
Self packets: 0
ICMP packets: 0
VPN packets: 0
Multicast packets: 0
Bytes permitted by policy: 0
Connections established: 0
Flow Output statistics:
Multicast packets: 0
Bytes permitted by policy: 0
Flow error statistics (Packets dropped due to):
Address spoofing: 0
Authentication failed: 0
Incoming NAT errors: 0
Invalid zone received packet: 0
Multiple user authentications: 0
Multiple incoming NAT: 0
No parent for a gate: 0
No one interested in self pakets: 0
No minor session: 0
No more sessions: 589723
No NAT gate: 0
No route present: 0
No SA for incoming SPI: 0
No tunnel found: 0
No session for a gate: 0
No zone or NULL zone binding 0
Policy denied: 0
Security association not active: 0
TCP sequence number out of window: 0
Syn-attack protection: 0
User authentication errors: 0
Protocol inet, MTU: 1500, Generation: 1685, Route table: 0
Flags: Sendbcast-pkt-to-re
Addresses, F1ags: Is-Preferred Is-Primary
Destination: 10.5.123/24, Local: 10.5.123.3, Broadcast:
10.5.123.255, Generation: 156
Protocol multiservice, MTU: Unlimited, Generation: 1686, Route table: 0 Policer: Input: __default_arp_policer__
...
An SRX Series device has been configured with a logical system LSYS1.
One of the BGP peers is down.
Referring to the exhibit, which statement explains this problem?

  • A. The maximum number of allowed flows is set to low.
  • B. The allocated memory is not sufficient for this LSYS.
  • C. The LSYS license only allows up to ten BGP peerings.
  • D. The minimum number of flows is set to high.

Answer: A


NEW QUESTION # 99
Which two statements are correct about the output shown in the exhibit? (Choose two.)

  • A. The packet is an SSH packet
  • B. The source address is translated.
  • C. The destination address is translated.
  • D. The packet matches a user-configured policy

Answer: A,B


NEW QUESTION # 100
Exhibit

You are using traceoptions to verity NAT session information on your SRX Series device Referring to the exhibit, which two statements are correct? (Choose two.)

  • A. The SRX device is changing the source address on this packet from
  • B. This is the first packet in the session
  • C. The SRX device is changing the destination address on this packet 10.0.1 1 to 172 20.101.10.
  • D. This packet is part of an existing session.

Answer: B,C


NEW QUESTION # 101
......


Juniper JN0-636 (Security, Professional (JNCIP-SEC)) certification exam is designed for IT professionals who wish to validate their knowledge and expertise in managing security policies and implementing security solutions using Juniper Networks technology. Security, Professional (JNCIP-SEC) certification is intended for those who have already obtained a JNCIA-Junos certification and have experience in security technologies and Junos OS.

 

JN0-636 Exam Dumps For Certification Exam Preparation: https://troytec.getvalidtest.com/JN0-636-brain-dumps.html